On April 17, 2026, the Federal Reserve, the OCC and the FDIC issued revised guidance on model risk management. Published as SR 26-2 and OCC Bulletin 2026-13, it rescinds SR 11-7, the guidance banks had followed since 2011.
A principles-based approach
The revised guidance replaces detailed expectations with principles that scale with a model's materiality and risk. It covers development, validation, monitoring, governance, controls and third-party models, and states that practices appropriate for one bank may be inappropriate for another with a different risk profile.
Who it's for
The agencies describe it as most relevant to banks with more than $30 billion in assets, though smaller institutions with significant model risk may also need to consider it.
What it leaves out
Generative and agentic AI models are explicitly outside its scope; the agencies describe them as novel and rapidly evolving. Banks using them still need governance, and frameworks such as NIST's AI Risk Management Framework and its Generative AI Profile fill much of that gap.
Credit decisions
For credit models, the Equal Credit Opportunity Act and Regulation B still require specific reasons for every adverse action, however complex the model. Explainability remains a design requirement, not an afterthought.
