Guide

SR 26-2 and generative AI: what banks still need

SR 26-2 is the revised model risk management guidance that the Federal Reserve, the OCC and the FDIC issued on 17 April 2026, published by the OCC as Bulletin 2026-13. It supersedes SR 11-7 and is expected to be most relevant to banking organisations with over $30 billion in total assets. A footnote puts generative AI and agentic AI models outside its scope as “novel and rapidly evolving”, while traditional statistical models and non-generative AI stay in. The same footnote says a bank’s own risk management and governance should still set the controls for those tools, and the agencies plan a request for information on AI. So a bank using language models still needs an inventory, risk tiers, testing, independent review, monitoring and vendor evidence for them, built on its own policy rather than on SR 26-2.

SR 26-2. The Federal Reserve’s supervisory letter of 17 April 2026 carrying the revised interagency guidance on model risk management, which replaced SR 11-7 and places generative and agentic AI models outside its scope.

Checked . The guidance, the agencies’ letters and releases and the Vice Chair for Supervision’s speech were read on federalreserve.gov, occ.gov and fdic.gov, the third-party risk proposal on federalregister.gov and the NIST framework pages on nist.gov, on this date. Supervisory guidance is revised and the agencies have promised more on AI, so check the current text before you rely on it. This page is not legal advice.

What changed on 17 April 2026

On 17 April 2026 the Federal Reserve, the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) issued one revised piece of guidance on model risk management, each under its own reference. For the Federal Reserve it is SR 26-2, which “supersedes and replaces” SR 11-7, the model risk letter banks have worked to since April 2011, and SR 21-8, the 2021 statement on models used for Bank Secrecy Act and anti-money laundering compliance [1]. The OCC and the FDIC withdrew their own versions of the old guidance on the same day [3, 5].

Three things about it matter before you get to AI. It is tailored: the agencies expect it to be most relevant to banking organisations with more than $30 billion in total assets, though it may also be relevant to smaller ones with significant exposure to model risk [2]. It is guidance rather than a rule: it “does not set forth enforceable standards or prescriptive requirements”, and not following it will not bring supervisory criticism, although a footnote keeps supervisory action open for violations of law or unsafe or unsound practices that come from managing model risk badly [2]. And it sets the effort by materiality, meaning how much a model’s output matters to the business and what the model is for, with more rigour for the models that matter most [2].

What each agency issued on 17 April 2026, and the guidance each one withdrew
DimensionIssued asWhat it replaced
Federal ReserveSR 26-2, Revised Guidance on Model Risk ManagementSR 11-7 (4 April 2011) and SR 21-8 (9 April 2021)
OCCBulletin 2026-13, Model Risk Management: Revised GuidanceBulletins 2011-12, 1997-24 and 2021-19, and the Model Risk Management booklet of the Comptroller’s Handbook
FDICFIL-15-2026, Agencies Revise the Interagency Model Risk Management GuidanceFIL-22-2017 and FIL-27-2021

The footnote that takes generative and agentic AI out of scope

The AI exclusion sits in footnote 3, attached to the guidance’s definition of a model: “a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates” [2]. The footnote reads, in full: “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization’s risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document. However, the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models.” [2]

Stop after the second sentence and it reads like a free pass. The third sentence says the opposite. The agencies have not said a bank’s chatbots and agents need no controls. They have said the model risk framework is the wrong vehicle for them, for now, and that the bank’s own risk management has to decide what the controls are. I think that is a harder job than the one it replaces, because nobody has handed you the template.

Two weeks later the Federal Reserve’s Vice Chair for Supervision, Michelle W. Bowman, described the revised guidance as one that “now applies narrowly to traditional models and basic AI applications”, and added: “Going forward, we expect other risk-management and governance practices to support adoption of generative and agentic AI in ways that will encourage ongoing innovation.” [6]

The agencies also said they plan to issue, “in the near future”, a request for information on model risk management that considers banks’ use of AI, including generative and agentic AI [3, 4]. When I searched the Federal Register on 29 September 2026, it had not been published.

In scope
Traditional statistical and quantitative models, and AI models that are neither generative nor agentic, where they meet the guidance’s definition of a model [2]. A machine-learning credit or fraud model, for example, would usually sit here.
Out of scope
Generative and agentic AI models: a language model drafting replies to customers, an assistant summarising a credit file, an agent that takes actions in a bank system [2].
Not a model at all
Simple arithmetic such as spreadsheet calculations, and deterministic rule-based processes and software with no statistical, economic or financial theory behind them [2].
The hybrid case
A language model that reads documents and passes extracted figures to an in-scope model. The guidance does not address this case. My reading is that the downstream model stays in scope and the extraction becomes part of its input data, so it needs an accuracy check the model’s validators can see. Confirm that reading with your own model risk function before you build on it. Our guide to data strategy for AI sets out the checks to run on a source before an AI system reads it.

A control set for language model systems that a model risk team can defend

If the bank’s own risk management now sets the controls, the quickest defensible route is to borrow the structure SR 26-2 uses for the models it does cover and adapt each part to what a language model is. Examiners and internal audit already know that structure, so a control set built on it takes less explaining. The table below does that part by part. The middle column says where each idea comes from, so nobody mistakes it for a requirement SR 26-2 places on generative AI. A bank whose holding company reports to the SEC has one more set of controls to meet wherever a language model touches financial reporting, and our guide to SOX controls for AI in the finance close sets those out.

Nine controls for generative and agentic AI systems, the principle each one adapts and the evidence each one leaves
DimensionWhat it means for a language model systemWhere the idea comes fromEvidence it leaves
InventoryEvery generative and agentic AI system in use or being built, with its owner, purpose, vendor model and version, the data it reads and the actions it can takeSR 26-2 on the model inventory: enough information to understand model risks individually and in aggregate [2]; the Map function of the NIST AI RMF [8]The register and its change history
Materiality tierThe guidance’s two questions, how much the output matters to decisions and what the system is for, plus a third a traditional model never raised: can the system act, or only advise?SR 26-2 on model exposure, purpose and materiality [2]The tier recorded against each system, with the reasoning
Statement of purposeThe tasks the system may do, the tasks it must refuse, the data it may see and who may use it. A use outside the statement is a new use and is reviewed as oneSR 26-2 on a clear statement of purpose, and on extending a model beyond its intended use [2]A one-page purpose statement for each system, under version control
Testing before useAn evaluation set of real cases from the process, graded against answers the business owner has agreed, with a pass threshold set before anyone sees the resultsSR 26-2 on model testing and outcomes analysis [2]; pre-deployment testing in NIST’s Generative AI Profile [9]Evaluation results for each release
Effective challengeA reviewer with the expertise to test the system, independence from the team that built it and the standing to stop a releaseSR 26-2’s definition of effective challenge [2]A signed review, with the findings and the responses to them
Human oversight and action gatesFor an assistant, a named person owns anything sent or decided on its output. For an agent, deterministic checks on every proposed action, and a named approver for any action that moves money or changes a customer recordThe bank’s own policy; the verifier-gate patternGate logs: the proposed action, the checks run, the approver and the time
Ongoing monitoringA fixed sample of production outputs reviewed by people, plus alerts on grader scores, refusals and escalations to a personSR 26-2 on ongoing monitoring [2]; the Measure and Manage functions of the NIST AI RMF [8]Monitoring reports, and the actions taken on them
Change controlThe vendor model version pinned. Any change to the model, a prompt, a tool or the retrieval index reruns the evaluation before releaseSR 26-2 on validation timing and model changes [2]Release history with the evaluation run for each change
Vendor evidenceWhat the model provider publishes about the model, its versions and retirement dates, and its data use and retention, plus what the bank tested itself because the provider will not share weights or training dataSR 26-2 on vendor and third-party products [2]; value chain risk in NIST’s Generative AI Profile [9]; the agencies’ proposed third-party risk guidance [7]A file for each provider, reviewed at each contract renewal

Not every system needs all nine at full weight. An internal assistant that drafts text a person reads and rewrites sits low on both materiality questions, and needs the register, the purpose statement, approved access and a light sample. An agent that can change a customer record needs everything in the table before it runs. The effort should follow the tier, which is the same tailoring SR 26-2 asks for in the models it does cover [2]. Whether a workflow needs an agent at all is worth settling first, and our guide to AI agents for business sets out where agents fit and where a simpler workflow does the job.

This is a design built from published principles. It is not a statement of what any agency requires for generative AI, and it is not legal advice: whether it is enough for your institution is a question for your model risk function, your compliance team and your counsel.

Why validating a language model is different

SR 26-2 describes validation in three parts: conceptual soundness, outcomes analysis and ongoing monitoring [2]. For a scorecard, all three can start from the model itself. For a language model bought from a vendor, conceptual soundness mostly cannot. You will not get the weights or the training data, and nobody inside the bank can review the design of a frontier model the way a validator reviews a regression. The guidance already anticipates the vendor half of that problem: it notes that a bank may not receive a vendor’s code, data or methodology, and says the principles of model risk management still apply [2].

So the validation moves to the system around the model: the prompt, the retrieval, the tools and the rules that decide what an output is allowed to do. Those are the parts the bank wrote, can change and can test. Outcomes analysis carries most of the weight. The guidance says that where a model’s design relies heavily on expert judgement, quantitative outcomes analysis helps to evaluate the quality of that judgement [2], and a language model is, in effect, a judgement engine somebody else trained.

The closest published work of ours is not in a bank, but the method carries over. On a finance data connector, connecting the data took an afternoon, and the week after went on checking the agent’s answers against the finance director’s until the two agreed on the definitions the business uses (engagement file D-06). On a regulated speaking assessment, agreement with human examiners is a release gate in CI, and low-confidence cases go to a human examiner (engagement file D-02). Both are outcomes analysis under another name: the system is judged against people the business already trusts, before it ships and after.

What to watch next

The request for information the agencies promised in April is the one to watch. It is where they will show how they think about generative and agentic AI in banks, and answering it is a cheap way for a bank’s model risk team to be heard before anything firmer arrives.

On 15 September 2026 the OCC, the Federal Reserve, the FDIC and the National Credit Union Administration proposed third-party risk management guidance that would replace the 2023 interagency guidance, with comments due by 16 November 2026 [7]. The proposal does not mention AI. It still matters here, because a bank’s language model systems nearly always run on a vendor’s model, so it will shape the vendor row of the control set. Where the supplier building the system around that model has no SOC report to send, our guide to reviewing an AI supplier that has no SOC report sets out the evidence to ask for instead.

NIST says its AI Risk Management Framework is being revised as part of the White House AI Action Plan [8]. The framework is voluntary, but if your control set is mapped to it, expect to remap when the new version lands.

Where 1AYM fits

1AYM works in financial services, and building the controls in the table into the systems they govern is our AI governance implementation work, delivered as a fixed-scope architecture and production build. In practice that means the register kept as code, the evaluation suite running in CI, verifier gates on what an agent may do, and an audit trail those gates write as they run. Whether the result satisfies your examiners stays with your model risk function and your counsel. Our job is to make sure they have evidence to judge rather than a slide.

US clients can contract with 1AYM’s US entity. We hold no ISO or SOC certification today, so if your third-party process makes a SOC report a hard requirement, a first call is the cheapest place to find that out. Once a scope is signed, the build can start within a day. The call is booked from the end of this page.

For engineers: evaluation, versioning and the audit record

The control set in engineering terms. Each item is something a validator or an examiner can check in configuration, code or logs, rather than by asking someone.

Pin the model
Call a dated model snapshot, not an alias that the vendor can move. Record the model identifier on every logged call. Treat a vendor model change or retirement as a change event that reruns the evaluation suite before traffic moves.
Evaluation set
Sample real cases from the process and have the business owner write the expected answer or a grading rubric for each. Keep a held-out set that is never used while tuning prompts, so the release score is out of sample, as SR 26-2 describes for traditional model testing.
Graders
Use deterministic checks wherever the output is structured: fields, amounts, dates, and citations back to a retrieved document. Use a second model as a grader only for open text, and check that grader against human grades before trusting its scores.
Retrieval trace
Log the identifiers of the documents retrieved for each answer and the index version, so any answer can be traced to its sources. Confabulation, NIST’s term for confidently stated false content, is the failure this makes visible.
Agent actions
Give each tool an allow-list and run it under the identity of the person or service it acts for. Put a verifier gate in front of every write: schema, business rules, reconciliation against the system of record and an idempotency key. Offer a dry-run mode, so a reviewer can see what would change.
Monitoring
Review a fixed random sample of production outputs every week. Alert on grader score drift, refusal rate and escalation rate, and on any change in the vendor’s published model list.
The hybrid boundary
Where language model output becomes an input to an in-scope model, validate the extraction as a data quality control with its own accuracy threshold, and record it in the in-scope model’s documentation so its validators see it.
The audit record
For each call, write the input reference, model and prompt versions, retrieved document identifiers, check results, approver and timestamp to an append-only store with a stated retention period.

Sources

  1. [1]Federal Reserve, SR 26-2: Revised Guidance on Model Risk Management (17 April 2026), read 29 September 2026
  2. [2]Federal Reserve, FDIC and OCC, Supervisory Guidance on Model Risk Management, SR 26-2 attachment (17 April 2026), read 29 September 2026
  3. [3]OCC, Bulletin 2026-13, Model Risk Management: Revised Guidance (17 April 2026), read 29 September 2026
  4. [4]OCC, News Release 2026-29, OCC Issues Updated Model Risk Management Guidance (17 April 2026), read 29 September 2026
  5. [5]FDIC, FIL-15-2026, Agencies Revise the Interagency Model Risk Management Guidance (17 April 2026), read 29 September 2026
  6. [6]Federal Reserve, Vice Chair for Supervision Michelle W. Bowman, Artificial Intelligence in the Financial System (1 May 2026), read 29 September 2026
  7. [7]Federal Register, Proposed Third-Party Risk Management Guidance, 91 FR 58536 (15 September 2026), read 29 September 2026
  8. [8]NIST, AI Risk Management Framework, read 29 September 2026
  9. [9]NIST, AI 600-1, Generative Artificial Intelligence Profile (26 July 2024), read 29 September 2026

Questions model risk teams ask

Is SR 11-7 still in force?

No. SR 26-2 supersedes and replaces SR 11-7 for the Federal Reserve, the OCC rescinded its matching Bulletin 2011-12, and the FDIC rescinded FIL-22-2017, all on 17 April 2026. Material written to SR 11-7 is now out of date wherever it describes the guidance as current.

Does SR 26-2 apply to generative AI and AI agents?

No. Footnote 3 of the guidance says generative AI and agentic AI models are not within its scope. The same footnote says a bank’s own risk management and governance practices should guide the controls for tools the guidance does not cover, so they are outside this guidance but not outside governance.

Does SR 26-2 cover machine-learning models?

Yes, if they are neither generative nor agentic and meet the definition of a model. The footnote says the principles apply to traditional statistical and quantitative models and to non-generative, non-agentic AI models, so a machine-learning credit or fraud model, for example, would usually sit inside it.

Is SR 26-2 binding?

It is supervisory guidance. It says it does not set enforceable standards or prescriptive requirements, and that not following it will not result in supervisory criticism. It also says supervisory action may still follow violations of law or unsafe or unsound practices that stem from managing model risk badly. This is not legal advice.

Does SR 26-2 apply to banks under $30 billion in assets?

The agencies expect it to be most relevant above $30 billion in total assets, and say that smaller banks’ models are usually covered by their own internal risk management. It may still be relevant to a smaller bank with significant exposure to model risk, because of how many models it uses, how complex they are, or activities outside traditional community banking.

Has the request for information on AI been published?

The agencies said in April 2026 that they plan to issue one in the near future, covering model risk management generally and banks’ use of AI in particular. A search of the Federal Register on 29 September 2026 found no such request yet.

Does SR 26-2 apply to credit unions?

It was issued by the Federal Reserve, the OCC and the FDIC. The National Credit Union Administration is not one of the issuing agencies, so a credit union should check the NCUA’s own guidance.

Further

We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.

Last reviewed · 1AYM