SR 26-2 · SR 11-7 · OCC 2011-12/2026-13 · updated 2026-07-29


Source model risk management firms and understand what examiners expect.

Model Risk Directory organizes 11 named regulatory guidance documents - including the April 2026 interagency update SR 26-2 and the original SR 11-7 it superseded - into 8 buyer guides, and pairs each with a sourced reference to 34 notable real firms in the space. Buyer education and a direct line to independent model validation firms. Not a compliance guarantee, not legal advice.

11
named frameworks
8
buyer guides
34
vendors indexed
53
glossary terms

New field guide

The global map of model risk management frameworks

See how US, UK, EU, Canadian, Australian, Singaporean, Hong Kong, and Basel materials differ before you put a framework name into an RFP. The video player stays unloaded until you press play.

Model risk procurement overview showing SR 11-7, SR 26-2, the three pillars of model risk management, the vendor directory, and a three-step firm sourcing process
Procurement overview supplied with the research brief. It depicts the original five-framework launch set; the live map on this page is the current 11-framework index.

Watch

SR 26-2 and model risk procurement in brief

Editorial note: the supplied brief informed this page's structure. The live map uses the directory's primary-source framework records and should be treated as the current version.


Named frameworks

What this index is organized around

Real, independently-issued regulatory guidance, cited directly rather than paraphrased - including the current 2026 interagency guidance and the historical SR 11-7/OCC 2011-12 it replaced.

CPG 230

APRA CPG 230 Operational Risk Management

CPG 230 explains APRA's view of sound practice for entities implementing Prudential Standard CPS 230 Operational Risk Management. It covers operational-risk governance, controls, business continuity, critical operations, and material service-provider arrangements across APRA-regulated industries. For model risk management, its practical relevance is the operating environment around models and third-party dependencies. It does not replace model validation, model inventory, or model-lifecycle standards and should not be presented as Australia's direct equivalent of SR 26-2.

BCBS Core Principles

Basel Core Principles and internal-model governance

The Basel Core Principles provide a global baseline for banking supervision, including board oversight, comprehensive risk management, independent control functions, and supervisory review. Model-specific requirements sit throughout the consolidated Basel Framework, especially where banks use internal ratings, market-risk models, stress tests, and other methods to calculate risk or regulatory capital. This page treats Basel as a collection of model-governance requirements, not as a nonexistent standalone document called the 'Basel model risk management principles.'

ECB Guide

ECB Guide to Internal Models

The Guide explains how the ECB interprets applicable EU and national law on internal models, creating a level playing field across significant institutions directly supervised by European banking supervision. It was originally developed through TRIM, a large-scale project (2016-2021) combining detailed methodological work with roughly 200 on-site internal model investigations at 65 institutions, and covers credit risk, market risk, and counterparty credit risk models along with general model governance topics.

EIOPA Internal Model Guidelines

EIOPA Guidelines on the use of internal models

The EIOPA Guidelines support national supervisory authorities and insurance or reinsurance undertakings applying Solvency II internal-model requirements. They focus on models used to calculate all or part of the Solvency Capital Requirement and the governance needed to show that a model is embedded in decision-making, understood, documented, validated, and controlled. They are narrower than an enterprise-wide model inventory regime, but highly relevant to insurers' capital-model governance, validation, change, data, and use-test evidence.

HKMA CA-G-4

HKMA CA-G-4: Validating Risk Rating Systems under the IRB Approach

CA-G-4 is a current module of the HKMA Supervisory Policy Manual for validating risk-rating systems under the internal-ratings-based approach. It applies to authorized institutions using or seeking approval to use IRB approaches for credit-risk capital. The module addresses governance, responsibilities, model design, data, discriminatory power, calibration, overrides, benchmarking, backtesting, stress testing, validation independence, documentation, and remediation. Broader enterprise risk governance sits in other HKMA modules, including IC-1.

Audit methodology guides

In-demand assessment categories

The categories buyers search for most, each a buyer checklist rather than a vendor ranking.

Retain with confidence

Need a model risk firm now?

Submit a procurement-safe scope and the service category you need. We route it toward qualified independent model validation firms, model risk management advisory firms, and MRM governance software vendors, usually within one business day. Procurement support, not a compliance guarantee.

Sourced reference

Notable model risk management vendors

All 34 vendors →

Frequently asked questions

What is Model Risk Directory?

A procurement-grade reference for bank and insurer model risk management. It organizes named regulatory guidance (SR 11-7, SR 26-2, OCC Bulletin 2011-12/2026-13, PRA SS1/23, ECB Guide to Internal Models) into buyer guides, explains what to verify before you retain an independent model validation firm, and pairs each guide with a sourced reference to notable real advisory firms and MRM governance software vendors in the space.

Is this a compliance guarantee or legal advice?

No. Model Risk Directory is procurement support and buyer education only. It does not provide a compliance guarantee, does not validate your models, and does not provide legal advice. Framework citations are informational context, never a claim that this index or a listed vendor satisfies an examiner or regulator.

How do I source a firm here?

Use the sourcing request form to submit a procurement-safe scope and the service category you need. We route it toward qualified independent model validation firms, model risk management advisory firms, and MRM governance software vendors. Keep confidential model architecture or training data out of the request.

Does it cost anything?

The guides, glossary, frameworks reference, and vendor reference are free to use. Featured and Verified placements are clearly labeled and never change the editorial content or ordering.

Model risk management sourcing brief

Occasional emails when we publish a new guide, framework update, or glossary update. No spam, unsubscribe anytime.

Single opt-in. We store only your email to send these updates. See ourprivacy notice. This is procurement information, not a compliance guarantee or legal advice.