Your model-risk program doesn't cover your GenAI
Banks have spent a decade building disciplined model-risk programs — inventories, validation, monitoring, documentation, all the machinery of SR 11-7. It works. The problem is that the AI you're deploying right now mostly falls outside it — and the regulators have just confirmed it.
The gap is now official
The OCC's revised model-risk guidance explicitly excludes generative and agentic AI from its scope. SR 11-7 was written for deterministic, relatively static models — not for probabilistic systems that generate language, reason over your data, and change behavior as they're updated. So your copilots, your RAG assistants, and the agents quietly wired into reporting workflows sit in a governance no-man's-land: too consequential to ignore, but outside the framework your second line actually runs.
Your SR 11-7 program didn't disappear — it just doesn't reach the AI you're actually deploying.
Why "it wasn't in scope" won't fly
The moment that AI touches credit, reporting, or a customer decision, the absence of governance becomes your exposure — not the tool's. "The model wasn't in our MRM scope" is not a defense to an examiner. And the pressure is converging from every direction:
- DORA now treats AI as part of ICT risk — supervisors expect controls at the start of the model lifecycle, not bolted on after.
- The EU AI Act tiers credit-scoring and risk-assessment AI as high-risk, with conformity obligations and penalties up to €15M or 3% of global turnover.
- US supervisors — including the Federal Reserve — are publicly signaling that AI in the financial system is squarely a safety-and-soundness matter.
- The FS AI RMF — the Treasury's Financial Services AI Risk Management Framework — now spells out, in 230 finance-specific control objectives, exactly what "good" looks like for the AI your SR 11-7 program doesn't reach. It's voluntary, but it's the yardstick an examiner will reach for.
None of this waits for a single deadline. The work is coming regardless; the only question is whether you lead it deliberately or scramble through an exam.
The fix: extend model risk, don't reinvent it
The good news is that you don't need a parallel rulebook — and you no longer have to invent the target. The Treasury's FS AI RMF maps the SR 11-7 disciplines onto generative and agentic AI in 230 finance-specific controls, so closing the gap is now a matter of extending the discipline you already have to the systems it wasn't written for:
- Inventory every AI use touching reporting, credit, or customers — including the shadow ones. You can't govern what you haven't catalogued.
- Risk-tier each use — not every model needs the same scrutiny; the ones near a regulated decision do.
- Validate and monitor as models that drift — extend validation, set quality SLAs, and watch for data and model drift.
- Govern the data beneath it — a semantic layer and lineage so the AI reasons over certified definitions, not raw tables, and every output can cite its source.
- Keep humans on high-stakes outputs, and evidence as you operate — the audit trail that proves all of the above, built continuously rather than reconstructed in a pre-exam fire drill.
This is governance a CFO and an examiner already understand — model risk, extended to AI. It's exactly the gap a fractional Head of AI Governance is built to close: one accountable owner extending your control environment to cover the AI, without the cost of a permanent hire.
The gap widens with every use case you ship
This isn't a theoretical risk anymore — the SR 11-7 GenAI exclusion is on the record, confirmed by the regulators themselves. That means the gap between your controls and your AI isn't holding steady; it grows every time you ship another copilot, RAG assistant, or reporting agent into production. Each new use case lands outside the framework your second line runs — and the day an examiner asks where it's governed, "outside scope" is the answer you'll be giving.
Every GenAI use case you deploy ungoverned is one more thing you'll have to explain after the fact.
Does your model-risk program cover your AI — before your examiner asks?
Take the free 4-minute risk assessment to see where the gaps are — or book a call to scope a full, expert-led review.
Take the free assessment See pricing & engagement →