Field Guide

AI Model Governance for Compliance: An SR 11-7 Field Guide

The short version

AI model governance is the application of model risk management discipline to artificial-intelligence systems that inform or produce compliance decisions. SR 11-7, the supervisory guidance on model risk, supplies the framework: sound development, independent validation, and documented oversight. An AI compliance tool is defensible when the institution can explain how the model works, show that it was validated independently, and identify the qualified person who reviewed and attested to the output. Accountability rests with that named person rather than with the model.

AI model governance is the application of model risk management discipline — sound development, independent validation, and documented oversight — to artificial-intelligence systems that inform or produce compliance decisions. In U.S. banking supervision the controlling framework is SR 11-7, the interagency Supervisory Guidance on Model Risk Management issued by the Federal Reserve and the OCC in 2011 (OCC Bulletin 2011-12). Its definition of a model reaches AI systems that score risk, draft SAR narratives, tune monitoring thresholds, or read regulatory change.

This guide covers what SR 11-7 requires, why it reaches AI compliance tools, what validation looks like in practice, the function of explainability and the audit trail, and the questions an institution puts to a vendor selling an AI compliance tool.

Supervisory posture toward AI in compliance

Compliance teams have adopted AI to score risk, draft SAR narratives, tune monitoring, and read regulatory change, and supervisory attention has followed. The examination question concerns how an institution controls the model it uses rather than whether it uses one. Documented control over the model is the condition on which supervisory acceptance turns; an AI treated as an unexamined vendor black box does not satisfy it.

What SR 11-7 is

SR 11-7 is the interagency Supervisory Guidance on Model Risk Management, issued by the Federal Reserve and the OCC in 2011 (OCC Bulletin 2011-12). It became the reference standard for how a regulated institution manages the risk of relying on a model. It defines a model broadly: a quantitative method that turns inputs into estimates, scores, or decisions. The definition is deliberately wide, and modern AI systems fall within it.

The guidance rests on the premise that models are useful and can also be wrong, so an institution that depends on a model must manage the risk that the model is wrong. The degree of rigor scales with the weight of the reliance and the consequence of an error.

The three elements SR 11-7 expects

ElementWhat it requires
Development, implementation, and useA sound design built on appropriate data and method, documented well enough that someone other than the builder can understand it, and used only for the purpose it was built for.
ValidationAn effective, independent challenge to the model: is it conceptually sound, does it still perform, and do its outcomes hold up. Performed by people with distance from the developers.
Governance, policies, and controlsClear ownership, written policies, an inventory of models, defined roles, and board and senior-management oversight of the whole thing.

SR 11-7 is the supervisory backbone, and a newer companion speaks directly to generative tools. The NIST AI Risk Management Framework (AI RMF 1.0, 2023) and its Generative AI Profile (NIST-AI-600-1, July 2024) give a common vocabulary for AI-specific risks such as confabulation and information integrity. They are voluntary rather than binding, but they are the reference an examiner and a model-risk team increasingly expect to see mapped alongside SR 11-7 when the model is generative.

What validating an AI compliance model means

SR 11-7 frames validation in three parts, each of which maps onto an AI system:

Independence is the operative term. Validation performed by the same people who built the model, without separation or effective challenge, carries limited weight in examination.

Explainability and the audit trail

A model that produces a score or a narrative with no traceable reasoning gives a reviewer nothing to inspect, and an attribution of the outcome to the model itself does not identify a decision-maker. Two elements address this condition. Explainability means the institution can describe, in terms a reviewer follows, how the model reached its result. The audit trail means every step is logged, so the path from input to output can be reconstructed long after the fact. Together they make an otherwise opaque output inspectable.

The human in the loop

Under this control a qualified person reviews the AI's work and attests to it before that work is used: the model produces a draft and the reviewer decides whether to adopt it. The control matters because accountability cannot sit with a model. It sits with a named person who can be asked to explain a filing or a decision. A design that removes the human from that loop removes the element that makes the output defensible.

Questions to ask an AI compliance vendor

An institution evaluating a tool that places AI near a compliance decision puts the following questions to the vendor and weighs the answers:

A vendor that cannot explain how its AI reaches a result leaves the institution without the documentation an examination requires. Governing an AI system on the same terms as any other model preserves the institution's ability to support the result.

Common questions

What is SR 11-7?
SR 11-7 is the U.S. interagency Supervisory Guidance on Model Risk Management, issued by the Federal Reserve and the OCC in 2011 (OCC Bulletin 2011-12). It sets the expectation that institutions manage the risk of any model they rely on through three things: sound model development, implementation, and use; effective and independent validation; and strong governance, policies, and controls.
Does SR 11-7 apply to AI compliance tools?
Yes. SR 11-7 defines a model broadly as a quantitative method that processes inputs into estimates or decisions. An AI system that scores risk, generates SAR narratives, or flags transactions fits that definition. When an AI tool influences compliance decisions, examiners expect it to be governed as a model: developed soundly, validated independently, and overseen with documented controls.
Can examiners accept AI-generated compliance work?
Examiners accept AI-supported work when the institution can show the AI is governed and a qualified human owns the output. The failure mode is an unexplained black box with no validation and no human accountability. A tool that can explain how it works, demonstrate it was validated, and prove a person reviewed and attested to each deliverable meets the expectation SR 11-7 sets.
What does it mean to validate an AI compliance model?
Validation under SR 11-7 has three parts: evaluating conceptual soundness (is the design and the data fit for purpose), ongoing monitoring (does it still perform as conditions change), and outcomes analysis (do its results hold up against benchmarks or back-testing). Validation should be performed with independence from the people who built the model, and documented so an examiner can follow it.
What questions should an institution ask an AI compliance vendor?
The questions are how the AI reaches a result and whether that reasoning is auditable, how the model was validated and by whom, what ongoing monitoring catches drift, how bias is tested, where the human reviews and attests before output is used, and what audit trail an examiner could inspect. A vendor that cannot answer how the AI works is a vendor whose tool the institution cannot defend.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.

Primary sources

The authoritative texts this guide is grounded in. Government sites may block automated access but resolve in a browser.