Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →OCC Model Risk Management: Revised Guidance (Bulletin 2026-13)
Issued by
Office of the Comptroller of the Currency
This bulletin updates the OCC's supervisory expectations for model risk management at national banks and federal savings associations. It addresses the full model lifecycle, covering development, validation, deployment, monitoring, and governance structures. Banks using AI and machine learning models are expected to align their risk controls with these revised standards.
Applies To
Overview
The OCC's revised model risk management guidance updates and extends the supervisory framework originally established under OCC Bulletin 2011-12, reflecting the expanded use of AI and machine learning in banking operations. The guidance sets expectations across four principal areas: model development and implementation, independent model validation, ongoing monitoring, and enterprise-wide governance including clear accountability structures. It applies to all models used in decision-making at OCC-supervised institutions, with heightened attention to complex or opaque models such as those based on machine learning techniques. Enforcement is exercised through the OCC's supervisory examination process, meaning deficiencies can result in Matters Requiring Attention, Matters Requiring Immediate Attention, or formal enforcement actions. Institutions are expected to demonstrate compliance during routine examinations, and the guidance does not prescribe a separate implementation deadline beyond its publication date. Banks relying on third-party or vendor models bear responsibility for ensuring those models also meet the guidance's standards.
Key Requirements
- •Maintain written model risk management policies that define model inventory scope, risk tiering, and ownership responsibilities across the institution.
- •Conduct independent validation of all models prior to deployment, covering conceptual soundness, data integrity, and performance benchmarking.
- •Implement ongoing performance monitoring with defined thresholds that trigger review or decommissioning of underperforming models.
- •Establish clear governance structures with senior management accountability and board-level oversight of model risk appetite.
- •Apply heightened scrutiny to AI and machine learning models, including explainability assessments and bias testing appropriate to model complexity.
- •Extend model risk management requirements to third-party and vendor-supplied models, requiring documentation and validation evidence from external providers.
What Your Organization Must Do
- →Audit the full model inventory and assign risk tiers to every model in use, including AI and machine learning applications, before the next scheduled OCC examination.
- →Establish or confirm independence of the model validation function from model development teams, documenting the reporting structure for examiners.
- →Update model monitoring protocols to include quantitative performance thresholds and a documented escalation process when those thresholds are breached.
- →Assign named senior management owners to each model risk domain and present a model risk appetite statement to the board for approval.
- →Review all third-party AI vendor contracts to require delivery of validation documentation, performance data, and conceptual soundness evidence.
- →Incorporate explainability and bias assessment requirements into the model development lifecycle for any model classified as complex or high-risk.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Does OCC Bulletin 2026-13 replace or supplement the 2011-12 model risk management guidance?
- Bulletin 2026-13 updates and extends the framework established under OCC Bulletin 2011-12, incorporating supervisory expectations for AI and machine learning that the original guidance did not address. Banks should treat it as the governing standard going forward, though the underlying validation and governance principles from 2011-12 remain foundational.
- What is the compliance deadline for OCC Bulletin 2026-13?
- The bulletin does not prescribe a separate implementation deadline beyond its April 17, 2026 publication date. Institutions are expected to demonstrate alignment with its requirements during routine OCC supervisory examinations, making pre-examination readiness the practical enforcement trigger.
- Are national banks responsible for validating third-party and vendor-supplied AI models under this guidance?
- Yes. OCC MRM 26 explicitly extends model risk management requirements to third-party and vendor-supplied models. Banks must obtain validation documentation, performance data, and conceptual soundness evidence from external providers, and cannot delegate that accountability to the vendor.
- What enforcement actions can the OCC take if a bank's model risk management program is deficient?
- The OCC enforces this guidance through its supervisory examination process. Deficiencies can result in Matters Requiring Attention, Matters Requiring Immediate Attention, or formal enforcement actions depending on severity, making examination preparation the primary compliance risk management priority.
- Does OCC Bulletin 2026-13 require explainability assessments for machine learning models?
- The guidance requires heightened scrutiny for complex or opaque models, including explainability assessments and bias testing calibrated to model complexity. Institutions must incorporate these requirements into the development lifecycle for any model classified as high-risk, not only at the validation stage.
- How does OCC MRM 26 define which models fall within its scope?
- The guidance applies to all models used in decision-making at OCC-supervised institutions, with scope defined by the institution's written model inventory policies. Banks must document inventory scope, assign risk tiers, and establish ownership responsibilities, ensuring AI applications are captured alongside traditional quantitative models.
