Skip to main content

Model risk management: What SR 26-2 means for financial institutions

Laura Clary, AAP
August 28, 2026
0 min read

Meet model risk management expectations

Updates to the FDIC Risk Management Manual should steer institutions toward better model risk governance across lending, risk, financial crimes, and AI 

This article covers these key topics: 

What SR 26-2 means for model risk management 

Financial institutions rely on models to approve loans, estimate credit losses, price risk, detect fraud, prioritize AML investigations, and support strategic decisions. Models are vital to banking strategy, but decisions based on inaccurate or poorly implemented models can create financial, compliance, and reputational risk. Model risk management gives institutions a framework for identifying, assessing, monitoring, and controlling that risk. 

In April 2026, the Federal Reserve, Office of the Comptroller of the Currency (OCC), and Federal Deposit Insurance Corporation (FDIC) issued SR 26-2, the revised Interagency Guidance on Model Risk Management. The guidance supersedes SR 11-7 and SR 21-8, including the prior interagency statement focused on model risk in systems supporting BSA/AML compliance. The latest guidance reinforces a key principle in model risk compliance: every significant model should be governed throughout its lifecycle in a manner proportionate to its risk.  

Insights that matter, all in one place. Make informed decisions faster with AI-powered live dashboards.

Learn more

The guidance is most relevant to banking organizations with more than $30 billion in assets regulated by the Federal Reserve. The guidance also states that it does not set enforceable standards or prescriptive requirements. Financial institutions have flexibility in how they structure model risk management. Supervisory action may still result from violations of law or unsafe or unsound practices stemming from insufficient management of model risk. 

What counts as a model under SR 26-2?

SR 26-2 defines a model as a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to input data to produce quantitative estimates. It excludes simple arithmetic calculations, such as those in spreadsheets, and deterministic rule-based processes or software that do not rely on those theories. 

SR 26-2 does apply to decision engines, machine learning, predictive analytics, vendor-provided models, and certain AI-enabled capabilities. 

This scope helps institutions make better decisions about what belongs in a model inventory and how much oversight is appropriate. A tool may fall outside the guidance's definition of a model while still creating operational, compliance, or technology risk. Institutions should therefore connect model risk management to broader risk and control processes rather than treating the definition as grounds to ignore systems that influence important decisions. The guidance should also encourage institutions to perform data integrity reviews annually and consider a full third-party model validation biannually or anytime there has been a significant change in an institution’s model 

Models support decisions across banking 

Ask someone to identify the models used by their bank, and many immediately think of CECL or credit scoring. In reality, model risk management in banking touches nearly every discipline, although not every tool used in those functions is a model under SR 26-2. 

Lending and credit 

Credit scorecards, probability-of-default models, loan pricing models, early-warning indicators, and commercial loan risk models can influence approval decisions, pricing, terms, and ongoing monitoring. Debt-to-income calculations and deterministic rules may also support underwriting without meeting the model definition in SR 26-2. Governance should connect each model's intended use to the decisions it supports and to the consequences of inaccurate outputs. 

Portfolio risk and financial reporting 

CECL calculations, stress testing, concentration risk analysis, economic forecasting, risk migration analysis, and capital planning models can affect reserves, capital allocation, management strategy, and board reporting. For these models, documentation and outcomes analysis help management understand whether outputs remain reliable as portfolio composition and economic conditions change. 

Financial crime

Financial crime programs may use models or predictive analytics for transaction monitoring, customer risk scoring, sanctions screening, fraud detection, payment anomaly detection, entity resolution, and behavioral analytics. Institutions should assess how model outputs affect alert prioritization and investigations, monitor performance and data quality, and understand the tradeoffs between missed activity and unnecessary false positives. Deterministic rules may not meet SR 26-2's model definition, but they still need effective controls and oversight. Institutions may also use model validation and parallel testing when appropriate to confirm that changes produce reliable results.

How SR 26-2 applies to AI adoption 

Generative and agentic AI deserve careful treatment. SR 26-2 says these models are outside the scope of the guidance because they are novel and rapidly evolving. It also says an institution's risk management and governance practices should guide the determination of appropriate controls for tools, processes, or systems not covered by the document. The guidance's principles apply to both traditional statistical and quantitative models and non-generative, non-agentic AI models. 

For institutions adopting AI, the practical question is how the capability affects decisions and risk. Governance should address intended use, data, human oversight, explainability or output limitations, performance monitoring, change controls, access, and incident escalation. AI governance should connect to model risk management when a system meets the relevant definition of a model, and to broader technology, operational, compliance, and third-party risk controls when it does not. 

What is model risk governance? 

Model risk governance is the structure that makes model risk management consistent and accountable. It includes policies, roles, approval authorities, reporting, controls, issue escalation, and oversight from senior management and the board. A sound model risk governance program should answer basic questions:

  • Who owns this model?
  • What decision does it influence?
  • What data and assumptions does it use?
  • Who provides effective challenge?
  • How is performance monitored?
  • What happens when the model changes or no longer fits its purpose? 

SR 26-2 emphasizes assessing model risk both individually and in aggregate. Aggregate risk can arise when several models rely on common data, assumptions, or methodologies. Governance should therefore look beyond one model's validation report and consider dependencies across lending, financial crime, portfolio risk, and other functions. 

Model risk management best practices for financial institutions 

SR 26-2 describes sound principles, not a single operating model. Institutions can tailor practices to risk while building a repeatable risk management lifecycle: 

  1. Identify and classify models. Maintain an inventory of models under development or in use, and record enough information to understand individual and aggregate risk. Consider inherent risk, exposure, purpose, and materiality when setting tiers. 
  2. Document intended use and limitations. Record purpose, methodology, assumptions, data sources, developmental evidence, approved use, limitations, and controls. Good documentation supports continuity, issue tracking, and remediation. 
  3. Use effective challenge. Objective, qualified reviewers should critically assess model risk and have enough independence and organizational influence to drive change when needed. 
  4. Validate and monitor based on risk. Validation should evaluate reliability and limitations. It can include conceptual soundness, outcomes analysis, benchmarking, back-testing, and other tests appropriate to the model. Frequency should reflect purpose, methodology, changes, data limitations, and materiality rather than a blanket schedule. 
  5. Control changes and extensions. Using a model beyond its intended purpose or changing data, assumptions, or methodology creates additional uncertainty. Set expectations for approval, testing, documentation, and monitoring before expanding use. 
  6. Oversee vendor and third-party products. Vendor models remain subject to model risk management principles. Institutions should understand conceptual soundness, development data, performance, ongoing monitoring, and any customization or overlays, even when proprietary limitations affect access. 
  7. Track findings and report them. Establish a process for exceptions, recommendations, responses, remediation, and escalation. Management and the board should receive information appropriate to their responsibilities. 

First steps toward updating model risk management practices

An effective update can begin with a focused review: 

  • Reconcile the model inventory with lending, financial crime, portfolio, reporting, and AI use cases. 
  • Reassess risk tiers using purpose, exposure, inherent risk, and materiality. 
  • Identify owners, validators, users, approvers, and escalation paths. 
  • Review validation and monitoring plans against model changes and business conditions. 
  • Document vendor dependencies, limitations, customizations, overlays, and performance evidence. 
  • Confirm that management and board reporting reflects aggregate model risk and open findings. 

Model risk management supports stronger decisions 

SR 26-2 reinforces a practical model risk management principle: oversight should be proportionate to risk, but accountability should be clear. Institutions with strong model risk governance can explain what their models do, where outputs may be unreliable, who can challenge them, and how the organization responds when conditions change. That discipline supports regulatory readiness and better decisions across lending, portfolio risk, and financial crimes. 

Financial institutions that want to strengthen their programs can start by formalizing existing practices, closing documentation gaps, and confirming that validation and monitoring reflect actual model use. Independent model validation and advisory support can help institutions assess model performance and build a model risk governance framework aligned with their risk profile. 

FAQs

What is model risk management?

Model risk management is the framework an institution uses to identify, assess, monitor, and control the potential for adverse consequences from models that inform decisions. It covers the model lifecycle, from development and implementation through validation, monitoring, change management, and retirement.

What is model risk governance?

Model risk governance is the set of policies, roles, controls, reporting, and oversight that makes model risk management accountable. It defines ownership, effective challenge, approval authority, issue escalation, and management and board visibility into model risk.

Does SR 26-2 apply to institutions with less than $30 billion in assets?

SR 26-2 is expected to be most relevant to banking organizations with more than $30 billion in assets regulated by the Federal Reserve. Smaller institutions should use model risk management practices appropriate to their size and risk profile, but the guidance may still be useful when model exposure is significant because of model complexity, prevalence, or activities outside traditional community banking.

Does SR 26-2 cover generative AI?

No. SR 26-2 states that generative and agentic AI models are outside the scope of the guidance. It also says institutions should use their existing risk management and governance practices to determine appropriate controls for tools and processes not covered by the document. Its principles apply to non-generative, non-agentic AI models.

Learn what to expect from an independent model validation.

Keep me informed Watch webinar

The information, content and materials provided through this website are for informational purposes only and are not intended to constitute legal advice. Customers should consult with their legal counsel regarding the application of laws and regulations to their specific circumstances.

About the Author

Laura Clary, AAP

Senior Director, Product Compliance
Abrigo
Laura Clary is an Accredited ACH Professional and Senior Director with the Abrigo Product Compliance Team, driving regulatory clarity, influencing product direction and ensuring high-confidence compliance software across the Abrigo solution areas.  She leads regulatory insight across product lines and owns the compliance positioning in the Financial Crimes software, acting

Full Bio

About Abrigo

Abrigo enables U.S. financial institutions to support their communities through technology that fights financial crime, grows loans and deposits, and optimizes risk. Abrigo's platform centralizes the institution's data, creates a digital user experience, ensures compliance, and delivers efficiency for scale and profitable growth.

Make Big Things Happen.