Model Risk Management After SR 26-2: A Practical Review for 2027 Planning
Model risk management has long been a core part of sound governance for financial institutions, but the expectations around it are changing. In April 2026, the Federal Reserve, OCC, and FDIC issued revised model risk management guidance through SR 26-2 and related agency releases. The guidance replaces SR 11-7 and SR 21-8 and places greater emphasis on a risk-based approach tailored to an institution’s size, complexity, model use, and model risk profile.
For banks preparing 2027 plans, this is a timely opportunity to step back and assess whether model governance still reflects how models are actually being used across the organization. The goal is not simply to maintain a list of models. It is to understand which tools influence key business, accounting, compliance, and risk decisions, and whether oversight is aligned with the level of risk those tools create.
Start With a Clear Inventory
A practical review begins with the model inventory. Under the revised guidance, an effective inventory should include enough information to support model risk management at both the individual model level and across the organization.
For many institutions, this may include models used for CECL, asset liability management, loan pricing, fraud monitoring, liquidity management, stress analysis, customer analytics, and vendor-supported platforms. It may also include tools that have grown more important over time but were not originally viewed as high-risk.
The review should help management distinguish between models that support routine analysis and models that influence financial reporting, regulatory compliance, capital planning, risk exposure, or customer outcomes.
Align Oversight With Risk
SR 26-2 recognizes that not every model carries the same level of risk. The guidance points to factors such as inherent risk, exposure, purpose, use, and materiality. Models tied to larger portfolios, regulatory needs, or key financial decisions generally warrant more rigorous review than tools with limited impact.
This risk-based approach can be especially helpful for community and regional institutions. Rather than applying the same review cycle to every model, management can focus attention where the business impact is greatest. The OCC has also noted that the guidance does not require community banks to perform annual model validation in every case.
Do Not Overlook Vendor-Supported Models
Vendor tools remain an important part of model risk management. The revised guidance notes that third-party products can create validation challenges, particularly when code, data, or methodology is proprietary. Still, institutions remain responsible for oversight of how those tools are used.
For 2027 planning, banks may benefit from reviewing documentation, assumptions, user controls, management reports, and any manual adjustments applied to vendor outputs. This can help leadership better understand where reliance exists and whether current governance remains appropriate.
SR 26-2 does not call for a one-size review process. It calls for thoughtful governance that fits the institution. As banks plan for 2027, a clear inventory, risk-based review process, and stronger visibility into vendor-supported tools can help make model risk management more practical, focused, and useful for decision-making.
