Skip to main content
Category: Compliance & Audit

OCC Bulletin 2011-12

Also known as: OCC 2011-12, Supervisory Guidance on Model Risk Management, Sound Practices for Model Risk Management: Supervisory Guidance on Model Risk Management, SR 11-7 (companion issuance by the Federal Reserve)
Simply put

OCC Bulletin 2011-12 was supervisory guidance issued by the U.S. Office of the Comptroller of the Currency (OCC) on April 4, 2011, describing sound practices for how banks should manage the risks that arise from using models. It set out expectations for identifying, measuring, and controlling model risk rather than acting as a rigid rulebook, and it was influential well beyond banking as a reference point for model risk management. Per OCC issuances dated April 17, 2026, this bulletin was rescinded and replaced with revised guidance, so practitioners should confirm which version applies to their situation.

Formal definition

OCC Bulletin 2011-12, titled 'Sound Practices for Model Risk Management: Supervisory Guidance on Model Risk Management,' was supervisory guidance issued by the OCC on April 4, 2011, describing key aspects of effective model risk management for supervised institutions. As supervisory guidance (as distinct from binding regulation), it articulated expectations for the identification, measurement, monitoring, and control of model risk arising from model use and potential model error. It was commonly regarded as a companion to the Federal Reserve's SR 11-7, and it should be distinguished from AI governance frameworks and from model performance measures, since its scope centered on model risk management practices. Based on OCC issuances dated April 17, 2026 (news release and Bulletin 2026-13), OCC Bulletin 2011-12 was rescinded and superseded by revised OCC model risk management guidance; the specific substantive changes in the replacement guidance are out of scope of this entry and should be verified against the current OCC issuance.

Why it matters

For more than a decade, OCC Bulletin 2011-12 served as one of the foundational reference points for how U.S. banks were expected to manage the risks arising from their use of models. Together with the Federal Reserve's companion issuance SR 11-7, it shaped a common vocabulary and set of expectations around identifying, measuring, monitoring, and controlling model risk. Its influence extended well beyond the banking institutions it directly applied to; practitioners in insurance, fintech, and, increasingly, AI and machine learning contexts frequently cited it as a de facto benchmark for sound model risk management practice, even though it was supervisory guidance for OCC-supervised institutions rather than a universal rulebook.

The practical importance of this bulletin lies in how it framed model risk as something distinct from model performance. It treated the risk of adverse consequences from decisions based on incorrect or misused models as a category requiring dedicated governance, validation, and control, not merely a question of whether a model performed well on a metric. This distinction remains central to how compliance officers, model validators, and auditors structure their programs.

Because the OCC rescinded and replaced this bulletin per issuances dated April 17, 2026, its status has changed, and practitioners must confirm which guidance currently applies to their situation. Historical references to "OCC 2011-12" in policies, procedures, and vendor documentation may now point to superseded expectations. The specific substantive changes in the replacement guidance are out of scope here and should be verified directly against the current OCC issuance.

Who it's relevant to

Model risk managers at OCC-supervised banks
Professionals responsible for model risk management programs have historically relied on this bulletin as a primary reference for structuring identification, validation, monitoring, and control activities. Because the bulletin has been rescinded and replaced per the OCC's April 17, 2026 issuances, they should confirm which guidance now governs their program and review existing documentation for outdated references.
Model validators and internal auditors
Validation and audit functions frequently used the expectations described in OCC Bulletin 2011-12 as a benchmark when assessing whether model risk controls were adequate. They should distinguish the historical guidance from the current OCC issuance and verify the substantive requirements of the replacement guidance directly, as those specific changes are out of scope of this entry.
Compliance and policy specialists
Those maintaining internal policies and mapping regulatory obligations should note that references to "OCC 2011-12" may now point to superseded guidance. It is worth distinguishing this model risk management guidance from AI governance frameworks, which address organizational oversight and accountability rather than the same set of model risk practices.
Practitioners outside banking who cite it as a reference
Data scientists and risk professionals in non-banking contexts have often treated OCC Bulletin 2011-12 as a de facto benchmark for model risk management, even though it was supervisory guidance directed at OCC-supervised institutions. Such practitioners should recognize both its limited direct scope and its rescinded status, and should not assume it reflects current OCC expectations.

Inside OCC Bulletin 2011-12

Model Risk Management Guidance
OCC Bulletin 2011-12 is the vehicle by which the Office of the Comptroller of the Currency issued supervisory guidance on model risk management to the institutions it supervises. It is commonly understood to correspond to the same supervisory guidance issued by the Federal Reserve as SR 11-7. As guidance rather than a statute or regulation, it sets supervisory expectations rather than codified legal requirements in the manner of a binding rule.
Definition of a Model
The guidance is typically associated with a broad functional definition of a model as a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical techniques to process input data into quantitative estimates. This scoping matters because it determines what falls within the model risk management perimeter.
Concept of Model Risk
Model risk is commonly framed in this guidance as the potential for adverse consequences from decisions based on incorrect or misused model outputs. This is distinct from model performance degradation; model risk encompasses fundamental errors and misuse, not only decline in accuracy over time.
Model Development, Implementation, and Use
The guidance is generally understood to address sound practices across the model lifecycle, including development, implementation, and appropriate use, so that risks are managed at their source rather than only at the point of review.
Model Validation
Validation is commonly described as a set of processes and activities intended to verify that models are performing as expected and are appropriate for their intended use, often including evaluation of conceptual soundness, ongoing monitoring, and outcomes analysis. Validation as framed here should not be conflated with verification of narrow implementation correctness.
Governance, Policies, and Controls
The guidance is typically associated with expectations around governance structures, policies, roles and responsibilities, and controls that establish accountability for model risk. This governance dimension overlaps with broader AI governance concerns but is scoped to model risk in supervised banking institutions rather than enterprise AI generally.
Effective Challenge and Independence
A recurring theme associated with this guidance is the principle of effective challenge, meaning critical review by objective, competent, and appropriately empowered parties, supported by independence between those who develop models and those who review or validate them.

Common questions

Answers to the questions practitioners most commonly ask about OCC Bulletin 2011-12.

Is OCC Bulletin 2011-12 the same thing as SR 11-7?
They are closely related but issued by different agencies. OCC Bulletin 2011-12 is the Office of the Comptroller of the Currency's issuance of supervisory guidance on model risk management, while SR 11-7 is the corresponding guidance issued by the Federal Reserve. In practice the two are commonly treated as substantively aligned and are often cited together, but they are distinct instruments from distinct supervisory bodies. When precision matters, professionals should reference the instrument applicable to the institution's primary regulator rather than assuming they are interchangeable in every respect.
Does OCC Bulletin 2011-12 govern AI governance broadly, or only model risk?
As commonly understood, this guidance addresses model risk management—the identification, measurement, monitoring, and control of risk arising from the use of models—rather than the broader organizational structures and policies typically described as AI governance. There is overlap, particularly where AI and machine learning systems function as models within scope, but the guidance should not be read as a comprehensive AI governance framework. Applying it to modern AI systems raises interpretive questions that fall outside the original framing, and treatment of such systems continues to evolve.
How does an institution determine whether a given tool falls within the scope of model risk management under this guidance?
Scoping typically depends on whether the tool meets the definition of a model as understood in the guidance—generally a quantitative method or approach that applies statistical, economic, financial, or mathematical techniques to process inputs into estimates. Institutions commonly maintain a model inventory and apply documented criteria to classify tools, including borderline cases sometimes handled as end-user computing or non-model tools. Because scope determinations can be judgment-intensive and contested, institutions usually document their rationale and revisit classifications as tools change. This entry does not prescribe a single definitive scoping test.
What is expected in terms of validation versus ongoing monitoring?
Validation and ongoing monitoring are distinct activities that are often conflated. Validation, as commonly framed, is an independent assessment of whether a model is conceptually sound and performing as intended, typically including evaluation of conceptual design, outcomes analysis, and process verification. Ongoing monitoring is the continuing activity that tracks a model's performance and use over time and can surface performance degradation. Institutions generally treat validation as periodic and event-driven while monitoring is continuous, though specific cadence and rigor commonly scale with the assessed risk of the model.
How is independence typically established for model validation functions?
Independence is commonly addressed through organizational separation between those who develop or own models and those who validate them, an arrangement often described in relation to the three lines of defense. In many implementations, validation sits in a second-line function distinct from first-line model developers and owners, with reporting lines intended to reduce conflicts of interest. Where full organizational separation is impractical, institutions commonly compensate with alternative controls such as heightened documentation, review by parties not involved in development, and clear escalation. The specific structure varies by institution size and complexity.
How do institutions typically document and evidence compliance with these expectations?
Documentation commonly includes a maintained model inventory, model development and validation records, ongoing monitoring results, policies and procedures defining roles and standards, and evidence of governance oversight such as committee review and issue tracking. The aim is generally to allow an independent party—including examiners or auditors—to understand a model's purpose, limitations, and controls without relying on the original developers. These are risk-reduction and traceability measures rather than guarantees of correctness, and expectations for depth typically scale with the materiality and complexity of the models involved.

Common misconceptions

OCC Bulletin 2011-12 is a binding regulation that applies to all organizations using AI.
It is supervisory guidance issued by the Office of the Comptroller of the Currency to the banking institutions it supervises, not a universally applicable statute. It is scoped to supervised institutions and to models as commonly defined, not to every AI system in every sector. Firms outside its supervisory scope may reference it as a leading practice, but that is voluntary rather than compelled by this instrument.
Model validation under this guidance is the same thing as verifying that code was implemented correctly.
Validation as framed in the guidance is broader than implementation verification. It is commonly understood to assess conceptual soundness, ongoing monitoring, and outcomes analysis, whereas verification typically addresses whether a system was built to specification. Treating the two as interchangeable understates the scope of validation.
Model risk and model performance degradation are the same concern.
Model risk, as commonly framed in this guidance, encompasses adverse consequences from incorrect or misused model outputs, including fundamental design errors and inappropriate use. Performance degradation over time is only one contributor. A model can perform as measured yet still create model risk through misuse or misapplication.

Best practices

Apply a clear, functional definition of what constitutes a model within your organization so the model risk management perimeter is explicit, and document why items are in or out of scope.
Establish independence and effective challenge by separating those who develop models from those who review or validate them, and ensure reviewers are competent and appropriately empowered.
Treat validation as broader than implementation verification, addressing conceptual soundness, ongoing monitoring, and outcomes analysis rather than only checking that code runs as specified.
Manage model risk across the full lifecycle, including development, implementation, and use, rather than relying solely on a review at the end.
Document governance structures, policies, roles, and controls so accountability for model risk is assigned and traceable, and revisit them as models and their uses change.
Recognize the guidance's supervisory scope and jurisdiction; if you operate outside supervised banking institutions, treat it as an optional reference point and confirm which frameworks actually bind your organization.