Skip to main content
Category: Compliance & Audit

SR 11-7 Supervisory Guidance on Model Risk Management

Also known as: SR 11-7, Supervisory Letter SR 11-7, Supervisory Guidance on Model Risk Management, SR 11-07
Simply put

SR 11-7 is supervisory guidance issued by the U.S. Federal Reserve in 2011 that describes how banking organizations should manage the risks that arise from using models in their decision-making. It set out expectations for how firms build, test, and oversee models so that errors or misuse do not lead to poor decisions or losses. According to the evidence provided, this guidance shaped industry practice for over a decade and is being succeeded by revised guidance (referenced as SR 26-2) effective in 2026.

Formal definition

SR 11-7 is the U.S. Federal Reserve supervisory letter, dated April 4, 2011, whose attachment describes the key aspects of an effective model risk management framework, including robust model development, implementation, and use, as well as validation and governance. In practice it has functioned as a detailed operating framework for identifying, measuring, monitoring, and controlling model risk, with policies that establish expectations for assessing the magnitude of model risk and applying model risk management accordingly. Based on the evidence, it is being modernized or replaced by a more principles-based supervisory framework (referred to as SR 26-2, with revised guidance dated April 17, 2026); the precise scope, binding status, and applicability across specific institution types should be confirmed against the current source documents rather than assumed from this entry.

Why it matters

For more than a decade, SR 11-7 functioned as the reference point that shaped model risk management practices across the U.S. banking industry. Its influence extends beyond the specific supervisory letter because it articulated an operating vocabulary and set of expectations, covering model development, implementation, use, validation, and governance, that many institutions adopted as the backbone of their internal frameworks. Understanding it matters because a large body of existing bank policy, validation methodology, and internal audit practice was built around its structure, and those foundations do not disappear simply because guidance is being revised.

The guidance also matters because it framed model risk as something to be identified, measured, monitored, and controlled rather than eliminated. That framing emphasizes that models are approximations that can be wrong or misused, and that firms should assess the magnitude of model risk and apply proportionate controls. Professionals treat SR 11-7 as detailed and prescriptive relative to more principles-based instruments, which affects how examiners, validators, and model owners set expectations for documentation and independent challenge.

SR 11-7 is now being succeeded by revised guidance referenced in the sources as SR 26-2, described as a modernized, principles-based supervisory framework with revised guidance dated April 17, 2026. This transition matters for anyone maintaining a model risk program, because the shift from a foundational, detailed operating framework toward a more principles-based approach can change how institutions demonstrate compliance. The precise scope, binding status, effective dates, and applicability across specific institution types should be confirmed against the current source documents rather than inferred from historical practice, as the sources here indicate change is underway but do not fully specify its final contours.

Who it's relevant to

Model risk managers and model validators
These professionals have historically built validation methodology, documentation standards, and independent challenge processes around the expectations articulated in SR 11-7. As guidance transitions toward the more principles-based framework referenced as SR 26-2, they are among the first who need to reconcile existing detailed practices with revised supervisory expectations, confirming specifics against current source documents.
Banking compliance and internal audit functions
Compliance officers and auditors rely on the SR 11-7 structure to assess whether policies define model risk management expectations and appropriately scale controls to the magnitude of model risk. They should note that the guidance is being succeeded by revised guidance and should not assume the historical framework remains the current supervisory standard without verification.
Model owners and developers within banking organizations
Those who build and use models are affected because SR 11-7 set expectations for robust development, implementation, and use, treating models as approximations whose errors or misuse can lead to poor decisions. The framework is meant to reduce and manage that risk rather than eliminate it, and developers should track how modernization may adjust documentation and testing expectations.
Policy specialists and regulatory affairs teams
These readers track the distinction between the foundational, detailed SR 11-7 framework and the modernized, principles-based approach in the revised guidance dated April 17, 2026. Because the precise scope, binding status, and applicability across institution types are not fully established by the available evidence, they carry responsibility for confirming the current instrument's requirements against the primary Federal Reserve sources.

Inside SR 11-7

Definition of Model and Model Risk
SR 11-7, issued jointly by the U.S. Federal Reserve (as SR 11-7) and the OCC (as Bulletin 2011-12), frames a model as a quantitative method that applies statistical, economic, financial, or mathematical techniques to process input data into estimates. Model risk is described as the potential for adverse consequences from decisions based on incorrect or misused model outputs, arising principally from fundamental errors in a model and from incorrect or inappropriate use.
Model Development, Implementation, and Use
The guidance addresses sound practices across the model lifecycle, emphasizing that model risk should be managed from the point of design through deployment and ongoing use, and that the purpose and limitations of a model should be understood by those who rely on it.
Model Validation
SR 11-7 describes validation as a set of processes and activities intended to verify that models are performing as expected and in line with their design objectives and intended business uses. Validation is commonly framed as encompassing evaluation of conceptual soundness, ongoing monitoring, and outcomes analysis (such as back-testing), and typically calls for effective challenge by parties with appropriate independence, competence, and authority.
Governance, Policies, and Controls
The guidance situates model risk management within a broader governance structure, including board and senior management oversight, written policies and procedures, defined roles and responsibilities, and controls such as model inventories and documentation standards.
Documentation and Model Inventory
SR 11-7 emphasizes maintaining documentation sufficient for independent parties to understand and evaluate models, and commonly points toward keeping a comprehensive inventory of models in use to support oversight.
Scope of Application
The guidance is supervisory guidance directed at banking organizations supervised by the Federal Reserve and, in its OCC form, national banks and federal thrifts. It is not a statute and its terms are not automatically applicable to non-banking entities, though its concepts are frequently referenced by analogy in other sectors.

Common questions

Answers to the questions practitioners most commonly ask about SR 11-7.

Is SR 11-7 a law that applies to all companies using AI models?
No. SR 11-7 is supervisory guidance issued by the U.S. Federal Reserve (with a parallel instrument, OCC 2011-12, issued by the Office of the Comptroller of the Currency), directed at the banking institutions those agencies supervise. It is not a statute of general applicability, and it does not automatically extend to non-bank enterprises or to AI systems outside its supervised scope. Many organizations voluntarily draw on its principles as a reference model, but adopting it by choice is distinct from being legally bound by it. Whether and how it applies to a given firm depends on that firm's regulatory status.
Does SR 11-7 govern AI governance, or does it address model risk management?
SR 11-7 is framed primarily around model risk management — the identification, measurement, monitoring, and control of risks arising from the use of models — rather than AI governance as a broad organizational discipline. Model risk management and AI governance overlap, particularly around oversight, accountability, and controls, but they are not the same thing. AI governance typically concerns the wider organizational structures, policies, and accountability arrangements for AI systems, whereas SR 11-7's focus is the risk posed by models themselves. Treating the guidance as a comprehensive AI governance framework can overstate its scope.
How do institutions commonly structure roles and responsibilities to align with SR 11-7?
Institutions frequently organize model risk responsibilities using a lines-of-defense structure, distinguishing model owners and developers (commonly associated with the first line) from independent model risk oversight and validation functions (often the second line) and internal audit (typically the third line). The intent is to keep model development separate from independent challenge and validation. The specific mapping of functions to lines varies by institution, and firms should confirm their own arrangements rather than assume a single standard structure; the guidance emphasizes independence and effective challenge more than any particular org chart.
What is typically expected in model validation under this guidance, and how does it differ from verification?
Validation, as commonly framed in connection with SR 11-7, is an ongoing, independent process to evaluate whether a model is performing as intended and is suitable for its purpose, often described in terms of evaluating conceptual soundness, ongoing monitoring, and outcomes analysis. Validation should be distinguished from verification, which is more narrowly about confirming that a model was implemented correctly and computes what it was specified to compute. A model can be correctly implemented (verification) yet still be conceptually inappropriate for its use (a validation concern). Institutions should treat these as complementary but separate activities.
How is a model inventory used in implementing model risk management?
A model inventory is commonly used as a foundational control, providing a comprehensive record of models in use so that risks can be tracked, ownership assigned, and validation and monitoring scheduled. Maintaining such an inventory supports the ability to apply oversight proportionate to each model's risk. Practical challenges include defining what qualifies as a model within the organization's own policy, keeping the inventory current, and capturing dependencies between models. The precise contents and definitions used are typically set by each institution's internal policy rather than prescribed uniformly.
How do firms apply a risk-based or proportionate approach when resources are limited?
A risk-based approach commonly involves tiering models by factors such as materiality, complexity, and potential impact, then calibrating the intensity of validation, monitoring, and oversight to each tier so that higher-risk models receive greater scrutiny. This helps allocate limited resources, but it does not eliminate model risk; it manages and reduces it. Firms should document the rationale for their tiering, recognize that residual risk remains even after controls are applied, and revisit tiering as models, uses, and conditions change. The specific tiering criteria are generally determined by the institution and its supervisory expectations.

Common misconceptions

SR 11-7 is a law that applies broadly to all organizations using AI or models.
SR 11-7 is supervisory guidance issued by U.S. banking regulators (the Federal Reserve, with the OCC's parallel Bulletin 2011-12) directed at supervised banking organizations. It is not a statute of general applicability, and it does not by its own terms govern non-banking entities or AI systems outside that supervisory scope, even though many organizations adopt its concepts voluntarily.
Model validation and model verification mean the same thing under SR 11-7.
The guidance frames validation as a broad set of activities—covering conceptual soundness, ongoing monitoring, and outcomes analysis with effective challenge—aimed at confirming a model performs as intended for its use. Verification, as commonly distinguished by practitioners, refers more narrowly to confirming that a model was built or implemented correctly per specification. Treating them as interchangeable understates the breadth of what SR 11-7 describes as validation.
Following SR 11-7 eliminates model risk.
The guidance describes practices to identify, measure, monitor, and control model risk, not to remove it. Model risk cannot be eliminated; sound model risk management is presented as a means of reducing and managing it, and residual risk typically remains even after controls are applied.

Best practices

Maintain a comprehensive model inventory with documentation sufficient for an independent party to understand each model's purpose, design, assumptions, and limitations.
Establish independent validation with effective challenge from parties who have appropriate competence, authority, and independence from model development.
Treat validation as an ongoing activity across the model lifecycle—covering conceptual soundness, ongoing monitoring, and outcomes analysis—rather than a one-time approval event.
Define clear governance roles, written policies, and board and senior management oversight so that accountability for model risk is explicit.
Document model limitations and intended uses, and communicate them to users so that models are not applied outside the conditions for which they were designed.
When applying SR 11-7 concepts outside supervised banking organizations, do so as a voluntary reference framework and confirm which requirements are actually binding in your own jurisdiction and sector.