THE EXECUTIVE VIEW
Three takeaways
Connect model oversight to business use, exposure and the consequences of error.
Scale the depth of review without losing visibility of important limitations.
Keep generative and agentic AI within an appropriate governance process, despite their exclusion from this guidance.
Establish where the guidance applies
On 17 April, the Federal Reserve, OCC and FDIC issued revised model risk management guidance. It replaces the earlier framework and emphasises tailoring to an institution's model risk profile, size and complexity. It is expected to be most relevant to banking organisations with more than $30 billion in assets, although it can be relevant to smaller organisations with significant model risk. Federal Reserve SR 26-2 (opens in a new tab)
The agencies describe this as nonbinding supervisory guidance. Its scope expressly excludes generative and agentic AI models, while covering traditional quantitative models and non-generative, non-agentic AI models. The exclusion does not remove the need for appropriate governance of tools outside its scope. Revised guidance, purpose and scope (opens in a new tab)
For organisations outside the relevant US banking perimeter, the useful question is how the underlying approach might improve their own arrangements. It should not be presented as a new obligation applying to every financial services firm or every use of AI.
Make the business decision visible
A model inventory becomes useful to leadership when it explains the decisions that depend on each model. Technical classification alone gives an incomplete picture. Two models using similar methods can create very different exposures if one supports an analyst's judgement and the other determines large volumes of customer outcomes with limited intervention.
Begin with the purpose, intended users and consequences of error. Establish how much activity depends on the output, how quickly a problem would become visible and what alternatives would be available. Identify situations in which users could apply the result outside the conditions for which it was assessed.
Consider a hypothetical business that uses a model to prioritise customer reviews. Expansion into a new customer segment could change the relationship between its inputs and the outcome being predicted. A performance result from the original population would provide limited assurance about that new use. The decision to expand should therefore include a fresh assessment of the relevant evidence and limitations.
This view helps leaders distinguish model improvements that support growth from changes that add exposure the organisation is not yet equipped to manage. It also gives the model owner a clearer basis for explaining what the model can reasonably support.
Allocate challenge according to consequences
Proportionate review needs an explicit rationale. A lower-risk application may justify a lighter assessment, while a model central to financial decisions or customer treatment may need deeper independent challenge. Record why the chosen level of scrutiny is appropriate and what would cause it to change.
The reviewer should be able to test whether the evidence supports the intended use. That includes the suitability of the data, the assumptions that matter and the conditions under which performance may deteriorate. A technically impressive result can still be unsuitable for a particular business decision.
Management should also understand the options when limitations remain. These might include restricting the model's use, introducing additional review of outputs or delaying expansion until stronger evidence is available. The decision should identify who accepts the remaining exposure and when it will be reconsidered.
This makes the process more predictable for delivery teams. They can plan the evidence required before investment is committed, and they can understand why a material change requires additional scrutiny. Review becomes easier to resource when the organisation knows which decisions justify specialist attention.
Keep oversight connected to use
Approval should establish how the business will recognise that a model is no longer performing as intended. Agree which indicators matter, who investigates a breach and what action is available while an investigation proceeds. An indicator without an owner or a defined response adds little protection.
Look beyond a single aggregate performance measure. The business may need to understand whether results differ materially across customer groups, whether inputs have changed or whether users are overriding outputs more frequently. The right measures depend on the application; a uniform dashboard can hide the differences that deserve attention.
Supplier-provided models need the same clarity about use and limitations. The firm should establish what information it can obtain, what independent testing is feasible and how it will manage constraints on transparency. A supplier's assurance should be assessed against the decision the organisation intends to make.
Maintain a clear route for tools outside the guidance's scope, including generative and agentic AI. Assign ownership and evaluate the permissions, information and actions involved. That assessment may require a different method, but it should still connect the tool's capabilities to business consequences.
For the next executive review, ask which decisions rely most heavily on model outputs, where evidence is weakest and whether oversight capacity matches the growth plan. A scalable approach gives leaders enough information to support appropriate use, restrict it where necessary and invest in the improvements that matter most.
April 2026 perspective. Sources reflect information available at the issue date.
