On April 17, 2026, the Federal Reserve, the Office of the Comptroller of the Currency, and the Federal Deposit Insurance Corporation replaced 15 years of model risk guidance built around SR 11-7 with a single interagency bulletin that keeps the same validation core — conceptual soundness, outcomes analysis, ongoing monitoring — but states plainly that non-compliance draws no supervisory criticism.
The new guidance, issued jointly as Federal Reserve SR letter 26-2 and OCC Bulletin 2026-13, rescinds OCC Bulletin 2011-12 — the 2011 supervisory letter known across the industry by its Federal Reserve designation, SR 11-7 — along with the Comptroller's Handbook booklet on model risk management, a 1997 credit-scoring bulletin, and the 2021 interagency statement on model risk for Bank Secrecy Act and anti-money-laundering compliance. The agencies describe the rewrite as an effort to "clarify model risk management principles" and set out "a risk-based approach" scaled to a bank's size and complexity, according to the OCC bulletin.
What is model risk management?
Model risk management is the discipline of governing, developing, and validating the quantitative tools a bank uses to price, forecast, or decide. The guidance defines a model as "a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates," per the OCC bulletin's text. That definition covers credit-scoring engines, stress-test models, fraud-detection systems, and market-risk forecasts alike — any tool converting inputs into a numerical estimate a bank relies on.
The framework rests on three linked activities: model development and implementation, independent validation, and governance that assigns clear ownership. The 2026 guidance keeps this structure from SR 11-7 largely intact. What moves is the applicability standard and the enforcement posture, not the validation vocabulary examiners have used since 2011.
What actually changed from SR 11-7?
Three changes stand out against the 2011 text, based on the OCC bulletin and the Federal Reserve's SR 26-2 letter. First, applicability is now explicitly tiered by size: the guidance states it "is expected to be most relevant to banking organizations with over $30 billion in total assets," though the agencies note it may still bear on smaller banks with concentrated model exposure. Second, generative and agentic AI models are carved out entirely — the bulletin states "generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance," with the agencies signaling a separate request for information to come. Third, the guidance now says directly what SR 11-7 left to supervisory interpretation: "This guidance does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism against a banking organization."
That third change reframes the document's legal weight without discarding its content. A bank that skips a step described in the bulletin is not automatically out of compliance in the way it would be under a binding rule — but examiners retain the underlying safety-and-soundness authority the guidance was written to support, and the validation practices it describes remain the reference point supervisors will still ask about.
How is a model's performance actually validated?
Validation under the new guidance runs through the same two-part test the industry has used for a decade and a half: conceptual soundness and outcomes analysis, backed by ongoing monitoring.
Conceptual soundness comes first. The OCC bulletin describes it as "assessing and documenting model design (including key modeling choices, assumptions, qualitative judgments, and data selection), construction, and developmental testing." This step asks whether the model was built to answer the question it is now being used to answer — before a single live output is checked.
Outcomes analysis follows, and it is where a model's real-world track record enters the picture. The guidance defines it as work that "compares model outputs to corresponding real-world outcomes to assess model performance relative to model objectives and business use," and it names backtesting specifically as one method: outcomes analysis "can take many forms, including testing conducted during model development, reports or analysis performed as part of ongoing monitoring, or standalone activities such as back-testing or outlier analysis." Backtesting here means comparing a model's historical forecasts against what actually happened over a defined window — the same out-of-sample logic that underlies performance claims anywhere in quantitative finance, not a bank-specific technique.
A third element, ongoing monitoring, tracks a model after deployment rather than at a single validation date, watching for performance drift as market conditions or input data shift away from the environment the model was built and tested in.
Binding the three together is a requirement the guidance calls "effective challenge," carried over conceptually from SR 11-7: work performed "by individuals with the appropriate expertise to conduct a critical and objective challenge, sufficient independence to maintain objectivity, as well as the organizational standing and influence to effect any change." In practice, that means the people validating a model cannot be the people who built it, and their findings need enough institutional weight that a flagged problem actually gets fixed rather than logged and ignored.
Validation does not stand alone; the guidance ties it to governance and inventory requirements built to make the three-part test auditable over time. The bulletin states that "model risk management benefits from clear roles and responsibilities with well-defined accountability," with "sound governance practices" assigning named individuals to each stage of a model's life cycle — and it draws a line around internal audit's role, noting that audit "would generally not duplicate model risk management activities such as model development or validation." Banks are expected to keep "an effective model inventory" containing "sufficient information to understand model risks" across every model in development or in use, plus documentation adequate to "support the tracking of recommendations, responses, and exceptions" if a validator flags a problem.
Vendor and third-party models get their own carve-out inside the same framework rather than a separate one. The guidance calls for "validation of vendor products, either by internal or outside parties," paired with "ongoing monitoring and outcome analysis to assess whether vendor models are accurate, remain fit for purpose, and continue to be reliable" — an acknowledgment that a bank buying a model off the shelf cannot inspect its internal construction the way it could a model built in-house, and so must lean more heavily on outcomes analysis to catch problems conceptual-soundness review cannot reach. Where a bank customizes a vendor model for its own use, the guidance says "sound practice involves appropriately documenting, justifying, and evaluating adjustments made to customize the model," treating each customization as a change that itself needs validation.
Where does this validation approach fail?
The guidance itself is not enforceable, which limits what it can be credited with achieving. Because the agencies state outright that non-compliance "will not result in supervisory criticism," the bulletin cannot be read as a floor that guarantees any particular bank's validation program meets a fixed bar — it describes sound practice without mandating it, and two banks can diverge widely in rigor while both remaining technically consistent with the guidance.
The framework also does not yet reach the models banks are now fastest to adopt. Generative and agentic AI systems are explicitly out of scope because, in the bulletin's own words, they "are novel and rapidly evolving," with a request for information promised but not yet issued as of this guidance's publication. Until that RFI produces its own standard, a bank deploying a large language model in an underwriting or fraud workflow is validating that system against no interagency benchmark specific to how such models fail — only against the general model-risk principles written for more conventional statistical and econometric tools.
Outcomes analysis and backtesting, the guidance's own preferred evidence of performance, carry a structural limit the bulletin does not resolve: they can only be run against a period that has already happened. A validation report built on outcomes analysis says how a model performed on its own historical or recent window — it does not, and cannot, establish how the same model will perform once market conditions move outside that window. The guidance's emphasis on ongoing monitoring is a partial answer to that gap, not a solution to it; monitoring detects drift after it has already begun to degrade performance, not before.
Finally, the $30 billion applicability threshold means the guidance's own text treats validation rigor as calibrated to bank size rather than to a model's actual materiality. A smaller institution running a high-stakes model — a concentrated lending book scored by a single algorithm, for instance — sits outside the guidance's primary intended audience even though the underlying risk the framework describes does not scale down with asset size.
For more context, read What does out-of-sample mean in a forecasting paper?.

