SR 26-2 explained: what replaced SR 11-7, and why AI agents fall outside it
SR 26-2 is the revised interagency model risk management guidance the Federal Reserve, OCC, and FDIC issued on April 17, 2026. It supersedes SR 11-7 and SR 21-8, is expected to be most relevant to banking organizations above $30 billion in total assets, and explicitly excludes generative and agentic AI. Institutions govern those systems under their own risk management practices until the agencies say more.
This post is part of our guide to agentic AI governance in mid-market financial services. It covers what SR 26-2 changed, who it reaches, what it leaves out, and what to do about the gap.
What did SR 26-2 replace?
According to the Federal Reserve’s letter, SR 26-2 supersedes two letters:
- SR 11-7, Guidance on Model Risk Management, issued April 4, 2011.
- SR 21-8, the Interagency Statement on Model Risk Management for Bank Systems Supporting Bank Secrecy Act/Anti-Money Laundering Compliance, issued April 9, 2021.
The OCC’s release issued the same guidance as Bulletin 2026-13 and rescinded OCC Bulletin 2011-12 (the companion to SR 11-7), Bulletin 2021-19 (the BSA/AML statement), Bulletin 1997-24 on credit scoring models, and the Model Risk Management booklet of the Comptroller’s Handbook.
If a policy, vendor questionnaire, or validation procedure at your institution cites SR 11-7 or OCC 2011-12 as current guidance, it needs updating.
What actually changed?
The principles survived; the posture changed. SR 26-2 keeps the familiar structure of model development and use, validation and monitoring, and governance and controls, including vendor models. What changed is how firmly it applies.
It is explicitly risk-based and tailored. Model risk management should fit a banking organization’s model risk profile and the size and complexity of its operations.
It is not an enforceable standard. The text states that it does not set enforceable standards or prescriptive requirements, and that non-compliance with the guidance will not result in supervisory criticism. It adds a caveat: supervisory action may still follow from violations of law or unsafe or unsound practices that stem from poor model risk management.
It frames model risk in four factors. A model’s inherent risk, its exposure, its purpose, and its use. Exposure and purpose together set materiality, and materiality sets how much rigor a model warrants.
It narrows the definition of a model. A model is a complex quantitative method that applies statistical, economic, or financial theories to turn inputs into quantitative estimates. Simple spreadsheet arithmetic and deterministic rule-based processes without that theory underneath are excluded.
It repositions internal audit. Audit evaluates whether the model risk program is rigorous and effective, rather than duplicating development or validation work.
Who does SR 26-2 apply to?
Mainly banking organizations with more than $30 billion in total assets. The guidance text says models at organizations with $30 billion or less are typically subject to internal practices appropriate to their size, and that generally excluding them is consistent with tailored supervision. It may still be relevant to smaller institutions with significant model risk, because of complex models or activities outside traditional community banking.
For context, the Federal Reserve classifies community banking organizations as under $10 billion in total assets and regional banking organizations as $10 billion to $100 billion. Most community banks, and many regional ones, sit below the $30 billion line.
Why are AI agents outside it?
Because a footnote to the scope section says so. It states that generative AI and agentic AI models are novel and rapidly evolving, and therefore not within the scope of the guidance. It continues: a banking organization’s own risk management and governance practices should guide the controls for any tools, processes, or systems the guidance does not cover. The principles still apply to traditional statistical and quantitative models and to non-generative, non-agentic AI.
The OCC added that the agencies plan to issue a request for information in the near future on model risk management generally, considering in particular banks’ use of AI, including generative and agentic AI. So the guidance does not say agents are unregulated. It says the agencies have not written their expectations yet, and that the institution’s own governance carries the weight until they do.
| System | Under SR 26-2? | What governs it today |
|---|---|---|
| Traditional statistical or quantitative model (credit scorecard, CECL, ALM) | Yes, if the organization is in scope | SR 26-2 principles, tailored to materiality |
| Non-generative, non-agentic machine learning model | Yes | SR 26-2 principles |
| Generative AI (drafting, summarization) | No | The institution’s own risk management and governance; third-party guidance if vendor-provided |
| Agentic AI (systems that act) | No | The same, plus whatever supervision applies to the action the agent takes |
| Deterministic rules engine | No (not a “model” under the definition) | Ordinary operational and IT controls |
Does the exclusion mean we can wait?
No, for three reasons.
Other obligations still apply. An agent that writes to a loan file or contacts a customer acts inside processes already governed by safety-and-soundness expectations, consumer protection law, BSA/AML rules, and recordkeeping duties. None of those wait for an AI request for information.
Vendor agents are third-party relationships. The 2023 interagency guidance on third-party relationships is unaffected by SR 26-2. Its life cycle of planning, due diligence, contracting, monitoring, and termination applies to an agent vendor as it does to any other.
The footnote assigns the work to you. “Your own governance practices should guide the controls” is a statement an examiner can ask you to demonstrate.
What to do now: five steps
- Update every reference to SR 11-7 and OCC 2011-12 in policies, procedures, validation templates, and vendor questionnaires.
- Inventory AI separately from models. Keep your SR 26-2 model inventory, and add a parallel inventory of generative and agentic systems, including default-on AI features inside tools you already license.
- Tier agents by what they can do, not by what they are. An agent that drafts for an internal approver carries less risk than one that writes to a system of record or reaches a customer. Our guide sets out five controls examiners are likely to ask about, and the reasoning for an autonomy ceiling per action class.
- Make the record contemporaneous. For every agent action, record the identity, inputs, rationale, approver or standing policy, and before-and-after state at the moment it happens. See the eight fields of a complete audit ledger entry.
- Use the Treasury framework as your structure. Treasury’s voluntary Financial Services AI Risk Management Framework gives you 230 control objectives organized by adoption stage. Start with the stage you are in, not all 230.
See which of your workflows are ready
The free Agentic Readiness Audit assesses governance, non-human identity, shadow AI, data readiness, workflow suitability, and evidence, and returns a written assessment within 48 hours of the intake session.
Get the readiness auditFrequently Asked Questions
- When was SR 26-2 issued?
- The Federal Reserve, OCC, and FDIC issued the revised interagency guidance on model risk management on April 17, 2026. The Federal Reserve published it as supervisory letter SR 26-2 and the OCC as Bulletin 2026-13. It replaces the model risk guidance that US banks had used since 2011, along with the 2021 BSA/AML statement.
- Is SR 11-7 still in effect?
- No. SR 26-2 supersedes and replaces SR 11-7, the 2011 Guidance on Model Risk Management, and SR 21-8, the 2021 interagency statement on model risk management for BSA/AML systems. The OCC also rescinded its companion Bulletin 2011-12 and the Model Risk Management booklet of the Comptroller’s Handbook on the same day.
- Does SR 26-2 apply to community banks?
- Generally not. SR 26-2 says it is expected to be most relevant to banking organizations with more than $30 billion in total assets, and that models at smaller organizations are typically governed by internal practices suited to their size. It may still apply to smaller banks with significant model risk or activities outside traditional community banking.
- Does SR 26-2 cover generative or agentic AI?
- No. A scope footnote in SR 26-2 states that generative AI and agentic AI models are novel and rapidly evolving and are not within the scope of the guidance. Banking organizations are directed to use their own risk management and governance practices to set appropriate controls for the tools and systems the guidance does not cover.
- Is SR 26-2 binding on banks?
- SR 26-2 states that it does not set enforceable standards or prescriptive requirements, and that non-compliance with the guidance will not result in supervisory criticism. It adds that supervisory action may still follow from violations of law or unsafe or unsound practices that stem from insufficient management of model risk.
- What should a bank do about AI agents while guidance is pending?
- A bank should keep a separate inventory of generative and agentic systems, govern vendor agents under the 2023 interagency third-party guidance, tier each agent by the actions it can take, require a named approver or standing policy for consequential actions, and record every agent action at the moment it happens.
Related Reading
Sources
- Board of Governors of the Federal Reserve System, SR 26-2: Revised Guidance on Model Risk Management and guidance text (PDF), April 17, 2026
- Office of the Comptroller of the Currency, News Release 2026-29, April 17, 2026
- Board of Governors of the Federal Reserve System, SR 23-4: Interagency Guidance on Third-Party Relationships, June 7, 2023
- Board of Governors of the Federal Reserve System, 2024 Annual Report: Supervision and Regulation
- ExecutiveGov, Treasury Issues AI Lexicon, Risk Framework for Financial Sector, February 23, 2026
This post summarizes public regulatory documents. It is not legal or regulatory advice. Whether a specific practice satisfies supervisory expectations is a determination for your compliance team and counsel.