AI Model Risk Management: Bridging SR 11-7 and the EU AI Act

For the past decade, SR 11-7 — the Federal Reserve's supervisory guidance on model risk management — has been the defining framework for model governance at US bank holding companies. It introduced concepts of model risk, model validation, and model inventory that financial institutions worldwide have adopted as best practice. Now, with the EU AI Act imposing its own set of requirements on AI systems deployed in the EU market, financial institutions face the challenge of operating under two overlapping but non-identical frameworks simultaneously.

What SR 11-7 Requires

SR 11-7 defines a model broadly as any quantitative method that applies statistical, economic, financial, or mathematical theories to transform input data into quantitative estimates. It requires that models be subject to: sound development and implementation practices, robust model validation by parties independent of development, governance and oversight through model risk management policies and an inventory, and ongoing monitoring to identify performance issues and changes in operating environment.

For AI and machine learning models, SR 11-7's principles remain applicable — but banks have had to develop new validation methodologies suited to the opacity and complexity of ML models. Regulators including the OCC, FDIC, and Fed have issued supplemental guidance making explicit that SR 11-7 applies to AI models.

Where EU AI Act Requirements Differ

The EU AI Act shares SR 11-7's emphasis on documentation, validation, and oversight — but it introduces requirements that most SR 11-7 implementations do not currently address.

Automatic decision logging (Article 12): SR 11-7 does not mandate that models automatically generate tamper-evident logs of each individual decision. Financial institutions typically have decision records in their core systems, but these are often modifiable by administrators and are not maintained with cryptographic integrity protection. The EU AI Act requires that high-risk AI systems generate logs automatically and that those logs enable post-hoc monitoring — a more demanding standard than SR 11-7's monitoring requirements.

Individual right to explanation: SR 11-7 focuses on institutional validation and oversight. The EU AI Act, combined with GDPR Article 22, gives individuals affected by automated decisions the right to obtain an explanation. This requires that AI systems be designed to generate individual-level explanations, not just aggregate performance metrics.

Conformity assessment before market placement: The EU AI Act requires that high-risk AI systems undergo conformity assessment before being placed on the EU market. SR 11-7 requires validation before deployment, but the EU AI Act's conformity assessment has specific documentation requirements and may require third-party involvement for certain system categories.

What Aligns Between the Frameworks

The good news for institutions with mature SR 11-7 programmes is that the foundations align well. Both frameworks require: comprehensive model/AI system inventory, independent validation, documentation of development process and assumptions, ongoing monitoring of model performance, and defined governance structures with clear accountability. Institutions that have invested in SR 11-7 compliance have built the governance infrastructure on which EU AI Act compliance can be constructed.

Bridging the Gap in Practice

The practical path forward for most financial institutions is to treat the EU AI Act as an extension layer on top of existing SR 11-7 programmes, rather than a separate compliance exercise. Extend the model inventory to capture EU AI Act classification (high-risk, limited risk, minimal risk) alongside existing SR 11-7 model tiers. Extend validation documentation to cover EU AI Act Article 11 technical documentation requirements. And — most significantly — implement automatic, tamper-evident decision logging for AI systems classified as high-risk under the EU AI Act, where current logging practices fall short of Article 12 requirements.

Build the audit trail the EU AI Act demands

Provara gives enterprise teams tamper-proof AI decision logs, real-time compliance dashboards, and evidence that holds up under regulatory scrutiny.

Request a demo →