Model Risk Management
Inventory models, tier them by impact and exposure, and track an eight-point validation checklist mapped to SR 26-2, OSFI E-23, PRA SS1/23 and MAS. Flags high-tier models that are not fully validated.
AUTOGOVERN FINANCE · INDUSTRY SECTION
Banks, lenders, insurers and investment firms govern AI under decades-old model-risk and fair-lending regimes plus the new AI layer. Everything here is free to read: a step-by-step guide, a vision board, a complete reference architecture, Workbench tools and policy templates — with an organization workspace when your team needs shared records.
01 / FOUR WAYS IN
Register and tier a model, map lineage and consumer-report use, review third parties, validate for soundness and fairness, approve a controlled release, monitor and respond.
PLANEight opportunities from servicing assistants to credit decisioning and algorithmic execution, each with data, authority limits, controls, evidence, monitoring and fallback.
DESIGNA complete financial services AI platform design: modules, trust zones, lineage, integration, decision workflows, model risk, fair lending, DORA, monitoring and delivery planning.
RECORDOrganization-private metadata: use cases, model inventory with tiering, validations, fair-lending reviews, third parties, data flows, risks, controls, releases, monitoring and domain reviews.
02 / THE REGIMES WE COVER
Finance AI regulation moved fast in 2025–2026. Status labels below distinguish what is enforceable from what supervisors expect and from what is voluntary, and note the dates that changed. Verify the current position for your entity type and jurisdiction before a formal decision.
| Regime | Status | What it requires of AI and models | Applies to |
|---|---|---|---|
| SR 26-2 / OCC 2026-13 / FDIC FIL-15-2026 — model risk management | Guidance | Inventory, materiality tiering, independent validation with effective challenge, ongoing monitoring and governance. Supervised machine learning is in scope; generative and agentic AI are out of scope pending interagency work. Issued 17 April 2026, superseding SR 11-7. | US banks over $30B in assets; proportionate expectations elsewhere |
| Treasury / CRI Financial Services AI RMF | Voluntary | About 230 control objectives across seven domains operationalising the NIST AI RMF for finance, crosswalked to SR 26-2. Released 19 February 2026. | US financial services; useful globally |
| ECOA / Regulation B and FCRA — fair lending and adverse action | Binding | Specific principal reasons for adverse credit action regardless of model complexity; FCRA notices and accuracy when consumer reports or scores are used. The ECOA disparate-impact effects test was removed from 21 July 2026 (contested); disparate impact remains live under the Fair Housing Act, DOJ and state law. | US consumer credit |
| NAIC Model Bulletin · NY DFS Circular Letter 7 · Colorado SB 21-169 | Guidance State | Written AI Systems Program; quantitative proxy and bias testing of external data and models in underwriting and pricing; Colorado governance framework and attestation (its quantitative-testing rule is still unadopted). | US insurers; adoption varies by state |
| SEC Rule 15c3-5 · Advisers Act · FINRA Notice 24-09 | Binding | Pre-trade risk controls and a kill switch for algorithmic and AI order flow; AI-washing enforcement under the marketing and compliance rules; supervision and recordkeeping of AI outputs. | US broker-dealers and investment advisers |
| EU AI Act — Annex III 5(b) credit scoring and 5(c) life/health insurance pricing | Binding From 2 Dec 2027 | High-risk obligations: risk management, data governance, documentation, logging, human oversight and a deployer fundamental rights impact assessment. Obligations deferred to 2 December 2027 by the Digital Omnibus; fraud detection is carved out. | EU providers and deployers |
| DORA — Digital Operational Resilience Act | Binding | ICT risk-management framework, register of information for ICT and AI third parties, major-incident reporting and resilience testing. Applies since 17 January 2025. | EU financial entities |
| PRA SS1/23 — model risk management principles | Supervisory | Five principles: identification and tiering, governance, development, independent validation, mitigants. Effective 17 May 2024; the model definition captures AI and machine learning. | UK banks with internal-model approval |
| FCA Consumer Duty (PRIN 2A) | Binding | Assess and prevent foreseeable harm before deploying AI; deliver good outcomes on products, price and value, understanding and support. In force since 31 July 2023. | UK retail financial services |
| OSFI E-23 · MAS FEAT and AI MRM · HKMA | Guidance Pending | Canada: lifecycle model risk management effective 1 May 2027. Singapore: AI inventory, materiality, validation and monitoring; draft AI risk-management guidelines in consultation. Hong Kong: generative AI consumer-protection principles. | Canada, Singapore, Hong Kong |
Withdrawn items are not cited as live: the CFPB's 2022–2023 adverse-action circulars were rescinded in May 2025 and the SEC's predictive data analytics proposal was withdrawn in June 2025. The statutes they described remain binding.
03 / WORKBENCH TOOLS FOR FINANCE
Inventory models, tier them by impact and exposure, and track an eight-point validation checklist mapped to SR 26-2, OSFI E-23, PRA SS1/23 and MAS. Flags high-tier models that are not fully validated.
Generate ECOA / Regulation B adverse-action notices with specific reasons and FCRA text, and run a four-fifths disparate-impact calculation with the 2026 jurisdiction caveat.
Score a representative FS AI RMF control set across seven domains with NIST, ISO 42001 and SR 26-2 crosswalks, and keep a DORA ICT and AI third-party register that flags critical providers missing contracts or exit plans.
04 / FREE FINANCE POLICY TEMPLATES
Detailed documents you can download and edit. Fill in the bracketed placeholders, route them through your governance committee and keep the version history.
A finance model-risk policy for banks, lenders and insurers — model inventory & materiality tiering, the full validation lifecycle (conceptual soundness, outcomes analysis, ongoing monitoring), effective challenge, vendor models and AI/ML-specific controls. Aligned to SR 26-2, OSFI E-23, PRA SS1/23, MAS and the Treasury/CRI FS AI RMF.
A procedure for AI/ML credit decisions — specific-reason adverse-action notices (ECOA/Reg B §1002.9, FCRA), reason-code & counterfactual explanations, and fair-lending / disparate-impact testing with the current jurisdiction caveats. Includes a ready-to-use adverse-action notice template.
A NAIC-aligned AI Systems Program for insurers — governance & accountability, lifecycle risk controls, third-party/vendor management, and testing for unfair discrimination (proxy/bias testing per NY DFS and Colorado). Documentation ready for market-conduct examination.
05 / DATES THAT MATTER
06 / WHO IT IS FOR
Inventory, tiering, validation reports, effective challenge and revalidation triggers that match SR 26-2, SS1/23, E-23 and MAS.
Adverse-action reason codes, disparate-impact testing by jurisdiction, FCRA notices, Consumer Duty and conduct reviews.
Vendor-model oversight, the DORA register of information, concentration, exit plans and incident reporting clocks.
Understand what regulated buyers must evidence about your model so due diligence, contracts and validation access go faster.
Educational aid, not legal advice. Sources were reviewed on 2026-09-12; finance AI regulation changes quickly, so confirm the current status for your jurisdiction and entity type.