Responding to SR 26-2: From Strategic Interpretation to Practical Evidence | Part 3 of 4
Under SR 26-2, Misclassification Is the New Model Risk
When materiality determines rigor, classification becomes a first-order governance issue.
|
Series introduction The first two blogs in this series examined the strategic and operating-model implications of SR 26-2. Part 1 argued that the guidance places greater responsibility on institutions to defend their risk-based judgments. Part 2 considered where that shift creates operating flexibility, including the treatment of immaterial models, validation frequency, and the definition of a model. This third blog examines the governance risk created by that flexibility. When materiality determines the rigor applied to a model, classification becomes an important control decision that must be consistently applied, documented, and independently challenged. |
The risk did not disappear. It moved.
SR 26-2 keeps the core disciplines of model risk management—conceptual soundness, outcomes analysis, ongoing monitoring, effective challenge, the model inventory, documentation, and vendor validation—but removes much of the prescriptive sub-detail beneath them.
That changes where the risk sits. The examination emphasis is likely to shift toward the quality, consistency, and independence of the materiality classification itself, because that judgment now determines how much process every model receives.
The rewrite may be aimed as much at examiners as at banks
It is worth understanding whom the rewrite is really aimed at. As Risk.net reported, a former senior US bank regulator has argued that the rewrite is directed less at banks than at examiners. Some examiners, in his view, had been over-enforcing the old guidance, treating its contents as hard requirements and applying them to institutions whose size or model use did not warrant it.
If the rewrite is really aimed at examiners, then the line saying non-compliance will not draw criticism is not a new idea. He notes that US regulators had already made the same point. A 2018 interagency statement said supervisory guidance does not carry the force of law, and 2021 rules confirmed that breaking guidance cannot, by itself, lead to an enforcement action or a matter requiring attention (MRA).
If that view is right, the practical change for a well-run model risk function is smaller than the shorter page count implies. But the change in examiner posture is real, and it puts the classification methodology squarely in their line of sight.
Three ways the exposure changes
1. Classification becomes the audit target
Every model that is down-tiered needs to be defended. The classification methodology must be consistent and well documented, and it has to hold up against the obvious criticism that models were tiered down simply to cut the amount of work.
2. Misclassification is asymmetric
The risk here is lopsided. A model that is down-tiered but later proves material and performs poorly leaves the firm holding a documented decision to under-resource something that mattered. And SR 26-2 still states plainly that even a fundamentally sound model can carry high model risk if it is misapplied or misused.
Sensible tiering is worth doing; on average, its expected value is positive. The real danger lies in the tail: the rare cases where a down-tiered model turns out to be material and fails. Because those outcomes are so costly, borderline calls should lean conservative.
3. Classification cannot be a front-office convenience
SR 26-2 explicitly names the conflict it has in mind: misalignment of incentives between reporting lines such as model development and validation. A classification that lowers the rigor applied to a desk’s own model, decided by that desk alone, is exactly that conflict.
The materiality framework has to be jointly owned with the second line and itself subject to effective challenge.
Dropped prescriptions are not permission
SR 11-7 spelled out override analysis, code quality, change control, and process verification. SR 26-2’s text does not. It is tempting to read those omissions as deregulation. They are not.
The clearest signal sits in a footnote, and its placement understates its weight. Footnote 1 of SR 26-2 preserves the point that supervisory action can still result from violations of law, or from unsafe or unsound practices stemming from insufficient management of model risk.
That single footnote is where the guidance reattaches its teeth. The body of the document reads as permissive—non-enforceable, non-prescriptive, no supervisory criticism for non-compliance—and the footnote is the place where that permissiveness is bounded. A reader who absorbs the main text but skips the note comes away with a materially softer picture than the guidance supports.
A practice dropped from the guidance text is not a practice the supervisor has declared unnecessary. It is a practice whose calibration the guidance now leaves to the firm.
Documentation makes the transition reversible
The right response is deliberate, not passive. Firms should decide which SR 11-7 practices they will retain as internal standards—for example, change control, override monitoring, and benchmarking for material models—and write down why. Discontinuing any of them should be a documented decision with a rationale, not a quiet lapse because the new text fell silent.
There is a second reason to document the rationale, and it has little to do with this year’s examiners. As risk managers at large banks have pointed out, SR 26-2 reflects the supervisory philosophy of the current administration, and a future administration could take a different view or revert.
A firm that has documented why it retained or discontinued each practice can adjust deliberately if the regime shifts. A firm that quietly let practices lapse, with no record of the reasoning, will be reconstructing its framework from memory under time pressure. Documentation is not bureaucratic overhead here. It is what makes the transition reversible.
Three additional pressure points
Model reuse
SR 26-2 explicitly elevates the use of a model beyond its intended purpose as a named risk, calling for additional analysis of the new use and a review of existing controls. Repurposing a model across products, markets, or regimes is routine on a quant desk, which makes it a likely focus area for examiners. It warrants a hard reassessment trigger, not informal judgment.
Generative and agentic AI
SR 26-2 places generative and agentic AI outside its scope, while stating that the organization’s own risk management should govern such tools. The trap is reading “out of scope of the guidance” as “uncontrolled.” It is not.
If generative AI is entering research or pricing workflows, it needs a control regime built on the firm’s own framework, and that regime should exist before deployment scales, not after.
The carve-out should be read as a deliberate pause, not an endorsement of inaction. The agencies have signaled that a separate AI framework will come in time, and supervisors are reportedly watching how the largest banks design AI governance. That means the practices firms build now are likely to shape whatever regulators eventually commit to paper.
Senior practitioners have warned that treating the absence of guidance as a reason to wait is the real mistake. A firm that defers will be passive when the standard arrives, rather than having helped set it.
There is also a longer-term complication to anticipate. As AI works its way into core decisions such as stress testing and credit scoring, the line between an “AI tool” and a “model” will blur. Firms will face genuine ambiguity over which framework governs a given application, or whether both do. Building a coherent, firm-owned AI control regime now is the best hedge against that ambiguity later.
Provisional use
SR 26-2 allows a model to go into use before validation is complete where there is an urgent business need, provided its limitations are flagged and compensating controls are in place. That is real flexibility, and it is in the guidance text itself.
But it is an exception, not a shortcut. The risk is that “urgent business need” becomes the path of least resistance for any model a desk wants to put into production quickly. Provisional use should sit behind a defined governance gate—a documented limitation assessment, named compensating controls, and a hard deadline for completing validation—so the exception stays an exception.
What to actually do
The strategy follows directly from the diagnosis.
First, build a materiality classification framework that can be defended. SR 26-2 points the way with two factors. Exposure captures how much a model’s output affects business decisions, and the guidance notes it can be measured quantitatively, for example by portfolio size or business impact. Purpose is a qualitative judgment about what the model is for, with regulatory and financial-risk models generally treated as higher risk. SR 26-2 leaves it to each firm to decide how those factors are scored and combined. What matters is that the methodology is consistent and jointly owned with model risk and validation, so it holds up under challenge. This framework is the foundation, and it should be treated as the first deliverable, not an afterthought.
Second, re-baseline the model inventory against both the new framework and SR 26-2’s narrower definition of a model. Remove the tools that no longer meet that definition, assign tiers to the rest, and concentrate validation effort on the models that genuinely move P&L and capital.
Third, for stable models, shift revalidation away from a fixed calendar and toward a trigger-based approach, staying within the limits set by the firm’s own policy and any other applicable rules.
Fourth, document which SR 11-7 practices are being kept, and why. Require a mandatory reassessment before any model is reused. And build generative AI controls on the firm’s own framework.
The bottom line
SR 26-2 removed prescriptions. It did not remove accountability. If materiality determines rigor, then materiality classification itself becomes a governed process that needs independence, evidence, documentation, and challenge.
The firms that handle the transition well will be the ones that treat classification as a disciplined control, not an administrative label. The firms that struggle will be the ones that treat the silence of the new guidance as permission to let old controls fade without a defensible rationale.
Previous: Part 2 — Where SR 26-2 Creates Flexibility—and Where It Does Not
Next: Part 4 — When Monitoring Should Trigger Validation: A Practical SR 26-2 Case Study
- カテゴリ:
- Risk Management


コメント
コメントを残すには、ここ をクリックして MathWorks アカウントにサインインするか新しい MathWorks アカウントを作成します。