What changed — SR 11-7 to SR 26-2 in plain terms
SR 11-7 was issued by the Federal Reserve in 2011. For 15 years, it was the foundational framework governing how banks identify, validate, monitor, and govern quantitative models. Every model risk management program in U.S. banking — and by extension, every AI vendor selling into those banks — has been built around SR 11-7's requirements.
On April 17, 2026, the Federal Reserve, OCC, and FDIC jointly issued SR 26-2, replacing SR 11-7 with a more modern, principles-based framework. The shift is significant — not because the discipline of model risk management has changed, but because the way it is applied and documented has changed meaningfully.
| Area | SR 11-7 (2011) | SR 26-2 (2026) |
|---|---|---|
| APPROACH | Prescriptive, directive, binding in practice | Principles-based, risk-proportionate, explicitly non-binding |
| MODEL DEFINITION | Expansive — pulled in spreadsheets, rule engines, workflow tools | Narrower — excludes simple arithmetic, deterministic rule-based processes |
| VALIDATION CYCLE | Default annual revalidation | Risk-based cadence tied to model materiality and change velocity |
| GOVERNANCE STANDARD | "Are we following the rules?" | "Is our discipline defensible on its own terms?" |
| AI / GENAI SCOPE | Not addressed | Traditional ML in scope — GenAI and agentic AI explicitly excluded |
| APPLICABILITY | All banking organizations | Most relevant to banks with over $30B in total assets |
The core disciplines of sound model governance remain — independent review, validation, ongoing monitoring, and effective challenge. What has changed is the expectation that each institution — and by extension, each AI vendor — tailor governance to actual risk rather than follow a one-size-fits-all checklist.
Why MedTech AI companies need to pay attention
This is where most MedTech AI teams make a mistake. SR 26-2 is a banking regulation — and many MedTech companies assume it does not apply to them. That assumption is wrong for a specific and growing category of MedTech AI.
If your AI model touches any of the following, the hospital systems and payers you sell into are subject to SR 26-2 — and they will require your compliance documentation to reflect the updated framework:
- Prior authorization AI — Any AI model used in payer prior authorization workflows is subject to both CMS non-discrimination requirements and the model risk governance framework the payer operates under
- Reimbursement coding and claims AI — AI that supports ICD-10 coding, CPT code selection, or claims adjudication touches financial decision-making systems that payers govern under model risk frameworks
- Clinical decision support with financial outcomes — AI that influences treatment decisions that directly affect billing, length of stay, or resource utilization sits at the intersection of FDA clinical AI guidance and payer model risk requirements
- Revenue cycle AI sold to hospital systems — Hospital systems with significant assets operate their own model risk programs aligned to SR 26-2. AI vendors in their revenue cycle stack are increasingly required to provide SR 26-2-aligned documentation
- AI sold to payers above $30B in assets — The largest health insurance organizations in the US are subject to SR 26-2 directly. Any AI vendor in their technology stack is expected to provide documentation that satisfies their model risk governance requirements
If your AI compliance documentation still references SR 11-7 — in your technical file, your vendor questionnaire responses, or your procurement materials — you are citing a superseded framework. Hospital and payer compliance teams reviewing your documentation in August 2026 onward will notice. Update your documentation now, before your next procurement conversation.
Three specific changes that affect your AI documentation
1. Materiality-based governance replaces checkbox compliance
Under SR 11-7, the expectation was largely procedural — follow the steps, document the annual validation, satisfy the checklist. SR 26-2 replaces that with a materiality construct: governance effort must be calibrated to actual risk, defined by the model's inherent complexity, its exposure (how many decisions it affects), and its purpose.
For MedTech AI vendors, this means your compliance documentation can no longer be a generic one-size-fits-all package. Hospital and payer risk teams will now evaluate whether your governance is proportionate to the actual risk your AI creates. A low-risk scheduling optimization model requires different documentation than a high-risk prior authorization AI — and your documentation needs to reflect that distinction explicitly.
2. Annual revalidation is out — risk-based monitoring is in
SR 11-7's de facto annual revalidation cycle has been replaced by a risk-based approach tied to model materiality, change velocity, and data availability. For MedTech AI companies, this is actually an opportunity — it means demonstrating ongoing monitoring capability matters more than producing an annual validation report.
Hospital and payer risk teams will increasingly ask: what does your post-deployment monitoring look like? How do you detect and respond to performance drift? What is your revalidation trigger? These questions map directly to FDA's Predetermined Change Control Plan (PCCP) requirements — which means MedTech AI companies that have invested in PCCP documentation are better positioned for SR 26-2-aligned procurement conversations than those that haven't.
3. The model definition has tightened — and that cuts both ways
SR 26-2 narrows the definition of a model, explicitly excluding simple arithmetic calculations and deterministic rule-based processes. For MedTech AI vendors, this creates clarity: if your AI applies statistical, economic, or financial theory to generate outputs that influence decisions — it is a model under SR 26-2, and it requires the full governance treatment.
The narrower definition also means that payer and hospital compliance teams will be more precise in what they require documentation for. Simple rule-based tools may no longer require full model risk documentation. But AI models that make probabilistic predictions — clinical decision support, risk stratification, utilization management — remain fully in scope and face higher scrutiny than before, because the governance burden has shifted from procedural compliance to defensible justification.
The GenAI gap — what SR 26-2 deliberately left out
SR 26-2 explicitly places generative AI and agentic AI outside its scope, describing them as "novel and rapidly evolving." This is the most consequential decision in the guidance — and it creates a specific compliance problem for MedTech AI companies building on large language models.
Being outside SR 26-2's scope is not the same as being outside the governance requirement. The guidance states explicitly that a bank's existing risk management principles — materiality, ongoing monitoring, effective challenge — should guide governance for any tools and systems not covered by the document. Payers and hospital systems deploying or procuring GenAI tools are still accountable for governing them. They will pass that accountability to their vendors.
The Federal Reserve has indicated that separate AI-specific guidance for generative and agentic AI is forthcoming — a Request for Information from the OCC, Fed, and FDIC on GenAI governance is widely anticipated but not yet published as of August 2026.
For MedTech AI companies building on LLMs or agentic architectures, this creates a documentation gap that no current framework fully fills. The frameworks that apply in this space right now are:
- NIST AI RMF — The most comprehensive voluntary framework for AI risk management, applicable across sectors
- FDA 2025 AI Guidance — For clinical AI and SaMD, FDA's Total Product Lifecycle approach applies regardless of the underlying architecture
- ISO 42001 — The AI Management System standard, increasingly referenced by enterprise buyers as a baseline governance requirement
- EU AI Act — For organizations operating in European markets or selling to European payers, high-risk AI system requirements apply to clinical AI regardless of SR 26-2's scope
If your MedTech AI is built on a generative or agentic architecture — and your hospital or payer client asks how it is governed under SR 26-2 — the honest answer is that it falls outside SR 26-2's formal scope, but is governed under a parallel framework you should be able to name, document, and evidence independently.
What to do before your next hospital or payer meeting
The transition from SR 11-7 to SR 26-2 is not a crisis — it is a documentation update opportunity. Here is what MedTech AI companies should do before the next procurement or compliance conversation:
- Audit your existing compliance documentation for SR 11-7 references and update them to SR 26-2. This includes technical files, vendor questionnaire templates, procurement response packages, and any marketing materials that reference the framework
- Map your AI model's governance to SR 26-2's materiality construct — explicitly document the inherent risk, exposure, and purpose of your model and justify the governance level you apply against those factors
- Strengthen your post-deployment monitoring documentation — SR 26-2's shift from annual revalidation to risk-based monitoring rewards companies that can demonstrate ongoing performance oversight. This overlaps directly with FDA's PCCP requirements
- Build a parallel governance framework for GenAI components — if your AI stack includes LLM or agentic elements, document how they are governed under NIST AI RMF, ISO 42001, or another named framework, and be prepared to explain that governance in a payer or hospital compliance meeting
- Get an independent evaluation — SR 26-2's emphasis on effective challenge and independent review means that hospital and payer risk teams will increasingly require evidence that someone outside your organization has assessed your AI model. Internal validation alone does not satisfy that requirement
Hospital and payer compliance teams are not waiting for MedTech AI vendors to catch up. The companies that arrive at procurement conversations with SR 26-2-aligned documentation, a named post-deployment monitoring program, and independent third-party evaluation evidence will close deals faster than those still referencing SR 11-7 and annual validation cycles. The gap between those two positions is closing fast.
Is your AI documentation SR 26-2 ready?
ClearanceAI evaluates AI models against SR 26-2, NIST AI RMF, FDA 2025 AI Guidance, and ISO 42001 — delivering a formal independent assessment your hospital and payer clients can rely on. Start with the free 2-minute assessment or request a full evaluation directly.