Regulation — banking-specific
Federal Reserve SR 11-7 — Supervisory Guidance on Model Risk Management
The 2011 foundational document that every OCC / Fed / FDIC exam team measures a bank's AI credit-underwriting stack against. The rule does not care that your model is "AI" — it cares whether the model is governed, validated, and monitored on a defined cadence with independent challenge.
What the guidance actually says
"Model risk should be managed like other types of risk. Banks should identify the sources of that risk, assess its magnitude, and establish a framework for managing it. … The guiding principle for managing model risk is 'effective challenge' of models: critical analysis by objective, informed parties who can identify model limitations and produce appropriate changes."
SR 11-7 (April 2011) — core framing
"Ongoing monitoring is essential to evaluate whether changes in products, exposures, activities, clients, or market conditions necessitate adjustment, redevelopment, or replacement of the model. … The purpose of ongoing monitoring is to confirm that the model is appropriate for its intended uses; annual model validation alone is not sufficient when conditions change."
SR 11-7 — ongoing monitoring requirement
What this means in plain English
Three loops the AI credit-underwriting engine must sit inside:
- Governance. Board / senior-management oversight of model risk, documented policy, defined roles.
- Independent validation. Not the model builders. Not the vendor. Someone who can produce "effective challenge" — distinct methodology, distinct incentives.
- Ongoing monitoring. Between-annual-validation-cycle observation. Detect condition changes. Trigger re-validation when they land.
Annual model validation alone is the modal weak stance. SR 11-7 is explicit: it is not enough on its own when the underlying conditions shift.
What triggers the exposure in the sample
45+ days of silent between-audit drift. The bank's annual SR 11-7 validation cycle would not have caught the B3 divergence for months. During that window, every AI-generated credit decision in the affected group is a documented model-risk-management gap. Examiners look for exactly this pattern — drift running silently between validation cycles — when writing MRA / MRIA / MRO findings.
What the $499 Snapshot shows against this rule
- Per-borrower-group distributional-shape analysis — the "ongoing monitoring" that annual validation misses
- Dated threshold + measured differential + severity classification — the effective-challenge record
- 3 fix-first items scoped to that AI surface — the "trigger for re-validation" starting point
- Independent-verifier signature — the exact "objective, informed party" stance SR 11-7 calls for
See the drift chart that surfaces the finding →
$499 Snapshot. 3 business days.
Independent-verifier determination scoped to your bank's AI credit-underwriting surface + 3 fix-first items + signed declaration.
Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.