15
Years SR 11-7 governed model risk management. Every hospital risk committee, payer compliance team, and bank examiner has been referencing SR 11-7 since 2011. On April 17, 2026, it was superseded — and most of the industry hasn't updated their AI compliance documentation to reflect that.

What changed — SR 11-7 to SR 26-2 in plain terms

SR 11-7 was issued by the Federal Reserve in 2011. For 15 years, it was the foundational framework governing how banks identify, validate, monitor, and govern quantitative models. Every model risk management program in U.S. banking — and by extension, every AI vendor selling into those banks — has been built around SR 11-7's requirements.

On April 17, 2026, the Federal Reserve, OCC, and FDIC jointly issued SR 26-2, replacing SR 11-7 with a more modern, principles-based framework. The shift is significant — not because the discipline of model risk management has changed, but because the way it is applied and documented has changed meaningfully.

Area SR 11-7 (2011) SR 26-2 (2026)
APPROACH Prescriptive, directive, binding in practice Principles-based, risk-proportionate, explicitly non-binding
MODEL DEFINITION Expansive — pulled in spreadsheets, rule engines, workflow tools Narrower — excludes simple arithmetic, deterministic rule-based processes
VALIDATION CYCLE Default annual revalidation Risk-based cadence tied to model materiality and change velocity
GOVERNANCE STANDARD "Are we following the rules?" "Is our discipline defensible on its own terms?"
AI / GENAI SCOPE Not addressed Traditional ML in scope — GenAI and agentic AI explicitly excluded
APPLICABILITY All banking organizations Most relevant to banks with over $30B in total assets

The core disciplines of sound model governance remain — independent review, validation, ongoing monitoring, and effective challenge. What has changed is the expectation that each institution — and by extension, each AI vendor — tailor governance to actual risk rather than follow a one-size-fits-all checklist.

Why MedTech AI companies need to pay attention

This is where most MedTech AI teams make a mistake. SR 26-2 is a banking regulation — and many MedTech companies assume it does not apply to them. That assumption is wrong for a specific and growing category of MedTech AI.

If your AI model touches any of the following, the hospital systems and payers you sell into are subject to SR 26-2 — and they will require your compliance documentation to reflect the updated framework:

// The Documentation Problem

If your AI compliance documentation still references SR 11-7 — in your technical file, your vendor questionnaire responses, or your procurement materials — you are citing a superseded framework. Hospital and payer compliance teams reviewing your documentation in August 2026 onward will notice. Update your documentation now, before your next procurement conversation.

Three specific changes that affect your AI documentation

1. Materiality-based governance replaces checkbox compliance

Under SR 11-7, the expectation was largely procedural — follow the steps, document the annual validation, satisfy the checklist. SR 26-2 replaces that with a materiality construct: governance effort must be calibrated to actual risk, defined by the model's inherent complexity, its exposure (how many decisions it affects), and its purpose.

For MedTech AI vendors, this means your compliance documentation can no longer be a generic one-size-fits-all package. Hospital and payer risk teams will now evaluate whether your governance is proportionate to the actual risk your AI creates. A low-risk scheduling optimization model requires different documentation than a high-risk prior authorization AI — and your documentation needs to reflect that distinction explicitly.

2. Annual revalidation is out — risk-based monitoring is in

SR 11-7's de facto annual revalidation cycle has been replaced by a risk-based approach tied to model materiality, change velocity, and data availability. For MedTech AI companies, this is actually an opportunity — it means demonstrating ongoing monitoring capability matters more than producing an annual validation report.

Hospital and payer risk teams will increasingly ask: what does your post-deployment monitoring look like? How do you detect and respond to performance drift? What is your revalidation trigger? These questions map directly to FDA's Predetermined Change Control Plan (PCCP) requirements — which means MedTech AI companies that have invested in PCCP documentation are better positioned for SR 26-2-aligned procurement conversations than those that haven't.

3. The model definition has tightened — and that cuts both ways

SR 26-2 narrows the definition of a model, explicitly excluding simple arithmetic calculations and deterministic rule-based processes. For MedTech AI vendors, this creates clarity: if your AI applies statistical, economic, or financial theory to generate outputs that influence decisions — it is a model under SR 26-2, and it requires the full governance treatment.

The narrower definition also means that payer and hospital compliance teams will be more precise in what they require documentation for. Simple rule-based tools may no longer require full model risk documentation. But AI models that make probabilistic predictions — clinical decision support, risk stratification, utilization management — remain fully in scope and face higher scrutiny than before, because the governance burden has shifted from procedural compliance to defensible justification.

The GenAI gap — what SR 26-2 deliberately left out

SR 26-2 explicitly places generative AI and agentic AI outside its scope, describing them as "novel and rapidly evolving." This is the most consequential decision in the guidance — and it creates a specific compliance problem for MedTech AI companies building on large language models.

// What "Out of Scope" Actually Means

Being outside SR 26-2's scope is not the same as being outside the governance requirement. The guidance states explicitly that a bank's existing risk management principles — materiality, ongoing monitoring, effective challenge — should guide governance for any tools and systems not covered by the document. Payers and hospital systems deploying or procuring GenAI tools are still accountable for governing them. They will pass that accountability to their vendors.

The Federal Reserve has indicated that separate AI-specific guidance for generative and agentic AI is forthcoming — a Request for Information from the OCC, Fed, and FDIC on GenAI governance is widely anticipated but not yet published as of August 2026.

For MedTech AI companies building on LLMs or agentic architectures, this creates a documentation gap that no current framework fully fills. The frameworks that apply in this space right now are:

If your MedTech AI is built on a generative or agentic architecture — and your hospital or payer client asks how it is governed under SR 26-2 — the honest answer is that it falls outside SR 26-2's formal scope, but is governed under a parallel framework you should be able to name, document, and evidence independently.

What to do before your next hospital or payer meeting

The transition from SR 11-7 to SR 26-2 is not a crisis — it is a documentation update opportunity. Here is what MedTech AI companies should do before the next procurement or compliance conversation:

// The Procurement Reality

Hospital and payer compliance teams are not waiting for MedTech AI vendors to catch up. The companies that arrive at procurement conversations with SR 26-2-aligned documentation, a named post-deployment monitoring program, and independent third-party evaluation evidence will close deals faster than those still referencing SR 11-7 and annual validation cycles. The gap between those two positions is closing fast.


🎓
NR Koka — Founder, ClearanceAI
20+ years in design assurance and regulatory compliance across medical device and AI systems. Previously at GE Healthcare and J&J. ClearanceAI provides independent third-party AI model evaluation for regulated industries — healthcare, finance, and defense.

Is your AI documentation SR 26-2 ready?

ClearanceAI evaluates AI models against SR 26-2, NIST AI RMF, FDA 2025 AI Guidance, and ISO 42001 — delivering a formal independent assessment your hospital and payer clients can rely on. Start with the free 2-minute assessment or request a full evaluation directly.