Contact us
Global

Optimising models for decision-making: navigating evolving model risk management requirements

28 September 2026 | Written by Lucy Worsley

4 minute read

The new regulatory context for model risk management

On 17 April 2026, the US banking agencies, the Federal Reserve, the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC), issued revised interagency Supervisory Guidance on Model Risk Management (SR 26-2). It replaces the 2011 guidance (SR 11-7) and rescinds the 2021 interagency statement on model risk management for BSA/AML systems. The update recognises advances in technology and the growing reliance on models to maintain competitive advantage.

Against this backdrop, 4most’s three pillars of robust model risk management, Culture, Innovation, and Efficiency, provide a forward-thinking ethos that aligns closely with both the new US guidance and the PRA’s existing SS1/23 principles. When embedded effectively, these pillars help firms robustly manage model risk in a way that protects profitability rather than eroding it.

Shared risk-based philosophy across the US agencies and the PRA

At the heart of both regimes sits a shared understanding: the relevance of model risk depends on the nature, scale and use of the model in relation to the business risks it supports. A model is inherently risky, and the same model can carry very different risk profiles across firms. As a result, there is no single “right” framework for model risk management. Proportionate judgement is essential, and this is where efficiency becomes central: firms need a framework that directs ownership, validation and monitoring effort to the models that pose the greatest risk to decisions and outcomes.

While there is broad alignment in principles, differences emerge in how each regime defines a “model”. The revised US guidance defines a model as a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates, explicitly excluding simple arithmetic calculations (such as those within spreadsheets) and deterministic, rule-based processes with no underlying statistical, economic, or financial theory.

Both regimes support a risk-based, proportionate approach: effort should be focused on the models that matter most. While the two regulators take different approaches to identifying material models, they share a common view that both individual model risk and aggregate risk across the wider model landscape must be continually assessed and managed, supported by an appropriate model inventory.

Differences between the US guidance and PRA SS1/23

Where the regimes differ most clearly is in scope, definition, and supervisory approach. The US guidance is expected to be most relevant to banking organisations with over USD 30 billion in total assets, though it may also apply to smaller firms with significant model-risk exposure, is stated to be non-binding. By contrast, SS1/23 applies to UK banks, building societies and PRA-designated investment firms that hold internal model approval to calculate regulatory capital, for credit risk (IRB), market risk (Internal Model Approach) or counterparty credit risk (Internal Model Method), and, once a firm is in scope, its expectations cover all of that firm’s models regardless of type. In-scope firms are expected to self-assess against the principles and remediate any gaps, applied proportionately.

The PRA’s principles are deliberately technology-agnostic, extending to novel and evolving techniques including artificial intelligence and machine learning. The revised US guidance, by contrast, expressly places generative AI and agentic AI outside its formal scope, though the agencies have signalled that they intend to consult further on AI, and supervisors and internal audit teams are already applying model risk principles to AI systems by analogy. This underlines the importance of responsible innovation: firms need frameworks that can accommodate new modelling techniques before regulation becomes fully prescriptive.

There is also a distinction in how each is enforced. The US guidance is explicitly non-binding: the agencies state that it does not set out enforceable standards or prescriptive requirements, and that non-compliance will not, in itself, result in supervisory criticism. By contrast, SS1/23 forms part of the PRA’s supervisory expectations, requiring firms to demonstrate that their model risk management framework is appropriate and effective, with gaps typically leading to supervisory challenge and remediation.

Key components of the guidance and links to SS1/23

Model development and use

Strong user engagement is critical, both during development and implementation. This engagement is central to understanding model outputs, particularly when results are unexpected. Testing should be aligned to model complexity, and the boundaries of acceptable performance should be clearly defined. Where models are used beyond their intended scope, additional controls are required. What the model is, how it was built, and how it is used all remain fundamental questions.

Model validation and monitoring

Validation is a proportionate and recurring activity that provides independent insight, enables effective challenge, and supports agreement of remediation steps. Model owners and developers in the first line own their models’ limitations and boundaries of performance, communicating them through ongoing monitoring and linking them to risk appetite, while independent validation is responsible for critically assessing those limitations and ensuring they are clearly identified and reported. When validating, it is important to understand your audience, including regulatory perspectives, so that key messages land correctly.

Governance and controls

Governance policies and processes should be informed by the sophistication of model use and the size and complexity of the organisation. Clear accountability is essential: all stakeholders must understand their roles, with responsibilities formally documented and conflicts of interest explicitly identified and managed. This is where culture becomes critical, because effective model risk management depends on people consistently escalating limitations, applying challenge, and treating documentation as part of decision governance rather than as an administrative exercise. Documentation is not merely a record of model development for replication purposes; it underpins continuity, supports informed challenge, and enables oversight. Likewise, the model inventory must provide sufficient transparency to manage model risk both at the level of individual models and across the aggregate model landscape.

Vendor and third-party models

Both the PRA and the US agencies are clear that vendor and third-party models are not immune from model risk. Despite their proprietary nature, they must be validated, monitored, and subjected to outcome analysis to ensure they remain understood and fit for purpose.

From compliance to better decisions

Ultimately, effective model risk management is not about adding more controls, it is about the right controls, better decisions, and enhanced outcomes. Model risk management regulation in both the UK and the US is principles-based rather than prescriptive, but each carries a common requirement: understand the risk that models present and apply proportionate controls.

Firms that build a strong culture, embrace innovation responsibly, and apply controls efficiently are better placed to navigate the evolving model risk management landscape. Culture ensures that accountability and effective challenge are embedded in day-to-day decision-making. Innovation keeps frameworks relevant as models and technologies continue to evolve. Efficiency helps firms maintain controls that are proportionate, practical, and commercially sustainable. Together, these pillars enable firms to meet regulatory expectations while using model risk management as a source of strategic advantage.

Get in touch

Get in touch if you would like to discuss how we can support the optimisation of your organisation’s model risk management strategy: info@4-most.co.uk.

 

 

 

 

 

 

Authors

Download our best practice guidance for MRM today

Read guide