Validation, monitoring, documentation, challenge.
The phrase model risk management framework is regulator language SR 11-7 established. SR 26-2 (17 April 2026) is the current guidance: it supersedes SR 11-7, restates the discipline as principles-based and risk-tailored, and — at footnote 3 to § II — puts generative and agentic AI outside its scope. This page reads the artefact against four pillars, and that four-way grouping is Warrant's: § III names three elements, § VI carries documentation separately, and neither letter numbers them. Two of the four resolve to a field the signed package actually carries; the rest are printed below as gaps, because naming a field that does not exist is the more expensive error. For the pillar-by-pillar reading, see SR 26-2 / SR 11-7 model risk, read against the AI agent.
The lifecycle obligations.
inputs — the sample underwriting trace carries model_validation_record_id there — but raw step inputs are read by the pipeline and not re-emitted, and the evidence schema defines no validation field. Nothing in the signed package binds a validation outcome to the decision.
authorizations[].preconditions_met per action, as yes, no or uncertain. NO FIELD for the monitoring metrics: there is no model_governance object and no drift or population-stability field in the schema. One sample trace mentions champion-challenger and a PSI figure inside a free-text step output — prose the emitter wrote, not a field the package carries.
agent_id and regulated_entity are real keys at the root of the trace a customer submits — siblings of the root trace array, not properties of it, so there is no trace.agent_id path. Neither is re-emitted into the signed package. NO FIELD for model identity: the evidence schema has no model identifier and no model version, and neither model_id nor model_version reaches the signed package, so no documentation gap can be surfaced from an absent version.
actions[*] carries action_id, actor, action and subject only, and the schema is additionalProperties: false, so a discarded alternative has nowhere to sit and nothing flags its absence.
agent_id and root regulated_entity, and neither is re-emitted into warrant-v1, so nothing in the package identifies an inventory row. Cross-trace inventory roll-up ships v0.5, 2026 Q3.
The current guidance. Tailored for AI.
SR 26-2 was issued jointly by the Federal Reserve, OCC, and FDIC on 17 April 2026 (OCC Bulletin 2026-13) as the Revised Guidance on Model Risk Management. It supersedes and replaces SR 11-7 (2011) and SR 21-8. The lifecycle discipline carries forward — Warrant's four-pillar grouping of it is Warrant's, not the regulator's numbering — restated as principles-based and risk-tailored rather than prescriptive, and reads as most relevant to banks above USD 30 billion in assets. Then footnote 3 to § II narrows who it reaches: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document. However, the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models."
Read that against a deployment. The conventional scoring, pricing, or fraud model an agent calls is squarely in scope and carries the whole lifecycle. The agent's own per-action conduct is not in scope at all, and no successor framework has issued. Be exact about what remains, because this is the sentence most often overstated: footnote 1 preserves supervisory action for violations of law or unsafe or unsound practices — the agencies' independent authority, which does not depend on this letter — and § I states that non-compliance with the guidance itself will not result in supervisory criticism. So the exclusion is not a safe harbour and it is also not a penalty regime; it is a gap, with an independent enforcement hook sitting beside it. Warrant's reading: the bank writes the standard it will be examined against, and finds out at the examination whether it wrote it high enough. Where the agent's audit trail does carry a binding rule today — NYDFS § 500.6(a)(2), read next to the footnote-3 carve-out — is worked through in the AI agent audit trail: NYDFS 500.6 + SR 26-2. Nothing in the guidance uses the phrases artificial intelligence, machine learning, large language model, or runtime.
GAO B-331324 (22 October 2019) is the Comptroller General's decision on SR 11-7 itself: Board of Governors of the Federal Reserve System — Applicability of the Congressional Review Act to Supervision and Regulation Letter 11-7, which concluded that SR 11-7 was a rule for Congressional Review Act purposes and so should have been submitted to Congress. Counsel still trace the lineage by number, but the paragraph references do not carry across: SR 26-2 renumbers and rewrites the subheads, dropped Implementation from the § IV heading, and neither letter has lettered subsections at all, so a lettered-subsection pinpoint cites nothing in either document. Map by topic, not by number. The artefact a supervisor reads is the same shape under the current guidance.
What did SR 26-2 change for AI in banking?
SR 26-2 was issued on 17 April 2026 and supersedes SR 11-7 and SR 21-8 while carrying the lifecycle discipline into a principles-based, risk-tailored restatement. What it changed for AI is a subtraction: footnote 3 to § II states that generative AI and agentic AI models are not within the scope of the guidance, and routes them to the bank's general risk management and governance practices. Two subtractions, not one: § I also states that the guidance sets no enforceable standards or prescriptive requirements and that non-compliance with it will not result in supervisory criticism. So the pillars — Warrant's four-way grouping of the regulator's three named elements plus documentation — describe sound practice a bank is expected to be able to evidence, not a rule an examiner can cite, including for any conventional model an agent calls. For the agent itself there is no test in the letter at all, which is why the question arrives as safety and soundness instead: what is your framework for monitoring and testing this system, and what evidence shows it worked.
The published enforcement record is thinner than the model-risk framing suggests, and it is worth stating precisely. On 20 April 2018 the OCC assessed a USD 500 million civil money penalty against Wells Fargo Bank, N.A., for "unsafe or unsound practices" and deficiencies in its "enterprise-wide compliance risk management program"; the Bureau of Consumer Financial Protection separately assessed USD 1 billion and credited the OCC's amount against its own. On 7 October 2020 the Federal Reserve issued a cease-and-desist order against Citigroup Inc. reciting "significant ongoing deficiencies in implementation and execution by Citigroup with respect to various areas of risk management and internal controls, including for data quality management and regulatory reporting, compliance risk management, capital planning, and liquidity risk management." Two points counsel should hold onto: that Federal Reserve order carried no monetary penalty — the USD 400 million civil money penalty announced the same day was the OCC's, against Citibank, N.A. — and the word "model" does not appear in the Federal Reserve order at all, nor in the OCC's 2018 Wells Fargo release. Warrant has not identified a published US banking enforcement action that cites SR 11-7 or SR 26-2 by number. Documents retrieved 6 August 2026.
Supervisory attention to AI is on the record; a model-risk hook for it is not. The OCC's Semiannual Risk Perspective for Spring 2025 records that AI in banking already includes "some components of credit underwriting, such as financial analysis and collateral evaluation processes" and that using any form of AI "can introduce model, cybersecurity, and compliance risks"; the Fall 2025 edition records that "Generative AI use cases have largely been internal facing." Neither edition designates generative AI in lending as a heightened-risk activity, and neither uses the phrase "model risk" at all. One thing follows from the text: there is no SR 26-2 citation to bring against the agent itself, because footnote 3 removed the agent from the letter's scope. What Warrant expects next is an inference, offered as such and not as a supervisory position — that the question would arrive in the general safety-and-soundness form instead, and that an unmapped agent in a material decisioning role would draw it at examination despite the carve-out. Neither agency has said so. Both editions retrieved 6 August 2026.
Per-pillar field map.
The mapping below carries each of Warrant's four pillars and the supervisory expectations Warrant reads out of them. Each row names the obligation, Warrant's reading of what a supervisor would look for, and what the signed package carries against it — including, in most rows, that it carries nothing. That is the honest state of a model-risk mapping for an agentic system, and SR 26-2 § II footnote 3 is why: it places generative and agentic AI outside the guidance, so Warrant does not claim to evidence obligations the guidance itself excludes. Warrant publishes this as the table it would put in front of an OCC or Federal Reserve examiner on horizontal review — our framing of an examination, not a procedure either agency has described.
inputs, as the sample underwriting trace does with model_validation_record_id. Raw step inputs are not re-emitted into the signed package and the evidence schema defines no validation field, so nothing binds a validation outcome to the decisions downstream of it.
model_governance object, no drift-indicator field and no validation-record field anywhere in the evidence schema, so the package carries no ongoing-testing evidence and no live-validation linkage.
authorizations[].preconditions_met is attached per action at decision time rather than aggregated post-hoc, and records whether that action's inputs satisfied its preconditions. NO FIELD for champion-challenger, population stability or drift metrics: the schema defines none of them.
agent_id is a real key at the root of the submitted trace, alongside the root trace array rather than inside it, and it is not re-emitted into the package. NO FIELD for model identity: neither model_id nor model_version exists in the evidence schema or reaches the signed package, so the per-decision snapshot does not resolve to model-card lineage. What it does resolve to is the obligation set — obligations.<action_id>[].evidence, an object keyed by action id rather than a flat array, read against trace_metadata.regulations_corpus_sha256.
regulated_entity is a real key at the root of the submitted trace and is not re-emitted into the package. NO FIELD for policy version: there is no policy_version_id in the evidence schema, so no gap can be surfaced from a missing or detached policy version. The replicability standard is served, to the extent it is served at all, by authorizations[*].justification and obligations.<action_id>[].evidence being readable without contacting Warrant.
actions[*] carries action_id, actor, action and subject only, so a discarded alternative is not recorded and its absence is not flagged. Warrant makes no claim about how often effective challenge appears in Matters Requiring Attention: those findings are not published, so no ranking of them is verifiable from the public record.
agent_id and root regulated_entity, and neither is re-emitted into warrant-v1, so nothing in the package identifies an inventory row. Cross-trace inventory roll-up ships v0.5, 2026 Q3.
signed_off_by in the evidence schema and no field carrying an officer's name, role or tenant, so the package does not bind a decision to a senior officer. The receipt's cosign_status, with cosign_signed_actions of cosign_total_actions, reports whether the customer co-signed the trace it submitted — a key holder, not a named accountable officer.
agent_id on the submitted trace identifies the deployment, and it stays on the input: it is not re-emitted into the signed package. NO FIELD for foundation-model lineage: model_version does not exist in the evidence schema. Whatever standard the bank writes for the excluded system, the package does not evidence the model's lineage against it.
regulated_entity on the submitted trace names the chartered bank, and it is not re-emitted into the signed package. NO FIELD for a vendor or sponsor-bank tenant: the evidence schema has no tenant field, so the bank's MRM framework does not read through to a third-party model via the package.
Questions a CRO and OCC examiner ask first.
Primary citations.
The current Federal Reserve guidance is SR 26-2 (17 April 2026) at federalreserve.gov/supervisionreg/srletters/SR2602.htm, with the OCC companion at OCC Bulletin 2026-13. The guidance itself is the attachment at SR2602a1.pdf, which is where § I, § II, § VI, § VII, footnote 3, and footnote 1 are quoted from on this page (retrieved 6 August 2026; a probe for the adjacent SR2601.htm and for a non-existent SR2699a1.pdf returns 404 on the same host, so the 200 on SR 26-2 discriminates). SR 26-2 supersedes SR 11-7 (2011) and SR 21-8; the supersession is stated in SR 26-2's own text. The Federal Reserve has withdrawn the SR 11-7 page — srletters/sr1107.htm returns 404 (re-checked 6 August 2026) — and the OCC has rescinded its companion, OCC Bulletin 2011-12, per the Rescissions list in OCC Bulletin 2026-13. The SR 11-7 passages quoted on this page are therefore taken from the identical guidance as adopted and published by the FDIC in FIL-22-2017, fil17022a.pdf, cross-checked against the Federal Reserve's own withdrawn attachment; both were read in full rather than searched. The full Supervision and Regulation Letters archive is at srletters.htm. GAO B-331324 is at gao.gov/products/b-331324.