YuVerse at Global Fintech Fest 2026View event
Talk to us
BlogBankingWhat Is ExplainerYusight

Model Risk Management for AI in Credit Analysis: What SR 26-2 Changed

SR 11-7 was superseded by SR 26-2 in April 2026. See what changed for AI credit tools, why generative AI now sits outside model risk

YT

YuVerse Team

Published September 5, 2026 · Updated September 13, 2026 · 15 min read

Model Risk Management for AI in Credit Analysis: What SR 26-2 Changed

If you are looking for SR 11-7, it no longer governs. On 17 April 2026 the Federal Reserve issued SR 26-2, superseding SR 11-7 and SR 21-8, with the OCC publishing the same guidance as Bulletin 2026-13. The definition of a model narrowed, an asset threshold around $30 billion appeared, and generative and agentic AI were placed expressly outside scope. For an AI credit tool that means fewer prescribed steps and more decisions you have to justify — which is why 100% of figures cited matters more now, not less.


Key facts

  • SR 26-2 is dated 17 April 2026 and supersedes SR letters 11-7 (4 April 2011) and 21-8 (9 April 2021) (Federal Reserve, SR 26-2, *Revised Guidance on Model Risk Management*).
  • The OCC rescinded four issuances at once — the Model Risk Management booklet of the Comptroller's Handbook and OCC Bulletins 1997-24, 2011-12 and 2021-19 (OCC Bulletin 2026-13, *Model Risk Management: Revised Guidance*).
  • Generative AI is out of scope by name. The guidance states: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance."
  • The guidance is not enforceable on its own terms. OCC Bulletin 2026-13 states: "This guidance does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism against a banking organization."
  • YuSight cites 100% of figures with one-click source verification and keeps immutable version history — the evidence base a bank needs when there is no validation template to fall back on.

What did SR 26-2 actually change?

Four things, and the order matters.

 

SR 11-7 (2011)

SR 26-2 / OCC 2026-13 (2026)

Definition of "model"

"a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates"

"a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates"

Express exclusions

None stated; extended to approaches with qualitative or expert-judgment inputs producing quantitative output

"excludes simple arithmetic calculations, such as those found within spreadsheets, as well as deterministic rule-based processes and software where there are no statistical, economic, or financial theories underpinning their design or use"

Institutional scope

No asset threshold

"expected to be most relevant to banking organizations with over $30 billion in total assets"; may also be relevant below that where there is significant model risk exposure

AI

Silent — predates the question

Generative and agentic AI expressly out of scope; "the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models"

Enforceability

Supervisory expectation

"does not set forth enforceable standards or prescriptive requirements"

Note what the second row does. The words "mathematical" and "complex" moved in opposite directions: the old definition swept in anything mathematical, the new one requires complexity and a statistical, economic or financial theory underneath. A rule that says if the field is labelled "Total Revenue" on Form 1120-S line 1c, map it to Revenue has no theory underneath it. It is deterministic software. It is not a model.

Read the AI paragraph in full, because it is routinely quoted at half length:

"Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document. However, the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models."

The second sentence is the one people cite. The third sentence is the one that costs you work. The agencies removed generative AI from the model risk framework and handed the design of its controls back to you. That is a redirection, not an exemption — and a redirection to an area where there is no template.

Is an AI credit analysis tool a "model" under the new definition?

Stop treating the tool as one object. Most AI credit platforms are three or four components with different answers.

Component

What it does

Likely classification under SR 26-2

Why

Document classification and extraction

Reads a tax return, identifies the form, pulls field values

Statistical, but arguably not "complex" and not theory-driven

Machine learning with a measurable error rate; no economic or financial theory underpinning it

Ratio computation

Divides cash flow by debt service

Not a model

"simple arithmetic calculations, such as those found within spreadsheets"

Narrative drafting

Writes the memo text from the spread

Not a model — expressly out of scope

Generative AI

Risk rating or PD/LGD estimation

Produces a grade or a probability

Model

Complex, theory-driven, quantitative estimate

The distinction that actually matters is not model versus tool. It is drafts versus decisions. A system that assembles evidence and writes a narrative a human then approves is a different risk object from one that emits a grade the bank acts on. If your vendor's system does the second, the classification argument gets much harder regardless of what technology sits underneath. The examiner-facing version of that question is worked through in what questions bank examiners ask about AI underwriting.

Where practice is genuinely unsettled: nobody has published a supervisory example of an AI credit-memo drafting tool being classified either way under SR 26-2, and the guidance itself gives no worked case. What is not unsettled is the process expectation — that a named committee reached a decision, wrote the reasoning down, and can produce it.

If generative AI is out of scope, what governs it instead?

Four bodies of expectation, none of which went anywhere:

  1. General safety and soundness. The guidance's own carve-out says your "risk management and governance practices should guide the determination of appropriate governance and controls." That sentence is an instruction, not a release.
  2. Third-party risk. The Interagency Guidance on Third-Party Relationships, adopted by the OCC as Bulletin 2023-17 (6 June 2023), states plainly in its community bank note: "This guidance applies to all banks with third-party relationships." It does not ask whether the third party supplies a model. If you bought the tool, this is the guidance that binds.
  3. Credit administration. The OCC's Rating Credit Risk booklet still says "the rating assigned to a credit should be well supported and documented in the credit file." Support in the file is agnostic about who drafted the narrative.
  4. Consumer and fair lending law. ECOA and Regulation B adverse-action requirements are statutory. They do not have a model-risk on-ramp.

On enforceability, be precise. SR 26-2 saying non-compliance "will not result in supervisory criticism" means the guidance document is not itself an enforceable standard. It does not mean an examiner cannot criticise an uncontrolled AI system — they would do it under safety and soundness, third-party risk or internal audit findings instead. The route changed; the destination did not.

The agencies have also signalled further work specifically on AI.

Who owns validation for a vendor AI system?

You do. SR 26-2 is explicit that vendor products require "validation of vendor products, either by internal or outside parties," and that the bank should conduct "ongoing monitoring and outcome analysis to assess whether vendor models are accurate, remain fit for purpose, and continue to be reliable."

That language sits in the model chapters, so a vendor will tell you it does not apply to a non-model tool. Two responses:

  • The same obligation arrives via Bulletin 2023-17 anyway, where it is unconditional.
  • "Validation" for a non-model tool is not a validation report. It is measured accuracy against a benchmark you defined, on documents that look like yours.

A vendor cannot make the classification decision for you. When one says "we are not a model, so you do not need validation," they are answering a question that belongs to your model risk committee. The evidence to demand at diligence stage is set out in how to evaluate AI underwriting software for examiner readiness.

What control set replaces validation?

Two calculations you should be able to produce on request. Both are illustrative arithmetic, not measured results for any particular institution — run them on your own numbers.

Calculation one — what an accuracy figure actually implies at file level.

A bank benchmarks extraction on a sample of real files:

Files in the benchmark set 40 Extracted fields per file (average) 180 Total fields tested: 40 × 180 7,200 Fields mismatched against manual re-keying 343 Fields correct: 7,200 − 343 6,857 Field-level accuracy: 6,857 ÷ 7,200 95.2% Mismatches sitting in fields that feed DSCR 61 As a share of all fields: 61 ÷ 7,200 0.85% Files containing at least one such mismatch that moves DSCR by more than 0.05x 9 Share of files affected: 9 ÷ 40 22.5%

That is the sentence a control framework has to be built around: a field-level accuracy of 95.2% — YuSight's measured figure against a manual benchmark — can still coexist with roughly one file in four carrying a materially different ratio if nobody reviews it. High accuracy is an argument for mandatory human review, not against it. The related failure mode where a drafting tool produces a plausible number with no source is covered in how to stop an AI credit memo tool from hallucinating numbers.

Calculation two — sizing the second-line sample.

A bank writes 1,200 AI-assisted commercial memos a year and samples 60 for independent review, at a suspected defect rate of 5%:

Sample size 60 Probability a given memo is clean 0.95 Probability all 60 sampled memos are clean: 0.95^60 0.0461 Probability of catching at least one defect: 1 − 0.0461 95.4%

Now suppose the defect rate you actually care about is 1%:

Probability all 60 are clean: 0.99^60 0.5472 Probability of catching at least one defect 45.3%

The same sample that is excellent against a 5% defect rate is a coin toss against a 1%. To reach 90% detection at 1%:

n = ln(0.10) ÷ ln(0.99) = (−2.3026) ÷ (−0.01005) = 229.1 Sample required 230

Being able to show that arithmetic is worth more than a policy sentence saying "a risk-based sample is reviewed."

The control set itself, sized to your institution:

Control

What it produces

Owner

Written classification decision

A memo saying model or not-model, the reasoning, the date, the approver

Model risk committee

Inventory entry

The tool listed in the model or technology inventory either way

Model risk / IT

Pre-implementation accuracy benchmark

Measured accuracy on your documents, with the test set described

Credit risk

Mandatory human review

A named approver on every memo, recorded

Credit

Provenance

Every figure traceable to a source document and page in one click

Vendor capability, bank verified

Immutable version history

What the draft said before the analyst changed it

Vendor capability

Periodic re-testing

Re-run the benchmark on a schedule and after any material model change

Credit risk

Change notification

Contractual notice when the vendor changes the underlying model

Vendor management

Independent sample review

The calculation above, run and documented

Internal audit

What if your bank is under $30 billion?

Here the guidance is in slight tension with itself, and you should know that before you rely on either half.

The scope statement says the guidance is "expected to be most relevant to banking organizations with over $30 billion in total assets," and that it "may also be relevant to banking organizations with total assets of $30 billion or less that have significant exposure to model risk." But OCC Bulletin 2026-13's note for community banks says: "This guidance is applicable to all community banks, subject to the limitations discussed in the guidance."

The defensible reading is that the interagency framework is not primarily addressed to a community bank, while the underlying expectation — that you govern your own tools proportionately — is. That is exactly what the carve-out sentence says. What a $30 billion threshold does not do is switch off third-party risk management, credit administration expectations or fair lending law, none of which have asset thresholds.

Practical position for a community bank: write a short classification memo, keep an inventory line, benchmark accuracy once before go-live and once a year after, require human sign-off, and sample. That is perhaps six pages of documentation. Doing nothing because you are under the threshold is the one position that is hard to defend, and it is the one an examiner is most likely to encounter.

What should you write down this quarter?

  1. A one-page classification memo per AI tool: model or not, reasoning, approver, date.
  2. An inventory entry, whichever way the classification went.
  3. The accuracy benchmark: test set composition, sample size, measured result, date.
  4. The human review requirement, with the approver recorded per memo.
  5. The vendor file: third-party diligence under Bulletin 2023-17, contract terms on change notification and data exit.
  6. The sampling plan, with the arithmetic behind the sample size.
  7. A named committee that owns all six and a review date.

None of this is heavy if the platform produces the evidence as a by-product of normal work. That is the argument for a single-platform audit trail: the citation, the version history and the approval are artefacts of drafting the memo, not a separate compliance exercise afterwards. What an examiner then asks to see is set out in what examiner review requires from an AI-drafted credit memo, and how this sits in the wider file in commercial loan underwriting in US banks. If you also run an SBA book, the documentation changes there are in what SOP 50 10 8 changes in the underwriting file.

FAQ

Does SR 11-7 apply to generative AI credit tools?

SR 11-7 does not apply to anything any more — it was superseded on 17 April 2026 by SR 26-2. And SR 26-2 puts generative and agentic AI expressly outside its scope, so the model risk framework is not the framework that governs a generative AI credit tool.

What is the difference between a model and a tool under SR 11-7?

Under SR 11-7 the line was blurry, because its definition covered anything applying mathematical theories to produce quantitative estimates. SR 26-2 sharpened it: a model must now be complex and have a statistical, economic or financial theory underneath it, and simple arithmetic and deterministic rule-based software are excluded by name.

Who owns model validation for a vendor AI system?

The bank does. The guidance contemplates validation of vendor products by internal or outside parties and puts ongoing monitoring on the bank. A vendor supplies evidence — accuracy testing, change logs, documentation — but cannot hold the bank's classification or validation decision.

Is SR 26-2 enforceable?

Not as a standalone standard. It says non-compliance "will not result in supervisory criticism." That does not immunise an uncontrolled AI system, because safety and soundness, third-party risk guidance and consumer protection law all still bite. The criticism arrives by a different route.

Does the $30 billion threshold mean smaller banks can ignore this?

No. It means the interagency model risk framework is not primarily addressed to them and their own proportionate practices govern instead. The OCC's note for community banks says the guidance is applicable to all community banks subject to the limitations in the text, so read both statements together rather than picking one.

Do we still need a model inventory if our AI tool is not a model?

Keep an inventory line either way. It costs one row and it is the fastest possible answer to "what AI are you using and who approved it." Record the classification and its rationale in the same place.

What did the OCC actually rescind?

The Model Risk Management booklet of the Comptroller's Handbook plus OCC Bulletins 1997-24 on credit scoring models, 2011-12 on sound practices for model risk management, and 2021-19 on BSA/AML model risk. On the Federal Reserve side, SR 11-7 and SR 21-8 were superseded.

Is our credit risk rating model still in scope?

Almost certainly yes. A rating scorecard or a PD/LGD estimate is complex, theory-driven and produces a quantitative estimate — the definition still catches it. What changed around it is the perimeter, not the treatment of core credit models.

How often should we re-test an AI extraction tool?

Annually as a baseline, and on any material change to the vendor's underlying model or to your document mix. Write the trigger conditions into the policy so the re-test is event-driven rather than diarised and forgotten.

What is the single most common gap examiners find here?

An undocumented decision. Not the wrong classification — the absence of one. A committee that considered the question, chose a position and recorded compensating controls is in a defensible place; a bank that never asked is not.

Key takeaways

  • SR 11-7 was superseded on 17 April 2026 by SR 26-2, issued by the OCC as Bulletin 2026-13.
  • The model definition narrowed: complexity plus a statistical, economic or financial theory, with simple arithmetic and deterministic rules excluded.
  • Generative and agentic AI are out of scope by name — and the same paragraph hands the control design back to the bank.
  • The $30 billion threshold changes which framework addresses you, not whether you must govern the tool.
  • Third-party risk guidance, credit administration expectations and fair lending law apply irrespective of the model question.
  • Write the classification memo, keep the inventory line, benchmark accuracy, mandate human review, and size the sample with arithmetic you can show.

See the audit trail an examiner would see — book a walkthrough of a live credit memo with every figure cited to its source page and full version history.

Stay Updated

Get the latest AI insights delivered to your inbox.

Product Brochure

A complete overview of YuVerse products, use cases, and capabilities.

Topics

SR 11-7 model risk management lending AISR 11-7 model riskSR 26-2 AImodel validation creditOCC 2026-13AI model risk management banks