Skip to main content

How SR 26-2 Changes the Model Risk Playbook

Share

Revised interagency guidance gives large banks more room to tailor model risk management programs to their own size, complexity, and risk profile. That flexibility also places more weight on the institution’s ability to explain and defend its choices. 

During a recent ProSight Model Validation Consortium webinar, model risk expert Kevin Oden said the new SR 26-2 framework preserves the familiar structure of model development and use, validation, and governance. The regulatory posture, however, is now “principles-based rather than prescriptive.” 

For banks subject to the guidance, a few practical priorities follow: 

Calibrate oversight to actual risk. Institutions have more leeway to adjust the intensity of monitoring and validation depending on the model at hand. Low-risk or immaterial models may warrant lighter treatment than models with greater exposure or materiality. The key is being able to justify the distinction and document it clearly. As Oden put it, “The framework gives you flexibility, not a pass.” 

Think bigger than one model at a time. SR 26-2 places greater emphasis on aggregate model risk, including shared assumptions, common data sources, and upstream and downstream dependencies. A problem affecting one widely used input could create exposure across the inventory. Oden suggested treating aggregate risk as an overlay that captures those concentrations and connections. 

Demonstrate effective challenge. Validation independence is becoming less about organizational charts and more about the rigor of the work. “The quality of the validation process now really depends even more so on rigor and effectiveness rather than organizational structure,” Oden said. External and co-sourced validation arrangements can be defensible when validators have the expertise and authority to challenge model owners and developers. 

Create a plan for emerging AI. Generative AI, retrieval-augmented generation systems, and agentic AI are explicitly outside the scope of the revised guidance, while traditional machine learning models remain within it. Oden advised institutions to consider a separate AI governance policy, potentially including AI-specific board reporting, processes for evaluating AI capabilities embedded in third-party products, and alignment with the National Institute of Standards and Technology’s AI Risk Management Framework. 

Focus on targeted updates. Will Kutteh, director of ProSight’s Model Validation Consortium, said institutions appear more likely to make measured adjustments than wholesale program changes. Likely areas of attention include policy language, inventory definitions, validation methodologies, and governance structures. Oden encouraged institutions to update references to older guidance, adopt the terminology introduced by the revised framework, and reassess inventory classifications. 

The takeaway: SR 26-2 gives large banks an opportunity to remove unnecessary process burden and align oversight more closely with material risk. The responsibility to identify, understand, and manage that risk remains. In Oden’s words, “This is an opportunity to right-size, not retreat.

Related Articles

Login to View This Content

 

Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.