Model Risk

Two Systems, One Problem: How the UK and US Regulate Model Risk in 2026

SR 26-2 superseded SR 11-7 in April 2026. The UK spreads the same obligations across PRA statements, FCA rules and Technical Actuarial Standards. What actually differs, and what a dual-jurisdiction framework should look like.

By Jonas Osman AbdelghafourPublished 4 August 2026

For fifteen years, transatlantic model risk conversations had a shortcut. Someone would say "SR 11-7" and everyone in the room, on both sides of the ocean, knew what was meant. The 2011 Federal Reserve guidance became the de facto global reference for model risk management — cited in UK board papers, European validation reports and Asian regulatory submissions by institutions that were never subject to it.

That shortcut expired on 17 April 2026, when the Federal Reserve, the OCC and the FDIC jointly issued SR 26-2, superseding both SR 11-7 and the 2021 interagency statement on model risk management for BSA/AML systems. The same document was published as OCC Bulletin 2026-13 and FDIC FIL-15-2026 — one framework, three agencies.

Firms operating on both sides now need to understand not just what changed in the US, but how the two regimes differ structurally. They differ more than most people assume, and the differences are widening rather than converging.

*This article discusses regulatory frameworks in general terms and is not legal advice.*

What Changed in the US

SR 26-2 is roughly half the length of its predecessor and reads very differently. Five changes matter operationally.

Proportionality is now explicit. Expectations are scaled to the size, complexity and model risk profile of the institution. SR 11-7 was applied broadly and uniformly in practice; SR 26-2 states plainly that rigour should follow materiality. The guidance is most relevant to banking organisations above roughly $30 billion in total assets, giving smaller and regional institutions a clearer basis for a lighter framework.

The definition of "model" has narrowed. Simple arithmetic spreadsheets, deterministic calculators and rule-based software may now fall outside formal model risk management scope. Most institutions will see their inventories shrink. This is a sensible reallocation of second-line effort — applying statistical validation to a discount calculator was always a misallocation — but it puts the burden on the firm to defend where it draws the line.

Annual revalidation as a default is gone. Validation cadence is now tied to model materiality and risk rather than to the calendar. High-materiality models keep or deepen the rigour SR 11-7 applied. Low-materiality models can move to lightweight monitoring with defined escalation triggers.

Effective challenge is decoupled from reporting lines. SR 11-7 was widely read to require organisational separation between developers and validators. SR 26-2 explicitly separates validation quality from where the validator sits on the org chart — what matters is accuracy, expertise, and the authority to force change.

Generative and agentic AI are explicitly out of scope. The agencies described these technologies as novel and rapidly evolving and placed them outside the guidance, while stating that a bank's existing risk management principles — materiality, ongoing monitoring, effective challenge — should govern anything outside the document's scope. The Federal Reserve has been soliciting input on appropriate governance approaches.

That last point deserves emphasis, because it is being widely misread. A carve-out from a specific supervisory letter is not a carve-out from supervision. The agencies' authority to act on unsafe or unsound practices is unaffected. What the carve-out actually means is that firms must construct their own defensible governance for generative and agentic AI without a rulebook to point at — a harder position, not an easier one.

The Structural Point Everyone Misses

Here is the sentence that reframes the whole comparison: SR 26-2 is explicitly non-binding.

Non-compliance alone does not trigger supervisory criticism. It is guidance describing sound practice, resting on the agencies' underlying authority to act against unsafe or unsound practices. Examiners and auditors treat it as the standard, but the instrument itself is not a rule.

This is characteristically American in a way that surprises people who assume US regulation is the more prescriptive of the two. The US approach is *detailed guidance under general statutory authority*. The UK approach — despite its reputation for principles — turns out to be, in several respects, the more binding one.

The UK Picture: Fragmented but Enforceable

The UK has no single equivalent of SR 26-2. Model risk obligations are distributed across at least four distinct sources, each with different legal force.

PRA supervisory statements. SS1/23 sets out model risk management principles for banks, covering identification, governance, development, validation and independent review. It applies to a defined population and carries supervisory expectation rather than direct rule status — the closest structural analogue to SR 26-2, but narrower in scope.

The FCA Handbook and Consumer Duty. Where models drive customer outcomes — pricing, creditworthiness assessment, claims decisions — SYSC systems and controls requirements and the Consumer Duty apply directly as rules. These are enforceable in a way supervisory statements are not.

Technical Actuarial Standards. The Financial Reporting Council sets TAS 100, which contains requirements for all technical actuarial work, supported by technical actuarial guidance on models and proportionality, plus TAS 200 for insurance and TAS 300 for pensions other than collective money purchase schemes. These bind through professional obligation: under the memorandum of understanding between the FRC and the IFoA, the IFoA requires the members to whom the standards are intended to apply to observe them.

Solvency UK and the model approval regime. For insurers using internal models, model governance is not guidance at all. It is a condition of a regulatory permission that can be varied or withdrawn.

Six Differences That Actually Bite

For a firm operating on both sides, these are the ones that create real work.

1. One document versus four sources. A US institution can hand an examiner a framework mapped to a single supervisory letter. A UK institution must map obligations across PRA statements, FCA rules, TASs and — for insurers — internal model conditions. UK model risk frameworks are correspondingly harder to write and harder to audit.

2. Individual accountability is far sharper in the UK. The Senior Managers and Certification Regime allocates model governance responsibility to a named individual with personal regulatory exposure. The US framework locates accountability with the board and senior management collectively. This single difference changes how model risk committees behave, how documentation is written, and how challenge is escalated.

3. The actuarial layer has no US federal counterpart. UK technical actuarial work is governed by FRC standards enforced through professional obligation, across insurance and pensions, regardless of the entity's prudential regulator. The US equivalent sits with the Actuarial Standards Board's Actuarial Standards of Practice and the qualification standards administered through the American Academy of Actuaries — professional rather than regulatory instruments, operating alongside state insurance regulation.

4. Proportionality is converging, from opposite directions. SR 26-2 has moved the US toward the tailoring the UK has always espoused. The UK, meanwhile, has moved toward more explicit expectation. The gap is narrowing — but the underlying legal architecture has not changed at all.

5. AI scope is handled inversely. The US carved generative and agentic AI *out* of its model risk framework pending further work. The UK has deliberately kept AI *inside* existing frameworks and declined to write AI-specific rules. Two opposite drafting choices reaching, for now, a fairly similar practical destination: govern it with what you have, and be prepared to defend it.

6. Insurance regulation is state-level in the US. There is no federal insurance prudential regulator. A US insurer's model governance obligations come from its domiciliary state and every state it writes in, coordinated but not unified through the NAIC. A UK insurer answers to the PRA and FCA. For a group operating across both, the US side is genuinely more complex, not less.

What a Dual-Jurisdiction Framework Should Look Like

Three design decisions save most of the pain.

Build to the strictest applicable standard, then document the delta. Maintain one framework calibrated to the highest bar across your footprint, with an explicit annex showing where each jurisdiction's requirements sit relative to it. Running parallel frameworks produces divergence within eighteen months, invariably.

Name individuals even where the regime does not require it. SM&CR forces this in the UK. Doing it voluntarily in the US costs nothing and materially improves governance quality. Collective accountability is, in practice, frequently no accountability.

Do not shrink the inventory just because you now can. SR 26-2's narrower model definition is an opportunity to reallocate effort, not to reduce it. A model removed from the inventory still produces numbers someone relies on. Move it to a lighter control tier with defined escalation triggers — do not move it into the dark.

The Underlying Shift

The most important thing about SR 26-2 is not any individual change. It is the shift in what regulators are asking.

SR 11-7 told institutions what to do. SR 26-2 asks them to defend what they choose to do, on their own terms. That is a considerably harder question, and it is the same question the UK regime has always asked through its principles-based construction.

The two systems remain structurally different. But they are now asking the same thing of firms: not *did you follow the rules*, but *can you justify your judgement*. Institutions that treated model risk as a compliance exercise will find that transition uncomfortable. Institutions that treated it as a discipline will barely notice.

Key Takeaways

  • SR 26-2, issued 17 April 2026 by the Fed, OCC and FDIC, superseded SR 11-7 and the 2021 BSA/AML model statement, introducing explicit proportionality, a narrower model definition and risk-based validation cadence.
  • SR 26-2 is explicitly non-binding guidance resting on the agencies' unsafe-and-unsound-practice authority, not a rule.
  • The UK has no single equivalent; obligations are distributed across PRA supervisory statements, FCA rules including the Consumer Duty, FRC Technical Actuarial Standards, and internal model permissions.
  • Individual accountability under SM&CR is the sharpest structural difference between the two regimes.
  • The US carved generative and agentic AI out of its model risk guidance; the UK deliberately kept AI inside existing frameworks — opposite drafting choices reaching similar practical outcomes.

Frequently Asked Questions

Does SR 26-2 replace SR 11-7 entirely? Yes. SR 26-2, issued jointly on 17 April 2026 by the Federal Reserve, OCC and FDIC, supersedes and replaces SR 11-7 (April 2011) and SR 21-8, the interagency statement on model risk management for BSA/AML systems (April 2021). It was published concurrently as OCC Bulletin 2026-13 and FDIC FIL-15-2026.

Is there a UK equivalent of SR 26-2? Not a single one. The closest analogue for banks is PRA supervisory statement SS1/23 on model risk management principles. Insurers using internal models are governed through the model approval regime, and actuarial work is subject to FRC Technical Actuarial Standards. UK model risk obligations are distributed rather than consolidated.

Does SR 26-2 mean generative AI is unregulated in US banks? No. The guidance places generative and agentic AI outside its scope while stating that existing risk management principles — materiality, ongoing monitoring and effective challenge — should govern systems outside that scope. Supervisory authority over unsafe or unsound practices is unaffected, so firms must build defensible governance without a specific rulebook to reference.

Related reading

See also Model Risk and Regulatory Compliance, or review qualifications.

About the author

Jonas Osman Abdelghafour is an actuary and risk expert advising insurers, banks and pension funds on model risk, regulatory compliance, financial crime and enterprise risk management across UK, EU and US regimes. He writes on where quantitative actuarial practice meets the governance, risk and compliance frameworks regulators expect boards to evidence. See qualifications and services, or get in touch to discuss an engagement.

Frequently asked questions

What Changed in the US?

SR 26-2 is roughly half the length of its predecessor and reads very differently. Five changes matter operationally.

What should risk leaders know about the Structural Point Everyone Misses?

Here is the sentence that reframes the whole comparison: **SR 26-2 is explicitly non-binding.**

What should risk leaders know about the UK Picture: Fragmented but Enforceable?

The UK has no single equivalent of SR 26-2. Model risk obligations are distributed across at least four distinct sources, each with different legal force.

What should risk leaders know about six Differences That Actually Bite?

For a firm operating on both sides, these are the ones that create real work.

What a Dual-Jurisdiction Framework Should Look Like?

Three design decisions save most of the pain.