Compliance·18 July 2026

SR 11-7 in the age of agents: model risk officers rewrite the checklist

Federal Reserve guidance from 2011 is quietly becoming the template for how US banks govern generative and agentic AI.

SR 11-7, the Federal Reserve's Supervisory Guidance on Model Risk Management, was written before the current wave of generative AI. It is nonetheless the document most US bank model risk officers reach for when they are asked to govern an LLM or an agent.

The core demand of SR 11-7 — an independent, verifiable record of what a model does — maps cleanly onto agent systems, provided the record actually exists. In practice, most agent deployments in 2026 still fail this test at the transcript layer alone.

Firms that pass it treat every agent call as a first-class object: the prompt, the tool calls, the retrieval sources, and the final output are all captured, versioned, and independently replayable.