SR 11-7 Compliance
What 'SR 11-7 compliance' means now that SR 11-7 itself has been replaced.
SR 11-7 was formally rescinded on April 17, 2026 and replaced by the interagency guidance SR 26-2. Institutions still describing their program as 'SR 11-7 compliant' should update to reference SR 26-2, which preserves SR 11-7's core disciplines, effective challenge, independent validation, governance, while shifting to a risk-based, tailored supervisory approach.
Real US search demand (Ahrefs): ~100 searches/mo for "sr 11-7 compliance".
The buyer problem
For fifteen years, 'SR 11-7 compliant' was the shorthand institutions, vendors, and consultants used to describe a sound model risk management program. As of April 17, 2026, SR 11-7 no longer exists as current guidance, it was rescinded and replaced by SR 26-2 (and companion OCC Bulletin 2026-13, issued jointly with the Fed and FDIC). Institutions, board members, and vendors still using 'SR 11-7 compliant' language risk sounding out of date to an examiner, even when the underlying program is otherwise sound. This guide explains exactly what changed and what an institution should verify and update, distinct from the broader model risk management framework guide, which covers full framework design.
What a sr 11-7 compliance engagement covers
Firms and internal teams working through this transition typically perform a targeted gap review comparing existing policy and program documentation against SR 26-2's specific changes: the risk-based revalidation cadence (replacing SR 11-7's de facto annual cycle), the refined model definition (excluding simple spreadsheet arithmetic and deterministic rule-based processes), expanded vendor/third-party model oversight, and the explicit exclusion of generative and agentic AI from current scope. The deliverable is usually a focused update to policy language, board materials, and vendor contract references, rather than a full framework rebuild, since SR 26-2 preserves most of SR 11-7's underlying structure.
Methods and techniques
- Targeted gap review: SR 11-7-era documentation against SR 26-2
- Revalidation-cadence policy update (calendar-based to risk-based)
- Model definition and inventory-scope reconciliation
- Vendor/third-party model oversight language update
- Board and management reporting-template refresh
What to verify before you retain
- Every reference to 'SR 11-7' in policy documents is reviewed. Search all MRM policy, board materials, and vendor contracts for 'SR 11-7' references and confirm whether each should now cite SR 26-2 instead.
- Revalidation cadence reflects a risk-based approach. If your policy still says 'all models revalidated annually,' confirm whether that blanket approach needs updating to tie cadence to materiality, change velocity, and data availability per SR 26-2.
- Model definition excludes what SR 26-2 excludes. Confirm your inventory doesn't still capture simple spreadsheet arithmetic or deterministic rule-based tools that SR 26-2 explicitly removed from the 'model' definition, unnecessary inventory bloat wastes validation resources.
- Generative/agentic AI scope is correctly understood. SR 26-2 explicitly excludes generative and agentic AI models from its current scope; don't assume SR 26-2 gives cover for those tools without separate, forthcoming guidance.
- Vendor contracts reference current guidance. If any vendor or software contract language cites SR 11-7 or OCC Bulletin 2011-12 as the compliance standard, confirm it should be updated to SR 26-2/OCC Bulletin 2026-13.
Questions to put in your RFP
- Can you do a focused SR 11-7-to-SR 26-2 gap review rather than a full framework rebuild, if our program is otherwise sound?
- How would you update our revalidation cadence policy to reflect a risk-based approach?
- How should we handle models currently in our inventory that no longer meet SR 26-2's refined model definition?
- What language changes do you recommend for vendor and software contracts that still cite the rescinded guidance?
- How should we address generative/agentic AI tools given they remain outside SR 26-2's current scope?
Skip the cold search. Send this scope to us and we route it toward qualified sr 11-7 compliance firms.
Request firmsRed flags
- A firm or vendor still marketing 'SR 11-7 compliance' services with no acknowledgment that SR 11-7 was rescinded.
- Recommending a full framework rebuild when a targeted gap update would suffice for an otherwise sound program.
- Claiming SR 26-2 covers generative or agentic AI models when the guidance explicitly excludes them.
- No clear plan for updating vendor contract language that references the rescinded guidance.
Frameworks referenced
Named regulatory guidance relevant to this category. Listed for context; they do not endorse this index or any vendor. Verify any framework alignment claim directly against the issuing body.
- SR 26-2
- SR 26-2 / OCC Bulletin 2026-13: Revised Guidance on Model Risk Management. SR 26-2 (issued by the Federal Reserve as a Supervisory Letter, and simultaneously as OCC Bulletin 2026-13 and an FDIC Financial Institution Letter) reflects fifteen years of supervisory experience since SR 11-7 and updates model risk management expectations for a risk-based, tailored era. It is expected to be most relevant to banking organizations with over $30 billion in total assets. The guidance retains the three foundational pillars, model development and use, validation and ongoing monitoring, and governance and controls, while replacing SR 11-7's de facto annual review cycle with revalidation frequency tied to model materiality, change velocity, and data availability, and expanding attention to vendor and third-party models. Read more →
- SR 11-7
- SR 11-7: Guidance on Model Risk Management. Issued April 4, 2011 jointly with the OCC (as Bulletin 2011-12), SR 11-7 set out supervisory expectations for how banks should manage the risk that quantitative models produce incorrect or misused results. It organized model risk management around three pillars: model development, implementation, and use; model validation; and governance, policies, and controls, and introduced 'effective challenge' as the guiding principle for meaningful independent review. Read more →
- OCC 2011-12
- OCC Bulletin 2011-12: Sound Practices for Model Risk Management. OCC Bulletin 2011-12, 'Supervisory Guidance on Model Risk Management,' articulated the elements of a sound program for managing risk from quantitative models used in bank decision-making. Its text was substantively identical to the Federal Reserve's SR 11-7, reflecting that both agencies developed the guidance jointly, and it applied to national banks and federal savings associations supervised by the OCC. Read more →
Notable sr 11-7 compliance vendors
Real, publicly-documented vendors active in this category. Sourced and verified; not a ranking or endorsement.
SR 11-7 Compliance: buyer FAQ
Do we need to redo our entire MRM program because SR 11-7 was replaced?
Usually not. SR 26-2 preserves SR 11-7's core disciplines. Most institutions need a targeted update, revalidation cadence, model definition scope, vendor model language, rather than a full rebuild, unless the underlying program had gaps independent of the guidance change.
Is there a compliance deadline for updating to SR 26-2?
SR 26-2 does not set a specific compliance deadline and explicitly states it does not establish enforceable or prescriptive requirements. That said, examiners will expect current program documentation going forward, so updating promptly avoids looking out of date at your next exam.
What's the difference between this guide and the OCC-specific guide?
This guide covers the broader interagency SR 11-7-to-SR 26-2 transition across the Fed, OCC, and FDIC. The OCC model risk management guide focuses specifically on OCC Bulletin 2026-13 and OCC exam practice for OCC-supervised institutions.