Below the Line Is Not the Same as Finished: SR 26-2 for Banks Under $30 Billion

When the Federal Reserve, OCC, and FDIC issued SR 26-2 on April 17, 2026, they were direct about who it is for. The guidance is expected to be most relevant to banking organizations with more than $30 billion in total assets. For a community or regional bank, that sentence can read like a pass.

It is not one. SR 26-2 describes, in more operational detail than anything since 2011, what supervisors now consider sound model risk practice. Examiners are already using it that way, at institutions well under the threshold. Being below the line today tells you what is required. It does not tell you what will be expected.

Asset size is the starting point, not the answer

The guidance includes a significant exposure exception. It may be relevant to smaller institutions whose models are prevalent or complex, or whose activities go beyond traditional community banking. Machine learning credit scoring, vendor AI tools, a complicated CECL build, or an unusual product mix can each put a smaller bank inside that language.

Where your bank lands depends on its profile:

Whatever your answer, make the determination in writing, have counsel review it, and keep it where an examiner can find it.

What changed from SR 11-7

For smaller institutions, several of the changes are good news. The narrower model definition and the end of the annual validation default both reduce overhead. The rest set a clearer bar.

Four moves worth making now

1. Take things off the list that were never models. Under SR 26-2, a tool is a model only if it applies statistical, economic, or financial theory, produces a quantitative estimate, and informs a decision with real consequence. All three. Amortization calculators, deterministic underwriting rules, templated report generators, and lookup tables do not qualify. Test every inventory item, remove what fails, and document why. Keep a non-model register rather than deleting the record.

2. Score materiality even though nobody is making you. Purpose asks how much weight rides on the decision. Exposure asks how far the damage travels if the model is wrong. The tier is the higher of the two. At most banks this size, CECL and BSA/AML land high, credit scorecards and ALM land medium, and internal analytics land low. Applied voluntarily, this gives you a program you can explain to an examiner in one sitting.

3. Remember vendor models are still your responsibility. The developmental evidence requirement is gone. Ownership is not. Someone inside the bank has to answer questions about each vendor model without calling the vendor first. Name that person, track performance quarterly, and check your agreements for documentation access rights before renewal, not after an examiner asks.

4. Close the AI governance gap. The GenAI exclusion is a deferral, not relief. AI-assisted document review, LLM compliance workflows, and vendor products with AI components you never scoped can all sit outside your model risk program with nothing over them. Inventory every AI tool, separate generative and agentic AI from traditional machine learning, and place accountability somewhere other than IT.

Why moving early beats waiting

Banks that wait for a requirement before building governance tend to end up in the same place: a compressed, expensive remediation program run on an examiner's timeline rather than their own. Four reasons to start now:

  • Examiner expectations have already moved. Supervisors trained on SR 26-2 apply its logic to institutions of every size.

  • The $30 billion line is not fixed. Organic growth or a single acquisition can move a bank across it faster than a program can be built.

  • CECL and BSA/AML carry real risk regardless. The allowance model driving reported credit losses is material at any asset size.

  • Done well, it costs less. Concentrating rigor on high-materiality models and pulling process off low-risk tools usually reduces total governance spend.

A preparation roadmap

Below $30 billion, this is voluntary. If growth or an acquisition is moving you toward the line, the same list becomes a pre-crossing checklist with a real deadline.

What examiners are already asking

SR 26-2 disclaims direct enforceability. Criticism arrives where a governance gap contributes to an unsafe or unsound practice, and these questions are surfacing at institutions well under the threshold:

  • Can you explain which of your quantitative tools are models and which are not?

  • Who owns your CECL model, and when did you last look at how it is performing?

  • Are your BSA/AML thresholds calibrated to current transaction patterns, or to the ones you had at installation?

  • Have you inventoried your AI tools, and what standard covers them?

  • If your CECL vendor changed methodology next quarter, how would you find out?

The bottom line

SR 26-2 gives smaller banks something rare: a clear description of the standard before it applies to them. Banks that use it as a target state will spend less, explain their programs with confidence, and cross the $30 billion line without a scramble. Banks that treat it as someone else's problem will meet it anyway, on an examiner's schedule.

For the full applicability guide and preparation roadmap, download the guide, SR 26-2 and the Bank Under $30 Billion.

Next
Next

You Are in Scope. Now Close the Distance: SR 26-2 for Banks Above $30 Billion