You Are in Scope. Now Close the Distance: SR 26-2 for Banks Above $30 Billion

For banks below $30 billion in total assets, SR 26-2 is a standard to prepare against. For banks above that line, it is a program to run today. The Federal Reserve, OCC, and FDIC issued the guidance on April 17, 2026, replacing SR 11-7 and SR 21-8. Above $30 billion, applicability is settled.

The useful question is how far your current program sits from the revised standard. Fifteen years under SR 11-7 built in assumptions about validation cadence, what counts as a model, how vendors are handled, and what internal audit does. SR 26-2 changes all four.

This is not SR 11-7 with an AI section bolted on

SR 11-7 rewarded procedural completeness. SR 26-2 asks for judgment, proportionality, and continuous assurance, and it expects the institution to defend each judgment. At scale, that shift shows up in five places:

  • Monitoring replaces periodic review as the primary assurance mechanism for material models.

  • Aggregate model risk becomes a governance concept in its own right.

  • Data quality moves from a development input to a component of inherent risk.

  • GenAI and agentic AI become an explicit organizational responsibility, outside SR 26-2 scope but well inside examiner interest.

  • Internal audit shifts from re-testing models to assessing whether the program works.

The model definition is the one change that gives time back. Every other row asks for more.

Where the gaps sit

Five areas carry the highest combination of examiner visibility and remediation cost. At most institutions above $30 billion, at least three are open.

1. Monitoring infrastructure. Tier 1 models need performance tracking against thresholds set in advance, at or near real time, with escalation that triggers recalibration before deterioration becomes a finding. Watch inputs for distributional drift, not only outputs for accuracy. Output monitoring finds the problem later than input monitoring does.

2. Aggregate model risk. SR 11-7 governed models one at a time, so most programs never built this. Models can each look well controlled while a defect in a shared data feed, a vendor methodology change, or a common scenario assumption moves through several at once. Map shared data sources, scenarios, vendor concentration, and pre-processing pipelines, and govern at the component level.

3. AI governance. This is the most consequential gap at scale, because the obligation falls between model risk and the technology teams that deployed the tools. The inventory has to include AI embedded in vendor products nobody scoped as AI, which is harder and slower than it sounds. Apply SR 26-2 logic as the interim standard and place accountability at board or senior management level. Leaving it with technology will not survive an examination.

4. Data governance integration. Monitoring now has to ask whether a model is still fit for purpose as its data evolves. That is a different question from whether outputs match historical benchmarks. At most large banks, model risk and data governance report separately. The guidance effectively requires a path that moves material data issues into model risk without a quarter of delay.

5. Internal audit scope. Many audit functions drifted toward technical re-testing under SR 11-7, effectively running a second validation. SR 26-2 positions audit to evaluate whether the program is rigorous and effective. Is materiality scoring defensible? Are validation resources allocated in line with risk? Does escalation function when something breaks? Those questions require different expertise.

What the board should see

Board reporting should move from model-by-model detail to aggregate model risk, Tier 1 performance trends and deterioration events, AI governance posture, and validation backlog on high-priority findings. Management reporting carries the operating detail: validation pipeline by tier, monitoring exceptions and what escalation produced, data events touching material models, and vendor friction over documentation access. Examiners will read both layers as evidence of oversight, whether or not they were written that way.

A sequence for closing the delta

Mature SR 11-7 programs will find much of this partly in place. The work is closing the gap, not rebuilding.

  1. Now: Run the gap assessment. Pick the five to ten highest-priority gaps by materiality and examiner visibility.

  2. Days 0 to 30: Re-classify the inventory against the three-part definition and move GenAI to its own track.

  3. Days 30 to 90: Replace the annual cycle with risk-based validation and stand up Tier 1 monitoring with thresholds, escalation, and drift detection. Stand up interim AI governance in the same window.

  4. Days 60 to 120: Map aggregate model risk and connect data governance to model risk with lineage, relevance monitoring, and a formal escalation path.

  5. Days 90 to 120: Rewrite policy and board reporting, and realign audit scope to governance oversight.

  6. Through 2026: Track the interagency AI RFI and keep the inventory and interim standard current.

What examiners will ask

SR 26-2 disclaims direct enforceability. Criticism arrives where governance weakness contributes to an unsafe or unsound practice, and at this scale that is not a narrow opening. Expect questions like these:

  • Walk through continuous monitoring on a Tier 1 model. What are the thresholds, who gets the alert, and what happened the last time one triggered?

  • If your primary CECL vendor changed methodology next quarter, what else moves?

  • Show us the GenAI and agentic inventory. What standard governs it, and who is the accountable executive?

  • Trace the path a source system change takes to reach the model risk function.

  • Take a model that underperformed in the last twelve months. What did monitoring catch, how long did it take, and what did escalation produce?

The bottom line

Above $30 billion, SR 26-2 is less about new rules and more about proof. Examiners will not ask whether your program follows a checklist. They will ask whether it sees problems early, connects risks across models and data, and reaches the board in a form leaders can act on. Banks that can show that with evidence will spend their exam discussing strategy. Banks that cannot will spend it discussing findings.

For the full component-by-component standard and implementation table, download the guide, SR 26-2 and the Bank Above $30 Billion.

Previous
Previous

Below the Line Is Not the Same as Finished: SR 26-2 for Banks Under $30 Billion

Next
Next

SR 26-2 Moves the Pen to the Bank: What the New Model Risk Guidance Asks of You