Regulation — banking-specific

Federal Reserve SR 11-7 — Supervisory Guidance on Model Risk Management

The 2011 foundational document that every OCC / Fed / FDIC exam team measures a bank's AI credit-underwriting stack against. The rule does not care that your model is "AI" — it cares whether the model is governed, validated, and monitored on a defined cadence with independent challenge.

What the guidance actually says

"Model risk should be managed like other types of risk. Banks should identify the sources of that risk, assess its magnitude, and establish a framework for managing it. … The guiding principle for managing model risk is 'effective challenge' of models: critical analysis by objective, informed parties who can identify model limitations and produce appropriate changes." SR 11-7 (April 2011) — core framing
"Ongoing monitoring is essential to evaluate whether changes in products, exposures, activities, clients, or market conditions necessitate adjustment, redevelopment, or replacement of the model. … The purpose of ongoing monitoring is to confirm that the model is appropriate for its intended uses; annual model validation alone is not sufficient when conditions change." SR 11-7 — ongoing monitoring requirement

What this means in plain English

Three loops the AI credit-underwriting engine must sit inside:

  1. Governance. Board / senior-management oversight of model risk, documented policy, defined roles.
  2. Independent validation. Not the model builders. Not the vendor. Someone who can produce "effective challenge" — distinct methodology, distinct incentives.
  3. Ongoing monitoring. Between-annual-validation-cycle observation. Detect condition changes. Trigger re-validation when they land.

Annual model validation alone is the modal weak stance. SR 11-7 is explicit: it is not enough on its own when the underlying conditions shift.

What triggers the exposure in the sample

45+ days of silent between-audit drift. The bank's annual SR 11-7 validation cycle would not have caught the B3 divergence for months. During that window, every AI-generated credit decision in the affected group is a documented model-risk-management gap. Examiners look for exactly this pattern — drift running silently between validation cycles — when writing MRA / MRIA / MRO findings.

What the $499 Snapshot shows against this rule

See the drift chart that surfaces the finding →

How does this help me?

The rule is the framing. The consequence of an SR 11-7 finding — MRA / MRIA / MRO, capital-plan constraint, charter-application headwind — is a very different exposure profile.

Read: SR 11-7 -- what it saves you when the exam team lands →

$499 Snapshot. 3 business days.

Independent-verifier determination scoped to your bank's AI credit-underwriting surface + 3 fix-first items + signed declaration.

Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.