On April 17, 2026, the Federal Reserve issued SR 26-2 and stated that it supersedes and replaces SR 11-7 and SR 21-8. The revision keeps the core disciplines of sound model risk management but makes the program more explicitly risk-based, proportionate, and tailored to a banking organization's model profile, size, complexity, and risk.
Scope matters
SR 26-2 is directed to Federal Reserve-supervised banking organizations with more than $30 billion in total consolidated assets and to U.S. branches and agencies of foreign banking organizations. Institutions outside that stated scope should not describe the letter as directly applicable without confirming their regulator's expectations. The risk-management principles may still be useful when an institution designs a proportionate program.
What changed from SR 11-7
The revised guidance removes the expectation that every model receive the same procedural treatment. Management should begin with the institution's actual model risk and then scale inventory information, validation, monitoring, governance, and documentation accordingly. A low-risk tool may justify a lighter control approach; a high-impact credit, capital, compliance, fraud, or balance-sheet model should receive deeper challenge and more frequent oversight.
This does not eliminate discipline. It raises the importance of a defensible risk-tiering method, documented judgment, clear ownership, and evidence showing that the selected control depth matches the model's use, materiality, complexity, uncertainty, and potential harm.
Keep one authoritative model inventory
The inventory should make it possible to understand which models exist, why they are used, who owns them, where they operate, which data and vendors they depend on, their risk tier, validation status, monitoring status, material limitations, open issues, and planned retirement. It should also distinguish a model from rules, reports, calculations, and other analytical tools under the institution's approved definition.
Inventory quality is an operating control. Reconcile the inventory to procurement, technology assets, applications, data platforms, model-development repositories, and business attestations so unregistered or retired models do not quietly persist.
Use validation depth that follows risk
Independent validation should remain credible, but the scope can be tailored. The review may address conceptual soundness, data, assumptions, implementation, outcomes, sensitivity, stability, benchmarking, limitations, controls, and the way people use the model. The validation plan should explain why particular procedures are sufficient for the risk tier.
Vendor models remain the bank's responsibility. Contractual limits or opaque methods do not remove the need for challenge. Where information is constrained, the institution may need alternative testing, stronger use limitations, compensating controls, enhanced monitoring, or a different product decision.
Monitor model performance and use in context
Monitoring should cover more than predictive accuracy. Depending on the use case, management may need indicators for data quality, drift, calibration, overrides, exceptions, population changes, fairness, reason-code behavior, downstream outcomes, incidents, unresolved limitations, and whether the model is being used outside its approved purpose.
Thresholds should trigger owned investigation and documented disposition. A dashboard without escalation, issue management, remediation, and closure evidence is reporting, not a complete control.
Separate SR 26-2 scope from generative and agentic AI governance
The Federal Reserve states that generative AI and agentic AI are outside the scope of the revised model risk guidance. That does not make those technologies ungoverned. Institutions should use their AI, technology, information-security, data, compliance, vendor, operational-risk, and change-governance processes to determine appropriate controls.
Traditional statistical and quantitative models, along with non-generative and non-agentic AI that meet the institution's model definition, remain within the model risk framework. An AI inventory should therefore identify the technology type and route each use to the right governance path rather than assuming one policy covers everything.
Management and board reporting should become more decision-useful
Reporting should show the model risk profile, material changes, validation coverage, overdue work, performance and control exceptions, concentrated vendor dependencies, unresolved limitations, significant issues, remediation progress, and decisions requiring escalation. The goal is not a larger packet. It is a clearer view of where risk is changing and whether management action is adequate.
A practical transition sequence
- Confirm scope and regulatory ownership. Document which entities and models are subject to SR 26-2 and which governance applies to other analytical or AI systems.
- Revisit the model definition and inventory. Identify omissions, duplicates, retired models, vendor dependencies, and unclear ownership.
- Recalibrate risk tiers. Use impact, complexity, uncertainty, use, exposure, and control reliance to determine proportional requirements.
- Map requirements to evidence. Define the minimum documentation, validation, approval, monitoring, change, issue, and reporting evidence for each tier.
- Address transition risk. Prioritize high-impact gaps and avoid weakening established controls before the revised approach is approved and operational.
How Cicrim helps
Cicrim helps banks translate SR 26-2 into an operating model: Scope, model definition, inventory, tiering, validation standards, monitoring, issues, vendor governance, committee reporting, AI-governance interfaces, and reviewable evidence. The work is tailored to the institution rather than built around a generic checklist.
Discuss SR 26-2 readinessThis article provides a general operating perspective and is not legal or regulatory advice. Institutions should confirm applicability and implementation expectations with their regulators and qualified advisors.