Audit methodologyMRM frameworkMRM policy framework

Model Risk Management Framework

What a defensible MRM framework actually contains, and how to verify yours holds up.

Quick answer

A model risk management framework is the documented set of policies, roles, and processes an institution uses to identify, tier, govern, and validate its models. Under SR 26-2, a sound framework covers model development and use, independent validation, and governance and controls, scaled to the institution's size and model risk profile rather than applied uniformly.

Real US search demand (Ahrefs): ~150 searches/mo for "model risk management framework" · ~$8.00 CPC.

The buyer problem

Many institutions have scattered model risk practices, an inventory spreadsheet here, a validation checklist there, without a coherent, documented framework tying policy, roles, tiering, and validation cadence together. Examiners expect a framework document (or coordinated set of documents) that shows how the institution defines a model, tiers it, assigns ownership, schedules validation, and escalates findings. Building or auditing that framework from scratch, especially updating one still built around the superseded SR 11-7 structure, requires specialized regulatory and quantitative expertise most institutions do not have permanently on staff.

What a model risk management framework engagement covers

A framework engagement produces (or audits) the core documents and structures: a model definition and inventory methodology, a risk-tiering approach, governance roles and committee structure, a validation cadence policy tied to tier and materiality (per SR 26-2's risk-based approach), model change management procedures, and escalation/remediation protocols for validation findings. Firms doing this work typically interview model owners and risk staff, review existing policy documents, benchmark against peer institutions and current regulatory guidance, and deliver either a gap report with recommendations or fully drafted policy documents ready for board approval.

Methods and techniques

  • Model definition and inventory-scope review
  • Risk-tiering methodology design
  • Governance structure and committee charter design
  • Validation cadence policy aligned to SR 26-2's risk-based approach
  • Model change management procedure design
  • Peer benchmarking against comparable institutions

What to verify before you retain

  • Definition of 'model' matches SR 26-2. Confirm the framework's model definition reflects SR 26-2's refined scope, which excludes simple spreadsheet arithmetic and deterministic rule-based processes, not the broader SR 11-7-era definition.
  • Tiering is materiality-driven. Tiering should be based on real factors, financial materiality, complexity, reliance on outputs, not an arbitrary or copy-pasted scheme from another institution's framework.
  • Validation cadence is risk-based, not calendar-only. Per SR 26-2, revalidation frequency should scale with model materiality, change velocity, and data availability, not a blanket annual cycle carried over from SR 11-7 habits.
  • Vendor and third-party models are in scope. Confirm the framework's inventory and governance explicitly capture vendor-supplied and third-party models, an area SR 26-2 expanded emphasis on.
  • Board and senior management ownership is documented. The framework should name who at the board/senior-management level owns model risk oversight, not leave it implicit.

Questions to put in your RFP

  1. How does your framework template define 'model,' and does it match SR 26-2's refined definition?
  2. How is your tiering methodology customized to our model population versus a generic template?
  3. How do you set validation cadence for each tier under a risk-based approach?
  4. How does the framework address vendor and third-party models specifically?
  5. What governance/committee structure do you recommend for an institution our size, and why?
  6. Will we receive board-ready policy documents, or only a gap-assessment report?

Skip the cold search. Send this scope to us and we route it toward qualified model risk management framework firms.

Request firms

Red flags

  • A framework template that is a lightly relabeled copy from a different, larger institution.
  • No explicit treatment of vendor or third-party models in the inventory scope.
  • A validation cadence policy that is just 'annual for everything' with no risk-based rationale.
  • No named governance owner at the board or senior-management level.
  • Refusal to explain how the framework would need to change if your model count or complexity grows.

Frameworks referenced

Named regulatory guidance relevant to this category. Listed for context; they do not endorse this index or any vendor. Verify any framework alignment claim directly against the issuing body.

SR 26-2
SR 26-2 / OCC Bulletin 2026-13: Revised Guidance on Model Risk Management. SR 26-2 (issued by the Federal Reserve as a Supervisory Letter, and simultaneously as OCC Bulletin 2026-13 and an FDIC Financial Institution Letter) reflects fifteen years of supervisory experience since SR 11-7 and updates model risk management expectations for a risk-based, tailored era. It is expected to be most relevant to banking organizations with over $30 billion in total assets. The guidance retains the three foundational pillars, model development and use, validation and ongoing monitoring, and governance and controls, while replacing SR 11-7's de facto annual review cycle with revalidation frequency tied to model materiality, change velocity, and data availability, and expanding attention to vendor and third-party models. Read more →
SR 11-7
SR 11-7: Guidance on Model Risk Management. Issued April 4, 2011 jointly with the OCC (as Bulletin 2011-12), SR 11-7 set out supervisory expectations for how banks should manage the risk that quantitative models produce incorrect or misused results. It organized model risk management around three pillars: model development, implementation, and use; model validation; and governance, policies, and controls, and introduced 'effective challenge' as the guiding principle for meaningful independent review. Read more →
PRA SS1/23
PRA SS1/23: Model Risk Management Principles for Banks. SS1/23 applies to UK-incorporated banks, building societies, and PRA-designated investment firms that have internal model approval to calculate regulatory capital requirements under Internal Ratings Based (credit risk), Internal Model Approach (market risk), or Internal Model Method (counterparty credit risk) approaches. It sets out five principles the PRA expects firms to embed as a strategic model risk discipline in its own right, comparable in spirit to SR 11-7/SR 26-2 but issued independently by the UK's prudential regulator. Read more →

Notable model risk management framework vendors

Real, publicly-documented vendors active in this category. Sourced and verified; not a ranking or endorsement.

Sourcing intake

Request a model risk management framework firm

Tell us the service category and a procurement-safe scope. We route it toward qualified independent model validation firms, model risk management advisory firms, and MRM governance software vendors. Keep confidential model details, training data, or system architecture out of this form. Procurement support, not a compliance guarantee and not legal advice.

No fee. No obligation. We reply by email, usually within one business day.

Model Risk Management Framework: buyer FAQ

Do we need a separate MRM framework document, or can it live inside our broader risk policy?

Either can work as long as the required elements, model definition, inventory, tiering, governance roles, validation cadence, change management, are clearly documented and board-approved. A dedicated MRM framework document is more common at institutions with larger or more complex model populations.

How often should the framework itself be reviewed?

Most institutions review their MRM framework annually or when a material regulatory change occurs, such as the April 2026 shift from SR 11-7 to SR 26-2, which is a clear trigger for a framework refresh even outside a normal review cycle.

Is a framework audit the same as model validation?

No. A framework audit or design engagement evaluates the governance structure and policies themselves. Model validation is the separate, ongoing activity of independently testing individual models against that framework's standards. See the model risk validation guide for that distinct service.

Related guides