Model Risk Management for AI Agents Under SR 11-7
Banks must apply model risk discipline to AI agents even though regulators carved them out.

The article shows practitioners exactly how those requirements map onto agentic AI systems and what governance evidence regulators will expect.
Origins and Scope of SR 11-7
The guidance, issued April 4, 2011, jointly by the Federal Reserve and OCC (as OCC Bulletin 2011-12), came about because quantitative models had become central to bank decision-making.
The guidance defined a model in three parts: something goes in, something processes it, something comes out, and that output has to be quantitative. Three pillars held the whole structure up. Development, implementation, and use covered documentation, data quality, and testing before and after release. Validation demanded an independent, technically competent review with real authority to force changes, scaled to how much the model mattered. Governance meant an inventory, clear ownership, a risk rating, and something regulators called effective challenge.
That phrase, effective challenge, recurs constantly once agentic AI enters the picture. It means a credible, independent reviewer with both the skill to find a model's flaws and the standing to make someone fix them. Simple to write down. Much harder to execute once the object being reviewed stops behaving like a model.
Why did this framework hold for a decade and a half without a major rewrite? Because the models it governed were deterministic. A bank built them or a vendor fully specified them, and every output traced back to an equation someone could inspect. Validate the equation once, confirm it still applies, and the job was done. Agentic AI erases every one of those assumptions, which is exactly why the guidance built on them needed to go.
The framework changes introduced on April 17, 2026
On April 17, 2026, the Federal Reserve, the FDIC, and the OCC rescinded SR 11-7, OCC Bulletin 2011-12, FIL-22-2017, and the related BSA/AML issuances tied to them. In their place: SR 26-2 from the Federal Reserve, OCC Bulletin 2026-13, and FDIC FIL-15-2026. Read that list and it looks like housekeeping. It isn't. Regulators are saying, in effect, that model risk now deserves the same seriousness as credit risk or market risk.
Risk-based tailoring means every model sits in a tier that reflects its inherent risk, its exposure, and its purpose, and the tiering itself has to be documented, not just claimed. Lifecycle thinking treats development, validation, deployment, monitoring, and retirement as one connected chain, so supervisors expect to trace lineage across every handoff rather than reviewing snapshots. Effective challenge now requires versioned, reproducible testing. Continuous monitoring tracks performance drift and data drift against thresholds tied to how much a failure would matter. And the guidance pushes risk controls to the very front of the lifecycle, a move regulators are calling "shift left".
The 2026 rules also narrowed what counts as a model in the first place. Coverage now applies to complex quantitative methods built on statistical, economic, or financial theory, and it explicitly excludes simple arithmetic and deterministic rule-based software. That narrowing sounds like it should shrink the scope of MRM. For agentic AI, it does something odder: it carves the technology out entirely. The guidance names generative and agentic AI as "novel and rapidly evolving" and puts them outside formal scope for now, while signaling that a request for information on AI and agentic model risk is coming.
So what should a bank actually do with a carve-out like that? The practical answer: keep applying MRM principles wherever the underlying risk warrants it. The formal rule stepped back. The risk did not go anywhere, and neither should the discipline built to manage it.
Proportionality softens the burden somewhat. Institutions under $30 billion in total assets aren't expected to run programs at the same intensity as the largest institutions, and OCC Bulletin 2025-26 has clarified that community banks aren't required to perform annual model validation Neurons Lab Anthropic / TrustX ARC. For everyone else, the transition itself is a real workload: something like two to three quarters of sprint work covering inventory migration, rewritten validation templates, new monitoring pipelines, refreshed documentation, vendor-model onboarding, and separate workstreams for GenAI and agentic systems running in parallel.
There's a state layer sitting on top of all this now, too. On September 16, 2026, the Conference of State Bank Supervisors released an AI supervisory framework for state examiners, covering governance and oversight, AI inventory and use cases, and generative AI's emerging applications. It's discretionary, meant to help examiners flag AI risk and decide when a deeper review is warranted. But discretionary tools get used. Banks that treat the federal carve-out as a green light are going to run into this framework at the state level regardless.
AI agents versus the models SR 11-7 was designed to govern
Start with what an agent actually is. It perceives, plans, and acts with a meaningful degree of autonomy, and it doesn't stop at producing an estimate the way a credit scoring model does. It executes the workflow itself.
Picture three of these running inside a bank right now. One agent pulls an applicant's file, prices the risk, and issues credit terms. Another triages an AML alert and decides, on its own, whether to close it or escalate it. A third rebalances a portfolio and places trades inside an approved mandate. Each one ends with a real action, something the institution will eventually have to justify to an examiner, and none of them produce a tidy number a validator can simply re-derive.
That's the structure that breaks the old assumption. Classic MRM assumed a fixed spec and a single, traceable answer. Generative and agentic systems break that assumption in three specific ways. First, non-determinism: run the same prompt twice and the answers can differ, so validation has to test a distribution of behavior rather than reproduce one fixed output. Second, there's no fixed specification to begin with. A traditional model is its equations. An agentic system is a prompt, a retrieval pipeline, and a foundation model bolted together, often from a vendor, with no closed-form spec anywhere in sight. Third, the core of the system usually isn't something the bank built. The foundation model comes from outside, which means due diligence has to reach into a component the institution can't fully inspect.
How bad is the fabrication rate? OpenAI's own system card from April 2025 reported its o3 reasoning model fabricating answers on 33 percent of one factual benchmark, a worse rate than the model that came before it Stanford RegLab / Seekr. A model failing one out of three factual questions, moving in the wrong direction as it got more capable. What does effective challenge even look like against a failure rate like that? A validator re-deriving an equation has nothing to check. There's no equation.
Agents also carry a security dimension classical MRM never had to model. They operate under service accounts and machine credentials, not human logins, and that expands the attack surface in ways a credit model never touched Neurons Lab Anthropic / TrustX ARC. Verizon's 2026 Data Breach Investigations Report found 48 percent of breaches involved a third party, up from 30 percent the year before, and agent identities sit squarely inside that growth Neurons Lab Anthropic / TrustX ARC. No credit scoring model has an analogue for that. A model that misprices risk loses money. An agent that gets hijacked acts. According to the TrustX ARC paper (arXiv, July 2026), Anthropic disclosed in November 2025 that a state-sponsored group manipulated Claude Code to conduct espionage against roughly 30 global targets, with the agent executing 80-90% of the attack autonomously, illustrating that ungoverned agentic systems carry risks with no analogue in a credit scoring model Neurons Lab Anthropic / TrustX ARC.
SR 11-7 pillars under strain when applied to agents that execute transactions
Development, implementation, and use starts with documentation. SR 11-7 asked banks to write down a model's purpose, its design theory, its methodology, its data, and its testing. For an agent, that list gets longer, including prompts, retrieval pipelines, the exact base model version in use, and the boundaries of whatever authority the agent's been delegated. Data quality strains even harder. Classical models get assessed on the training data behind them, checked once, revisited periodically. Agents ingest live, unstructured data at runtime, pulling from documents and systems the bank may not fully control in the moment. A training-time data quality review doesn't cover that. Governance has to extend into production, watching what the agent actually retrieves and acts on while it's acting.
Effective challenge is where things really strain. Classical challenge means re-deriving the math, running an alternative model against the same inputs, testing sensitivity to changed assumptions, all legible work because the model has a spec sitting still long enough to check. An agent gives a validator nothing to hold onto. The validator needs to see the actual document and the actual passage that produced that number, or there's no challenge happening at all, just trust. Without that kind of source traceability, effective challenge collapses into spot-checking, which is precisely the weak control supervisors are trained to spot. The workable fix treats the prompt, the retrieval pipeline, and the foundation model as one composite object: test it against representative cases, measure its hallucination rate directly, and log every output alongside the sources it drew from.
Governance, inventory, and monitoring is the third pillar, and it has to widen in both scope and intensity. A classical inventory holds one registered model per use case. An agent inventory needs to capture prompts, base models, agent instances, data sources, and tool integrations as connected pieces, each with a named owner and a risk rating. Monitoring has to grow the same way: performance drift against a benchmark is still relevant, but now it sits alongside hallucination rate, faithfulness to source material, and silent behavior shifts introduced by a base model update the bank never asked for or approved. Thresholds have to match the speed of the decision, too. An agent authorizing payments in under 200 milliseconds needs monitoring running on that same clock PYMNTS.
MRM is the regulatory floor. It exists to catch models that produce bad outputs or get used somewhere they shouldn't. AI governance sits on top of that floor, adding fairness, transparency, accountability, and strategic oversight into the mix. Banks need both. Satisfying MRM is a narrower achievement than running a real AI governance program, and treating the two as interchangeable is how gaps get missed. This is framed as a mapping exercise, pillar by pillar, structured to mirror what an MRM team or internal auditor would walk through.
Risk tiering for agentic systems: how to classify agents by the consequences of what they do
The 2026 guidance is blunt about tiering: every model sits in a tier that reflects its inherent risk, its exposure, and its purpose, controls scale to that tier, and the tiering itself needs evidence behind it beyond a label. General-purpose model risk frameworks weren't built with agents in mind, which is where the TrustX Agent Risk Classification Framework, published on arXiv on July 10, 2026, comes in. It covers seven distinct types of agentic AI systems and scores each one across twelve dimensions, deliberately structured so a high risk on any single dimension can't get averaged down by low scores elsewhere. It's built for the same audience MRM guidance already targets: governance practitioners, risk officers, developers, regulators.
Autonomy level does most of the work in deciding where an agent lands. An agent that surfaces a recommendation for a human to approve sits in a different tier than one that executes a payment outright, closes an AML alert without review, or rebalances a portfolio on its own. What matters is what happens when the agent gets it wrong, not just how often. It's what happens when it does.
A handful of practical dimensions fall out of that logic for banking agents specifically. Materiality asks whether a bad output causes financial loss, a regulatory breach, or reputational damage. Reversibility asks whether the action can be unwound before it settles. Autonomy asks whether a human checks the action before it executes or the agent just acts. Data sensitivity asks whether the agent touches customer PII, account records, or confidential credit files. Third-party dependency asks how much of the core model sits outside the bank's control. Systemic exposure asks whether correlated responses across multiple institutions' agents could amplify volatility together, the way S&P Global has warned automation now links trading, credit, and compliance systems in ways that can spread a shock rather than contain it.
Proportionality is visible here too, explicitly. A community bank under $30 billion doesn't need to run tiering at the same intensity as a globally systemic institution, and the tier structure itself should flex to match the bank's risk profile and operational complexity. The mechanics stay familiar even as the object gets more complicated: register prompts, base models, agents, and data sources as connected pieces in the inventory, each with an owner and a rating, the same registry discipline banks already run for credit models, just applied to something with more moving parts. The output is a three-tier governance output with mapped control recommendations.
Validation evidence regulators and auditors will expect for transaction-executing agents
The carve-out in SR 26-2 does not mean validation obligations disappeared. Supervisors and internal audit teams are already applying MRM expectations by analogy, and the CSBS examiner framework released September 16, 2026 puts real teeth behind that scrutiny at the state level.
Before an agent ever touches a live transaction, a handful of artifacts need to exist. A model definition document laying out the agent's purpose, the boundaries of what it's authorized to do, and what data it can reach. A composite inventory entry that registers the prompt version, the base model and its version, the retrieval pipeline, and every tool integration as one governed object with a named owner. A test plan needs actual results, including a representative case library that includes adversarial prompts and out-of-scope instructions, a measured hallucination rate against that library, and a faithfulness-to-source score for any retrieval-augmented component. An effective challenge memo written by an independent validator, laying out methodology, findings, limitations, and whatever authority got exercised if changes were required, work that simply can't happen without the source traceability discussed earlier. And threshold documentation spelling out exactly what the agent can do without a human signing off, at what dollar amounts, under what conditions. J.P. Morgan framed the underlying question at NY Tech Week 2026: what is a bank actually willing to delegate to a machine, at what threshold, and under what conditions?
Once the agent is live, the evidence obligation doesn't stop. Every automated action needs to generate an immutable log entry, the record that lets a bank later demonstrate a payment, an AML closure, or a credit decision happened inside its authorized parameters. That log is the foundation everything else in this piece rests on. Without it, there's no effective challenge, no tiering that means anything, and no way to answer an examiner who asks the only question that actually matters: how do you know the agent stayed inside the lines?
Sources
- Model Risk Management for Generative AI: How Banks Can Extend SR 11-7 to LLMs
- TrustX Agent Risk Classification Framework (ARC): Risk-Tiering Internally Created Agentic AI Systems
- Revised Guidance on Model Risk Management
- Supervisory Letter SR 11-7 on guidance on Model Risk ...
- SR 11-7 Rescinded: What Replaced It and the AI Gap
- Model Risk Management: Revised Guidance | OCC
- Visual memo: Key changes under the federal banking agencies’ revised model risk management guidance | Davis Polk
- SR 11-7 in the Age of Agentic AI: Where the Framework Holds – and Where It Strains


