Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsAI governance is the organization-wide system for directing, overseeing, and controlling AI use; model risk management (MRM) is the more focused discipline for managing risks from models and their outputs. In a financial institution, MRM belongs within the broader AI governance environment, but it does not cover every AI system or every risk. In particular, the revised U.S. interagency model-risk guidance issued in April 2026 excludes generative and agentic AI models.
How AI governance and model risk management differ
The practical distinction is scope. AI governance sets direction and accountability for an institution’s AI use across the organization and over the AI lifecycle. MRM concentrates on risks associated with models: how they are developed, tested, validated, used, monitored, and governed. The disciplines overlap, but neither is a substitute for the other.
| Dimension | AI governance | Model risk management |
|---|---|---|
| Primary scope | Organization-wide oversight of AI adoption and use, including uses that are not within a model-risk framework’s model definition. | Risks arising from models and their outputs, considered in the context of how they are used and the institution’s exposure. |
| Main focus | Strategy, accountability, responsible adoption, lifecycle safeguards, and AI-specific risks. | Model assumptions, complexity, input quality, materiality, development, use, validation, and monitoring. |
| Typical lifecycle concerns | Oversight of AI adoption and use across development and deployment, plus organization-wide risk controls. | Development and use; testing, validation, and monitoring; governance and controls; and third-party products. |
| Generative and agentic AI under revised U.S. guidance | May raise governance concerns and require appropriate controls even when outside the revised MRM guidance’s scope. | Generative and agentic AI models are expressly outside the scope of the 2026 interagency guidance. |
| Authority and geography | The Financial Stability Board’s June 2026 proposal is an international, non-prescriptive consultation, not a binding standard. | The April 2026 guidance is U.S. banking supervisory guidance. It does not set enforceable standards or prescriptive requirements. |
In short, MRM is a model-focused control discipline; AI governance provides the wider operating and oversight environment in which model controls sit. A model’s approval is not the end of oversight: the guidance emphasizes that risk also depends on materiality, exposure, purpose, and whether a model is applied or used improperly.
What changed in U.S. banking guidance in 2026
SR 26-2 replaced SR 11-7 and SR 21-8
On April 17, 2026, the Federal Reserve, Office of the Comptroller of the Currency, and Federal Deposit Insurance Corporation issued revised interagency model risk management guidance. The Federal Reserve’s SR 26-2 letter says the revision supersedes and replaces SR 11-7 and SR 21-8. Accordingly, SR 11-7 should not be described as the current guidance.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →It is principles-based, not a prescriptive rule
The agencies describe the revised approach as risk-based and tailored to an institution’s model-risk profile and the size and complexity of its operations. The guidance says it does not set enforceable standards or prescriptive requirements, and that non-compliance with the guidance by itself will not result in supervisory criticism. That does not remove separate legal or safety-and-soundness concerns: supervisory action may follow violations of law or unsafe or unsound practices arising from insufficient model-risk management.
Expected relevance depends on exposure, not only asset size
The guidance is expected to be most relevant to banking organizations with more than $30 billion in total assets. That figure is an applicability marker for expected relevance, not a universal bright-line exemption. The guidance may also matter to smaller organizations when the prevalence or complexity of their models, or activities outside traditional community banking, creates significant model-risk exposure.
Rank #2
Does SR 26-2 apply to generative AI?
No. The revised U.S. guidance covers traditional statistical and quantitative models and non-generative, non-agentic AI models; it excludes generative and agentic AI models. The boundary is about the scope of this particular guidance, not a conclusion that generative or agentic systems pose no risk or need no oversight. The agencies say broader risk-management and governance practices should guide appropriate controls for tools and systems the guidance does not cover.
How the guidance defines a model
For this guidance, a model is a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to input data to produce quantitative estimates. Simple arithmetic, deterministic rule-based processes, and software whose design or use is not underpinned by those theories are excluded. Institutions should therefore assess systems against the guidance’s definition rather than assume that any software or AI-enabled tool is a covered model.
Rank #3
What a financial institution’s MRM program should address
The revised guidance describes a risk-based program, with rigor reflecting model use, materiality, exposure, and the institution’s circumstances. It discusses the following connected areas:
- Development and use: maintain oversight of how models are built and how they are used in the institution’s activities.
- Testing, validation, and monitoring: assess model performance and fitness for purpose over time, not solely at initial approval.
- Governance and controls: assign clear roles and responsibilities across the model lifecycle and support them with effective policies and procedures.
- Inventory and documentation: keep a model inventory with enough information to understand model risks and maintain adequate documentation.
- Third-party products: for vendor models, understand conceptual soundness, design, development data, and performance, then monitor outcomes and continuing fitness for purpose.
Risk assessment also needs to account for the context of use. The guidance frames model risk in relation to inherent risk and materiality, including exposure and purpose. An otherwise sound model can still carry high risk if it is misapplied or misused, so intended use, decision impact, user controls, monitoring, and escalation belong in the institution’s oversight arrangements.
Rank #4
What broader AI governance adds
AI governance addresses institutional questions that model validation alone cannot settle: who is accountable for AI adoption, how the organization oversees AI use across its lifecycle, and how risks outside model-specific controls are managed. The Financial Stability Board’s June 2026 consultation proposes 12 sound practices for responsible AI adoption by financial institutions, grouped around organization-wide AI governance, risk management through development and deployment, and AI-related cyber, information and communication technology (ICT), and third-party risk.
The FSB presents these practices as a non-prescriptive toolkit, not an international standard. As of October 4, 2026, its final report was expected later in October; the consultation proposal should not be presented as the final report or as a settled binding requirement.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
How the disciplines fit together in practice
A useful operating model is to connect organization-wide AI oversight with model-specific controls, while keeping clear which systems fall within each framework. The following is a practical way to apply the distinction, not a separate regulatory requirement:
- Set organization-wide AI accountability. Establish who oversees AI adoption and use, and how decisions and lifecycle risks receive appropriate scrutiny.
- Classify the system and its use. Determine whether it meets the revised U.S. guidance’s model definition, whether it is generative or agentic, and what purpose, exposure, and decision impact are involved.
- Apply MRM where the model falls within scope. Use proportionate development, testing, validation, monitoring, documentation, inventory, governance, and third-party controls.
- Address risks beyond MRM. For AI uses outside the revised guidance’s scope, use the institution’s broader governance and risk-management practices to set appropriate controls, including attention to cyber, ICT, and third-party risks.
- Keep oversight active after deployment. Monitor performance and continuing fitness for purpose, manage use and user controls, and provide for escalation when risks or outcomes warrant attention.
This division prevents two opposite mistakes: treating every AI system as though the revised MRM guidance covers it, and treating an out-of-scope system as though it therefore needs no governance. Model-specific assurance remains important where applicable; institution-wide AI oversight fills the wider accountability and risk-management role.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

