SR 26-2 replaces bank model risk management's checklist regime with a materiality-based framework: governance effort should scale with a model's financial exposure and purpose rather than apply uniformly to every spreadsheet and GLM alike.

It imposes nothing on insurers. Its value to an actuarial department is as a reference architecture for a triage nobody has written on the insurance side: which models need independent validation, which need monitoring, and which need only documentation.

Key Takeaways

What SR 26-2 Actually Changed

The three pillars survive from SR 11-7: model development and use, validation and monitoring, and governance and controls. What moved is the calibration underneath them.

The definition narrowed first. A model is now "a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates," with simple arithmetic and deterministic rules explicitly out. For an actuarial department that carve-out is immediate: a rating factor lookup table or a fixed development-triangle spreadsheet with no estimation inside it may sit outside formal governance entirely.

Materiality tiering replaced the de facto annual review that applied the same rigor to every model regardless of stakes. The joint supervisory guidance combines model exposure, the dollar magnitude of the decisions driven, with model purpose. Low-materiality models get identification and performance monitoring; high-materiality models get comprehensive validation whatever the line item looks like.

Ongoing monitoring gained ground on point-in-time review, with continuous drift detection and outcomes analysis elevated relative to periodic formal validation. That fits reserving and pricing better than an annual cycle ever did, because loss experience, exposure mix and settlement patterns move faster than a yearly sign-off tracks. The OCC and FDIC issued the same framework the same day.

Materiality, Not Institution Size, Is the Transferable Idea

The framework's language is written for banking organizations, scaled to size, complexity and model use. The part that crosses the regulatory line intact is the distinction between how large the institution is and how much rides on a given model.

A $2 billion regional insurer running a machine-learning claims-severity model that drives reserve adjustments carries more model risk in that one model than a $50 billion bank running a thousand low-stakes reporting calculations. SR 26-2 says the governance effort should track the second number. Applied to an actuarial inventory, that is what separates a reserve model feeding a Statement of Actuarial Opinion from a commission-calculation spreadsheet, and it is a distinction insurance guidance has never drawn explicitly.

The AI boundary is narrower than it is usually read. Vice Chair for Supervision Michelle Bowman said on May 1, 2026 that the revised guidance "applies narrowly to traditional models and basic AI applications," with other practices expected for generative and agentic AI. Basic AI applications means conventional supervised learning: a gradient-boosted severity model or a random-forest underwriting score sits under the same three pillars as a GLM. What falls outside is generative output and agentic systems that plan and execute multi-step actions.

That split is usable because the validation exercises genuinely differ. Back-testing a loss frequency GLM against observed claim counts has a defined right answer; back-testing a language model's claims summary does not, and an agentic system that chooses its next step mid-process cannot be cleared by one pre-deployment sign-off.

Vendor models are where the accountability language matters most. The guidance is explicit that third-party models get the same rigor as internally built ones, and the insurance analogue is direct: catastrophe models, mortality improvement tables, credit-based scores, geospatial property scores. Buying the tool does not move the conclusion. An actuary signing a filing or an opinion that relies on a vendor score owns it whether or not the training data is visible, which usually means testing the vendor's output against the carrier's own experience and setting a usage limitation where independent validation is not possible.

Two Axes, and a Model Can Pass One While Failing the Other

SR 26-2 and the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted December 2023 and now in force in 24 states and the District of Columbia, get discussed as substitutes. They answer different questions.

SR 26-2 asks whether the institution has a defensible process for building, validating and monitoring the model, independent of what it is used for. The bulletin asks whether the model's use produces unfair discrimination, whether that use is documented and explainable to a regulator, and whether the carrier is accountable for a vendor's outputs under its own program.

Dimension SR 26-2 (2026) NAIC AI Model Bulletin (2023)
Core question Is the model itself sound, validated, and monitored? Does the model's use produce a fair, explainable, documented outcome?
Orientation Enterprise model governance Consumer protection and insurance law
Scope trigger Model materiality (exposure x purpose) Any AI system affecting a consumer-facing insurance decision
AI treatment Covers traditional models and basic AI; generative/agentic AI excluded pending separate guidance Covers AI broadly, including generative and predictive systems, regardless of technique
Vendor accountability Validate third-party models with the same rigor as internal ones Carrier accountable for vendor AI system outcomes under its own governance program

The gap between them is where a program gets caught. A conceptually sound, well-validated underwriting model can still produce disparate impact if the training data encoded a historical pattern validation never tested for, which is a bulletin failure and not a governance one. A model built to satisfy every documentation and explainability expectation can still be poorly calibrated, badly monitored, or validated by the team that built it, which the consumer-protection framework was never designed to catch.

The uncovered corner is larger than either gap. Generative and agentic tools sit outside SR 26-2's scope by design, and the bulletin governs their use rather than their construction, so the fastest-moving category of insurance model has no validation vocabulary on either axis. Sullivan & Cromwell notes the agencies have signaled a separate request for information on exactly that category, which is an acknowledgment that the framework issued in April does not reach it.

Further Reading

Sources

  1. Federal Reserve, SR Letter 26-2: Revised Guidance on Model Risk Management (April 17, 2026)
  2. Federal Reserve/OCC/FDIC, Supervisory Guidance on Model Risk Management attachment (April 2026)
  3. OCC Bulletin 2026-13: Model Risk Management, Revised Guidance (April 17, 2026)
  4. FDIC FIL-15-2026: Agencies Revise the Interagency Model Risk Management Guidance (April 2026)
  5. Federal Reserve SR 11-7: Guidance on Model Risk Management (April 4, 2011)
  6. Federal Reserve, Vice Chair for Supervision Bowman speech on AI in the financial system (May 1, 2026)
  7. NAIC, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023)
  8. Quarles Law Firm, "Nearly Half of States Have Now Adopted NAIC Model Bulletin on Insurers' Use of AI" (2026)
  9. NAIC, Health Artificial Intelligence/Machine Learning Survey Report (May 2025; 92% of 93 responding health insurers report current or planned AI/ML use)
  10. NAIC, Artificial Intelligence Insurance Topics (private passenger auto AI/ML survey; 88% of 193 responding insurers)
  11. Sullivan & Cromwell, "Federal Banking Agencies Issue Revised Guidance on Model Risk Management" (April 2026)