As at August 2026. This article is general commentary on publicly available regulatory material, not legal advice. Positions summarised here should be verified against the primary sources - the federal banking agencies, the PRA and the FRC - before being relied on.
Model risk regulation UK vs USA became a live comparison question on 17 April 2026, when the US federal banking agencies - Federal Reserve, OCC and FDIC - issued revised interagency guidance on model risk management. The Federal Reserve version is SR 26-2; the same text travels as an OCC bulletin and an FDIC financial institution letter. It supersedes SR 11-7, the 2011 guidance that defined the discipline for fifteen years, along with the 2021 supervisory letter on complex models. Anyone searching for the UK equivalent of SR 26-2 is really asking how three UK instruments - the PRA's supervisory statement on model risk management principles for banks (SS1/23), the FRC's technical actuarial standards (TAS 100 and the specialist standards), and the Solvency UK internal model permissions regime - line up against the new US baseline.
What SR 26-2 actually changes
Three shifts matter most, read against SR 11-7.
Materiality tiering is now explicit. The revised guidance formalises risk-based proportionality: validation intensity, documentation depth and revalidation frequency scale with a model's materiality and complexity, rather than a uniform expectation across the inventory. This legitimises what mature MRM functions already did, and pressures firms whose tiering was informal to defend it formally.
Evidence, not narrative. The revised guidance leans hard on demonstrable evidence - that validation conclusions, monitoring thresholds and override decisions be supported by artefacts an examiner can inspect, not by policy prose. The practical consequence is a shift of effort from framework documents to model-level evidence trails.
AI is acknowledged - and partly carved out. The guidance addresses machine learning within scope while explicitly noting that generative and agentic AI raise questions beyond it, with supplementary material anticipated. That carve-out matters: it leaves the fastest-moving model class governed by principles rather than specific expectations, a gap I have argued firms must fill internally in my article on agentic AI risk management.
The UK position: three instruments, one philosophy
The UK never had a single SR 11-7 analogue. SS1/23 gives banks five principles - model identification, governance, development and implementation, independent validation, and model risk mitigants - with board-level responsibility and a senior manager accountable for the MRM framework. It is principles-based where the US guidance is procedural, but the distance has narrowed: SR 26-2's tiering and evidence emphasis reads, from a UK desk, like the US guidance converging on outcome-focused proportionality while keeping its characteristic documentary depth.
For insurers and actuarial work, the load is carried by the FRC's technical actuarial standards - TAS 100's judgement, evidence and communication requirements apply to technical actuarial work wherever it sits, including models - and, for capital models, by the Solvency UK internal model framework, where model change policies, validation and use-test expectations function as a sector-specific MRM regime with regulatory pre-approval attached. UK insurers thus experience "model risk regulation" primarily through actuarial standards and internal model supervision rather than a dedicated MRM rulebook, though supervisory expectations increasingly read across from SS1/23.
The comparison that matters in practice
| Dimension | USA (SR 26-2 regime) | UK (SS1/23 + TAS + Solvency UK) |
|---|---|---|
| Instrument type | Interagency supervisory guidance | Supervisory statement (banks); professional/technical standards (actuarial); internal model permissions (insurers) |
| Style | Procedural, evidence-heavy, now tiered | Principles-based, accountability-led |
| Individual accountability | Institutional; examiner-enforced | Named senior manager under SM&CR |
| AI treatment | ML in scope; GenAI/agentic explicitly deferred | Technology-neutral principles; no AI-specific rules |
| Insurers | Guidance addressed to banking organisations; read-across by examiners and state expectations | TAS apply directly to actuarial work; internal models supervised under Solvency UK |
Two asymmetries deserve attention from dual-regime groups. First, accountability: the UK attaches model risk to a named individual through the senior managers regime, which the US guidance does not replicate - so a group can satisfy US evidence expectations while leaving its UK accountability map underspecified, and vice versa. Second, scope texture: TAS bite at the level of work, not institutions, so UK actuarial models carry obligations even where no banking-style MRM framework reaches them.
What dual-regime firms should do now
Map the group MRM framework once against both regimes, at the level of requirements rather than headings - tiering criteria, validation evidence, monitoring artefacts, accountability. Run a gap analysis specifically on SR 26-2's evidence standard: most UK-headquartered frameworks are principles-compliant but artefact-light by the revised US expectation. Assign the GenAI/agentic gap to an internal standard now, since both regimes currently defer it. And date-stamp the whole exercise: supplementary US material on AI is anticipated, UK supervisory statements evolve, and this comparison - as at August 2026 - will not stay current unattended.
Key Takeaways
- SR 26-2 (17 April 2026) supersedes SR 11-7 as the US interagency model risk baseline, formalising materiality tiering and a demonstrable-evidence standard, while explicitly deferring generative and agentic AI.
- The UK spreads equivalent expectations across SS1/23 for banks, FRC technical actuarial standards for actuarial work, and Solvency UK internal model supervision for insurers.
- The regimes are converging in substance - proportionality, validation, governance - but differ in style (procedural vs principles) and in the UK's named-individual accountability under SM&CR.
- Dual-regime groups should gap-analyse against SR 26-2's evidence standard and close the shared GenAI/agentic gap with internal standards.
- Regulatory positions summarised as at August 2026; verify against primary sources before reliance.
Frequently Asked Questions
What is SR 26-2? Revised interagency guidance on model risk management issued by the Federal Reserve, OCC and FDIC on 17 April 2026, superseding SR 11-7. It formalises risk-based tiering of validation and documentation, raises the evidential bar for model risk decisions, and notes that generative and agentic AI raise questions to be addressed further.
What is the UK equivalent of SR 26-2? There is no single equivalent. For banks, the PRA's SS1/23 sets principles for model risk management with senior-manager accountability; for actuarial work, the FRC's technical actuarial standards apply; and for insurers' capital models, the Solvency UK internal model regime imposes validation, change-control and use-test expectations.
How does SR 26-2 treat AI models? Machine learning models are within scope and subject to the same lifecycle expectations as other models, but the guidance explicitly acknowledges that generative and agentic AI raise questions beyond its current scope, with further supervisory material anticipated - leaving firms to set internal standards for those systems in the interim.