What the Revised Model Risk Guidance Means for Fintechs Using AI
On April 17, 2026, the Federal Reserve, OCC, and FDIC issued revised interagency model risk management guidance, published as Supervisory Letter SR 26-2, OCC Bulletin 2026-13, and FDIC FIL-15-2026. It supersedes SR 11-7, which had governed model risk management in banking since 2011, along with the 2021 interagency statement on model risk management for systems supporting Bank Secrecy Act and anti-money laundering compliance.
The part that matters most to anyone building with AI is what the guidance leaves out. Generative and agentic AI are described as novel and rapidly evolving, and are placed outside the formal scope of the guidance. The agencies also noted that existing risk management principles continue to apply to tools that fall outside that scope, and signaled plans to issue a request for information on how banks are using AI.
Two points about scope before going further. The guidance is explicitly non-binding, and the agencies indicated that deviating from it will not by itself trigger supervisory criticism. It is also aimed most directly at banking organizations above roughly thirty billion dollars in total assets. If you are running a fintech, SR 26-2 does not govern you directly.
Why It Still Matters If You Are Not a Large Bank
Two reasons. Sponsor banks and enterprise partners that are in scope will push their own expectations down through diligence questions and contract terms, so the standard tends to reach you through the relationship rather than through an examiner. And many non-bank fintechs adopt frameworks like this voluntarily, because it is a recognized benchmark of sound practice when an investor, an acquirer, or a bank partner asks how you govern models.
The part that has been most widely misread is the AI carve-out, and a number of teams have taken it as a green light. It is closer to the opposite. Being outside the scope of one supervisory document does not create a regulatory exemption. It means no agency has published a specific framework telling you how to govern these systems, while every general obligation you already had remains in force.
In practice, that removes the checklist and leaves the accountability. If your AI system contributes to a credit decision, fair lending law still applies. If it touches customer information, the GLBA Safeguards Rule still applies. If you are a covered entity in New York, Part 500 obligations around access control, third parties, and governance still apply. If your model produces a consumer-facing outcome, unfair or deceptive practices exposure has not moved.
The absence of an AI-specific rulebook is not the absence of AI-specific risk. It shifts the burden of defining reasonable practice onto you, and it means examiners and sponsor banks will evaluate your judgment rather than your conformance to a published standard.
Why This Is Harder Than Following a Rule
When a supervisory framework exists, the compliance question is whether you met it. When one does not, the question becomes whether your approach was reasonable given what was known at the time. That is a defensibility standard, and defensibility rests almost entirely on documentation.
Firms that can show a deliberate, documented process typically fare better in examination than firms with more sophisticated technology and no record of how decisions were made. The record is the control.
What to Document Now
A Model and Agent Inventory
Every AI system in use, what it does, who owns it, what data it consumes, what decisions or actions it influences, and whether it was built internally or supplied by a third party. Most organizations discover during this exercise that they have more AI in production than leadership believed, often introduced through vendor product updates rather than deliberate procurement.
Purpose and Scope Boundaries
What the system is authorized to do, and equally important, what it is not. A system introduced for internal summarization that quietly begins informing customer-facing decisions has changed its risk profile without anyone recording that it did.
Validation and Testing Evidence
How the system was evaluated before deployment, what testing was performed for accuracy and for disparate outcomes across protected classes, and how often that testing is repeated. For credit and lending applications in particular, evidence of fair lending testing is likely to be among the first things a regulator or sponsor bank requests.
Human Oversight Checkpoints
Which decisions require human approval before execution, and how that approval is recorded. This becomes materially more important with agentic systems, where the model does not simply recommend but acts.
Monitoring and Drift
How performance is tracked over time, what thresholds trigger review, and who is responsible for acting on them. A model that performed acceptably at deployment and has not been evaluated since is a documented risk rather than a managed one.
The Sponsor Bank Dimension
If your fintech works with a sponsor bank, the practical effect of SR 26-2 may reach you through that relationship before it reaches you through any examiner. Sponsor banks are generally held accountable for the risk their fintech partners introduce, and many are increasingly asking partners to evidence AI governance as part of ongoing oversight and periodic due diligence.
A fintech that can produce a model inventory, validation records, and a monitoring process is answering a question its sponsor bank has to answer to its own regulator. A fintech that cannot is creating work for the bank, which tends to slow relationships down.
Where to Start
Begin with the inventory. It is unglamorous and it is the prerequisite for everything else, because you cannot govern systems you have not enumerated. From there, classify by consequence: which systems influence decisions that affect customers, money movement, or access to sensitive data. Governance effort should concentrate there rather than being spread evenly across every tool that happens to use a model.
The organizations that will handle the eventual arrival of AI-specific rules most easily are the ones building the documentation habit now, while there is time to do it deliberately.
Sources: Federal Reserve Supervisory Letter SR 26-2, Revised Guidance on Model Risk Management, April 17, 2026, with companion OCC Bulletin 2026-13 and FDIC FIL-15-2026. Scope and applicability discussion, including the non-binding nature of the guidance and its orientation toward larger banking organizations, reflects the agencies' issuance and contemporaneous legal analysis of it. Verify current text at federalreserve.gov.
This article is provided for general information and does not constitute legal advice. Regulatory requirements, compliance dates, examiner priorities, and enforcement posture change frequently. Verify current requirements against primary agency sources and your legal counsel before acting on anything described here.

