Supervisory Guidance on Model Risk Management
United States
RAI-US-NA-FEDSR117-2011SR 11-7 / OCC 2011-12
Supervisory Guidance on Model Risk Management is Superseded in United States as of 9 Sep 2026, according to federalreserve.gov.
GuidelineRisk ManagementGovernance and OversightUS Federal Reserve SR 11-7 guides banking organizations on managing risks from quantitative models, including AI, through robust governance and validation.
Summary
The Federal Reserve SR 11-7, issued in 2011, provides a comprehensive framework for US banking organizations to manage risks associated with quantitative models. It emphasizes robust governance, validation, and monitoring to mitigate potential financial loss or reputational damage from incorrect or misused models. Crucially, this principles-based guidance has been extended to cover AI and Machine Learning systems, establishing a foundational regulatory backbone for AI governance in the financial sector.
Full article
Read full text ↗Overview
The Federal Reserve SR 11-7, officially titled “Supervisory Guidance on Model Risk Management,” was jointly issued by the Board of Governors of the Federal Reserve System and the Office of the Comptroller of the Currency (OCC) on April 4, 2011. This foundational guidance provides a comprehensive framework for banking organizations to effectively manage the risks associated with the use of quantitative models in their decision-making processes. The issuance of SR 11-7 stemmed from the recognition of the increasingly critical role that quantitative analysis and models play across a broad spectrum of banking activities, including credit underwriting, valuing investments, measuring risk, managing client assets, and determining capital adequacy. Prior to this guidance, supervisory focus was primarily on model validation; however, SR 11-7 broadened the scope to encompass all aspects of model risk management, from development and implementation to ongoing monitoring and robust governance. It emphasizes that while models can significantly enhance business decisions, they also introduce potential adverse consequences, such as financial loss, poor strategic decision-making, or reputational damage, if they are incorrect or misused. The guidance is principles-based, allowing for proportionality in its application, meaning the rigor and sophistication of model risk management efforts should be commensurate with a bank's overall use of models, their complexity, materiality, and the size and complexity of the bank's operations.
Although initially published in 2011, the principles articulated in SR 11-7 have been explicitly extended and confirmed to apply to Artificial Intelligence (AI) and Machine Learning (ML) systems within the financial sector. The broad definition of a “model” under SR 11-7—as any quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories to process input data into quantitative estimates—is considered sufficiently expansive to include most AI and ML algorithms used in banking operations. This interpretation has been reinforced by subsequent interagency statements and pronouncements from regulatory bodies, underscoring that firms utilizing newer AI techniques are expected to adhere to existing model risk management expectations. Consequently, SR 11-7 serves as a critical regulatory backbone for AI governance in US banking and financial services, requiring institutions to adapt its established framework to the unique characteristics and challenges posed by advanced AI models, including considerations for explainability, bias testing, and continuous performance monitoring.
Definitions
Central to SR 11-7 is its comprehensive definition of a “model.” The guidance defines a model as “a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates”. This definition is deliberately broad to capture a wide array of analytical tools used in banking. A model typically comprises three essential components: an information input component responsible for delivering assumptions and data; a processing component that transforms these inputs into estimates; and a reporting component that translates the resulting estimates into actionable business information. This expansive definition ensures that institutions cannot narrowly interpret what constitutes a “model” to circumvent supervisory expectations, thereby encompassing everything from traditional statistical models to more complex modern systems. For instance, it includes pricing models, risk measurement models, stress testing tools, and, crucially, AI and machine learning systems.
The guidance also clearly defines “model risk” as the potential for adverse consequences arising from decisions based on models that are either incorrect or misused. This risk can manifest in various forms, including financial loss, suboptimal business and strategic decision-making, or damage to a bank's reputation. Model risk can stem from fundamental errors within the model itself, such as incorrect data inputs, flawed logic, or inaccurate formulas, or from the improper application or use of a model beyond its intended scope. SR 11-7 emphasizes that model risk is a form of operational and strategic risk that necessitates structured controls and independent review, much like other types of risk. The guidance further clarifies that model risk increases with greater model complexity, higher uncertainty regarding inputs and assumptions, broader use cases, and a larger potential impact on the bank's operations. Therefore, understanding these definitions is paramount for financial institutions in establishing robust model risk management frameworks that are applicable to both traditional and advanced AI-driven analytical tools.
Governance and Institutional Framework
SR 11-7 establishes a robust governance framework as a cornerstone of effective model risk management (MRM) within banking organizations. This framework mandates clear lines of responsibility and accountability, extending from the board of directors and senior management down to individual model owners and developers. Senior management, either directly or through relevant committees, bears the responsibility for regularly reporting to the board on significant model risks, both from individual models and in the aggregate, and for ensuring compliance with established policies. The board, in turn, is expected to understand the aggregate model risk exposure of the institution. A strong governance structure provides explicit support and direction to risk management functions through well-defined policies, clear procedures, appropriate resource allocation, and mechanisms for evaluating the consistent execution of these policies and procedures. This includes defining roles and responsibilities for all personnel involved in the model lifecycle, from development and implementation to validation and ongoing monitoring.
The institutional framework for MRM, as outlined by SR 11-7, is often conceptualized through the “three lines of defense” model, which remains highly relevant even for AI agents. The first line of defense consists of the business units that develop, implement, and use the models, including AI systems. These units are responsible for managing model risk in their day-to-day operations. The second line of defense is an independent model risk management function, tasked with validating and monitoring models, providing critical analysis, and challenging model assumptions and outputs. This independent validation is crucial for ensuring the conceptual soundness, outcomes analysis, and ongoing performance of models. The third line of defense is internal audit, which provides an independent assessment of the overall MRM framework's effectiveness and compliance. For AI models, this framework necessitates that validation teams possess expertise in both regulatory compliance (e.g., UDAAP, Reg B, Reg Z) and the technical intricacies of AI systems, such as prompt construction and retrieval grounding. Furthermore, institutions are required to maintain a comprehensive model inventory, a register of every in-scope model detailing its purpose, risk tier, validation status, and ownership, which is particularly vital for managing the complex and interconnected nature of AI systems.
Key Focus Areas
SR 11-7 delineates three primary areas of focus for effective model risk management: model development, implementation, and use; model validation; and governance, policies, and controls. In the realm of model development, implementation, and use, the guidance stresses the importance of a disciplined, knowledge-based approach. This involves thorough documentation of the model's purpose, design theory, logic, methodologies, and data sources, including explorations and comparisons of alternative approaches. Model creators must demonstrate that the data used for training and operation is of high quality and suitable for the model's intended purpose. Pre-release and post-release testing are essential to ensure the model performs as expected and to identify any limitations. For AI models, this translates to documenting the use-case baseline, data source records, prompt or model versions, control design, test sets, and implementation sign-off. Decision-makers must understand the limitations of each model and avoid using them in ways inconsistent with their original intent.
The second key focus area is model validation, which is defined as the set of processes and activities designed to verify that models are performing as expected, aligning with their design objectives and business uses. Effective validation helps ensure model soundness, identifies potential limitations and assumptions, and assesses their possible impact. Validation encompasses three core elements: evaluation of conceptual soundness, ongoing monitoring, and outcomes analysis. Conceptual soundness involves assessing the quality of the model's design and construction, reviewing documentation, and scrutinizing the empirical evidence supporting the methods and variables selected. Ongoing monitoring confirms appropriate implementation and performance, evaluating if changes in conditions necessitate model adjustments or redevelopment. Outcomes analysis compares model outputs to actual outcomes, often utilizing back-testing. For AI models, validation requires independent assessment of conceptual soundness, outcomes, ongoing performance, and limitations, often involving benchmark results, exception analysis, challenger model reviews, and a weakness log. The third area, governance, policies, and controls, ensures a robust oversight structure, as detailed in the previous section, including a comprehensive model inventory, defined roles, and senior management and board accountability.
Implementation Framework
The implementation framework for SR 11-7 emphasizes a structured and systematic approach to integrating model risk management throughout a banking organization's operations. It requires institutions to develop and maintain an MRM framework approved by the Board and managed by senior management, which includes regular reporting and oversight to ensure ongoing compliance. This framework is not a one-size-fits-all solution; rather, the rigor and sophistication of MRM efforts must be commensurate with the bank's overall model usage, the complexity and materiality of its models, and the size and complexity of its operations. For smaller banks with fewer and less complex models, a more streamlined MRM program may be appropriate compared to larger institutions with extensive and intricate model portfolios. The guidance encourages a proactive approach to identifying, assessing, and mitigating model risk, treating it akin to other types of risk. This involves identifying sources of risk, assessing their magnitude, and considering both individual model risk and the aggregate risk posed by all models in use, including interdependencies and reliance on common assumptions or data.
A critical component of the implementation framework is the concept of “effective challenge,” which is considered a guiding principle for most risk management frameworks. Effective challenge entails critical analysis of models by objective, informed, and technically competent parties who can identify model limitations and assumptions and propose appropriate changes to mitigate identified risks. This principle should be applied across the entire model lifecycle, from development and validation to ongoing monitoring. For AI models, the implementation framework necessitates adapting these principles to the unique characteristics of AI, such as the need for specialized expertise in AI validation and the integration of AI-specific risk management tools. This includes maintaining a complete AI system inventory with ownership, purpose, use, limitations, materiality flags, dependency maps, and approval states. Furthermore, the framework requires robust documentation standards, covering model design, data, assumptions, limitations, and implementation controls, which is particularly vital for the transparency and explainability of complex AI systems. The implementation framework also extends to third-party risk management, requiring banks to identify and assess risks associated with third-party models and applications, ensuring they meet internal standards and that the integrity and applicability of external information sources are regularly analyzed.
Monitoring and Evaluation
Ongoing monitoring is a critical element of SR 11-7's model validation framework, designed to confirm that models, including AI systems, are appropriately implemented, used, and performing as intended over time. This continuous oversight is essential to detect any deterioration in model performance, identify emerging risks, and ensure that models remain fit for purpose in dynamic business and market environments. Monitoring activities involve regular checks to evaluate whether changes in products, exposures, activities, clients, or market conditions necessitate adjustments, redevelopment, or even replacement of the model. It also verifies that any extension of a model beyond its original scope is valid and appropriately managed. For AI and machine learning models, ongoing monitoring takes on heightened importance due to their adaptive nature and potential for concept drift, requiring continuous evaluation of performance, robustness, and fairness metrics in real-time production environments.
Evaluation within the SR 11-7 framework also includes outcomes analysis, which involves systematically comparing model outputs to corresponding actual outcomes. Back-testing is a common form of outcomes analysis, where actual outcomes are compared with model forecasts over a sample time period not used in model development, at a frequency matching the model's forecast horizon or performance window. Benchmarking, comparing a given model's inputs and outputs to estimates from alternative models or industry standards, can also be used to assess performance and identify potential weaknesses. For AI models, this includes rigorous performance benchmarking, ongoing monitoring of false positive and false negative rates, and robust drift detection mechanisms. The monitoring and evaluation processes must be well-documented, with results regularly reported to senior management and the board, facilitating informed decision-making and timely remediation of any identified issues. The goal is to ensure that the model risk management program remains effective and responsive to both internal changes within the institution and external shifts in the regulatory and operational landscape.
Penalties, Liability, and Appeals
While SR 11-7 itself is supervisory guidance rather than a statute, non-compliance with its principles can lead to significant adverse consequences for banking organizations. The Federal Reserve and OCC, as supervisory bodies, have the authority to impose various enforcement actions when institutions fail to adequately manage model risk. These actions can range from formal agreements and cease-and-desist orders to civil money penalties, depending on the severity and persistence of the deficiencies. Model-related enforcement actions frequently cite SR 11-7 as the governing framework, underscoring its importance as a de facto industry standard. The potential for financial loss, poor business and strategic decisions, or damage to a bank's reputation due to flawed or misused models constitutes the core of “model risk,” which the guidance aims to mitigate. Therefore, inadequate model risk management directly exposes institutions to these adverse outcomes, which can be far more costly than direct regulatory fines.
In the context of AI, the implications for liability and penalties become even more complex and potentially magnified. While SR 11-7 does not explicitly detail AI-specific liability frameworks, its principles of accountability and oversight apply directly to AI systems. If an AI model, due to fundamental errors, bias, or misuse, leads to discriminatory outcomes (e.g., in lending decisions under the Equal Credit Opportunity Act), significant legal and reputational liabilities can arise, including consumer protection penalties and lawsuits. The guidance emphasizes that senior management and the board are ultimately accountable for overseeing model risk management activities, meaning they bear responsibility for ensuring that models, including AI, are sound and properly governed. While the guidance does not outline a formal appeals process, institutions typically engage in ongoing dialogue with their supervisors to address findings and demonstrate remediation efforts. The focus is on proactive management and continuous improvement of the MRM framework to prevent issues that could lead to enforcement actions, especially as AI models introduce new dimensions of risk such as explainability, fairness, and robustness that were not explicitly covered in the original 2011 guidance but are now considered under its broader principles.
Relationship to Other Instruments
SR 11-7 does not exist in isolation but is part of a broader regulatory ecosystem governing financial institutions in the United States. It was jointly issued with the Office of the Comptroller of the Currency (OCC) as OCC Bulletin 2011-12, effectively establishing a unified standard for model risk management across national banks, state member banks, and bank holding companies. The Federal Deposit Insurance Corporation (FDIC) subsequently adopted parallel guidance through FIL-22-2017 in 2017, extending the same standards to state non-member banks. This ensures that virtually every federally regulated U.S. bank operates under consistent expectations regarding model governance, validation, and oversight. Furthermore, SR 11-7 built upon and replaced earlier guidance, such as OCC Bulletin 2000-16, by broadening the scope of model risk management beyond just validation to encompass the entire model lifecycle and governance.
The principles of SR 11-7 also interact with and underpin other significant regulatory frameworks. For instance, regulations like Basel II & III, ICAAP, SCAP, CCAR, and DFAST, which involve stress testing and capital adequacy assessments, heavily rely on models that fall under the purview of SR 11-7's risk management requirements. In the context of AI, the Federal Reserve, FDIC, and OCC issued an interagency statement in April 2021 specifically addressing model risk management for AI and ML systems supporting Bank Secrecy Act/Anti-Money Laundering (BSA/AML) compliance, confirming that SR 11-7 principles apply to these systems. More recently, in April 2026, the OCC, Federal Reserve, and FDIC jointly issued updated interagency model risk management guidance. This revised guidance formally rescinds OCC Bulletin 2011-12 and SR 11-7 for banks covered by the new document, while maintaining the core principles of its predecessor but introducing a more explicit risk-based approach and a narrower definition of “model”. Notably, the 2026 guidance explicitly excludes generative and agentic AI models from its scope, with additional guidance planned, highlighting the evolving regulatory landscape for advanced AI. Despite these updates, the fundamental tenets of SR 11-7, particularly regarding independent validation, documentation, and board-level governance, remain highly influential and foundational for AI governance in banking. Additionally, the National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF) has been adopted by the Federal Reserve as a reference for AI governance, filling in gaps that SR 11-7, written before the widespread adoption of advanced AI, was not built to cover, such as bias, robustness, explainability, and human oversight for non-quantitative models.
International Alignment
While SR 11-7 is a U.S.-specific supervisory guidance, its principles for model risk management resonate with and have influenced similar regulatory developments internationally. The increasing reliance on quantitative models in financial decision-making is a global phenomenon, and the risks associated with these models are universal. Consequently, other prudential regulators worldwide have introduced their own guidance and frameworks that align with many of the core tenets of SR 11-7, particularly regarding the need for robust model validation, comprehensive governance, and continuous monitoring. This reflects a global consensus on the importance of managing model risk to ensure financial stability and protect consumers.
Examples of such international alignment include the Prudential Regulation Authority (PRA) at the Bank of England's Supervisory Statement 3/18 (SS 3/18) on model risk management for stress testing, issued in April 2018. Similarly, the European Central Bank (ECB) released its Guide to Internal Models (TRIM) in February 2017 and updated it in October 2019, which provides detailed expectations for the development, validation, and governance of internal models used by banks under its supervision. Canada's Office of the Superintendent of Financial Institutions (OSFI) also issued Guideline E-23 on Model Risk Management in September 2017. These international frameworks, while tailored to their respective jurisdictions, share common themes with SR 11-7, such as emphasizing independent validation, comprehensive documentation, clear roles and responsibilities, and proportionality in application based on model materiality and complexity. This convergence of regulatory approaches highlights a global effort to establish sound practices for managing model risk, which increasingly includes the risks posed by advanced AI and machine learning models in the financial sector.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| SR 11-7 Issued by Federal Reserve and OCC | 2011-04-04 | Established comprehensive guidance on model risk management. |
| FDIC Adopts Parallel Guidance (FIL-22-2017) | 2017-06-07 | Extended SR 11-7 principles to state non-member banks. |
| Interagency Statement on BSA/AML AI/ML Systems | 2021-04-01 | Confirmed applicability of SR 11-7 principles to AI/ML for BSA/AML compliance. |
| Federal Reserve Vice Chair Confirms SR 11-7 Applies to AI | 2023-01-01 | Stated firms using newer AI techniques are expected to comply with existing MRM expectations. |
| OCC Revised MRM Guidance Issued (Rescinding SR 11-7 for some) | 2026-04-01 | New interagency guidance issued, rescinding SR 11-7 for banks covered by the new document, but maintaining core principles. Excludes generative AI for now. |
Sources and References
| Source | Type |
|---|---|
| Supervisory Guidance on Model Risk Management (SR 11-7) | government |
| SR 11-7 Attachment: Supervisory Guidance on Model Risk Management | government |
| FIL-22-2017: Adoption of Supervisory Guidance on Model Risk Management (FDIC) | government |
| OCC Bulletin 2011-12: Supervisory Guidance on Model Risk Management | government |
Requirements for a company
What an organisation has to do under Supervisory Guidance on Model Risk Management, at a glance. Not legal advice.
Related Regulations
Singapore - AI Model Risk Management
Singapore86% similar
Switzerland - AI Governance Guidelines (08/2024)
Switzerland86% similar
United States - AI Risk Management Framework
United States86% similar
Canada - Model Risk Management (E-23)
Canada85% similar
NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers
United States85% similar
More AI regulation in United States
AI regulation in United States: full overview
- Guides Concerning the Use of Endorsements and Testimonials in Advertising
- NIST Generative AI Risk Profile
- US AI Tax and Worker Protection Bill
- AI PLAN Act: Combating AI Financial Crimes
- Healthy Technology Act
- AI Accountability Act
- US AI Kill Switch Bill for Rogue Systems
- GUARDRAILS Act: Repealing Federal AI Policy
© Regulations.AI — created on 20 May 2026 using Gemini 2.5 Flash · updated on 13 Jun 2026 · reviewed against official sources on 9 Sep 2026