Law / United States

Interagency Supervisory Guidance on Model Risk Management (2026 revision)

Federal Reserve SR 26-2; OCC Bulletin 2026-13; FDIC FIL-15-2026

Guidance, not a law: the Federal Reserve Board, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation's reading of Safety and soundness standards for insured depository institutions: internal controls, information systems and internal audit systems. It binds nobody by itself; the law it reads does.

Guidance on an AI sector rules rule, addressed to private bodies.

Criminal exposure
No
Private right of action
No
Instrument type
guidance published by a regulator
Obligation class
Governance
Audit expectation
periodic
Who audits it
Internal independent, Independent third party
Where the report goes
Kept

As of .

What the regulator expects

  • It reaches you if you are a banking organization supervised by the Federal Reserve Board, the Office of the Comptroller of the Currency (OCC) or the Federal Deposit Insurance Corporation (FDIC), including a national bank, federal savings association, federal branch or agency of a foreign banking organization, or FDIC-supervised financial institution. The agencies expect it to be most relevant if you have over $30 billion in total assets, and it may also be relevant below that if you have significant exposure to model risk. Generative AI and agentic AI models are outside its scope, and its principles apply to traditional statistical and quantitative models and non-generative, non-agentic AI models. It sets no enforceable standards or prescriptive requirements, so each line below states what the agencies describe as sound practice.
  • Tailor model risk management to your model risk profile and the size and complexity of your operations, with more comprehensive and rigorous oversight for models of higher materiality.
  • Test a model as part of development, with rigor commensurate with the model's complexity and materiality.
  • Validate a model before its first use. Where an urgent business need requires use before validation is complete, give greater attention to the model's limitations, inform relevant stakeholders of them, and set controls such as limits on use or closer monitoring of performance.
  • Validate conceptual soundness, compare model outputs with real-world outcomes, and monitor model performance on an ongoing basis, considering adjustment, recalibration or redevelopment when performance deviates meaningfully from expectations.
  • Have objective experts with appropriate expertise, sufficient independence to maintain objectivity, and the organizational standing and influence to effect change provide effective challenge of models throughout the model lifecycle.
  • Maintain a model inventory with enough information to understand model risks at the individual and aggregate levels; the guidance calls this common industry practice.
  • Keep documentation adequate to support effective model risk management, including the tracking of recommendations, responses and exceptions.
  • Set clear policies and roles and responsibilities for model development, validation and monitoring, including how conflicts of interest are handled. Where internal audit is part of the practice, its role is generally to evaluate whether model risk management practices are rigorous and effective rather than to duplicate development or validation.
  • Apply model risk management to vendor and other third-party models, including validating them, developing an understanding of their conceptual soundness, design, development data and performance, and monitoring them on an ongoing basis.

Who enforces it

Enforcement body

Board of Governors of the Federal Reserve System, Office of the Comptroller of the Currency and Federal Deposit Insurance Corporation, as supervisors of the banking organizations each reaches. The guidance carries no enforcement action of its own.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

The Federal Reserve Board, the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) issued revised model risk management guidance on . The Federal Reserve issued it as SR Letter 26-2. The OCC issued it as Bulletin 2026-13. The FDIC issued it as FIL-15-2026.

SR Letter 26-2 supersedes and replaces SR Letter 11-7 and SR Letter 21-8, the 2021 interagency statement on model risk management for bank systems supporting Bank Secrecy Act and anti-money laundering compliance. OCC Bulletin 2026-13 rescinds OCC Bulletin 1997-24, OCC Bulletin 2011-12 and OCC Bulletin 2021-19, together with the Model Risk Management booklet of the Comptroller's Handbook. The FDIC rescinds FIL-22-2017 and FIL-27-2021.

Generative AI and agentic AI models are not within the scope of the guidance. The guidance says its principles apply to traditional statistical and quantitative models and non-generative, non-agentic AI models. For tools and systems it does not cover, the guidance says a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls.

The guidance defines a model as a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates. The definition excludes simple arithmetic calculations and deterministic rule-based processes and software with no statistical, economic, or financial theories underpinning their design or use. The guidance is expected to be most relevant to banking organizations with over $30 billion in total assets.

It may also be relevant to banking organizations with $30 billion or less in total assets that have significant exposure to model risk because of the prevalence and complexity of their models or because of activities outside the scope of traditional community banking. The FDIC states that its letter applies to all FDIC-supervised financial institutions.

The FDIC letter adds that the guidance generally does not apply to models used by banking organizations with total assets of $30 billion or less, to the extent such institutions do not have significant exposure to model risk. OCC Bulletin 2026-13 says the guidance is applicable to all community banks, subject to the limitations discussed in the guidance.

The guidance covers model development and use, model validation and monitoring, governance and controls, and vendor and other third-party products. The guidance does not set forth enforceable standards or prescriptive requirements, and non-compliance with it will not result in supervisory criticism against a banking organization. Supervisory action may still result for any violations of law or unsafe or unsound practices stemming from insufficient management of model risk.

The Federal Reserve Board's codified statement on the role of supervisory guidance says that supervisory guidance does not have the force and effect of law. The OCC's codified statement on the role of supervisory guidance says that the OCC does not take enforcement actions based on supervisory guidance. The FDIC's codified statement on the role of supervisory guidance says that supervisory guidance does not have the force and effect of law.

Back to the example  ·  Lint your app