Who this entry is for — Anyone who uses estimates, signals, valuations or risk measures to make decisions and wants to control not only the calculation, but the full path from data through model and output to use.
The 2026 joint guidance from the Federal Reserve, OCC and FDIC defines model risk as the potential for adverse financial consequences associated with models that may result from decisions based on their output.
A model is a simplified representation. It transforms data through theories, assumptions and methods to produce estimates. Because it selects and simplifies, it can be useful without being a complete description of reality.
In plain terms — A model can calculate exactly what it was built to calculate and still support a fragile decision if the data, purpose, conditions or interpretation are unsuitable.
Model risk is more than model error
| Source | Example |
|---|---|
| Data | Incomplete sample, information unavailable at decision time, poor quality or representativeness |
| Assumptions and method | Distribution, dependencies or dynamics unsuited to the phenomenon |
| Development and implementation | Wrong formula, bug, mapping or version inconsistent with documentation |
| Valuation | Payoffs, prices, costs or liquidity represented inadequately |
| Use | Model applied beyond its original scope, horizon or purpose |
| Interpretation | Output treated as certainty, a hard limit or an automatic recommendation |
| Governance | Roles, challenge, inventory, changes or incidents left untracked |
A model error is therefore one possible source of model risk, not a synonym. The 2026 guidance notes that even a fundamentally sound model producing output consistent with its design objective can carry high risk when misapplied or misused.
For example, a VaR correctly calculated over a calm window may be unsuitable as the only limit during a regime change. Data and use can be the issue even without an arithmetic error.
Materiality and proportionality
The amount of control does not come from a universal calendar. It depends on:
- inherent risk: complexity, assumptions, data quality and constraints;
- exposure: how much output and resulting decisions affect capital or activity;
- purpose: the importance of the function supported by the model;
- use: people, processes, automation and opportunities for misuse;
- aggregate dependencies: data, methods or assumptions shared across models.
More material models warrant more rigorous challenge and controls. Models that share a dataset or assumption can fail together, so an inventory needs an aggregate as well as an individual view.
Control across the lifecycle
- Purpose and intended use — Describe the decision, users, output, limitations and conditions in which the model should not be used.
- Development and testing — Document data, selection, assumptions, method, implementation and relevant out-of-sample or out-of-time tests.
- Validation — Assess conceptual soundness, reliability, limitations and outcomes analysis with appropriate expertise and objectivity.
- Before use — The guidance treats validation before first use as the general practice. Any exception calls for limits, communication and stronger controls, not implied approval.
- Ongoing monitoring — Compare outputs with outcomes and assess changes in performance, data, products and markets.
- Change and remediation — Track overlays, recalibration, versions, exceptions, corrections and model retirement.
- Governance — Assign owners, approvals, independent challenge, escalation, inventory and documentation.
Validation and monitoring frequency and depth depend on purpose, methodology, changes, data availability and materiality. A monthly or annual check is not sound by definition merely because it recurs on a calendar.
Third-party models and connected tools
Buying data, parameters or a model does not transfer the duty to understand risk and limitations to the vendor. Proprietary code or methodology can reduce transparency, but assessment, validation, outcomes monitoring and control of customisation remain necessary.
Overfitting, data leakage and weak robustness are important sources, but they do not exhaust model risk. Use, exposure, dependencies, interpretation and governance remain.
SR 26-2 covers traditional quantitative models and non-generative, non-agentic AI; generative and agentic AI are outside its scope. That source boundary does not imply those tools are risk-free, but it prevents treating them as automatically governed by the same guidance.
What validation does not prove
- it does not show that the model represents every future regime;
- it does not eliminate material residual model risk;
- it does not authorise use outside scope;
- it does not replace benchmarks, informed judgement and complementary analysis;
- it does not turn an output into an automatic decision.
Typical mistake — Reducing control to “the code runs” or “the backtest passes”. Development, use, limitations, monitoring and governance are parts of the same risk.
Scope of the institutional source
SR 26-2 was issued on 17 April 2026 and supersedes SR 11-7. It is risk-based supervisory guidance described as most relevant to banking organisations with more than USD 30 billion in total assets; it is not a universal requirement for every trader. This entry uses it as an institutional reference for definitions and the control lifecycle.
Sources
- Federal Reserve — SR 26-2, Revised Guidance on Model Risk Management
- Federal Reserve, OCC and FDIC — Supervisory Guidance on Model Risk Management, SR 26-2 attachment