SR 26-2 vs OSFI E-23: US and Canadian model risk guidance
Both frameworks use a risk-based approach to model governance, but they apply in different jurisdictions, use different structures, and have different effective timelines. This comparison is a planning aid, not a crosswalk or legal conclusion.
Decision factors
| Factor | SR 26-2 | OSFI E-23 |
|---|---|---|
| Regulator and scope | Joint US interagency guidance for banking organizations supervised by the Federal Reserve, OCC, and FDIC. | OSFI guideline for Canadian federally regulated financial institutions, including banks, insurers, and branches. |
| Effective status | Issued 17 April 2026 and replaced the agencies' earlier model risk guidance. | Finalized 11 September 2025 and takes effect 1 May 2027. |
| Risk-based approach | Tailors MRM to model risk profile and the size and complexity of the banking organization. | Uses inherent model risk ratings and proportionality across institution size, strategy, risk profile, complexity, and interconnectedness. |
| Inventory and lifecycle | Expects an inventory and controls across development and use, validation and monitoring, and governance. | Defines inventory content and lifecycle stages from design through review, deployment, monitoring, and decommissioning. |
| AI and third parties | Applies MRM principles to models regardless of technique and highlights customized vendor and third-party products. | Explicitly includes AI/ML and vendor or external models in the enterprise MRM framework. |
Guidance
A cross-border institution should build one control inventory, then map each control to the exact legal entity, regulator, model population, and effective date. Do not assume a control that satisfies one framework automatically satisfies the other.
Related guides
Ready to source a firm? Send a procurement-safe scope and we route it toward qualified firms.
Request firms