Feature Regulatory Compliance
OCC Bulletin 2026-13: What the Revised Model Risk Guidance Means for Banks
The agencies issued revised, risk-based model risk guidance. Here is what changed, what did not, and how to oversee third-party models.
Table of Contents
On April 17, 2026, the OCC, Federal Reserve, and FDIC issued revised interagency guidance on model risk management. The central change is a clearer risk-based, tailored framework: practices should reflect a model’s inherent risk, materiality, purpose, use, and the size and complexity of the banking organization.
The guidance is not an enforceable rule. It also is not a promise that model-risk deficiencies cannot be criticized. The agencies expressly preserve supervisory action for violations of law and unsafe or unsound practices stemming from insufficient management of model risk.
August 17, 2026 correction
Several status points are easy to overstate:
- Agency actions differed. The OCC rescinded OCC Bulletins 2011-12, 2021-19, and 1997-24, plus the Comptroller’s Handbook booklet on model risk management. The Federal Reserve said SR 26-2 supersedes SR 11-7 and SR 21-8. The FDIC rescinded FIL-22-2017.
- The guidance is nonbinding, not irrelevant. It says noncompliance will not result in supervisory criticism, while its footnote preserves action for unsafe or unsound practices and violations of law.
- Generative and agentic AI are outside this document, not outside governance. The agencies direct banks to use broader risk-management and governance practices for tools, processes, or systems not covered by the guidance.
- Third-party controls are risk-based. The guidance offers ways to address limits on access to proprietary vendor information; it does not require every contract to contain identical audit, source-code, or validation clauses.
Scope and the definition of a model
For this guidance, a model is a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to input data to produce quantitative estimates. It excludes simple arithmetic calculations, such as those in spreadsheets, and deterministic rule-based processes or software without statistical, economic, or financial theories underpinning their design or use.
That does not mean every spreadsheet or rules engine can be deleted from risk inventories. A tool outside this guidance can still create operational, compliance, financial-reporting, or other risk. Classify it under the right control framework and document why it is not treated as a model for this guidance.
The agencies expect the guidance to be most relevant to organizations with more than $30 billion in total assets. Smaller organizations may still find it relevant when their model exposure is significant because of model prevalence, complexity, or activities outside traditional community banking.
The risk-based framework
The guidance connects the rigor of model risk management to several related concepts:
- Inherent risk: assumptions, complexity, input quality, and data constraints.
- Exposure: the significance of model output to business decisions.
- Purpose: the nature and importance of the model’s use.
- Materiality: the interaction of purpose and exposure.
- Aggregate risk: dependencies across models, common data, methodologies, and assumptions.
A lower-materiality model may warrant identification, monitoring, and triggers for reassessment. A higher-materiality model warrants more comprehensive development, validation, monitoring, governance, and challenge.
What remains important
The revised guidance continues to emphasize:
Development and use
A sound development process starts with a clear purpose, aligns design and testing to intended use, evaluates data and assumptions, and documents limitations. Use beyond the original purpose can add uncertainty and should prompt additional analysis and control review.
Validation and monitoring
Validation should evaluate reliability and limitations with rigor proportionate to approach, use, and materiality. Ongoing monitoring should assess performance as conditions change and escalate material deterioration, misuse, overrides, or limitations.
Effective challenge
The guidance retains the concept of effective challenge by people with expertise, sufficient independence to remain objective, and enough organizational standing to drive change. It does not prescribe one universal reporting line or cadence.
Governance
Policies, roles, issue management, reporting, internal audit, and senior-management and board oversight should be proportionate to the organization’s model risk. Tailoring requires a reasoned basis; it is not a reason to leave decisions undocumented.
Generative and agentic AI
A footnote states that generative AI and agentic AI are not within the guidance because they are novel and rapidly evolving. The same footnote says a banking organization’s risk management and governance should guide controls for systems outside the document.
A defensible AI inventory therefore distinguishes:
- traditional statistical or quantitative models and non-generative, non-agentic AI that meet the model definition;
- generative or agentic systems outside this guidance but subject to broader governance; and
- deterministic or simple tools governed under other risk frameworks.
For the second category, practical controls may include approved use cases, data and security restrictions, testing, human oversight, change management, output monitoring, incident escalation, and vendor oversight. Do not treat the scope exclusion as a conclusion that there is no supervisory, legal, or operational risk.
August 17 update: third-party model oversight
The guidance says banking organizations should conduct appropriate due diligence before acquiring a third-party model and perform ongoing monitoring. The level of work should reflect the model’s use, complexity, materiality, and risk.
Proprietary restrictions can make validation harder. The agencies identify several ways to respond, including:
- asking for developmental evidence, test results, performance information, and documentation needed for validation;
- considering independent third-party reviews or validation reports;
- testing the model against the bank’s own data and outcomes;
- monitoring limitations, overrides, drift, and material changes; and
- establishing contingency plans when adequate support is unavailable.
The guidance also notes that a bank may negotiate contractual rights to information. Depending on risk, useful terms can include documentation access, validation support, notice of material changes, audit cooperation, performance reporting, and exit assistance. These are implementation tools—not proof that the guidance mandates the same clause for every provider or guarantees access to proprietary source code.
A practical implementation sequence
1. Map the agency-specific change
Update citations accurately. Do not say the OCC rescinded a Federal Reserve letter or that the Federal Reserve rescinded an OCC bulletin.
2. Reassess inventory boundaries
Apply the revised definition consistently. Preserve the rationale, reviewer, affected tools, and the control framework used for anything moved outside the formal model inventory.
3. Recalibrate by risk
For each model, connect development, validation, monitoring, issue management, and review frequency to inherent risk and materiality. A risk-based cadence should have documented triggers for earlier review.
4. Review third-party evidence
Identify vendor models where the bank lacks enough information to understand purpose, limitations, performance, and change. Escalate material gaps and align contract changes to actual risk.
5. Maintain a separate AI governance view
Track generative and agentic systems even though they are outside this guidance. Record why each system is classified as it is and which controls govern it.
Bottom line
OCC Bulletin 2026-13 and the parallel agency issuances replace the prior model risk guidance with a less prescriptive, more explicitly tailored approach. They do not eliminate model risk management, effective challenge, validation, monitoring, or third-party responsibility. The immediate task is to document proportionate choices—and to preserve broader governance for AI and other tools outside the guidance’s definition.
Primary sources:
- OCC Bulletin 2026-13: Model Risk Management—Revised Guidance
- Interagency Supervisory Guidance on Model Risk Management (April 17, 2026 PDF)
- Federal Reserve SR 26-2: Revised Guidance on Model Risk Management
- FDIC FIL-16-2026: Agencies Revise the Interagency Model Risk Management Guidance
This article is for general informational purposes and is not legal advice. Confirm applicability and supervisory expectations with counsel and the appropriate agency.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is OCC Bulletin 2026-13?
Does the guidance cover AI and generative AI?
Did all three agencies rescind SR 11-7?
Which banks are in scope?
What should a bank require from a third-party model provider?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
Regulatory Compliance
How to Test a Bank CIP: Sampling, Evidence, Exceptions, and Conclusions
Customer identification program testing that covers population completeness, CIP attributes, evidence, exceptions, and defensible workpaper conclusions.
Aug 21, 2026
Regulatory Compliance
SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed
The SEC's Tricolor fraud case alleges $1.9B in ABS offerings and an $800M collateral hole. Here are the controls lenders should test now.
Aug 21, 2026
Regulatory Compliance
CFP Activation and Override Decision Record: Trigger, Funding Choice, Approval, and Review Evidence
Your contingency funding plan's weakest link isn't the trigger framework—it's the decision record. Here's what examiners expect to see when your CFP gets pulled during a review, and how to document activation, non-activation, and overrides contemporaneously.
Aug 19, 2026