Advisory Service

SR 26-2 Model Risk Management for Fintechs

In April 2026 the Federal Reserve, OCC, and FDIC replaced SR 11-7, the model risk management guidance that had governed the industry for fifteen years. If your company uses scoring models, underwriting algorithms, or fraud detection systems in consumer financial decisions, your sponsor bank's model risk team is now applying a revised standard to them. This engagement builds the framework that satisfies it.

Book a Discovery Call

What SR 26-2 Actually Requires

SR 26-2, issued April 17, 2026, is interagency guidance from the Federal Reserve Board, the OCC, and the FDIC. It supersedes and replaces SR 11-7, Guidance on Model Risk Management (2011), and SR 21-8, the Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance (2021).

The Fed states the letter is most relevant to banking organizations with over $30 billion in total assets. That threshold describes the bank, not the standard your sponsor bank will apply to you. A bank of any size is expected to govern the model risk it takes on, and the revised guidance is now the reference point its model risk team will work from when it reviews a fintech partner's decisioning.

A point most advisors get wrong. Footnote 3 of the guidance places generative AI and agentic AI expressly outside its scope. The guidance applies to traditional statistical and quantitative models and to non-generative, non-agentic AI models. Most fintech credit scoring, underwriting, and fraud models fall squarely inside that boundary. If you are using an LLM in a consumer-facing decision, SR 26-2 does not govern it, but your bank's general risk management and governance expectations still do, and the guidance says so directly.

Knowing which of your models the guidance reaches, and which it does not, is the first deliverable of this engagement.

Framework Components

Model Inventory and Classification

Complete inventory of all models and algorithms affecting consumer decisions: scoring models, underwriting algorithms, fraud detection systems, and AI-assisted decisioning. Classification by inherent risk, exposure, purpose, and use, the four factors the guidance itself identifies as driving model risk. First step: a scope determination separating models the guidance reaches from generative and agentic systems governed under your bank's general risk management expectations instead.

Model Validation Framework

Pre-deployment validation protocol, ongoing performance monitoring cadence, back-testing methodology, and documentation standards. Structured to produce the evidence a bank examiner would require for each model in production.

Human-in-the-Loop Governance

HITL decision matrix identifying which model outputs require human review before consumer action. Escalation procedures, override documentation, and exception logging: the standard a bank's model risk team will expect to see regardless of which specific guidance is cited.

Fair Lending and Disparate Impact Testing

Disparate impact analysis for models affecting credit decisions. ECOA and Fair Housing Act protected class testing. Adverse action reason code defensibility review under CFPB Circular 2022-03 on explainability.

Model Performance Monitoring

Ongoing monitoring protocol: performance metrics, drift detection thresholds, revalidation triggers, and escalation procedures when model performance degrades below established benchmarks.

Bank Partner Documentation Package

Complete MRM documentation package formatted for bank sponsor review. Model cards, validation summaries, HITL attestations, and board-level governance summary for each material model.

Who Needs This Engagement

  • BaaS fintechs using scoring, underwriting, or fraud models whose sponsor banks are updating model risk programs to the revised interagency guidance
  • Fintechs approaching bank partner conversations where the compliance due diligence will include model governance questions
  • Companies using third-party scoring APIs or alternative data models in consumer-facing financial decisions who have not yet established model validation documentation for those vendor models. (If your stack also includes an LLM, that piece sits outside SR 26-2's scope under Footnote 3; ask about the separate governance approach it needs.)
  • Fintechs that received CFPB Circular 2022-03 questions from bank partners about explainability of AI-driven adverse action decisions

The Examiner Perspective on Model Governance

Bank examiners reviewing SR 26-2 compliance are not primarily evaluating the technical performance of your models. They are evaluating whether the governance framework demonstrates that the bank's board understands the model risk it is accepting, has established appropriate controls, and can demonstrate ongoing oversight.

A fintech that can produce a model inventory with risk tiering, validation evidence, performance monitoring records, and HITL documentation is demonstrating that its bank partner relationship is being managed to examination standard. That documentation is what this engagement produces.

Build Your SR 26-2 Model Risk Management Framework

Discovery call to understand your model landscape and scope the engagement to your specific bank partner requirements.

Book a Discovery Call

// Scoped and priced per engagement complexity · Fixed fee · Written deliverables