SR 11-7 Model Risk Management and AI

Compliance — SR 11-7 Model Risk Management

Applying SR 11-7 Model Risk Management to AI in Financial Services

SR 11-7 (and OCC Bulletin 2011-12) established the supervisory expectations for model risk management at financial institutions. The guidance was written for the era of statistical and econometric models; AI models, particularly generative AI and large language models, sit awkwardly within the original SR 11-7 framework. Armorstack’s AI Adoption Security Framework, applied to the SR 11-7 question, gives mid-market financial institutions a practical path to bringing AI under their existing MRM framework.

How the Guidance Applies

How SR 11-7 Applies to AI Today

SR 11-7 defines a model as a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates. AI models, particularly those informing customer decisions — underwriting, fraud detection, AML, pricing — fall squarely within this definition. The supervisory expectation is that these models be validated, monitored, and governed under the institution’s MRM framework.

The challenge for mid-market banks, credit unions, broker-dealers, and insurance carriers: AI models are appearing in production workflows faster than the MRM function can identify them, classify them, and bring them under validation. AI features embedded in core banking systems by the vendor, AI in fraud detection vendors, AI in customer service, AI in compliance review — many are functioning as models under SR 11-7 without explicit MRM coverage. Pillar 1 discovery surfaces them; Pillar 2 classifies them; Pillar 4 governance brings them into the MRM framework.

Common Questions

Frequently Asked Questions — SR 11-7 Model Risk Management and AI

Which AI use cases are “models” under SR 11-7?

SR 11-7 applies broadly to any quantitative method producing decisions or estimates used in business processes. AI-driven fraud detection, AML monitoring, underwriting, loss reserving, fair lending analysis, and pricing decisions almost certainly qualify. AI-driven customer service may not, depending on whether the AI is influencing material business decisions. Pillar 2 classification addresses the case-by-case determination.

How does the framework integrate with our existing MRM function?

The framework is designed to feed into your existing MRM framework rather than replace it. Pillar 1 discovery produces an updated model inventory that includes AI models. Pillar 2 classification identifies SR 11-7-relevant AI models for MRM intake. Pillar 4 governance produces AI-specific MRM policy elements.

How do we validate generative AI models under SR 11-7?

SR 11-7 validation requires evaluation of conceptual soundness, ongoing monitoring, and outcomes analysis. For generative AI models the conceptual soundness review evaluates the model architecture and training approach; ongoing monitoring includes prompt-injection and output-quality monitoring; outcomes analysis tracks model behavior over time. The framework’s Pillar 3 observability produces the monitoring data the validation function needs.

What about vendor-supplied AI models?

SR 11-7 applies to vendor-supplied models the institution uses. The framework’s Pillar 4 governance addresses vendor model documentation requirements, validation expectations, and ongoing monitoring obligations the vendor must provide.

How does this affect our model risk governance committee?

The framework’s deliverables — the updated model inventory, the AI model risk register, the validation evidence, the ongoing monitoring data — are sized to feed into your existing model risk governance committee. Most committees benefit from explicit AI model agenda items added to their standing reviews.

AI Under Your Existing MRM Framework

Apply for the free 30-day AI Risk Assessment and get a model inventory, risk classification, and governance elements sized to feed directly into your existing model risk management framework.

877-890-5508 · [email protected]