REGULATOR · US FED · MODEL RISK MANAGEMENT
UPDATED 2026-06-10 · SR 26-2 (2026-04-17) SUPERSEDES SR 11-7

SR 26-2 / SR 11-7.

Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant. SR 26-2 (17 April 2026, OCC Bulletin 2026-13) is the current Federal Reserve / OCC / FDIC interagency guidance on model risk management; it supersedes and replaces SR 11-7 (2011) and SR 21-8, principles-based and risk-tailored, most relevant to banks above USD 30 billion in assets · jurisdiction: US banks under Fed, OCC, FDIC supervision · penalty: none flows from the guidance itself. Say that precisely, because it is routinely got wrong: § I states the guidance sets no enforceable standards, and footnote 1 preserves supervisory action only for violations of law or unsafe or unsound practices — an independent authority the agencies hold regardless of this letter, not a sanction for departing from it. Matters Requiring Attention, Matters Requiring Immediate Attention and civil money penalties are instruments of that independent authority. And for a generative or agentic system, footnote 3 puts the system outside the guidance altogether, so the guidance supplies no standard to depart from in the first place. The guidance runs to model development and use, validation and monitoring, governance and controls, and vendor and other third-party products. Read its own status first: § I states that it "does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism against a banking organization." Footnote 3 to § II then takes generative and agentic AI out of scope and leaves them to the bank's general risk management and governance practices, while footnote 1 keeps supervisory action available for any violations of law or unsafe or unsound practices stemming from insufficient management of model risk.

DISCIPLINE
Four pillars
Model risk management lifecycle, all material decision models. Warrant's four-way grouping; § III names three elements.
CURRENT GUIDANCE
SR 26-2 · 2026-04-17
Supersedes SR 11-7 (2011) and SR 21-8. OCC Bulletin 2026-13 companion.
SUPERVISORS
Fed · OCC · FDIC
Joint guidance, enforced under examinations.
01 · MODEL RISK LIFECYCLE

Validation, monitoring, documentation, challenge.

A bank's board and senior management should establish a strong model risk management framework that fits into the broader risk management of the organization. That framework should be grounded in an understanding of model risk — not just for individual models but also in the aggregate. The framework should include standards for model development, implementation, use, and validation. SR 11-7 § VI, "Board of Directors and Senior Management" — quoted verbatim. Issued 4 Apr 2011, superseded 17 Apr 2026. As at the source retrieved 6 Aug 2026. SR 11-7 does not use the words artificial intelligence or machine learning anywhere.

The phrase model risk management framework is regulator language SR 11-7 established. SR 26-2 (17 April 2026) is the current guidance: it supersedes SR 11-7, restates the discipline as principles-based and risk-tailored, and — at footnote 3 to § II — puts generative and agentic AI outside its scope. This page reads the artefact against four pillars, and that four-way grouping is Warrant's: § III names three elements, § VI carries documentation separately, and neither letter numbers them. Two of the four resolve to a field the signed package actually carries; the rest are printed below as gaps, because naming a field that does not exist is the more expensive error. For the pillar-by-pillar reading, see SR 26-2 / SR 11-7 model risk, read against the AI agent.

"A bank's board and senior management should establish a strong model risk management framework." The phrase is the spec. Everything else is engineering.SR 11-7 § VI · quoted verbatim; the two sentences after the quotation are Warrant's, not the regulator's
02 · FOUR PILLARS

The lifecycle obligations.

Validation
Independent validation evidence. WARRANT · NO FIELD. A submitted trace may carry a validation reference in a step's inputs — the sample underwriting trace carries model_validation_record_id there — but raw step inputs are read by the pipeline and not re-emitted, and the evidence schema defines no validation field. Nothing in the signed package binds a validation outcome to the decision.
Monitoring
Ongoing monitoring (champion-challenger, PSI, drift). WARRANT · authorizations[].preconditions_met per action, as yes, no or uncertain. NO FIELD for the monitoring metrics: there is no model_governance object and no drift or population-stability field in the schema. One sample trace mentions champion-challenger and a PSI figure inside a free-text step output — prose the emitter wrote, not a field the package carries.
Documentation
Comprehensive model documentation. WARRANT · agent_id and regulated_entity are real keys at the root of the trace a customer submits — siblings of the root trace array, not properties of it, so there is no trace.agent_id path. Neither is re-emitted into the signed package. NO FIELD for model identity: the evidence schema has no model identifier and no model version, and neither model_id nor model_version reaches the signed package, so no documentation gap can be surfaced from an absent version.
Challenge
Effective challenge captured. WARRANT · NO FIELD. actions[*] carries action_id, actor, action and subject only, and the schema is additionalProperties: false, so a discarded alternative has nowhere to sit and nothing flags its absence.
Inventory
Model inventory maintained. WARRANT · no field in the signed package. The submitted trace carries root agent_id and root regulated_entity, and neither is re-emitted into warrant-v1, so nothing in the package identifies an inventory row. Cross-trace inventory roll-up ships v0.5, 2026 Q3.
03 · SR 26-2 SUPERSESSION

The current guidance. Tailored for AI.

SR 26-2 was issued jointly by the Federal Reserve, OCC, and FDIC on 17 April 2026 (OCC Bulletin 2026-13) as the Revised Guidance on Model Risk Management. It supersedes and replaces SR 11-7 (2011) and SR 21-8. The lifecycle discipline carries forward — Warrant's four-pillar grouping of it is Warrant's, not the regulator's numbering — restated as principles-based and risk-tailored rather than prescriptive, and reads as most relevant to banks above USD 30 billion in assets. Then footnote 3 to § II narrows who it reaches: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document. However, the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models."

Read that against a deployment. The conventional scoring, pricing, or fraud model an agent calls is squarely in scope and carries the whole lifecycle. The agent's own per-action conduct is not in scope at all, and no successor framework has issued. Be exact about what remains, because this is the sentence most often overstated: footnote 1 preserves supervisory action for violations of law or unsafe or unsound practices — the agencies' independent authority, which does not depend on this letter — and § I states that non-compliance with the guidance itself will not result in supervisory criticism. So the exclusion is not a safe harbour and it is also not a penalty regime; it is a gap, with an independent enforcement hook sitting beside it. Warrant's reading: the bank writes the standard it will be examined against, and finds out at the examination whether it wrote it high enough. Where the agent's audit trail does carry a binding rule today — NYDFS § 500.6(a)(2), read next to the footnote-3 carve-out — is worked through in the AI agent audit trail: NYDFS 500.6 + SR 26-2. Nothing in the guidance uses the phrases artificial intelligence, machine learning, large language model, or runtime.

GAO B-331324 (22 October 2019) is the Comptroller General's decision on SR 11-7 itself: Board of Governors of the Federal Reserve System — Applicability of the Congressional Review Act to Supervision and Regulation Letter 11-7, which concluded that SR 11-7 was a rule for Congressional Review Act purposes and so should have been submitted to Congress. Counsel still trace the lineage by number, but the paragraph references do not carry across: SR 26-2 renumbers and rewrites the subheads, dropped Implementation from the § IV heading, and neither letter has lettered subsections at all, so a lettered-subsection pinpoint cites nothing in either document. Map by topic, not by number. The artefact a supervisor reads is the same shape under the current guidance.

2026-04-17
SR 26-2 CURRENT
Issued 17 April 2026 by Fed / OCC / FDIC. Supersedes SR 11-7 (2011) and SR 21-8; principles-based, banks above USD 30B in assets. § II n.3 excludes generative and agentic AI from scope.
B-331324
GAO REFERENCE
Comptroller General decision of 22 Oct 2019: SR 11-7 was a rule for Congressional Review Act purposes and should have been submitted to Congress.
04 · WHY THIS REGULATOR NOW

What did SR 26-2 change for AI in banking?

SR 26-2 was issued on 17 April 2026 and supersedes SR 11-7 and SR 21-8 while carrying the lifecycle discipline into a principles-based, risk-tailored restatement. What it changed for AI is a subtraction: footnote 3 to § II states that generative AI and agentic AI models are not within the scope of the guidance, and routes them to the bank's general risk management and governance practices. Two subtractions, not one: § I also states that the guidance sets no enforceable standards or prescriptive requirements and that non-compliance with it will not result in supervisory criticism. So the pillars — Warrant's four-way grouping of the regulator's three named elements plus documentation — describe sound practice a bank is expected to be able to evidence, not a rule an examiner can cite, including for any conventional model an agent calls. For the agent itself there is no test in the letter at all, which is why the question arrives as safety and soundness instead: what is your framework for monitoring and testing this system, and what evidence shows it worked.

The published enforcement record is thinner than the model-risk framing suggests, and it is worth stating precisely. On 20 April 2018 the OCC assessed a USD 500 million civil money penalty against Wells Fargo Bank, N.A., for "unsafe or unsound practices" and deficiencies in its "enterprise-wide compliance risk management program"; the Bureau of Consumer Financial Protection separately assessed USD 1 billion and credited the OCC's amount against its own. On 7 October 2020 the Federal Reserve issued a cease-and-desist order against Citigroup Inc. reciting "significant ongoing deficiencies in implementation and execution by Citigroup with respect to various areas of risk management and internal controls, including for data quality management and regulatory reporting, compliance risk management, capital planning, and liquidity risk management." Two points counsel should hold onto: that Federal Reserve order carried no monetary penalty — the USD 400 million civil money penalty announced the same day was the OCC's, against Citibank, N.A. — and the word "model" does not appear in the Federal Reserve order at all, nor in the OCC's 2018 Wells Fargo release. Warrant has not identified a published US banking enforcement action that cites SR 11-7 or SR 26-2 by number. Documents retrieved 6 August 2026.

Supervisory attention to AI is on the record; a model-risk hook for it is not. The OCC's Semiannual Risk Perspective for Spring 2025 records that AI in banking already includes "some components of credit underwriting, such as financial analysis and collateral evaluation processes" and that using any form of AI "can introduce model, cybersecurity, and compliance risks"; the Fall 2025 edition records that "Generative AI use cases have largely been internal facing." Neither edition designates generative AI in lending as a heightened-risk activity, and neither uses the phrase "model risk" at all. One thing follows from the text: there is no SR 26-2 citation to bring against the agent itself, because footnote 3 removed the agent from the letter's scope. What Warrant expects next is an inference, offered as such and not as a supervisory position — that the question would arrive in the general safety-and-soundness form instead, and that an unmapped agent in a material decisioning role would draw it at examination despite the carve-out. Neither agency has said so. Both editions retrieved 6 August 2026.

05 · MAPPING · FOUR PILLARS

Per-pillar field map.

Model risk management should include disciplined and knowledgeable development and implementation processes that are consistent with the situation and goals of the model user and with bank policy. […] An understanding of model uncertainty and inaccuracy and a demonstration that the bank is accounting for them appropriately are important outcomes of effective model development, implementation, and use. SR 11-7 § IV, "Model Development, Implementation, and Use" — first sentence of the section, then a later sentence in the same section, quoted verbatim. As at the source retrieved 6 Aug 2026.

The mapping below carries each of Warrant's four pillars and the supervisory expectations Warrant reads out of them. Each row names the obligation, Warrant's reading of what a supervisor would look for, and what the signed package carries against it — including, in most rows, that it carries nothing. That is the honest state of a model-risk mapping for an agentic system, and SR 26-2 § II footnote 3 is why: it places generative and agentic AI outside the guidance, so Warrant does not claim to evidence obligations the guidance itself excludes. Warrant publishes this as the table it would put in front of an OCC or Federal Reserve examiner on horizontal review — our framing of an examination, not a procedure either agency has described.

Validation
Independent validation · model methodology, assumptions, limitations. WARRANT · NO FIELD. A submitted trace may carry a validation reference in a step's inputs, as the sample underwriting trace does with model_validation_record_id. Raw step inputs are not re-emitted into the signed package and the evidence schema defines no validation field, so nothing binds a validation outcome to the decisions downstream of it.
Validation
Independent validation · ongoing testing as conditions change. WARRANT · NO FIELD. There is no model_governance object, no drift-indicator field and no validation-record field anywhere in the evidence schema, so the package carries no ongoing-testing evidence and no live-validation linkage.
Monitoring
Ongoing monitoring · champion-challenger, PSI, drift, performance metrics. WARRANT · authorizations[].preconditions_met is attached per action at decision time rather than aggregated post-hoc, and records whether that action's inputs satisfied its preconditions. NO FIELD for champion-challenger, population stability or drift metrics: the schema defines none of them.
Monitoring
Ongoing monitoring · benchmark and back-testing. WARRANT · NO FIELD. The evidence schema carries no back-testing or benchmark reference, so the package cannot flag a decision for missing benchmark metrics.
Documentation
Comprehensive documentation · methodology, data, limitations, validation. WARRANT · agent_id is a real key at the root of the submitted trace, alongside the root trace array rather than inside it, and it is not re-emitted into the package. NO FIELD for model identity: neither model_id nor model_version exists in the evidence schema or reaches the signed package, so the per-decision snapshot does not resolve to model-card lineage. What it does resolve to is the obligation set — obligations.<action_id>[].evidence, an object keyed by action id rather than a flat array, read against trace_metadata.regulations_corpus_sha256.
Documentation
Comprehensive documentation · third-party replicability standard. WARRANT · regulated_entity is a real key at the root of the submitted trace and is not re-emitted into the package. NO FIELD for policy version: there is no policy_version_id in the evidence schema, so no gap can be surfaced from a missing or detached policy version. The replicability standard is served, to the extent it is served at all, by authorizations[*].justification and obligations.<action_id>[].evidence being readable without contacting Warrant.
Challenge
Effective challenge · objective, qualified, influential. WARRANT · NO FIELD. actions[*] carries action_id, actor, action and subject only, so a discarded alternative is not recorded and its absence is not flagged. Warrant makes no claim about how often effective challenge appears in Matters Requiring Attention: those findings are not published, so no ranking of them is verifiable from the public record.
Inventory
Model inventory · SR 11-7 § VI: models "implemented for use, under development for implementation, or recently retired". SR 26-2 § VI restates this as common industry practice for models "under development or in use". WARRANT · no field in the signed package. The submitted trace carries root agent_id and root regulated_entity, and neither is re-emitted into warrant-v1, so nothing in the package identifies an inventory row. Cross-trace inventory roll-up ships v0.5, 2026 Q3.
Governance
Roles, governance, board oversight. WARRANT · NO FIELD. There is no signed_off_by in the evidence schema and no field carrying an officer's name, role or tenant, so the package does not bind a decision to a senior officer. The receipt's cosign_status, with cosign_signed_actions of cosign_total_actions, reports whether the customer co-signed the trace it submitted — a key holder, not a named accountable officer.
SR 26-2 · § II n.3
Generative and agentic AI models excluded from scope. Excluded systems route to the bank's general risk management and governance practices; footnote 1 keeps supervisory action live for unsafe or unsound practices. WARRANT · root agent_id on the submitted trace identifies the deployment, and it stays on the input: it is not re-emitted into the signed package. NO FIELD for foundation-model lineage: model_version does not exist in the evidence schema. Whatever standard the bank writes for the excluded system, the package does not evidence the model's lineage against it.
SR 23-4
Interagency Guidance on Third-Party Relationships: Risk Management (SR 23-4, 7 June 2023, Fed/FDIC/OCC) read with SR 26-2 § VII, "Vendor and Other Third-Party Products", which states that for vendor and third-party models "the principles of model risk management remain applicable". SR 23-4 itself does not use the word "model". WARRANT · root regulated_entity on the submitted trace names the chartered bank, and it is not re-emitted into the signed package. NO FIELD for a vendor or sponsor-bank tenant: the evidence schema has no tenant field, so the bank's MRM framework does not read through to a third-party model via the package.
06 · FAQ

Questions a CRO and OCC examiner ask first.

Does the model risk guidance reach my firm if i am not a bank holding company?

Start with the current letter, not the 2011 one. SR 26-2's applicability line reads: "This letter is expected to be most relevant to banking organizations with over $30 billion in total assets regulated by the Federal Reserve." SR 11-7, which it superseded on 17 April 2026, defined its subjects at footnote 1 as "national banks and all other institutions for which the Office of the Comptroller of the Currency is the primary supervisor, and … bank holding companies, state member banks, and all other institutions for which the Federal Reserve Board is the primary supervisor" — and its cover letter said the guidance "should be applied as appropriate", which is the register of supervisory guidance rather than a binding rule. Non-bank lenders and fintech firms outside Federal Reserve supervision are not addressed by either letter. Where a bank partner is the chartered entity (BaaS, sponsor-bank model), the bank's own model risk management practices are what the supervisor examines, and the agent sits inside that perimeter through the bank. The supervisor reads the chain irrespective of who deploys the model.

What did SR 26-2 change for AI agents specifically?

It removed them from scope. SR 26-2, issued 17 April 2026 (OCC Bulletin 2026-13), supersedes and replaces SR 11-7 (2011) and SR 21-8, and carries the same lifecycle discipline — Warrant's four-pillar grouping of it is Warrant's, not the regulator's numbering — into a principles-based, risk-tailored restatement most relevant to banks above USD 30 billion in assets. Footnote 3 to its § II then reads: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." The same footnote hands those systems to the banking organization's own risk management and governance practices, and footnote 1 preserves supervisory action for violations of law or unsafe or unsound practices. The attachment never uses the phrases artificial intelligence, machine learning, large language model, or runtime. So the agent's own conduct sits outside model risk management while every conventional model it calls stays inside, and the bank writes the evidentiary standard for the agent itself. GAO B-331324 remains the canonical historical reference for the 2011 letter under Congressional Review Act review.

How do i generate model risk evidence if my agent runs on the Anthropic API?

Warrant produces a signed evidence package per action, and it does not map to all four of the pillars this page groups. Per action it carries actions[*] (action_id, actor, action, subject), an authorizations[] row (within_purpose, preconditions_met, human_oversight_appropriate, reversible, justification, confidence), and the obligations rows those feed, each with a compliance status and an evidence string. There is no validation reference, no monitoring metric, no model-version snapshot and no record of alternatives considered — four gaps named here rather than papered over. Same artefact whether the LLM is Anthropic, OpenAI, or open-source. Note what the artefact is and is not: under SR 26-2 footnote 3 the agent itself is outside model risk management, so the package evidences per-action authorization and obligation mapping for the agent's own conduct against the standard the bank writes. It carries no model-level evidence for the conventional models the agent calls; those stay in the bank's own MRM record.

What counts as sufficient documentation now that SR 11-7 is superseded?

SR 11-7 set the bar at documentation detailed enough that parties unfamiliar with a model could understand how it operates. That standard did not carry into SR 26-2, whose § VI Documentation subsection reads, in full: "Adequate documentation helps to support effective model risk management. For example, documentation can help maximize the likelihood of continuity of operations, including supporting the tracking of recommendations, responses, and exceptions; it can also be used to more effectively help manage any model remediation efforts." Two permissive sentences — and for a generative or agentic system, footnote 3 puts the model outside scope, so even those do not attach. The practical bar is whatever the bank can defend when an examiner pulls one decision and walks it back to the active validation record. Per-decision documentation snapshots are the lever, and be precise about what a Warrant package contributes to one: the per-action authorization judgement and its justification, the obligations rows with their evidence strings, and the corpus digest they were read against. It carries no model version, so the snapshot does not tie itself to one — that tie stays the bank's to make. Aggregated model-card PDFs are necessary and not sufficient.

Are non-bank fintech AI deployments in scope?

Not directly, under either letter. But the bank-partner relationship pulls fintechs into the perimeter through the bank's third-party risk management. Be precise about the hook: the Interagency Guidance on Third-Party Relationships (SR 23-4, 7 June 2023, Fed/OCC/FDIC) does not use the word "model" at all, and SR 23-4 describes the guidance as offering "the agencies' views on sound risk management principles" rather than imposing requirements. The model-risk hook is in SR 26-2 § VII, "Vendor and Other Third-Party Products": for vendor and third-party models "the principles of model risk management remain applicable". The fintech that wants to scale BaaS deployments should treat evidence against the current letter, SR 26-2, as the operative artefact — not against the superseded 2011 one.

What enforcement actions reference model risk management?

Fewer than the framing usually implies, and none by letter number that Warrant has been able to find. The two actions most often cited in this context say something narrower than model risk. On 20 April 2018 the OCC assessed a USD 500 million civil money penalty against Wells Fargo Bank, N.A., for "unsafe or unsound practices" and deficiencies in its "enterprise-wide compliance risk management program", with the Bureau of Consumer Financial Protection separately assessing USD 1 billion; the word "model" does not appear in that OCC release. On 7 October 2020 the Federal Reserve issued a cease-and-desist order against Citigroup Inc. reciting "significant ongoing deficiencies in implementation and execution by Citigroup with respect to various areas of risk management and internal controls, including for data quality management and regulatory reporting, compliance risk management, capital planning, and liquidity risk management" — model risk management is not among the areas listed, the word "model" does not appear in the order, and that order carried no monetary penalty. The USD 400 million civil money penalty announced the same day was the OCC's, against Citibank, N.A. Matters Requiring Attention and MRIA findings are not published, so any claim about what they cite is not verifiable from the public record and Warrant does not make one. Documents retrieved 6 August 2026.

07 · READ THE SOURCE

Primary citations.

The current Federal Reserve guidance is SR 26-2 (17 April 2026) at federalreserve.gov/supervisionreg/srletters/SR2602.htm, with the OCC companion at OCC Bulletin 2026-13. The guidance itself is the attachment at SR2602a1.pdf, which is where § I, § II, § VI, § VII, footnote 3, and footnote 1 are quoted from on this page (retrieved 6 August 2026; a probe for the adjacent SR2601.htm and for a non-existent SR2699a1.pdf returns 404 on the same host, so the 200 on SR 26-2 discriminates). SR 26-2 supersedes SR 11-7 (2011) and SR 21-8; the supersession is stated in SR 26-2's own text. The Federal Reserve has withdrawn the SR 11-7 page — srletters/sr1107.htm returns 404 (re-checked 6 August 2026) — and the OCC has rescinded its companion, OCC Bulletin 2011-12, per the Rescissions list in OCC Bulletin 2026-13. The SR 11-7 passages quoted on this page are therefore taken from the identical guidance as adopted and published by the FDIC in FIL-22-2017, fil17022a.pdf, cross-checked against the Federal Reserve's own withdrawn attachment; both were read in full rather than searched. The full Supervision and Regulation Letters archive is at srletters.htm. GAO B-331324 is at gao.gov/products/b-331324.

W
Sample US evidence package · Northcentral Trust Bank small-business underwriting agentINDEPENDENTLY VERIFIABLE · ID 041f2335488dd56f
→ us-fintech.pdf
Verify a package → Open the demo All regulators