METHODOLOGY NOTES

Model risk management for AI: what SR 11-7 covers, and where the EU AI Act goes further

Banks have had model risk management frameworks since 2011. The EU AI Act adds obligations SR 11-7 does not cover. Here is the gap map — and what a unified audit looks like.

iDharma · July 23, 2026 · 6 min read
Model risk management for AI: what SR 11-7 covers, and where the EU AI Act goes further

US banks have operated under Model Risk Management guidance (SR 11-7) since 2011. Many are now treating that framework as their primary response to AI regulation. It is not sufficient — and regulators on both sides of the Atlantic are beginning to say so explicitly. Here is where SR 11-7 stops and the EU AI Act begins.

What SR 11-7 does well

SR 11-7 established three practices that remain best-in-class for model governance: independent model validation (the team validating the model must be separate from the team that built it), conceptual soundness review (the underlying assumptions and methodology must be documented and defensible), and ongoing performance monitoring with defined thresholds for model review and decommission.

These three practices directly address the most common failure mode in financial AI: models that perform well in development and drift in production without detection. Any financial services firm that has implemented SR 11-7 seriously — not just documented it — has a stronger baseline than most non-financial-services AI deployments.

Where SR 11-7 has gaps against the EU AI Act

Fundamental rights impact assessment. SR 11-7 requires model validation but does not require an assessment of the model's impact on fundamental rights — the EU AI Act does, for all high-risk systems. A bank deploying AI in credit decisions, lending, or any Annex III-listed application must conduct and document an impact assessment that goes beyond performance metrics to address potential discrimination, privacy implications, and systemic effects on affected populations.

Training data governance. SR 11-7 requires documentation of model inputs but does not mandate the level of training data governance the EU AI Act requires: documented data provenance, representativeness assessment, bias testing against the intended deployment population, and ongoing data quality monitoring. Many banks can document what data was used; fewer can document that the data was representative of the population the model will act on.

Transparency toward affected individuals. SR 11-7 is internally focused — it governs the bank's own model management. The EU AI Act requires transparency toward the individuals whose decisions the AI influences: the right to a meaningful explanation of automated decisions, notification that AI was used, and a right to human review of consequential outcomes. SR 11-7 has no analogue to these outward-facing obligations.

Conformity assessment before deployment. SR 11-7 requires validation before a model goes into production — the EU AI Act requires a formal conformity assessment against a specific checklist of Annex III obligations before deployment. These are related but different: SR 11-7 asks "does the model perform as intended?" The EU AI Act asks "does the deployment satisfy the legal requirements for high-risk AI systems?"

The unified audit approach

The most efficient path for a bank subject to both frameworks is a single audit that maps against SR 11-7, EU AI Act Annex III, and MiFID II (where trading or advisory AI is involved) simultaneously. The alternative — three separate reviews by three separate teams against three separate checklists — produces redundant documentation and typically misses the intersections where compliance gaps are most likely to occur.

In practice, a unified audit for a retail bank deploying AI in credit decisioning produces: a gap register organised by legal obligation (not by framework), a technical documentation package that satisfies both SR 11-7 and EU AI Act requirements in one set of documents, and a remediation roadmap ordered by legal priority — so you are addressing the obligations that create the greatest exposure first.

If you are a bank or financial services firm assessing your AI compliance position, the free Risk Snapshot gives you a starting-point exposure assessment. For a scoped audit engagement, contact us.

Wondering where your AI stands?