Supervisory guidance is a text before it is a framework, and the text changed on 17 April 2026. SR 26-2 superseded SR 11-7, the OCC issued it as Bulletin 2026-13, the FDIC as FIL-15-2026, and the OCC also withdrew Bulletin 2011-12, Bulletin 2021-19, Bulletin 1997-24 on credit scoring models with its appendix, and the Model Risk Management booklet of the Comptroller’s Handbook.
Summaries of that change are plentiful and mostly describe the same four themes. Reading the two documents word by word gets somewhere different, because a supervisory text does its work through particular words, and the ones that arrived, left or changed grammatical mood are countable.
Ten words carry the whole revision. Each section below takes one of them, quotes both texts, and says what the word does to an AI system. Counts come from the two guidance attachments, twenty-one pages and 9,868 words in 2011 against twelve pages and 2,987 words in 2026.
“Complex”: one adjective decides whether a method is a model at all
SR 26-2 moved the definition by a single adjective. SR 11-7 defined a model as “a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates”. SR 26-2 defines it as “a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates”.
Model risk used to carry complexity downstream, in the risk assessment, where a simple method could be a low-risk model. Complexity now sits in the definition, where a simple method is not a model. The revised text adds the exclusions to match, removing “simple arithmetic calculations, such as those found within spreadsheets, as well as deterministic rule-based processes and software where there are no statistical, economic, or financial theories underpinning their design or use”.
SR 26-2 also brings vocabulary the older text lacked, which is worth saying because most coverage reports only subtractions. Section III introduces inherent risk, model exposure, model purpose and model materiality as named concepts, and states that “model purpose, together with model exposure, determines model materiality”.
Materiality then drives how much rigour a model gets, with immaterial models reduced to identification and monitoring of the conditions under which they might become material. Interpretation: the new text gives a bank a defensible way to tier its estate, which is precisely what an AI inventory running to hundreds of entries needs.
Nothing in the document says what makes a method complex. A single logistic regression, a deposit beta maintained in a spreadsheet with a fitted curve behind it, a vendor scorecard delivered as a lookup table: each arguably fails the test, and each still moves money. Interpretation: the adjective transfers a classification decision to the bank and leaves no criterion behind, which makes the written rationale for each call the artefact that matters.
“Mathematical”: the deleted theory that carried the algorithms
Model risk management lost one of its four founding theories. The 2011 list read “statistical, economic, financial, or mathematical theories”. The 2026 list reads “statistical, economic, or financial theories”.
Model risk scope once reached the mathematical catch-all. An optimisation routine, a graph algorithm, a clustering method and a similarity search are mathematical before they are statistical, and several of them underpin fraud detection, customer segmentation and anti-money laundering alerting. Removing the word narrows the doorway those methods walked through.
Statistical still covers most machine learning, so the effect is at the edges rather than at the centre. The edges are where the arguments happen.
“Techniques, and assumptions”: the phrase that reached judgment-based inputs
SR 11-7 carried two words in the middle of its definition that disappeared, and they took a sentence with them. SR 11-7 covered methods applying theories, “techniques, and assumptions”, and then said expressly: “The definition of model also covers quantitative approaches whose inputs are partially or wholly qualitative or based on expert judgment, provided that the output is quantitative in nature.”
SR 26-2 contains no equivalent sentence. Its definition requires theories alone, and says nothing about qualitative or judgment-based inputs.
Consider what that removal touches. An underwriting overlay taking a language model’s summary of a borrower file as an input and producing a numeric adjustment was covered by the 2011 wording on its face. Under the 2026 wording, the same construction has to argue its way in through “complex quantitative method” instead, and the bank making that argument is arguing with itself rather than with a regulator.
“Generative” and “agentic”: two undefined adjectives draw the perimeter
SR 26-2‘s only mention of artificial intelligence sits in a footnote, and that footnote does two things at once. Footnote 3 reads: “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.
Nonetheless, a banking organization’s risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document. However, the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models.”
SR 26-2 reads in both directions. A gradient boosting model scoring credit applications, a random forest ranking fraud alerts, a neural network forecasting deposit attrition: each is an AI model, none is generative or agentic, and each is expressly inside. A retrieval assistant drafting credit memoranda, a summarisation tool in the anti-money laundering queue, an agent executing steps in a servicing workflow: each is expressly outside.
Neither adjective is defined anywhere in the document, and the phrase “AI-based models” appears nowhere in it, surfacing only in the OCC news release. Searching the attachment returns no definition of either term beyond the footnote that uses them.
SR 26-2 does not leave the excluded systems ungoverned in principle. The same footnote says a banking organization’s own practices “should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document”, which is an instruction to build something without saying what. A bank that reads the exclusion as permission to do nothing has read one clause of a three-clause footnote.
Hard cases are therefore the common ones. A fraud model retrained on embeddings produced by a foundation model is not generative at the point of scoring, and its feature pipeline is. A credit model whose reason codes are written by a language model produces a quantitative estimate and a generated artefact from one run. A vendor platform that calls itself agentic in marketing may be a scripted workflow in implementation.
“Should”: one survivor out of a hundred and eighty
SR 26-2‘s grammatical mood is the one thing a summary cannot convey. Counting with word boundaries across the two attachments gives 180 occurrences of “should” in 2011 and one in 2026. “Must” appears once in 2011 and never in 2026. “Sound practice” appears nine times in 2026 and never in 2011.
The single surviving “should” sits inside footnote 3, in the sentence telling banks that their own risk management practices “should guide the determination of appropriate governance and controls” for the systems the guidance does not cover. So the one instruction left in the revised text is an instruction about the material it declines to govern.
SR 26-2 kept effective challenge and tightened its definition, which cuts against a reading of the revision as pure loosening. The 2011 attachment said effective challenge “depends on a combination of incentives, competence, and influence”. The revised text says it is “performed by individuals with the appropriate expertise to conduct a critical and objective challenge, sufficient independence to maintain objectivity, as well as the organizational standing and influence to effect any change”.
Independence therefore survives, inside the definition of effective challenge rather than as a rule about reporting lines. Anyone citing the revision as authority for letting model developers validate their own work has to answer that sentence.
Interpretation: a document written in “sound practice involves” rather than “banks should” is describing behaviour rather than setting expectations, and an examiner reading it has principles to discuss instead of items to check.
“Annual”: a frequency that left without a replacement
SR 11-7 gave review cadence a floor and SR 26-2 does not. The 2011 attachment instructed that “Banks should conduct a periodic review” of each model, “at least annually but more frequently if warranted”. The word “annual” appears twice in that attachment and zero times in the revised one.
SR 26-2 replaces the floor with a list of considerations: “The timing, nature, and frequency of validation activities vary based on model purpose, model methodology, frequency and scope of model changes, data limitations, and other practical constraints.”
Validation timing loosened at the other end too. The revised text says validation “generally occurs prior to a model’s first use”, then allows that “certain circumstances (e.g., an urgent business need) may necessitate using the model before validation is completed”, with limits on use or closer monitoring as the compensating controls.
A cadence the bank chooses is defensible, and a cadence the bank cannot explain is not. Interpretation: the useful artefact is now the reasoning behind the interval rather than the interval itself.
“Inventory”: the noun survived and the verb did not
Model risk inventories are where careless comparisons go wrong, because both texts describe the same object with the same phrase. The 2011 attachment puts “Banks should maintain” in front of it. The 2026 text puts “It is common industry practice for banking organizations to maintain” in front of it.
What actually disappeared sits around that sentence. The 2011 attachment required a firm-wide view, saying that while each line of business may keep its own record, “a specific party should also be charged with maintaining a firm-wide inventory of all models”.
The 2011 text listed what each entry should describe: purpose and products, actual or expected usage, restrictions on use, type and source of inputs, underlying components including other models, outputs and their intended use, whether the model is functioning properly, when it was last updated, and any exceptions to policy. Any variation warranting separate validation had to be listed as a separate model.
SR 26-2 keeps none of that detail. Its whole treatment is that an effective record holds enough information to understand model risks individually and in aggregate. The word count tells the same story: “inventory” appears eight times in 2011 and three times in 2026.
“Independence”: the word that changed less than the commentary claims
SR 26-2 is widely said to have abolished validator independence, and the 2011 attachment is the reason that reading fails. SR 26-2 says: “The quality of validation process depends on the rigor and effectiveness of the review rather than on organizational structure of the banking organization’s risk management function.” Read alone, that sounds like a reversal.
Read the older text and it is not. The 2011 attachment already said “Independence is not an end in itself but rather helps ensure that incentives are aligned with the goals of model validation”, and that “while independence may be supported by separation of reporting lines, it should be judged by actions and outcomes, since there may be additional ways to ensure objectivity and prevent bias”.
One thing did go. The 2011 default was explicit: “Generally, validation should be done by people who are not responsible for development or use and do not have a stake in whether a model is determined to be valid.” No equivalent default survives. The word “independen” and its variants appear eight times in the 2011 attachment and once in the revised one.
So the accurate statement is narrow. Structural independence was never the test, and the presumption that validators sit outside development has stopped being written down.
“$30 billion”: the number that replaced a judgment about size
Scope under the revised guidance turned from a judgment into a figure. SR 11-7 was to be “applied as appropriate to all banking organizations supervised by the Federal Reserve, taking into account each organization’s size, nature, and complexity”.
SR 26-2 states that it “is expected to be most relevant to banking organizations with over $30 billion in total assets”, adding that models at or below that figure “typically are subject to internal risk management and governance practices appropriate for the size and risk profile of these banking organizations”.
Counting what the figure covers takes one query against the FDIC’s own institution file. Run on 19 September 2026 against 30 June 2026 call report data, it returns 4,232 active insured institutions, of which 71 report more than $30 billion in total assets. Between them those 71 hold about $21.3 trillion of the $26.5 trillion held by the whole set, or 80.5 per cent.
So the line passes over 98.3 per cent of insured institutions and keeps roughly four fifths of the money. Figures here sit at the insured-institution level while the guidance addresses banking organisations, which are holding companies, so the count is the closer of the two available proxies rather than an exact match.
SR 26-2 keeps a door open below the line, saying the guidance “also may be relevant to banking organizations with total assets of $30 billion or less that have significant exposure to model risk because of the prevalence and complexity of their models or because of activities outside the scope of traditional community banking”. A mid-sized bank running machine learning across underwriting, pricing and fraud is describing itself in that sentence.
Scope can now also change through a transaction. A bank crossing the threshold by acquisition inherits the relevance statement on closing day, with no modelling decision having been taken, and the framework it needs that day is the one it built beforehand.
“Criticism”: the word that tells you the guidance cannot be breached
SR 26-2 settles enforceability in a sentence with no counterpart in 2011: “This guidance does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism against a banking organization.” SR 11-7 closed instead by telling organisations to keep internal policies consistent with the supervisory expectations it contained.
Footnote 1 supplies the limit, and the limit is the operative part. After citing 12 CFR Part 4 Subpart F Appendix A for the OCC, 12 CFR Part 262 Appendix A for the Board and 12 CFR Part 302 Appendix A for the FDIC, it adds that “supervisory action may result for any violations of law or unsafe or unsound practices stemming from insufficient management of model risk”.
Read together, those two sentences are the whole federal position on AI models in banking. A bank cannot be criticised for departing from a validation practice the guidance describes, and a bank can still be pursued for an unsafe or unsound practice arising from a model that failed.
Consumer statutes sit outside both, so adverse action reasons under the Equal Credit Opportunity Act and Regulation B, accuracy duties under the Fair Credit Reporting Act, and prohibitions on unfair or deceptive practices reach a generative system exactly as they reach a scorecard.
The same footnote appears in the next instrument down the line. Proposed third-party risk management guidance published at 91 FR 58536 on 15 September 2026, under Docket No. OP-1881 with comments open until 16 November 2026, cites the same three appendices. Extracting that nine-page notice and searching it finds “artificial intelligence” zero times and “generative” zero times, and its single use of “model” is in the phrase “business model”.
Words that appear nowhere in the revised text
Four absences are measurable in the revised text, and each of them matters. “Board of directors” appears twice in the 2011 attachment and never in the revised one. “Senior management” appears eight times and never. “Internal audit” falls from sixteen mentions to three. And the Bank Secrecy Act, anti-money laundering and money laundering appear nowhere in the 2026 attachment at all, which matters because SR 21-8 and OCC Bulletin 2021-19 were rescinded on the same day and nothing replaced them.
Credit scoring lost its text in the same sweep. OCC Bulletin 1997-24, “Credit Scoring Models: Examination Guidance”, and its appendix on safety, soundness and compliance issues were withdrawn on 17 April 2026, leaving no examination text specific to scoring models. A scorecard built on gradient boosting sits inside the revised guidance as a non-generative AI model, and the document that once described how to examine one no longer exists.
An interagency promise accompanied the carve-out. The OCC news release of 17 April 2026 says the three agencies “plan to issue in the near future a request for information that addresses model risk management generally and considers, in particular, banks’ use of AI, including generative AI and agentic AI and AI-based models”.
Searching the Federal Register on 19 September 2026 by full text, across every document published by the Comptroller of the Currency, the Board and the FDIC since 17 April 2026, returns two documents mentioning artificial intelligence at all and no such request. The gap stands at 155 days, against a release that set no deadline.
What the British text kept that the American text dropped
British model risk rules kept every word the American revision removed. The Prudential Regulation Authority’s SS1/23 came into effect on 17 May 2024 and tells firms to adopt a definition of a model as “a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into output”, with inputs that may be “quantitative and / or qualitative in nature or expert judgement-based, and output that are quantitative or qualitative”.
Every word the American revision removed is still in that sentence. Mathematical theories, techniques and assumptions, and qualitative inputs all survive, and the output may be qualitative, which is the limb that decides whether a system producing a paragraph counts. Principle 1.1(b) then reaches further, telling firms to consider applying relevant parts of the framework to material deterministic methods “such as decision-based rules or algorithms” that are complex and bear on business decisions.
Neither “artificial intelligence” nor “machine learning” appears anywhere in SS1/23. The British regulator caught AI by writing a definition wide enough to hold it and never naming it, while the American agencies named it in order to release half of it.
European law adds a third answer for any group operating there, because Annex III point 5(b) of the EU AI Act treats creditworthiness evaluation and credit scoring as high risk, excluding fraud detection, with classification under Article 6(2) applying from 2 December 2027 after the Digital Omnibus moved the date.
What to keep when the words are gone
Six records carry the weight now that the instructions have thinned, and each answers a question the revised text no longer answers for you.
A written classification rationale for every AI system, recording whether it was judged generative, agentic or neither, whether it met the complexity test, who decided and on what date. One inventory holding models and excluded AI tools together, because the excluded ones are where the classification argument gets tested.
Validation records carrying an explicit independence statement, since the default that validators sit outside development is no longer written down. A stated review cadence with the reasoning behind the interval. Vendor evidence on what the provider discloses about training data, evaluation results and change notification. And a decision log for any model used before validation completed, naming the urgent business need and the compensating controls.
Model risk monitoring works at the cadence of change rather than the cadence of a calendar, which is the practical answer to the loss of the annual floor. Retraining, threshold tuning, a new data source and a shift in the customer mix each move model behaviour without anyone touching the validation schedule. Tying review to those events, and recording the tie, produces a cadence that survives the question of why it was chosen.
Model risk management under a thinner text is exactly where governance software earns its place, and it is the problem Govern365.ai was built around. Holding the classification rationale, the inventory entry, the validation record, the approval and the vendor evidence in one dated place turns a judgement call into a file rather than a reconstruction.
Govern365.ai maps each obligation to the record that proves it across the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework, so a bank answering an American examiner, a British supervisor and a European conformity assessment works from one artefact.
Word by word
| Word | SR 11-7, 4 April 2011 | SR 26-2, 17 April 2026 |
| complex | Absent from the definition | Required before a method is a model |
| mathematical | One of four theories listed | Removed |
| techniques, and assumptions | In the definition | Removed |
| qualitative inputs | Expressly covered where output is quantitative | Sentence removed |
| generative | Not addressed | Expressly out of scope, footnote 3 |
| agentic | Not addressed | Expressly out of scope, footnote 3 |
| should | 180 occurrences | 1, inside footnote 3 |
| must | 1 occurrence | 0 |
| sound practice | 0 occurrences | 9 |
| annual | 2 occurrences, at least annually | 0 |
| inventory | 8 occurrences, firm-wide, itemised | 3, described as common industry practice |
| independen | 8 occurrences, default separation stated | 1, no default stated |
| board of directors | 2 occurrences | 0 |
| senior management | 8 occurrences | 0 |
| internal audit | 16 occurrences | 3 |
| criticism | Absent | Non-compliance will not result in supervisory criticism |
| $30 billion | Absent | Relevance threshold, 71 of 4,232 insured institutions |
Frequently Asked Questions
Is SR 11-7 still in effect?
Not since 17 April 2026. SR 26-2 supersedes and replaces it, along with SR 21-8, and the OCC and FDIC rescinded their parallel issuances the same day.
Does the revised guidance cover generative AI?
Footnote 3 places generative AI and agentic AI models outside its scope, and places traditional statistical models and non-generative, non-agentic AI models inside it.
How is “generative” defined in the guidance?
Nowhere. Neither that adjective nor “agentic” carries a definition in the document, which leaves the classification to the banking organisation.
What does the word “complex” do to the model definition?
A method must be complex before it counts as a model, so simple deterministic processes, spreadsheet arithmetic and software without an underlying statistical, economic or financial theory fall outside.
Did the guidance remove the annual validation requirement?
The word “annual” appears twice in the 2011 attachment and not at all in the revised one, which lists considerations that determine frequency instead of setting a floor.
Is the model inventory still expected?
The revised text calls maintaining that record common industry practice rather than instructing banks to do it, and drops the firm-wide requirement and the itemised contents the 2011 text specified.
Did SR 26-2 abolish validator independence?
The 2011 attachment already said independence is not an end in itself and should be judged by actions and outcomes. What went is the stated default that validation is done by people not responsible for development or use.
Which banks does the guidance apply to?
The guidance is expected to be most relevant above $30 billion in total assets, a line above which 71 of 4,232 active FDIC-insured institutions sat at the 30 June 2026 call report date.
Can an examiner criticise a bank for departing from it?
The guidance says non-compliance will not result in supervisory criticism, and the same footnote preserves supervisory action for violations of law or unsafe or unsound practices stemming from insufficient management of model risk.
Has the promised AI request for information been published?
No such request appeared in the Federal Register from the OCC, the Board or the FDIC in the 155 days to 19 September 2026, on a full-text search of everything those agencies published since the announcement.
How does the United Kingdom define a model?
SS1/23 keeps mathematical theories, techniques and assumptions, and qualitative inputs, and accepts output that is quantitative or qualitative, which captures systems the American definition excludes.
What should a bank do with its existing framework?
Nothing in the revised guidance requires dismantling one, and every element it keeps is now the organisation’s own policy rather than a supervisory expectation
