The global map of model risk management frameworks
There is no single global MRM rulebook. This map separates enterprise model risk guidance from model-specific and adjacent controls so banks, insurers, and procurement teams can identify the right source before scoping validation work.
Research package
Report, infographic and short video
Use the web map below for the current framework count and status. Keep the downloadable brief as a portable working reference.

Editorial note: the supplied brief informed this page's structure. The live map uses the directory's primary-source framework records and should be treated as the current version.
Current coverage
11-framework jurisdiction map
Use the relevance label before treating two documents as equivalents. Some govern enterprise model risk, some govern a specific capital or AI model class, and some govern the operational dependencies around models.
Start with scope, not geography
A multinational institution should not choose a framework by country name alone. First identify the regulated entity, model purpose, regulatory approval, business use, and model owner. Then determine whether the governing document is an enterprise model risk standard, a model-specific capital or AI document, or an adjacent operational-risk control.
That distinction matters in procurement. A validation statement written for an internal ratings-based credit model will not automatically cover an enterprise fraud model, a vendor score, an insurer's capital model, or a generative AI tool. The RFP should name the model class and the controlling source instead of asking for generic global compliance.
United States: a current standard and two legacy anchors
SR 26-2 and its OCC and FDIC companion issuances are the current US interagency model risk guidance. The Federal Reserve says the guidance is expected to be most relevant to banking organizations with more than $30 billion in total assets. That is a relevance statement, not a universal hard scope threshold.
SR 11-7 and OCC Bulletin 2011-12 remain useful for understanding legacy policies, contracts, inventories, and industry language, but both were superseded in April 2026. Current work should cite SR 26-2 or the applicable companion issuance and account for its risk-based, tailored approach.
- Use SR 26-2 for current US interagency model risk program design.
- Use SR 11-7 and OCC 2011-12 to interpret legacy documentation, not as the current standard.
- Match validation depth and revalidation frequency to materiality, change, exposure, data, and risk.
United Kingdom, European Union, and insurance
PRA SS1/23 sets five model risk management principles for UK banks, building societies, and PRA-designated investment firms with specified internal model approvals. It is a direct model risk statement, but its formal scope should not be stretched to every UK company or every model without analysis.
The ECB Guide to Internal Models focuses on significant institutions using approved internal models for credit, market, and counterparty credit risk. EIOPA's internal-model guidelines sit inside Solvency II and focus on insurance and reinsurance capital models, including use, governance, data, documentation, validation, change, and external models.
Canada: enterprise MRM with a 2027 effective date
OSFI Guideline E-23 is a direct enterprise model risk guideline for Canadian federally regulated financial institutions, including banks and insurers. The final guideline was published in 2025 and takes effect on May 1, 2027.
Implementation teams should separate readiness work from current compliance status. Procurement can begin mapping inventories, classifications, independent review, lifecycle controls, third-party models, monitoring, and decommissioning now without describing a future effective date as a present requirement.
Australia and Asia: do not force false equivalence
APRA CPG 230 is operational-risk guidance for implementing CPS 230. It matters where model platforms, data services, cloud systems, validation vendors, or other providers support critical operations, but it is not a standalone Australian equivalent of SR 26-2.
The MAS AI MRM information paper reports good practices observed in a thematic review of selected banks. HKMA CA-G-4 addresses validation of internal ratings-based credit-risk systems. Both are useful, but their model and supervisory context must remain visible in any crosswalk.
- Treat APRA CPG 230 as an adjacent operational and service-provider control source.
- Treat the MAS paper as AI model risk supervisory observations and good practices.
- Treat HKMA CA-G-4 as model-specific guidance for IRB risk-rating systems.
Basel is a baseline, not one global MRM document
The Basel Committee does not publish one general-purpose document called the Basel model risk management principles. Model governance and validation expectations appear across the Core Principles, consolidated Basel Framework, and model-specific capital rules.
A defensible crosswalk names the exact Basel chapter and the jurisdiction's implementing rule. Citing Basel generically can hide the difference between an international supervisory baseline and a requirement that applies directly to a particular institution.
Turn the map into a procurement control
For each model or vendor, record the legal entity, jurisdiction, regulator, model class, business use, materiality, applicable source, effective date, evidence required, validation standard, owner, and open interpretation questions. That record becomes the bridge between legal or regulatory analysis and a practical RFP.
Ask bidders to state which framework versions they have actually worked with, what evidence they need, where their method changes by model class, and what they cannot conclude. Framework familiarity is useful. It is not proof that a firm, product, or engagement satisfies a regulator.
- Name the current framework and version in the scope.
- Separate direct requirements from adjacent controls and observed good practices.
- Require jurisdiction-specific evidence instead of a generic compliance claim.
- Verify credentials, references, independence, and deliverables directly.
Primary sources
The global map of model risk management frameworks: FAQ
Is there one global model risk management framework?
No. Jurisdictions use different enterprise, capital-model, AI-model, insurance, and operational-risk documents. The correct source depends on the regulated entity, model class, business use, and local implementation.
Did SR 26-2 replace SR 11-7?
Yes. The Federal Reserve issued SR 26-2 on April 17, 2026, and states that it supersedes and replaces SR 11-7. The OCC simultaneously replaced Bulletin 2011-12 with Bulletin 2026-13.
Is APRA CPG 230 Australia's version of SR 26-2?
No. CPG 230 is operational-risk guidance for implementing CPS 230. It is relevant to model systems and material service providers, but it is not a standalone enterprise model risk management standard.
Does OSFI E-23 already apply?
The final revised OSFI E-23 guideline is scheduled to take effect on May 1, 2027. Institutions can prepare now, but should distinguish implementation planning from current compliance status.