For 15 years, SR 11-7 was the bible of model risk management in US banking. In April 2026 it officially became obsolete — replaced by guidance written with generative AI and agents in mind, not the statistical models of 2011.
SR 11-7, introduced by the Federal Reserve and the Office of the Comptroller of the Currency (OCC) in 2011, gave banks guidance on model risk management — ensuring the quantitative methods used to make decisions were accurate and properly applied, to prevent financial losses and operational problems. It required a formal model inventory, clear documentation, defined roles and responsibilities, and board- or senior-management-level oversight.
In April 2026, the OCC, the Federal Reserve, and the FDIC jointly issued updated interagency model risk management guidance, formally rescinding OCC Bulletin 2011-12 and SR 11-7 for banks covered by the new document. SR 11-7 was formally replaced by SR 26-02, with updated expectations reflecting the current, rapidly evolving, AI-driven risk landscape.
Model validation under the original framework included evaluating conceptual soundness, ongoing monitoring of model performance, and outcomes analysis — principles SR 26-02 keeps as its foundation, extending them to the specific challenges of generative AI models (which don't have a fixed, deterministic output) and autonomous agents (which execute actions, not just generate predictions).
The original SR 11-7 framework assumed statistical models with relatively predictable, auditable outputs. An AI agent that dynamically decides which tools to use and which actions to execute doesn't fit cleanly into that mold — hence the need for new guidance that explicitly addresses how to validate and monitor systems whose behavior isn't fully deterministic.
Any financial institution that already had a mature model risk management program under SR 11-7 has a solid foundation for the transition — the governance, documentation, and oversight principles carry over. But model risk teams need to specifically review how their model inventory and validation processes cover (or don't) the generative and agentic AI systems that are likely already in production, before a regulatory examiner asks first.
Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.
Contact Carlos Montiel