What does SR 11-7 require for AI agents and automated decision models?
SR 11-7, issued jointly by the Federal Reserve and OCC, defines a model as any quantitative method used to inform business decisions — which explicitly captures AI agents that evaluate credit, detect fraud, or drive underwriting. The guidance requires a three-pillar program: rigorous development and implementation controls, documented model use policies, and independent validation through effective challenge. For AI agents specifically, this means maintaining a model inventory of every agent in production, versioned documentation of how each agent makes decisions, and an audit trail demonstrating that governance controls were applied consistently at the point of access — not reconstructed after the fact.
How does SR 11-7 apply to AI agent deployments at banks and broker-dealers?
SR 11-7 applies to any Federal Reserve member bank, bank holding company, or OCC-supervised national bank. It covers all models in scope regardless of whether the model is vendor-supplied, internally built, or embedded in a third-party AI system. An AI agent that retrieves customer data, scores creditworthiness, or flags transactions for review qualifies as a model under the guidance. Banks deploying AI agents must inventory them, document intended use, validate them independently, and monitor ongoing performance. Examiners from the Fed and OCC review model risk management programs during safety and soundness examinations — deficiencies can result in MRAs (Matters Requiring Attention) and mandatory remediation timelines.
What is the effective challenge requirement under SR 11-7 and how does it apply to AI?
Effective challenge under SR 11-7 means independent, competent review of a model's conceptual soundness, data integrity, and ongoing performance — conducted by staff separate from those who built or operate the model. For AI agents, this requirement is operationally demanding: validators need a decision-level audit trail showing exactly which data the agent accessed, under which policy, at what sensitivity level, and what the governance outcome was. Without pre-retrieval enforcement logs, validators are forced to reconstruct evidence from application logs that may be incomplete or mutable. SR 11-7 expects tamper-evident documentation — not reconstructed records.
How does AutoPIL support SR 11-7 model inventory and validation requirements?
AutoPIL's agent registry functions as the model inventory SR 11-7 requires. Each AI agent is registered with a unique ID, assigned role, governing policy, and owner team — creating a discoverable record of every agent operating in production. The policy engine enforces access controls before data enters the agent's context window, and every decision is written to a cryptographic audit chain that cannot be retroactively altered. Policy YAML versioning provides the change-control record SR 11-7 expects when model assumptions or access rules change. Examiners and internal validators can query the audit log by agent, data source, sensitivity level, or time window without relying on application-layer logs.
What are the enforcement risks for banks that fail SR 11-7 model risk requirements for AI?
SR 11-7 is supervisory guidance, not a formal regulation with statutory penalties — but violations carry real enforcement consequences. Examiners who find gaps in model inventory, validation documentation, or governance controls issue Matters Requiring Attention (MRAs), which require a documented remediation plan with deadlines. Repeat or unresolved MRAs can escalate to Matters Requiring Immediate Attention (MRIAs) and formal enforcement actions, including consent orders. For banks expanding AI agent programs, an inadequate model risk management framework also creates CCAR and stress testing exposure, since models used in capital planning must meet SR 11-7 standards. Regulators have made clear that AI and ML models are in scope — not a future consideration.