Regulatory Reference

SR 11-7 and AI model risk management vendors

SR 11-7 is no longer in force. On 17 April 2026 the Federal Reserve, the OCC and the FDIC issued revised guidance on model risk management, published by the Federal Reserve as SR 26-2, which superseded the 2011 framework and rescinded 4 further documents alongside it, including the one bulletin addressed specifically to credit scoring models. The replacement is shorter, principles based, disclaims its own enforceability, and excludes generative and agentic AI from its scope entirely.

Reviewed 2026-08-18. This page records what the documents say and what the vendor population documents. It is not legal advice.

The framework everyone cites for AI model risk does not cover most AI

The revised guidance explicitly excludes generative and agentic AI models, on the stated basis that the technologies are novel and rapidly evolving. It continues to apply to traditional statistical and quantitative models and to AI models that are neither generative nor agentic. The agencies said they plan to issue a request for information addressing banks’ use of AI, including generative and agentic AI. That request has not been issued.

The word to hold on to is excluded, not exempt. The guidance directs banking organizations to apply their general risk management and governance practices to systems outside its scope, and nothing about fair lending, adverse action, unfair or deceptive practices, or safety and soundness moved on 17 April. What went away is the named framework a buyer could point at, at precisely the moment the products being bought became generative.

What was issued and what it replaced

The table records the 2011 framework, the two documents built on it that carry dates of their own, the replacement, and the one step the agencies have announced without a date. Two further OCC issuances were rescinded on the same date and are named in the replacement row. The last row is an open question rather than a dated obligation.

Status as of 2026-08-18
4 of 5 already apply
  1. Applies now
    4 April 2011

    SR 11-7 and OCC Bulletin 2011-12, Supervisory Guidance on Model Risk Management

    Superseded 17 April 2026

    The Federal Reserve and the OCC jointly issued the framework that defined US model risk management for fifteen years: model development, implementation and use; model validation; and governance, policies and controls. It defined a model broadly, required review or validation at least annually, and set out detailed expectations for validating vendor models including obtaining developmental evidence and maintaining contingency plans. It is no longer in force.

  2. Applies now
    7 June 2017

    FDIC FIL-22-2017 adopts the 2011 guidance for FDIC supervised institutions

    Rescinded 17 April 2026

    The FDIC adopted the 2011 guidance with technical conforming changes, and added an applicability note: it was not expected to pertain to institutions under 1 billion dollars in total assets unless model use was significant or complex. That is where the 1 billion dollar figure in circulation comes from, and it has been replaced.

  3. Applies now
    9 April 2021

    Interagency Statement on Model Risk Management for BSA and AML systems

    Rescinded 17 April 2026

    Issued as Fed SR 21-8, OCC Bulletin 2021-19 and FDIC FIL-27-2021, it addressed how the 2011 principles applied to the systems banks use for Bank Secrecy Act and anti money laundering compliance, and confirmed that whether a given BSA or AML system is a model is a bank specific determination. It is rescinded.

  4. Applies now
    17 April 2026

    SR 26-2, Revised Guidance on Model Risk Management

    Current guidance

    The Federal Reserve, OCC and FDIC issued revised guidance replacing all of the above, plus OCC Bulletin 1997-24 on credit scoring models and the Model Risk Management booklet of the Comptroller’s Handbook. It narrows the definition of a model, introduces a materiality framework, sets a uniform 30 billion dollar applicability threshold, removes the annual validation cadence, lightens the vendor model expectations, and states on its face that it does not set enforceable standards and that non compliance will not by itself result in supervisory criticism.

  5. Applies from
    Announced, not yet issued
    Next live date

    Request for information on model risk management and banks’ use of AI

    No date set

    The OCC announcement accompanying the revised guidance said the agencies plan to issue a request for information addressing model risk management generally and, in particular, banks’ use of AI including generative AI, agentic AI and AI based models. Until something follows it, generative and agentic systems sit outside the named model risk framework and inside general risk management and governance expectations.

Source: Federal Reserve SR 26-2 and its attachment, Supervisory Guidance on Model Risk Management, 17 April 2026; FDIC and OCC press releases of the same date; Federal Reserve SR 11-7 and OCC Bulletin 2011-12, 4 April 2011; FDIC FIL-22-2017, 7 June 2017. This table records dates and scope. It is not legal advice, and a classification decision on a specific system should be taken with counsel.

What actually changed

Six substantive changes. The first column is the 2011 position, the second is the position since 17 April 2026, and the third is the part that reaches a vendor evaluation.

The definition of a model narrowed

Under the 2011 guidance

A quantitative method, system or approach applying statistical, economic, financial or mathematical theories, techniques and assumptions to process input data into quantitative estimates.

Since 17 April 2026

A complex quantitative method, system or approach applying statistical, economic or financial theories to process input into quantitative estimates, expressly excluding simple arithmetic calculations such as those found in spreadsheets, and deterministic rule based processes and software with no statistical, economic or financial theory underpinning their design or use.

A deterministic rules engine is now outside the definition on its face. A large amount of what is sold into financial institutions as risk software is exactly that, sometimes with a model beside it, and the boundary now has to be drawn product by product rather than assumed.

Generative and agentic AI are excluded from scope

Under the 2011 guidance

The 2011 guidance predated generative AI and did not address it.

Since 17 April 2026

The revised guidance explicitly excludes generative and agentic AI models from its scope on the basis that the technologies are novel and rapidly evolving. It confirms that it does apply to traditional statistical and quantitative models and to non generative, non agentic AI models.

This is the change with the widest reach and it is the most misread. Excluded does not mean unregulated: the guidance directs banking organizations to apply their general risk management and governance practices to anything outside its scope, and consumer protection, fair lending and safety and soundness law is untouched. What has gone is the named framework a buyer could point at.

A uniform 30 billion dollar applicability threshold

Under the 2011 guidance

The Fed and OCC set no asset threshold. The FDIC set 1 billion dollars in 2017, with a proviso for significant or complex model use below it.

Since 17 April 2026

The revised guidance is stated to be most relevant to banking organizations with over 30 billion dollars in total assets, while noting it may also be relevant to smaller institutions with significant exposure to model risk through the prevalence and complexity of their models or activities outside traditional community banking.

Most of the institutional buyer base described in vendor copy across this index sits below 30 billion dollars. That does not make a model at a community bank or a credit union unsupervised, and the guidance says so, but the default expectation that used to sit over a 1 billion dollar institution has moved.

The annual validation cadence is gone

Under the 2011 guidance

Review or validation at least annually, with prescriptive detail on validator independence including compensation design, and specific board and senior management duties such as annual approval of model risk policies.

Since 17 April 2026

No required validation cadence. Effective challenge is described as performed by individuals with sufficient independence to maintain objectivity, and governance is described as benefiting from clear roles and responsibilities with well defined accountability.

A buyer can no longer assume an annual revalidation rhythm on the other side of the table, and a vendor cannot assume its customers are on one. Where a procurement document says annual model validation, it is now a contractual term rather than a supervisory given.

Vendor model expectations were lightened

Under the 2011 guidance

Detailed expectations including obtaining developmental evidence from the vendor, conducting independent validation, and maintaining contingency plans for vendor disruption.

Since 17 April 2026

Sound practice for validating a vendor product is described as developing an understanding of the model, together with ongoing monitoring and outcome analysis. The guidance acknowledges that proprietary components may limit a banking organization’s visibility. There is no explicit contingency plan requirement.

This is the change that matters most to a vendor evaluation, and it cuts in an uncomfortable direction. The supervisory pressure that pushed vendors to hand over developmental evidence has been relaxed, while the buyer still owns the outcome of the model. Less obligation to disclose is not less need to know.

The guidance disclaims its own enforceability

Under the 2011 guidance

Formally non binding but written in the language of supervisory expectations, with no statement about what non compliance would mean.

Since 17 April 2026

It states that it does not set forth enforceable standards or prescriptive requirements and that non compliance with the guidance will not result in supervisory criticism, while noting in a footnote that supervisory action may still result from violations of law or unsafe or unsound practices stemming from insufficient management of model risk.

Read both halves. The framework is not a checklist a supervisor will score, and a badly managed model is still an unsafe or unsound practice. The consequence for a buyer is that the discipline has to come from somewhere other than a fear of the examiner citing a paragraph.

What the vendors themselves publish, now that less is asked of them

The 2011 guidance told a bank to obtain developmental evidence from its vendors. The revised guidance asks for an understanding of the model and acknowledges that proprietary components may prevent one. That shifts the question from what a vendor must hand over under supervisory pressure to what a vendor chooses to publish, which is measurable. Across 490 indexed AI vendors selling into financial services, 240 document model risk and transparency at A or B, which is 49 percent.

The spread by lane is the finding, and it is a spread at the bottom rather than a race at the top. Four lanes sit within three points of each other in the low to mid fifties, capital markets and research among them at 90 of 167 or 54 percent, and which of the four leads changes with ordinary intake. What does not change is the floor. Customer and banking agents documents it least often, 43 of 112 at 38 percent, which is last of the nine lanes in the index and has been last on every read. That is the lane where generative and agentic systems are most concentrated, and it is therefore the lane most fully outside the revised guidance. The products least covered by the framework are the products whose makers say least about how their models work.

Between those two sit the lanes with the longest supervisory history. Credit decisioning documents it 77 of 136 at 57 percent, compliance and surveillance 87 of 160 at 54 percent, and insurance AI 42 of 81 at 52 percent. Credit also sits at the top of the index on AI governance and bias disclosure, at 33 of 136, which is what decades of fair lending supervision look like in a public record. Fraud and transaction risk now sits level with it on that axis, which is worth knowing before treating the credit figure as a category of one. It is worth noting that the one piece of US supervisory guidance addressed specifically to credit scoring models, OCC Bulletin 1997-24, was rescinded on the same date, with nothing product specific put in its place.

Every grade behind these figures sits on the vendor profile it came from, with the public artifact it was read from and the date it was verified. The methodology explains the bands, and the average vendor documents of nine regulatory axes in public.

In summary

SR 11-7 was superseded on 17 April 2026 by revised interagency guidance on model risk management, issued by the Federal Reserve as SR 26-2, which also rescinded OCC Bulletin 2011-12, FDIC FIL-22-2017, the 2021 interagency BSA and AML model risk statement and OCC Bulletin 1997-24 on credit scoring models. The replacement narrows the definition of a model, introduces a materiality framework, applies a uniform 30 billion dollar threshold, removes the annual validation cadence, lightens vendor model expectations, and explicitly excludes generative and agentic AI from its scope pending a request for information that has not yet been issued. Of 490 AI vendors selling into financial services indexed by the AI FinTech Index in August 2026, 240 publicly document model risk and transparency, and the lane where generative and agentic systems are most concentrated documents it least, at 43 of 112.

Source: AI FinTech Index, August 2026

Work from the data

If the framework no longer supplies the questions, the questions have to come from the record. The due diligence checklist turns the grades into fifteen questions with the share of vendors whose public record already answers each one. The compliance evaluation framework sets out how the axes are graded. The credit underwriting guide covers the lane the rescinded credit scoring bulletin used to speak to, and the EU AI Act reference covers the regime moving in the opposite direction on the same systems.

Common questions

What does SR 11-7 require from AI vendors in financial services?

Nothing, on two counts. SR 11-7 was superseded on 17 April 2026 by revised interagency guidance published as SR 26-2, and neither document places a requirement on a vendor in the first place. Model risk guidance binds the banking organization; the vendor is a supplier whose model the institution has to understand and monitor. Three changes matter to anyone selling an AI product into this market. Generative and agentic AI are excluded from the scope of the revised guidance entirely. The 2011 expectations that a buyer obtain developmental evidence from the vendor and maintain contingency plans for vendor disruption are gone, which moves vendor disclosure from a supervisory expectation toward a commercial negotiation. And the guidance states on its face that it does not set enforceable standards. What a buyer can still check without asking permission is the public record: about half of the AI vendors indexed here document model risk and transparency at A or B.

Is SR 11-7 still in effect?

No. On 17 April 2026 the Federal Reserve, OCC and FDIC issued revised guidance on model risk management, published by the Federal Reserve as SR 26-2, which supersedes SR 11-7 and OCC Bulletin 2011-12 from April 2011, FDIC FIL-22-2017, the 2021 interagency statement on model risk management for BSA and AML systems, OCC Bulletin 1997-24 on credit scoring models, and the Model Risk Management booklet of the Comptroller’s Handbook. A large amount of material published before that date, and some published after it, still describes SR 11-7 as the current framework.

Does the current model risk guidance cover generative AI?

No. The revised guidance explicitly excludes generative and agentic AI models from its scope, on the stated basis that the technologies are novel and rapidly evolving, and the agencies announced a request for information on banks’ use of AI that has not yet been issued. It does apply to traditional statistical and quantitative models and to AI models that are neither generative nor agentic. Excluded from this guidance is not excluded from oversight: the agencies direct banking organizations to apply their general risk management and governance practices to systems outside its scope.

What are the best AI model risk management vendors?

The honest answer is that the question has two halves and only one of them is a software purchase. Platforms that automate model documentation, validation, inventory and monitoring exist and several are indexed here, but the obligation they support sits with the institution and not with the tool. The other half is what the vendors already inside your model inventory publish about their own models, which is what this index grades: across 490 indexed AI vendors selling into financial services, 240 document model risk and transparency at A or B in public, so a shortlist built on that axis is a shortlist of vendors whose models can actually be understood by the buyer who has to answer for them.

Does the revised guidance still require validation of vendor models?

It describes sound practice rather than requiring anything. For a vendor product, the revised guidance identifies developing an understanding of the model together with ongoing monitoring and outcome analysis, and it acknowledges that proprietary components may limit a banking organization’s visibility. Gone are the 2011 expectations to obtain developmental evidence from the vendor and to maintain contingency plans for vendor disruption. The practical effect is that how much a vendor tells you is now closer to a commercial negotiation than a supervisory one.

Does the 30 billion dollar threshold mean community banks are exempt?

No. The revised guidance says it is expected to be most relevant to banking organizations over 30 billion dollars in total assets, and adds that it may also be relevant to smaller institutions with significant exposure to model risk through the prevalence and complexity of their models or through activities outside traditional community banking. Separately, none of the law that reaches a model output moved: fair lending, adverse action notice duties, unfair or deceptive practices rules and safety and soundness all apply at any size.

What replaced the credit scoring model guidance?

Nothing specific to credit scoring. OCC Bulletin 1997-24, Credit Scoring Models: Examination Guidance, including its appendix on safety and soundness and compliance issues, was rescinded on 17 April 2026 and the revised guidance is general rather than product specific. Credit decisioning remains the most legally exposed category in this index for reasons that sit outside model risk guidance entirely, and it is also the lane whose vendors document AI governance and bias disclosure most often, at 33 of 131.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746