Feature AI Risk
OCC Bulletin 2026-13: What Changed from SR 11-7 and the 7-Item Update Checklist for Your MRM Program
The federal banking agencies replaced SR 11-7 with OCC Bulletin 2026-13 and SR 26-02 in April 2026. Here's what changed in validation, independence, and community bank expectations — plus the GenAI exclusion that creates a compliance gap your MRM team can't afford to ignore.
Table of Contents
TL;DR
- OCC Bulletin 2026-13 / SR 26-02 (April 17, 2026) replaced SR 11-7 and OCC 2011-12 — the most significant model risk management guidance update in 15 years
- Risk-based proportionality replaces implied annual validation requirements; community banks get meaningful relief
- Simplified validation: three core components retained, prescriptive detail on VaR backtesting and code verification removed
- Independence emphasis softened: rigor and effectiveness of review matters more than organizational structure
- GenAI explicitly excluded from scope — agencies promised a separate AI RFI that hasn’t landed as of June 2026
- 7-item update checklist: policy citations, risk tiering, validation cadence, effective challenge documentation, vendor model parity, GenAI gap, board briefing
On April 17, 2026, the OCC issued Bulletin 2026-13 and the Federal Reserve issued SR 26-02, finally replacing SR 11-7 — the model risk management guidance that had governed bank MRM programs since 2011. Fifteen years of SR 11-7 citations. Policy frameworks built around it. Validation standards derived from it. Replaced with a shorter, more principles-based document that is explicitly less prescriptive than what came before.
For MRM teams, this creates two immediate questions. What actually changed, and what do you need to update? And for banks deploying AI and generative models, a more uncomfortable question: what does it mean that the new guidance specifically excludes GenAI from scope?
Let me walk through both.
What Was Rescinded
The April 17 issuance formally rescinded:
- SR 11-7 (Federal Reserve, 2011) — the original model risk management guidance
- OCC Bulletin 2011-12 — OCC’s version of SR 11-7
- OCC Bulletin 2021-19 — subsequent OCC model risk updates
- FIL-22-2017 — the FDIC’s equivalent issuance
Any internal policy, procedure, board charter, or vendor contract that cites these documents by number now references rescinded guidance. That’s not just a citation cleanup exercise — it’s a signal to examiners that your program hasn’t been reviewed since the guidance update. This is the first item on the checklist because it’s visible in documentation reviews and it’s easy to address.
The Three Biggest Changes from SR 11-7
1. Risk-Based Proportionality Replaces the Implied Annual Cadence
SR 11-7 created a de facto expectation of annual model validation across the banking system, regardless of institution size or model complexity. Community banks with straightforward credit scoring models built validation programs that mirrored what large, systemically important banks needed for complex derivative pricing and stress testing models. The compliance cost was real and the risk-management benefit was marginal.
OCC 2026-13 resets this explicitly. The guidance states it is “expected to be most relevant to banking organizations with over $30 billion in total assets” while simultaneously noting it applies to all institutions with material model risk. The key shift: annual model validation is not required. Validation frequency should be commensurate with model risk — more frequent for high-risk, high-complexity models; less frequent for stable, lower-impact models with strong track records.
For community banks, the practical analysis is straightforward: if you’re running FICO-based credit scoring, a vendor-provided CECL tool, and basic deposit pricing models, you don’t need an annual validation cycle for each. Document the risk-based rationale for your validation schedule, focus resources on models with the highest financial and customer impact, and you’re in compliance with the new guidance.
For larger institutions: the $30B threshold is directional, not exempting. A $5B bank with significant model usage in credit decisioning, CECL, BSA/AML transaction monitoring, and liquidity stress testing still needs robust MRM governance. The variable is model risk exposure, not asset size.
2. Simplified Validation Framework
SR 11-7 retained three core validation components — conceptual soundness, outcomes analysis, and ongoing monitoring — and OCC 2026-13 keeps all three. What changed is the prescriptive detail around each.
SR 11-7 included specific guidance on VaR backtesting methodology, parallel outcomes analysis procedures, computer code verification requirements, override analysis standards, and benchmarking approaches. OCC 2026-13 replaced this prescriptive list with the principle that validation approaches “may differ across models based on their characteristics and use.”
| Validation Component | SR 11-7 Treatment | OCC 2026-13 Treatment |
|---|---|---|
| Conceptual soundness | Detailed review requirements, theoretical basis documentation | Review of design choices and assumptions — methodology proportionate to model complexity |
| Outcomes analysis | VaR backtesting specifics, parallel run requirements | Comparison to actual outcomes or benchmarks — form depends on model characteristics |
| Ongoing monitoring | Early warning metrics, process verification of computer code | Appropriateness assessment over time — risk-based monitoring cadence |
The practical implication: validation reports don’t need to work through a 15-year-old checklist. They need to demonstrate that the model was assessed for conceptual soundness, that outputs were evaluated against actual outcomes or benchmarks, and that monitoring is appropriate for the model’s risk profile. The documentation can be proportionate to the risk.
3. De-Emphasized Validation Independence
The Orrick analysis of the guidance overhaul called this the most notable change, and it’s the right call. SR 11-7 devoted substantial space to validation independence — reporting lines, compensation practices, separation from model development teams. The implication was that specific organizational structures were necessary to achieve meaningful challenge.
OCC 2026-13’s language is notably different: “The quality of the validation process depends on the rigor and effectiveness of the review rather than on organizational structure.”
This doesn’t eliminate the independence expectation. The guidance still states that effective challenge requires “appropriate expertise, sufficient independence to permit objectivity, and organizational standing and influence to effect change when appropriate.” What it removes is the emphasis on how that independence is structured.
For community banks and mid-size institutions that used third-party validation as their primary independence mechanism, this is clarifying — the rigor of the review, not the org chart, determines whether challenge is effective. For large institutions, a formally structured independent validation function still serves the risk management purpose well; the guidance change doesn’t require restructuring programs that are working.
What Stayed the Same
The fundamentals didn’t change:
- Model inventory — every quantitative tool used in consequential decision-making should be inventoried and risk-tiered
- Board and senior management oversight — board awareness of material model risk and governance responsibilities remains expected
- Vendor/third-party model parity — the same rigor applied to in-house models applies to vendor-supplied models; the Sullivan & Cromwell analysis highlights this as an area where banks have historically underinvested
- Documentation through model lifecycle — development, validation, deployment, modification, and retirement all require documentation commensurate with model risk
The GenAI Exclusion: The Gap That OCC 2026-13 Left Behind
Right in the scope section of OCC 2026-13, the agencies carved out generative AI and agentic AI. The bulletin states these technologies are “novel and rapidly evolving” and outside the guidance scope, with a commitment to release an AI-specific request for information “in the near future.”
It is now June 2026. That RFI has not been published.
This creates a governance gap that is neither small nor comfortable. Banks are deploying large language models — for customer service chatbots, compliance assistance, model validation support, board report drafting, and internal knowledge management. None of these deployments fall under OCC 2026-13 scope. All of them face examiner scrutiny.
The agencies addressed the gap with a sentence: banking organizations should apply “broader risk management and governance practices” to GenAI tools not covered by the guidance. That sentence is doing real work. “Excluded from scope” is not a governance pass — it means your GenAI program needs to be governed by your existing risk infrastructure until the formal framework arrives.
We’ve covered the interim governance framework in detail in The GenAI Model Risk Gap. The short version: NIST AI 600-1 and the FS AI RMF’s 230 control objectives provide structured governance that addresses the categories examiners are most likely to focus on. Build the parallel GenAI governance program now, so you’re calibrating when the formal RFI drops rather than starting from scratch under scrutiny.
The 7-Item OCC 2026-13 Update Checklist
Here is the practical update list for MRM teams and compliance officers working through this guidance change:
| # | Update | Priority | Why It Matters |
|---|---|---|---|
| 1 | Update all internal documents citing SR 11-7 / OCC 2011-12 / OCC 2021-19 | High | Stale citations are visible in documentation reviews; board and risk committee charters need to reference current guidance |
| 2 | Document risk-based rationale for validation frequency by model tier | High | New guidance relieves the implied annual cadence; document the risk-based justification for your schedule |
| 3 | Review model inventory completeness and risk tiering | High | Risk-based approach requires knowing which models are High, Medium, Low risk — the inventory drives everything else |
| 4 | Update effective challenge documentation to emphasize rigor over structure | Medium | Independence language shifted; your MRM policy shouldn’t still cite SR 11-7’s org structure requirements as the standard |
| 5 | Confirm vendor/third-party model oversight parity | Medium | Same rigor as in-house is explicit; request validation evidence from key model vendors and document the oversight activities |
| 6 | Build separate GenAI governance documentation | High | GenAI is excluded from OCC 2026-13 scope but not from examiner expectations; the governance gap needs to be filled before the AI RFI lands |
| 7 | Brief board and risk committee on the guidance change | Medium | Board oversight expectations remain; a brief documentation of the update and program impact demonstrates governance awareness |
The Exam Lens: What “Noncompliance Won’t Result in Criticism” Actually Means in Practice
OCC 2026-13 is explicit: it does not establish enforceable standards, and “noncompliance alone will not result in supervisory criticism.” This is important — it’s guidance, not a rule. An examiner cannot issue a citation for failing to follow non-mandatory guidance the way they can for violating a regulation.
But examiners evaluate MRM programs against the principles in this guidance as part of routine examination. The Databricks practitioner analysis frames it correctly: the practical exam question is still “is your model risk management program commensurate with your model risk exposure?” Banks with no model inventory, no validation documentation, and no governance structure get MRA attention regardless of the guidance’s non-mandatory status.
OCC 2026-13 reshapes how you answer the commensurate question. Risk-based. Proportionate. Principles-driven. And with an explicit GenAI carveout that creates a parallel compliance obligation your MRM team inherits.
The SR 11-7 baseline we covered in 2026 is now the foundation to build from rather than the active standard to comply with. The update is substantial enough to warrant a formal MRM program review this quarter.
So What?
OCC 2026-13 is genuinely good news for most organizations. Less prescriptive validation requirements. Community bank proportionality relief. Independence based on rigor rather than org charts. The 15-year-old guidance that had accumulated layers of interpretation and industry practice has been replaced with something shorter and more flexible.
The catch: the principles still require real governance. The simplified framework still requires a model inventory, risk tiering, documented validation, and meaningful challenge. And the GenAI exclusion isn’t a pass — it’s a governance gap that your MRM team now owns.
If your AI governance program needs to cover both the traditional model risk management transition to OCC 2026-13 and the GenAI infrastructure that sits outside formal guidance, the AI Risk Assessment Template & Guide covers the model inventory framework, pre-deployment assessment, vendor AI questionnaire, and governance documentation — the artifacts that apply to both traditional models under 2026-13 and GenAI tools where the formal framework hasn’t arrived yet.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Did OCC Bulletin 2026-13 fully replace SR 11-7?
Does OCC 2026-13 apply to community banks?
What happened to the validation independence requirements from SR 11-7?
Is generative AI covered by OCC 2026-13?
What does 'noncompliance alone will not result in supervisory criticism' mean?
Do vendor-supplied models need the same governance as in-house models?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026