SR 26-2 (with OCC 2026-13 and FDIC FIL-15-2026) replaced fifteen-year-old model risk guidance with a materiality-based framework that explicitly reaches AI systems and agents. This guide maps its expectations to concrete controls.
1. Inventory: from models to systems
The guidance expects a defensible inventory that covers AI beyond the classical model validation perimeter — vendor agents, copilots, embedded AI. Control: discovery from real traffic, not periodic surveys; every system carries an owner, a tier, and a lifecycle state. Evidence to retain: the inventory itself, discovery method, and change history.
2. Tiering: materiality you can defend
Risk-tier each system by what it can actually do: data sensitivity, autonomy level, customer impact, dollar exposure. Control: autonomy tiers (Observe → Advise → Act-with-Approval → Act-Autonomously) with promotion criteria and named approvers. Evidence: tiering rationale per system; promotion and demotion records.
3. Ongoing monitoring: beyond annual validation
Annual review cycles don’t fit systems that change weekly. Control: continuous behavioral monitoring against baselines — grounding accuracy, escalation rates, drift — with alerting tied to tier. Evidence: monitoring coverage, thresholds, and alert dispositions.
4. Vendor oversight: their agent, your exam
Third-party AI is inside the perimeter now. Control: vendor systems governed at the same gateway, under the same policies, with the same evidence stream as internal builds. Evidence: per-vendor traffic, controls applied, incidents.
5. The reconstruction standard
The single highest-leverage capability for the new exam era: reconstruct any material AI-assisted decision — governing policy and version, grounding, model version, evaluations, human sign-off — in minutes. If your program can do this, every other conversation gets easier.
This guide is informational and is not legal or regulatory advice. Map it to your institution’s obligations with counsel and your examiners.