Skip to main content

Elevate

Model Risk Management Framework: What to Rebuild After 2026

A model risk management framework written before April 2026 now rests on guidance that no longer exists. The rescission of SR 11-7 and its companion issuances did not simply retire a citation. It narrowed the definition of what counts as a model, removed the prescriptive methodology that validation programs were built around, introduced an asset-size marker for relevance, and folded a specialized BSA and AML regime back into the general framework without replacement. Each of those changes alters a different part of the framework document, and an institution that updates only the citations will carry a policy that describes a program the guidance no longer asks for. This article covers what each change means structurally and what a framework rebuild actually has to touch.

What the Revised Guidance Actually Says

Three Areas, Not a Methodology

The revised guidance, issued April 17, 2026 as OCC Bulletin 2026-13, Federal Reserve SR 26-2, and FDIC FIL-15-2026, organizes its content around the factors that influence model risk and the features of effective practice in three areas: model development and model use, including model testing; model validation and monitoring, including validation of conceptual soundness and outcomes analyses; and governance and controls, including clear policies and roles and responsibilities. It adds a dedicated treatment of vendor and other third-party products, including validation of those products.

Read against the 2011 framework, the continuity is real and the change is in specificity rather than subject matter. Conceptual soundness and outcomes analysis survive as validation concepts. What does not survive is the detailed operating model built on top of them: prescribed validation frequencies, enumerated board and internal audit task lists, and the specific methodology requirements that most framework documents reproduced almost verbatim from the guidance.

What Survives the Change Unchanged

Before cataloguing what moved, it is worth being precise about what did not, because a rebuild that rewrites settled sections wastes effort and introduces error. Conceptual soundness remains a validation concept. Outcomes analysis remains a validation concept. Ongoing monitoring remains an expectation. Clear policies and documented roles and responsibilities remain a governance expectation. Effective challenge by parties independent of model development and use remains the mechanism by which validation carries weight.

An institution whose framework describes those things well already holds most of a compliant document. What it does not hold is the justification layer underneath them, which the 2011 guidance supplied and the revised guidance withdrew. The rebuild adds reasoning to sections that survive and rewrites the sections that did not.

The Enforceability Statement Changes the Drafting Problem

The guidance states that it does not set forth enforceable standards or prescriptive requirements and that non-compliance will not result in supervisory criticism. That sentence is usually reported as a relaxation, and it functions as a drafting burden.

Under prescriptive guidance, a framework document could justify its choices by citing the source. A validation cycle was annual because the guidance implied annual. Under principles-based guidance that disclaims enforceability, the same document has to justify the same choice on the institution’s own risk rationale, and a reviewer asking why the cycle is annual will not accept a citation as the answer. The framework now has to carry the reasoning it previously borrowed.

The Relevance Marker at $30 Billion

The OCC states that the updated guidance is expected to be most relevant to banking organizations with over $30 billion in total assets, while allowing relevance for certain smaller institutions. This is a marker rather than a scoping rule, and it should be read carefully in both directions.

For an institution above the threshold, nothing about the marker reduces expectations. For an institution below it, the marker does not mean model risk management stops applying. It means the depth and formality of the program should be commensurate with the institution’s model use rather than modeled on what a large institution runs, which is a point the agencies had made in earlier clarifications and have now placed in the guidance itself. The practical effect for a smaller institution is that a framework copied from a larger peer is now harder to defend as a proportionate choice, not easier.

The Narrower Model Definition Changes the Inventory

What Left the Definition

The revised guidance narrows what counts as a model to complex quantitative methods, systems, or approaches applying statistical, economic, or financial theories. Re-scoping against it is an AI and model inventory exercise before it is a policy exercise. Several categories of tool that many institutions had pulled into model inventory over the previous decade fall outside that narrower definition, including deterministic rule-based tools and spreadsheet calculations that perform no statistical estimation, alongside the explicit exclusion of generative and agentic AI.

ItemStatus under the revised definition
Statistical and econometric modelsIn scope
Machine learning models producing quantitative estimatesGenerally in scope
Deterministic rule-based toolsOutside the narrower definition
Spreadsheet calculations without statistical estimationOutside the narrower definition
Generative AI and agentic AIExplicitly excluded, pending a forthcoming request for information

The table describes what the guidance reaches, not what the institution can stop caring about, and conflating the two is the most expensive available mistake here. A rule-based sanctions screening tool that falls outside the model definition still produces regulatory outcomes the institution answers for. What changed is which framework governs it, not whether it needs governing.

Removing Items Requires a Documented Rationale

The temptation after a narrowing definition is to trim the inventory, and trimming is legitimate. Doing it silently is not. Every item removed from model inventory needs a recorded rationale explaining why it falls outside the revised definition, and a statement of what governs it instead.

That second half is the part institutions skip. An item removed from model inventory with no successor control regime named has not been reclassified. It has been dropped, and an examiner reading an inventory that shrank by forty percent in one cycle will ask where those items went. A rebuild that produces a smaller inventory and a companion register of reclassified items with their new governance owner is defensible. A rebuild that produces only the smaller inventory is not.

The BSA and AML Fold-Back

A Specialized Regime Rescinded Without Replacement

The 2021 interagency statement on model risk management for systems supporting BSA and AML compliance was rescinded alongside the 2011 guidance, and nothing replaced it. Transaction monitoring and sanctions screening models now sit inside the general model risk framework with no dedicated carve-out language.

This affects a specific and common program design. Institutions that built their financial crime model governance around the 2021 statement’s clarifications, particularly its treatment of how model risk principles apply to transaction monitoring tuning and threshold setting, now have those programs anchored to a rescinded document. The underlying supervisory interest in those systems did not diminish. The specialized framing did.

What a Financial Crime Program Has to Reassess

The reassessment is narrower than a rebuild and more specific than a citation update. It covers which of the financial crime models remain inside the narrower definition, since threshold-based rules engines may not, what governs those that fall outside it, and whether the tuning and validation cadence the program runs can be justified on the institution’s own risk rationale now that the 2021 clarifications no longer back it.

Programs that were already running a defensible risk-based approach will mostly survive this intact and need documentation rather than redesign. Programs that were following the 2021 statement as a checklist have lost the checklist.

There is a sequencing consideration specific to financial crime here. Transaction monitoring and sanctions screening carry their own supervisory attention independent of model risk, through examination of the BSA and AML program itself, and that attention did not change in April. An institution that lets its financial crime model governance sit in limbo while it rebuilds the general framework is exposed on a second front that operates on its own examination calendar. The financial crime reassessment is worth running in parallel rather than waiting for the framework rebuild to finish.

What a Model Risk Management Framework Rebuild Touches

What Each Section Now Has to Carry

A framework document written against the 2011 guidance and its successors has a predictable structure, and the rebuild touches most of it unevenly. Some sections need a rewrite, some need only a justification added underneath text that stays, and one has no predecessor at all.

Framework sectionWhat the rebuild requires
Model definition and scopeRestate against the narrower definition, with a reclassification register for items that leave
InventoryRe-scope, record removal rationales, and add AI type as an attribute
Validation methodologyKeep conceptual soundness and outcomes analysis, replace prescribed cadences with risk-based rationale
Governance and rolesRetain clear policies and responsibilities, revisit the enumerated internal audit tasks that are no longer prescribed
Third-party and vendor modelsExpand, since the revised guidance treats this explicitly and acknowledges proprietary constraints
AI systems outside scopeNew section, stating what governs generative and agentic AI in the absence of supervisory specification

The last row is the one with no precedent in the previous document, and it is the row most likely to be examined first. The agencies announced a forthcoming request for information covering model risk management generally and banks’ use of AI including generative and agentic AI, with no published timeline. Until that process concludes, an institution’s written position on what governs those systems is the institution’s own work product, and its absence is conspicuous.

Third-Party Models Get Their Own Treatment

The revised guidance includes a dedicated section on vendor and third-party products that acknowledges what practitioners have long dealt with informally: an institution frequently cannot fully validate a proprietary vendor model because the code, data, and methodology are not disclosed. The guidance confirms that model risk principles still apply and shifts the emphasis toward developing model understanding and monitoring outcomes on an ongoing basis.

For a framework document, that means the third-party section stops being a paragraph acknowledging a limitation and becomes a set of controls describing what the institution does when validation is not available: what it requires from the vendor, what it tests at the boundary, what outcome monitoring it runs, and what triggers escalation. Institutions that had been treating unvalidatable vendor models as an accepted exception now have a place to put the compensating work.

The expansion also has a second-order effect worth planning for. A framework that describes real controls for unvalidatable vendor models creates obligations the institution then has to meet, which is more work than an acknowledgment paragraph produced. That is the correct trade and it should be resourced deliberately rather than discovered during the first cycle after the document is approved. Institutions that write the section aspirationally and staff it afterward end up with a framework their own practice does not match, which is a worse position than the acknowledgment paragraph they replaced.

Where the AI Gap Sits in the Document

Because generative and agentic AI fall outside the revised guidance, an institution has to decide what framework covers them and record the decision inside or alongside the model risk framework. Leaving the question unanswered means the framework implicitly claims coverage it does not have.

The available options are not equivalent. An institution can extend its own model risk framework to those systems voluntarily, which is coherent but requires building the methodology from scratch, since conceptual soundness and outcomes analysis do not map cleanly onto generative systems. The NIST AI RMF supplies a functional structure for that work without supplying the control objectives, which the institution then has to author and defend. It can adopt a sector framework such as the Financial Services AI Risk Management Framework published by the Cyber Risk Institute in February 2026, which supplies control objectives scaled to an assessed adoption stage and shares a publisher and vocabulary with the CRI Profile many institutions already run for cybersecurity. Or it can build an internal control set with no external anchor, which is permissible and carries the full burden of justification.

Where Elevate Fits

Elevate Consult works with financial institutions on the boundary between a model risk framework rebuilt for the 2026 guidance and an AI governance framework covering what that guidance excludes, including the FS AI RMF adoption stage determination that sizes the second one. That work includes mapping which existing model risk controls already satisfy part of an AI control objective, so the two frameworks route to each other rather than duplicating content that will diverge at the next policy update. To scope a rebuild at a specific institution, book a readiness call with an Elevate advisor.

The Order the Rebuild Should Follow

Definition First, Everything Else After

The order matters because each step depends on the one before it. The model definition determines the inventory, the inventory determines the validation population, and the validation population determines the resourcing. An institution that starts by revising validation cadences before re-scoping the definition will redo that work once the population changes.

A workable sequence runs: restate the model definition, re-scope the inventory against it and record the reclassification rationales, rewrite validation methodology with risk-based justification replacing prescribed cadence, revisit governance to remove task lists the guidance no longer prescribes while keeping the roles and policies it does, expand the third-party section, and add the section stating what governs the systems outside scope. Only the last of those can run in parallel with the others, because it concerns a population the definition work already excluded.

Time the Work to the Validation Cycle

The rescission took effect immediately and the guidance sets no compliance date, which creates an ambiguity institutions resolve badly in both directions. Treating it as urgent produces a rushed rewrite. Treating it as optional produces a framework citing a rescinded document at the next examination.

The practical anchor is the institution’s own next internal audit or validation cycle, which is when the framework will be read against practice anyway. Aligning the rebuild to that cycle means the updated document and the evidence of it operating arrive together, rather than producing a revised policy with no operating history behind it.

Conclusion

The April 2026 guidance asks institutions for less specification and more justification, and a model risk management framework rebuilt for it has to carry reasoning the previous version could borrow from the source. The narrower model definition, the third-party treatment, the BSA and AML fold-back, and the explicit AI exclusion each land in a different section of the document, which is why a citation update produces a framework that is current on its references and stale on its substance.

The section with no precedent is the one describing what governs the AI the guidance declined to reach. That section is where an institution’s own judgment is most exposed, and writing it during the deferral rather than after the request for information concludes is what separates a documented position from a gap.

Elevate Consult works with banks, credit unions, insurers, asset managers and the technology vendors serving them on model risk framework rebuilds and the AI governance work that sits beside them. To scope both together, schedule a readiness call.

Key Takeaways

  • The rebuild is structural, not a citation update. The narrower model definition, the third-party section, the BSA and AML fold-back, and the AI exclusion each change a different part of the framework document.
  • The guidance organizes around three areas. Model development and use including testing, validation and monitoring including conceptual soundness and outcomes analysis, and governance and controls including clear policies and responsibilities, plus a dedicated treatment of vendor and third-party products.
  • The enforceability statement shifts the drafting burden. A framework can no longer justify a validation cadence by citing the guidance, because the guidance no longer prescribes one, so the reasoning has to live in the document.
  • The $30 billion marker is not a scoping rule. It signals where the guidance is most relevant, and for smaller institutions it makes a framework copied from a larger peer harder to defend as proportionate.
  • Items leaving the inventory need a documented successor. A narrower definition justifies a smaller inventory, but each removal needs a recorded rationale and a statement of what governs the item instead.
  • BSA and AML model governance lost its specialized statement. The 2021 interagency statement was rescinded without replacement, so transaction monitoring and sanctions screening models sit inside the general framework with no carve-out language.

FAQs

What does a model risk management framework need to change after April 2026? At minimum: the model definition, restated against the narrower scope; the inventory, re-scoped with documented rationales for removals; validation methodology, with risk-based justification replacing prescribed cadences; governance, with enumerated task lists reconsidered; the third-party section, expanded to match the guidance’s dedicated treatment; and a new section stating what governs generative and agentic AI, which the guidance excludes.

What is the new definition of a model? The revised guidance narrows the definition to complex quantitative methods, systems, or approaches applying statistical, economic, or financial theories. Deterministic rule-based tools and spreadsheet calculations that perform no statistical estimation generally fall outside it, as do generative AI and agentic AI models, which are excluded explicitly. Institutions should treat the narrowing as a change in which framework governs an item rather than as a reduction in accountability for it.

Does the $30 billion asset threshold mean smaller banks are exempt? No. The OCC states the guidance is expected to be most relevant to banking organizations above $30 billion in total assets while allowing relevance for certain smaller institutions. Model risk management still applies below the threshold, scaled to the institution’s actual model use. The practical effect is that a small institution running a framework copied from a large peer now has a harder proportionality argument, not an easier one.

What happened to BSA and AML model risk guidance? The 2021 interagency statement on model risk management for BSA and AML systems was rescinded alongside the 2011 guidance and was not replaced. Transaction monitoring and sanctions screening models now sit within the general model risk framework with no dedicated carve-out. Programs built around the 2021 statement’s specific clarifications need reassessment against the broader principles.

How should an institution time the framework rebuild? The rescission took effect immediately and the guidance sets no compliance date. The practical anchor is the institution’s next internal audit or model validation cycle, since the framework will be read against actual practice at that point. Aligning the rebuild to that cycle means the revised document arrives with operating evidence behind it rather than as a policy with no history.