Supersession Notice (April 17, 2026)

SR 26-2 and OCC Bulletin 2026-13 jointly supersede SR 11-7, SR 21-8, OCC Bulletin 2011-12, OCC Bulletin 2021-19, OCC Bulletin 1997-24, and the Comptroller's Handbook MRM booklet. The revised guidance was issued jointly by the Federal Reserve, OCC, and FDIC.

Key change for AI practitioners: SR 26-2 explicitly states that "generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." A future request for information (RFI) addressing AI-specific model risk management is planned but not yet issued.

What this means: Traditional quantitative models (credit scoring, fraud detection, capital calculation) remain governed by SR 26-2. GenAI and agentic AI systems fall into a regulatory gap. The SWT3 procedures documented below apply to both traditional MRM and the emerging AI governance space. Institutions deploying AI models should not wait for the RFI to establish governance practices.

Who this is for: Model Risk Management Officers, Chief Risk Officers, internal auditors, and OCC/Federal Reserve examiners evaluating model governance frameworks. If your institution uses AI or statistical models for credit, fraud, pricing, or capital decisions, this document maps SWT3 procedures to SR 26-2 (and its predecessor SR 11-7) examination requirements.

Contents

What Changed in SR 26-2 FIN Procedure Overview Control-by-Control Mapping The GenAI Governance Gap Examiner Quick Reference Recommended MRM Policy Language Document Lineage

What Changed in SR 26-2

SR 26-2 modernizes model risk management expectations while narrowing the definition of "model" to exclude GenAI and agentic AI. Key changes from SR 11-7:

AreaSR 11-7 (2011)SR 26-2 (2026)
Model definitionBroad: "quantitative method, system, or approach"Narrowed: adds qualifier "complex" and excludes simple arithmetic and deterministic rule-based processes
GenAI / Agentic AINot addressedExplicitly excluded from scope; future RFI planned
ProportionalityOne-size-fits-allTailored to institution size, complexity, and model footprint; most directly applies to institutions with >$30B assets
Issuing agenciesFed + OCCFed + OCC + FDIC (joint interagency)
Binding statusSupervisory guidanceExplicitly non-binding; non-compliance alone will not trigger supervisory criticism
SupersedesN/ASR 11-7, SR 21-8, OCC 2011-12, OCC 2021-19, OCC 1997-24, Comptroller's Handbook MRM

FIN Procedure Overview

SWT3 defines 5 procedures for model risk management. Each procedure produces a tamper-evident Witness Anchor that proves a specific MRM activity occurred, when it occurred, and what the outcome was. These procedures apply to both traditional quantitative models governed by SR 26-2 and AI/ML models that fall outside its explicit scope.

ProcedureWhat it provesSR 11-7 SectionExamination Focus
FIN-GOV.1Governance committee reviewed and approved the modelSection IIICommittee minutes, quorum, approval votes
FIN-MRM.1Model registered, version matches approved inventorySection VInventory completeness, version lineage
FIN-VAL.1Independent validator performed effective challengeSection VIValidator independence, sign-off records
FIN-MON.1Performance metric within threshold, no driftSection VIIPSI/CSI thresholds, alerting frequency
FIN-OUT.1Back-test completed, results within toleranceSection VIIISample adequacy, prediction accuracy

Control-by-Control Mapping

FIN-GOV.1

Model Governance Committee Approval

SR 11-7 requires: The board and senior management should ensure model risk management is part of the overall risk framework. A governance structure with clear roles and responsibilities should be established.

How SWT3 addresses it: When the Model Risk Governance Committee votes to approve a model, the vote is anchored with three factors: quorum requirement (factor_a), actual vote count (factor_b), and approval decision (factor_c). The anchor proves a properly constituted committee made a documented decision on a specific date.

What to show the examiner

The SWT3 anchor for FIN-GOV.1. Factor values confirm quorum was met and the vote was recorded. Cross-reference with your committee charter to confirm the quorum threshold matches governance policy. The anchor is independently verifiable with no vendor dependency.

FIN-MRM.1

Model Inventory and Lineage

SR 11-7 requires: A firm-wide model inventory should be maintained with version lineage, purpose, limitations, and risk tier for each model.

How SWT3 addresses it: Each time a model is deployed or updated, the SDK records whether the deployed model hash matches the approved version. PASS means production matches inventory. FAIL means a mismatch was detected, which could indicate an unauthorized model change.

What to show the examiner

The SWT3 ledger filtered by FIN-MRM.1 for your model. A continuous chain of PASS verdicts demonstrates the model in production has always matched the approved inventory. Any FAIL creates an auditable record of when a mismatch was detected.

FIN-VAL.1

Independent Model Validation

SR 11-7 requires: Validation should be conducted by qualified staff independent of model development. "Effective challenge" involves critical analysis by objective, informed parties.

How SWT3 addresses it: When an independent validator signs off, the sign-off is anchored. Factor_b confirms the validator signed. Factor_c records days since last validation for staleness tracking. The anchor proves effective challenge occurred on a specific date.

What to show the examiner

The SWT3 anchor for FIN-VAL.1 along with the validator's identity from ledger metadata. The examiner confirms: validation occurred, when it occurred, and the record hasn't been altered. Factor_c provides a built-in staleness indicator to compare against your validation frequency policy.

FIN-MON.1

Ongoing Performance Monitoring

SR 11-7 requires: Models should be subject to ongoing monitoring to confirm they continue to perform as expected. Deterioration should trigger review.

How SWT3 addresses it: The SDK records the performance metric (PSI, CSI, AUC, Gini) against its defined threshold at each monitoring interval. PASS means within bounds. FAIL means the threshold was breached, creating a tamper-evident record of when drift was detected.

What to show the examiner

The time series of FIN-MON.1 anchors. The examiner sees: monitoring frequency, consecutive PASS verdicts showing stability, and if drift occurred, exactly when. The cryptographic integrity layer binds all monitoring anchors into a single tamper-evident verification artifact.

FIN-OUT.1

Outcomes Analysis (Back-testing)

SR 11-7 requires: Outcomes analysis compares model outputs to actual outcomes. This should be performed regularly with sufficient sample sizes.

How SWT3 addresses it: Each back-testing cycle is anchored with: required sample size (factor_a), actual sample size (factor_b), and whether results were within tolerance (factor_c). PASS means adequate data and predictions aligned with reality.

What to show the examiner

The SWT3 anchor for FIN-OUT.1 from the most recent cycle. Factor_a vs factor_b proves sample adequacy. Factor_c proves tolerance was evaluated. The timestamp proves when the analysis was conducted. Compare frequency against your MRM policy.

The GenAI Governance Gap

SR 26-2 creates a documented governance gap for financial institutions deploying generative AI and agentic AI. The guidance explicitly states these technologies are "not within the scope" while acknowledging they present novel risks. Institutions cannot wait for the planned RFI to establish governance practices.

SWT3 Procedures That Address the Gap

The following AI-namespace procedures provide witness evidence for GenAI/agentic governance activities that SR 26-2 does not cover but examiners will increasingly expect:

ProcedureWhat it provesGap addressed
AI-MDL.1Model card registered with version, architecture, and intended use documentedGenAI model inventory (SR 26-2 Section V equivalent for AI)
AI-DRIFT.1Output drift detected or confirmed absent at monitoring intervalGenAI performance monitoring (SR 26-2 Section VII equivalent)
AI-GRD.1Safety guardrails active and testedGenAI output controls (no SR 26-2 parallel)
AI-FAIR.1Bias evaluation performed, results within thresholdFair lending / disparate impact for AI scoring models
AI-GOV.1AI governance policy reviewed and approvedBoard-level AI oversight (SR 26-2 Section III equivalent)
AI-EXPL.1Explainability method applied, output interpretableModel transparency for complex AI (effective challenge)
AI-HITL.1Human-in-the-loop review performed on high-risk decisionHuman oversight for automated decisions

These procedures produce the same tamper-evident Witness Anchors as the FIN procedures above. An institution can present a unified evidence chain covering both traditional models (FIN-*) and AI models (AI-*) to demonstrate comprehensive governance regardless of the regulatory gap.

Examiner Quick Reference

Examiner questionWhere to look
"Show me your model governance documentation"FIN-GOV.1 anchors. Each represents a committee vote with quorum and approval status.
"Is this model in your inventory?"FIN-MRM.1 anchors. PASS = hash matches approved version. FAIL = mismatch detected.
"Who validated this model?"FIN-VAL.1 anchors + ledger metadata for validator identity.
"How often do you monitor performance?"FIN-MON.1 anchor frequency. Daily anchors = daily monitoring.
"Has this model drifted?"FIN-MON.1 factor_c values. 0 = no drift. 1 = threshold breached.
"When was the last back-test?"FIN-OUT.1 most recent anchor timestamp.
"Can I verify this independently?"Yes. Public verifier or offline SHA-256 formula. No vendor dependency.
"How do I know records weren't altered?"Each anchor is a SHA-256 fingerprint. A periodic integrity rollup binds all anchors into a tamper-evident digest. Tampering breaks the chain.
"Where is the data stored?"Clearing Level 2+: factors only, no model details on TeNova side.

Recommended MRM Policy Language

When documenting SWT3 in your Model Risk Management Policy, consider language similar to the following:

The institution uses the SWT3 Witness Anchor protocol (TeNova Axiom) to create tamper-evident records of model governance decisions, validation sign-offs, performance monitoring results, and outcomes analysis. Each model risk management activity produces a cryptographic anchor that is independently verifiable without reliance on the vendor's infrastructure. The SWT3 Clearing Protocol is configured at Level [1/2/3] to ensure model-specific metadata is handled in accordance with the institution's data classification policy. A periodic integrity rollup provides an aggregate tamper-evident digest that can be furnished to examiners as a single verification artifact covering all model risk management activities for a given period.

Document Lineage