OCC Model Risk Management Guidance: Updated Framework & Best Practices Model risk management just got a major overhaul, and most compliance teams are still catching up.

On April 17, 2026, the OCC, Federal Reserve, and FDIC jointly issued Revised Guidance on Model Risk Management (OCC Bulletin 2026-13), replacing the framework that has governed bank models since 2011.

For compliance and risk leaders at banks, fintechs, and payments companies, the questions are piling up fast:

  • Which systems still count as "models" under the narrower definition?
  • Does the new $30 billion threshold actually change our applicability?
  • What happens to existing MRM policies and BSA/AML model programs built around the old rules?

This article breaks down what changed, who the guidance applies to, and the concrete steps your institution should take to align with the new principles-based approach.

Key Takeaways

  • 2011 MRM guidance and the 2021 BSA/AML Model Risk Statement are fully rescinded and replaced by a shorter, principles-based framework.
  • "Model" now has a narrower definition, explicitly excluding spreadsheets, deterministic rule-based tools, and generative/agentic AI.
  • Scope centers on institutions with over $30 billion in assets; complex smaller banks may still need to comply.
  • Non-compliance alone won’t draw supervisory criticism—unsafe practices from weak model risk management still can.
  • Banks should revisit model inventories, apply the new materiality framework, and rewrite policies built around old prescriptive requirements.

Understanding OCC Model Risk Management Guidance

Model risk management is the discipline of identifying, measuring, and controlling risks from quantitative models. Banks rely on these models for credit decisions, capital planning, BSA/AML monitoring, and other business-critical functions. Get it wrong, and you're making decisions on flawed math without realizing it.

The OCC and Federal Reserve jointly issued SR 11-7/OCC Bulletin 2011-12 in 2011, largely in response to the surge in model use tied to post-financial-crisis capital rules. The FDIC didn't adopt it until 2017, applying it to institutions with $1 billion or more in total assets.

In 2021, the agencies added the Interagency Statement on BSA/AML Model Risk Management, extending MRM principles to transaction monitoring and sanctions screening systems.

Why the Framework Got Overhauled

Industry feedback, including the OCC's own Bulletin 2025-26, revealed a problem: the original 2011 guidance was being applied far too prescriptively, especially at community banks. Institutions read "annual validation" as a hard requirement rather than a suggestion, and many built out-of-scale validation teams they didn't need.

That feedback prompted a recalibration toward materiality-based, principles-driven oversight. The 2026 guidance formally rescinds:

  • OCC Bulletin 2011-12
  • The 2021 BSA/AML Interagency Statement
  • OCC Bulletin 1997-24 (Credit Scoring Models)
  • The "Model Risk Management" booklet of the Comptroller's Handbook

Those rescissions clear the way for a single, risk-based framework that scales with model materiality rather than one-size-fits-all process.

Key Changes in the 2026 Revised Guidance

The 2026 update isn't a minor edit. It rewrites the definition of what a model even is, shifts the applicability threshold dramatically, and softens several requirements that banks treated as mandatory for over a decade.

Narrower Definition of "Model"

Under the new guidance, a model is a "complex quantitative method" applying statistical, economic, or financial theories to process data into estimates. Notice what's missing: the prior reference to "mathematical" theories is gone.

The guidance also adds explicit carve-outs. These are not considered models anymore:

  • Simple spreadsheets performing basic arithmetic
  • Deterministic rule-based processes and software
  • Simple arithmetic tools with no underlying statistical or economic theory

That's a meaningful narrowing. Plenty of tools that previously sat in bank model inventories out of caution no longer need to be there.

Generative and Agentic AI Carve-Out

Here's one that will surprise a lot of risk teams: generative and agentic AI models are explicitly excluded from scope. The agencies call them "novel and rapidly evolving" and decline to regulate them under this framework.

That doesn't mean AI gets a free pass. Banks still have to govern these tools under broader enterprise risk management practices. The agencies have also announced plans to issue a Request for Information focused on AI-based models, so this carve-out likely won't last forever.

New $30 Billion Applicability Threshold

This is the headline change for a lot of institutions. The FDIC's prior threshold sat at $1 billion. The new uniform threshold across all three agencies jumps to $30 billion in total assets.

That's a 30x increase. Smaller institutions with complex or extensive model use, however, may still find the guidance relevant, so institutions under the line should not assume they are automatically off the hook.

Materiality-Based Risk Assessment Framework

The new approach measures overall model risk as inherent risk weighed against materiality:

  • Inherent risk — driven by complexity, assumptions, and data quality
  • Materiality — driven by exposure (how much output matters to decisions) and purpose (why the model is used)

Low-risk, low-materiality models can get lighter-touch oversight under this structure, according to the full interagency guidance. That's a real shift away from blanket, one-size-fits-all validation cycles.

Explicit Non-Enforcement Disclaimer

The guidance states plainly that non-compliance will not, by itself, result in supervisory criticism. Read the footnote carefully, though: agencies preserve full authority to act on unsafe or unsound practices tied to inadequate model risk management. The disclaimer is not a safe harbor from supervisory action on weak model risk management.

2011 versus 2026 OCC model risk management guidance key changes comparison

Validation, Governance & Vendor Risk Management Under the New Framework

The three core validation pillars survive: conceptual soundness, outcomes analysis, and ongoing monitoring. But they're treated far more concisely now. The old requirement for annual validation cycles and detailed backtesting procedures is gone.

Independence Is De-Emphasized

Validation independence used to hinge on reporting-line separation and compensation structures. Now, the guidance simply states validation quality "depends on rigor and effectiveness." That's a philosophical shift from structural mandates to outcome-based standards.

Governance gets the same treatment. Detailed board and senior-management duties, along with enumerated internal audit tasks, are replaced with higher-level principles:

  • Clear roles and responsibilities
  • Defined accountability
  • Effective, risk-scaled policies

The New Vendor Risk Section

For the first time, there's a stand-alone section addressing third-party and vendor models. It acknowledges something banks have known for years: you often can't fully validate a proprietary vendor model. Instead, the focus shifts to developing model understanding and monitoring outcomes on an ongoing basis.

What This Means for BSA/AML Programs

This is the part fincrime compliance teams need to sit with. The 2021 BSA/AML Statement is rescinded without replacement. Transaction monitoring and sanctions screening models are now folded back into the general MRM framework, with no BSA/AML-specific carve-out language to lean on.

Programs built around the 2021 statement's specific clarifications now need to be reassessed against the broader, more general 2026 principles.

That reassessment is a practical place for specialized support. Pillars FinCrime Advisory works with institutions on transaction monitoring optimization and exam readiness, turning shifts like this into concrete program updates rather than leaving teams to reverse-engineer a rescinded bulletin.

Who Must Comply: Applicability & Scope

The guidance is expected to be "most relevant" to banking organizations with over $30 billion in total assets—a major jump from the prior $1 billion FDIC threshold.

Community banks and smaller institutions aren't automatically exempt. If your institution has significant model risk exposure, whether from complexity or from activities outside traditional community banking, the framework can still apply to you.

Fintechs and payments companies should pay attention too, regardless of asset size. Here's why:

  • Bank partners often pass down model risk expectations through vendor and third-party oversight requirements.
  • Sponsor banks remain responsible for third-party risk under separate interagency guidance, meaning your compliance posture directly affects their exam outcomes.
  • Weak model governance at a fintech can become a liability in its bank partner's next examination.

If you're a fintech relying on a sponsor bank relationship, expect that bank to ask sharper questions about your model governance—even if your balance sheet is nowhere near $30 billion.

Best Practices to Prepare Your Institution

Waiting for an exam to force the issue is the wrong strategy. Here's what to do now:

  1. Reassess your model inventory. Identify which tools no longer qualify as "models" under the narrower definition, and separately determine governance for out-of-scope generative and agentic AI tools.
  2. Apply the materiality framework. Right-size validation frequency and oversight intensity instead of defaulting to blanket annual cycles across every model regardless of risk.
  3. Rewrite outdated policy language. Strip out fixed validation cycles and structural independence mandates; replace them with principles-based, risk-tiered language that matches the new guidance.
  4. Watch for the AI-focused RFI. The agencies have signaled a forthcoming Request for Information on AI-based models. Staying ahead of it beats scrambling once it drops.
  5. Bring in outside expertise where it counts. Turning a principles-based guidance document into an audit-ready policy update is hard—especially after BSA/AML programs lost a dedicated framework overnight.

5-step action plan for OCC model risk guidance compliance readiness

An experienced financial crime advisory partner can help you convert the guidance into practical policy without overbuilding the program or leaving gaps examiners will flag. Pillars FinCrime Advisory, led by CAMS-certified founder Joshua Douglas, matches compliance infrastructure to your risk profile and transaction volume rather than a generic template. That approach matters more now that BSA/AML models sit inside a broader, less prescriptive framework than before.

Frequently Asked Questions

What is an OCC audit?

An OCC audit, more accurately called an examination, is a supervisory review where OCC examiners assess a national bank's safety, soundness, and compliance with laws and guidance. Model risk management practices are typically part of that review.

What are the three types of model risk?

Model risk generally falls into three categories: errors from flawed methodology, risk from incorrect or inappropriate model use, and risk from poor data quality or faulty assumptions feeding the model.

What are the OCC risk categories?

The OCC's core supervisory risk categories include credit, interest rate, liquidity, price, operational, compliance, and strategic risk. Model risk doesn't stand alone; it cuts across several of these categories at once.

Does the new OCC model risk guidance apply to community banks?

The guidance is framed as most relevant to institutions over $30 billion in assets, but community banks with complex or extensive model use may still find it applicable. Asset size alone doesn't guarantee exemption.

Are AI models covered under the OCC's model risk management guidance?

No. Generative and agentic AI are explicitly excluded from the guidance's scope for now. Banks still need to govern these tools through broader enterprise risk management practices.

What happens if a bank doesn't comply with the OCC's model risk guidance?

The guidance states that non-compliance alone won't trigger supervisory criticism. That said, unsafe or unsound practices stemming from poor model risk management can still prompt regulatory action.