Blog

SR 26-2 Changes Model Risk Management. EUC Governance Needs to Change With It.

August 19, 2026

The banking industry has spent the better part of fifteen years building model risk management programs around SR 11-7. Earlier this year, the Federal Reserve, OCC and FDIC issued revised guidance, with the Federal Reserve publishing it as SR 26-2. The new guidance supersedes SR 11-7 and puts greater emphasis on a simple principle: risk management should be commensurate with the actual risk a model creates.

That sounds straightforward, but in practice, it requires banks to understand their risk environment much better than they have in the past. And that environment extends well beyond the formal model inventory.

Across every large financial institution are thousands—or potentially hundreds of thousands—of spreadsheets, analytical applications, databases, scripts, workflow tools and other end-user computing applications that support important business decisions. That is why EUC governance should increasingly be viewed as part of the infrastructure supporting effective model risk management.

SR 26-2 Is About Understanding Risk, Not Checking Boxes

 

One of the most important aspects of SR 26-2 is its emphasis on proportionality. The guidance recognizes that models do not all represent the same level of risk. It points institutions toward factors such as inherent risk, exposure, purpose and use, with more comprehensive oversight appropriate for models with greater materiality.

That same logic should apply to the technology surrounding those models. A spreadsheet used for an inconsequential internal calculation should not receive the same scrutiny as an EUC that adjusts a regulatory capital calculation, manipulates inputs to a material model or provides information used in a significant financial decision.

The challenge is knowing which is which. Traditional EUC programs have often struggled with exactly that problem. They depend heavily on self-identification, questionnaires, periodic attestations and manual inventories. Those approaches can tell management what people say exists. They do not necessarily tell management what actually exists and an AI-enabled EUC governance program can change that.

You Cannot Govern What You Cannot See

 

SR 26-2 specifically discusses maintaining sufficient information about models to understand risk at both the individual and aggregate level. It also emphasizes documentation, monitoring, controls, and clearly defined accountability throughout the model lifecycle. Those principles become difficult to execute when critical processes extend into uncontrolled or poorly understood EUCs.

Consider a formally governed model whose outputs are exported into Excel. The model itself may be validated, documented and monitored. But what happens next? A user may add assumptions. Formulas may be modified. Data may be copied between workbooks. Macros may automate calculations. External links may pull information from other sources. Results may eventually flow into financial reporting, risk management or management decision-making. The model may be controlled, but the process may not be. This is where AI can fundamentally improve EUC governance. CIMCON’s AI-enabled governance capabilities can not only help identify and assess these risks, but also summarize the detailed audit trails and risk assessments generated by governed EUCs. While automated audit trails and risk assessments are already a major improvement over manual processes, they can still contain substantial volumes of data. AI can distill that information into concise, actionable summaries that highlight material changes, key risk indicators, exceptions and areas requiring attention—helping risk teams focus on what matters most. Instead of asking employees to identify every important spreadsheet manually, modern governance technology can help organizations discover EUCs, analyze their characteristics, identify relationships, classify their potential risk and focus human attention where it matters most. That is exactly the direction a risk-based governance program should be moving.

AI Should Make Governance More Intelligent, Not More Complicated

 

There is an important distinction in SR 26-2. The agencies explicitly state that generative AI and agentic AI models are not within the scope of the revised guidance because they are novel and rapidly evolving. At the same time, they make clear that an institution’s risk-management and governance practices should guide appropriate governance and controls for tools, processes and systems that are outside the document’s scope. The guidance continues to apply to traditional statistical and quantitative models as well as non-generative, non-agentic AI models.

That distinction matters. Banks should not interpret the exclusion of generative AI as an invitation to ignore it. Nor should every application of AI automatically be forced into a traditional model governance framework. The better approach is to apply sound governance principles according to risk. And AI itself can help institutions do that at scale.

AI can assist in identifying potentially critical EUCs, detecting unusual changes, analyzing dependencies and directing risk teams toward applications that warrant deeper review. Instead of adding another layer of bureaucracy, AI can help reduce the enormous amount of manual work involved in maintaining an effective governance program.

The objective should not be more governance. It should be better governance.

The Model Inventory Is Only Part of the Picture

 

SR 26-2 states that an effective model inventory should contain enough information to support understanding of model risk individually and in aggregate. For large financial institutions, I would take that thinking one step further. Management should also understand the ecosystem surrounding its most important models, answering questions like:

  • What applications provide their inputs?
  • Where do their outputs go?
  • Which spreadsheets perform subsequent calculations?
  • Which EUCs are relied upon for reporting?
  • Who changed them?
  • What changed?
  • Which applications are interconnected?
  • Which ones could materially affect the institution if they fail?

Those questions are becoming increasingly important as financial institutions adopt more automation, citizen development, analytics and AI. A model does not operate in isolation. Neither should its governance.

The Opportunity

 

SR 26-2 should not simply cause banks to rewrite their SR 11-7 policies. It should cause them to reconsider how model risk is actually managed. The technology available today allows institutions to move away from static inventories, periodic attestations and manual reviews toward continuous, risk-based governance.

AI-enabled EUC governance can provide greater visibility into the applications surrounding critical models, identify changes faster, prioritize the EUCs that represent the greatest risk and give management a much clearer view of how risk moves through the organization.

Financial institutions naturally are going to use more models, more automation, and more AI. SR 26-2 recognizes that technology and modeling practices have evolved significantly since SR 11-7 was issued in 2011. In order for institutions to succeed they must find what matters, understand why it matters, and apply the right controls based on the risk, and this is where AI-enabled EUC governance becomes essential.

How CIMCON Can Help

 

CIMCON can help financial institutions operationalize the risk-based principles emphasized in SR 26-2 by providing greater visibility, automation, and control across the EUC environment surrounding critical models and business processes. EUC Insight’s Discovery capabilities can continuously scan the enterprise to identify spreadsheets and other end-user applications, analyze their characteristics and dependencies, and help determine which applications warrant for further review. CIMCON’s automated risk assessment capabilities can then apply configurable criteria to help classify EUCs based on factors such as complexity, materiality, business use, dependencies, and potential impact, allowing institutions to focus governance resources where the risk is greatest rather than treating every EUC the same. Once identified and assessed, higher-risk EUCs can be brought into a centralized Inventory with defined ownership, documentation, controls, attestations, and approval workflows, while Change Management provides ongoing monitoring of modifications to formulas, values, macros, external links, and other critical elements. CIMCON’s AI capabilities further strengthen this process by helping identify EUC candidates, automatically update inventory records, review risk assessment information while summarizing for quicker human consumption, summarize complex spreadsheets, and analyze audit trails and risk assessments to surface material changes, exceptions, and potential control gaps. Together, these capabilities enable institutions to move from static, manually maintained inventories toward a more continuous, risk-based governance framework that supports the visibility, proportionality, documentation, monitoring, and accountability objectives at the heart of SR 26-2.

AI Risk Management Policy

AI Policy
Explore the realm of Artificial Intelligence (AI) with our AI Risk Management Policy. This concise guide covers the spectrum of AI models, including supervised, unsupervised, and deep learning, and emphasizes making AI trustworthy based on the NIST AI Risk Management Framework. Learn to assess and manage AI Risk, cultivate a culture of risk awareness, and utilize periodic testing with tools like ours. This policy is your essential toolkit for responsible and effective AI utilization in your organization.