โ†
AI for Banking & Lending
Aware ยท M12 ยท lesson 12 of 19 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
OCC Bulletin 2026-13 and Model Risk
๐Ÿ“–
now learning

OCC Bulletin 2026-13 and Model Risk

15 min

On a Tuesday morning in April 2026, three agencies published a document that changed what it means to govern AI at an American bank. The Office of the Comptroller of the Currency (OCC), the Federal Reserve, and the Federal Deposit Insurance Corporation (FDIC) released updated interagency model-risk management guidance under OCC Bulletin 2026-13, formally superseding OCC Bulletin 2011-12, which had been the governing framework for model risk at federally regulated institutions for fifteen years. The 2011-12 bulletin was written when a "model" at a bank meant a credit scoring formula or a loan-loss provisioning algorithm. By 2026, with AI or machine learning in use across a substantial and growing share of mortgage underwriting workflows, and generative AI (GenAI) drafting credit memos, adverse-action notices, and customer communications across thousands of institutions, the 2011-12 framework had become a regulatory relic. The new bulletin did not gently update the old one. It rewrote the governance expectations for any technology that meets the definition of a model, and its most significant move was pulling AI and GenAI squarely and explicitly into that definition, alongside model-risk, fair-lending, third-party risk, and board-governance expectations that did not previously apply with this level of specificity to AI systems.

What OCC 2011-12 Said and Why It Was Not Enough

OCC Bulletin 2011-12, "Sound Practices for Model Risk Management," established the foundational framework that banks have operated under since 2011. The bulletin defined a model as "a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates." Under that definition, the bulletin required banks to implement a model risk management program covering three pillars: model development and implementation (building the model correctly), model validation (independently testing it), and model governance and oversight (managing its ongoing use).

The framework was well-designed for the world it was written in: actuarial credit scoring models, economic capital models, interest rate risk models, loan-loss provisioning models, and other quantitative tools whose inputs, assumptions, and outputs were relatively transparent and where the model developer could articulate the theoretical basis for the model's structure.

Generative AI and modern machine learning models do not fit this mold in several important ways:

The opacity problem: A gradient-boosted ensemble trained on thousands of features or a large language model trained on billions of parameters does not have a clean theoretical basis that a developer can articulate in a validation memo. The model learns its structure from data. Its "assumptions" are not stated; they are embedded in billions of weights. Under the 2011-12 framework, validating a model meant understanding and challenging its theoretical assumptions. For a large language model, there are no assumptions to challenge in the traditional sense.

The scope problem: OCC 2011-12 was designed for quantitative models that produce numerical outputs: a credit score, a loan-loss estimate, a market-risk value. GenAI produces text, structured data, and recommendations. A model that drafts an adverse-action notice or summarizes a credit memo is performing a function that has regulatory consequences (the notice must state accurate reasons under Regulation B; the memo will inform a credit decision) but that falls outside the narrow numerical-output paradigm the 2011-12 framework was designed for.

The third-party problem: In 2011, most models at regulated institutions were built internally or by quantitative vendors whose methodologies were documented and available for review. By 2026, many AI models are provided by fintech vendors, cloud platforms, and AI companies that treat their model architecture as proprietary intellectual property, providing only an API and a performance certification. The 2011-12 framework's validation requirements assume access to the model's internals that vendors often do not provide.

The GenAI hallucination problem: Traditional quantitative models produce wrong answers, but they produce wrong answers in systematic, analyzable ways. A credit score that misbehaves for a specific input range can be identified through backtesting. A large language model that produces fabricated income figures, invented loan covenants, or inaccurate adverse-action reasons does so in ways that are not predictable from backtesting and that may look correct to a reviewer who is not closely verifying against source documents. This failure mode did not exist in the 2011-12 world.

These gaps meant that as AI adoption accelerated from 2022 to 2026, regulated banks were technically required to apply a model-risk framework designed for a completely different technology. Some applied it rigorously and documented the gaps. Many applied it superficially. A few argued that AI tools were not "models" under the 2011-12 definition and therefore did not require model-risk treatment at all. OCC Bulletin 2026-13 closed all of these gaps, definitively and explicitly.

What OCC 2026-13 Says: The Core Provisions

OCC Bulletin 2026-13 is an interagency document, meaning it reflects the joint position of the OCC, the Federal Reserve, and the FDIC. For nationally chartered banks, it is guidance issued by the OCC (Office of the Comptroller of the Currency) as the primary regulator. For state member banks, the Federal Reserve equivalent applies. For state nonmember banks, the FDIC equivalent applies. The substance is the same across all three: any federally regulated institution using AI or machine learning in a function that meets the revised model definition is subject to the updated framework.

The bulletin's key provisions for AI and GenAI are:

The Expanded Model Definition

The most consequential technical change in 2026-13 is the expansion of the model definition to explicitly include AI and machine learning systems. The new definition covers "any quantitative method, system, or AI-driven approach, including machine learning models, large language models, and generative AI systems, that is used to support decisions or produce outputs with business, financial, regulatory, or compliance consequences." The phrase "AI-driven approach" and the specific mention of large language models and generative AI systems close the definitional escape route that some institutions had attempted to use.

This means: if your bank uses a generative AI tool to draft adverse-action notices, credit memos, SAR (Suspicious Activity Report) narratives, or customer communications, that tool is a model under the 2026-13 definition. It requires development documentation, validation, and ongoing oversight, just as a credit scoring model does. The fact that it produces text rather than numbers does not change its governance status.

Fair Lending as a Dimension of Model Risk

Perhaps the most significant governance change for credit-focused institutions is the explicit integration of fair-lending risk into the model-risk framework. OCC 2026-13 requires that model risk management programs for AI models used in credit decisioning specifically address:

  • Testing for disparate impact on protected classes under ECOA (Equal Credit Opportunity Act) and the Fair Housing Act, as part of the model validation process.
  • Documentation of the less-discriminatory alternative (LDA) search in the model's risk documentation.
  • Ongoing monitoring of the model's outcomes for fair-lending risk as part of the model's post-deployment performance monitoring.
  • Escalation procedures when model monitoring identifies emerging disparate impact concerns.

The practical consequence is that fair-lending testing is no longer solely a compliance function's responsibility. It is an element of model-risk governance, which means it falls under the model risk management program, is subject to independent model validation requirements, and is part of the reporting chain that goes up to the board. A compliance officer who conducts fair-lending testing but does not route the results through the model-risk governance structure is not satisfying the 2026-13 framework.

Third-Party and Vendor AI Models

OCC 2026-13 addresses the vendor opacity problem directly by establishing that the institution's model-risk management obligations extend to vendor-provided AI models. The institution cannot delegate its model-risk responsibilities to a vendor; it must conduct or obtain independent validation of any vendor AI model used in a model-risk-relevant function.

For models where the vendor does not provide access to the model's internals (architecture, weights, training data), the bulletin requires that the institution's validation approach address this opacity through alternative means: analysis of model outputs across a range of input scenarios, testing for disparate impact, performance monitoring against documented benchmarks, and contractual requirements for vendor transparency regarding material model changes.

The bulletin also introduces specific requirements for notifying the institution when a vendor changes its model materially. A vendor that silently retrains its AI model, changes its feature set, or alters its output logic must notify the institution, and the institution must reassess its model-risk documentation following any such change. An institution that does not have these notification requirements in its vendor contracts is already non-compliant with the spirit of the guidance.

Board Governance and Senior Management Expectations

OCC 2026-13 is explicit that model risk management is a board-level governance responsibility, not merely a technical or compliance function. The bulletin requires that:

  • The board of directors approve the institution's model risk management policy, including the policy's treatment of AI and GenAI models.
  • Senior management establish the institutional risk appetite for model risk, including specific parameters for AI model use in credit decisioning, customer communications, and compliance functions.
  • The board receive periodic reporting on the AI model inventory, model performance, model validation findings, and fair-lending monitoring results.
  • Management establish clear accountability for model outcomes. For AI models used in credit decisioning, this means someone owns every model in the inventory, is responsible for its validation and monitoring, and is accountable when the model produces unexpected outcomes.

A bank where AI models are deployed by technology teams without board-level visibility, without a documented model inventory, and without a clear accountability structure for model outcomes is non-compliant with OCC 2026-13, regardless of how well-intentioned or technically sophisticated the AI deployment may be.

The Model Inventory and Risk Rating

One of the most operationally significant requirements of the 2026-13 framework is the model inventory: a comprehensive register of every model (including AI and GenAI systems) that the institution uses, with documented risk ratings for each.

A model inventory entry for an AI credit decisioning system should include:

  • Model identification (name, version, owner, vendor if applicable).
  • Model description (purpose, function, inputs, outputs, users).
  • Risk rating (typically High, Medium, or Low based on the model's consequentiality, complexity, and uncertainty).
  • Validation status (when last validated, by whom, with what findings).
  • Fair-lending testing status (when last tested for disparate impact, results, LDA documentation).
  • Third-party management status (contract terms, vendor notification requirements, last vendor review).
  • Open findings and remediation timeline.

AI models used in credit decisioning will almost always be rated High risk under any reasonable risk-rating methodology, because their outputs have direct legal and financial consequences for applicants and the institution. A High-rated model requires more frequent validation, more rigorous monitoring, and direct reporting to senior management and the board.

The model inventory is not a static document. It must be updated when new models are deployed, when existing models are retrained or reconfigured, when validation findings are resolved or escalated, and when the fair-lending monitoring produces material results. An institution whose model inventory was last updated at deployment and has not been touched since has a governance gap that an examiner will note.

The Model Risk File: What to Have Ready

When a model-risk examiner reviews an AI credit model at your institution, they will ask to see a model risk file for that specific model. This file should contain, at minimum:

  • The model development documentation: how the model was built, what data it was trained on, what features it uses, and what the developer's documentation says about its theoretical basis and intended use.
  • The independent validation report: a report from a party independent of the model developer confirming the model was tested for accuracy, stability, and fitness for the intended purpose.
  • The fair-lending testing results: the disparate-impact analysis and LDA documentation, as described in the previous lesson.
  • The adverse-action reason-code validation: documentation that the model's explanation methodology has been tested for accuracy, as described in the ECOA lesson.
  • The ongoing monitoring results: the performance data tracked since deployment, including any material deviations from expected performance.
  • The override and exception logs: records of human overrides of the model's recommendations, with demographic analysis.
  • Open findings: any validation findings or monitoring findings that have not yet been remediated, with a documented remediation plan and timeline.

An institution that cannot produce this file for a deployed AI credit model does not merely have a documentation problem. It has a governance problem, because the absence of the file is evidence that the required processes did not occur.

GenAI-Specific Model Risk Considerations

OCC 2026-13 includes specific provisions for generative AI systems that distinguish them from traditional statistical models. These provisions address the specific risk characteristics of large language models that do not apply to conventional credit scoring models.

Hallucination risk documentation: The bulletin requires that institutions using GenAI in any function with regulatory or compliance consequences document their assessment of hallucination risk and the controls in place to mitigate it. For an AI system that drafts adverse-action notices, this means the model-risk file must describe how the institution detects and prevents the issuance of adversely incorrect reasons. For an AI system that extracts income figures from tax returns, the file must describe how the institution verifies the extracted figures against source documents.

Prompt governance: The bulletin introduces prompt governance as a model-risk consideration for GenAI systems. System prompts, prompt templates, and prompt configurations that materially affect the model's outputs are subject to change-control requirements equivalent to those for model configuration changes. An institution that allows individual users to modify system prompts without a change-control process has a model governance gap.

Output verification requirements: For GenAI models producing outputs used in regulated functions, the bulletin requires that the institution's model-risk framework address how the model's outputs are verified before use. This is the formal codification of the verification principle: AI-generated content used in credit decisions, adverse-action notices, regulatory filings, or customer communications must be verified by a human before it is acted upon. The model-risk framework must describe the verification controls, not just assume they are happening.

The accountability chain for GenAI outputs: The bulletin is explicit that an institution cannot disclaim responsibility for AI-generated outputs used in its operations. If a GenAI system drafts an adverse-action notice and that notice contains an inaccurate reason, the institution is responsible for the inaccuracy regardless of which vendor provided the AI system. The accountability chain runs through the institution's human decision-maker, not through the AI.

What 2026-13 Means Operationally for Working Bankers

For a loan officer, underwriter, or operations staff member reading this lesson, the most practically important aspect of OCC 2026-13 is how it changes the daily operating environment rather than the governance structure at the board level. The governance framework matters because it determines what oversight exists; what matters for daily operations is what the framework requires of the people who use AI every day.

Every AI tool is a governed model. If your institution has implemented OCC 2026-13 compliance, any AI tool you use in a credit-related function should appear in the model inventory, should have been validated, and should have an owner who is accountable for its performance. If you are using an AI tool that is not in the model inventory, that is itself a finding when discovered. The right response if you discover such a tool is to escalate to your model risk management team, not to continue using it quietly.

Human verification is now a documented control, not an assumed practice. The 2026-13 framework's requirement that verification controls be documented means that "of course the underwriter checks the AI's output" is no longer sufficient. There must be a documented workflow that specifies what is verified, by whom, and how, and that workflow must be followed. If you are using AI to draft documents and you are not following a documented verification workflow, you are not just missing a best practice; you may be operating outside your institution's model-risk compliance program.

Vendor changes require action. If your AI vendor updates its model, changes its outputs, or modifies its system prompts and does not notify your institution, that is a compliance gap. If your institution's contract with the vendor does not require notification, that is a procurement gap that needs to be closed. When a vendor does notify you of a material change, that change triggers a model-risk reassessment, not a simple acknowledgment.

Override documentation matters. Under 2026-13, human overrides of AI model recommendations in credit decisioning are subject to oversight requirements. When you override an AI model's recommendation, that override should be documented with the reason, and the aggregate override pattern should be analyzed periodically for fair-lending implications. This is not a bureaucratic requirement; it is the documentation that allows your institution to demonstrate that human judgment is actually operating in the credit process and that it is operating fairly.

Key Takeaways

  • OCC Bulletin 2026-13 was issued in April 2026 by the OCC, Federal Reserve, and FDIC as an interagency document. It superseded OCC Bulletin 2011-12 and explicitly pulls AI, machine learning, large language models, and generative AI systems under the model-risk management framework.
  • The expanded model definition covers any AI-driven approach used to support decisions or produce outputs with business, financial, regulatory, or compliance consequences. GenAI tools that draft adverse-action notices, credit memos, or SAR narratives are models under this definition and require development documentation, validation, and ongoing oversight.
  • OCC 2026-13 integrates fair-lending risk explicitly into the model-risk framework, requiring that disparate-impact testing and LDA documentation appear in the model's risk file, not just in the compliance department's files.
  • Vendor-provided AI models are within the institution's model-risk management scope. The institution must conduct or obtain independent validation of vendor models and must have contractual requirements for vendor notification of material model changes.
  • Board governance is required: the board must approve the model risk management policy, receive periodic reporting on AI model performance and fair-lending monitoring, and ensure clear accountability for model outcomes at the management level.
  • The model inventory is the operational center of the model-risk framework: it must be current, it must include every AI model in use, and it must document risk ratings, validation status, fair-lending testing status, and open findings for each model.
  • GenAI-specific provisions require documentation of hallucination risk and controls, prompt governance procedures, output verification requirements, and an explicit accountability chain for AI-generated outputs used in regulated functions.
  • For working bankers, 2026-13 means: every AI tool you use in a credit function should be in the model inventory, verification of AI outputs is a documented control, vendor changes trigger model-risk reassessments, and override documentation is part of fair-lending governance.