AI Model Risk Management for Banks: SR 11-7 Compliance
SR 11-7 was written for credit and market risk models, but regulators now apply its principles to AI and LLM systems, and exam questions are getting specific: How is the model validated? How is ongoing performance monitored? Where is the documentation? Trussed AI helps banks extend model risk management (MRM) discipline to AI, copilots, and agents, with runtime enforcement, continuous monitoring, and exam-ready evidence generated automatically.
What does SR 11-7 require for AI models?
SR 11-7 (the Federal Reserve and OCC's supervisory guidance on model risk management) requires effective challenge across the model lifecycle: sound development and documentation, independent validation, ongoing monitoring, and governance with clear accountability. Applied to AI and LLMs, that means documented model inventory, controlled deployment, continuous behavioral monitoring, and traceable records of every consequential model decision.
Why LLMs strain traditional MRM programs
- Opacity: third-party foundation models can't be validated like in-house credit models
- Drift by vendor update: model behavior changes without a new version entering your inventory process
- Volume: thousands of daily inferences vs. periodic batch model runs, monitoring must be continuous
- Agentic behavior: models that act (tool calls, data access) create risks validation alone can't cover
How Trussed AI supports SR 11-7 alignment
- AI Control Plane, enforce policies in real time across AI models, applications, and agents, with centralized controls, monitoring, and regulator-ready records.
- Audit Assurance, continuous evidence with complete traces, policy decisions, model versions, timestamps, and lineage, supporting internal audit, validation teams, and examinations.
- Risk Monitoring, ongoing visibility into usage, policy exceptions, and performance, enabling the continuous monitoring SR 11-7 expects.
- Agent Governance, execution-layer controls so agentic AI actions are evaluated against policy before they occur in banking environments.
- Governance Advisory, map MRM frameworks to AI-specific controls, approval workflows, and accountability structures.
- Cost Governance, connect model usage to business outcomes with spend attribution and thresholds.
Why banks choose Trussed AI
Examiners increasingly distinguish between banks that describe AI controls and banks that can demonstrate them. Trussed produces the demonstration automatically: every governed interaction generates evidence of policy enforcement, model version, and outcome, deployed as a drop-in proxy with no changes to banking applications and sub-20ms latency.
Frequently Asked Questions
Does SR 11-7 actually apply to LLMs and GenAI? Regulators have signaled that MRM principles extend to AI systems used in decisioning and operations. Banks are expected to inventory, validate where feasible, monitor, and document AI models, including third-party LLMs.
How does Trussed help with model inventory? The control plane observes which models and versions are actually in use across applications and agents, turning inventory from a self-reported spreadsheet into measured fact.
Can validation teams use Trussed's records? Yes. Complete traces with model versions, inputs, outputs, and policy results give validators and internal audit the raw material for effective challenge.
Related resources
Ready to govern your AI in production?