Skip to content
Mayrian

SR 26-2: what changed from SR 11-7

The US banking agencies replaced their 2011 model risk guidance in April 2026. What the new guidance covers, and what it leaves out.

By Mayrian

· 1 min read

Share

On April 17, 2026, the Federal Reserve, the OCC and the FDIC issued revised guidance on model risk management. Published as SR 26-2 and OCC Bulletin 2026-13, it rescinds SR 11-7, the guidance banks had followed since 2011.

A principles-based approach

The revised guidance replaces detailed expectations with principles that scale with a model's materiality and risk. It covers development, validation, monitoring, governance, controls and third-party models, and states that practices appropriate for one bank may be inappropriate for another with a different risk profile.

Who it's for

The agencies describe it as most relevant to banks with more than $30 billion in assets, though smaller institutions with significant model risk may also need to consider it.

What it leaves out

Generative and agentic AI models are explicitly outside its scope; the agencies describe them as novel and rapidly evolving. Banks using them still need governance, and frameworks such as NIST's AI Risk Management Framework and its Generative AI Profile fill much of that gap.

Credit decisions

For credit models, the Equal Credit Opportunity Act and Regulation B still require specific reasons for every adverse action, however complex the model. Explainability remains a design requirement, not an afterthought.

How we can help

Choose a service to see its capabilities. Point at one to see what it's used for and what you receive.

All services

Custom Software Development

Software development

Web platforms and internal tools built around how your business works, released in small, tested increments.

Used for

  • Customer portals
  • Internal tools
  • SaaS products
  • Workflow and approvals
  • Marketplaces and booking platforms
  • Enterprise application extensions

What you receive

  • Source code in your repository, with a documented architecture
  • CI/CD pipeline and infrastructure as code
  • Automated test suite
  • Monitoring, logging and alerting
  • Security review against the OWASP Top 10:2025 and ASVS 5.0
  • Ownership and documentation handover
More on Software development

Working on something like this?

Start with a free technical consultation: a plan covering the right tech stack, architecture, timeline and budget.

Start a project