Model risk is the risk of adverse consequences from decisions based on incorrect, misused, or misunderstood quantitative models. Developed as a formal risk category in financial services, model risk management is now being extended to AI and machine learning systems, creating new governance obligations for APRA-regulated entities and, increasingly, any organisation deploying consequential AI. In the US, SR 26-2 (April 2026) explicitly excludes generative and agentic AI from its scope for now, treating them as too novel for the existing framework, a gap organisations still need their own governance to cover.
Run the free AI Health CheckModel Risk, the risk of adverse consequences arising from decisions based on incorrect or misused model outputs, encompassing data quality, model design, implementation, and ongoing use.
Model risk management is a long-established discipline in banking. Federal Reserve SR 11-7 (2011) was the original US baseline; it was superseded on 17 April 2026 by interagency SR 26-2, issued jointly with the OCC and FDIC, which shifts from a fixed annual revalidation cycle to risk-based oversight tied to model materiality. SR 26-2 explicitly excludes generative AI and agentic AI as "novel and rapidly evolving", it applies to traditional statistical and non-generative, non-agentic AI/ML models. The UK PRA's SS1/23 (2023) is technology-neutral and covers AI/ML under its general model definition. APRA CPS 230 incorporates equivalent expectations. AI does not introduce model risk; it amplifies it. The traditional three-lines model, model development, model validation, internal audit, extends to AI but requires new technical capability in the second line of defence.
Source: Federal Reserve SR 26-2 (2026, supersedes SR 11-7); PRA SS1/23; APRA CPS 230
Model risk governance originated in financial services following a series of high-profile failures in which quantitative models, credit scoring, risk measurement, derivative pricing, produced incorrect outputs with material financial consequences. Regulators including the US Federal Reserve (SR 11-7, superseded by SR 26-2 in April 2026), the European Banking Authority, and APRA developed frameworks requiring financial institutions to validate, monitor, and control the models they use in consequential decisions.
APRA-regulated entities, banks and insurers, are expected to manage model risk within their enterprise risk management frameworks under CPS 220, and superannuation trustees under the equivalent standard SPS 220. APRA's supervisory guidance has increasingly flagged that model risk management frameworks must extend to AI and machine learning systems, including: large language models used in customer communications; machine learning models in credit, pricing, and underwriting decisions; AI tools in claims handling and fraud detection; and third-party AI services accessed through APIs as material operational dependencies under CPS 230 (in force from July 2025).
Traditional model risk management was developed for relatively interpretable quantitative models, regression equations, actuarial tables, option pricing formulae. AI and machine learning models are more complex: they may have billions of parameters, non-linear relationships that cannot be directly inspected, and emergent behaviour that was not designed into the system. Standard validation techniques must be adapted or supplemented. The field of explainable AI (XAI) exists partly to address this gap, making AI model outputs interpretable enough to be validated and challenged.
The US and UK have taken different positions on where AI sits within model risk management. SR 26-2 explicitly carves generative AI and agentic AI out of scope, calling them "novel and rapidly evolving", while still covering traditional statistical models and non-generative, non-agentic AI/ML. The UK PRA's Supervisory Statement SS1/23 (effective 17 May 2024) is technology-neutral: its general model definition brings AI and machine learning into scope by default, and the PRA has since run supervisory roundtables specifically testing how firms apply SS1/23's principles to AI and machine learning. Organisations operating in both markets should not assume the same AI system is treated consistently by both frameworks.
What is "model risk" in banking and financial services?
Per the current US interagency guidance (SR 26-2), model risk is the potential for adverse financial consequences from decisions made using flawed, misapplied, or misunderstood model output. It can cause financial loss, errors in financial statements and regulatory reporting, or flawed risk decisions, and is a function of a model's inherent risk (its assumptions, complexity, data quality) combined with its materiality to the business.
Is SR 11-7 still the governing US guidance?
No. SR 11-7 (2011) was superseded on 17 April 2026 by interagency SR 26-2, issued jointly by the Federal Reserve, OCC, and FDIC. SR 26-2 also replaces SR 21-8 (the 2021 BSA/AML model risk guidance). It shifts from a fixed annual revalidation expectation to risk-based oversight tied to model materiality.
Does model risk management cover generative AI and AI agents?
Under the current US guidance, no. SR 26-2 explicitly excludes generative AI and agentic AI models from its scope, describing them as "novel and rapidly evolving", and states that firms' own risk-management practices should guide oversight of these systems in the interim. It covers traditional statistical and quantitative models plus non-generative, non-agentic AI/ML models under its ordinary definition of "model". The UK's PRA SS1/23 is technology-neutral and does not carve out AI, so AI/ML models used in bank decisioning generally fall within its scope.
Who does SR 26-2 apply to?
SR 26-2 states it is expected to be most relevant to banking organisations with over USD 30 billion in total assets supervised by the Federal Reserve. Institutions below that threshold are generally excluded unless model prevalence, complexity, or non-traditional activities create significant model-risk exposure.
Has the Basel Committee issued AI-specific model risk guidance?
No binding standard. The Basel Committee's only dedicated publication is a March 2022 newsletter on AI and machine learning that explicitly states it is for informational purposes only and does not constitute new supervisory guidance. The Financial Stability Board, a separate body, has been more active, publishing work on AI's financial stability implications and consulting in 2026 on sound practices for AI adoption.
Last reviewed July 2026