Model Governance for AI Fraud Systems: Building the Audit Trail That Regulators Now Demand

Model governance for AI fraud systems is no longer a best-practice recommendation. In 2026, it is a binding regulatory requirement, enforced by the Federal Reserve, the OCC, the UK Prudential Regulation Authority, and from August 2026, the EU AI Act. The question for CROs and Model Risk Officers is not whether to build an audit trail for AI fraud models. It is whether the audit trail you currently have would satisfy an examiner who walked through the door today. For most institutions, the honest answer requires careful scrutiny.
What Changed in April 2026: SR 11-7 Is Gone SR 26-2 Is Here
On 17 April 2026, the Federal Reserve, OCC, and FDIC jointly issued SR 26-2 Revised Guidance on Model Risk Management, superseding SR 11-7 in its entirety. This is the most significant update to the US model risk management framework in fifteen years, incorporating supervisory experience accumulated since 2011 and addressing the realities of modern AI and machine learning in financial services.
The revised guidance applies to banking organisations with over $30 billion in total assets and emphasises a risk-based approach to model risk management one that is tailored to the institution's specific model risk profile rather than applying a uniform standard across all models. For fraud detection AI, this means the depth of documentation, validation, and oversight required scales with the consequences the model's outputs can produce.
CRITICAL UPDATE FROM SR 26-2: SR 26-2 simultaneously supersedes SR 21-8 the Interagency Statement on Model Risk Management for BSA/AML compliance systems. This means the same updated framework now governs both fraud detection AI and AML transaction monitoring models. Institutions that maintained separate governance approaches for fraud and AML models under the old guidance must now assess whether a unified framework better reflects the risk-based expectations of the new standard.
What SS1/23 Requires From AI Fraud Models Right Now
In the UK, the PRA's Supervisory Statement SS1/23 Model Risk Management Principles for Banks has been in effect since May 2024. The PRA's Business Plan 2025/26 confirms it is actively assessing how banks are embedding these principles in practice not just on paper, and that the 2025/26 supervisory cycle includes direct firm-level engagement on SS1/23 implementation.
At CRO roundtables held in October 2025 with 21 PRA-regulated firms, the PRA identified specific challenges with AI and ML model governance: AI models introduce higher uncertainty than traditional models due to their opaque nature and the lack of transparency compared to conventional approaches. The PRA's expectation from SS1/23 is that firms establish a model risk appetite articulating the level and types of model risk they are willing to accept before deploying AI and ML not after deployment, when the model is already in production and influencing fraud decisions.
5 core principles: Bank of England SS1/23 bankofengland.co.uk govern MRM under SS1/23: model identification and classification, governance and ownership, model development and implementation, model validation, and model use. All five apply to AI fraud detection models. The PRA held dedicated AI/ML roundtables in October 2025 to assess firm-level compliance gaps confirming active supervisory scrutiny.
What the EU AI Act Adds on Top
For institutions with EU operations, the EU AI Act layers additional requirements onto whatever the Federal Reserve and PRA already demand. Fraud detection AI that profiles natural persons is likely high-risk under Article 6(3) triggering Article 13 transparency requirements, Article 9 risk management system obligations, and Article 61 post-market monitoring duties, all active from August 2026. We covered the full classification and compliance checklist in our earlier blog on the EU AI Act compliance deadline for fraud teams.
The EU AI Act's Article 13 requires high-risk AI systems to be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret the system's output and use it appropriately. For fraud AI, this is the explainability requirement, and it operates independently of, and in addition to, whatever documentation the Federal Reserve or PRA require.
THE EXPLAINABILITY GAP: ACFE's 2024 anti-fraud technology research confirmed that 82% of organisations identify explainability as important in AI fraud models, but only 6% feel completely confident explaining how their AI fraud model makes decisions. That gap between stated importance and actual capability is precisely what SR 26-2, SS1/23, and the EU AI Act are each designed to close, from three different regulatory directions simultaneously.
Conclusion
The regulatory conversation around AI has changed fundamentally.
The question is no longer whether AI fraud models improve detection accuracy. It is whether institutions can explain, govern, validate and continuously monitor those models in a way that satisfies regulators, auditors and executive stakeholders. SR 26-2, SS1/23 and the EU AI Act all arrive at the same destination from different regulatory paths. AI fraud systems must now be treated as governed business assets not simply analytical tools.
Institutions that build governance into their AI lifecycle today will be better positioned for regulatory scrutiny, stronger operational resilience and greater confidence in automated fraud decision-making. In 2026, competitive advantage will not come from deploying more AI. It will come from governing AI better.