How to Prepare for an OCC Exam on AI Model Governance
Extend your existing SR 11-7 model risk management program so it covers AI, machine learning, and agentic systems, and ensure you can produce ownership, testing, and runtime oversight evidence on demand.
Preparing for an OCC exam on AI model governance means extending an existing SR 11-7-based model risk management program, inventory, validation, monitoring, and audit trails, so it explicitly covers AI, machine learning, and agentic systems, and being able to produce ownership, testing, and runtime oversight evidence on demand.
Model risk pillars examiners assess
OCC reviews of model risk typically organize around four practical pillars. Making each of these explicit for AI and agentic systems is a useful preparation baseline.
- Model inventoryComplete, current listing of AI/ML models and agentic systems with ownership and risk tier.
- ValidationIndependent testing calibrated to AI-specific behavior such as drift and retraining.
- Ongoing monitoringPerformance and outcomes tracking with defined revalidation triggers.
- Audit trailReconstructable evidence of model version, configuration, and decision history.
What OCC examiners typically assess in AI model governance
OCC examinations of model risk have long been organized around the framework set out in SR 11-7 and OCC Bulletin 2011-12, which structures oversight around model development, independent validation, and governance with ongoing monitoring. When AI and machine learning models enter scope, examiners generally expect institutions to apply this same structure rather than build a separate, parallel process.
That means the model inventory should explicitly identify which entries are AI or ML systems, who owns them, what risk tier they carry, and what data sources feed them. Validation documentation should address how the institution tested the model before deployment and how it continues to test it in production. Governance committees should be able to demonstrate that their charter and reporting lines extend to AI systems, not only to traditional statistical or econometric models.
Institutions that treat AI governance as an add-on program, disconnected from established model risk management, tend to create gaps that are difficult to explain during an exam. The practical goal is a single, coherent inventory and control structure that examiners can walk through using the same questions they would ask about any other model.
Where agentic and autonomous systems complicate the framework
Traditional model risk guidance assumes a relatively bounded artifact: a model with defined inputs, outputs, and a validation cycle. Agentic AI systems, which plan, call tools, and take multi-step actions, do not fit that boundary cleanly. A single agent may orchestrate several underlying models, invoke external tools, and produce different execution paths depending on context.
This raises a practical question compliance teams need to resolve before an exam, not during one: where does the model inventory entry begin and end? Does it cover only the underlying language model, or does it also cover the orchestration logic, the tools the agent is permitted to call, and the actions it can take autonomously?
There is no published OCC position specific to agentic systems, so institutions should resolve this through their own risk tiering policy and be prepared to explain their reasoning to an examiner. What tends to matter most in practice is whether the institution can show it understood the full scope of what the system can do, documented that scope, and applied proportional controls and monitoring to it.
Governance structures that hold up under examination
- Extend, do not duplicate, existing governance. Bring AI and agentic systems under the same model risk committee and reporting structure used for other models rather than standing up a separate track.
- Define what counts as a model. Document the criteria the institution uses to decide when an AI component, such as an orchestration layer or supporting tool, is treated as a model for inventory purposes.
- Assign clear ownership. Map AI systems to accountable owners consistent with the institution's existing three-lines-of-defense structure so responsibility is not ambiguous during review.
- Address vendor and third-party AI explicitly. Confirm that third-party risk policy covers embedded model providers and API-based AI services, since these arrangements are common and frequently reviewed.
- Test readiness before the exam. Run an internal mock review against likely examiner questions to confirm documentation can be produced quickly and consistently.
Documentation compliance teams should have ready
- A model inventory entry for every AI, ML, or agentic system, including vendor-supplied components, with owner and risk tier
- Validation reports addressing AI-specific characteristics such as retraining cadence, data drift thresholds, and non-deterministic outputs
- Monitoring reports showing ongoing performance and outcomes review, not only pre-deployment testing
- Decision logs and version records sufficient to reconstruct model or agent configuration as of a specific past date
- Governance committee minutes or charters demonstrating explicit oversight scope over AI and agentic systems
- Third-party risk documentation covering embedded model providers or foundation model APIs used within the institution
Building audit-ready evidence for AI and agentic systems
Runtime controls as a practical evidence source
A recurring theme in model risk management, extended to AI systems, is that policy documentation alone is rarely sufficient. Examiners generally look for evidence that controls are operating, not just described. For agentic systems specifically, this often means being able to show what tools an agent was permitted to invoke, what permissions it held at a given point in time, and what actions it actually took.
Runtime governance capabilities that enforce least-privilege access for agents, log tool calls and decisions, and route higher-risk actions through approval workflows can produce exactly this type of evidence as a byproduct of normal operation, rather than requiring a separate manual reconstruction effort after the fact.
Trussed AI provides runtime governance and security for enterprise AI agents, including agent identity, permissions, tool approval workflows, and audit logging, which can support the kind of evidence trail described in this guide. Institutions evaluating how to close gaps in AI audit readiness should weigh whether their current logging and access control architecture can already answer these questions before considering additional tooling.
Prepare your AI governance program for examination
Review how your model inventory, validation process, and audit trails extend to AI and agentic systems before your next OCC exam.
Explore Runtime Governance