Federal Reserve SR 26-2 — Revised Guidance on Model Risk Management

Tag: S-2026-04-17-fed-sr-26-2-mrm Type: report (US inter-agency supervisory guidance) Author(s): Board of Governors of the Federal Reserve System, OCC and FDIC (joint) Date of source: 2026-04-17 Date ingested: 2026-06-22 Authority weight: high — primary US prudential supervisory guidance; the governing federal MRM standard. (Confidence on detail is medium-high: ingested via WebSearch summaries, not a direct read of the SR letter — see Ingestion note.) Raw file: S-2026-04-17-fed-sr-26-2-mrm.md. External URL: https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm

What it claims

On 17 April 2026 the Federal Reserve, OCC and FDIC jointly issued SR 26-2, “Revised Guidance on Model Risk Management”, which supersedes the long-standing SR 11-7 (2011) and SR 21-8 (2021) [S-2026-04-17-fed-sr-26-2-mrm]. The revised guidance is described as most relevant to banking organisations with over $30 billion in total assets regulated by the Federal Reserve, and it remains non-binding — it “does not set forth enforceable standards or prescriptive requirements” and non-compliance “will not result in supervisory criticism” [S-2026-04-17-fed-sr-26-2-mrm].

The point most material to governance practitioners is the scope carve-out for AI: the guidance states that generative AI and agentic AI models are “novel and rapidly evolving” and are NOT within the scope of this guidance [S-2026-04-17-fed-sr-26-2-mrm]. For tools, processes or systems not covered, a banking organisation’s own risk-management and governance practices “should guide the determination of appropriate governance and controls” [S-2026-04-17-fed-sr-26-2-mrm]. The agencies also signalled they plan to issue a Request for Information (RFI) in the near future addressing model risk management generally and, in particular, banks’ use of AI including generative and agentic AI [S-2026-04-17-fed-sr-26-2-mrm].

In effect, the US replaced its 15-year-old MRM anchor with a modernised version that deliberately leaves the fastest-moving and most-deployed class of AI (GenAI/agentic) outside the prescribed validation, documentation and independent-review perimeter, deferring it to a future RFI and to firms’ own judgement in the interim [S-2026-04-17-fed-sr-26-2-mrm].

Notable quotes

“Generative AI and agentic AI models are novel and rapidly evolving, and as such, they are not within the scope of this guidance.” — SR 26-2 attachment (via WebSearch summary, federalreserve.gov)

“[The guidance] does not set forth enforceable standards or prescriptive requirements [and] non-compliance with this guidance will not result in supervisory criticism against a banking organization.” — SR 26-2 (via WebSearch summary)

What’s speculative vs. asserted

  • Asserted (as fact): issuance on 17 April 2026; supersession of SR 11-7 and SR 21-8; joint Fed/OCC/FDIC issuance; non-enforceable nature; the explicit genAI/agentic out-of-scope carve-out; the stated intent to issue an RFI.
  • Reported but not read in primary text (medium-high confidence): the >$30bn applicability threshold; exact phrasing of the carve-out and RFI language. Sourced from WebSearch summaries and three independent legal/vendor analyses, not a direct fetch.
  • Forward-looking / not yet existing: the RFI on AI model risk is announced but not published; its scope and timing are not yet known.

Topics this feeds

  • Model Risk Management and Agentic AI — updates the wiki’s named Federal Reserve anchor from SR 11-7 to SR 26-2 and adds a regulator-confirmed perimeter gap (genAI/agentic out of scope) that reinforces the page’s existing “where the framework strains” thesis.

Open questions raised

  • When the agencies’ AI / genAI / agentic model-risk RFI will be published, and whether it will lead to binding requirements or remain guidance.
  • How firms should evidence governance of GenAI/agentic systems in the interim, given they sit outside the prescribed MRM perimeter but inside supervisory expectations on overall risk management.
  • Whether the >$30bn threshold and US scoping limit read-across to UK/EU practice, where SS1/23 (PRA) and the EU AI Act high-risk obligations take a different perimeter.

Ingestion note

Ingested via WebSearch (not a direct fetch of SR2602a1.pdf) on 2026-06-22, after the BIS/BCBS publications page (the day’s source 3) returned a JavaScript-only shell. Existence and core facts are corroborated across the federalreserve.gov page, OCC Bulletin 2026-13, and Sullivan & Cromwell / Domino / ValidMind analyses. The supersession recorded on the topic page is SR 26-2 over SR 11-7 / SR 21-8 (neither of which has its own Source page, so the supersession is documented in prose on the topic rather than as a frontmatter edge). This is a US item recorded under the daily scan’s practitioner/regulatory-intelligence remit.