Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

OCC Bulletin 2026-13: What Changed from SR 11-7 and the 7-Item Update Checklist for Your MRM Program

The federal banking agencies replaced SR 11-7 with OCC Bulletin 2026-13 and SR 26-02 in April 2026. Here's what changed in validation, independence, and community bank expectations — plus the GenAI exclusion that creates a compliance gap your MRM team can't afford to ignore.

By Rebecca Leung · June 9, 2026 ·
Table of Contents

TL;DR

  • OCC Bulletin 2026-13 / SR 26-02 (April 17, 2026) replaced SR 11-7 and OCC 2011-12 — the most significant model risk management guidance update in 15 years
  • Risk-based proportionality replaces implied annual validation requirements; community banks get meaningful relief
  • Simplified validation: three core components retained, prescriptive detail on VaR backtesting and code verification removed
  • Independence emphasis softened: rigor and effectiveness of review matters more than organizational structure
  • GenAI explicitly excluded from scope — agencies promised a separate AI RFI that hasn’t landed as of June 2026
  • 7-item update checklist: policy citations, risk tiering, validation cadence, effective challenge documentation, vendor model parity, GenAI gap, board briefing

On April 17, 2026, the OCC issued Bulletin 2026-13 and the Federal Reserve issued SR 26-02, finally replacing SR 11-7 — the model risk management guidance that had governed bank MRM programs since 2011. Fifteen years of SR 11-7 citations. Policy frameworks built around it. Validation standards derived from it. Replaced with a shorter, more principles-based document that is explicitly less prescriptive than what came before.

For MRM teams, this creates two immediate questions. What actually changed, and what do you need to update? And for banks deploying AI and generative models, a more uncomfortable question: what does it mean that the new guidance specifically excludes GenAI from scope?

Let me walk through both.

What Was Rescinded

The April 17 issuance formally rescinded:

  • SR 11-7 (Federal Reserve, 2011) — the original model risk management guidance
  • OCC Bulletin 2011-12 — OCC’s version of SR 11-7
  • OCC Bulletin 2021-19 — subsequent OCC model risk updates
  • FIL-22-2017 — the FDIC’s equivalent issuance

Any internal policy, procedure, board charter, or vendor contract that cites these documents by number now references rescinded guidance. That’s not just a citation cleanup exercise — it’s a signal to examiners that your program hasn’t been reviewed since the guidance update. This is the first item on the checklist because it’s visible in documentation reviews and it’s easy to address.

The Three Biggest Changes from SR 11-7

1. Risk-Based Proportionality Replaces the Implied Annual Cadence

SR 11-7 created a de facto expectation of annual model validation across the banking system, regardless of institution size or model complexity. Community banks with straightforward credit scoring models built validation programs that mirrored what large, systemically important banks needed for complex derivative pricing and stress testing models. The compliance cost was real and the risk-management benefit was marginal.

OCC 2026-13 resets this explicitly. The guidance states it is “expected to be most relevant to banking organizations with over $30 billion in total assets” while simultaneously noting it applies to all institutions with material model risk. The key shift: annual model validation is not required. Validation frequency should be commensurate with model risk — more frequent for high-risk, high-complexity models; less frequent for stable, lower-impact models with strong track records.

For community banks, the practical analysis is straightforward: if you’re running FICO-based credit scoring, a vendor-provided CECL tool, and basic deposit pricing models, you don’t need an annual validation cycle for each. Document the risk-based rationale for your validation schedule, focus resources on models with the highest financial and customer impact, and you’re in compliance with the new guidance.

For larger institutions: the $30B threshold is directional, not exempting. A $5B bank with significant model usage in credit decisioning, CECL, BSA/AML transaction monitoring, and liquidity stress testing still needs robust MRM governance. The variable is model risk exposure, not asset size.

2. Simplified Validation Framework

SR 11-7 retained three core validation components — conceptual soundness, outcomes analysis, and ongoing monitoring — and OCC 2026-13 keeps all three. What changed is the prescriptive detail around each.

SR 11-7 included specific guidance on VaR backtesting methodology, parallel outcomes analysis procedures, computer code verification requirements, override analysis standards, and benchmarking approaches. OCC 2026-13 replaced this prescriptive list with the principle that validation approaches “may differ across models based on their characteristics and use.”

Validation ComponentSR 11-7 TreatmentOCC 2026-13 Treatment
Conceptual soundnessDetailed review requirements, theoretical basis documentationReview of design choices and assumptions — methodology proportionate to model complexity
Outcomes analysisVaR backtesting specifics, parallel run requirementsComparison to actual outcomes or benchmarks — form depends on model characteristics
Ongoing monitoringEarly warning metrics, process verification of computer codeAppropriateness assessment over time — risk-based monitoring cadence

The practical implication: validation reports don’t need to work through a 15-year-old checklist. They need to demonstrate that the model was assessed for conceptual soundness, that outputs were evaluated against actual outcomes or benchmarks, and that monitoring is appropriate for the model’s risk profile. The documentation can be proportionate to the risk.

3. De-Emphasized Validation Independence

The Orrick analysis of the guidance overhaul called this the most notable change, and it’s the right call. SR 11-7 devoted substantial space to validation independence — reporting lines, compensation practices, separation from model development teams. The implication was that specific organizational structures were necessary to achieve meaningful challenge.

OCC 2026-13’s language is notably different: “The quality of the validation process depends on the rigor and effectiveness of the review rather than on organizational structure.”

This doesn’t eliminate the independence expectation. The guidance still states that effective challenge requires “appropriate expertise, sufficient independence to permit objectivity, and organizational standing and influence to effect change when appropriate.” What it removes is the emphasis on how that independence is structured.

For community banks and mid-size institutions that used third-party validation as their primary independence mechanism, this is clarifying — the rigor of the review, not the org chart, determines whether challenge is effective. For large institutions, a formally structured independent validation function still serves the risk management purpose well; the guidance change doesn’t require restructuring programs that are working.

What Stayed the Same

The fundamentals didn’t change:

  • Model inventory — every quantitative tool used in consequential decision-making should be inventoried and risk-tiered
  • Board and senior management oversight — board awareness of material model risk and governance responsibilities remains expected
  • Vendor/third-party model parity — the same rigor applied to in-house models applies to vendor-supplied models; the Sullivan & Cromwell analysis highlights this as an area where banks have historically underinvested
  • Documentation through model lifecycle — development, validation, deployment, modification, and retirement all require documentation commensurate with model risk

The GenAI Exclusion: The Gap That OCC 2026-13 Left Behind

Right in the scope section of OCC 2026-13, the agencies carved out generative AI and agentic AI. The bulletin states these technologies are “novel and rapidly evolving” and outside the guidance scope, with a commitment to release an AI-specific request for information “in the near future.”

It is now June 2026. That RFI has not been published.

This creates a governance gap that is neither small nor comfortable. Banks are deploying large language models — for customer service chatbots, compliance assistance, model validation support, board report drafting, and internal knowledge management. None of these deployments fall under OCC 2026-13 scope. All of them face examiner scrutiny.

The agencies addressed the gap with a sentence: banking organizations should apply “broader risk management and governance practices” to GenAI tools not covered by the guidance. That sentence is doing real work. “Excluded from scope” is not a governance pass — it means your GenAI program needs to be governed by your existing risk infrastructure until the formal framework arrives.

We’ve covered the interim governance framework in detail in The GenAI Model Risk Gap. The short version: NIST AI 600-1 and the FS AI RMF’s 230 control objectives provide structured governance that addresses the categories examiners are most likely to focus on. Build the parallel GenAI governance program now, so you’re calibrating when the formal RFI drops rather than starting from scratch under scrutiny.

The 7-Item OCC 2026-13 Update Checklist

Here is the practical update list for MRM teams and compliance officers working through this guidance change:

#UpdatePriorityWhy It Matters
1Update all internal documents citing SR 11-7 / OCC 2011-12 / OCC 2021-19HighStale citations are visible in documentation reviews; board and risk committee charters need to reference current guidance
2Document risk-based rationale for validation frequency by model tierHighNew guidance relieves the implied annual cadence; document the risk-based justification for your schedule
3Review model inventory completeness and risk tieringHighRisk-based approach requires knowing which models are High, Medium, Low risk — the inventory drives everything else
4Update effective challenge documentation to emphasize rigor over structureMediumIndependence language shifted; your MRM policy shouldn’t still cite SR 11-7’s org structure requirements as the standard
5Confirm vendor/third-party model oversight parityMediumSame rigor as in-house is explicit; request validation evidence from key model vendors and document the oversight activities
6Build separate GenAI governance documentationHighGenAI is excluded from OCC 2026-13 scope but not from examiner expectations; the governance gap needs to be filled before the AI RFI lands
7Brief board and risk committee on the guidance changeMediumBoard oversight expectations remain; a brief documentation of the update and program impact demonstrates governance awareness

The Exam Lens: What “Noncompliance Won’t Result in Criticism” Actually Means in Practice

OCC 2026-13 is explicit: it does not establish enforceable standards, and “noncompliance alone will not result in supervisory criticism.” This is important — it’s guidance, not a rule. An examiner cannot issue a citation for failing to follow non-mandatory guidance the way they can for violating a regulation.

But examiners evaluate MRM programs against the principles in this guidance as part of routine examination. The Databricks practitioner analysis frames it correctly: the practical exam question is still “is your model risk management program commensurate with your model risk exposure?” Banks with no model inventory, no validation documentation, and no governance structure get MRA attention regardless of the guidance’s non-mandatory status.

OCC 2026-13 reshapes how you answer the commensurate question. Risk-based. Proportionate. Principles-driven. And with an explicit GenAI carveout that creates a parallel compliance obligation your MRM team inherits.

The SR 11-7 baseline we covered in 2026 is now the foundation to build from rather than the active standard to comply with. The update is substantial enough to warrant a formal MRM program review this quarter.

So What?

OCC 2026-13 is genuinely good news for most organizations. Less prescriptive validation requirements. Community bank proportionality relief. Independence based on rigor rather than org charts. The 15-year-old guidance that had accumulated layers of interpretation and industry practice has been replaced with something shorter and more flexible.

The catch: the principles still require real governance. The simplified framework still requires a model inventory, risk tiering, documented validation, and meaningful challenge. And the GenAI exclusion isn’t a pass — it’s a governance gap that your MRM team now owns.

If your AI governance program needs to cover both the traditional model risk management transition to OCC 2026-13 and the GenAI infrastructure that sits outside formal guidance, the AI Risk Assessment Template & Guide covers the model inventory framework, pre-deployment assessment, vendor AI questionnaire, and governance documentation — the artifacts that apply to both traditional models under 2026-13 and GenAI tools where the formal framework hasn’t arrived yet.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Did OCC Bulletin 2026-13 fully replace SR 11-7?
Yes. OCC Bulletin 2026-13, issued April 17, 2026, formally rescinded OCC Bulletin 2011-12 (the OCC's implementation of SR 11-7), OCC Bulletin 2021-19, and related issuances. The Federal Reserve issued SR 26-02 simultaneously as its parallel replacement for SR 11-7. Any internal policy that cites SR 11-7 or OCC 2011-12 by document number now references rescinded guidance.
Does OCC 2026-13 apply to community banks?
Yes, with important scaling. The guidance is 'expected to be most relevant to banking organizations with over $30 billion in total assets' but explicitly applies to all OCC-supervised institutions with material model risk exposure. For community banks, the practical relief is that annual model validation is not required — validation frequency should be commensurate with model risk. Focus resources on models that most directly impact operations and credit decisions.
What happened to the validation independence requirements from SR 11-7?
OCC 2026-13 significantly softened the independence emphasis. SR 11-7 devoted extensive guidance to reporting-line separation and compensation practices. OCC 2026-13 states that 'the quality of the validation process depends on the rigor and effectiveness of the review rather than on organizational structure.' Effective challenge still requires appropriate expertise and sufficient independence to permit objectivity — but the structural requirements are less prescriptive.
Is generative AI covered by OCC 2026-13?
No. The agencies explicitly excluded generative AI and agentic AI from the guidance scope, noting these are 'novel and rapidly evolving.' The agencies committed to releasing a request for information on AI model risk management in the near future. As of June 2026, that RFI has not been published. Banks are expected to apply broader risk management practices to GenAI tools in the interim.
What does 'noncompliance alone will not result in supervisory criticism' mean?
OCC 2026-13 is supervisory guidance, not an enforceable rule. The agencies cannot issue a violation for failing to follow guidance the way they can for violating a regulation. However, examiners will still evaluate whether your model risk management program is commensurate with your model risk exposure — and the guidance describes what that means. Weak MRM programs lead to MRAs regardless of the guidance's non-mandatory status.
Do vendor-supplied models need the same governance as in-house models?
Yes. OCC 2026-13 is explicit that banks should apply the same rigor to vendor and third-party models as to those developed in-house. This includes requesting independent validation reports from vendors and documenting oversight activities. The 2026 guidance makes this expectation clearer than SR 11-7's treatment of the same question.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.