Financial Services Governance
SR 11-7 Compliant AI Model Risk Management Consulting
What model risk management consulting means for AI under the Fed's current guidance, and why SR 11-7 by itself no longer answers the question.
SR 11-7 was superseded in April 2026 by SR 26-2, which sets model risk standards for banks with over $30 billion in assets, but explicitly excludes generative and agentic AI from its formal scope. Kriv AI helps regulated institutions apply SR 26-2's governance discipline, inventory, risk tiering, and validation, to AI systems the rule itself does not yet name.
context
What SR 11-7 and SR 26-2 Actually Require
The regulation everyone still searches for by its old name has already been replaced, and the replacement changes who it applies to and what counts as a model.
SR 26-2 supersedes SR 11-7
The Federal Reserve, OCC, and FDIC jointly issued SR 26-2 on April 17, 2026, superseding both the original 2011 SR 11-7 guidance and the 2021 interagency statement on model risk. The revised guidance keeps the same foundational discipline, model definition, independent validation, and governance, but calibrates how much of it applies based on a bank's size and model-risk profile. The agencies expect it to be most relevant to banking organizations with more than $30 billion in total assets, though they note smaller institutions with concentrated model risk exposure may still need to apply it.
A narrower definition of "model"
To count as a model under SR 26-2, a system needs a complex quantitative method, a grounding in statistical, economic, or financial theory, and a quantitative output. Simple spreadsheets and fixed rule-based tools no longer qualify on their own, which narrows the guidance's literal reach compared with how examiners applied SR 11-7 in practice.
scope gap
Why Generative and Agentic AI Sit Outside SR 26-2's Formal Scope
SR 26-2 explicitly excludes generative and agentic AI models from its scope, describing them as novel and rapidly evolving. That is a deliberate carve-out, not an oversight: a large language model does not produce the single measurable prediction that validation techniques like backtesting were built to check, so the agencies chose not to force it into a framework designed for credit-scoring and stress-testing models.
The exclusion does not mean AI goes ungoverned. The same guidance directs banks to apply their broader risk management and governance practices to these systems, and examiners still expect a defined owner, an inventory, and a risk-tiering approach for every AI system in production, including vendor tools with an embedded model. Well-run institutions apply SR 26-2's underlying discipline, inventory, ownership, tiering, ongoing monitoring, to generative and agentic AI voluntarily, even though the letter does not require it by name.
That gap between formally in scope and actually needs governance is where most of the practical compliance risk sits today. An engagement built only around SR 26-2's literal checklist will miss the AI systems the rule does not name but examiners will still ask about.
engagement
What an SR 26-2-Informed AI Governance Engagement Includes
The work typically starts with an inventory: every AI system in production or pilot, including third-party vendor tools with an embedded model, cataloged with a named owner and a risk tier based on the decision it influences. A customer-facing FAQ assistant sits in a different tier than an agent that can initiate a payment or approve a loan.
Because generative and agentic systems cannot be backtested the way SR 26-2's traditional models can, validation shifts to structured output sampling against a rubric, red-teaming for guardrail failures, and ongoing drift monitoring on output quality. The deliverable is a validation framework the institution's second line can actually run on its own, not a one-time report.
The engagement closes with a governance structure: defined ownership, a review cadence, and board-level reporting on AI risk, built to absorb new AI use cases as they appear rather than requiring a fresh engagement every time one does.
rate card
Kriv AI's Rates for This Work
These are Kriv AI's own published rate floors, not a market average or a third-party benchmark.
| Track | Kriv hourly rate | Typical engagement model | Minimum engagement |
|---|---|---|---|
| Enterprise / regulated (banks, financial services) | From $200/hr | Fixed-scope project or retainer | $8,000 |
| Fractional CTO / AI governance lead | $300 to $400/hr | Part-time, ongoing (monthly) | $8,000 |
| Specialized advisory (model risk, expert consults) | $400 to $700/hr | Hourly, per-session | Varies by engagement |
| Small business | $150/hr | Referred to Kriv AI's partner network | n/a |
get a quote
How to Get a Real Quote
The rates above are floors, not quotes. A real number depends on how many AI systems are in scope, how many of them sit outside SR 26-2's formal definition of a model, and whether the work is a one-time inventory or ongoing oversight. Book a discovery call and we will scope it honestly, including whether a smaller assessment makes more sense as a first step.
Straight answers
Frequently asked questions about SR 11-7 Compliant AI Model Risk Management Consulting
What is SR 26-2 and how does it relate to SR 11-7?
SR 26-2 is the Federal Reserve, OCC, and FDIC's joint guidance issued April 17, 2026, superseding the original 2011 SR 11-7 model risk management guidance and the 2021 interagency statement. It keeps SR 11-7's core discipline but calibrates it to a bank's size and risk profile.
Does SR 26-2 apply to generative AI or agentic AI systems?
No. SR 26-2 explicitly excludes generative and agentic AI models from its formal scope, describing them as novel and rapidly evolving. The guidance still expects banks to apply their broader risk management practices to these systems even though the letter does not name them.
What size bank does SR 26-2 apply to?
The agencies expect it to be most relevant to banking organizations with over $30 billion in total assets, though smaller institutions with concentrated model risk exposure may still need to apply it.
How do you validate an AI model that cannot be backtested?
Through structured output sampling against a rubric, red-teaming for guardrail failures, and ongoing drift monitoring on output quality, rather than the single input-output accuracy check traditional models use.
What does an SR 26-2-informed AI governance engagement cost?
Kriv AI's rates start at a $200/hr floor for enterprise and regulated work, with an $8,000 minimum engagement. Specialized model-risk advisory runs $400 to $700/hr.
Does Kriv AI work with community banks?
Small-business and community-bank work is referred to Kriv AI's partner network at a $150/hr rate. Kriv AI's own consulting practice focuses on enterprise and regulated institutions.
Talk to the team that would do the work
Bring your requirements to a working session with the person who'll actually deliver.
Book a Discovery Call