How Revised U.S. Bank Model Risk Guidance Changes Quantitative Oversight
Summary
The document compares the 2026 U.S. supervisory guidance SR 26-2 with its predecessor, SR 11-7, emphasizing implications for quantitative models at banking organizations. It describes a shift from detailed, prescriptive recommendations toward shorter, more flexible principles, and reports that the revised guidance is framed as nonbinding absent legal violations or unsafe practices. It also highlights an expected focus on organizations above a stated asset threshold, a narrower definition of models, and a new distinction for generative and agentic AI tools.
The comparison says the revision formalizes materiality, supports tailoring model controls to risk, and reduces detailed expectations for inventories, documentation, governance, validation frequency, and vendor contingency planning. It describes retained attention to monitoring and assessment of vendor customizations, alongside the removal of several former best-practice topics such as sensitivity analysis and testing beyond ordinary scenarios. These are claims presented by the document, not independently verified here; the source is an individual commentary and the excerpt contains omissions. Readers should consult the official guidance for authoritative interpretation, especially because applicability and supervisory expectations depend on institutional circumstances.
Key ideas
- The document characterizes SR 26-2 as more principles-based and less prescriptive than SR 11-7.
- It reports an asset threshold and a materiality approach that may affect the depth of model controls.
- The revised definition is described as excluding simple calculations and deterministic software without underpinning theories.
- The comparison notes reduced detail on documentation, validation, governance, and vendor contingency planning.
- The commentary is not an official interpretation, so the guidance itself is needed to confirm requirements and applicability.
Tags
Full text
# Answer by Dimitri Vulis (score 0)
# How does the U.S. SR 26-2 Revised Guidance on Model Risk Management differ from the prior SR 11-7 Guidance on Model Risk Management?
The agencies published the new Supervisory and Regulatory Letter SR 26-2: "Revised Guidance on Model Risk Management" on April 17, 2026. The new SR letter replaces and rescinds the prior SR 11-7. How does the new guidance differ from the prior guidance, particularly from the quantitative finance perspective?
## Answer by Dimitri Vulis (score 0)
https://quant.stackexchange.com/a/85598
(I tried to use several AI tools to help me draft this comparison, but they were of little help.)
History
In the 1990, the US stopped testing its nuclear weapons. Instead of physical tests, the Department of Energy and other federal agencies developed sophisticated computer models that simulated nuclear explosions. Since these models could not be physically tested, the federal agencies greatly enhanced the model risk management practices developed during the earlier space flight programs, with the focus of verification, validation, and ongoing performance monitoring of models.
Following the Great Financial Crisis of 2008, FRB's David Palmer picked selected model risk management practices previously developed for nuclear weapons test simulations, skipping such important elements as model verification (determining that a model implementation accurately represents the developer’s conceptual description of the model and its solution), or the distinction between aleatory and epistemic uncertainty, which were eventually published as the Supervisory and Regulatory Letter SR 11-7 on April 4, 2011.
Because the FRB staff who "distilled" SR 11-7 from the DoE model risk management practices were no quant subject matter experts (SME), some elements of the SR letter made little sense and were subjected to widespread industry criticism and outright ridicule, e.g. The Most Damaging “Guidance” in Banking by Greg Baer and Greg Hopper at the Bank Policy Institute.
15 years later, on April 17, 2026, the agencies published the new SR 2602: Revised Guidance on Model Risk Management, replacing and rescinding their prior guidance.
Links
The new SR 26-2:
Cover: FRB version / OCC version / FDIC version
Appendix: FRB version / OCC version / FDIC version
The old SR 11-7
OCC's Comptroller's Handbook Booklet: Model Risk Management has been removed.
Format Changes
SR 11-7 was prescriptive, comprehensive, and rule-based, 21 pages of single-space text. SR 26-2 is principles-based, streamlined, and flexible, down to 12 pages of double-spaced text, eliminating the Table of Contents and the Conclusion section. Vendor models have been moved to their own new section. Some section names have changed slightly.
Prescriptive language ("banks should") is replaced with permissive, descriptive language, such as:
- "Sound practice involves..."
- "Banking organizations may..."
- "An effective... generally..."
- "Sound governance practices delineate..."
SR 26-2 used the term "banks" throughout, with a footnote defining this term to include national banks and bank holding companies. SR 26-2 uses the term "banking organizations" throughout, which is more inclusive of state non-member banks, savings associations, and other financial institutions.
Introduction
SR 11-7 described how "banks rely heavily on quantitative analysis and models" across a broad range of activities and framed model use in terms of costs and benefits, noting the "direct cost of devoting resources to develop and implement models properly" and "indirect costs of relying on models."
SR 26-2:
- reframes the opening: model use "continues to grow in complexity and scope" and is "essential to maintaining the competitiveness of banking organizations."
- sets more positive tone: models help "improve efficiencies, better mitigate risks, and help maximize profits."
- acknowledges that "model risk management practices vary from banking organization to banking organization", introducing institutional flexibility from the start.
- makes explicitly non-enforceable suggestions, unless they actually violate laws or threaten the institution's safety and soundness: "this guidance does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism... However, supervisory action may result for any violations of law or unsafe or unsound practices stemming from insufficient management of model risk."
The unenforceability is consistent with FRB's Statement of Supervisory Operating Principles and the testimony by Vice Chair for Supervision Michelle W. Bowman, which likewise say that only practices that demonstrably threaten the institution's safety and soundness can lead to MRAs, while other non-compliant practices will lead to supervisory observations.
Applicability - Asset Threshold
SR 11-7 applied broadly to all banking organizations, with a brief caveat that community banks using fewer models might have less involved practices - in particular, did not need model validation.
SR 26-2 is "expected to be most relevant to banking organizations with over \$30 billion in total assets". Under the strict tailoring approach, the guidance only applies to institutions under the threshold if they have significant model risk exposure due to complex operations or activities outside traditional community banking.
The \$30B threshold is unusual - most tiering uses \$10B, \$50B, \$100B, or \$250B - suggesting that it was specifically calibrated to capture larger regional banks while exempting most community and mid-sized regional banks.
In practice, many non-bank institutions that were not required to follow SR 11-7, nevertheless followed many of the model risk management best practices.
Model Definition
SR 11-7 defined a model as "a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates."
SR 26-2 defines a model as "a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates." "Complex" was added, "mathematical" was dropped, as well as "techniques and assumptions".
In practice, many institutions broadly followed SR 11-7's definition of model. Some institutions explicitly included "hypotheses" with "theories"; some required the theories to be "testable"; some noted that the estimates or forecasts produced by models are inherently uncertain and discussed aleatory versus epistemic uncertainty.
SR 11-7 footnote 3 said: "While outside the scope of this guidance, more qualitative approaches used by banking organizations - i.e., those not defined as models according to this guidance - should also be subject to a rigorous control process." This is gone from SR 26-2.
In practice, some institutions' model governance frameworks also cover non-model or qualitative estimation approaches, which are similar to models in that their output is also uncertain, but are largely or entirely based on qualitative assumptions, such as expert judgment or other qualitative evidence, rather than on theories. Model controls such as independent validation, ongoing performance monitoring, and compensatory actions to mitigate weaknesses can be useful in managing the risk of such non-model estimation approaches. Some institutions choose to call these "qualitative models" and to use the term "model" for all estimates whose output is uncertain; while others choose to use the term "estimation approaches" for models and "qualitative estimates".
SR 15-18 and SR 15-19, which have not been rescinded or updated, both say, identically: "A firm should maintain an inventory of all estimation approaches... including models... The definition of a model covers quantitative approaches whose inputs are partially or wholly qualitative or based on expert judgment, provided that the output is quantitative in nature."
SR 26-2 further states that "The term “model” in this guidance excludes simple arithmetic calculations, such as those found within spreadsheets, as well as deterministic rule-based processes and software where there are no statistical, economic, or financial theories underpinning their design or use."
In practice, some institutions' model validators also perform the verification of models as well as of selected complex tools whose output is not uncertain. The model inventory contains all model, qualitative estimates, and other tools subjected to model risk controls.
SR 26-2 footnote 3 says: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization’s risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document. However, the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models."
Some entirely separate regulatory guidance may be coming for generative and agentic AI.
Model Risk
SR 26-2 renames Section III from "Overview of Model Risk and Model Risk Management" to "Overview of Model Risk and Model Risk Management"
SR 11-7 discussed model risk primarily based on complexity, uncertainty of inputs, and potential impact; discussed two primary sources of model risk:
- Fundamental errors / inaccurate outputs
- Incorrect or inappropriate use
SR 26-2 formalizes "Model Materiality" determined by only two factors:
Models deemed immaterial may only require "identifying those models and monitoring model performance."
We note that neither SR 11-7 nor SR 26-2 require that all models be treated the same or that all model reviews be the same. In practice, most institutions classify their models into 3 or 4 tiers of risk. There are at least 2 levels of model review: a full-blown re-validation and a perfunctory review to confirm that the conceptual soundness has not changed and the ongoing performance monitoring does not show unacceptable deterioration. The models in the riskier tiers might undergo the full-blown re-validation every 2 or 3 years and the perfunctory review annually. The models in the less risky tiers might undergo only the perfunctory review annually. SR 26-2 drops the requirement for the annual perfunctory review, although still requires ongoing performance monitoring as part of continuous monitoring.
We note that although the banks no longer need to review every model annually, some annual full-blown re-validations are still required for some financial institutions and models.
The Commodity Futures Trading Commission (CFTC) heavily regulates the models used by Swap Dealers (SDs), Major Swap Participants (MSPs), and Derivatives Clearing Organizations (DCOs).
CFTC Regulation § 23.154(b)(5)(i) states that each swap dealer and major swap participant shall have its initial margin model (such as the ISDA Standard Initial Margin Model, or SIMM) to calculate initial margin for uncleared swaps "reviewed and validated on a periodic basis, but no less frequently than annually, by a qualified and independent party."
CFTC Regulation § 39.13(g)(3) and the National Futures Association (NFA) practically require Derivatives Clearing Organizations (DCOs) to re-validate their margin systems and models annually.
The Securities and Exchange Commission (SEC) requires annual model validations primarily for entities acting as "Covered Clearing Agencies" (CCAs) and certain Broker-Dealers or Security-Based Swap Dealers (SBSDs) using internal capital models.
SEC Rule 17Ad-22(e)(6)(vii) requires CCAs to perform "a model validation for its margin system and related models not less than annually or more frequently as may be contemplated by the covered clearing agency’s risk management framework."
SEC Rule 17Ad-22(e)(4)(vii) similarly requires a model validation for credit risk models not less than annually.
SEC Rule 15c3-1e(d) practically requires Broker-Dealers computing Alternative Net Capital (ANC) to re-validate their VaR models annually.
SR 26-2:
- removes the discussion of "only two" sources of model risk and the discussion of model quality metrics. Rather, model risk is now based on its inherent risk, exposure, purpose, and use.
- removes the discussion of "informed conservatism".
- streamlines the description of "effective challenge", removing the detailed breakdown of incentives/compensation practices.
- retains aggregate risk discussion in abbreviated form.
Still No Mention of Model Risk Taxonomy
The ORX Reference Risk Taxonomy and the similar ECB/EBA Risk Taxonomy place model risk under non-financial risk, with 3 risk sub-stripes:
- Model/methodology design error
- Model implementation error
- Model application error
The SR Letter still does not discuss any model risk taxonomy.
Model Development and Model Use
SR 26-2 renames Section IV from "Model Development, Implementation, and Use" to just "Model Development and Model Use". "Implementation" is deleted, as is the long IT systems discussion.
In SR 26-2, the "Model Development" subsection is much shorter:
- Emphasizes user input as a positive enhancement; removes the skeptical discussion of user bias.
- Testing is described more briefly: "out-of-sample and out-of-time testing, comparison of alternative assumptions, critical assessment of data quality."
- Testing rigor is explicitly scaled to model complexity and materiality.
- Removes the detailed guidance on data proxies, external data considerations, system integration, and statistical testing methodology.
The "Model Use" subsection is also shorter:
- Removes the skeptical discussion of user challenge weaknesses and biases.
- Removes the discussion of reports, model uncertainty, and conservatism.
- Adds new language about using models "beyond their intended purpose" and what sound practice looks like when extending model use.
- The user feedback discussion is framed positively rather than cautiously.
Model Validation (and Monitoring)
SR 26-2 renames Section V from "Model Validation" to "Model Validation (and Monitoring)", emphasizing the elevation of model performance monitoring into a co-equal validation component.
SR 11-7 contained highly prescriptive and exhaustive sections on the mechanics of model validation, detailing specific statistical tests, value-at-risk (VaR) back-testing, and strict organizational separation for independence.
SR 26-2 compresses and streamlines these requirements into a principles-based framework:
- Organizational Flexibility: explicitly states that the quality of validation depends on the "rigor and effectiveness of the review rather than on organizational structure". This gives institutions more freedom in how they structure their risk management functions.
SR 11-7 said: "Generally, validation should be done by people who are not responsible for development or use and do not have a stake.." Institutions sought to make their model validation and model governance staff independent from the model developer owners, which included not only first line models, but also models developed and owned by the second line, such as various VaR-like models, and challenger models build specifically to benchmark first line's models. The relaxation of the independence requirement may mean, for example, that without the loss of stature, model risk management could report to the chief risk officer not directly, but via non-financial risk management.
The best practices to ensure that second line risk management staff are not improperly incentivized are not unique to model risk management and include limiting or eliminating:
- the benefit to the risk management staff from the profits of first line's risk taking activities. Rather, they should be rewarded for their risk management.
- the impact on risk management staff's performance reviews, bonuses, and promotions from the feedback, positive or negative, from the first line or any other group affected by their risk management.
SR 26-2:
- removes the explicit "at least annually" review frequency requirement.
- removes the explicit requirement that significant deficiencies prevent model use.
- allows model use before validation is complete - if business needs necessitates it and governance and compensating controls are present.
It is risky to simply forbid outright the use of unvalidated models, and then to have no governance in place for when such use happens anyway. Sometimes the risks of having no model at all exceed the risks of using a deficient one with sufficient controls.
The following discussions are shorter:
- Conceptual Soundness - acknowledges that for some models, "interpretability measures or benchmarking" may be more practical than evaluating theoretical construction, providing new flexibility for ML/AI models.
- Outcomes Analysis- removes the detailed back-testing methodology, VaR example, parallel testing discussion, early warning metrics.
- Ongoing Model Performance Monitoring introduces new concept of "overlays" as a response option; removes process verification, code change control, override analysis, benchmarking discussions. The addition of "data relevance" as a monitoring consideration acknowledges data drift risks.
However the discussion of Ongoing Performance Monitoring still does not mention profit and loss attribution analysis as a recommended element of monitoring for pricing and market risk models.
Vendor products are moved to a standalone Section VII.
Governance and Controls
SR 26-2 renames Section VI from "Governance, Policies, and Controls" to "Governance and Controls".
SR 26-2 only keeps 3 sub-sections, much shorter than SR 11-7:
- Roles and Responsibilities notes that internal audit's role is "generally" to evaluate (not mandatory); notes that external resources require proper oversight; removes the detailed discussion of model owners, risk-control staff, compliance obligations, board duties, and senior management duties.
- Model Inventory is condensed to two paragraphs; removes the specific itemized list of what the inventory must contain.
- Documentation is condensed to two sentences essentially; removes the detailed guidance on validation reports, executive summaries, and incentives to document.
SR 26-2 removes separate sub-sections on Board/Senior Management, Policies and Procedures, Compliance, Internal Audit, and External Resources.
The following significant topics from SR 11-7 are absent from SR 26-2, but institutions may still consider some as "best practices":
- Comparison with alternative theories and approaches.
- Testing across "scenarios outside the range of ordinary expectations"
- Evaluation of boundaries of model effectiveness
- Impact assessment on downstream models that consume outputs
- Treatment of proxy data
- Model uncertainty quantification: Point estimates vs. ranges, confidence intervals, qualitative assessments of uncertainty.
- Sensitivity analysis requirements: Detailed requirements for checking impact of small input changes, varying multiple inputs simultaneously, stress testing model performance.
- Code review and change control: Requirements for computer code quality assurance, change logging, and auditability.
- VaR back-testing example: Detailed discussion of VaR back-testing methodology.
- Parallel outcomes analysis: Testing original and adjusted models simultaneously against realized outcomes.
- Explicit board/senior management responsibilities: Detailed governance expectations.
- GAAP compliance footnote: SR 11-7 footnote about model uncertainty adjustments complying with GAAP.
New concepts introduced in SR 26-2 include:
- Interpretability measures: As an alternative to theoretical soundness evaluation.
- "Model lifecycle" language: Framing model risk management as spanning the entire lifecycle.
- "Fit for purpose" language: In vendor model assessment.
Vendor and Other Third-Party Products
SR 26-2 moves this discussion to a new separate section.
SR 11-7 focused heavily on obtaining developmental evidence from vendors and planning contingencies in case the vendor model failed or the vendor went out of business.
SR 26-2 acknowledges the "widespread use" of customized vendor models and proprietary constraints. It places a heavier emphasis on validating the customizations a institutions makes to a vendor model to fit its specific business needs, requiring those adjustments to be documented and justified.
SR 26-2 removes:
- the requirement to select vendor models using a formal process.
- the contingency planning requirement.
- the requirement to maintain in-house knowledge.
SR 26-2 focuses on validation of vendor products, ongoing monitoring, outcome analysis, and appropriate documentation of customizations; adds new language about validating customizations to vendor models.Shown in full with attribution under the source's licence. Licence: CC BY-SA 4.0 (Stack Exchange)
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.