SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight
What happened
CRA, a financial and economic consulting firm, published Model Risk Management Guidance SR 26-2: In the Era of AI on August 24, 2026, analyzing how the revised federal model risk guidance changes practical governance obligations for banks. The guidance replaces an older supervisory framework with a materiality-based structure that applies to both traditional quantitative models and AI systems, closing the ambiguity that previously allowed banks to treat the two regimes as separate tracks. CRA identifies four areas requiring redesign: model inventory scope, risk-proportionate tiering, validation independence, and governance alignment up to the board level. The piece notes that regulators now expect banks to demonstrate that their governance structures are calibrated to the actual risk of each model or AI system, not simply that a program exists. This directly implicates how banks classify generative AI tools, vendor-supplied models, and internally developed systems under a single, coherent inventory.
Why it matters
- ·Banks running AI governance and model risk management as parallel but disconnected programs now face direct supervisory exposure: SR 26-2 effectively requires a unified governance structure, meaning gaps between the two regimes will be visible to examiners.
- ·The materiality-based tiering approach changes validation resourcing decisions. High-risk AI systems used in credit, fraud detection, or treasury functions will require more rigorous and independent validation than many banks currently provide, raising both cost and staffing implications.
- ·Vendor-supplied AI models are squarely within scope. Banks that rely on third-party AI systems without subjecting them to model risk governance disciplines equivalent to internally built models carry unresolved supervisory risk under the revised framework.
Governance controls affected
What to do now
- ☐Audit your model inventory to confirm all AI systems, including vendor-supplied and generative AI tools, are captured and tiered under the SR 26-2 materiality framework.
- ☐Map any gaps between your existing AI governance program and your model risk management program, and assign ownership for resolving each gap within a defined remediation timeline.
- ☐Review validation independence arrangements for high-risk AI systems: confirm that validators are organizationally separate from model developers and have sufficient technical competency to assess AI-specific failure modes.
- ☐Update board and senior management reporting to include AI model risk appetite statements and tiered model inventory summaries consistent with the materiality-based approach.
- ☐Assess all third-party AI model contracts to confirm you have sufficient rights and information to perform model risk governance obligations, including validation, documentation, and incident escalation.
What to watch next
Examiners are expected to apply SR 26-2 during routine safety and soundness reviews, meaning banks should anticipate model governance questions at their next examination cycle. Federal banking agencies may issue supplemental FAQs or examination guidance as institutions begin implementation, particularly on the treatment of generative AI and large language models within traditional model risk frameworks. Non-bank financial institutions subject to analogous model risk expectations, including those monitored by the SEC under the SEC AI Governance Guidance, should watch for whether their regulators follow the SR 26-2 materiality-based precedent in upcoming rulemaking or supervisory letters.
Stay ahead of stories like this
Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.
