Skip to main content

Elevate

SR 11-7 Was Rescinded, and the Guidance That Replaced It Excludes AI

SR 11-7 no longer governs model risk management at US banking organizations. On April 17, 2026, the Office of the Comptroller of the Currency, the Federal Reserve Board, and the Federal Deposit Insurance Corporation jointly issued revised interagency guidance that rescinds the 2011 framework outright, and the document that replaced it carries a scope exclusion most institutions have not yet worked through: generative AI and agentic AI models sit outside it. For a risk function that spent fifteen years building validation programs against SR 11-7, the practical question is no longer how to extend that framework to cover AI. It is what governs the AI that the new guidance declined to reach.

What Changed on April 17, 2026

The Rescission Was Total, Not a Revision

The agencies did not amend SR 11-7. They replaced it and withdrew the surrounding body of guidance with it. OCC Bulletin 2026-13, issued alongside Federal Reserve SR 26-2, rescinds OCC Bulletin 2011-12, the OCC companion to SR 11-7, along with three other issuances that together formed the operating manual most model risk functions were built from.

Rescinded issuanceWhat it covered
OCC Bulletin 2011-12 / Fed SR 11-7The foundational supervisory guidance on model risk management
OCC Bulletin 2021-19 / Fed SR 21-8The interagency statement on model risk for BSA and AML systems
OCC Bulletin 1997-24Examination guidance on credit scoring models
Model Risk Management booklet, Comptroller’s HandbookThe examination procedures built on the 2011 guidance

Reading that list together rather than item by item is what makes the scale clear. An institution that lost only SR 11-7 would still have the BSA and AML statement and the Handbook booklet to anchor its validation methodology. Losing all four in a single issuance removes the accumulated interpretation as well as the source document, which is why a model risk function cannot treat this as a citation update in its policy library.

The New Guidance Is Voluntary in a Way SR 11-7 Was Not

The more consequential change is the enforcement posture. SR 11-7 was technically supervisory guidance rather than a rule, but examiners applied it as a baseline expectation and cited deficiencies against it in supervisory findings. The 2026 guidance states plainly that it does not set forth enforceable standards or prescriptive requirements, and that non-compliance will not result in supervisory criticism.

That sentence reads like relief and functions like the opposite. A prescriptive standard tells an institution what adequate looks like, which means an institution that meets it has a defensible position. Principles-based guidance that disclaims enforceability transfers the definition of adequate from the supervisor to the institution, and an institution that has to define adequate for itself needs a documented methodology behind that definition. The supervisory expectation did not disappear. The specification of how to meet it did.

What the Revised Guidance Keeps

The revised guidance retains the conceptual core of validation, including conceptual soundness, outcomes analysis, and ongoing monitoring, while removing the prescriptive methodology around them. Traditional statistical and machine learning models used in credit underwriting, fraud detection, and transaction monitoring generally remain within scope. An institution running a logistic regression credit scorecard or a gradient boosting fraud model is still doing model risk management, and the 2026 principles still describe what the agencies expect from it.

The change for those models is a shift from a detailed operating model to an outcomes description. A validation program built around fixed cycles, prescribed backtesting frequencies, and specific board task lists now has to justify those choices on its own risk rationale rather than by pointing to a paragraph in the 2011 guidance.

The Scope Exclusion That Creates the Gap

Generative and Agentic AI Are Outside the Guidance

The revised guidance excludes generative AI and agentic AI models from its scope, on the stated basis that these technologies are novel and rapidly evolving. The agencies also announced that they plan to issue a request for information in the near future addressing model risk management generally and banks’ use of AI specifically, including generative AI, agentic AI, and AI-based models.

Two things follow from that, and institutions tend to get one of them right and the other wrong. The first is widely understood and rarely acted on; the second is widely misunderstood and expensive.

The first is straightforward: the exclusion is a deferral, not an exemption. Nothing about the underlying activity changed. A generative AI system that drafts customer communications, summarizes credit files, or routes service requests still produces outcomes the institution is accountable for, still touches consumer data, and still sits inside the obligations attached to that activity. The agencies withdrew the specification of what adequate governance looks like for these systems. They did not withdraw the accountability.

The second is where programs go wrong: the exclusion is not a reason to wait for the request for information. An RFI has no published timeline, and a request for information is a step before a proposal, which is itself a step before a final issuance. Counting those steps against how fast generative AI is being deployed inside institutions produces an uncomfortable answer about how long the interval will run.

An institution deploying generative AI across its operations during that interval is accumulating a governance record that a future examiner will read retrospectively. The examination will not ask whether guidance existed at the time. It will ask what the institution did about a known risk during a period when the supervisors had publicly flagged that they intended to address it. Waiting produces an unexplainable gap in that record rather than a clean slate, and the institutions that fare worst are usually the ones that read the exclusion as permission and documented nothing for eighteen months.

What the Exclusion Actually Removes

It helps to be specific about what an institution loses when a system falls outside the revised guidance, because the answer is narrower than it first appears and more awkward than a simple gap. The exclusion removes one layer of a stack rather than the whole stack, and what remains underneath is where most of the practical obligation still lives.

ElementTraditional model under 2026 guidanceGenerative or agentic AI
Governing documentRevised interagency guidance appliesNo supervisory framework currently applies
Validation expectationConceptual soundness, outcomes analysis, ongoing monitoringUndefined by supervisors
Underlying accountabilityUnchangedUnchanged
Third-party obligationsInteragency third-party risk guidance appliesInteragency third-party risk guidance applies

That last row matters more than institutions expect. Most generative AI in production at a bank arrives through a vendor, either consumed by API or embedded inside a product the institution already bought. The interagency guidance on third-party relationships remains fully in force, which means a generative AI capability delivered by a vendor carries live third-party risk obligations even while sitting outside model risk scope. An institution that reads the exclusion as “nothing applies” has misread it.

Why SR 11-7 Methodology Does Not Stretch to Cover AI

Model Risk Management Was Built for a Different Object

The instinct inside a mature risk function is to stretch the validation methodology it already owns to cover the new systems. That instinct is reasonable and it runs into a structural problem. The 2011 framework was designed around quantitative models with a defined input set, a specified functional form, and an output that can be compared against a realized outcome. Conceptual soundness means the theory behind the model holds. Outcomes analysis means the predictions can be graded against what happened.

A generative system breaks both tests. There is no functional form to review for conceptual soundness in the sense the guidance meant, and for most generative use cases there is no realized outcome to backtest against, because the output is text or a recommendation rather than a probability that either materialized or did not. The methodology is not weak here. It is aimed at a different object.

The Risks Sit Outside What Validation Examines

Beyond methodology, the risk surface itself is different. A traditional model risk program covers validation, performance monitoring, and documentation, and that work transfers cleanly to the AI systems that remain in scope. What it was never built to evaluate is a separate list.

Bias and fairness testing sits partly inside fair lending compliance and partly nowhere, and neither the 2011 nor the 2026 model risk guidance defines what adequate testing looks like for a generative system. Explainability expectations differ in kind rather than degree, because explaining a credit scorecard’s coefficients is not the same problem as explaining why a language model produced a given recommendation. Foreseeable misuse, meaning the ways a system will be used that the deploying team did not design for, has no analogue in traditional validation at all. Opacity in third-party models leaves an institution accountable for behavior it cannot inspect. And agentic behavior, where a system takes actions rather than producing outputs a human then acts on, moves the question from model accuracy to authority and enforcement at the point of action.

Each of those is a real exposure inside a supervised institution, and none of them is closed by running the 2026 principles harder. They are not gaps in execution of an existing framework. They are categories the framework was never asked to cover, which is why a well-run traditional model risk program can be genuinely strong and still leave the institution exposed on all five.

What Fills the Gap Now

The Sector Built a Framework While the Agencies Were Deferring

The most useful development for a US financial institution in this position predates the April rescission by two months. In February 2026, the Cyber Risk Institute published the Financial Services AI Risk Management Framework at version 1.0, developed with the Financial Services Sector Coordinating Council, the US Department of the Treasury, and more than 100 financial institutions, with input from NIST.

It is a voluntary industry framework rather than a supervisory rule, and that distinction should be stated clearly rather than blurred. Its weight comes from sector consensus and from who participated in building it, not from an agency issuing it. In a period where the supervisors have explicitly deferred, a framework that institutions, counterparties, and examiners can all read is a more useful reference point than the alternative, which is each institution inventing its own definition of adequate and defending it alone.

How It Relates to the Frameworks Already in Place

The FS AI RMF was not designed to displace what an institution already runs, which matters for a risk function that does not want a fourth parallel program. It routes to the programs that exist rather than restating their content, and the table below shows where each of the adjacent frameworks sits relative to it.

FrameworkRelationship to FS AI RMF
NIST AI RMFDirect parent structure. FS AI RMF builds on Govern, Map, Measure, Manage and adds the control objectives and staging logic NIST leaves to the implementer
Revised model risk guidanceAdjacent. Traditional models stay under the 2026 principles; FS AI RMF reaches the AI risks model risk was not built to evaluate
CRI ProfileSame publisher, cybersecurity rather than AI risk. Institutions already using the Profile know the structure and vocabulary
ISO/IEC 42001Certifiable standard rather than sector framework. FS AI RMF produces supervisory-ready evidence, ISO 42001 produces an accredited certificate

Reading across that table, the overlap that causes the most confusion is the third row down rather than the second. Institutions expect tension between model risk management and AI risk and plan for it. What surprises them is how much the CRI Profile prepares them structurally for the FS AI RMF, because a firm already fluent in the Profile’s control objective format is not learning a new document architecture, only a new risk domain inside a familiar one.

Obligations Scale to a Documented Adoption Stage

The mechanic that makes the framework usable across institution sizes is that it establishes maturity before assigning obligations. An adoption stage questionnaire places an institution in one of four stages, Initial, Minimal, Evolving, or Embedded, assessed across business impact, technology implementation, and scalability. The stage is not a maturity score. It determines which control objectives apply, which makes it the single decision that sizes the entire program.

The number that tends to end the debate inside a risk committee is the distance between two adjacent stages. An institution at Minimal carries 120 control objectives. An institution at Evolving carries 193. The line between them is crossed the moment AI touches sensitive data or an external-facing outcome, which is a lower threshold than most institutions assume when they estimate their own position from impression rather than from the questionnaire.

What a Risk Function Should Do Before the RFI Lands

Establish the Position on Record

The first move is documentary rather than technical. An institution needs a written statement of which of its AI systems fall inside the revised model risk guidance, which fall into the generative and agentic exclusion, and what governs the second group in the absence of supervisory specification. That document is what an examiner reads later to understand whether the institution was tracking the change or discovered it during the examination.

This is also where institutions find that their inventory does not support the analysis. Most model inventories were built to catalogue models, not AI capabilities, which means they miss the generative features embedded inside vendor products that no one procured as AI. A productivity suite that added a drafting assistant, a service platform that added summarization, and a core banking vendor that added an anomaly narrative generator all introduced AI into the institution without a single procurement decision that named AI as the thing being bought.

An inventory built for the new question covers three categories rather than one. Built systems are the models the institution developed itself, which the existing inventory already captures. Procured systems are the AI capabilities the institution knowingly bought, which are usually findable through contracts even when they are not in the model inventory. Embedded systems are the capabilities that arrived inside products bought for other reasons, and they are the category that takes real work to surface, because no internal record identifies them as AI. An incomplete inventory is a finding to scope rather than a reason to postpone the exercise, and institutions that wait for a complete one before starting the governance work generally never start.

Choose a Reference Framework and Say Why

Because the supervisors deferred, the institution has to name its own reference point and be able to explain the choice. A sector framework developed with Treasury and the Financial Services Sector Coordinating Council participation is a defensible answer. An internally invented control set with no external anchor is a harder one to defend, not because it is necessarily worse, but because the institution carries the entire burden of justifying it.

Build to the Stage Above the Current One

Where an institution sits close to a stage boundary, the defensible position is to build to the higher stage and implement in tranches. A framework written below an institution’s actual AI footprint will be criticized by Internal Audit or an examiner, while one written to the higher stage and phased in over time will not. The adoption stage should then be reassessed annually, because internal model development is the trigger that moves an institution into the highest stage, and that trigger is frequently crossed by a team shipping something without routing it through risk.

Where Elevate Fits

Elevate Consult runs the FS AI RMF adoption stage determination, the control objective gap read-out, and the framework design that closes the distance between a model risk program built for 2011 and the AI footprint an institution actually carries in 2026. That work includes mapping which existing model risk, third-party risk, and information security controls already satisfy part of an FS AI RMF objective, so the framework routes to the programs an institution already runs instead of duplicating them. To determine where an institution stands against the control objectives that apply to its stage, book a readiness call with an Elevate advisor.

Conclusion

The April 2026 rescission removed the framework a generation of model risk professionals built their programs against, and replaced it with principles that explicitly decline to reach the systems creating the most new exposure. For traditional models, the practical consequence is a shift from following a prescribed methodology to justifying a chosen one. For generative and agentic AI, the consequence is that the institution now defines adequate on its own, with an examiner reading that definition later.

The gap is real and it is not permanent, but the institutions that handle it well will be the ones that documented a position during the deferral rather than the ones that waited for the request for information to resolve into something citable. A voluntary sector framework built with Treasury participation is currently the strongest available anchor for that position, and the adoption stage determination is the cheapest possible first step toward it.

Elevate Consult works with banks, credit unions, insurers, asset managers, and the technology vendors that serve them on exactly this transition. To scope what applies to a specific institution, schedule a readiness call.

Key Takeaways

  • SR 11-7 was rescinded, not revised. OCC Bulletin 2026-13 and Federal Reserve SR 26-2, issued April 17, 2026, withdrew SR 11-7, OCC Bulletin 2011-12, the BSA and AML model risk statement, the 1997 credit scoring guidance, and the Comptroller’s Handbook booklet together.
  • The replacement guidance disclaims enforceability. It states that it does not set forth enforceable standards and that non-compliance will not result in supervisory criticism, which moves the definition of adequate from the supervisor to the institution.
  • Generative and agentic AI are explicitly out of scope. The agencies excluded them as novel and rapidly evolving, and announced a forthcoming request for information with no published timeline.
  • The exclusion is a deferral, not an exemption. The underlying accountability for outcomes, consumer impact, and third-party relationships is untouched, and interagency third-party risk guidance still applies to vendor-delivered AI.
  • Traditional model risk methodology does not stretch to cover generative systems. Conceptual soundness and outcomes analysis assume a functional form and a realized outcome, and generative use cases usually provide neither.
  • A sector framework now fills the gap. The Cyber Risk Institute published the Financial Services AI Risk Management Framework in February 2026 with Treasury and Financial Services Sector Coordinating Council participation, scaling control objectives to a documented adoption stage.

FAQs

Is SR 11-7 still in effect? No. On April 17, 2026, the OCC, Federal Reserve, and FDIC jointly issued revised interagency guidance on model risk management that rescinds SR 11-7 and OCC Bulletin 2011-12, along with the 2021 interagency statement on BSA and AML model risk, OCC Bulletin 1997-24 on credit scoring models, and the Model Risk Management booklet of the Comptroller’s Handbook. Institutions citing SR 11-7 in current policy documents are citing a withdrawn issuance.

What replaced SR 11-7? Federal Reserve SR 26-2 and OCC Bulletin 2026-13, issued jointly on April 17, 2026, replaced it with a principles-based framework. The revised guidance retains conceptual soundness, outcomes analysis, and ongoing monitoring as validation concepts while removing the prescriptive methodology around them, and states that it does not set forth enforceable standards or prescriptive requirements and that non-compliance will not result in supervisory criticism.

Does the new model risk guidance cover AI? Partially. Traditional statistical and machine learning models used in areas such as credit underwriting, fraud detection, and transaction monitoring generally remain within scope. Generative AI and agentic AI models are explicitly excluded, on the stated basis that they are novel and rapidly evolving. The agencies announced plans to issue a request for information addressing banks’ use of AI, including generative and agentic AI, without publishing a timeline for it.

If generative AI is out of scope, does anything govern it? Yes, though not through model risk management. The exclusion removes the supervisory specification of adequate governance, not the institution’s accountability for outcomes, consumer impact, or fair treatment. Interagency third-party risk guidance remains fully in force, which reaches most generative AI in production at banks, since it typically arrives through a vendor by API or embedded inside a purchased product.

What should an institution use in the meantime? The Financial Services AI Risk Management Framework, published by the Cyber Risk Institute at version 1.0 in February 2026, is the most widely referenced sector option. It was developed with the Financial Services Sector Coordinating Council, the US Department of the Treasury, and more than 100 financial institutions, and it scales control objectives to an assessed AI adoption stage rather than applying one set to every institution. It is a voluntary framework rather than a supervisory rule, and its value is as a common reference that institutions, counterparties, and examiners can all read.