SR 26-2 Gets a GenAI Control Layer: New Framework Maps Compliance to Practice
What happened
Researchers published An SR 26-2-Compatible Framework for Generative AI Risk on arXiv on July 27, 2026, proposing a structured, layered control architecture for managing generative AI risk within the scope of SR 26-2 expectations. The framework organizes controls across six functional layers: approved-use boundary setting, risk-tier assignment, evidence-based input assessment, output evaluation, ongoing monitoring, and auditability. Each layer is designed to generate the kind of documented, traceable governance evidence that examiners reviewing model risk management programs would expect to find. The paper is particularly relevant for institutions that have identified gaps between their legacy model risk management programs and the demands of deploying non-deterministic, generative systems. It also addresses agentic AI configurations, where standard input-output review workflows are insufficient because the system takes autonomous actions between prompt and result.
Why it matters
- ·Financial institutions operating under SR 26-2 face a structural mismatch: guidance written primarily for statistical models is now being applied to generative AI systems whose outputs are non-deterministic and whose behavior in agentic configurations can be difficult to audit after the fact. This framework offers a compliance team a concrete starting point for closing that gap with documented controls.
- ·Risk-tier assignment is one of the most contested elements of SR 26-2 implementation for GenAI, because there is no settled industry standard for classifying a model that spans multiple use cases at different risk levels. The paper's proposed tiering methodology gives compliance teams a defensible, evidence-based approach they can present to internal audit and external examiners.
- ·Auditability requirements for GenAI outputs are increasingly scrutinized alongside broader documentation expectations, as seen in EU AI Act enforcement activity and emerging domestic model risk guidance. A framework that explicitly structures controls around audit-trail generation addresses a control gap that regulators across jurisdictions are beginning to test.
Governance controls affected
What to do now
- ☐Map your existing model risk management control inventory against the six layers proposed in the framework to identify where GenAI systems are not covered by current SR 26-2 controls.
- ☐Review your risk-tier assignment methodology to confirm it can accommodate generative AI use cases, including multi-use models that span risk tiers depending on deployment context.
- ☐Assess whether your current output evaluation and monitoring workflows are designed to handle non-deterministic outputs, and document any gaps for internal audit.
- ☐For any agentic GenAI deployments, confirm that your audit trail controls capture actions taken between prompt and final output, not just the final output itself.
- ☐Use the framework's approved-use boundary layer as a reference when drafting or updating acceptable-use policies for GenAI systems subject to model risk management oversight.
What to watch next
Implementation timelines under SR 26-2 are active, and examiners are beginning to probe GenAI-specific controls at institutions that have already inventoried these systems, as covered in the SR 26-2 Implementation Guide analysis. Compliance teams should watch for Federal Reserve supervisory letters or examination findings that reference GenAI specifically, which would signal that the translation gap this framework addresses is becoming an active examination focus. Broader alignment between domestic model risk management expectations and international frameworks, including the ISO/IEC 42001:2023 AI management system standard, may also accelerate as regulators compare notes across jurisdictions.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
