Frameworks / SR_26_2
SR 26-2 — Model Risk Management
Federal Reserve / OCC · US · effective 2026-04-17 · SR_26_2
Replaced SR 11-7. Explicitly excludes generative and agentic AI as novel and rapidly evolving — the exclusion is the gap this registry addresses. VERIFY the citation before external use.
4 controls, mapped to the evidence that satisfies each
Every control links to the dimension whose evidence would satisfy it. That mapping is the working link between an obligation written in law or a standard and a document somebody has to produce. Each row has its own address: link to a single control.
| Control | Title | Requirement | Satisfied by |
|---|---|---|---|
| III.B | Effective challenge | Independent, informed, incentivised challenge of model design and outcomes. | D2 |
| V.A | Validation independence | Validation carried out with rigour and free of misaligned commercial incentive. | D2 |
| II.A | Model definition and inventory | Model inventory covers every model in use, with owner and version. | D6 |
| IV.C | Ongoing monitoring | Performance tracked against benchmarks with escalation thresholds. | D6 |
What this mapping is, and what it is not
It is a reading of a published instrument, with each control cited to its source, mapped to the kind of evidence that would satisfy it. It is not legal advice, not a certification, and not a statement that any organisation complies with anything. Where an instrument is not yet in force, this page says so rather than selling urgency.
Talk to the person who built this
If you assess clients against this instrument, the mapping is the part you can check line by line. There is no sales team: this is founder-led, so it reaches the founder directly. Tenant access is $500 a month, and free early access to the method, the corpus and the router is on offer first if that is useful. If it is not a fit, saying so costs you one reply.