Start Free Trial
Home/Regulations/SR 11-7 — Federal Reserve / OCC Model Risk Management Guidance — Regulatory Reference
Regulatory Reference
Financial Services Federal (US) high

SR 11-7 — Federal Reserve / OCC Model Risk Management Guidance — Regulatory Reference

OCC/Fed AI model validation and audit requirements — agent registry and policy enforcement are the primary enforcement layer.

Key Provisions
  • Model definition — quantitative methods used for business decisions, including AI/ML
  • Model risk = development risk + implementation risk + use risk
  • Three pillars — model development and implementation, model use, model validation
  • Effective challenge — independent and competent review of models
How AutoPIL Enforces It
  • Agent registry implements the model inventory SR 11-7 requires
  • Audit chain supports independent validation by exposing every decision the model contributed to
  • Policy YAML versioning provides the change-control record SR 11-7 expects
Audit LogPolicy EngineAgent RegistryAlert RulesLineage
AutoPIL Policy IDs
FS-SR117-INV-001AI Agent Inventory as Model Inventory
FS-SR117-VAL-001Model Validation Evidence Chain
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does SR 11-7 require for AI agents and automated decision models?
SR 11-7, issued jointly by the Federal Reserve and OCC, defines a model as any quantitative method used to inform business decisions — which explicitly captures AI agents that evaluate credit, detect fraud, or drive underwriting. The guidance requires a three-pillar program: rigorous development and implementation controls, documented model use policies, and independent validation through effective challenge. For AI agents specifically, this means maintaining a model inventory of every agent in production, versioned documentation of how each agent makes decisions, and an audit trail demonstrating that governance controls were applied consistently at the point of access — not reconstructed after the fact.
How does SR 11-7 apply to AI agent deployments at banks and broker-dealers?
SR 11-7 applies to any Federal Reserve member bank, bank holding company, or OCC-supervised national bank. It covers all models in scope regardless of whether the model is vendor-supplied, internally built, or embedded in a third-party AI system. An AI agent that retrieves customer data, scores creditworthiness, or flags transactions for review qualifies as a model under the guidance. Banks deploying AI agents must inventory them, document intended use, validate them independently, and monitor ongoing performance. Examiners from the Fed and OCC review model risk management programs during safety and soundness examinations — deficiencies can result in MRAs (Matters Requiring Attention) and mandatory remediation timelines.
What is the effective challenge requirement under SR 11-7 and how does it apply to AI?
Effective challenge under SR 11-7 means independent, competent review of a model's conceptual soundness, data integrity, and ongoing performance — conducted by staff separate from those who built or operate the model. For AI agents, this requirement is operationally demanding: validators need a decision-level audit trail showing exactly which data the agent accessed, under which policy, at what sensitivity level, and what the governance outcome was. Without pre-retrieval enforcement logs, validators are forced to reconstruct evidence from application logs that may be incomplete or mutable. SR 11-7 expects tamper-evident documentation — not reconstructed records.
How does AutoPIL support SR 11-7 model inventory and validation requirements?
AutoPIL's agent registry functions as the model inventory SR 11-7 requires. Each AI agent is registered with a unique ID, assigned role, governing policy, and owner team — creating a discoverable record of every agent operating in production. The policy engine enforces access controls before data enters the agent's context window, and every decision is written to a cryptographic audit chain that cannot be retroactively altered. Policy YAML versioning provides the change-control record SR 11-7 expects when model assumptions or access rules change. Examiners and internal validators can query the audit log by agent, data source, sensitivity level, or time window without relying on application-layer logs.
What are the enforcement risks for banks that fail SR 11-7 model risk requirements for AI?
SR 11-7 is supervisory guidance, not a formal regulation with statutory penalties — but violations carry real enforcement consequences. Examiners who find gaps in model inventory, validation documentation, or governance controls issue Matters Requiring Attention (MRAs), which require a documented remediation plan with deadlines. Repeat or unresolved MRAs can escalate to Matters Requiring Immediate Attention (MRIAs) and formal enforcement actions, including consent orders. For banks expanding AI agent programs, an inadequate model risk management framework also creates CCAR and stress testing exposure, since models used in capital planning must meet SR 11-7 standards. Regulators have made clear that AI and ML models are in scope — not a future consideration.
Covered Industries

SR 11-7 applies to Federal Reserve member banks, bank holding companies, and OCC-supervised national banks — any institution using quantitative models, including AI agents, to inform business decisions. As AI agents are deployed across lending, fraud detection, trading, and customer operations, the guidance's model inventory, validation, and audit trail requirements become active compliance obligations, not aspirational controls.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries