SR 26-2 Moves the Pen to the Bank: What the New Model Risk Guidance Asks of You

On April 17, 2026, the Federal Reserve, OCC, and FDIC retired SR 11-7 and replaced it with SR 26-2. It is the first full rewrite of U.S. model risk management guidance in fifteen years, and the early commentary has focused on what was removed: the annual review, the broad model definition, the vendor contingency language.

That reading misses the point. SR 26-2 did not lower the bar. It moved the bar from the regulator's page to the bank's policy. Every judgment the guidance no longer makes is now one the institution must make, write down, and defend in front of an examiner.

What changed, in brief

  • A narrower model definition. A model is now a complex quantitative method grounded in statistical, economic, or financial theory. Simple spreadsheet arithmetic and deterministic rule-based processes are out.

  • Generative and agentic AI are outside scope. Traditional statistical models and non-generative, non-agentic AI remain in.

  • No validation calendar. The annual review default is gone. Validation generally happens before first use, with timing driven by the model itself.

  • Materiality finally has a structure. Model purpose together with model exposure determines materiality.

  • Not enforceable on its own. Non-compliance with the guidance will not by itself draw criticism. Unsafe or unsound practices still will.

  • Consolidation. SR 11-7 and SR 21-8 (the BSA/AML model statement) are both superseded.

The $30 billion line is a relevance line, not a scope test

SR 26-2 says it is expected to be most relevant to banking organizations above $30 billion in total assets. It also says it may apply below that line where model use is complex or activities go beyond traditional community banking.

Three groups should pay close attention. Banks approaching $30 billion through growth or acquisition, since balance sheets can cross the line faster than programs mature. Smaller banks with heavy mortgage servicing, capital markets activity, or fintech partnerships. And large credit unions, which are not covered directly but will find SR 26-2 the clearest current statement of sound practice.

Data quality is now model risk

This is the change data leaders should notice first. SR 26-2 names input quality and data constraints as drivers of a model's inherent risk, and it lists data relevance among the conditions ongoing monitoring must track. A model whose inputs have drifted is no longer just a data issue. It is a model risk issue.

At many institutions, data governance and model risk management run as separate functions with separate tools. SR 26-2 gives both a regulatory reason to connect: lineage documentation for material models, monitoring of production inputs against development data, and a defined path for data events to reach model owners. Neither function can meet this obligation alone.

The GenAI exclusion is the most misread part of the guidance

Removing generative and agentic AI from scope does not remove them from oversight. Footnote 3 of the attachment is explicit: the institution's broader risk management and governance practices should determine the controls for anything the guidance does not cover.

Supervisors can still reach these tools through third-party risk, operational resilience, information security, and consumer protection. Every deployment, from LLM-assisted document review to agentic workflows, needs a documented governance basis today. The agencies have announced a request for information on AI and model risk, and the banks that answer it best will be the ones answering from documented practice rather than intent. Treasury's Financial Services AI Risk Management Framework, released in February 2026, offers a practical control matrix for building that interim standard.

Vendor models: lighter text, same substance

SR 26-2 says less about vendor models than SR 11-7 did. The principles still apply, and validation of vendor products by internal or outside parties is still called an important element. What dropped out is the explicit expectation of contingency plans. SR 23-4 on third-party relationships still covers that ground, and a material vendor model with no fallback is still a resilience gap.

The harder problem is the AI boundary inside vendor platforms. A single fraud or BSA/AML product can hold in-scope models, non-model rules, and out-of-scope generative features at once. Ask each material vendor to identify which components fall where, and record the answer in both the model inventory and the due diligence file.

Monitoring without a calendar

SR 26-2 does not require real-time monitoring. It removes the calendar as the default and replaces it with a rationale the institution has to defend. For high-materiality models with fast-moving inputs, a defensible cadence is hard to sustain without automated pipelines, threshold alerts, and escalation workflows. For low-materiality models, periodic checks may be enough if the reasoning is written down. Either way, an examiner should be able to follow each finding from detection to resolution.

Where to start: sequence beats speed

The work has a natural order. Materiality scoring depends on a clean inventory, and the policy rewrite depends on both.

  1. Days 0 to 30: Re-classify the inventory. Test every entry against the new definition. Classify each as a model, a non-model tool, or out-of-scope AI, with a written rationale. Keep non-model tools under end-user computing or application controls.

  2. Days 30 to 60: Score materiality and map data. Define purpose and exposure criteria, tier the inventory, and map lineage and data constraints for higher-tier models.

  3. Days 60 to 90: Close vendor and AI gaps. Test vendor validation evidence and adopt an interim GenAI standard that examiners can review.

  4. Days 90 to 120: Rewrite policy. Remove SR 11-7 prescriptive language, set validation frequency by tier, and take it to the board or risk committee.

  5. Ongoing: Build monitoring infrastructure. Thresholds, drift detection, escalation, and evidence of review.

Five questions to be ready to answer

  1. Which tools did you remove from the model inventory, and what is the documented basis for each?

  2. How do you determine materiality, and how does it set validation depth and frequency?

  3. How does ongoing monitoring detect data quality deterioration in material models?

  4. How do you validate vendor models when the vendor will not share code or data?

  5. What governs your generative and agentic AI while they sit outside SR 26-2?

The bottom line

SR 11-7 rewarded institutions that followed the checklist. SR 26-2 rewards institutions that can explain their reasoning. That is a better standard, and a more demanding one. The banks that treat it as deregulation will find out otherwise at their next exam. The banks that treat it as an invitation to build a program around their own risk, data, and models will come out ahead.

For the full line-by-line gap analysis and a detailed roadmap, download the SR 26-2: The New Model Risk Management Guidance, Explained white paper.

Previous
Previous

You Are in Scope. Now Close the Distance: SR 26-2 for Banks Above $30 Billion

Next
Next

How Do You Measure Whether an AI Policy Is Working?