MiddlebrookData & AI Governance← Back to site

Free gap check · SR 11-7 vs. GenAI

Does your model-risk program actually cover your GenAI?

Your bank runs disciplined model risk (SR 11-7) — but the OCC's revised guidance explicitly excludes generative and agentic AI. So the most consequential AI in your stack may sit outside the controls your second line runs. Answer six questions and see exactly where your examiner exposure is.

2 minutes, no email required to see your result. Anchored to SR 11-7, the OCC, NIST AI RMF, the EU AI Act, SOX and CFPB/ECOA.
Full readiness assessment
Q1 Do you run a formal model-risk management (MRM) / SR 11-7 program?
Q2 Are generative or agentic AI tools in use touching reporting or decisions?
Q3 Are those AI tools in your model inventory?
Q4 Are they validated & monitored like models — drift, performance, periodic review?
Q5 Output governance on AI-generated figures — provenance, human-in-the-loop, audit trail?
Q6 Regulatory exposure — check all that apply
Gap severity

Answer the six questions, then press See my gap. Your result updates live as you go — no email needed.

Why this gap is real: Banks already run model risk under SR 11-7, but the OCC's revised model-risk guidance excludes generative and agentic AI — so your most consequential AI can sit outside the validation, monitoring, and inventory controls your second line actually runs. Closing it means extending SR 11-7 to cover GenAI and mapping the controls to NIST AI RMF (Govern/Map/Measure/Manage), the EU AI Act, and your SOX and CFPB/ECOA obligations.

Email me the full gap report

We'll send a fuller written breakdown of your gap — the controls to evidence, mapped to SR 11-7, NIST AI RMF and the EU AI Act — plus an occasional governance note. No spam; unsubscribe anytime.

Ready for the full picture?

From a gap check to a governed program.

The free readiness assessment scores all seven pillars; a call scopes the work to close the gap. Pick whichever fits.

Informational only — not legal advice. A directional indicator; confirm specifics with your risk and compliance teams.