AI Governance Institute

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
VoluntaryGuidelineUSHigh riskLimited risk

OCC Updated Model Risk Management Guidance (2026)

Issued by

Office of the Comptroller of the Currency

liveEffective 2026-04-17OCC-MRM-26Updated September 2026
Official document →

The Office of the Comptroller of the Currency has issued updated model risk management guidance establishing revised expectations for how national banks and federal savings associations develop, validate, monitor, and govern models. The guidance applies to all institutions supervised by the OCC that use models in material business decisions, with particular relevance where AI or machine learning is embedded in credit underwriting, pricing, fraud detection, or compliance monitoring workflows. Institutions are expected to maintain rigorous validation programs, clear governance structures, and documented controls proportionate to the risk a given model presents.

Applies To

Large enterpriseAI deployerAI developerPublic sector

Overview

The OCC's updated model risk management guidance revises and extends prior supervisory expectations, most notably those originally established under OCC Bulletin 2011-12, to address the expanded use of AI and machine learning models in banking operations. The guidance covers the full model lifecycle, including development, implementation, validation, ongoing monitoring, and retirement, and applies to models used in any material business function at OCC-supervised institutions. Key provisions strengthen requirements around independent model validation, documentation standards, and board-level governance oversight of model inventories. Institutions must demonstrate that validation processes are technically sound and that validators possess sufficient expertise relative to the model type being reviewed, including familiarity with AI-specific risks such as data drift, explainability limitations, and emergent behavior. The guidance also reinforces expectations for ongoing performance monitoring, requiring institutions to detect and respond to model degradation in a timely manner. Supervisory examinations will assess compliance with these expectations, and deficiencies may result in Matters Requiring Attention or formal enforcement actions.

Key Requirements

  • Maintain a complete, current inventory of all models in use, classified by materiality and risk level.
  • Conduct independent validation of all material models prior to deployment and on a periodic basis thereafter, with validation frequency tied to model risk tier.
  • Ensure validators have sufficient technical expertise for the model type under review, including AI and machine learning methodologies where applicable.
  • Establish board or senior management oversight of the model risk management framework, including review of aggregate model risk exposure.
  • Implement ongoing monitoring programs capable of detecting performance degradation, data drift, and changes in model behavior, with defined escalation thresholds.
  • Document all model development assumptions, limitations, and validation findings in a manner accessible to examiners; deficiencies may result in Matters Requiring Attention or formal enforcement action.

What Your Organization Must Do

  • Audit the institution's full model inventory and confirm each model is classified by risk tier and materiality before the next scheduled examination cycle.
  • Assess whether current validation teams have documented expertise in AI and machine learning techniques for any model using such methods in credit, pricing, or monitoring decisions.
  • Update model validation policies to explicitly address AI-specific risk factors including data drift, feature instability, and explainability constraints.
  • Establish or refresh board-level reporting on aggregate model risk, ensuring senior governance bodies receive regular summaries of validation findings and open deficiencies.
  • Define quantitative monitoring thresholds for model performance metrics and document the escalation process triggered when those thresholds are breached.
  • Review vendor and third-party model arrangements to confirm that validation rights, documentation access, and monitoring obligations are contractually specified and operationally enforced.