Banking and Financial Services
What Is AI Model Risk Management for Banks?
The guidance sounds like it covers every AI model a bank runs. The regulators who wrote it say otherwise, and the difference changes what a compliance program actually has to build.
AI model risk management for banks is the discipline of identifying, validating, and monitoring the AI and statistical models banks use for credit, fraud, and compliance decisions. It now runs under the Federal Reserve, OCC, and FDIC's April 2026 SR 26-2 guidance, which explicitly excludes generative and agentic AI models from its formal scope.
regulatory basis
SR 26-2: The Guidance That Actually Governs This
Bank model risk management has one real regulatory anchor. For fifteen years it was SR 11-7, the Federal Reserve's 2011 guidance on model risk. On April 17, 2026, the Federal Reserve, the OCC, and the FDIC jointly superseded it with SR 26-2, Revised Guidance on Model Risk Management, along with SR 21-8, the 2021 interagency guidance on anti-money-laundering models. If a vendor, a consultant, or an internal policy still points only to SR 11-7 as the current standard, that citation is fifteen years out of date.
SR 26-2 is expected to be most relevant to banking organizations with more than $30 billion in total assets. Banks at or below that threshold are typically expected to run internal model risk practices sized to their own complexity, and the agencies say excluding them from this specific guidance is consistent with a tailored supervisory approach, though a smaller bank with unusually complex or high-volume model use can still fall inside its relevance. The guidance is also explicit that it sets no enforceable standard: it is supervisory guidance, not a regulation, and non-compliance with it alone does not by itself trigger supervisory criticism. In practice, examiners still use it as the working definition of a sound program, so treating it as optional is a mistake even where it is not one on paper.
scope
What Counts as a Model, and Why Generative AI Doesn't
The Guidance's Own Definition of a Model
SR 26-2 defines a model as a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to convert input data into quantitative estimates. That definition deliberately excludes simple spreadsheet arithmetic and deterministic, rule-based software with no underlying statistical or economic theory. A credit-scoring model, a fraud-detection classifier, or an anti-money-laundering alert engine built on statistical or machine-learning methods fits squarely inside that definition.
Generative AI and Agentic AI Are Explicitly Out of Scope
The guidance draws its most consequential line in a single footnote: generative AI and agentic AI models are described as novel and rapidly evolving, and the agencies state plainly that they are not within the scope of this guidance. A bank's large language model chatbot, an AI coding assistant, or an autonomous agent that takes multi-step actions does not fall under SR 26-2's formal validation and governance requirements as written today.
That does not mean generative and agentic AI are ungoverned. The same footnote directs banks to let their own risk management and governance practices determine appropriate controls for any tool the guidance does not cover, and the core SR 26-2 principles, inventory, validation, monitoring, governance, are the natural starting point most banks use to build that internal coverage even though the letter itself does not mandate it for these newer systems.
Vendor and Third-Party AI Models Stay the Bank's Responsibility
A large share of the AI banks use for credit, fraud, and underwriting is licensed from a vendor rather than built in house. SR 26-2 is explicit that using a third-party or vendor model does not transfer away model risk: the guidance calls for validating vendor products, understanding their conceptual soundness, design, and development data even when the underlying code or methodology is proprietary, and running the same ongoing monitoring and outcomes analysis a bank would run on a model it built internally.
framework
The Core Components of a Bank AI Model Risk Management Program
1. Model Inventory
A comprehensive, maintained record of every model under development or in use, detailed enough to understand risk at both the individual model and portfolio level, not just a spreadsheet of names.
2. Independent Validation
A review function separate from the team that built the model, evaluating conceptual soundness (design, assumptions, and data) and running outcomes analysis that compares model output against real-world results to catch drift or persistent errors.
3. Ongoing Monitoring
Continuous evaluation of whether a model still performs as expected as products, customer behavior, data, or market conditions shift, with a defined process for adjusting, recalibrating, or retiring a model that no longer holds up.
4. Governance, Roles, and Effective Challenge
Clear accountability for development, validation, and monitoring, with policies proportional to the bank's size and model complexity, and a genuine effective-challenge process rather than validation staff who report to the same people who built the model.
5. Vendor and Third-Party Oversight
The same validation and monitoring discipline applied to purchased or licensed models, including documenting any customization made to fit the bank's specific use case.
6. Documentation
Records thorough enough to support continuity when staff turn over, track outstanding validation findings and remediation, and give an examiner a clear paper trail without reconstruction under deadline pressure.
differentiation
How Kriv AI Helps
Kriv AI works with banks and other regulated financial institutions to build or strengthen the AI model risk management program SR 26-2 describes: model inventory design, independent validation support, vendor model due diligence, and the governance documentation examiners expect to see. This is advisory and implementation work, not a replacement for a bank's own model risk function.
Enterprise and regulated-industry engagements start at $200 per hour, a fractional AI governance lead who owns your program on an ongoing basis runs $300 to $400 per hour, and specialized advisory work, including independent model validation, runs $400 to $700 per hour. All engagements carry an $8,000 minimum. See current rate detail on the pricing page, or book a discovery call to scope what your specific model inventory and governance gap actually needs.
Straight answers
Frequently asked questions about What Is AI Model Risk Management for Banks?
What is AI model risk management for banks?
AI model risk management for banks is the discipline of identifying, validating, and monitoring the AI and statistical models banks use for credit, fraud, and compliance decisions. It now runs under the Federal Reserve, OCC, and FDIC's April 2026 SR 26-2 guidance, which explicitly excludes generative and agentic AI models from its formal scope.
Does SR 26-2 cover generative AI or AI agents used by banks?
No. SR 26-2 states directly that generative AI and agentic AI models are novel and rapidly evolving and are not within the scope of the guidance. Non-generative, non-agentic AI models, such as statistical credit-scoring or fraud-detection models, remain squarely covered.
Which banks does SR 26-2 apply to?
SR 26-2 is expected to be most relevant to banking organizations with more than $30 billion in total assets. Banks at or below that threshold are typically excluded as a matter of tailored supervisory practice, though a smaller bank with unusually complex or high-volume model use can still fall inside its relevance.
What did SR 26-2 replace?
SR 26-2, issued April 17, 2026 by the Federal Reserve, OCC, and FDIC, superseded SR 11-7 (the Federal Reserve's original 2011 model risk management guidance) and SR 21-8 (the 2021 interagency guidance on anti-money-laundering models).
What are the core components of a bank AI model risk management program?
A model inventory, independent validation covering conceptual soundness and outcomes analysis, ongoing monitoring, clear governance with effective challenge, oversight of vendor and third-party models, and documentation thorough enough to survive an examiner's review without reconstruction under deadline pressure.
How does Kriv AI help banks with AI model risk management?
Kriv AI builds and strengthens AI model risk management programs for banks: model inventory design, independent validation support, vendor model due diligence, and governance documentation. Enterprise engagements start at $200 per hour, a fractional AI governance lead runs $300 to $400 per hour, and specialized advisory work runs $400 to $700 per hour, with an $8,000 minimum engagement.
Talk to the team that would do the work
Bring your requirements to a working session with the person who'll actually deliver.
Book a Discovery Call