Sector
Banking & capital markets
Where model risk management meets systems that act.
Federal Reserve SR 11-7 / OCC 2011-12
Internal audit & effective challenge
Operational resilience
Internal audit & effective challenge
Operational resilience
The problem in one sentence
SR 11-7 was written in 2011 for models that score and predict. Your agents act. The guidance did not change — the exposure did.
Where it breaks
| Failure point | What actually happens |
|---|---|
| Inventory | Is an agent a model, an application, or forty models in a trench coat? Most MRM inventories cannot represent a system that chains tools, prompts and sub-models at runtime. |
| Validation | You validated the model. Did you validate the agent's authority? A well-scored model wrapped in an agent that can act outside its grant is a governance failure with excellent metrics. |
| Effective challenge | Challenge assumes the reviewer can reconstruct the decision. If the agent's context is gone, so is the evidence. |
| Monitoring | Model performance drifts slowly. Agent behaviour changes the day a provider ships a new version — with no code change and often no revalidation trigger. |
Next step
If any of this is live for you
The fastest route is a conversation. Bring the architecture you are worried about — the first useful thing usually surfaces inside twenty minutes.