US banking agencies replace model-risk guidance with risk-based supervisory framework
→Bank model-risk teams must remap governance, validation and vendor controls to the revised supervisory baseline
- → Model risk management teams at banking organizations with over $30 billion in assets must map existing model-development, validation, monitoring, governance and control practices against the revised risk-based supervisory guidance — unsafe or unsound practices or legal violations stemming from insufficient model-risk management can still trigger supervisory action.
- → Bank governance and control owners using vendor or third-party model products must document how those products are validated, monitored and controlled under the revised guidance — the agencies identify third-party products as part of the model-risk management framework.
- → Risk owners for generative and agentic AI models at banking organizations must keep those models outside the revised guidance scope and define separate governance and control coverage under internal risk-management practices — the agencies explicitly excluded those AI model types from this guidance.
Full decision brief
See the decision layer
Use 1 free preview to unlock implications, who’s affected, what to watch, and Clarify for this brief.
2 free previews left this month · Resets 1 Jun