Reese Orman
Manager
Chase Fingerson
Senior Regulatory Compliance Associate
Karen Leiter
Principal

The use of models within banks continues to grow in complexity and scope since the first model risk management (MRM) guidance was issued in 2011 by the Federal Reserve and Office of the Comptroller of the Currency (OCC). Over the last 15 years, advances in technology along with increased competition have driven banks to leverage innovative approaches to help improve efficiencies, better mitigate risks and boost profits.

The Fed, OCC and Federal Deposit Insurance Corp. (FDIC) recently released supervisory guidance on MRM in April 2026, rescinding prior guidance.

Key Changes and Overview
The 2026 guidance represents a clear evolution from the 2011 framework. It shifts expectations away from a uniform, control-heavy compliance approach to a risk-based approach scaling model governance, validation and oversight with the model’s materiality and business impact.

The 2026 version preserves the core expectation that model risk be identified, challenged, validated, monitored and governed, but it provides greater flexibility in how banks can demonstrate effective oversight, particularly for lower-risk or less critical models.

It also significantly strengthens expectations around governance and ongoing oversight of third-party and vendor models, aligning MRM more closely with third-party risk management.

Key Takeaways From 2026 Guidance and Discussions With Regulators

  • The underlying model risk management expectations haven’t changed.
  • Banks should conduct periodic validations and oversight on models to operate in a safe and sound manner. This would be considered sound banking practice in an examiner’s mind.
  • The recission of the prior guidance removes any inconsistencies to better align with the current risk-based regulatory approach over uniform programs.
  • If a bank chooses not to validate a low-materiality model, it should have supporting risk management and documentation in place. Otherwise, regulators will likely recommend validation commensurate with the model’s materiality as a sound banking practice.
  • Banks remain responsible for validating third-party and vendor models, with ongoing internal monitoring and outcome analysis expected.
  • MRM won’t be governed by regulators; it is the responsibility of bank management.

Impact on AML automated systems
Anti-money laundering (AML) transaction monitoring, alert scoring and customer risk rating systems are now treated consistently with other highly material models, such as credit and market models, and must be included in formal model inventories and lifecycle management processes.

While the guidance narrows the technical definition of a model, most AML systems would still qualify due to their application of statistical formulas that result in the output of quantitative estimates. Banks should carefully document classification decisions and maintain appropriate oversight.

At the same time, the guidance shifts to a non-prescriptive approach, providing flexibility in validation frequency, documentation and controls. This places greater responsibility on banks to demonstrate effectiveness and provide risk-based justification of current MRM practices.

Impact on Current Expected Credit Losses
The new MRM guidance removes the long-standing expectation that current expected credit losses (CECL) models must be fully validated on an annual basis. Instead, the new framework allows community banks to scale both the frequency and depth of validation activities based on actual risk.

This means higher-risk or more complex models may still warrant robust and more frequent validation, while simpler or more stable models can be reviewed less frequently. As a result, bank leadership is afforded greater flexibility to align validation efforts with risk exposure, helping reduce unnecessary cost and operational burden while still maintaining strong and effective oversight where it matters.

At the same time, the guidance highlights that flexibility doesn’t eliminate the need for responsiveness to change. If significant events occur — such as shifts in portfolio composition, changes in economic conditions, updates to model methodology or modifications to processes affecting the allowance — a targeted validation would still be expected.

This helps keep CECL models appropriate, reliable and well-aligned with the bank’s current risk profile and financial reporting objectives.

On the Horizon
While the 2026 guidance was partially released to keep up with the advancement of model complexity and technology in the banking industry, it explicitly called out that generative and agentic artificial intelligence (AI) models aren’t within the scope of the guidance due to their novelty and rapidly evolving nature.

The latest March 2026 FDIC testimony reinforces that banks are encouraged to adopt innovation, including AI and fintech partnerships without unnecessary supervisory friction when risks are well governed.

With many third-party providers in the AML space currently working on integrating more AI analytics into their models, banks should be on the lookout for more guidance on this topic in the future.

Overall, the 2026 supervisory guidance on MRM emphasizes a proportionate approach that shifts expectations to a risk-based approach, scaling model governance, validation and oversight with the model’s materiality and business impact.


The information contained herein is general in nature and is not intended, and should not be construed, as legal, accounting, investment, or tax advice or opinion provided by CliftonLarsonAllen LLP (CLA) to the reader. For more information, visit CLAconnect.com.

CLA exists to create opportunities for our clients, our people, and our communities through our industry-focused wealth advisory, digital, audit, tax, consulting, and outsourcing services. CLA (CliftonLarsonAllen LLP) is an independent network member of CLA Global. See CLAglobal.com/disclaimer. Securities and investment advisory services are offered through CliftonLarsonAllen Wealth Advisors, LLC, an SEC-registered investment advisor, member FINRA/SIPC.

WRITTEN BY

Reese Orman

Manager

Reese is a Manager in CLA’s Financial Services group, serving clients in the community banking and equipment finance industries. He specializes in financial statement audits, integrated audits, and reviews performed in accordance with AICPA and PCAOB standards. Reese also has extensive consulting experience, including CECL validations, ALM validations, and loan credit quality reviews. In addition to his audit responsibilities, he serves as Chair of the Financial Services Advisory Committee and helps lead CLA’s national CECL Validation practice.

WRITTEN BY

Chase Fingerson

Senior Regulatory Compliance Associate

Chase Fingerson is a senior regulatory compliance associate with CLA. He works with banks and credit unions nationwide, conducting regulatory compliance engagements and other consulting services. Chase joined the Financial Services Group at CLA full-time in 2023 after interning with the firm during his junior year at the University of Minnesota.

WRITTEN BY

Karen Leiter

Principal

Karen Leiter is a Principal with CLA. She works with banks and credit unions nationwide, managing regulatory compliance engagements and other consulting services.  Karen joined the Financial Services Group at CLA in 2020 after working in financial institutions since 2004. She has spent the majority of that time focused on regulatory compliance, Bank Secrecy Act (BSA) compliance and bank operations. Karen has spent her career working at a mortgage broker, local community bank and a larger regional bank.