SR 26-2 vs PRA SS1/23: model risk principles compared
SR 26-2 and PRA SS1/23 both expect model risk to be governed across the lifecycle, but they organize the work differently and apply to different supervised populations. The table highlights procurement and implementation differences without claiming equivalence.
Decision factors
| Factor | SR 26-2 | PRA SS1/23 |
|---|---|---|
| Structure | Organized around development and use, validation and monitoring, and governance, with a risk-based approach. | Organized around five principles covering identification and classification, governance, development and use, validation, and mitigants. |
| Scope | Applies to US banking organizations supervised by the issuing agencies. | Applies to PRA-regulated banks, building societies, and PRA-designated investment firms within stated scope. |
| Inventory | Expects an inventory that supports governance proportionate to model risk. | Places explicit emphasis on model identification, model definition, inventory, and risk classification. |
| Validation | Requires effective challenge and validation appropriate to model use, risk, limitations, and complexity. | Sets a dedicated validation principle with independence, scope, frequency, and outcome expectations. |
| Third-party models | Highlights vendor and other third-party products, data, parameters, and complete models. | Expects firms to manage externally developed models and understand limitations even when information is constrained. |
Guidance
Use a shared enterprise MRM policy only if local appendices preserve the exact regulator, entity, terminology, model perimeter, evidence, and approval requirements. A generic global policy can reduce duplication, but it cannot erase jurisdiction-specific obligations.
Related guides
Ready to source a firm? Send a procurement-safe scope and we route it toward qualified firms.
Request firms