Get in touch
Close

Is your model the risk?

We'll find out.

SR 26-2: Is Your Model Risk Program Ready?

Interconnected highways

SR 26-2 just changed the model risk rulebook. Here’s what Chief Credit Officers need to know before their next model review.

On April 17, 2026, the Federal Reserve, OCC, and FDIC jointly issued SR 26-2, the first meaningful update to model risk management guidance since SR 11-7 in 2011. It’s non-binding. No bank is required to adopt it. And yet, within weeks, it has become the de facto standard examiners and auditors use to judge whether a model risk program is sound.

If you’re a Chief Credit Officer, you’ve probably heard about SR 26-2 secondhand. A summary from your risk team. A headline in a compliance newsletter. That’s typical. The guidance itself reads like it was written for model risk officers, not for the person who actually owns the credit models it governs.

But buried inside SR 26-2 is something that should matter to you directly, and it’s easy to miss if you’re skimming for what changed.

The SR 26-2 change that should matter most to CCOs

SR 11-7 built its credibility on structure. Validation had to sit apart from model development. If the org chart showed separation, the review counted as independent.

SR 26-2 keeps the same underlying principle of “effective challenge,” or the idea that models must be critically reviewed by people with the standing to actually push back. But it redefines what makes that challenge real. The new guidance is explicit: effective challenge is a function of the quality of the review, not of where the reviewer sits in the org chart.

If that sounds like a small wording change, it isn’t. It means a validation team can be fully independent, fully documented, and still fail the standard. The bar moved from “did you have a separate team look at this” to “did that team actually catch what matters.”

For a CCO, this is the part that lands closest to home. When your models get reviewed, SR 26-2 is quietly asking is whether that review would actually hold up under scrutiny.

Where comfort turns into a blind spot

We often hear “We’re comfortable with our framework” or  “We use SHAP for explainability.

It sounds like due diligence. Explainability is documented. Adverse action reason codes are generated. Fair lending reviews cite feature importance rankings. The boxes are checked.

But “checked” and “correct” aren’t the same. The gap between them is exactly where an effective challenge is supposed to live. A review that runs a standard explainability method, produces a plot. And, its sign off has performed a process, not a challenge. 

Whether that process actually holds up depends on whether the method itself is reliable for the specific question being asked of it. That’s a much narrower and more technical question than most validation checklists are built to catch, and it’s precisely the kind of question SR 26-2’s redefinition of effective challenge is pointing at.

The bigger point of SR 26-2

SR 26-2 isn’t asking you to do more model governance. It’s asking whether the governance you already have would survive someone with real expertise looking closely at the methods underneath it.

That’s a different kind of scrutiny than most institutions are set up to apply internally. It requires someone who understands both the credit risk side and the underlying ML methodology deeply enough to know where the seams are. Not someone running through a standard validation checklist. Not a generalist auditor who wasn’t in the room when the model was built.

The real exposure under the new guidance sits between process-level review and method-level scrutiny. It’s also where the most useful conversations happen once you start looking.