SR 26-2 vs OSFI E-23

SR 26-2 vs OSFI E-23: US and Canadian model risk guidance

Both frameworks use a risk-based approach to model governance, but they apply in different jurisdictions, use different structures, and have different effective timelines. This comparison is a planning aid, not a crosswalk or legal conclusion.

Published: Last updated: Last reviewed by: Model Risk Directory editorial team

Decision factors

FactorSR 26-2OSFI E-23
Regulator and scopeJoint US interagency guidance for banking organizations supervised by the Federal Reserve, OCC, and FDIC.OSFI guideline for Canadian federally regulated financial institutions, including banks, insurers, and branches.
Effective statusIssued 17 April 2026 and replaced the agencies' earlier model risk guidance.Finalized 11 September 2025 and takes effect 1 May 2027.
Risk-based approachTailors MRM to model risk profile and the size and complexity of the banking organization.Uses inherent model risk ratings and proportionality across institution size, strategy, risk profile, complexity, and interconnectedness.
Inventory and lifecycleExpects an inventory and controls across development and use, validation and monitoring, and governance.Defines inventory content and lifecycle stages from design through review, deployment, monitoring, and decommissioning.
AI and third partiesApplies MRM principles to models regardless of technique and highlights customized vendor and third-party products.Explicitly includes AI/ML and vendor or external models in the enterprise MRM framework.

Guidance

A cross-border institution should build one control inventory, then map each control to the exact legal entity, regulator, model population, and effective date. Do not assume a control that satisfies one framework automatically satisfies the other.

Sources. source 1 · source 2

Related guides

Ready to source a firm? Send a procurement-safe scope and we route it toward qualified firms.

Request firms