Home / Resources / Frameworks / SR 11-7
Model risk management for banks running AI, before the examiner asks.
SR 11-7 has been the backbone of model risk management in U.S. banking since 2011. Its successor, SR 26-2, shifts to a principles-based framework while leaving generative and agentic AI in a regulatory gap. For operators, the mandate is clear: know what you have, prove it works, and show the evidence on demand.
What SR 11-7 and SR 26-2 require, and why it matters now
SR 11-7, issued jointly by the Federal Reserve and OCC on April 4, 2011, established the first comprehensive framework for model risk management across U.S. banking. The OCC published it as Bulletin 2011-12, and the FDIC adopted the framework in 2017 via FIL-22-2017. On April 17, 2026, all three agencies jointly issued SR 26-2 (OCC Bulletin 2026-13, FIL-15-2026), superseding the original guidance and shifting from prescriptive rules to a principles-based, risk-proportionate approach. SR 26-2 narrows the model definition to require a "complex" quantitative method, introduces a $30 billion asset threshold for primary relevance, and explicitly excludes generative and agentic AI from scope, though general governance obligations still apply.
68%
of U.S. banks with AI platforms have at least one system not in their model inventory
Moody's Analytics 2025
14
institutions received OCC MRAs in 2024 for model inventory gaps alone
OCC Examination Findings 2024
41%
year-over-year increase in SR 11-7 findings for model governance gaps in 2024
Federal Reserve Examination Data 2024
Who must comply
National banks and federal savings associations
All OCC-supervised institutions are subject to model risk management expectations. Under SR 26-2, institutions with $30 billion or more in total consolidated assets face heightened examination scrutiny and are expected to maintain comprehensive model inventories, independent validation functions, and board-approved MRM policies.
OCC Bulletin 2026-13 · SR 26-2
State member banks and holding companies
The Federal Reserve applies SR 26-2 to state member banks, bank holding companies, and their subsidiaries. Every model used in decision-making, risk measurement, or reporting falls within scope, including those developed internally or acquired from third parties.
Federal Reserve SR 26-2
FDIC-supervised institutions
The FDIC adopted the original SR 11-7 framework in 2017 and has co-issued SR 26-2 as FIL-15-2026. State nonmember banks, savings institutions, and insured branches of foreign banks supervised by the FDIC are expected to maintain model risk management practices proportionate to their complexity and risk profile.
FIL-15-2026 · FIL-22-2017
U.S. branches of foreign banking organizations
Foreign banks operating branches in the United States are subject to model risk management expectations from the OCC or Federal Reserve depending on their charter. The same inventory, validation, and governance requirements apply to models used in U.S. operations.
OCC · Federal Reserve supervisory guidance
Vendor and third-party model providers
Models sourced from vendors, fintech partners, or third-party providers are explicitly within scope. The institution remains responsible for inventory inclusion, independent validation, ongoing monitoring, and documentation of all third-party models, regardless of where the model was developed.
SR 26-2 third-party risk expectations
What you must do
"We need a complete, current inventory of every model in production, including vendor models and AI systems."
SR 26-2, Model Inventory Requirements Inventory completeness is the most common examination finding. 68% of banks with AI platforms have at least one system that does not appear in the model inventory. OCC issued MRAs to 14 institutions in 2024 for this single gap.
→ Nexovern's automated discovery identifies models and AI systems across the environment before examiners arrive, closing the gap between what is deployed and what is recorded in the inventory.
"Every model requires independent validation with effective challenge, documented and repeatable."
SR 26-2, Model Validation Validation must be performed by parties independent of the model development and implementation process. Examiners evaluate whether the challenge function is substantive, not merely procedural, and whether findings are tracked to resolution.
→ Nexovern provides correlated app-layer and system-level evidence for every model and AI system, giving independent validators the raw data they need for substantive challenge and reproducible findings.
"Models must be monitored continuously for performance degradation, drift, and unexpected behavior."
SR 26-2, Ongoing Monitoring Periodic review alone is insufficient. Examiners expect continuous monitoring with defined thresholds, escalation procedures, and documented change-control processes whenever model behavior deviates from established baselines.
→ Nexovern's runtime monitoring captures continuous performance and drift evidence, providing the documented baselines and deviation alerts that examiners expect to see in production.
"The board must approve a model risk management policy with clear ownership, risk tiering, and escalation paths."
SR 26-2, Governance and Controls SR 26-2 requires a board-approved MRM policy that defines roles, responsibilities, risk appetite, model tiering criteria, and reporting lines. Governance gaps contributed to the 41% increase in examination findings during 2024.
→ Nexovern enforces governance policies at the endpoint, ensuring that risk-tiering decisions, approval gates, and escalation paths are applied consistently across all AI systems, not just documented in a policy manual.
"Documentation must cover the entire model lifecycle, from development through deployment, monitoring, and retirement."
SR 26-2, Documentation Standards Examiners evaluate documentation for completeness, accuracy, and currency. Model documentation must include purpose, assumptions, limitations, data sources, validation results, and performance monitoring outcomes for every model in the inventory.
→ Nexovern's evidence exports produce examination-ready documentation that maps directly to SR 26-2 expectations, reducing the manual effort of assembling lifecycle records across siloed teams.
"Generative and agentic AI systems are excluded from SR 26-2 scope, but they still require governance."
SR 26-2, Scope Exclusion for GenAI SR 26-2 explicitly excludes generative and agentic AI from the formal model definition. However, the interagency statement confirms that general risk management, third-party risk, and consumer protection obligations continue to apply. A planned interagency RFI on AI model risk management will address these systems directly.
→ Nexovern governs AI agents regardless of whether they meet the formal "model" definition, providing the inventory, monitoring, and evidence trail that will be required when the interagency RFI produces binding guidance.
Penalties for non-compliance
Examination findings
The first tier of supervisory response. Examiners document deficiencies in model inventory, validation, monitoring, or governance as findings in the examination report. These become part of the institution's supervisory record and influence future examination scope and intensity.
OCC · Federal Reserve · FDIC examination procedures
Matters Requiring Attention (MRAs)
Formal written directives requiring the institution to address specific deficiencies within a defined timeframe. The OCC issued MRAs to 14 institutions in 2024 for model inventory gaps alone. Unresolved MRAs escalate to more severe supervisory actions.
OCC MRA procedures · 14 institutions cited in 2024
Matters Requiring Immediate Attention (MRIAs)
Urgent directives with compressed remediation timelines, typically 30 to 90 days. MRIAs indicate that the deficiency poses immediate risk to the institution's safety and soundness, or that prior MRAs remain unresolved. Failure to remediate within the timeline triggers enforcement escalation.
OCC · Federal Reserve MRIA procedures
Formal agreements and consent orders
Legally binding agreements between the institution and its primary regulator. These orders prescribe specific corrective actions, reporting requirements, and board-level accountability. Consent orders become public record and may restrict business activities until deficiencies are resolved.
12 USC § 1818(b) · OCC enforcement authority
Civil money penalties up to $1M per day
Regulators may impose civil money penalties (CMPs) of up to $1 million per day per violation for sustained non-compliance. Citibank received a $400 million penalty in 2020 for risk management failures that included model oversight deficiencies. Morgan Stanley paid $60 million in 2022 for data management failures tied to model inventory controls.
12 USC § 1818(i) · Citibank 2020 ($400M) · Morgan Stanley 2022 ($60M)
Officer removal and industry bars
In cases of personal culpability or willful disregard, regulators may pursue removal of officers or directors and impose industry-wide prohibition orders. These actions target individuals responsible for sustained governance failures and carry career-ending consequences.
12 USC § 1818(e) · Individual enforcement actions
Key dates
01
April 4, 2011
Federal Reserve and OCC issue SR 11-7, establishing the original model risk management framework for U.S. banking institutions. OCC publishes the guidance as Bulletin 2011-12.
02
2017
FDIC formally adopts the SR 11-7 framework via FIL-22-2017, extending model risk management expectations to all FDIC-supervised institutions.
03
April 17, 2026
OCC, Federal Reserve, and FDIC jointly issue SR 26-2 (OCC Bulletin 2026-13, FIL-15-2026), superseding all prior model risk management guidance with a principles-based, risk-proportionate framework.
04
May 2026
OCC identifies artificial intelligence as "significantly transforming" the banking industry, signaling heightened examination focus on AI governance, inventory completeness, and risk controls.
05
TBD (Announced)
Planned interagency Request for Information on AI model risk management, including generative and agentic AI systems. This RFI will shape the next wave of binding guidance for AI systems currently excluded from SR 26-2 scope.
How Nexovern helps
- Automated model and AI system discovery finds every model, agent, and AI-driven system across the environment before examiners do, closing the inventory gap that triggered 14 OCC MRAs in a single year.
- Runtime monitoring with drift detection provides the continuous performance evidence SR 26-2 requires, replacing periodic manual reviews with real-time baselines, threshold alerts, and documented deviation histories.
- Correlated app-layer and system-level evidence ties every agent action to a verified identity and a reconstructable decision path, giving independent validators the raw data they need for substantive challenge.
- Policy enforcement at the endpoint ensures that governance controls, approval gates, risk tiering, and data boundaries are applied in production, not just documented in policy manuals.
- Examination-ready evidence exports map directly to SR 26-2 expectations, producing the documentation examiners request for inventory completeness, validation results, monitoring outcomes, and lifecycle records.
- Coverage beyond the formal model definition governs generative and agentic AI systems that SR 26-2 excludes from scope, ensuring readiness for the forthcoming interagency RFI and any binding guidance that follows.
Your next examination will ask for the evidence. Build it before they ask.
Nexovern gives your model risk management team the automated discovery, continuous monitoring, and examination-ready evidence that SR 26-2 demands. See how it maps to your institution's MRM program.