Back to Articles

Tier 1 First: SR 11-7 Compliance for U.S. Banks in 30–180 days

9/16/2026
11 min read
Tier 1 First: SR 11-7 Compliance for U.S. Banks in 30–180 days

SR 11-7 has been superseded by SR 26-2, effective April 17, 2026. Banks and credit unions now operate under a risk-based, proportionate model risk framework rather than the older prescriptive checklist. The immediate task is straightforward: audit your model inventory, flag every Tier-1 model, and prioritize validation resources there first, while keeping the core disciplines of governance, documentation, and monitoring fully intact.


TL;DR:

  • Institutions must focus validation efforts on Tier-1 models with the highest potential financial impact, relying on risk-based tiering and focused validation.
  • Maintaining a complete, detailed model inventory with clear purpose, owner, inputs, validation status, and risk tier is essential for compliance and exam readiness.
  • Effective challenge requires validators to be organizationally independent, credible, and to document assumptions, responses, and remediations thoroughly, especially for Tier-1 models.
  • Boards should review concise dashboards showing the status of top-tier models, validation dates, open findings, and performance trends, rather than detailed model-by-model reports.
  • Vendor models are held to the same validation standards, requiring independent testing, methodology documentation, and ongoing re-validation using institution-specific data.
Model Governance

Automate Regulatory Model Risk Governance

Examine models against 32 qualitative criteria and resolve risk Tiers with pre-deployment checklists per OCC 2011-12 guidelines.


Table of Contents

Understanding SR 11-7 Compliance in the SR 26-2 Era

Compliance officers who built their programs around SR 11-7 compliance requirements now have a new reference point. SR 26-2 does not throw out the old model risk management guidance; it recalibrates how aggressively you apply it. The Federal Reserve's SR 26-2 letter explicitly supersedes SR 11-7, and the accompanying PDF attachment confirms it also replaces SR 21-8. The shift is best described as precision over volume: rather than treating every model with roughly the same validation intensity, institutions are now expected to concentrate rigor where the potential for financial harm is greatest.

What survives the transition matters as much as what changes. The original SR 11-7 guidance from 2011 established pillars that examiners still expect to see functioning:

  • A complete, current model inventory
  • Independent validation with genuine effective challenge
  • Documentation sufficient to reconstruct a model's logic and testing history
  • Ongoing monitoring and outcomes analysis
  • Board and senior management oversight of model risk

SR 26-2 changes the intensity dial on these pillars. It does not remove any of them.

How Do You Build a Risk-Tiered Model Inventory?

An inventory that lists every model with the same level of detail is not a modern SR 26-2 compliance checklist item, it is a liability. Examiners increasingly treat incomplete or flat inventories as a significant deficiency, and the guidance is specific about minimum content: purpose, owner, users, inputs and outputs, current validation status, and an assigned risk tier.

Tiering should reflect four factors: potential financial impact if the model fails, how heavily the business relies on its output, whether it feeds regulatory reporting, and its structural complexity. A CECL reserve model driving quarterly provisions belongs in a different tier than an internal scheduling tool, even if both technically qualify as models.

To rationalize an inventory that has grown unwieldy:

  1. Pull every model touching credit decisions, capital, or regulatory filings first and confirm Tier-1 status
  2. Reassign lower-impact models to lighter validation cycles rather than annual full-scope reviews
  3. Retire or consolidate duplicate or unused models still sitting in the inventory
  4. Document the tiering rationale itself, since examiners will ask why a model landed where it did

Pro Tip: Don't tier by model type alone. Two credit scoring models can sit in different tiers if one drives $2 million in monthly originations and the other supports a discontinued pilot program.

What Does Effective Challenge Look Like Now?

Independent validation under SR 26-2 still rests on three legs: conceptual soundness review, ongoing monitoring, and outcomes analysis or back-testing. None of those three disappeared in the transition, and examiners will ask about all three regardless of a model's tier.

Three-part model validation framework

Effective challenge means the validator has both organizational independence from the model's developers and enough technical authority to question their assumptions credibly. A validator who can't explain why a logistic regression's variable selection is defensible isn't providing challenge, just paperwork. The OCC's companion bulletin reinforces that this expectation travels with the institution regardless of size.

What examiners want to see documented:

  • The specific assumptions a validator questioned, not just a pass/fail summary
  • The developer's response to each challenge
  • Remediation taken, or a documented rationale for why none was needed
  • A dated trail connecting challenge to resolution

One insight worth internalizing: SR 26-2's proportionality principle gives institutions formal cover to put the most rigorous validation and challenge on Tier-1 models, while applying lighter-touch review to models with limited financial consequence. That's a deliberate regulatory signal, not a loophole.

What Should the Board Actually See?

Board members don't need a model-by-model dossier. They need enough to exercise real oversight, which means a concise report covering the institution's top-tier models, any material changes to those models since the last report, and the status of open remediation items.

Policy clarity matters here more than volume of detail. Every model needs a named owner, and every escalation path needs to be unambiguous when a model fails a validation test or drifts outside tolerance.

Useful elements for a governance dashboard:

  • Count of Tier-1 models and their last validation date
  • Open findings by severity, with age since identification
  • Vendor models awaiting updated evidence
  • Trend lines on key model performance metrics, not just point-in-time snapshots

A board that sees this quarterly can ask sharper questions than one buried in a 40-page appendix.

Are Vendor Models Held to the Same Standard?

Yes. Regulators expect institutions to treat vendor and third-party models with the same accountability as anything built in-house. Outsourcing the model does not outsource the risk, and vendor documentation alone is often insufficient without institution-specific validation evidence, a point the OCC bulletin reiterates directly.

Before accepting a vendor's model, request its methodology documentation, independent testing reports, stated limitations, and its process for notifying clients of material changes. If the vendor doesn't produce any of that, the institution needs to validate the model's outputs itself using its own data.

  • Build change-notice requirements into vendor contracts, not just service level terms
  • Re-test vendor model outputs against your own portfolio periodically, not just at onboarding
  • Track vendor model risk in the same inventory as internal models, tiered the same way

Pro Tip: Ask vendors for their back-testing results on data resembling your portfolio, not just their original development sample. A model validated on national data can behave very differently against a regional loan book.

What Documentation Keeps You Exam-Ready?

Documentation is where good validation work either survives an examination or gets rediscovered from scratch under deadline pressure. At minimum, keep the conceptual framework explaining why the model works the way it does, data lineage showing where inputs originate, the assumptions baked into the model, and every validation finding tied to a date and an owner.

  1. Set monitoring thresholds tied to business impact, not arbitrary statistical defaults
  2. Automate alerts when a model's performance metrics cross those thresholds, rather than waiting for the next scheduled review
  3. Run outcomes analysis on a cadence matched to the model's tier: Tier-1 models warrant quarterly review, lower tiers can run annually
  4. Retain the challenge-response record between validators and developers, since examiners often weigh that trail as heavily as numeric test results

Skipping outcomes analysis until the annual review is one of the more common ways institutions get caught flat when a model has quietly degraded for months.

SR 26-2 Compliance Checklist: A Time-Boxed Roadmap

Turning SR 26-2 from a regulatory letter into a working program happens in three phases.

  1. Days 1 to 30: Audit the full model inventory for completeness, confirm every field regulators expect is populated, and identify which models qualify as Tier-1 under the new proportionality criteria
  2. Days 30 to 180: Re-tier the remaining inventory, clear the validation backlog on Tier-1 models first, and collect updated evidence packages from every vendor supplying a material model
  3. Months 6 to 12: Update governance policy language to reflect risk-based tiering, standardize documentation templates across business lines, and automate monitoring where manual spreadsheet tracking has been the norm

Industry practitioners increasingly recommend using this transition window to prune genuinely low-risk models from heavy annual review cycles, freeing validator time for AI-driven and other complex models where SR 26-2's proportionality language matters most.

TimeframePrimary focusKey deliverable
30 daysInventory auditConfirmed Tier-1 model list
180 daysRemediationCleared validation backlog, vendor evidence on file
12 monthsProgram maturityUpdated policy, templates, automated monitoring

Institutions that treat this as a documentation exercise instead of an operational one tend to resurface the same gaps at the next exam cycle.

Common Pitfalls in the SR 11-7 to SR 26-2 Transition

The single biggest mistake I see coming out of this transition is treating SR 26-2 as SR 11-7 with a new cover page, and simply re-running the old checklist against every model at the same intensity. That defeats the entire point of proportionality and burns validator hours on low-risk models while Tier-1 models wait in the backlog.

The second pitfall is understaffing effective challenge. If your validation team is thin, don't dilute challenge quality across every model, concentrate it on the ones that actually move earnings or capital. Brief the board on that trade-off directly: fewer models get deep review, but the ones that matter get more of it, not less.

— Raj

How Riskinmind Operationalizes SR 26-2 Compliance

A specialized platform can support this transition by providing a live model inventory tracking purpose, owner, validation status, and risk tier in one place instead of a spreadsheet updated quarterly. That's a meaningfully faster starting point than rebuilding a proportional inventory system by hand while examiners are already asking about your SR 26-2 readiness.

Riskinmind

The platform's Regulatory Agent and CECL Modeling tools generate audit-ready documentation and monitoring alerts automatically, which maps directly onto the outcomes analysis and challenge-trail expectations examiners now emphasize. The platform operates on secure, compliant infrastructure with real-time processing, helping keep validation evidence and reporting current rather than reconstructed after the fact. If you're mapping your model inventory against Tier-1 criteria this quarter, check current plans on the pricing page or explore the Loan Application module to see how automated validation evidence works on a live credit model.

Sources

FAQ

What Is SR 11-7 Compliance?

SR 11-7 compliance referred to adherence to the Federal Reserve's 2011 model risk management guidance covering inventory, independent validation, documentation, and governance. As of April 17, 2026, that guidance has been superseded by SR 26-2, so compliance now means meeting the revised, risk-based version of those same expectations.

Does SR 26-2 Replace SR 11-7?

Yes. SR 26-2 explicitly supersedes SR 11-7, and the PDF attachment confirms it also replaces SR 21-8, the guidance that previously extended model risk expectations to community banks.

What Replaced SR 11-7?

SR 26-2, issued April 17, 2026, replaced SR 11-7. It keeps the same foundational pillars, inventory, validation, documentation, monitoring, and governance, but applies them proportionally based on a model's risk tier rather than uniformly.

What Is the $3,000 Rule for Banks?

The rule referenced is not in SR 11-7 or SR 26-2 and concerns Bank Secrecy Act thresholds unrelated to model risk management guidance.

Do Vendor Models Need Independent Validation Under SR 26-2?

Yes. Regulators expect institutions to hold vendor models to the same validation standard as internally built ones, and vendor documentation alone is often insufficient without institution-specific testing evidence, according to the OCC's companion bulletin.

Recommended

SR 11-7 compliance checklist
understanding SR 11-7
SR 11-7 regulations
compliance with SR 11-7
SR 11-7 guidelines
SR 11-7 best practices
SR 11-7 compliance requirements
model risk management guidance
how to achieve SR 11-7 compliance
sr 11-7 guidance
sr 11-7 compliance