Skip to content

FinTech and the office of the CFO

Subscribe

Model risk management for AI in finance, practically

Learn how finance teams can manage AI model risk in practice through governance, validation, monitoring, documentation and human oversight.

Model risk management for AI in finance, practically

The guidance most firms cite was rescinded in April 2026. What replaced it is narrower, looser, and explicitly excludes generative and agentic AI.

Comparison of the 2011 model risk management guidance with the guidance that superseded it on 17 April 2026. The left column is what many firms still describe as their framework.

If your model risk policy opens by citing SR 11-7, it is citing a document that no longer exists as guidance. On 17 April 2026 the Federal Reserve issued SR 26-2, revised guidance on model risk management, which expressly supersedes and replaces SR letter 11-7 and SR 21-8. The OCC did the same thing the same day through Bulletin 2026-13, rescinding OCC Bulletin 2011-12, Bulletin 2021-19, Bulletin 1997-24 on credit scoring models, and the Model Risk Management booklet of the Comptroller's Handbook. The guidance was issued jointly by the Board, the OCC and the FDIC.

This is not a cosmetic refresh. Four things changed in ways that alter what a validation function is required to do.

1. The definition of a model narrowed

SR 11-7 defined a model as a quantitative method, system or approach applying statistical, economic, financial or mathematical theories to process input data into quantitative estimates. SR 26-2 defines it as a complex quantitative method, system or approach applying statistical, economic or financial theories, and then excludes simple arithmetic calculations such as those found within spreadsheets, along with deterministic rule-based processes and software with no statistical, economic or financial theory underpinning them.

For most institutions the practical effect is that a large part of the model inventory is, on the new definition, not a model. That is a reduction in scope, and it should be a deliberate reclassification exercise with a documented rationale rather than a quiet shrinkage of the register.

2. Generative and agentic AI are outside the scope, on purpose

Footnote 3 of the new guidance is the single most consequential sentence in it. Generative AI and agentic AI models are novel and rapidly evolving and, as such, they are not within the scope of this guidance. The principles apply to traditional statistical and quantitative models and to non-generative, non-agentic AI models.

The Federal Reserve's Vice Chair for Supervision, Michelle Bowman, described the reasoning in remarks published on 1 May 2026: the agencies amended the guidance to clarify that it does not apply to generative or agentic AI, having concluded that supervisors had expanded the scope of the previous guidance beyond its original purpose and applied it in unintended ways.

The agencies say they plan to issue a request for information covering model risk management generally and banks' use of AI, including generative and agentic AI. As at 30 July 2026 no such request has been published, so there is no docket to comment into.

A gap in supervisory guidance is not a gap in risk. If your generative AI use case fails, the loss, the customer harm and the reputational cost are unchanged by the fact that the framework no longer names it.

3. Annual validation is gone

SR 11-7 called for periodic review at least annually and more frequently if warranted. SR 26-2 says the timing, nature and frequency of validation activities vary based on model purpose, methodology, frequency and scope of model changes, data limitations and other practical constraints. Validation generally occurs before first use, but an urgent business need can justify use before validation completes, with added controls.

That is more defensible risk management and more work to evidence. A calendar is easy to audit. A risk-based frequency has to be argued, model by model, in writing.

4. Independence was reframed

The new text states that the quality of the validation process depends on the rigour and effectiveness of the review rather than on the organisational structure of the risk management function. Firms that have justified a validation team's reporting line by reference to the old guidance no longer have that argument, in either direction.

What was retained: conceptual soundness, outcomes analysis and ongoing monitoring, with monitoring defined as evaluating the extent to which a model performs as expected given potential changes in products, exposures, activities, clients, data relevance or market conditions. The model inventory survives as described industry practice rather than as a requirement.

Vendor models, which is where most AI actually enters

Section VII of the new guidance is the part most institutions will use most. It accepts that vendors may not provide the underlying code, data or methodology, and states that the principles of model risk management remain applicable regardless. Sound practice is validation of vendor products by internal or outside parties, understanding conceptual soundness, design, development data and performance, ongoing monitoring and outcome analysis, and, where the product is customised, appropriately documenting, justifying and evaluating those adjustments as part of validation.

This matters because third-party is the dominant delivery route. The Bank of England and FCA survey of AI in UK financial services, published in November 2024 across 118 firms, found 75 per cent of firms already using AI with a further 10 per cent planning within three years, and a third of use cases implemented by third parties, up from 17 per cent in 2022. The same survey found 46 per cent of firms reported only partial understanding of the AI they use, against 34 per cent reporting complete understanding.

The rest of the world went the other way

The United States loosened. Three other jurisdictions did not.

United Kingdom. The Prudential Regulation Authority's SS1/23 on model risk management principles for banks has a current version published and effective 23 April 2026. Its sub-principles expressly cover identifying and managing risks from artificial intelligence and machine learning techniques, and allocate responsibility for the framework to a Senior Management Function holder. The FCA has said it does not plan to introduce extra regulations for AI and will rely on existing frameworks, which is a different position from the PRA's but not a contradictory one.

European Union. The AI Act's high-risk obligations for creditworthiness assessment and for life and health insurance pricing now apply from 2 December 2027, deferred by Regulation (EU) 2026/1744, which entered into force on 27 July 2026. The European Banking Authority's November 2025 factsheet concluded that no significant contradictions were found between the AI Act and EU banking and payments legislation and that it had not identified any immediate need for new or revised guidelines, noting that the DORA framework extensively covers the cybersecurity and business continuity requirements set out in the AI Act.

Singapore and India. The Monetary Authority of Singapore consulted on guidelines on artificial intelligence risk management from 13 November 2025 to 31 January 2026, proposing to cover generative AI and AI agents with a twelve-month transition, and was reviewing responses as of March 2026. The Reserve Bank of India issued draft guidance on regulatory principles for model risk management on 24 June 2026, with comments closed on 24 July 2026, stating that the guidance is applicable to all models used by regulated entities, including third-party models and models employing AI and machine learning.

What a practical framework looks like now

  • Reclassify the inventory against the narrower definition, and record why each exclusion was made. A shrinking register with no rationale is the finding.

  • Set validation frequency by model materiality and write the argument down. The calendar is no longer the answer.

  • Do not let the generative AI carve-out become an internal exemption. Run those use cases under a named framework of your own, even if no supervisor currently requires one.

  • Set quantitative monitoring limits. The PRA's roundtable found firms broadly did not, and that six-month monitoring intervals may be insufficient for dynamically recalibrating models.

  • Treat post-hoc explanation techniques with suspicion where features are correlated, which in financial data they usually are.

  • Have a pre-approved fallback or challenger model, and in extremis a kill switch. That was the PRA's phrase, and it is a design requirement, not a slogan.

  • For any model that touches EU creditworthiness or life and health insurance pricing, use the deferral to 2 December 2027 as build time rather than as relief.

The through-line is that supervisory scope has narrowed while the actual use of these systems has widened. Firms that treat the guidance as the ceiling will have a thinner framework in 2027 than they had in 2025, against a materially larger deployment. That is a choice, and it should be made deliberately rather than by default.

This is reporting on regulation as it stood at the date of publication. It is not legal or compliance advice, and obligations differ by jurisdiction and change. Take qualified advice on your own circumstances.

References

Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.

  1. Board of Governors of the Federal Reserve System, SR 26-2, Revised Guidance on Model Risk Management, 17 April 2026. https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm

  2. Board of Governors of the Federal Reserve System, SR 26-2 guidance attachment, 17 April 2026. https://www.federalreserve.gov/supervisionreg/srletters/SR2602a1.pdf

  3. Office of the Comptroller of the Currency, News release 2026-29 and Bulletin 2026-13, rescinding prior model risk guidance, 17 April 2026. https://www.occ.gov/news-issuances/news-releases/2026/nr-occ-2026-29.html

  4. Board of Governors of the Federal Reserve System, SR 11-7, Guidance on Model Risk Management, 4 April 2011, superseded. https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm

  5. Michelle W. Bowman, Federal Reserve, Remarks at the FSOC AI Series Roundtable, published 1 May 2026. https://www.federalreserve.gov/newsevents/speech/bowman20260501a.htm

  6. Prudential Regulation Authority, SS1/23, Model risk management principles for banks, current version, 23 April 2026. https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss

  7. Prudential Regulation Authority, PRA holds model risk management roundtable on AI, published 24 November 2025. https://www.bankofengland.co.uk/prudential-regulation/publication/2025/november/pra-holds-model-risk-management-roundtable-on-ai

  8. Bank of England and Financial Conduct Authority, Artificial intelligence in UK financial services 2024, survey of 118 firms, 21 November 2024. https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024

  9. European Banking Authority, AI Act: implications for the EU banking and payments sector, factsheet, 21 November 2025. https://www.eba.europa.eu/sites/default/files/2025-11/d8b999ce-a1d9-4964-9606-971bbc2aaf89/AI%20Act%20implications%20for%20the%20EU%20banking%20sector.pdf

  10. Monetary Authority of Singapore, Consultation Paper P017-2025, Guidelines on Artificial Intelligence Risk Management, 13 November 2025. https://www.mas.gov.sg/publications/consultations/2025/consultation-paper-on-guidelines-on-artificial-intelligence-risk-management

  11. Reserve Bank of India, Draft Guidance on Regulatory Principles for Model Risk Management, 24 June 2026. https://www.rbi.org.in/scripts/BS_PressReleaseDisplay.aspx?prid=63006

  12. European Union, Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force 27 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng

How we work. This article was researched and written by the Financy editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, which is named and linked above. Where an instrument is proposed rather than in force, we say so. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@financyhub.com and tell us what and why.

Filed under AI in Finance · Get The Weekly Brief

The briefing

Keep reading the stack.

One email a week on financial technology and the finance stack.