What is the difference between PRA SS1/23 and SR 26-2?
SS1/23 is narrower in who it covers but broader in what it covers: it applies to UK banks with internal-model approval for regulatory capital, yet reaches "all types of models" used to inform business decisions, "regardless of technology", and names a Senior Management Function holder accountable for model risk. SR 26-2 addresses all US banking organizations but is "most relevant" above $30 billion in assets, narrows the model definition and places generative and agentic AI outside its scope.[1][2][3]
| PRA SS1/23 (UK) | SR 26-2 (US) | |
|---|---|---|
| Instrument | Prudential Regulation Authority Supervisory Statement 1/23, Model risk management principles for banks (May 2023; current version April 2026) | Revised Guidance on Model Risk Management — Federal Reserve SR 26-2 / OCC Bulletin 2026-13 / FDIC FIL-15-2026 (April 17, 2026) |
| Status | In force since May 17, 2024; updated Apr 23, 2026 | In force since Apr 17, 2026 |
| In the tracker | PRA SS1/23 · PRA AI/ML model-risk roundtable (Nov 2025) Authority: UK (BoE / PRA / FCA) | SR 26-2 · OCC Bulletin 2026-13 Authority: Federal Reserve, OCC |
How do the UK and US model risk frameworks differ?
| Dimension | PRA SS1/23 (UK) | SR 26-2 (US) |
|---|---|---|
| Issued by | The Prudential Regulation Authority; published May 17, 2023 and effective from May 17, 2024; current version published and effective April 23, 2026.[2] | The Federal Reserve, OCC and FDIC jointly, April 17, 2026, superseding SR 11-7.[4] |
| Which firms | UK-incorporated banks, building societies and PRA-designated investment firms "with internal model approval to calculate regulatory capital requirements"; firms without internal-model permission "may find the proposed principles useful".[1] | "Expected to be most relevant to banking organizations with over $30 billion in total assets", and to smaller banks with significant model risk exposure.[3] |
| Definition of a model | "A quantitative method that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into output"; inputs may be qualitative or expert judgement-based, and "the output can be quantitative or qualitative".[1] | "A complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates".[3] |
| Rules-based tools | Where material "deterministic quantitative methods such as decision-based rules or algorithms" that are not models are complex, firms "should consider whether to apply the relevant aspects of the MRM framework".[1] | The model definition "excludes simple arithmetic calculations, such as those found within spreadsheets, as well as deterministic rule-based processes and software where there are no statistical, economic, or financial theories underpinning their design or use".[3] |
| AI and machine learning | Applies to all models "regardless of technology". For "newly advanced approaches or technologies", tiering may weigh "alternative and unstructured data" and a model's "interpretability, explainability, transparency, and the potential for designer or data bias". The supervisory statement itself does not use the terms AI or machine learning; the PRA's publication page summarises this as a sub-principle on "identifying and managing the risks associated with the use of artificial intelligence in modelling techniques such as machine learning".[2][1] | "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance"; the principles apply to "non-generative, non-agentic AI models".[3] |
| Structure | Five principles: model identification and model risk classification; governance; model development, implementation, and use; independent model validation; model risk mitigants.[1] | Sections on model development and model use; model validation and monitoring; governance and controls; vendor and other third-party products.[3] |
| Accountability | "The board should approve the MRM policy and appoint an accountable individual"; firms allocate responsibility for the MRM framework "to the relevant SMF(s)" and update their Statements of Responsibilities.[1] | Calls for "clear roles and responsibilities with well-defined accountability"; the text does not name board or senior-management duties.[3] |
| Risk appetite | Governance through "a board that promotes an MRM culture from the top through setting clear model risk appetite".[1] | Materiality, set by model exposure and purpose, drives the rigor of oversight; banks "may deem certain models immaterial".[3] |
| Tiering and inventory | "A model inventory and a risk-based tiering approach" (Principle 1), including a firm-wide inventory; the tiering approach is itself subject to periodic validation or review.[1] | An effective inventory "includes sufficient information to understand model risks"; model risk is assessed through inherent risk and materiality.[3] |
| Validation | "A validation process that provides ongoing, independent, and effective challenge to model development and use"; the frequency of validation and re-validation is "commensurate with the associated model tier".[1] | Effective challenge by experts with "sufficient independence to maintain objectivity"; "The timing, nature, and frequency of validation activities vary" with model purpose, methodology and constraints.[3] |
| Model risk mitigants | Principle 5: policies for model risk mitigants when models under-perform, and "procedures for the independent review of post-model adjustments".[1] | A model that no longer performs as expected "may warrant overlays, adjustment, or redevelopment" under the bank's policy.[3] |
| Vendor models | Covers models "developed in-house or externally, including vendor models"; firms should satisfy themselves that vendor models "have been validated to the same standards as their own".[1] | Vendor products stay in scope: "the principles of model risk management remain applicable"; sound practice includes validating vendor products and understanding their "conceptual soundness, design, development data, and performance".[3] |
| Financial reporting | A report on the effectiveness of MRM for financial reporting should be available to the audit committee "on a regular basis, and at least annually".[1] | Model risk can lead to "errors in financial statements and reporting"; there is no audit-committee reporting expectation in the text.[3] |
| Supervisory force | The expectations "are not conditions for internal model approval"; firms newly permitted to use internal models have "12 months" to comply.[1] | The guidance "does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism".[3] |
What does a bank supervised in both the UK and the US need to reconcile?
- Keep one inventory with two scope flags: tools that are models under SS1/23's broader definition may fall outside SR 26-2's "complex" definition, and complex rules-based tools may still need SS1/23 treatment.[1][3]
- SS1/23 draws no line around generative AI (it applies to all models used to inform business decisions, regardless of technology), while SR 26-2 excludes generative and agentic AI; a bank under both needs to decide which generative tools meet the UK definition of a model.[2][1][3]
- Name an accountable SMF for UK model risk and record it in the Statement of Responsibilities; the US text asks for clear roles but names no individual.[1][3]
- Tier models on complexity factors that capture AI (unstructured data, explainability, bias) so the same tiering serves the PRA's expectations and the US materiality approach.[1][3]
- Use the PRA's AI/ML roundtable material as the closest UK statement on applying SS1/23 to AI; the US agencies' promised request for information has not yet appeared.[5][6]
When did each happen?
| Date | Instrument | Event |
|---|---|---|
| May 17, 2023 | PRA SS1/23 (UK) | PRA publishes SS1/23 (with PS6/23).[2] |
| May 17, 2024 | PRA SS1/23 (UK) | SS1/23 takes effect.[2] |
| Nov 24, 2025 | PRA SS1/23 (UK) | PRA publishes slides from two CRO roundtables (October 20 and 22, 2025) with 21 firms on applying SS1/23 to AI and ML.[5] |
| Apr 17, 2026 | SR 26-2 (US) | SR 26-2 / OCC Bulletin 2026-13 / FDIC FIL-15-2026 issued; SR 11-7 superseded.[4] |
| Apr 23, 2026 | PRA SS1/23 (UK) | Updated SS1/23 published and effective, following LIAF01/26.[2] |
| Apr 17, 2026 | SR 26-2 (US) | US agencies say they plan a request for information on model risk management and banks' use of AI "in the near future".pending[6] |
What is still open?
Is PRA SS1/23 the UK equivalent of SR 11-7 and SR 26-2?
It is the PRA's supervisory statement on model risk management for banks, covering the same ground as the US guidance: model identification, governance, development and use, independent validation and model risk mitigants.[1]
Which banks does SS1/23 apply to?
UK-incorporated banks, building societies and PRA-designated investment firms with internal model approval to calculate regulatory capital requirements. Other firms may find the principles useful but are not in scope.[1]
Does SS1/23 cover AI and machine learning models?
It applies to all models used to inform business decisions regardless of technology, and its tiering principle points to interpretability, explainability, transparency and bias for newly advanced approaches. The supervisory statement itself does not use the words AI or machine learning, though the PRA's publication page describes a sub-principle on AI in modelling techniques such as machine learning, and the PRA has discussed AI and ML under SS1/23 at CRO roundtables.[2][1][5]
Does SR 26-2 require a named accountable executive like the SMF under SS1/23?
No. SR 26-2 asks for clear roles and responsibilities with well-defined accountability; SS1/23 expects firms to allocate responsibility for the MRM framework to the relevant SMF holder.[3][1]
Do SS1/23 and SR 26-2 define a model the same way?
No. SS1/23 covers quantitative methods whose output can be quantitative or qualitative; SR 26-2 covers only complex quantitative methods producing quantitative estimates and excludes simple spreadsheet arithmetic and deterministic rule-based processes and software with no statistical, economic or financial theory underpinning them.[1][3]
When did SS1/23 take effect?
On May 17, 2024. The PRA published an updated version, effective April 23, 2026, following LIAF01/26.[2]
- Supervisory Statement SS1/23, Model risk management principles for banks (April 2026) — Bank of England, Prudential Regulation Authority, Apr 23, 2026
- SS1/23 – Model risk management principles for banks — Bank of England, Prudential Regulation Authority, May 17, 2023 · tracker page
- Supervisory Guidance on Model Risk Management (SR 26-2 attachment) — Federal Reserve Board, FDIC and OCC, Apr 17, 2026
- SR 26-2: Revised Guidance on Model Risk Management — Board of Governors of the Federal Reserve System, Apr 17, 2026 · tracker page
- The PRA holds model risk management roundtable on artificial intelligence and machine learning technologies — Bank of England, Prudential Regulation Authority, Nov 24, 2025 · tracker page
- OCC Bulletin 2026-13, Model Risk Management: Revised Guidance — Office of the Comptroller of the Currency, Apr 17, 2026 · tracker page
Every cell and answer on this page cites the official text it comes from; quotations are verbatim. Last reviewed Sep 24, 2026.
When either side of this comparison moves, the next morning's brief says so.
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning