A Real‑World Scenario
On April 17, 2026, the Office of the Comptroller of the Currency released Bulletin 2026‑13, a joint revision of inter‑agency model risk management guidance. The bulletin rescinded earlier OCC handbooks and bulletins, then laid out a risk‑based framework that explicitly calls out the importance of data inputs across the model lifecycle. This scenario underscores why model data governance is critical for banks seeking to meet OCC expectations. Imagine a mid‑size national bank that recently deployed a predictive loss‑forecasting model for its commercial loan portfolio.
The model’s outputs drove capital allocation decisions, but during a routine OCC examination the examiners uncovered that the data feed feeding the model contained stale credit‑risk scores for a subset of borrowers. Because the bank had not instituted continuous validation of those inputs, the model’s predictions drifted, leading to an under‑allocation of reserves and a supervisory finding that the bank failed to meet prudent model risk standards.
The bank now faces a corrective action plan that demands a comprehensive overhaul of its data‑input governance – a costly and time‑consuming effort that could have been avoided with stronger controls. A robust model data governance program would have identified the stale feed before it impacted capital decisions.
Beyond this single case, the bulletin notes that banks must document data lineage, maintain versioned data dictionaries, and perform periodic re‑validation of source feeds. Failure to do so can trigger supervisory criticism, raise capital buffers, or result in enforcement actions. The guidance therefore elevates model data governance from a best‑practice consideration to a regulatory expectation.
Additional insight: The OCC also expects banks to conduct periodic stress‑testing of data‑input changes, ensuring that any alteration to source systems does not unintentionally degrade model performance. This adds a layer of resilience that many institutions currently overlook.
The Problem: Model Data Governance
Current model risk frameworks often treat data inputs as a peripheral concern, relegating them to ad‑hoc checks or relying on legacy data‑quality routines. In practice, banks operate fragmented data pipelines, with multiple legacy systems, third‑party vendors, and emerging AI‑driven workloads feeding the same model. When data lineage is unclear, a single erroneous feed can cascade through risk calculations, inflating or deflating exposure metrics without detection.
The OCC’s bulletin emphasizes that “practices appropriate for one organization may be ineffective for another” and warns that “generative AI models are not within the scope of this guidance,” underscoring how rapidly evolving data sources can outpace traditional controls. The bulletin also requires banks to maintain a data‑input inventory, track changes to source schemas, and document any manual data transformations.
The stakes are high. Regulatory examinations that surface data‑input deficiencies can trigger supervisory criticism, raise capital buffers, and even result in enforcement actions. Moreover, inaccurate inputs erode the credibility of risk dashboards relied upon by senior executives, potentially prompting misguided strategic decisions. As banks scale their use of AI‑enhanced analytics, the frequency and complexity of data‑input failures will only increase, making a proactive, governance‑first approach essential.
A typical failure mode involves a third‑party data vendor updating its scoring algorithm without notifying the bank. Without an automated alert, the bank’s model continues to consume the new scores, which may be calibrated to a different risk horizon. The resulting drift can remain hidden for months, only surfacing when a regulator asks for a justification of reserve levels. To mitigate this, banks should embed contractual clauses that require vendors to provide advance notice of any scoring methodology changes and automatically ingest those notices into the governance platform.
Further depth: Emerging cloud‑based data lakes introduce additional risk vectors, such as inconsistent metadata tagging and latency‑induced data staleness. Effective model data governance must therefore extend to cloud storage policies, ensuring that data freshness thresholds are enforced at the storage layer.
The CoComply Approach
CoComply addresses the data‑input gap by embedding continuous data provenance, metadata enrichment, and AI‑assisted validation into every stage of the model lifecycle. First, CoComply automatically captures lineage from source systems to model features, creating an immutable audit trail that satisfies OCC expectations for “transparent governance.” The platform records the origin of each data element, timestamps of ingestion, and any transformation logic applied, allowing auditors to trace a model output back to the raw source.
Second, the platform employs AI agents to monitor input streams in real time, flagging anomalies such as stale credit scores, format mismatches, or unexpected statistical shifts. These agents compare incoming data against historical baselines, detect outliers, and raise alerts when thresholds are breached. For example, if a credit‑risk score has not been refreshed for more than 30 days, the system generates a warning and can automatically pause model execution until the data is refreshed.
When an issue is detected, CoComply triggers automated remediation workflows that can pause model execution, request fresh data, or alert data‑stewards for manual review. The workflow engine integrates with existing ticketing systems, ensuring that the right owners are notified and that remediation steps are documented. Third, CoComply’s certification engine ties these controls to the bank’s overall risk‑management framework, generating evidence bundles that can be presented directly to examiners, reducing the burden of manual documentation.
By turning data‑input governance into a live, auditable process rather than a periodic checklist, CoComply helps banks meet the OCC’s revised expectations without sacrificing agility. The platform also supports scenario testing, allowing banks to simulate the impact of a data feed change on model outputs before the change is deployed to production. This proactive capability reduces the likelihood of surprise findings during examinations. Additionally, CoComply provides a governance health dashboard that aggregates data‑input risk scores across the enterprise, giving senior leadership a single‑pane‑of‑glass view of compliance posture.
Extended capability: CoComply can integrate with third‑party data vendor APIs to automatically ingest change logs, ensuring that any upstream modifications are immediately reflected in the bank’s data‑input inventory.
Closing Insight
The OCC’s 2026 guidance makes it unmistakable: data inputs are the new front line of model risk. Banks that treat model data governance as a static, after‑the‑fact task will find themselves scrambling to remediate findings and protect capital. Those that adopt a continuous, AI‑enhanced approach, like CoComply, will not only satisfy regulators but also gain more reliable risk insights, enabling smarter decision‑making in an increasingly data‑driven landscape. Robust model data governance is therefore the cornerstone of sustainable compliance and operational resilience.
Source: OCC Bulletin 2026‑13 – Model Risk Management: Revised Guidance
Tags: Model Risk Management, Data Governance, Bank Compliance
