Law / United States

Interagency Supervisory Guidance on Model Risk Management (2011)

Federal Reserve SR 11-7; OCC Bulletin 2011-12; FDIC FIL-22-2017

Guidance, not a law: the Federal Reserve Board, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation's reading of Safety and soundness standards for insured depository institutions: internal controls, information systems and internal audit systems. It binds nobody by itself; the law it reads does.

Guidance on an AI sector rules rule, addressed to private bodies.

Criminal exposure
No
Private right of action
No
Instrument type
guidance published by a regulator
Obligation class
Governance
Audit expectation
periodic
Who audits it
Internal independent, Independent third party
Where the report goes
Kept

As of .

What the regulator expects

  • The 2011 guidance reached a national bank or other institution for which the Office of the Comptroller of the Currency (OCC) is the primary supervisor, and a bank holding company, state member bank or other institution for which the Federal Reserve Board is the primary supervisor. The Federal Deposit Insurance Corporation (FDIC) adopted it in 2017 for FDIC-supervised institutions and did not expect it to pertain to those with under $1 billion in total assets unless their model use was significant, complex, or posed elevated risk.
  • Banks should maintain a comprehensive set of information for models implemented for use, under development for implementation, or recently retired, with a specific party charged with maintaining a firm-wide inventory of all models.
  • Validation should be done by people who are not responsible for development or use and do not have a stake in whether a model is determined to be valid, and developmental evidence should be reviewed before a model goes into use.
  • Banks should conduct a periodic review of each model, at least annually but more frequently if warranted, to determine whether it is working as intended and whether the existing validation activities are sufficient.
  • Banks should design a program of ongoing testing and evaluation of model performance, along with procedures for responding to any problems that appear.
  • Documentation of model development and validation should be sufficiently detailed so that parties unfamiliar with a model can understand how the model operates, its limitations, and its key assumptions.
  • The board and senior management should establish a strong model risk management framework that fits into the broader risk management of the organization, and the board or its delegates should approve model risk management policies and review them annually.
  • A bank's internal audit function should assess the overall effectiveness of the model risk management framework, and findings related to models should be documented and reported to the board or its appropriately delegated agent.
  • Vendor products should be incorporated into a bank's broader model risk management framework following the same principles as applied to in-house models.

Who enforces it

Enforcement body

Board of Governors of the Federal Reserve System and Office of the Comptroller of the Currency, and for institutions it supervises the Federal Deposit Insurance Corporation, as primary supervisors. The guidance carries no enforcement action of its own.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

The Federal Reserve Board and the Office of the Comptroller of the Currency (OCC) issued Supervisory Guidance on Model Risk Management on . The Federal Reserve issued it as SR Letter 11-7 and the OCC issued it as Bulletin 2011-12.

In the guidance, banks means national banks and all other institutions for which the Office of the Comptroller of the Currency is the primary supervisor, and bank holding companies, state member banks and all other institutions for which the Federal Reserve Board is the primary supervisor. The Federal Deposit Insurance Corporation (FDIC) adopted the guidance with technical conforming changes, which made it applicable to certain FDIC-supervised institutions.

The FDIC's adoption, FIL-22-2017, is dated . The FDIC did not expect the guidance to pertain to FDIC-supervised institutions with under $1 billion in total assets unless the institution's model use was significant, complex, or posed elevated risk. The guidance says all banks should ensure that internal policies and procedures are consistent with its risk management principles and supervisory expectations.

It says practical application should be customized to a bank's risk exposures, its business activities, and the complexity and extent of its model use. It defines model risk as the potential for adverse consequences from decisions based on incorrect or misused model outputs and reports. SR Letter 26-2, issued , supersedes and replaces SR Letter 11-7. OCC Bulletin 2026-13 rescinds OCC Bulletin 2011-12. FDIC letter FIL-15-2026 rescinds FIL-22-2017.

In October 2025 the OCC clarified for community banks that its model risk management guidance does not, and should not be interpreted to, require annual model validation. The Federal Reserve Board's codified statement on the role of supervisory guidance says that supervisory guidance does not have the force and effect of law. The OCC's codified statement on the role of supervisory guidance says that the OCC does not take enforcement actions based on supervisory guidance.

The FDIC's codified statement on the role of supervisory guidance says that supervisory guidance does not have the force and effect of law.

Back to the example  ·  Lint your app