AI Governance Institute
← News
Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

What happened

CRA, a financial and economic consulting firm, published Model Risk Management Guidance SR 26-2: In the Era of AI on August 24, 2026, analyzing how the revised federal model risk guidance changes practical governance obligations for banks. The guidance replaces an older supervisory framework with a materiality-based structure that applies to both traditional quantitative models and AI systems, closing the ambiguity that previously allowed banks to treat the two regimes as separate tracks. CRA identifies four areas requiring redesign: model inventory scope, risk-proportionate tiering, validation independence, and governance alignment up to the board level. The piece notes that regulators now expect banks to demonstrate that their governance structures are calibrated to the actual risk of each model or AI system, not simply that a program exists. This directly implicates how banks classify generative AI tools, vendor-supplied models, and internally developed systems under a single, coherent inventory.

Why it matters

  • ·Banks running AI governance and model risk management as parallel but disconnected programs now face direct supervisory exposure: SR 26-2 effectively requires a unified governance structure, meaning gaps between the two regimes will be visible to examiners.
  • ·The materiality-based tiering approach changes validation resourcing decisions. High-risk AI systems used in credit, fraud detection, or treasury functions will require more rigorous and independent validation than many banks currently provide, raising both cost and staffing implications.
  • ·Vendor-supplied AI models are squarely within scope. Banks that rely on third-party AI systems without subjecting them to model risk governance disciplines equivalent to internally built models carry unresolved supervisory risk under the revised framework.

Governance controls affected

What to do now

  • Audit your model inventory to confirm all AI systems, including vendor-supplied and generative AI tools, are captured and tiered under the SR 26-2 materiality framework.
  • Map any gaps between your existing AI governance program and your model risk management program, and assign ownership for resolving each gap within a defined remediation timeline.
  • Review validation independence arrangements for high-risk AI systems: confirm that validators are organizationally separate from model developers and have sufficient technical competency to assess AI-specific failure modes.
  • Update board and senior management reporting to include AI model risk appetite statements and tiered model inventory summaries consistent with the materiality-based approach.
  • Assess all third-party AI model contracts to confirm you have sufficient rights and information to perform model risk governance obligations, including validation, documentation, and incident escalation.

What to watch next

Examiners are expected to apply SR 26-2 during routine safety and soundness reviews, meaning banks should anticipate model governance questions at their next examination cycle. Federal banking agencies may issue supplemental FAQs or examination guidance as institutions begin implementation, particularly on the treatment of generative AI and large language models within traditional model risk frameworks. Non-bank financial institutions subject to analogous model risk expectations, including those monitored by the SEC under the SEC AI Governance Guidance, should watch for whether their regulators follow the SR 26-2 materiality-based precedent in upcoming rulemaking or supervisory letters.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-01

PwC Banking AI Framework Maps Five Gaps SR 26-2 Left Unresolved

PwC Germany published a whitepaper structuring AI governance for banks around five core challenges: scope definition, three-lines-of-defense adaptation, proportionality, third-party risk, and AI-specific model validation. The paper offers a practical implementation scaffold for financial institutions working through model risk management reform. It does not introduce regulatory obligations, but provides detailed control-ownership guidance banks can use to close gaps left by existing supervisory requirements.

Research2026-09-01

SR 26-2 Implementation Guide Exposes Legacy Model Inventory Gaps

Lumenova AI has published a practitioner implementation guide for SR 26-2, the Federal Reserve and OCC's updated model risk management supervisory guidance. The guide identifies concrete steps including model inventory rationalization, revised materiality-based tiering, strengthened validation independence, and a separate governance lane for agentic and generative AI. Compliance teams at regulated financial institutions can use the operating model recommendations as a readiness benchmark ahead of examinations.

Research2026-09-01

SR 26-2 Gets a GenAI Control Layer: New Framework Maps Compliance to Practice

A research paper published on arXiv proposes a layered control framework for generative AI risk that is structured to align with SR 26-2, the Federal Reserve's updated model risk management guidance. The framework covers approved-use boundaries, risk-tier assignment, input assessment, output evaluation, monitoring, and auditability. It is designed to help compliance and risk teams build traceable governance evidence for GenAI deployments subject to model risk management expectations.