SR 26-2 vs PRA SS1/23

SR 26-2 vs PRA SS1/23: model risk principles compared

SR 26-2 and PRA SS1/23 both expect model risk to be governed across the lifecycle, but they organize the work differently and apply to different supervised populations. The table highlights procurement and implementation differences without claiming equivalence.

Published: Last updated: Last reviewed by: Model Risk Directory editorial team

Decision factors

FactorSR 26-2PRA SS1/23
StructureOrganized around development and use, validation and monitoring, and governance, with a risk-based approach.Organized around five principles covering identification and classification, governance, development and use, validation, and mitigants.
ScopeApplies to US banking organizations supervised by the issuing agencies.Applies to PRA-regulated banks, building societies, and PRA-designated investment firms within stated scope.
InventoryExpects an inventory that supports governance proportionate to model risk.Places explicit emphasis on model identification, model definition, inventory, and risk classification.
ValidationRequires effective challenge and validation appropriate to model use, risk, limitations, and complexity.Sets a dedicated validation principle with independence, scope, frequency, and outcome expectations.
Third-party modelsHighlights vendor and other third-party products, data, parameters, and complete models.Expects firms to manage externally developed models and understand limitations even when information is constrained.

Guidance

Use a shared enterprise MRM policy only if local appendices preserve the exact regulator, entity, terminology, model perimeter, evidence, and approval requirements. A generic global policy can reduce duplication, but it cannot erase jurisdiction-specific obligations.

Sources. source 1 · source 2

Related guides

Ready to source a firm? Send a procurement-safe scope and we route it toward qualified firms.

Request firms