global regulationframework crosswalkmodel validationbanking

The global map of model risk management frameworks

There is no single global MRM rulebook. This map separates enterprise model risk guidance from model-specific and adjacent controls so banks, insurers, and procurement teams can identify the right source before scoping validation work.

Published: Last updated: Last reviewed by: Model Risk Directory editorial team

Research package

Report, infographic and short video

Use the web map below for the current framework count and status. Keep the downloadable brief as a portable working reference.

Model risk procurement overview showing SR 11-7, SR 26-2, the three pillars of model risk management, the vendor directory, and a three-step firm sourcing process
Procurement overview supplied with the research brief. It depicts the original five-framework launch set; the live map on this page is the current 11-framework index.

Watch

SR 26-2 and model risk procurement in brief

Editorial note: the supplied brief informed this page's structure. The live map uses the directory's primary-source framework records and should be treated as the current version.

Current coverage

11-framework jurisdiction map

Use the relevance label before treating two documents as equivalents. Some govern enterprise model risk, some govern a specific capital or AI model class, and some govern the operational dependencies around models.

Enterprise MRMUnited StatesSR 26-2SR 26-2, issued jointly by the Federal Reserve, OCC, and FDIC on April 17, 2026, is the current US interagency guidance on model risk management. It supersedes SR 11-7 (2011) and SR 21-8 (2021), preserving core disciplines like effective challenge and independent validation while shifting to a risk-based approach tailored to an institution's model risk profile, size, and complexity.Status: Issued 17 April 2026Enterprise MRMUnited StatesSR 11-7SR 11-7 was the Federal Reserve's foundational 2011 guidance on model risk management, covering model development, implementation, use, validation, and governance. It was formally rescinded on April 17, 2026 and replaced by SR 26-2, though SR 11-7's core principles, including effective challenge and independent validation, carried forward into the new guidance.Status: Superseded 17 April 2026Enterprise MRMUnited StatesOCC 2011-12OCC Bulletin 2011-12 was the OCC's companion issuance to the Federal Reserve's SR 11-7, published the same day in April 2011, applying identical model risk management expectations to OCC-supervised national banks and federal savings associations. It was rescinded April 17, 2026 and replaced by OCC Bulletin 2026-13, issued jointly with the Fed and FDIC.Status: Rescinded 17 April 2026Enterprise MRMUnited KingdomPRA SS1/23PRA SS1/23 is the Bank of England Prudential Regulation Authority's supervisory statement setting out five model risk management principles for UK banks with internal model approval for credit, market, or counterparty credit risk. It took effect May 17, 2024 and explicitly extends to risks from AI and machine learning modeling techniques.Status: 17 May 2024Model-specificEuropean UnionECB GuideThe ECB Guide to Internal Models sets out European banking supervision's expectations for how significant institutions use internal models to calculate regulatory capital for credit, market, and counterparty credit risk. Developed through the 2016-2021 Targeted Review of Internal Models (TRIM) project, it was most recently revised in July 2025 to reflect CRR3 and updated machine-learning expectations.Status: Revised 28 July 2025Model-specificEuropean UnionEIOPA Internal Model GuidelinesEIOPA's Guidelines on the use of internal models support consistent Solvency II supervision of insurers using full or partial internal models. They address application and approval, model changes, the use test, governance, documentation, data, validation, expert judgment, external models and data, group models, and supervisory communication.Status: Applied through Solvency II national implementationEnterprise MRMCanadaOSFI E-23OSFI E-23 is Canada's enterprise-wide model risk management guideline for federally regulated financial institutions. The final 2025 guideline takes effect on 1 May 2027 and applies a risk-based approach across model identification, inventory, risk ratings, lifecycle governance, independent review, monitoring, third-party models, and decommissioning.Status: 1 May 2027Adjacent controlAustraliaCPG 230APRA CPG 230 is operational-risk guidance for implementing CPS 230. It is not a standalone Australian MRM standard. It matters to model risk teams when critical operations depend on model platforms, data services, cloud providers, validation vendors, or other material service providers that must be governed, monitored, and supported by continuity plans.Status: 1 July 2026Model-specificSingaporeMAS AI MRMThe MAS AI MRM paper reports good practices observed in a thematic review of selected banks. It covers AI governance, inventories, materiality assessment, data, development, independent validation, deployment, monitoring, change, generative-AI risks, and third-party models. It is supervisory guidance and observed practice, not a general statutory MRM rule.Status: Information paper published 5 December 2024Model-specificHong KongHKMA CA-G-4HKMA CA-G-4 sets validation expectations for internal-ratings-based credit-risk systems used by authorized institutions. The current 2025 version covers governance, data, model design, quantitative and qualitative validation, use tests, stress testing, overrides, validation frequency, independence, findings, and supervisory review. It is model-specific rather than an enterprise-wide MRM standard.Status: 18 July 2025Model-specificInternationalBCBS Core PrinciplesThe Basel Committee does not publish a single, general-purpose MRM standard equivalent to SR 26-2. Its Core Principles, consolidated Basel Framework, and model-specific capital rules establish supervisory expectations for governance, risk measurement, validation, controls, and independent review that national regulators apply to banks using internal models.Status: Current Basel Framework version varies by chapter

Start with scope, not geography

A multinational institution should not choose a framework by country name alone. First identify the regulated entity, model purpose, regulatory approval, business use, and model owner. Then determine whether the governing document is an enterprise model risk standard, a model-specific capital or AI document, or an adjacent operational-risk control.

That distinction matters in procurement. A validation statement written for an internal ratings-based credit model will not automatically cover an enterprise fraud model, a vendor score, an insurer's capital model, or a generative AI tool. The RFP should name the model class and the controlling source instead of asking for generic global compliance.

United States: a current standard and two legacy anchors

SR 26-2 and its OCC and FDIC companion issuances are the current US interagency model risk guidance. The Federal Reserve says the guidance is expected to be most relevant to banking organizations with more than $30 billion in total assets. That is a relevance statement, not a universal hard scope threshold.

SR 11-7 and OCC Bulletin 2011-12 remain useful for understanding legacy policies, contracts, inventories, and industry language, but both were superseded in April 2026. Current work should cite SR 26-2 or the applicable companion issuance and account for its risk-based, tailored approach.

  • Use SR 26-2 for current US interagency model risk program design.
  • Use SR 11-7 and OCC 2011-12 to interpret legacy documentation, not as the current standard.
  • Match validation depth and revalidation frequency to materiality, change, exposure, data, and risk.

United Kingdom, European Union, and insurance

PRA SS1/23 sets five model risk management principles for UK banks, building societies, and PRA-designated investment firms with specified internal model approvals. It is a direct model risk statement, but its formal scope should not be stretched to every UK company or every model without analysis.

The ECB Guide to Internal Models focuses on significant institutions using approved internal models for credit, market, and counterparty credit risk. EIOPA's internal-model guidelines sit inside Solvency II and focus on insurance and reinsurance capital models, including use, governance, data, documentation, validation, change, and external models.

Canada: enterprise MRM with a 2027 effective date

OSFI Guideline E-23 is a direct enterprise model risk guideline for Canadian federally regulated financial institutions, including banks and insurers. The final guideline was published in 2025 and takes effect on May 1, 2027.

Implementation teams should separate readiness work from current compliance status. Procurement can begin mapping inventories, classifications, independent review, lifecycle controls, third-party models, monitoring, and decommissioning now without describing a future effective date as a present requirement.

Australia and Asia: do not force false equivalence

APRA CPG 230 is operational-risk guidance for implementing CPS 230. It matters where model platforms, data services, cloud systems, validation vendors, or other providers support critical operations, but it is not a standalone Australian equivalent of SR 26-2.

The MAS AI MRM information paper reports good practices observed in a thematic review of selected banks. HKMA CA-G-4 addresses validation of internal ratings-based credit-risk systems. Both are useful, but their model and supervisory context must remain visible in any crosswalk.

  • Treat APRA CPG 230 as an adjacent operational and service-provider control source.
  • Treat the MAS paper as AI model risk supervisory observations and good practices.
  • Treat HKMA CA-G-4 as model-specific guidance for IRB risk-rating systems.

Basel is a baseline, not one global MRM document

The Basel Committee does not publish one general-purpose document called the Basel model risk management principles. Model governance and validation expectations appear across the Core Principles, consolidated Basel Framework, and model-specific capital rules.

A defensible crosswalk names the exact Basel chapter and the jurisdiction's implementing rule. Citing Basel generically can hide the difference between an international supervisory baseline and a requirement that applies directly to a particular institution.

Turn the map into a procurement control

For each model or vendor, record the legal entity, jurisdiction, regulator, model class, business use, materiality, applicable source, effective date, evidence required, validation standard, owner, and open interpretation questions. That record becomes the bridge between legal or regulatory analysis and a practical RFP.

Ask bidders to state which framework versions they have actually worked with, what evidence they need, where their method changes by model class, and what they cannot conclude. Framework familiarity is useful. It is not proof that a firm, product, or engagement satisfies a regulator.

  • Name the current framework and version in the scope.
  • Separate direct requirements from adjacent controls and observed good practices.
  • Require jurisdiction-specific evidence instead of a generic compliance claim.
  • Verify credentials, references, independence, and deliverables directly.

Primary sources

  1. Federal Reserve SR 26-2
  2. Federal Reserve SR 11-7
  3. OCC Bulletin 2011-12
  4. PRA SS1/23
  5. ECB Guide to Internal Models
  6. EIOPA Guidelines on the use of internal models
  7. OSFI Guideline E-23
  8. APRA CPG 230
  9. MAS Artificial Intelligence Model Risk Management information paper
  10. HKMA CA-G-4
  11. Basel Core Principles

The global map of model risk management frameworks: FAQ

Is there one global model risk management framework?

No. Jurisdictions use different enterprise, capital-model, AI-model, insurance, and operational-risk documents. The correct source depends on the regulated entity, model class, business use, and local implementation.

Did SR 26-2 replace SR 11-7?

Yes. The Federal Reserve issued SR 26-2 on April 17, 2026, and states that it supersedes and replaces SR 11-7. The OCC simultaneously replaced Bulletin 2011-12 with Bulletin 2026-13.

Is APRA CPG 230 Australia's version of SR 26-2?

No. CPG 230 is operational-risk guidance for implementing CPS 230. It is relevant to model systems and material service providers, but it is not a standalone enterprise model risk management standard.

Does OSFI E-23 already apply?

The final revised OSFI E-23 guideline is scheduled to take effect on May 1, 2027. Institutions can prepare now, but should distinguish implementation planning from current compliance status.