Category: Regulation | Reading time: 5 min
The Supersession
On 17 April 2026, the Board of Governors of the Federal Reserve System, the OCC and the FDIC jointly issued SR 26-2, Revised Guidance on Model Risk Management.
It supersedes and replaces SR letter 11-7, issued April 2011, and SR letter 21-8, the interagency statement on model risk management for systems supporting Bank Secrecy Act and anti money laundering compliance, issued April 2021.
SR 11-7 governed how banks built, validated, monitored and documented quantitative models for fifteen years. Most large institutions have programmes built directly on its structure.
What Changed
SR 26-2 is roughly half the length of its predecessor and reads differently.
The guidance emphasises a risk based approach tailored to each institution model risk profile and the size and complexity of its operations. Assessment moves toward materiality, determined by model exposure and model purpose together, rather than uniform treatment.
The definition of model narrowed. It now excludes simple arithmetic calculations such as those in spreadsheets, along with deterministic rule based processes and software with no statistical, economic or financial theory underpinning their design.
On validation independence, the letter states directly that the quality of the validation process depends on the rigour and effectiveness of the review rather than on organisational structure.
The guidance is expected to be most relevant to banking organisations with over 30 billion dollars in total assets.
The Footnote That Matters Most
Footnote 3 states that generative AI and agentic AI models are novel and rapidly evolving and are therefore not within the scope of the guidance.
It continues: a banking organisation risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes or systems not covered in the document. The principles described apply to traditional statistical and quantitative models and to non generative, non agentic AI models.
Read plainly, three federal banking regulators have said that AI agents are outside their model risk framework and that each institution must determine appropriate governance itself.
What That Creates
A bank deploying an autonomous agent in 2026 has no supervisory rulebook for it and an explicit instruction to build one.
That is not an absence of obligation. The agencies retain authority to act on unsafe or unsound practices regardless of whether a specific guidance document applies. Examiners and auditors will still ask what governance exists.
The difference is that the institution must define the standard and then evidence that it met its own definition. Both halves of that are harder than following a prescriptive rule.
Vendor Products Remain In Scope
Section VII addresses vendor and other third party products, noting that the principles of model risk management remain applicable to them.
The guidance calls for understanding a vendor model conceptual soundness, design, development data and performance, along with ongoing monitoring and outcome analysis to assess whether vendor models remain accurate and fit for purpose.
For institutions buying agentic AI from a vendor rather than building it, both parts apply at once: the third party expectations of Section VII, and the self defined governance obligation of footnote 3.
The Practical Position
SR 26-2 is explicitly non binding. The letter states it does not set forth enforceable standards or prescriptive requirements and that non compliance alone will not result in supervisory criticism.
That has not historically stopped guidance from being treated as the standard for sound practice. SR 11-7 carried the same framing and was enforced as de facto binding for fifteen years.