Skip to content
RiskTemplates · The Daily Brief Saturday, August 22, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Feature Regulatory Compliance

OCC Bulletin 2026-13: What the Revised Model Risk Guidance Means for Banks

The agencies issued revised, risk-based model risk guidance. Here is what changed, what did not, and how to oversee third-party models.

By Rebecca Leung · April 28, 2026 ·
Table of Contents

On April 17, 2026, the OCC, Federal Reserve, and FDIC issued revised interagency guidance on model risk management. The central change is a clearer risk-based, tailored framework: practices should reflect a model’s inherent risk, materiality, purpose, use, and the size and complexity of the banking organization.

The guidance is not an enforceable rule. It also is not a promise that model-risk deficiencies cannot be criticized. The agencies expressly preserve supervisory action for violations of law and unsafe or unsound practices stemming from insufficient management of model risk.

August 17, 2026 correction

Several status points are easy to overstate:

  • Agency actions differed. The OCC rescinded OCC Bulletins 2011-12, 2021-19, and 1997-24, plus the Comptroller’s Handbook booklet on model risk management. The Federal Reserve said SR 26-2 supersedes SR 11-7 and SR 21-8. The FDIC rescinded FIL-22-2017.
  • The guidance is nonbinding, not irrelevant. It says noncompliance will not result in supervisory criticism, while its footnote preserves action for unsafe or unsound practices and violations of law.
  • Generative and agentic AI are outside this document, not outside governance. The agencies direct banks to use broader risk-management and governance practices for tools, processes, or systems not covered by the guidance.
  • Third-party controls are risk-based. The guidance offers ways to address limits on access to proprietary vendor information; it does not require every contract to contain identical audit, source-code, or validation clauses.

Scope and the definition of a model

For this guidance, a model is a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to input data to produce quantitative estimates. It excludes simple arithmetic calculations, such as those in spreadsheets, and deterministic rule-based processes or software without statistical, economic, or financial theories underpinning their design or use.

That does not mean every spreadsheet or rules engine can be deleted from risk inventories. A tool outside this guidance can still create operational, compliance, financial-reporting, or other risk. Classify it under the right control framework and document why it is not treated as a model for this guidance.

The agencies expect the guidance to be most relevant to organizations with more than $30 billion in total assets. Smaller organizations may still find it relevant when their model exposure is significant because of model prevalence, complexity, or activities outside traditional community banking.

The risk-based framework

The guidance connects the rigor of model risk management to several related concepts:

  • Inherent risk: assumptions, complexity, input quality, and data constraints.
  • Exposure: the significance of model output to business decisions.
  • Purpose: the nature and importance of the model’s use.
  • Materiality: the interaction of purpose and exposure.
  • Aggregate risk: dependencies across models, common data, methodologies, and assumptions.

A lower-materiality model may warrant identification, monitoring, and triggers for reassessment. A higher-materiality model warrants more comprehensive development, validation, monitoring, governance, and challenge.

What remains important

The revised guidance continues to emphasize:

Development and use

A sound development process starts with a clear purpose, aligns design and testing to intended use, evaluates data and assumptions, and documents limitations. Use beyond the original purpose can add uncertainty and should prompt additional analysis and control review.

Validation and monitoring

Validation should evaluate reliability and limitations with rigor proportionate to approach, use, and materiality. Ongoing monitoring should assess performance as conditions change and escalate material deterioration, misuse, overrides, or limitations.

Effective challenge

The guidance retains the concept of effective challenge by people with expertise, sufficient independence to remain objective, and enough organizational standing to drive change. It does not prescribe one universal reporting line or cadence.

Governance

Policies, roles, issue management, reporting, internal audit, and senior-management and board oversight should be proportionate to the organization’s model risk. Tailoring requires a reasoned basis; it is not a reason to leave decisions undocumented.

Generative and agentic AI

A footnote states that generative AI and agentic AI are not within the guidance because they are novel and rapidly evolving. The same footnote says a banking organization’s risk management and governance should guide controls for systems outside the document.

A defensible AI inventory therefore distinguishes:

  1. traditional statistical or quantitative models and non-generative, non-agentic AI that meet the model definition;
  2. generative or agentic systems outside this guidance but subject to broader governance; and
  3. deterministic or simple tools governed under other risk frameworks.

For the second category, practical controls may include approved use cases, data and security restrictions, testing, human oversight, change management, output monitoring, incident escalation, and vendor oversight. Do not treat the scope exclusion as a conclusion that there is no supervisory, legal, or operational risk.

August 17 update: third-party model oversight

The guidance says banking organizations should conduct appropriate due diligence before acquiring a third-party model and perform ongoing monitoring. The level of work should reflect the model’s use, complexity, materiality, and risk.

Proprietary restrictions can make validation harder. The agencies identify several ways to respond, including:

  • asking for developmental evidence, test results, performance information, and documentation needed for validation;
  • considering independent third-party reviews or validation reports;
  • testing the model against the bank’s own data and outcomes;
  • monitoring limitations, overrides, drift, and material changes; and
  • establishing contingency plans when adequate support is unavailable.

The guidance also notes that a bank may negotiate contractual rights to information. Depending on risk, useful terms can include documentation access, validation support, notice of material changes, audit cooperation, performance reporting, and exit assistance. These are implementation tools—not proof that the guidance mandates the same clause for every provider or guarantees access to proprietary source code.

A practical implementation sequence

1. Map the agency-specific change

Update citations accurately. Do not say the OCC rescinded a Federal Reserve letter or that the Federal Reserve rescinded an OCC bulletin.

2. Reassess inventory boundaries

Apply the revised definition consistently. Preserve the rationale, reviewer, affected tools, and the control framework used for anything moved outside the formal model inventory.

3. Recalibrate by risk

For each model, connect development, validation, monitoring, issue management, and review frequency to inherent risk and materiality. A risk-based cadence should have documented triggers for earlier review.

4. Review third-party evidence

Identify vendor models where the bank lacks enough information to understand purpose, limitations, performance, and change. Escalate material gaps and align contract changes to actual risk.

5. Maintain a separate AI governance view

Track generative and agentic systems even though they are outside this guidance. Record why each system is classified as it is and which controls govern it.

Bottom line

OCC Bulletin 2026-13 and the parallel agency issuances replace the prior model risk guidance with a less prescriptive, more explicitly tailored approach. They do not eliminate model risk management, effective challenge, validation, monitoring, or third-party responsibility. The immediate task is to document proportionate choices—and to preserve broader governance for AI and other tools outside the guidance’s definition.


Primary sources:

This article is for general informational purposes and is not legal advice. Confirm applicability and supervisory expectations with counsel and the appropriate agency.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is OCC Bulletin 2026-13?
OCC Bulletin 2026-13 is the OCC's April 17, 2026 issuance of revised interagency model risk management guidance. The guidance uses a risk-based approach tailored to a banking organization's model risk profile, size, and complexity. It does not set enforceable standards, but violations of law or unsafe or unsound practices can still lead to supervisory action.
Does the guidance cover AI and generative AI?
Traditional statistical and quantitative models and non-generative, non-agentic AI models can be in scope. Generative AI and agentic AI are outside this guidance because their risks are evolving, but the agencies say a bank's broader risk management and governance should determine appropriate controls for tools outside the document.
Did all three agencies rescind SR 11-7?
No. Each agency acted through its own issuance. The OCC rescinded specified OCC bulletins and a handbook booklet; the Federal Reserve said SR 26-2 supersedes SR 11-7 and SR 21-8; and the FDIC rescinded FIL-22-2017. The result is common revised interagency guidance, but the agency-specific actions should not be collapsed into one statement.
Which banks are in scope?
The agencies say the guidance is expected to be most relevant to banking organizations with more than $30 billion in total assets. It may also be relevant to smaller organizations with significant model-risk exposure because of the prevalence or complexity of their models or nontraditional activities.
What should a bank require from a third-party model provider?
The guidance supports risk-based due diligence, validation, and ongoing monitoring. Depending on risk, a bank may seek developmental evidence, testing and performance information, independent reviews, change notices, data or documentation access, and contingency support. Those are proportionate controls, not a universal source-code, audit-right, or contract-clause mandate.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.