SR 11-7 Is Gone: What the 2026 Model-Risk Framework Means for AI in Finance
SR 26-2 replaces a 2011 checklist with risk-based judgment. Here is what the new model-risk rules actually require from teams running AI over financial figures.
By The Rexfin team
On April 17, 2026, the Federal Reserve, the OCC, and the FDIC jointly retired the guidance that governed model risk in U.S. banking for fifteen years. SR 11-7, issued in 2011, is replaced by SR 26-2. If you run any kind of AI over financial figures, this is the document that now sets the tone for what your supervisors expect.
The headline change is not a longer list of controls. It is the opposite. SR 26-2 is deliberately principles-based. The agencies went out of their way to say it does not establish enforceable standards, and that non-compliance will not, on its own, trigger supervisory criticism. After a decade of teams treating SR 11-7 as a compliance checklist to be ticked off once a year, the regulators are asking for something harder: judgment, applied continuously, proportional to how much damage a model can do.
That sounds softer. It isn’t.
From checklist to judgment
The old framework rewarded paperwork. You inventoried your models, you wrote validation reports, you had a board policy, and you could point to all of it during an exam. The artifacts existed whether or not the model was actually under control day to day.
SR 26-2 anchors on materiality instead. The expected intensity of oversight scales with a model’s financial exposure and the weight of the decisions it drives. A simple spreadsheet calculation and a CECL allowance model are no longer treated as the same category of thing with the same documentation burden. You are expected to spend your governance budget where the consequences live.
This is where the phrase “shift-left” earns its place. In software, shifting left means catching defects early, at the point where data and logic are created, rather than at the end in a final review. The 2026 rewrite pushes model risk in the same direction. Controls embedded in the data flow beat a validation report written months after the model went live. If the inputs are wrong, the validation was theater.
For anyone wiring an LLM into financial reporting, that reframing is the whole game.
Why this lands hard on AI
There is a carve-out worth reading carefully. Generative and agentic AI are placed outside the direct scope of SR 26-2. The agencies say institutions should govern those systems with their existing risk-management practices for now, and they have signaled a forthcoming request for information specifically on AI, including generative and agentic AI.
Do not read that carve-out as a holiday. Read it as a warning that the rules are coming, and that the principles already in SR 26-2 are the template. Two of them apply directly to AI over financial data.
First, you own the risk even when the model is someone else’s. SR 26-2 reaffirms that reliance on a vendor does not transfer responsibility. You cannot point at OpenAI or Anthropic and call your model risk managed. The model is theirs; the risk is yours.
Second, oversight has to be proportional to consequence. An AI that drafts a meeting summary is low-stakes. An AI that tells your CFO the company’s gross margin moved 180 basis points, and that figure ends up in a board deck or a covenant calculation, is a high-materiality model whether or not anyone called it one. The number carries weight. The weight is what the framework now measures.
The uncomfortable part: the thing most teams are deploying, a chatbot that “answers questions about the financials,” is precisely the high-materiality, low-control quadrant the new guidance is built to expose.
What the new principles actually require
Strip SR 26-2 down to what it asks of an AI-over-finance stack, and three demands stand out.
The figures have to tie out. Principles-based governance still assumes the model’s inputs are sound. If your AI reads from a pile of unreconciled exports, a spreadsheet here and a CSV there, there is no “single model” to govern. There are dozens of conflicting answers, and validation has nothing stable to validate against. The first control is a reconciled financial model that ties to the ledger.
The math cannot be a guess. LLMs are probabilistic. They are good at language and bad at arithmetic, and they fail silently, which is the worst combination for finance. The 2026 emphasis on materiality means the calculation behind a high-stakes figure must be reliable and reproducible. That argues for keeping the LLM out of the math entirely and running the numbers through a deterministic engine, so the same question returns the same answer every time and the answer can be checked.
Every output has to trace to source. Shift-left controls only work if you can see where a number came from. An AI that produces a figure with no path back to the underlying transactions is, in materiality terms, an unvalidated model producing material output. Traceability is not a nice-to-have feature. Under the new framing it is the audit trail your supervisor will ask for.
Where Rexfin fits
This is the architecture we built Rexfin around, and the 2026 rewrite makes the case better than we could.
Rexfin connects your accounting and financial-data platforms, QuickBooks, Xero, NetSuite, Sage, SAP, Oracle, or a warehouse, or works from uploaded statements, and builds one reconciled financial model that ties out to the ledger. That is the single source of truth a governance framework can actually point at. When AI retrieves a figure, it retrieves it from that model, not from a stale export.
Calculations run through a deterministic engine, not the language model. The LLM handles the question and the explanation; the math is computed and reproducible. What-if scenarios run against the same reconciled base. And every insight traces back to the source transactions, so the answer to “where did this number come from” is a click, not an investigation.
None of that makes SR 26-2 a solved problem. Governance is a program, not a product, and you still own the policies, the inventory decisions, and the judgment calls about materiality. What the architecture does is make those calls defensible. You cannot govern figures that don’t reconcile or math you cannot reproduce. Fix the substrate first, and the principles-based regime becomes something you can actually satisfy.
For the deeper mechanics, see how we handle output-based validation for vendor LLMs, since you can’t validate the weights, and the reference architecture for an AI control stack that ties these controls together. The full governance pillar covers the risks SR 11-7 never anticipated.
The 2026 framework asks one question of every AI you point at your financials: can you prove the number? If the honest answer is no, that is the gap to close before the RFI turns into a rule. Book a demo and we’ll show you what it looks like when the answer is yes.
Part of Governing AI in Finance: Model Risk, Controls, and Validation for the LLM Era