Compliance
SR 11-7 model risk
Model risk management discipline applied to AI and LLMs. Monitoring, validation, and change history in one place.
At a glance
Who this covers, and who enforces it
Banking organizations regulated by the Federal Reserve, OCC, or FDIC that develop or rely on models — including AI and LLM-based systems — for decisions.
On 17 April 2026, the Federal Reserve, OCC, and FDIC issued SR 26-2, which supersedes the original 2011 SR 11-7 letter this framework is still commonly searched for. The screenshot, source link, and requirements below reflect SR 26-2, the guidance currently in force.
- Instrument
- SR 26-2 supervisory guidance (formerly SR 11-7)
- Issued by
- Federal Reserve, OCC, and FDIC jointly
- Timeline
- 17 Apr 2026 — supersedes SR 11-7 (2011)
- Most relevant
- Banking organizations over $30B in assets
- Enforcement
- Supervisory examinations and findings
Requirements
What it asks for
- 1Maintain a model inventory with documentation
- 2Perform independent validation before and during use
- 3Run ongoing performance monitoring
- 4Apply governance and change-control discipline
Evidence mapping
What PRISM records against each requirement
Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.
- Model inventory & documentation
- Model Inventory registers every AI system with an owner and version.
- Independent validation
- Evaluators run reviewer-attested test criteria against real activity.
- Ongoing monitoring
- Traces, Sessions, and Scores & Alerts form the continuous monitoring record.
- Governance & change control
- The Audit Log timestamps every configuration and access change with an actor.
Primary source
Read the actual text
Everything on this page is drawn from Federal Reserve — SR 26-2, Revised Guidance on Model Risk Management. The capture is live, not a paraphrase — go straight to the source and check us.

Evidence, not certification
This page describes SR 11-7 model risk’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. SR 11-7 model risk compliance remains your organization’s responsibility, in consultation with qualified counsel.
Keep reading
- All frameworksThe full evidence-layer overview and all twelve frameworks.
- NY DFS Part 500Cybersecurity oversight extended to AI systems, with incident evidence and access records examiners expect.
- NAIC Model BulletinAI governance for insurers: documented testing, decision oversight, and incident handling with evidence attached.
Ask us about your framework
Tell us how SR 11-7 model risk applies to your systems and we'll show you the evidence path.