SR 26-2 — revised Model Risk Management guidance (supersedes SR 11-7)
Modernised interagency MRM guidance for banks >$30B; supervised ML is in scope, generative & agentic AI are explicitly out of scope pending an interagency RFI.
The same obligation themes, side by side, from the catalogue that powers the rest of this site — 5 catalogued requirements across 3 themes. Expand any requirement to read it. Free, no login.
Comparing 2 of 38 regulations we track. This URL is the comparison — send it to anyone.
Every theme below appears in exactly one group, so these account for all 3 of them. Sharing a theme means both regimes legislate in that area — it does not mean complying with one discharges the other.
OSFI E-23 · SR 26-2
OSFI E-23not: SR 26-2
A dash means we have not catalogued a requirement for that regulation under that theme — a summary of our catalogue, not a finding that the law is silent. Always check the official text, linked from each regulation's page.
| Theme | OSFI E-23 | SR 26-2 |
|---|---|---|
| What you must assess first | ||
| Risk management system Must you run a documented, continuous risk process? | E-23 · Governance Model risk governance & lifecycle mustOperate an enterprise-wide model risk-management framework over the full model lifecycle, with a model inventory and risk-based materiality rating that explicitly captures AI/ML models. Read it in context → | Inventory Model inventory & tiering shouldMaintain a complete model inventory tiered by materiality, with documented development evidence for each model. Read it in context → |
| What you must build and prove | ||
| Accuracy, robustness & security Must you hit and evidence performance targets? | E-23 · Validation Independent validation mustIndependently validate models before first use and periodically thereafter — conceptual soundness, data quality, performance, and bias/fairness. Read it in context → | Validation Independent validation & monitoring shouldIndependent validation covering conceptual soundness, ongoing monitoring (incl. benchmarking) and outcomes analysis/backtesting; change management triggers revalidation; vendor models validated too. Read it in context → |
| What you must do while it runs | ||
| Monitoring after deployment Must you keep watching it once it is live? | E-23 · Monitoring Ongoing monitoring & human oversight mustContinuously monitor model performance and drift, document model decisions, and ensure appropriate human oversight of outputs. Read it in context → | — |
Every dated obligation attached to these regulations, merged into one timeline.
Modernised interagency MRM guidance for banks >$30B; supervised ML is in scope, generative & agentic AI are explicitly out of scope pending an interagency RFI.
Federally regulated financial institutions must manage model risk across the lifecycle — inventory, risk-based materiality, independent validation, monitoring and human oversight — explicitly covering AI/ML models.