Getting a generative AI system from a successful pilot into production is where most bank AI programs stop. The usual explanations are data quality, legacy integration or a shortage of talent. More often the hold-up is an approval that nobody can defensibly sign, and the reason for that changed in April 2026. 

A model validator is an independent internal gatekeeper. They are responsible for mathematically auditing bank software and signing off to ensure it is accurate, safe, and compliant. 

When asked to approve a generative AI assistant, they will open the supervisory guidance. They look for the official standard to validate it against. This is what they find: 

“Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.” 

That sentence comes from the revised interagency guidance on model risk management, issued 17 April 2026 by the Federal Reserve, the OCC and the FDIC. It is probably the most consequential sentence in US banking AI right now, and almost nobody outside a model risk function has read it. 

It leaves your validator in an unusual position. The system on her desk isn’t prohibited, and it isn’t permitted either. It simply sits outside the document that would tell her which. 

 

What Actually Happened in April 2026 

Banking regulators use supervisory guidance to ensure financial institutions manage the risks posed by their quantitative models- from credit scoring and fraud detection to capital allocation and trading algorithms. For fifteen years, model risk management across US banking was defined by a single core standard: SR 11-7, which got replaced with SR 26-2 in the year 2026. 

Model risk in US banking ran on SR 11-7 for fifteen years. Issued 4 April 2011, adopted by the FDIC in 2017, it defined what counted as a model, what validation meant, and what an examiner expected to see. Every validation template in every large bank traces back to it. 

On 17 April 2026 the agencies rescinded it, replacing it with SR 26-2. The OCC issued Bulletin 2026-13 and went further, withdrawing the Model Risk Management booklet of the Comptroller’s Handbook, Bulletin 2011-12, the 1997 credit scoring guidance and the 2021 BSA/AML model risk statement. A decade and a half of accumulated expectation, retired in an afternoon. 

The replacement is shorter, more principles-based and deliberately proportionate. Models get tiered by materiality, controls scale with the tier, and it applies most directly to banking organizations above $30 billion in total assets. 

It also contains a second sentence that matters as much as the first: 

This guidance does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism against a banking organization.” 

Read the two together and the position is clear. Generative and agentic AI fall outside the scope of the guidance, and the guidance was never enforceable to begin with. 

Why the Agencies Did It 

The easy reading is that regulators ducked a hard problem. The record suggests otherwise, and the reasoning deserves a fair hearing. 

Shortly before the guidance landed, Ryan Billingsley, who leads the Division of Risk Management Supervision at the FDIC, testified before the House Financial Services Subcommittee on how bank regulators keep pace with technology. On model risk he was direct: 

The guidance has often been applied to models that pose no material financial risk to banks. In addition, it imposes significant burdens on small banks and has encouraged supervisory criticisms of policies, procedures, and documentation deficiencies.” 

Anyone who has sat in a validation meeting knows he is describing something real. A framework designed for capital and credit models drifted outward until it governed spreadsheet calculators. Validation queues filled with work that mattered to nobody, while the models that actually moved money waited behind it. Documentation findings became the currency of examination because documentation is easy to count. 

Narrowing the definition of a model, tiering by materiality and dropping enforceability are all reasonable answers to over-application. On its own terms the April revision is a good piece of work. 

The trouble starts at the edge of the new scope. 

Out of Scope Is Not Out of Risk 

An LLM that summarizes an applicant’s financials for an underwriter shapes a credit decision. Nobody inside the bank pretends otherwise, least of all the board and internal audit. 

So the system still needs governing, and it has no named standard to be governed against. Supervisors and internal audit are reaching for the principles of a framework that formally excludes these systems, then applying them by analogy to LLM underwriting assistants, AML triage agents and customer-facing copilots. 

Governance by analogy is a hard thing to put your signature on. 

More is promised. The guidance says the agencies “plan to issue in the near future a request for information that addresses model risk management generally and considers, in particular, banks’ use of AI, including generative AI and agentic AI and AI-based models.” 

Look closely at what that is. It isn’t a rule, it’s a request for information about whether to write a rule, on no stated timetable. Four months later it had not appeared, and at the time of writing there is still no date attached to it. 

There is an irony worth noting here, though it would be unfair to lean on it. In the same testimony, the FDIC described piloting generative AI for its own staff, with a rollout to the wider workforce expected by mid-year. The regulator is deploying the technology it has, for now, declined to write a standard for.

Where Your Program Actually Stalls 

Ask a bank why its AI program hasn’t reached production and you’ll hear about data quality, legacy integration and talent. All of those are real, and none of them is usually the binding constraint once a system has cleared a successful pilot. 

The binding constraint is a signature. 

Think about where your validator is standing. She is asked to approve a system whose behaviour isn’t deterministic, the formal guidance is silent on it, and no enforceable standard exists to test it against. The promised clarification hasn’t arrived and has no date. If she approves it and it produces a discriminatory outcome in eighteen months, her name is on that decision. If she asks for another round of evidence instead, nothing happens to her at all. 

The asymmetry is total: nobody has ever been criticized for the AI system they did not approve. 

That is why the queue doesn’t move. Not obstruction, not incompetence, and not risk-aversion as a personality trait. It is the correct response to being asked to certify something against a standard that doesn’t exist. Layer on ordinary capacity arithmetic, where the business wants to ship in four weeks and the model risk function is working through a backlog measured in months, and a pilot that succeeded in March is still sitting there in October. 

The technology cleared its own bar months ago, then sat down in a queue built for a different kind of problem. The way out is to give your validator something defensible to test against, which is what the rest of this article is about. 

Set Your Own Standard, Because Nobody Is Coming 

Here is the uncomfortable arithmetic for anyone running an AI program in a regulated institution. Waiting for the request for information, then the proposed rule, then the comment period, then final guidance puts you somewhere between two and four years out. Your competitors aren’t waiting. 

The institutions moving fastest have stopped expecting a standard to arrive and have written their own. It is unglamorous work and all of it is available today. 

  1. Start with the inventory, because it costs nothing and settles the hardest argument. Every LLM assistant, agent and copilot that influences a decision goes in, with a tier, an owner and a stated intended use, whether or not the guidance requires it. Coverage gaps are far cheaper to find yourself than to have found for you, and an inventory is the one artifact every future standard will assume you already had. 
  1. Then write the evaluation criteria you would be willing to defend out loud. Groundedness, refusal behavior, stability of output across reruns, performance across protected classes, escalation rates to a human. All of these are testable today and none of them require anyone’s permission to define. Apply the materiality tiering the bank already uses while you are at it, because a copilot drafting internal summaries and an assistant shaping credit decisions are not the same risk and should not carry the same weight of process. 
  1. The last part matters most, and it’s the part most programs skip. Make the decision reversible. Most of the fear in that room is about permanence, so a staged rollout to a defined population, with monitored outputs and a rollback path that has actually been tested, converts an irreversible approval into a reversible one. That is a far easier signature to obtain. Then document why each judgment was made rather than only what was decided, because when a standard does eventually arrive, the bank that can show its reasoning will be in a much better position than the one that waited and has nothing to show at all. 

None of this needs new regulation, and all of it survives whatever the agencies eventually publish, because materiality, testing and monitoring are what any future standard will ask for. 

Two Years From Now 

Two years from now there will be banks that read the regulatory silence as permission to wait, and banks that read it as room to build. The second group will have spent the time converting judgment into policy, one system at a time, and will hold a working framework by the time anyone is required to have one. 

The first group will still be piloting. 

Krasan Consulting works with organizations in regulated environments where governance capacity not technology, sets the pace of what can be deployed. Where no standard exists, the work is to build one you would be willing to defend in front of an examiner. 

References 

1. Board of Governors of the Federal Reserve System. SR 26-2: Revised Guidance on Model Risk Management. 17 April 2026. https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm 

2. Office of the Comptroller of the Currency. Bulletin 2026-13: Model Risk Management, Revised Guidance. 17 April 2026. https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html 

3. Office of the Comptroller of the Currency. OCC Issues Updated Model Risk Management Guidance. News release NR-OCC-2026-29. https://www.occ.gov/news-issuances/news-releases/2026/nr-occ-2026-29.html 

4. Billingsley, R. Innovation at the Speed of Markets: How Regulators Keep Pace With Technology. Testimony before the House Financial Services Subcommittee, FDIC, 2026. https://www.fdic.gov/news/speeches/2026/innovation-speed-markets-how-regulators-keep-pace-technology-0 

5. Board of Governors of the Federal Reserve System. SR 11-7: Guidance on Model Risk Management. 4 April 2011 (superseded). https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm 

6. Sullivan & Cromwell LLP. Federal Banking Agencies Issue Revised Guidance on Model Risk Management. April 2026. https://www.sullcrom.com/insights/memo/2026/April/OCC-Fed-FDIC-Issue-Revised-Guidance-Model-Risk-Management 

Meet with us!

Talk to a Krasan Consulting Project Specialist to get started.

Subscribe to our
Get updates about Krasan Consulting in your inbox.
Newsletter
WBENC WBE & WOSB Caltrans DBE SAM Registration for Krasan WMATA DBE National Minority Supplier MBE Illinois CMS WMBE & Good Standing Indiana DBE City of Chicago DBE Virginia WMBE Virginia DBE
Supplier Codes
Applications Software Programming Services, Custom Computer (NAICS, 541511) Computer Software Consulting Services or Consultants (NAICS, 541512) Software Installation Services, Computer (NAICS, 541519) Business Management Consulting Services (NAICS, 541611) Software, Microcomputer (Not Otherwise Classified) (NIGP, 20880) Computer Software Consulting (NIGP, 91829) Computer Network Consulting (NIGP, 91830) Governmental Consulting (NIGP, 91858) IT Consulting, (Not Otherwise Classified) (NIGP, 91871) Management Consulting (NIGP, 91875) Organization Development Consulting (NIGP, 91883) Procurement Consulting, Including Specification Development & Contract Consulting (NIGP, 91887) Quality Assurance & Control Consulting (NIGP, 91888) Strategic Planning & Consulting (NIGP, 91890) Data Conversion Services (NIGP, 92024) Processing System Services, Data (Not Otherwise Classified) (NIGP, 92039) Programming Services, Computer, Including Mobile Device Applications (NIGP, 92040) Software Maintenance & Support Services (NIGP, 92045) Software Updating & Upgrading Services (NIGP, 92046) Support Services, Computer, Includes Computer Warranties (NIGP, 92047) Teaching & Training Materials For Computer Science/Technology (Printed or Magnetically Stored) (NIGP, 92074) Technical Writing & Documentation, IT Services (NIGP, 92075) Website Development (NIGP, 92078) Training, Computer Based, Software Supported (NIGP, 92091) Computer Management Services (NIGP, 95823) Project Management Services (NIGP, 95877)
Applications Software Programming Services, Custom Computer (NAICS, 541511) Computer Software Consulting Services or Consultants (NAICS, 541512) Software Installation Services, Computer (NAICS, 541519) Business Management Consulting Services (NAICS, 541611) Software, Microcomputer (Not Otherwise Classified) (NIGP, 20880) Computer Software Consulting (NIGP, 91829) Computer Network Consulting (NIGP, 91830) Governmental Consulting (NIGP, 91858) IT Consulting, (Not Otherwise Classified) (NIGP, 91871) Management Consulting (NIGP, 91875) Organization Development Consulting (NIGP, 91883) Procurement Consulting, Including Specification Development & Contract Consulting (NIGP, 91887) Quality Assurance & Control Consulting (NIGP, 91888) Strategic Planning & Consulting (NIGP, 91890) Data Conversion Services (NIGP, 92024) Processing System Services, Data (Not Otherwise Classified) (NIGP, 92039) Programming Services, Computer, Including Mobile Device Applications (NIGP, 92040) Software Maintenance & Support Services (NIGP, 92045) Software Updating & Upgrading Services (NIGP, 92046) Support Services, Computer, Includes Computer Warranties (NIGP, 92047) Teaching & Training Materials For Computer Science/Technology (Printed or Magnetically Stored) (NIGP, 92074) Technical Writing & Documentation, IT Services (NIGP, 92075) Website Development (NIGP, 92078) Training, Computer Based, Software Supported (NIGP, 92091) Computer Management Services (NIGP, 95823) Project Management Services (NIGP, 95877)
Supplier Codes
Contact our TOPs team to review the contract with us.
Contract Request
Contact our TOPs delivery team to review the process with us.
Get in touch with the team
Sign up to join the Top Hat Hackathon to join a team and get updates on the event.
Top Hat HackeRS
Sign up to join the Top Hat Hackathon to join a team and get updates on the event.
Top Hat HackeRS