← back to overview
SR 26-2 · regulation pack · preview

SR 26-2 — Risk Management for AI and Models

US Federal Reserve / OCC / FDIC interagency guidance replacing SR 11-7. Extends Model Risk Management to AI systems explicitly — covers foundation models, third-party AI services, agentic AI, and continuous monitoring obligations for banks supervised by the Federal Reserve System.

jurisdiction · US version · 2026.04 effective · April 17, 2026 requirements · 7
requirements — preview
II.1 · Principle high-risk gate

Scope — AI systems are models

Any AI system that influences a business decision falls within the MRM perimeter, including foundation models accessed via third-party APIs.

artifact: model_cardartifact: vendor_register_entry evidence: model_inventoryevidence: model_doc
III.1 · Principle high-risk gate

Model development + implementation

Development and implementation must be thoroughly documented. For AI systems this includes data lineage, training-set provenance, and prompt versioning.

artifact: model_card evidence: model_docevidence: data_lineageevidence: prompt_versions
III.2 · Principle high-risk gate

Independent validation

Models must be validated independently and on a regular cadence; AI systems require eval-set pass rates and adversarial / red-team testing.

artifact: model_card evidence: eval_pass_rateevidence: validation_reportevidence: red_team_report
remaining 4 requirements — locked
III.3 · Principle

Governance, policies, and controls

Written policies, board and senior-management oversight. AI committee charter must explicitly cover foundation-model and agentic-AI usage.

III.4 · Principle

Ongoing monitoring + outcome analysis

Performance must be monitored against benchmarks continuously. AI systems additionally require drift detection on inputs, outputs, and refusal rates.

IV.1 · Principle

Third-party AI risk

Foundation models and managed AI services consumed from vendors must be governed through the third-party risk program — vendor due diligence, contractual rights to audit, and an incident-response runbook.

IV.2 · Principle

Autonomous + agentic systems

Agentic AI systems require explicit human-in-the-loop checkpoints for consequential actions, plus full traceability of tool invocations.

Unlock the full SR 26-2 pack

Get all 4 remaining requirements, generated reports, evidence-mapping templates, and the audit-chain export. Cancel anytime.

Unlock the pack → or full platform

Not ready to buy? Run the free EU AI Act gap report.

12-question intake mapped to Articles 9-15. Branded PDF in your inbox in minutes. No card required.

Free gap report →