Skip to main content

Model risk management: What SR 26-2 means for financial institutions

Laura Clary, AAP
August 28, 2026
0 min read

Meet model risk management expectations

Updates to the FDIC Risk Management Manual should steer institutions toward better model risk governance across lending, risk, financial crimes, and AI 

This article covers these key topics: 

What SR 26-2 means for model risk management 

Financial institutions rely on models to approve loans, estimate credit losses, price risk, detect fraud, prioritize AML investigations, and support strategic decisions. Models are vital to banking strategy, but decisions based on inaccurate or poorly implemented models can create financial, compliance, and reputational risk. Model risk management gives institutions a framework for identifying, assessing, monitoring, and controlling that risk. 

In April 2026, the Federal Reserve, Office of the Comptroller of the Currency (OCC), and Federal Deposit Insurance Corporation (FDIC) issued SR 26-2, the revised Interagency Guidance on Model Risk Management. The guidance supersedes SR 11-7 and SR 21-8, including the prior interagency statement focused on model risk in systems supporting BSA/AML compliance. The latest guidance reinforces a key principle in model risk compliance: every significant model should be governed throughout its lifecycle in a manner proportionate to its risk.  

Insights that matter, all in one place. Make informed decisions faster with AI-powered live dashboards.

Learn more

The guidance is most relevant to banking organizations with more than $30 billion in assets regulated by the Federal Reserve. The guidance also states that it does not set enforceable standards or prescriptive requirements. Financial institutions have flexibility in how they structure model risk management. Supervisory action may still result from violations of law or unsafe or unsound practices stemming from insufficient management of model risk. 

What counts as a model under SR 26-2?

SR 26-2 defines a model as a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to input data to produce quantitative estimates. It excludes simple arithmetic calculations, such as those in spreadsheets, and deterministic rule-based processes or software that do not rely on those theories. 

SR 26-2 does apply to decision engines, machine learning, predictive analytics, vendor-provided models, and certain AI-enabled capabilities. 

This scope helps institutions make better decisions about what belongs in a model inventory and how much oversight is appropriate. A tool may fall outside the guidance's definition of a model while still creating operational, compliance, or technology risk. Institutions should therefore connect model risk management to broader risk and control processes rather than treating the definition as grounds to ignore systems that influence important decisions. The guidance should also encourage institutions to perform data integrity reviews annually and consider a full third-party model validation biannually or anytime there has been a significant change in an institution’s model 

Models support decisions across banking 

Ask someone to identify the models used by their bank, and many immediately think of CECL or credit scoring. In reality, model risk management in banking touches nearly every discipline, although not every tool used in those functions is a model under SR 26-2. 

Lending and credit 

Credit scorecards, probability-of-default models, loan pricing models, early-warning indicators, and commercial loan risk models can influence approval decisions, pricing, terms, and ongoing monitoring. Debt-to-income calculations and deterministic rules may also support underwriting without meeting the model definition in SR 26-2. Governance should connect each model's intended use to the decisions it supports and to the consequences of inaccurate outputs. 

Portfolio risk and financial reporting 

CECL calculations, stress testing, concentration risk analysis, economic forecasting, risk migration analysis, and capital planning models can affect reserves, capital allocation, management strategy, and board reporting. For these models, documentation and outcomes analysis help management understand whether outputs remain reliable as portfolio composition and economic conditions change. 

Financial crime

Financial crime programs may use models or predictive analytics for transaction monitoring, customer risk scoring, sanctions screening, fraud detection, payment anomaly detection, entity resolution, and behavioral analytics. Institutions should assess how model outputs affect alert prioritization and investigations, monitor performance and data quality, and understand the tradeoffs between missed activity and unnecessary false positives. Deterministic rules may not meet SR 26-2's model definition, but they still need effective controls and oversight. Institutions may also use model validation and parallel testing when appropriate to confirm that changes produce reliable results.

How SR 26-2 applies to AI adoption 

Generative and agentic AI deserve careful treatment. SR 26-2 says these models are outside the scope of the guidance because they are novel and rapidly evolving. It also says an institution's risk management and governance practices should guide the determination of appropriate controls for tools, processes, or systems not covered by the document. The guidance's principles apply to both traditional statistical and quantitative models and non-generative, non-agentic AI models. 

For institutions adopting AI, the practical question is how the capability affects decisions and risk. Governance should address intended use, data, human oversight, explainability or output limitations, performance monitoring, change controls, access, and incident escalation. AI governance should connect to model risk management when a system meets the relevant definition of a model, and to broader technology, operational, compliance, and third-party risk controls when it does not. 

What is model risk governance? 

Model risk governance is the structure that makes model risk management consistent and accountable. It includes policies, roles, approval authorities, reporting, controls, issue escalation, and oversight from senior management and the board. A sound model risk governance program should answer basic questions:

  • Who owns this model?
  • What decision does it influence?
  • What data and assumptions does it use?
  • Who provides effective challenge?
  • How is performance monitored?
  • What happens when the model changes or no longer fits its purpose? 

SR 26-2 emphasizes assessing model risk both individually and in aggregate. Aggregate risk can arise when several models rely on common data, assumptions, or methodologies. Governance should therefore look beyond one model's validation report and consider dependencies across lending, financial crime, portfolio risk, and other functions. 

Model risk management best practices for financial institutions 

SR 26-2 describes sound principles, not a single operating model. Institutions can tailor practices to risk while building a repeatable risk management lifecycle: 

  1. Identify and classify models. Maintain an inventory of models under development or in use, and record enough information to understand individual and aggregate risk. Consider inherent risk, exposure, purpose, and materiality when setting tiers. 
  2. Document intended use and limitations. Record purpose, methodology, assumptions, data sources, developmental evidence, approved use, limitations, and controls. Good documentation supports continuity, issue tracking, and remediation. 
  3. Use effective challenge. Objective, qualified reviewers should critically assess model risk and have enough independence and organizational influence to drive change when needed. 
  4. Validate and monitor based on risk. Validation should evaluate reliability and limitations. It can include conceptual soundness, outcomes analysis, benchmarking, back-testing, and other tests appropriate to the model. Frequency should reflect purpose, methodology, changes, data limitations, and materiality rather than a blanket schedule. 
  5. Control changes and extensions. Using a model beyond its intended purpose or changing data, assumptions, or methodology creates additional uncertainty. Set expectations for approval, testing, documentation, and monitoring before expanding use. 
  6. Oversee vendor and third-party products. Vendor models remain subject to model risk management principles. Institutions should understand conceptual soundness, development data, performance, ongoing monitoring, and any customization or overlays, even when proprietary limitations affect access. 
  7. Track findings and report them. Establish a process for exceptions, recommendations, responses, remediation, and escalation. Management and the board should receive information appropriate to their responsibilities. 

First steps toward updating model risk management practices

An effective update can begin with a focused review: 

  • Reconcile the model inventory with lending, financial crime, portfolio, reporting, and AI use cases. 
  • Reassess risk tiers using purpose, exposure, inherent risk, and materiality. 
  • Identify owners, validators, users, approvers, and escalation paths. 
  • Review validation and monitoring plans against model changes and business conditions. 
  • Document vendor dependencies, limitations, customizations, overlays, and performance evidence. 
  • Confirm that management and board reporting reflects aggregate model risk and open findings. 

Model risk management supports stronger decisions 

SR 26-2 reinforces a practical model risk management principle: oversight should be proportionate to risk, but accountability should be clear. Institutions with strong model risk governance can explain what their models do, where outputs may be unreliable, who can challenge them, and how the organization responds when conditions change. That discipline supports regulatory readiness and better decisions across lending, portfolio risk, and financial crimes. 

Financial institutions that want to strengthen their programs can start by formalizing existing practices, closing documentation gaps, and confirming that validation and monitoring reflect actual model use. Independent model validation and advisory support can help institutions assess model performance and build a model risk governance framework aligned with their risk profile. 

No black boxes allowed. Discover Abrigo's AI-powered, banker-controlled solutions

View the AI hub

The information, content and materials provided through this website are for informational purposes only and are not intended to constitute legal advice. Customers should consult with their legal counsel regarding the application of laws and regulations to their specific circumstances.

Meet model risk management expectations

Updates to the FDIC Risk Management Manual should steer institutions toward a model that manages risk and drives growth.

Would you like other articles like this in your inbox?

FDIC update

Model risk management in the spotlight

Last April, the FDIC released an Interagency Statement titled Model Risk Management (MRM) for Bank Models and Systems Supporting BSA/AML Compliance. The statement assured financial institutions that no specific model risk management is required, and that the guidance is intended to provide flexibility in applying risk management principles commensurate with a bank’s risk profile and the complexity and materiality of its models.

While this statement softened the enforcement of regulatory guidance, the FDIC recently issued an update to its Risk Management Manual of Examination that incorporates model risk management into bank ratings. The update includes a new section titled “Model Risk Management,” which details how examiners will evaluate bank management’s performance under the CAMELS rating system to determine if the institution is run safely and soundly.

The CAMELS rating is a measure of a financial institution’s risk based on an evaluation and rating of six essential components of its financial condition and operations. Examiners assign ratings on a 1 to 5 scale, with 1 indicating low risk and 5 indicating high risk. “CAMELS” is an acronym for six different components: 

  • Capital Adequacy: The amount of capital that must be held in the financial institution relative to the institution’s asset amount and type of asset risk.
  • Asset Quality: The quality of the assets on a financial institution’s balance sheet.
  • Management: The capability of the board of directors and management to identify, measure, monitor, and control the risks of an institution’s fiduciary activities.
  • Earnings: The quality, trend, and sustainability of the net profits from a financial institution’s operations.
  • Liquidity: The ability of the bank to meet the demands of its depositors and other creditors when due. 
  • Sensitivity to Market Risk: The bank’s position relative to inherent market risks.

The update signals regulatory attention to model risk. It should encourage institutions to perform data integrity reviews annually and consider a full third-party model validation bi-annually or anytime there has been a significant change in an institution’s model. Aside from meeting examiner expectations, these ingredients are the basis for a strong and sound BSA/AML program that can protect your institution from unnecessary risk. 

Evaluating leadership

What regulators look for in top-down guidance

The FDIC update clarifies how examiners will evaluate a financial institution's executives and board of directors under the Management component. The board of directors and senior management provide model risk governance at the highest level when they establish a bank-wide approach to model risk management. Banks should formalize their existing model risk management activities with official policies and procedures to follow good business practices and existing supervisory expectations. Key concepts that now contribute to the Management rating include:

  • Whether the policies, procedures, standards, and monitoring practices the bank may have sufficiently address model risk management practices.
  • Whether the bank maintains a model inventory. While not required, model inventory can be an important practice to assist in model risk management.
  • Whether the bank has model documentation or validation reports for models used.
  • Whether model risk management is covered in the audit scope.
  • Whether the bank maintains any exception or findings tracking reports.

Although model validations are a vital component of monitoring an institution’s BSA/AML risk, some institutions don’t have formalized model risk procedures and don’t know when an independent third-party validation is required. This is, of course, assuming that the bank employs a model for BSA/AML transaction monitoring, as some manual monitoring processes don’t meet the definition of a model.

Lowering risk

Monitoring and managing high-risk customers

Regulatory agencies have shifted resources and attention to assessing how institutions model their transaction monitoring and high-risk customer management programs. In fact, one of the most cited areas of examiner AML criticism is about sound model risk management. The most frequent model deficiencies noted by regulators include the following:

  • The model has fundamental errors and may produce inaccurate outputs
  • The model is used incorrectly, leading to inaccurate outputs
  • The model is not tailored to the Bank’s specific AML risk profile

Model risk management is critical to a sound BSA program and is expected by regulators, especially after the AML Act of 2020 gave FinCEN the responsibility to review model validation to combat the financing of terrorism. Increasingly risk-focused examiners will be looking closely at how bank management uses their models, so banks should strongly consider establishing a protocol to perform periodic data integrity reviews. They should also seek out a full third-party model validation on a rotating risk-focused timeline or anytime there has been a significant change in an institution’s model.

Developing and maintaining strong governance, policies, and controls over the model risk management framework is fundamentally important to its effectiveness.  After the ups and downs of the COVID era, it is more apparent than ever that banks should ensure that their model risk management framework extends beyond satisfying the regulatory regimes and serves the true purpose of adding value. Model risk validation, done correctly, is an investment that can help place financial institutions in a more comfortable position in crisis, leading to increased value for the shareholders.

Learn what to expect from an independent model validation.

Keep me informed Watch webinar
About the Author

Laura Clary, AAP

Senior Director, Product Compliance
Abrigo
Laura Clary is an Accredited ACH Professional and Senior Director with the Abrigo Product Compliance Team, driving regulatory clarity, influencing product direction and ensuring high-confidence compliance software across the Abrigo solution areas.  She leads regulatory insight across product lines and owns the compliance positioning in the Financial Crimes software, acting

Full Bio

About Abrigo

Abrigo enables U.S. financial institutions to support their communities through technology that fights financial crime, grows loans and deposits, and optimizes risk. Abrigo's platform centralizes the institution's data, creates a digital user experience, ensures compliance, and delivers efficiency for scale and profitable growth.

Make Big Things Happen.