Skip to main content
    Regulatory alignment · Model risk and validation

    The cadence stopped being prescribed. The drift did not stop.

    Validation is not a milestone, it is a lifecycle. A model validated in March is not the model answering in June if the provider shipped in between, and the question a validation team has to answer is whether anyone would know.

    The validation lifecycleThe registry of recordWhere it maps

    No compliance claim. iTmethods makes no compliance, certification or accreditation claim under SR 26-2 or any other framework named on this page. We are not certified against, accredited for, or approved under any of them. Alignment is not compliance. The determination belongs to your own risk function, and nothing here transfers it to us.

    The validation lifecycle

    Pre-deployment to decommissioning, instrumented throughout.

    Every phase produces evidence, and the phases that produce none are the ones that fail an examination.

    Validated

    What was tested, against what, and what the result was. Held as a record rather than reconstructed from a validator’s notes when someone asks.

    Where does your last validation live?

    Versioned

    Which version of which model was in production on a given day. Without that, a finding about behavior cannot be tied to the thing that produced it.

    Could you answer that for last quarter?

    Change-controlled

    Prompt revisions, routing changes and policy edits are model changes. Under change control they are events; outside it, the validated model and the running model drift apart quietly.

    Who can change one today?

    The registry of record

    What is allowed to run, and on whose authority.

    A model inventory that lists what exists is a document. A registry that governs what may run is a control.

    The distinction matters at examination. An inventory tells a regulator what you believe you have. A registry tied to the path tells them what actually ran, which is the question that gets asked second and answered badly.

    Where it maps

    The obligations these frameworks share.

    SR 26-2, the EU AI Act and the NIST AI RMF ask for different documents and much the same underlying evidence.

    SR 26-2, issued 17 April 2026 by the Federal Reserve, the OCC and the FDIC, supersedes SR 11-7 and SR 21-8. On generative and agentic systems it is explicit:

    “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.”

    That gap is where most validation teams are currently working, and it is why evidence produced by the path matters more than evidence assembled for the file. The guidance still expects an institution to apply its own governance to the tools it leaves out.

    The assessment against any of these rests with your validation function and your examiners. Reign produces the operating record their judgment draws on.

    Reign is aligned to SR 26-2 and to the wider model risk expectations named on this page. It is not certified against them, no product can be, and no product makes an institution compliant with them. No authority responsible for them endorses, approves or recommends Reign or iTmethods.

    Next step

    Bring us a model you have to revalidate.

    We will look at what evidence exists across its lifecycle today, and where the gap between the validated model and the running one actually opens.