A mid-market bank or specialty lender that runs AI models should keep a record for each one, ready before an independent AI governance audit or an examiner asks for it. The record names the data each model reads, the system each field comes from, who approved that use, and the date it was approved.
On April 17, 2026 the Federal Reserve, the OCC and the FDIC issued revised model risk management guidance that supersedes and replaces SR letter 11-7. The letter is expected to be most relevant to banking organizations with over $30 billion in total assets; below that line, generally excluding them from this guidance is consistent with a tailored supervisory approach, though it may still reach banks with significant model risk exposure. Even then, the OCC's release says it does not set forth enforceable standards or prescriptive requirements, and non-compliance will not result in supervisory criticism. A specialty lender that is not itself a banking organization sits outside the letter entirely, and the record above is then a standard its own board sets. The same three agencies say they plan to issue in the near future a request for information that addresses model risk management generally and considers, in particular, banks’ use of AI. Generative and agentic AI models are not within the scope of this guidance, leaving controls to the bank's own governance practices.
The guidance defines a model as a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates, excluding spreadsheets and deterministic rule-based processes with no such theory behind them, and counts the quality of inputs for the model, and data constraints among the factors in a model's inherent risk. It calls a model inventory common practice, with sufficient information to understand model risks.
KPMG, which sells audit and advisory services, asked 1,013 senior finance leaders, 58 percent of them in technology and financial services, at organizations with annual revenues of at least 250 million US dollars, 500 million in the United States, across 20 countries, online in March 2026, and reported on May 11, 2026 that fewer than half of organizations (42 percent) are fully assurance-ready for AI-enabled finance processes, meaning able to produce audit evidence and explain it.
At a specialty lender, one line of the record might read: model, the consumer loan credit decision model; data read, applicant fields from the loan origination system, tradelines and scores from the credit bureau feed, payment history from the servicing system; approved by, the chief credit officer and the head of servicing, each for their own fields; approved on, March 3, 2026.
In the first month the model risk lead, or the chief risk officer where none exists, lists every model and AI tool from the inventory, IT's software list and purchasing record; the CFO adds finance's own tools. In the second, data owners approve fields in writing, riskiest models first. In the third, internal audit takes the role the guidance gives it: to evaluate whether the model risk management practices are rigorous and effective. The CFO then takes it to the board's risk committee, gaps included. No source prices this work. The record above is what a buyer should check.
A generative tool that summarizes loan files sits outside this guidance too, and the record above is how the bank's own governance covers it.