AI Governance Institute
← News
Research2026-09-01

SR 26-2 Implementation Guide Exposes Legacy Model Inventory Gaps

What happened

Lumenova AI published SR 26-2: Actionable Guide to Model Risk Management, a practitioner-oriented implementation guide addressing the Federal Reserve and OCC's updated model risk management supervisory framework, which replaces the foundational SR 11-7 guidance that had governed bank model governance programs since 2011. The guide follows the SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight coverage of the underlying regulatory development and focuses on translating supervisory expectations into operating model changes. Key recommendations include rationalizing model inventories to remove stale or redundant entries, revising tiering criteria so materiality assessments reflect actual risk rather than legacy classifications, and strengthening the independence of model validation functions. Critically, the guide argues that agentic and generative AI systems require a distinct governance lane rather than being absorbed into programs designed for traditional quantitative models. Compliance teams are directed toward centralized workflow tracking and audit-ready documentation as the two operational anchors for demonstrating SR 26-2 readiness to examiners.

Why it matters

  • ·Banks and other regulated financial institutions whose model risk programs were built around SR 11-7 face direct examination exposure if they have not updated inventory, tiering, and validation processes to meet SR 26-2 expectations, which are already in effect.
  • ·The guide's emphasis on a separate governance lane for agentic and generative AI is significant: compliance teams that have simply mapped AI models into existing model risk tiers without adjusting oversight workflows may find those mappings challenged by examiners who expect purpose-built controls.
  • ·Centralized workflow tracking and audit-ready documentation are identified as the operational foundation for SR 26-2 compliance, meaning organizations with fragmented or static documentation practices face a material readiness gap that must be closed before the next examination cycle.

Governance controls affected

What to do now

  • Conduct a full model inventory audit to identify stale, redundant, or misclassified entries that would not withstand examiner scrutiny under SR 26-2 materiality standards.
  • Revise model tiering criteria to ensure materiality assessments reflect current risk exposure, particularly for models that have expanded in scope or usage since their last classification review.
  • Establish a distinct governance lane for agentic and generative AI systems, with validation protocols and oversight workflows that differ from those applied to traditional quantitative models.
  • Implement centralized workflow tracking so that model development, validation, approval, and monitoring activities are logged in a single system of record available for examiner review.
  • Review model validation independence arrangements to confirm that validators are structurally separated from model development teams, as SR 26-2 reaffirms this as a non-negotiable supervisory expectation.

What to watch next

Examiners at the Federal Reserve and OCC are expected to begin incorporating SR 26-2 into routine model risk management reviews, meaning the next examination cycle will be the practical test of whether institutional programs have caught up. Financial institutions should also monitor whether the OCC Model Risk Management: Revised Guidance (Bulletin 2026-13) produces supplemental FAQs or examination guidance that further specifies expectations for agentic AI governance within model risk frameworks. The Financial Stability Board's ongoing work on agentic AI in financial services, reflected in the Financial Stability Board Recommendations on Agentic AI Controls in Financial Services, may also produce cross-border supervisory alignment that affects how multinational banks structure their model governance programs.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-01

SR 26-2 Gets a GenAI Control Layer: New Framework Maps Compliance to Practice

A research paper published on arXiv proposes a layered control framework for generative AI risk that is structured to align with SR 26-2, the Federal Reserve's updated model risk management guidance. The framework covers approved-use boundaries, risk-tier assignment, input assessment, output evaluation, monitoring, and auditability. It is designed to help compliance and risk teams build traceable governance evidence for GenAI deployments subject to model risk management expectations.

Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

The OCC's revised model risk management guidance, SR 26-2, resets supervisory expectations for U.S. banks by shifting to a materiality-based approach that covers both traditional statistical models and AI systems. CRA's practitioner analysis identifies four practical redesign areas: inventory scope, model tiering, validation, and governance alignment. Banks that operate AI governance and model risk management as separate programs face immediate pressure to harmonize them.

Research2026-09-01

PwC Banking AI Framework Maps Five Gaps SR 26-2 Left Unresolved

PwC Germany published a whitepaper structuring AI governance for banks around five core challenges: scope definition, three-lines-of-defense adaptation, proportionality, third-party risk, and AI-specific model validation. The paper offers a practical implementation scaffold for financial institutions working through model risk management reform. It does not introduce regulatory obligations, but provides detailed control-ownership guidance banks can use to close gaps left by existing supervisory requirements.