Agentic AI Model Risk Management for Banks — SR 11-7 / OCC 2011-12
Kriv AI · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
**SR 11-7 was written in 2011 for GLMs and scorecards. Multi-step agents with tool use break the taxonomy — and bank MRM teams, Internal Audit, and the Board Risk Committee need a new framework before the next OCC / FRB / FDIC / NYDFS exam cycle.**
US bank MRM is defined by **SR 11-7** + **OCC 2011-12**, with **FDIC FIL 22-2017** for state non-member banks, **OCC 12 CFR Part 30 App D** Heightened Standards ($50B+), **SR 15-18** effective challenge, **SR 17-3** for complex BHCs, **NYDFS 23 NYCRR Part 500** AI scope, **CFPB** Reg B / ECOA / FCRA / TILA, **OCC Bulletin 2023-17** third-party AI. International parallels: **PRA SS1/23**, **ECB TRIM**, **BaFin MaRisk + BAIT**.
Show the rest of the publisher’s description (8 more lines)
SR 11-7's "model" definition reaches LLM-driven agents, planner/tool-use loops, and retrieval-augmented decisioning. Most banks have 500–5,000 registered traditional models; the agentic wave adds 50–500 more, and traditional tiering and validation patterns do not fit. **Multi-step agents with tool use fail traditional effective challenge.** MRA / MRIA findings citing "AI governance gap" are appearing in OCC / FRB / FDIC / NYDFS exams through 2025–2026. Stakes are clear: TD Bank $3B CMP (Oct 2024), Binance $4.3B (Nov 2023).
Existing AWS Marketplace listings don't close this gap. IBM watsonx.governance + ModelOp Center sell platforms. Credo AI sells a registry. Adastra + NorthBay sell agentic build/deploy. Big-4 bank MRM (Deloitte, PwC, EY, KPMG, Oliver Wyman, Promontory, Protiviti) run **$200K–$1.5M+** off-Marketplace. DataRobot, Arthur AI, Fiddler AI, ModelOp sell platforms at $100K–$500K+/yr. **N24 is the first fixed-fee, transparent, agentic-AI-specific MRM framework on AWS Marketplace from a vendor with Anthropic CPN + Claude Agent SDK + LangGraph + Bedrock Agents fluency.**
Deliverable is **document + process + tooling** — not a platform, not an implementation. Methodology leverages **N14 AML/KYC**, **N13 P&C Underwriting**, **N17 Trade Surveillance**, **N18 Claude Code Training Banking & FS**, and Anthropic CPN agent-pattern depth.
**Methodology.** Inventory → Tiering → Validation → Monitoring → Retirement lifecycle for agentic AI, covering cross-BU agent inventories (sanctioned, shadow, vendor), agent taxonomy (single-step, multi-step, autonomous, HITL), and T1–T4 risk tiering based on tool use, autonomy, and auditability. Includes effective challenge testing (prompt injection, decomposition quality, counterfactual replay), champion–challenger setup, and agent-aware Model Cards integrated with SageMaker Model Registry and MLflow. Ongoing monitoring via SageMaker + Bedrock (drift, hallucination, tool-use anomalies, intervention trends), plus Governance Committee charter and examiner Q&A pack.
**Week-by-week (6 weeks).** W1 Discovery + inventory + CRO/MRM/CCO workshops + regulatory citation map. W2 Taxonomy + T1–T4 Tiering. W3 Validation Design (effective-challenge; champion-challenger; Model Card templates; Registry integration). W4 Monitoring spec + SageMaker + Bedrock integration + IR. W5 Governance (charter; RACI; Board reporting; examiner Q&A). W6 Finalization + executive readout + Board briefing + handoff.
**Three tiers.** Foundation $40K (single BU; up to 10 agents) for community banks $500M–$10B, mid-tier first-pilots, fintech BaaS. Standard $65K (enterprise-wide; up to 30 agents; full SR 11-7 + OCC 2011-12 + FDIC FIL 22-2017 + NYDFS 500; examiner Q&A; Board briefing; 90-day adoption) for mid-tier $10B–$100B, large-tier, BDs, asset managers. Enterprise $95K (G-SIB / Category 1–2 $100B–$500B+; systemic agents; OCC Part 30 App D Heightened Standards + PRA SS1/23 + EU AI Act high-risk overlap; multi-jurisdictional examiner pack; quarterly refresh option).
**Important disclosures.** Kriv is NOT a bank, bank holding company, broker-dealer, investment adviser, or FRB / OCC / FDIC / NCUA / NYDFS / CFPB supervised entity. Kriv performs no model validation — Customer's independent MRM retains sole authority; Kriv delivers validation patterns + templates only. Kriv signs no MRM, Part 30, CCAR / DFAST, or any regulatory filing. Kriv represents no clients before any regulator. No legal, regulatory, or supervisory advice. **Document + process + tooling framework only — not a platform, not an implementation, not a Managed MRM service.** No guarantee of exam outcomes, MRA / MRIA remediation, consent-order lift, CMP mitigation, CCAR / DFAST approval, or Part 30 attestation acceptance. Anthropic CPN membership does not constitute endorsement.
**Get Started**. EDP-eligible — framework engagement fees ($40K–$95K) count toward your AWS Enterprise Discount Program commitment (up to 25%). Structure via Marketplace private offer — makes AWS the compliant procurement channel for bank vendor management. Contact info@kriv.ai or +1-732-433-5564
Highlights
Highlighted by the publisher on AWS Marketplace.
First agentic-AI-specific MRM framework on AWS Marketplace — SR 11-7 + OCC Bulletin 2011-12 + FDIC FIL 22-2017 + OCC 12 CFR Part 30 Appendix D Heightened Standards + SR 15-18 + SR 17-3 + NY DFS Part 500 + OCC Bulletin 2023-17 Third-Party Risk + CFPB Reg B/ECOA/FCRA/TILA aligned. International parallels: PRA SS1/23 (BoE), ECB TRIM, BaFin MaRisk + BAIT. Deliverable is document + process + tooling framework, not a platform.
T1–T4 agentic tiering (tool-invocation risk, compounding step-error probability, autonomy, materiality, reversibility, audit-trail completeness, customer-impact surface). Effective-challenge patterns for agents (tool-use behavioral tests, decomposition-quality, prompt-injection resilience, counterfactual trajectory replay). Champion-challenger harness; agent-aware Model Cards; MRM Governance Committee charter + RACI; examiner Q&A prep pack (OCC / FRB / FDIC / NYDFS).
AWS Select + Databricks + Anthropic CPN + Claude Agent SDK fluency — 6-week fixed-fee $40K / $65K / $95K, document + tooling, no add-on. Foundation $40K (single BU, 10 agents) for community banks $500M–$10B; Standard $65K (enterprise-wide, 30 agents, examiner Q&A + Board briefing + 90-day adoption) for mid-tier $10B–$100B; Enterprise $95K (G-SIB / Category 1–2, systemic agents, Part 30 Heightened Standards overlay + PRA SS1/23 + EU AI Act overlap).
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

