Reference, not a compliance guarantee
Model risk management frameworks
Model Risk Directory is organized around named, real regulatory guidance rather than a generic explainer. The collection separates direct MRM standards from model-specific prudential rules and adjacent operational-risk guidance, so an APRA service-provider rule is not presented as if it were Australia's version of SR 26-2. Each page covers the issuer, scope, pillars, current status, and official source.
Framework reference
APRA CPG 230 Operational Risk Management
CPG 230 explains APRA's view of sound practice for entities implementing Prudential Standard CPS 230 Operational Risk Management. It covers operational-risk governance, controls, business continuity, critical operations, and material service-provider arrangements across APRA-regulated industries. For model risk management, its practical relevance is the operating environment around models and third-party dependencies. It does not replace model validation, model inventory, or model-lifecycle standards and should not be presented as Australia's direct equivalent of SR 26-2.
Issued by Australian Prudential Regulation Authority
Basel Core Principles and internal-model governance
The Basel Core Principles provide a global baseline for banking supervision, including board oversight, comprehensive risk management, independent control functions, and supervisory review. Model-specific requirements sit throughout the consolidated Basel Framework, especially where banks use internal ratings, market-risk models, stress tests, and other methods to calculate risk or regulatory capital. This page treats Basel as a collection of model-governance requirements, not as a nonexistent standalone document called the 'Basel model risk management principles.'
Issued by Basel Committee on Banking Supervision
ECB Guide to Internal Models
The Guide explains how the ECB interprets applicable EU and national law on internal models, creating a level playing field across significant institutions directly supervised by European banking supervision. It was originally developed through TRIM, a large-scale project (2016-2021) combining detailed methodological work with roughly 200 on-site internal model investigations at 65 institutions, and covers credit risk, market risk, and counterparty credit risk models along with general model governance topics.
Issued by European Central Bank (Banking Supervision)
EIOPA Guidelines on the use of internal models
The EIOPA Guidelines support national supervisory authorities and insurance or reinsurance undertakings applying Solvency II internal-model requirements. They focus on models used to calculate all or part of the Solvency Capital Requirement and the governance needed to show that a model is embedded in decision-making, understood, documented, validated, and controlled. They are narrower than an enterprise-wide model inventory regime, but highly relevant to insurers' capital-model governance, validation, change, data, and use-test evidence.
Issued by European Insurance and Occupational Pensions Authority
HKMA CA-G-4: Validating Risk Rating Systems under the IRB Approach
CA-G-4 is a current module of the HKMA Supervisory Policy Manual for validating risk-rating systems under the internal-ratings-based approach. It applies to authorized institutions using or seeking approval to use IRB approaches for credit-risk capital. The module addresses governance, responsibilities, model design, data, discriminatory power, calibration, overrides, benchmarking, backtesting, stress testing, validation independence, documentation, and remediation. Broader enterprise risk governance sits in other HKMA modules, including IC-1.
Issued by Hong Kong Monetary Authority
MAS Artificial Intelligence Model Risk Management information paper
MAS published Artificial Intelligence Model Risk Management: Observations from a Thematic Review in December 2024 after reviewing selected banks. The paper focuses on AI and generative-AI model controls across governance, identification, inventory, materiality, development, validation, deployment, monitoring, and third-party use. MAS later consulted on broader AI risk-management guidelines and supported an industry toolkit. This page covers the 2024 information paper and clearly separates observed good practices from binding requirements or later consultation proposals.
Issued by Monetary Authority of Singapore
OCC Bulletin 2011-12: Sound Practices for Model Risk Management
OCC Bulletin 2011-12, 'Supervisory Guidance on Model Risk Management,' articulated the elements of a sound program for managing risk from quantitative models used in bank decision-making. Its text was substantively identical to the Federal Reserve's SR 11-7, reflecting that both agencies developed the guidance jointly, and it applied to national banks and federal savings associations supervised by the OCC.
Issued by Office of the Comptroller of the Currency
OSFI Guideline E-23: Model Risk Management
The final E-23 guideline applies to Canadian federally regulated financial institutions, including banks, foreign bank branches, insurers, and trust and loan companies. It expands model risk management beyond deposit-taking institutions and explicitly addresses AI and machine-learning models. Expectations are proportional to the institution's size, strategy, risk profile, operational complexity, and interconnectedness. The guideline organizes requirements around enterprise-wide governance, risk-based classification, model lifecycle controls, review, deployment, monitoring, and decommissioning.
Issued by Office of the Superintendent of Financial Institutions
PRA SS1/23: Model Risk Management Principles for Banks
SS1/23 applies to UK-incorporated banks, building societies, and PRA-designated investment firms that have internal model approval to calculate regulatory capital requirements under Internal Ratings Based (credit risk), Internal Model Approach (market risk), or Internal Model Method (counterparty credit risk) approaches. It sets out five principles the PRA expects firms to embed as a strategic model risk discipline in its own right, comparable in spirit to SR 11-7/SR 26-2 but issued independently by the UK's prudential regulator.
Issued by Bank of England Prudential Regulation Authority
SR 11-7: Guidance on Model Risk Management
Issued April 4, 2011 jointly with the OCC (as Bulletin 2011-12), SR 11-7 set out supervisory expectations for how banks should manage the risk that quantitative models produce incorrect or misused results. It organized model risk management around three pillars: model development, implementation, and use; model validation; and governance, policies, and controls, and introduced 'effective challenge' as the guiding principle for meaningful independent review.
Issued by Board of Governors of the Federal Reserve System
SR 26-2 / OCC Bulletin 2026-13: Revised Guidance on Model Risk Management
SR 26-2 (issued by the Federal Reserve as a Supervisory Letter, and simultaneously as OCC Bulletin 2026-13 and an FDIC Financial Institution Letter) reflects fifteen years of supervisory experience since SR 11-7 and updates model risk management expectations for a risk-based, tailored era. It is expected to be most relevant to banking organizations with over $30 billion in total assets. The guidance retains the three foundational pillars, model development and use, validation and ongoing monitoring, and governance and controls, while replacing SR 11-7's de facto annual review cycle with revalidation frequency tied to model materiality, change velocity, and data availability, and expanding attention to vendor and third-party models.
Issued by Federal Reserve, OCC, and FDIC (joint interagency guidance)