AI Governance Institute
← News
Research2026-09-01

SR 26-2 Gets a GenAI Control Layer: New Framework Maps Compliance to Practice

What happened

Researchers published An SR 26-2-Compatible Framework for Generative AI Risk on arXiv on July 27, 2026, proposing a structured, layered control architecture for managing generative AI risk within the scope of SR 26-2 expectations. The framework organizes controls across six functional layers: approved-use boundary setting, risk-tier assignment, evidence-based input assessment, output evaluation, ongoing monitoring, and auditability. Each layer is designed to generate the kind of documented, traceable governance evidence that examiners reviewing model risk management programs would expect to find. The paper is particularly relevant for institutions that have identified gaps between their legacy model risk management programs and the demands of deploying non-deterministic, generative systems. It also addresses agentic AI configurations, where standard input-output review workflows are insufficient because the system takes autonomous actions between prompt and result.

Why it matters

  • ·Financial institutions operating under SR 26-2 face a structural mismatch: guidance written primarily for statistical models is now being applied to generative AI systems whose outputs are non-deterministic and whose behavior in agentic configurations can be difficult to audit after the fact. This framework offers a compliance team a concrete starting point for closing that gap with documented controls.
  • ·Risk-tier assignment is one of the most contested elements of SR 26-2 implementation for GenAI, because there is no settled industry standard for classifying a model that spans multiple use cases at different risk levels. The paper's proposed tiering methodology gives compliance teams a defensible, evidence-based approach they can present to internal audit and external examiners.
  • ·Auditability requirements for GenAI outputs are increasingly scrutinized alongside broader documentation expectations, as seen in EU AI Act enforcement activity and emerging domestic model risk guidance. A framework that explicitly structures controls around audit-trail generation addresses a control gap that regulators across jurisdictions are beginning to test.

Governance controls affected

What to do now

  • Map your existing model risk management control inventory against the six layers proposed in the framework to identify where GenAI systems are not covered by current SR 26-2 controls.
  • Review your risk-tier assignment methodology to confirm it can accommodate generative AI use cases, including multi-use models that span risk tiers depending on deployment context.
  • Assess whether your current output evaluation and monitoring workflows are designed to handle non-deterministic outputs, and document any gaps for internal audit.
  • For any agentic GenAI deployments, confirm that your audit trail controls capture actions taken between prompt and final output, not just the final output itself.
  • Use the framework's approved-use boundary layer as a reference when drafting or updating acceptable-use policies for GenAI systems subject to model risk management oversight.

What to watch next

Implementation timelines under SR 26-2 are active, and examiners are beginning to probe GenAI-specific controls at institutions that have already inventoried these systems, as covered in the SR 26-2 Implementation Guide analysis. Compliance teams should watch for Federal Reserve supervisory letters or examination findings that reference GenAI specifically, which would signal that the translation gap this framework addresses is becoming an active examination focus. Broader alignment between domestic model risk management expectations and international frameworks, including the ISO/IEC 42001:2023 AI management system standard, may also accelerate as regulators compare notes across jurisdictions.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-01

SR 26-2 Implementation Guide Exposes Legacy Model Inventory Gaps

Lumenova AI has published a practitioner implementation guide for SR 26-2, the Federal Reserve and OCC's updated model risk management supervisory guidance. The guide identifies concrete steps including model inventory rationalization, revised materiality-based tiering, strengthened validation independence, and a separate governance lane for agentic and generative AI. Compliance teams at regulated financial institutions can use the operating model recommendations as a readiness benchmark ahead of examinations.

Research2026-09-01

PwC Banking AI Framework Maps Five Gaps SR 26-2 Left Unresolved

PwC Germany published a whitepaper structuring AI governance for banks around five core challenges: scope definition, three-lines-of-defense adaptation, proportionality, third-party risk, and AI-specific model validation. The paper offers a practical implementation scaffold for financial institutions working through model risk management reform. It does not introduce regulatory obligations, but provides detailed control-ownership guidance banks can use to close gaps left by existing supervisory requirements.

Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

The OCC's revised model risk management guidance, SR 26-2, resets supervisory expectations for U.S. banks by shifting to a materiality-based approach that covers both traditional statistical models and AI systems. CRA's practitioner analysis identifies four practical redesign areas: inventory scope, model tiering, validation, and governance alignment. Banks that operate AI governance and model risk management as separate programs face immediate pressure to harmonize them.