financial · Federal Reserve SR 11-7 · OCC 2011-12 · Basel III Pillar 2
Bank Model Risk Management (SR 11-7)
CMRO must document human review before remediation — receipt or 483-equivalent
—Freddie Mac AI governance (SR 11-7 baseline)
Regulatory exposure — commonly overlooked:
Banks validate models quarterly but cannot produce per-inference audit — examiners now ask both. · Annex III high-risk list covers 8 domains — one vertical per domain minimum for compliance.
TAM / Exposure
Every OCC-supervised bank · SR 11-7 is law since 2011
Insurance lines
Bank E&O · D&O · Crime
Exhibit authority
EU AI Act Conformity Pack — SR 11-7 Model Validation Evidence Pack
Global leaders
Federal Reserve · OCC · JPMorgan · Goldman Sachs · Moody's · EU AI Office · EDPB · European Parliament
Model drift
Performance degradation without documented override = consent order pattern.
Vendor models
Third-party credit models — bank owns validation, vendor owns nothing.
CECL correlation
AI loss forecasting for CECL requires auditable assumption chain.
[European Union] FRIA requirement
Fundamental rights impact assessment for public/high-risk — exhibit pack maps to FRIA.
[European Union] PLD strict liability
Dec 2026 product liability directive — software and AI explicitly included.
[Text / Chat] Modality hook
Baseline — all frameworks apply to text decisions.
7 mandate layers (live)
Regulatory ClockCountdown to operative regulatory deadline — NAIC adoption, GSE mandate, EU transposition.Open →
Domain ClassifierIndustry-specific SAFE/CRISIS/VIOLATION with regulatory framework mapping.Open →
Exhibit / Filing PackRegulator-ready external validation — NAIC Exhibit D, Fannie QC, EU FRIA, FDA Part 11.Open →
Mandate RegistryEnroll deployers/insureds under vertical-specific governance mandate.Open →