Models support decisions across banking
Ask someone to identify the models used by their bank, and many immediately think of CECL or credit scoring. In reality, model risk management in banking touches nearly every discipline, although not every tool used in those functions is a model under SR 26-2.
Lending and credit
Credit scorecards, probability-of-default models, loan pricing models, early-warning indicators, and commercial loan risk models can influence approval decisions, pricing, terms, and ongoing monitoring. Debt-to-income calculations and deterministic rules may also support underwriting without meeting the model definition in SR 26-2. Governance should connect each model's intended use to the decisions it supports and to the consequences of inaccurate outputs.
Portfolio risk and financial reporting
CECL calculations, stress testing, concentration risk analysis, economic forecasting, risk migration analysis, and capital planning models can affect reserves, capital allocation, management strategy, and board reporting. For these models, documentation and outcomes analysis help management understand whether outputs remain reliable as portfolio composition and economic conditions change.
Financial crime
Financial crime programs may use models or predictive analytics for transaction monitoring, customer risk scoring, sanctions screening, fraud detection, payment anomaly detection, entity resolution, and behavioral analytics. Institutions should assess how model outputs affect alert prioritization and investigations, monitor performance and data quality, and understand the tradeoffs between missed activity and unnecessary false positives. Deterministic rules may not meet SR 26-2's model definition, but they still need effective controls and oversight. Institutions may also use model validation and parallel testing when appropriate to confirm that changes produce reliable results.
How SR 26-2 applies to AI adoption
Generative and agentic AI deserve careful treatment. SR 26-2 says these models are outside the scope of the guidance because they are novel and rapidly evolving. It also says an institution's risk management and governance practices should guide the determination of appropriate controls for tools, processes, or systems not covered by the document. The guidance's principles apply to both traditional statistical and quantitative models and non-generative, non-agentic AI models.
For institutions adopting AI, the practical question is how the capability affects decisions and risk. Governance should address intended use, data, human oversight, explainability or output limitations, performance monitoring, change controls, access, and incident escalation. AI governance should connect to model risk management when a system meets the relevant definition of a model, and to broader technology, operational, compliance, and third-party risk controls when it does not.