Model risk management governs the risks arising from the development, use, and limitations of models within a defined institution and its policy. In US banking supervision the reference document changed in 2026, and the change matters most for the question people bring to it.
SR 11-7 is superseded
SR 26-2, issued 17 April 2026, expressly replaces SR 11-7 and SR 21-8. Fifteen years of practice, vendor marketing, and internal policy cite the old letter, so the older label now describes lineage rather than the current version.
The revised guidance is expected to be most relevant to banking organisations above 30 billion dollars in assets, and its attachment also discusses smaller organisations with significant model risk exposure. Size is a strong signal about relevance and not a scope boundary on its own.
Footnote 3
The attachment defines models through complex quantitative methods that produce quantitative estimates. It excludes simple arithmetic and deterministic rule-based processes and software where no statistical, economic, or financial theory underpins their design or use.
Footnote 3 goes further and explicitly excludes generative and agentic AI, directing organisations to their own risk-management and governance practices for tools outside the guidance’s scope. The principles apply to traditional statistical and quantitative models, and to non-generative, non-agentic AI models.
This is the opposite of what most institutions assumed while building AI policy on the SR 11-7 lineage. A large language model drafting summaries, answering member questions, or extracting fields from documents is not brought inside model risk management by being called AI.
Out of scope is a routing instruction
Exclusion does not mean unreviewed. The guidance directs the organisation to its own risk-management and governance practices, which means the work moves rather than disappears — to the institutional AI policy, the technology review, third-party risk, security, and legal.
The failure mode is treating the exclusion as a finding of low risk. Nothing in the footnote says a generative application is safe, and the routing step is the point: name the applicable internal review path for the specific application, and record that the path has not yet approved it.
Composite systems make this concrete. A statistical credit-risk model sitting alongside a generative assistant that drafts staff summaries has two components with two treatments. The statistical component needs its own scope assessment. The assistant does not enter scope by adjacency. And where staff begin relying on generated summaries for consequential decisions, the changed use is what triggers governance review — a fact about how the output is used, not about how the system was built.
What the guidance actually asks for in scope
Three things carry over and are worth stating because they are the substance rather than the vocabulary.
Tailoring. Validation and monitoring are proportionate to model use and materiality. There is no universal annual-validation rule, and inventing one substitutes ceremony for judgement.
Vendor products. Model risk principles are retained for models obtained from vendors. Supplier confidentiality is not immunity from them.
Effective challenge. This requires expertise, sufficient independence to be objective, and enough influence to effect changes. All three are necessary. A reviewer with expertise and no authority produces a documented objection and no correction, which is indistinguishable from no review in the outcome.
The attachment also recognises that rigorous validation can leave material risk outstanding. Validation is not a discharge.
The rule
What stays fixed is that scope follows the method and the use, not the name of the technology or the department that built it. What changes is which document governs, and that has to be checked against the current version rather than the one the internal policy was written against.
Where this goes wrong
A superseded interpretation propagates. An internal standard citing SR 11-7 and asserting that all AI is covered now contradicts the guidance it claims to implement. The direction of the error matters: it pulls generative systems into a validation process not designed for them while leaving the actual governance path unassigned.
Non-binding is read as optional. The attachment states that it does not set enforceable standards or prescriptive requirements. Its accompanying footnote distinguishes supervisory action arising from legal violations or unsafe or unsound practices connected to insufficient model risk management. Those two statements coexist, and reading only the first is how institutions arrive at a defence nobody accepts.
Not to be confused with
An AI risk framework. NIST’s framework and ISO/IEC 42001 address different objects and neither is supervisory guidance for a US bank.
Permission to deploy. A component-level scope determination establishes which review applies. It is not lawful lending, and it is not approval.