<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Model Risk Directory</title><description>Model Risk Directory is a procurement-grade reference for bank and insurer model risk management. Understand what SR 26-2, SR 11-7, OCC Bulletin 2011-12/2026-13, PRA SS1/23, and the ECB Guide to Internal Models actually require, learn exactly what to verify before you retain an independent model validation firm, and explore a sourced reference to the real advisory firms and MRM governance software vendors active in the space. Procurement support, not a compliance guarantee.</description><link>https://modelriskdirectory.com/</link><language>en-us</language><item><title>AI model risk under SR 26-2: what is in scope and what is not</title><link>https://modelriskdirectory.com/insights/ai-model-risk-under-sr-26-2/</link><guid isPermaLink="true">https://modelriskdirectory.com/insights/ai-model-risk-under-sr-26-2/</guid><description>SR 26-2 applies its model risk principles to traditional statistical, quantitative, and non-generative, non-agentic AI models. Generative and agentic AI are outside this guidance&apos;s model scope, but they are not outside bank risk management.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The global map of model risk management frameworks</title><link>https://modelriskdirectory.com/insights/global-map-model-risk-management-frameworks/</link><guid isPermaLink="true">https://modelriskdirectory.com/insights/global-map-model-risk-management-frameworks/</guid><description>There is no single global MRM rulebook. This map separates enterprise model risk guidance from model-specific and adjacent controls so banks, insurers, and procurement teams can identify the right source before scoping validation work.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>APRA CPG 230 Operational Risk Management</title><link>https://modelriskdirectory.com/frameworks/apra-cpg-230/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/apra-cpg-230/</guid><description>CPG 230 explains APRA&apos;s view of sound practice for entities implementing Prudential Standard CPS 230 Operational Risk Management. It covers operational-risk governance, controls, business continuity, critical operations, and material service-provider arrangements across APRA-regulated industries. For model risk management, its practical relevance is the operating environment around models and third-party dependencies. It does not replace model validation, model inventory, or model-lifecycle standards and should not be presented as Australia&apos;s direct equivalent of SR 26-2.</description></item><item><title>Basel Core Principles and internal-model governance</title><link>https://modelriskdirectory.com/frameworks/basel-core-principles-model-risk/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/basel-core-principles-model-risk/</guid><description>The Basel Core Principles provide a global baseline for banking supervision, including board oversight, comprehensive risk management, independent control functions, and supervisory review. Model-specific requirements sit throughout the consolidated Basel Framework, especially where banks use internal ratings, market-risk models, stress tests, and other methods to calculate risk or regulatory capital. This page treats Basel as a collection of model-governance requirements, not as a nonexistent standalone document called the &apos;Basel model risk management principles.&apos;</description></item><item><title>ECB Guide to Internal Models</title><link>https://modelriskdirectory.com/frameworks/ecb-guide-to-internal-models/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/ecb-guide-to-internal-models/</guid><description>The Guide explains how the ECB interprets applicable EU and national law on internal models, creating a level playing field across significant institutions directly supervised by European banking supervision. It was originally developed through TRIM, a large-scale project (2016-2021) combining detailed methodological work with roughly 200 on-site internal model investigations at 65 institutions, and covers credit risk, market risk, and counterparty credit risk models along with general model governance topics.</description></item><item><title>EIOPA Guidelines on the use of internal models</title><link>https://modelriskdirectory.com/frameworks/eiopa-guidelines-internal-models/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/eiopa-guidelines-internal-models/</guid><description>The EIOPA Guidelines support national supervisory authorities and insurance or reinsurance undertakings applying Solvency II internal-model requirements. They focus on models used to calculate all or part of the Solvency Capital Requirement and the governance needed to show that a model is embedded in decision-making, understood, documented, validated, and controlled. They are narrower than an enterprise-wide model inventory regime, but highly relevant to insurers&apos; capital-model governance, validation, change, data, and use-test evidence.</description></item><item><title>HKMA CA-G-4: Validating Risk Rating Systems under the IRB Approach</title><link>https://modelriskdirectory.com/frameworks/hkma-ca-g-4/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/hkma-ca-g-4/</guid><description>CA-G-4 is a current module of the HKMA Supervisory Policy Manual for validating risk-rating systems under the internal-ratings-based approach. It applies to authorized institutions using or seeking approval to use IRB approaches for credit-risk capital. The module addresses governance, responsibilities, model design, data, discriminatory power, calibration, overrides, benchmarking, backtesting, stress testing, validation independence, documentation, and remediation. Broader enterprise risk governance sits in other HKMA modules, including IC-1.</description></item><item><title>MAS Artificial Intelligence Model Risk Management information paper</title><link>https://modelriskdirectory.com/frameworks/mas-ai-model-risk-management/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/mas-ai-model-risk-management/</guid><description>MAS published Artificial Intelligence Model Risk Management: Observations from a Thematic Review in December 2024 after reviewing selected banks. The paper focuses on AI and generative-AI model controls across governance, identification, inventory, materiality, development, validation, deployment, monitoring, and third-party use. MAS later consulted on broader AI risk-management guidelines and supported an industry toolkit. This page covers the 2024 information paper and clearly separates observed good practices from binding requirements or later consultation proposals.</description></item><item><title>OCC Bulletin 2011-12: Sound Practices for Model Risk Management</title><link>https://modelriskdirectory.com/frameworks/occ-2011-12/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/occ-2011-12/</guid><description>OCC Bulletin 2011-12, &apos;Supervisory Guidance on Model Risk Management,&apos; articulated the elements of a sound program for managing risk from quantitative models used in bank decision-making. Its text was substantively identical to the Federal Reserve&apos;s SR 11-7, reflecting that both agencies developed the guidance jointly, and it applied to national banks and federal savings associations supervised by the OCC.</description></item><item><title>OSFI Guideline E-23: Model Risk Management</title><link>https://modelriskdirectory.com/frameworks/osfi-e-23/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/osfi-e-23/</guid><description>The final E-23 guideline applies to Canadian federally regulated financial institutions, including banks, foreign bank branches, insurers, and trust and loan companies. It expands model risk management beyond deposit-taking institutions and explicitly addresses AI and machine-learning models. Expectations are proportional to the institution&apos;s size, strategy, risk profile, operational complexity, and interconnectedness. The guideline organizes requirements around enterprise-wide governance, risk-based classification, model lifecycle controls, review, deployment, monitoring, and decommissioning.</description></item><item><title>PRA SS1/23: Model Risk Management Principles for Banks</title><link>https://modelriskdirectory.com/frameworks/pra-ss1-23/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/pra-ss1-23/</guid><description>SS1/23 applies to UK-incorporated banks, building societies, and PRA-designated investment firms that have internal model approval to calculate regulatory capital requirements under Internal Ratings Based (credit risk), Internal Model Approach (market risk), or Internal Model Method (counterparty credit risk) approaches. It sets out five principles the PRA expects firms to embed as a strategic model risk discipline in its own right, comparable in spirit to SR 11-7/SR 26-2 but issued independently by the UK&apos;s prudential regulator.</description></item><item><title>SR 11-7: Guidance on Model Risk Management</title><link>https://modelriskdirectory.com/frameworks/sr-11-7/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/sr-11-7/</guid><description>Issued April 4, 2011 jointly with the OCC (as Bulletin 2011-12), SR 11-7 set out supervisory expectations for how banks should manage the risk that quantitative models produce incorrect or misused results. It organized model risk management around three pillars: model development, implementation, and use; model validation; and governance, policies, and controls, and introduced &apos;effective challenge&apos; as the guiding principle for meaningful independent review.</description></item><item><title>SR 26-2 / OCC Bulletin 2026-13: Revised Guidance on Model Risk Management</title><link>https://modelriskdirectory.com/frameworks/sr-26-2/</link><guid isPermaLink="true">https://modelriskdirectory.com/frameworks/sr-26-2/</guid><description>SR 26-2 (issued by the Federal Reserve as a Supervisory Letter, and simultaneously as OCC Bulletin 2026-13 and an FDIC Financial Institution Letter) reflects fifteen years of supervisory experience since SR 11-7 and updates model risk management expectations for a risk-based, tailored era. It is expected to be most relevant to banking organizations with over $30 billion in total assets. The guidance retains the three foundational pillars, model development and use, validation and ongoing monitoring, and governance and controls, while replacing SR 11-7&apos;s de facto annual review cycle with revalidation frequency tied to model materiality, change velocity, and data availability, and expanding attention to vendor and third-party models.</description></item><item><title>Top model risk management firms: sourcing a model risk management firm</title><link>https://modelriskdirectory.com/guides/top-model-risk-management-firms/</link><guid isPermaLink="true">https://modelriskdirectory.com/guides/top-model-risk-management-firms/</guid><description>Compare sourced model risk management, independent validation, quantitative risk, and actuarial advisory firms without fake rankings or paid review scores.</description></item><item><title>Best model risk management software: sourcing a model risk management firm</title><link>https://modelriskdirectory.com/guides/best-model-risk-management-software/</link><guid isPermaLink="true">https://modelriskdirectory.com/guides/best-model-risk-management-software/</guid><description>Compare sourced MRM software vendors by model inventory, workflow, validation, monitoring, evidence, integrations, security, and implementation fit.</description></item><item><title>Model Risk Management: sourcing a model risk management firm</title><link>https://modelriskdirectory.com/guides/model-risk-management/</link><guid isPermaLink="true">https://modelriskdirectory.com/guides/model-risk-management/</guid><description>What model risk management advisory firms actually do, what to verify before you retain one, RFP questions to ask, and red flags. Grounded in SR 26-2, SR 11-7, and OCC guidance.</description></item><item><title>Model Risk Management Framework: sourcing a model risk management firm</title><link>https://modelriskdirectory.com/guides/model-risk-management-framework/</link><guid isPermaLink="true">https://modelriskdirectory.com/guides/model-risk-management-framework/</guid><description>How to design or audit a model risk management framework under SR 26-2: inventory, tiering, governance, and validation structure. What to verify before you sign off.</description></item><item><title>Model Risk Validation: sourcing a model risk management firm</title><link>https://modelriskdirectory.com/guides/model-risk-validation/</link><guid isPermaLink="true">https://modelriskdirectory.com/guides/model-risk-validation/</guid><description>What independent model validation covers under SR 26-2/SR 11-7, methods used (conceptual soundness, benchmarking, outcomes analysis), and what to verify before you retain a validator.</description></item><item><title>OCC Model Risk Management: sourcing a model risk management firm</title><link>https://modelriskdirectory.com/guides/occ-model-risk-management/</link><guid isPermaLink="true">https://modelriskdirectory.com/guides/occ-model-risk-management/</guid><description>What OCC-supervised banks need to know now that OCC Bulletin 2011-12 was rescinded and replaced by Bulletin 2026-13. What to verify before an exam, and how to source a firm.</description></item><item><title>Model Risk Management Software: sourcing a model risk management firm</title><link>https://modelriskdirectory.com/guides/model-risk-management-software/</link><guid isPermaLink="true">https://modelriskdirectory.com/guides/model-risk-management-software/</guid><description>What MRM governance software actually does, how to evaluate model inventory and validation-workflow platforms, RFP questions, and red flags. Grounded in real vendor research.</description></item><item><title>SR 11-7 Compliance: sourcing a model risk management firm</title><link>https://modelriskdirectory.com/guides/sr-11-7-compliance/</link><guid isPermaLink="true">https://modelriskdirectory.com/guides/sr-11-7-compliance/</guid><description>SR 11-7 was rescinded April 17, 2026 and replaced by SR 26-2. What that means for your MRM program, what examiners now expect, and how to update your compliance approach.</description></item></channel></rss>