AI Governance Institute
← News
Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

What happened

CRA, a financial and economic consulting firm, published Model Risk Management Guidance SR 26-2: In the Era of AI, analyzing how the OCC and Federal Reserve's revised guidance changes practical governance obligations for banks. SR 26-2 replaces SR 11-7, the foundational supervisory letter that had governed bank model governance since 2011, with a materiality-based structure that applies to both traditional quantitative models and AI systems. That closes an ambiguity many banks had relied on: treating AI governance and model risk management as separate tracks. CRA identifies four areas requiring redesign: model inventory scope, risk-proportionate tiering, validation independence, and governance alignment up to the board level.

A companion implementation guide from Lumenova AI translates those supervisory expectations into concrete operating model changes. It recommends rationalizing model inventories to remove stale or redundant entries, revising tiering criteria so materiality reflects actual risk rather than legacy classifications, and strengthening validator independence. Its most pointed recommendation is that agentic and generative AI systems need their own governance lane rather than being absorbed into programs built for traditional statistical models, backed by centralized workflow tracking and audit-ready documentation as the two anchors examiners will look for.

A separate academic paper, An SR 26-2-Compatible Framework for Generative AI Risk, goes further and proposes a six-layer control architecture purpose-built for GenAI: approved-use boundaries, risk-tier assignment, input assessment, output evaluation, monitoring, and auditability. It targets the structural mismatch CRA and Lumenova both flag: guidance written for statistical models is now being applied to non-deterministic systems, and agentic configurations are hard to audit after the fact because the system acts autonomously between prompt and result.

Why it matters

  • ·Banks running AI governance and model risk management as parallel but disconnected programs now face direct supervisory exposure, since SR 26-2 effectively requires a unified structure and gaps between the two regimes will be visible to examiners.
  • ·The materiality-based tiering approach raises validation costs and staffing needs, since high-risk AI systems used in credit, fraud detection, or treasury functions require more rigorous, independent validation than most banks currently provide.
  • ·Compliance teams that mapped AI models into existing model risk tiers without adjusting oversight workflows may find those mappings challenged, since purpose-built controls for agentic and generative AI are now the explicit expectation rather than a fit into traditional tiers.
  • ·Risk-tier assignment for GenAI remains one of the most contested parts of SR 26-2 implementation, since no settled industry standard exists for classifying a model that spans multiple use cases at different risk levels.
  • ·Vendor-supplied AI models are squarely in scope: banks relying on third-party AI without model risk governance equivalent to internally built systems carry unresolved supervisory risk.

Governance controls affected

What to do now

  • Audit your model inventory, including vendor-supplied and generative AI tools, to confirm materiality-based tiering under SR 26-2 and remove stale or redundant entries.
  • Establish a distinct governance lane for agentic and generative AI, with validation protocols and oversight workflows that differ from those used for traditional quantitative models.
  • Review validation independence: confirm validators are organizationally separate from model developers and have the technical competency to assess AI-specific failure modes.
  • Map your controls against a layered framework covering approved-use boundaries, risk tiering, input assessment, output evaluation, monitoring, and auditability, to find where GenAI systems fall outside current coverage.
  • For agentic deployments, confirm audit trail controls capture actions taken between prompt and final output, not just the output itself.
  • Assess third-party AI model contracts to confirm you have sufficient rights and information to perform validation, documentation, and incident escalation obligations.

What to watch next

Examiners are expected to apply SR 26-2 during routine safety and soundness reviews, so banks should anticipate model governance questions at their next examination cycle, with GenAI-specific controls now an active area of scrutiny for institutions that have already completed their inventories. Federal banking agencies may issue supplemental FAQs or examination guidance as institutions implement the framework, particularly on generative and agentic AI. Non-bank financial institutions subject to analogous expectations, including those monitored by the SEC under the SEC AI Governance Guidance, should watch for whether their regulators follow the SR 26-2 materiality-based precedent, and multinational banks should track the Financial Stability Board's work on agentic AI in financial services for signs of cross-border alignment.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-15

McKinsey's Banking AI Risk Blueprint Sets a Model Governance Benchmark

McKinsey has published a practitioner operating model for AI model risk management in banking. The guide covers risk appetite, use-case taxonomy, model tiering, approval thresholds, independent validation, and portfolio monitoring. Compliance teams at banks and financial institutions can use it to benchmark and extend existing model risk programs to cover AI.

Research2026-09-12

ISACA: Point-in-Time AI Compliance Cannot Survive Legal Scrutiny

ISACA's practitioner guidance argues that legally defensible AI governance requires continuous, lifecycle-spanning evidence, not periodic sign-offs. The piece identifies a live AI inventory, named ownership, and documented legal and risk bases as the minimum conditions. Defensibility. Organizations relying on static compliance documentation face significant exposure under active regulatory and litigation environments.

Research2026-09-12

IEEE Survey Links Explainability and Fairness as a Single Audit Obligation

A peer-reviewed survey published by the IEEE Computer Society examines the relationship between explainability and fairness in machine learning. Finding that the two properties are increasingly inseparable in practice. The survey, titled 'On the Interplay of Explainability. Fairness in AI,' documents how each capability reinforces the other when diagnosing and mitigating bias. The work has direct implications for model validation, audit readiness, and bias documentation programs.