New MRM Supervisory Guidance SR 26-2: 10 Subtle Shifts You Need to Know
- Naresh Raheja

- Jun 7
- 12 min read
Updated: Jun 9
Note- This article is the expansion of the original article authored by Naresh Raheja,
On April 17, 2026, U.S. banking regulators- including the Federal Reserve Board, the Federal Deposit Insurance Corporation, and the Office of the Comptroller of the Currency- jointly issued SR 26-2, also published under OCC Bulletin 2026-13.
This revised supervisory guidance formally supersedes and replaces SR 11-7, the foundational model risk management framework that has governed the financial sector since 2011.
The transition to SR 26-2 represents a major structural shift in federal supervision, replacing rigid, checklist-based compliance with a modernized, principles-based, and highly tailored risk management paradigm. (Disclaimer: This article presents my personal viewpoint and interpretations, and does not reflect the views of my former employer, the OCC. The “Examiner Lens” section does not constitute supervisory guidance from the agencies or SR 26-2).
Historical Context and Regulatory Origins
While not explicitly detailed in the text of SR 26-2, to fully comprehend the operational significance of SR 26-2, banking organizations must examine the regulatory environment that preceded its drafting.
Following the 2007–2008 financial crisis, federal regulators issued SR 11-7 to mitigate severe failures in underwriting, stress testing, and capital calculations stemming from incorrect or misused quantitative tools.
While SR 11-7 succeeded in elevating risk discipline, its highly directive, prescriptive, and detailed operating framework gradually introduced systemic inefficiencies. Over the next fifteen years, mature model risk management functions found themselves handling rapidly growing model inventories under flat budgets.
The legacy guidance was frequently applied as a de facto binding rule, where minor procedural deviations triggered formal supervisory criticism, such as Matters Requiring Attention.
This rigid enforcement culture was reinforced in October 2019, when the Government Accountability Office issued legal opinion B-331324.
This ruling determined that SR 11-7 met the Administrative Procedure Act definition of a rule under the Congressional Review Act, meaning it should have been formally submitted to Congress before taking effect. This legal friction intensified the banking industry's demand for a clearer, non-binding, and more flexible supervisory approach.
In parallel, federal regulators recognized that smaller community financial institutions were being crushed under the weight of compliance expectations intended for global systemically important banks.
On October 6, 2025, the OCC issued Bulletin 2025-26, which underscored flexibility in model risk management and formally clarified that community banks were not required to perform annual model validations. This late-2025 clarification served as a testing ground for the broader, asset-based applicability thresholds ultimately codified in SR 26-2.
Upon releasing SR 26-2 in April 2026, the FDIC concurrently rescinded legacy guidance documents, including FIL-22-2017 and FIL-27-2021, which had previously governed BSA/AML systems, thereby consolidating model risk oversight into a single unified framework.
Comparative Analysis of Framework Architectures
The architectural transition from the legacy SR 11-7 guidance to the modernized SR 26-2 framework is structured around six core pillars of oversight.
The table below provides a side-by-side technical comparison of these frameworks and outlines their operational impacts on financial institutions.

Deep Dive into the Ten Subtle Shifts
A thorough examination of SR 26-2 reveals ten subtle shifts that will govern future regulatory scoping and supervisory examinations.
The following sections provide a detailed analysis of each shift, incorporating its theoretical drivers, practical execution, and corresponding examiner perspectives.
1. Enforceable Standards, Principles-Based Governance, and the Unsafe and Unsound Backstop
The transition from the rigid mandates of SR 11-7 to the flexible, principles-based framework of SR 26-2 represents a major shift for the financial industry.
Under the old paradigm, banking organizations managed model risk to satisfy checklist-oriented examinations, prioritizing rule adherence over risk optimization.
By stating that the new guidance "does not set forth enforceable standards or prescriptive requirements," the regulatory agencies have officially decoupled MRM from narrow technical compliance, elevating the role of institutional self-determination and professional judgment.
However, this newfound flexibility contains a critical, quiet regulatory backstop.
The guidance includes a powerful reservation of authority: supervisory action may still result for violations of law or unsafe and unsound practices stemming from insufficient management of model risk.
This means that while the prescriptive path of the guidance is optional, maintaining an effective risk management environment remains a non-negotiable statutory requirement for safety and soundness.
The Examiner Lens
Supervisory teams and examiners will no longer issue criticisms solely because an institution has deviated from a standard, calendar-based validation schedule.
However, if an institution's chosen, flexible validation process fails to detect a major conceptual flaw in a credit risk model- resulting in severe capital inadequacy- examiners will act swiftly.
Similarly, if an unmonitored BSA/AML transaction monitoring system misses systemic financial crimes, the resulting compliance failures will trigger severe enforcement actions.
Examiners will leverage the safety and soundness footnote to cite the broken risk management process as an unsafe and unsound practice.
2. The Formal Elevation of Model Materiality and Tiered Oversight
Under the legacy framework, model materiality was treated as a general consideration, often leading banks to apply identical testing rigor to models with vastly different risk profiles.
SR 26-2 heavily elevates materiality to the core operational driver of the entire MRM program.
The guidance formally defines materiality through a dual-lens construct of "model exposure" (the financial scale, portfolio size, or business significance of the decisions the model drives) and "model purpose" (such as whether the model supports regulatory compliance or capital adequacy calculations).
While SR 26-2 does not prescribe a mathematical formula, an institution might conceptualize this mathematically by letting model materiality M be computed as a function of the model exposure score E and the model purpose weight
P: M = E * P
This mathematical representation enables quantitative scoring that tiers models into low, medium, and high risk.
High-materiality models will continue to warrant rigorous, independent validation and continuous testing.
Crucially, for models deemed immaterial, institutions are permitted to simplify their governance, shifting oversight to monitoring only model performance and the conditions under which they might become material later.
The Examiner Lens
Examiners will evaluate whether risk management teams are actively utilizing this materiality framework to scale their oversight resources both upward and downward.
If an institution continues to dedicate expensive quantitative validator resources to performing full validations on immaterial, low-risk tools, examiners may view this as an inefficient use of risk resources.
Conversely, the institution must demonstrate that it has implemented a robust, ongoing monitoring framework capable of detecting when an immaterial model’s exposure has grown to the point where it must transition into a higher-materiality tier.
3. Generative and Agentic AI Scope Exclusion and the Upcoming RFI
Because SR 11-7 was published in 2011, it entirely predated modern generative artificial intelligence paradigms.
SR 26-2 addresses this regulatory lag by explicitly excluding generative AI and agentic AI models from its formal scope, characterizing these advanced systems as "novel and rapidly evolving".
Traditional statistical models, machine learning algorithms, and non-generative, non-agentic AI remain firmly within the scope of the guidance.
While not explicitly mentioned within SR 26-2, the agencies have separately noted they plan to issue a Request for Information in the near future, focusing on banks' use of AI, including generative AI, agentic AI, and AI-based models.
In the interim, the guidance emphasizes that an institution's broader "risk management and governance practices" should continue to guide controls for these excluded, highly complex tools.
The Examiner Lens
During standard MRM validation reviews, examiners will generally not focus on generative and agentic AI systems, given their explicit exclusion from the text of SR 26-2. However, they will closely scrutinize them under broader, non-MRM safety and soundness and compliance frameworks.
For example, if an unmonitored customer service bot hallucinates and commits a fair lending violation, or if an agentic AI tool autonomously processes fraudulent transactions, examiners will issue critical findings.
These actions will be pursued under broader operational risk, consumer compliance, and cybersecurity standards, regardless of the tools' exclusion from formal MRM validation scope.
4. The Complexity Threshold in Redefining a Model
The definition of a model under SR 11-7 was famously broad, pulling simple spreadsheets, deterministic rule engines, and basic workflow calculators into the costly orbit of formal MRM validation.
This caused significant inventory bloat and distracted risk teams from managing high-risk systems.
SR 26-2 narrows this definition by adding a vital qualifier, officially defining a model as a "complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates".
By explicitly excluding simple arithmetic calculations- such as basic formulas found within spreadsheets- as well as deterministic, rule-based software where no statistical or financial theories underpin the design, the guidance establishes a clear complexity threshold.
The Examiner Lens
Supervisory teams will expect institutions to leverage this narrowed definition to clean up their model inventories and de-scope simple, low-risk calculators.
Examiners will view a bank's failure to purge these simple tools from its inventory as a lack of understanding of the complexity threshold.
However, examiners will also verify that alternative, lighter-touch receiving controls (such as standard industry End-User Computing or operational risk programs) are actively managing the operational risks of the de-scoped spreadsheets…so they do not run unmitigated.
5. The Conditional Sub-$30B Asset Applicability
While SR 11-7 applied broadly to all banking organizations regardless of size, SR 26-2 clarifies that it is expected to be most relevant to banking organizations with over $30 billion in total assets.
This change formally codifies the trend toward supervisory tailoring, providing significant regulatory relief to community and smaller regional banks.
However, this threshold is not an absolute exemption.
The guidance notes that its principles may still be relevant to institutions with total assets of $30 billion or less if they have significant exposure to model risk.
This occurs when a smaller institution utilizes complex models or engages in non-traditional banking activities, such as automated trading or fintech-partnered underwriting.
The Examiner Lens
If a $25 billion regional bank utilizes highly complex, proprietary AI-driven credit underwriting algorithms to support an extensive consumer lending program, examiners will expect its model risk management practices to align with the advanced principles of SR 26-2.
Smaller banks cannot treat the $30 billion asset threshold as an absolute shield if their underlying operational complexity introduces material model risk.
6. The Structural Independence Illusion vs. Effective Challenge
The legacy SR 11-7 guidance placed heavy emphasis on structural independence, typically demonstrated by a strict separation of reporting lines up to the executive level.
While intended to prevent conflicts of interest, this often created organizational friction and delayed model deployments.
SR 26-2 decouples validation quality from rigid organizational design, noting that the effectiveness of the review depends on the "rigor and effectiveness of the review rather than on organizational structure".
Under the revised guidance, having model development and validation functions within the same team or reporting to the same executive is acceptable, provided that the review remains truly objective and rigorous.
The primary requirement is that the validators maintain independence, possess the necessary technical competence, and retain the organizational authority to deliver an "effective challenge".
The Examiner Lens
Examiners will focus heavily on the substance of the review rather than its structural form.
If a shared reporting structure creates a conflict of interest or a misalignment of incentives- such as a validator feeling pressured to rubber-stamp a colleague's model to meet a commercial deadline, or lacking the authority to challenge the developer's underlying assumptions- the rigor and effectiveness of the review is compromised.
In such cases where the shared structure dilutes the "effective challenge," examiners will view the validation as ineffective, regardless of the organizational flexibility permitted by the text.
7. Elevated Expectations for Customizing Third-Party and Vendor Models
The use of third-party vendor models for critical processes like stress testing, credit scoring, and fraud detection has grown substantially.
SR 11-7 required banks to document and justify vendor model selections but allowed considerable latitude for proprietary modifications.
SR 26-2 significantly elevates supervisory expectations in this area.
The guidance explicitly mandates that when vendor models are customized to fit specific institutional portfolios or business needs, banks must appropriately document, justify, and evaluate adjustments made to customize the model as part of model validation.
Customizations can no longer bypass standard MRM controls, and institutions remain fully responsible for the performance and limitations of modified third-party outputs.
The Examiner Lens
Supervisory teams will closely scrutinize modified vendor models during validation reviews.
If an institution has adjusted the weights or parameters of a vendor-supplied credit underwriting model to fit its portfolio, examiners will demand comprehensive documentation demonstrating that the bank evaluated how those modifications affected the model's reliability.
The bank must provide quantitative evidence that the customized model remains conceptually sound and has been back-tested against the bank's actual performance data.
8. The Provisional Use and Urgent Business Need Exception
Under legacy governance, model deployment was frequently delayed because models were strictly barred from entering production until they had completed the full, independent validation process.
This rigid "gatekeeper" model often restricted a bank's ability to respond quickly to volatile market conditions or sudden operational challenges.
SR 26-2 addresses this by introducing a pragmatic carve-out.
The guidance recognizes that an "urgent business need" might necessitate using a model before validation is completed.
However, this exception is highly conditional and must be supported by appropriate controls.
The revised guidance permits provisional use prior to full validation under tight compensating controls, such as placing limits on use, informing relevant stakeholders of those limitations, and closer monitoring.
The Examiner Lens
This exception is not a free pass to bypass validation.
If an institution pushes an unvalidated credit scoring or anti-fraud model into production, citing urgency, examiners will demand a comprehensive, documented audit trail.
This trail must show the formal business justification, the specific transaction or exposure limits applied to the model's output, written evidence that executive stakeholders and risk committees were informed of the limitations, and a commitment to a rapid, prioritized validation schedule.
9. Preservation of Core Validation and Outcome Bedrocks
While SR 26-2 introduces operational flexibility and removes mandatory, calendar-driven review schedules, it does not dilute the core analytical standards of model validation.
Evaluating conceptual soundness, conducting ongoing monitoring, and performing outcomes analysis remain the foundation of comprehensive MRM validation.
Outcomes analysis remains a critical expectation, requiring banks to compare model outputs directly against actual, real-world results on an ongoing basis.
This includes regular back-testing and benchmarking to detect performance degradation.
The Examiner Lens
If a credit scoring model's underlying design is fundamentally flawed, or if real-world outcomes consistently deviate from predictions without triggering recalibration, examiners will cite the validation process as ineffective.
The freedom to customize validation schedules under SR 26-2 does not permit any reduction in analytical rigor.
10. Systemic Aggregate Risk and Enterprise Interdependency Management
Model risk is frequently managed in silos, with validation teams evaluating models in isolation.
Evaluating aggregate risk requires accounting for interactions and dependencies among models, and reliance on common assumptions, data, or methodologies, carrying this critical concept forward from the old SR 11-7 framework.
While the guidance leaves the methodology up to the institution, risk teams might choose to quantify this systemic operational risk by letting aggregate model risk Ragg across N models with individual model risk scores Ri and interaction coefficients pij be modeled as:

This captures the systemic compounding risk when multiple models share common data pipelines or macroeconomic assumptions.
If multiple highly material models share a common baseline assumption or data source, a single data error or economic shift could simultaneously compromise credit underwriting, pricing, and allowance for credit losses.
The Examiner Lens
Examiners will look beyond individual, siloed validations.
They will expect institutions to maintain a dynamic, enterprise-wide model inventory that maps interactions and identifies concentrated dependencies on specific third-party data providers or macroeconomic forecasts.
If a bank fails to evaluate these compounding relationships, examiners will cite this as a failure to manage aggregate model risk.
Technical Summary of Subtle Shifts
To help risk executives and board members navigate these changes, the table below maps each of the ten shifts to its primary regulatory driver and practical implementation method.

Strategic Recommendations for Financial Institutions
The modernization of model risk management introduces several operational opportunities that will distinguish market leaders from laggards.
Banking organizations should execute the following programmatic steps to successfully transition their frameworks.
Re-Architect the Materiality and Tiering Framework
Institutions should update their current model tiering methodologies.
The revised framework should formally define and incorporate the dual concepts of model exposure and model purpose.
Crucially, institutions should consider establishing a formalized "immaterial" classification.
This classification should be supported by automated, light-touch performance-monitoring controls that replace full validation requirements, thereby allowing the institution to redeploy expensive quantitative talent.
Rationalize the Enterprise Model Inventory
Risk management teams should conduct a systematic review of the active model inventory.
By applying the narrower definition of "complex quantitative methods" , institutions can de-scope rule-based systems, simple spreadsheets, and deterministic calculators.
However, to ensure no risk goes unmitigated, the institution should verify that these de-scoped tools have been successfully transitioned to alternative receiving controls (such as standard industry End-User Computing or operational risk programs).
Tailor and Automate the Validation Lifecycle
The flexibility allowed by SR 26-2 should be translated into a concrete, risk-based validation matrix.
This matrix should detail specific testing expectations, documentation standards, and review frequencies for each model tier.
Rather than relying on default calendar cycles, validation frequency should be tied to clear operational triggers, such as model performance drift, changes in input data quality, or material shifts in macroeconomic conditions.
Standardize Provisional Use Playbooks
To safely utilize the "urgent business need" exception, institutions should formalize their provisional approval processes.
Sound practice involves establishing clear policies that define what constitutes an urgent business need, setting strict usage and exposure limits, identifying relevant stakeholders who must be notified of model limitations, and defining an accelerated validation timeline to move the model out of provisional status.
Establish Parallel AI Governance Tracks
While generative and agentic AI models are excluded from formal SR 26-2 scoping, institutions must not ignore their risks.
Organizations should develop a parallel, dedicated AI governance program that runs alongside traditional MRM frameworks.
This parallel framework should focus on explainability, bias detection, data privacy, and prompt validation.
Establishing these controls now will ensure the institution is well-prepared for the regulatory requirements that will follow the agencies' upcoming Request for Information.
Analytical Conclusions
The transition from SR 11-7 to SR 26-2 represents a pivotal shift for Model Risk Management, moving the focus from rigid compliance to a risk-based, pragmatic, and value-added framework.
By formalizing materiality-driven tiering and narrowing the definition of a model, the revised guidance allows banking organizations to streamline legacy frameworks and reduce operational costs without sacrificing regulatory defensibility.
However, this increased flexibility is balanced by a heightened supervisory focus on safety and soundness, vendor model customization, and aggregate risk.
Ultimately, institutions that proactively realign their MRM programs with these new principles will not only satisfy supervisory expectations but also gain significant advantages in speed to market and operational efficiency.
(Disclaimer: This article presents my personal viewpoint and interpretations, and does not reflect the views of my former employer, the OCC. The “Examiner Lens” section does not constitute supervisory guidance from the agencies or SR 26-2).
About The Author
Naresh Raheja

is a risk management specialist focused on AI governance, model risk management, and extreme event-related financial risks. He has worked across banking, insurance, and regulatory environments, including roles at the Office of the Comptroller of the Currency and Moody's.


Comments