By framework

Meet SR 26-2 with Yields

SR 26-2 moves US model risk management away from static checklists and toward dynamic, interconnected orchestration. Yields gives banks a configurable platform to operationalise their own policies, map risk across the model landscape, and keep a transparent audit trail throughout the lifecycle.

Trusted by leading financial institutions including HSBC, BNP Paribas, Euroclear, and Banco do Brasil.

The context

What SR 26-2 changes

SR 26-2 is the revised supervisory guidance on model risk management issued by the US banking agencies, the Federal Reserve, the OCC, and the FDIC, replacing the long-standing SR 11-7. The foundational pillars of MRM remain, but the emphasis shifts from a checklist mentality to expert risk judgment. There are no prescriptive standards. Instead, practices must be tailored to an institution's specific nature, scale, and risk profile.

That shift has direct consequences for your tech stack. Rigid frameworks with hard-coded workflows, business logic, and risk tiering become a liability. Model risk must be assessed in aggregate, not just model by model. Validation intensity is calibrated to materiality rather than a fixed annual cycle. And the model inventory needs to work as a relational knowledge base, not a flat spreadsheet. That is where Yields comes in.

Tailored, not prescriptiveAggregate risk, not model-by-modelMateriality-driven validationA relational inventory, not a flat list

The Yields approach

How Yields supports the transition to SR 26-2

Meeting SR 26-2 expectations requires more than a document repository or a static inventory. It requires a platform built around flexibility, interconnectivity, and auditability. Yields is designed as a configurable orchestration engine, so institutions can operationalise their own policies, map dependencies across the model landscape, and maintain a transparent audit trail throughout the lifecycle. Whether you are a Tier 1 bank with a mature MRM framework or a smaller institution scaling up governance, Yields is built to evolve alongside your risk profile. Here is how it maps to the shifts SR 26-2 introduces.

01

Extreme configurability, not a rigid mould

SR 26-2 expects practices tailored to each institution, with no one-size-fits-all standard. Yields is built as a highly configurable orchestration engine, so you can centralise best practice while tailoring business logic, workflows, and risk tiering to your own internal policies. The platform evolves as your risk profile changes, rather than forcing you into a vendor's fixed structure.

02

Aggregate risk through a dependency graph

The guidance emphasises assessing model risk in aggregate, not just individually. A flat inventory cannot do this. Yields treats the model inventory as a web of interconnected, relational objects, so you can trace the lineage of risk across the enterprise and quickly spot where a shared data source or assumption could impact multiple downstream models.

03

An inventory that works as a knowledge base

SR 26-2 expects constructive engagement between developers, users, and business managers throughout a model's life. Yields functions as a centralised knowledge base accessible to all stakeholders, not a gated system for validators alone, so insights and limitations raised during development flow directly into monitoring plans and user-facing dashboards.

04

A unified view across the “shadow AI” perimeter

SR 26-2 leaves generative and agentic AI outside its specific scope, while traditional models that feed into or receive inputs from those systems stay firmly in scope. Yields supports a multi-governance mode, maintaining a comprehensive inventory that accommodates different validation paths for novel AI systems while giving MRM and AI or data science teams a shared, unified view of the risk perimeter, so no governance gaps open up.

05

Exception-based workflows for urgent business needs

The guidance recognises that urgent needs may require using a model before formal validation is complete, with temporary controls in place. Yields supports exception-based workflows that allow pre-validation use while automatically enforcing strict monitoring, stakeholder notification, and exception tracking, so “temporary” use never quietly becomes permanent without oversight.

06

A workflow engine that tracks effective challenge

SR 26-2 shifts the focus from structural independence to the quality and impact of the challenge itself. Yields acts as a workflow engine rather than a document repository, tracking the full challenge dialogue and creating a transparent, non-erasable audit trail of validator queries and developer remediations, whatever your organisational structure looks like.

07

Black-box testing for vendor models

For proprietary vendor models, the guidance shifts the focus from code review to ongoing outcomes analysis and monitoring. Yields provides specialised support for black-box testing, with automated outcomes analysis and standardised quantitative tests that benchmark vendor outputs against internal challenger models or real-world data to detect deterioration early.

Configurable, interconnected, and auditable. Yields turns SR 26-2's expectations into a framework that evolves with your organisation.

Request a demo

Why one platform matters

One framework for a multi-jurisdiction reality

SR 26-2 rarely stands alone. Institutions operating across borders also answer to frameworks that take very different approaches, from Canada's lifecycle-driven OSFI E-23 to the UK's SS1/23 and the EU AI Act. A single model can fall under a narrow, materiality-driven scope in the US and a strict, all-model lifecycle in Canada at the same time.

Forcing these regimes into one rigid framework breaks down fast, and running them as separate silos creates duplication and constant reconciliation. The Yields Multi-Governance framework structures the complexity instead of flattening it. Its Triplet architecture, Model x Usage x Governance, lets a single model carry multiple governance lenses without ever being duplicated. Core model information lives once as a single source of truth, while each regime keeps its own attributes, workflows, and lifecycle. The result is clear oversight across borders, far less manual reconciliation, and validation work that can be reused from one regime to the next.

SR 26-2OSFI E-23SS1/23EU AI ActISO/IEC 42001NIST AI RMFDORA

Why Yields

From compliance to performance

SR 26-2 reinforces that model risk management is not a technical exercise. It is a multidisciplinary effort that requires sound judgment and robust technology. As technology becomes the backbone of MRM, the focus shifts from checking the box to using these systems to drive better risk decisions. A platform that acts as a flexible orchestration engine, like Yields, is designed to operationalise your unique internal policies and ensure your MRM framework can evolve seamlessly with your organisation's risk profile.

Configurable orchestration engine, built for Tier 1 and scaling institutions alike

Model risk management and AI governance on one platform

Trusted by HSBC, BNP Paribas, Euroclear, and Banco do Brasil

Turn SR 26-2 into defensible risk judgement

Yields helps you move from rigid checklist compliance to structured, defensible risk judgment, with the configurability to operationalise your own policies and the auditability to prove you are in control. Built to evolve with your risk profile, whatever the regulator asks next.