Six supervisory regimes — covering every market a multinational bank or insurer is likely to operate in — independently require the same thing: the people who build a model must not be the only people who review it. Not as best practice. As a supervisory expectation, in force or dated, in every one of the six.
That much is checkable. What makes it worth writing down is the second fact: one of the six supervisors has already published that the separation is commonly absent in the institutions it supervises.
The requirement, in each regulator’s own words
| Jurisdiction | Instrument | The requirement |
|---|---|---|
| 🇨🇦 Canada | OSFI E-23, Principle 3.4 | “The model review process should be independent from model development.” |
| 🇬🇧 United Kingdom | PRA SS1/23, Principle 4.1(d)–(e) | “The validation function should operate independently from the model development process and from model owners” — and must have “sufficient organisational standing to provide effective challenge.” |
| 🇨🇭 Switzerland | FINMA Guidance 08/2024, §2.7 | Independent review must be “an objective, informed and unbiased opinion” on the application — and distinct from its development. |
| 🇺🇸 United States | SR 26-2 (Fed / OCC / FDIC), §III | Effective challenge requires “sufficient independence to maintain objectivity, as well as the organizational standing and influence to effect any change.” |
| 🇪🇺 Euro area | ECB guide to internal models (Feb 2024), §§15, 19 | “the effective independence of the internal validation function from the model development process (i.e. model design, development, implementation and monitoring)” — and “the staff of the validation function is separate from the staff involved in the model development process.” |
| 🇪🇺 European Union | AI Act, Art. 17(1)(b)–(d) | The quality management system must cover “design control and design verification” and “examination, test and validation procedures to be carried out before, during and after the development.” |
Six supervisory regimes, five legal traditions, five decades of institutional memory. One requirement.
The European Union appears twice on purpose. The AI Act is legislation about AI systems; the ECB guide is banking supervision about internal models. Different body, different instrument, different decade, different subject matter — and they arrive at the same control.
The requirement does not come from AI regulation — which is why it is durable
This is the part worth pausing on, because it inverts how most firms are approaching the subject.
Only two of the six are AI instruments at all. FINMA Guidance 08/2024 is AI-specific supervision, and the AI Act is AI legislation. The other four — OSFI E-23, PRA SS1/23, SR 26-2 and the ECB guide — are model-risk and capital-model supervision that would say the same thing if generative AI had never been invented. Two of them never use the phrase “artificial intelligence” at all: SS1/23 reaches complex “deterministic quantitative methods”, and the ECB guide is about internal models for capital. Hong Kong’s CA-G-4, quoted later, is the same shape.
And the instrument that defines independence most forcefully, SR 26-2, expressly excludes generative and agentic AI from its scope.
Sit with that. The sharpest statement of the requirement in the entire set is in a document that says it does not apply to your agent. The requirement was not reaching for AI. AI walked into it.
Which is why “we’re waiting to see how AI regulation settles” is the wrong posture. Four of these six do not depend on AI regulation settling, and three of the four are in force today.
So the requirement is not a feature of the current wave of AI legislation. It is older than that wave, it sits in prudential model-risk supervision, and it applies whether or not an AI statute ever arrives in your jurisdiction. A firm waiting for an AI law to tell it what to do has misread where the obligation lives — and a firm that treats AI Act readiness as the whole programme has scoped it to the one instrument of the six that is furthest from being in force.
Switzerland is the one that matters most, because it stopped describing the rule and described the gap
Every regulator tells you what should be true. FINMA published what it found:
“FINMA did not observe a clear distinction between the development of AI applications and the independent review in all cases.”
“It also observed that only a few supervised institutions carry out an independent review of the entire model development process by qualified personnel in order to consistently identify and reduce model risks.”
— FINMA Guidance 08/2024, §2.7
Read that as a supervisor would. It is not a warning about a future state. It is a finding about the present one, published by the authority that will be asking the question at the next examination. And Switzerland has no compliance date attached to it — the guidance is in force now, which means there is no runway to point at.
The ECB says it most plainly, and says why
If you read only one of the six, read this one. The ECB’s guide to internal models is the most explicit, and — for any bank supervised under the Single Supervisory Mechanism — the most operationally consequential:
“To ensure the effective independence of the internal validation function from the model development process (i.e. model design, development, implementation and monitoring), institutions should have appropriate organisational arrangements in place.” — §15
It then does something none of the others do: it explains the failure mode it is protecting against.
“A proper separation of the staff of the development function from the staff of the validation function enables institutions to limit the risk of conflicts of interest resulting in an ineffective challenge from the validation. To mitigate this risk, the institution should ensure that the staff of the validation function is separate from the staff involved in the model development process.” — §19
The control is not there to satisfy an auditor. It is there because a validator who was part of building the thing cannot effectively challenge it — and the ECB names that as a conflict of interest.
Then, in §15, it lists the organisational arrangements it will accept:
- separation into two different units reporting to different members of senior management;
- separation into two different units reporting to the same member of senior management;
- separate staff within the same unit.
Option 3 is the one worth noticing. The ECB is explicit that you do not need two boxes on an org chart — you need different people. Reporting lines are one way to achieve that and not the thing itself. The requirement bottoms out in staff separation, which is exactly the part of it that an org chart cannot evidence and exactly the part that a coding agent quietly removes.
Note also what this row does to the EU’s position. The AI Act is the instrument everyone is preparing for and the last one to arrive. The ECB guide has applied since February 2024. A euro-area bank with internal models has had a development-versus-validation separation requirement in force for over two years, entirely independent of anything the AI Act will eventually add.
Three regulators, three continents, reached for the same words
Put these side by side. The UK’s PRA, on what a validation function needs:
“sufficient organisational standing to provide effective challenge” — SS1/23, Principle 4.1(e)
The US agencies, on what an effective challenger needs:
“sufficient independence to maintain objectivity, as well as the organizational standing and influence to effect any change” — SR 26-2, §III
And Hong Kong’s HKMA, on who may validate a rating system:
“functionally independent of the staff and management functions responsible for developing the underlying rating systems … and have sufficient stature in the organisational hierarchy to challenge effectively the work of the rating system developers” — SPM CA-G-4, §5.1.6 (V.3, in force 18 July 2025)
Three regulators, three continents, independently drafted, converging on standing as the operative test. Not the org chart. Not the reporting line. Standing — the capacity to be listened to.
(Hong Kong is the one voice here that is not a row in the table above. Its instrument is narrower than the six in the table and I explain why further down — but on this particular point it is the clearest of the lot, so it belongs in the comparison.)
That last clause of the US text is the whole argument. A reviewer who cannot force a change is not a gate. They are a formality with a signature block. You can staff a second line, chart it, seat it in the right reporting line, and still fail this test — if the reviewer’s objection does not stop the change from shipping.
That is gate erosion described by two banking supervisors, in documents effective today, without either using the phrase.
Two further things about SR 26-2 worth knowing before you cite it:
- It supersedes SR 11-7. SR 26-2 was issued 17 April 2026 and replaces both SR 11-7 (2011) and SR 21-8 (2021). A model risk framework that still cites SR 11-7 as its authority is citing a superseded document. This is more common than it sounds: MAS’s own December 2024 information paper anchors its definition of validator independence to SR 11-7, in a footnote that was accurate when written and is not now.
- It excludes generative and agentic AI on purpose. Footnote 3 states that generative and agentic AI models “are not within the scope of this guidance” — while adding that the organisation’s own risk management and governance practices should determine appropriate controls “for any tools, processes, or systems not covered in this document.” The carve-out does not create an exemption. It hands the question back to you and asks what you did with it.
Two scope limits on the UK row, stated plainly
SS1/23 is the newest addition to this table and the easiest to over-read, so:
- It does not apply to everyone. §1.2 scopes it to UK-incorporated banks, building societies and PRA-designated investment firms with internal model approval for regulatory capital. Third-country firms operating in the UK through a branch are expressly out of scope, as are credit unions, insurers and reinsurers — though the PRA notes those firms “may find the proposed principles useful.”
- It does not mention AI. SS1/23 reaches models generally, and §2.5 extends the concern to “deterministic quantitative methods such as decision-based rules or algorithms” that have become complex. That is broad enough to cover AI in substance, but unlike OSFI E-23 — which expressly names “AI/ML methods” in its model definition — the UK gets there by construction rather than by naming.
Both limits are worth knowing before someone else points them out to you.
What these six instruments do not say
This is the part most people writing about AI and regulation get wrong, and getting it wrong is expensive: a compliance officer will find the overreach in the first meeting and discount everything else you said.
None of these six instruments requires you to produce evidence about AI-generated code. They regulate models and systems, not the tools used to author software. Anyone telling you the AI Act obliges you to prove a human reviewed each AI-written commit is selling you something that is not in the text.
The nearest genuine hooks are narrower and more interesting than the overreach:
- The AI Act’s technical documentation must describe “the methods and steps performed for the development of the AI system, including, where relevant, recourse to pre-trained systems or tools provided by third parties and how those were used, integrated or modified by the provider” (Annex IV, pt 2(a)).
- Its quality management system must cover “techniques, procedures and systematic actions to be used for the development, quality control and quality assurance” (Art. 17(1)(c)).
Those are real duties about how a system was built. They are not a code-provenance regime, and the distinction matters: the separation requirement is what six regulators actually say; code provenance is what people wish they said. Build the argument on the first and it survives scrutiny. Build it on the second and it does not.
Then there is the part no instrument addresses
Here the citations stop and my own reading begins, and I would rather label it than blur it.
Every one of these six requirements assumes development and review are performed by different parties, because when they were drafted they always were. That assumption is now doing load-bearing work it was never designed for. When an agent writes a change and an agent reviews it, the separation is satisfied on the org chart and defeated in substance — the same system, the same training, the same blind spots, appearing on both sides of a control that exists specifically to put unlike things on either side.
No regulator has said this about AI. It is an inference, and I am flagging it as one.
But it is a smaller step than it first appears, and two supervisors have already done most of the walking.
The ECB has already located the requirement in staff, not structure. Its §15 accepts “separate staff within the same unit” as a valid arrangement — the org chart is optional, the different people are not. So the question “are development and validation separated?” was never really a question about reporting lines. It was always a question about whether two different judgements were applied. An agent that writes and an agent that reviews satisfies zero of the ECB’s three arrangements, because all three of them bottom out in separate staff, and there is only one of it.
The HKMA has already ruled that reciprocity is not independence. The same module quoted above continues:
“However, to maintain the independence of the validation process, cross-validations, whereby two or more separate units validate the rating systems developed by one another, should be avoided.” — SPM CA-G-4, §5.1.6
Read what that rules out. Two units, each formally independent of the other, each validating the other’s work — and the regulator says no, because reciprocity is not independence. The org chart is satisfied; the control is not. That is the same failure this section is about, arrived at from a different direction, and written down by a banking supervisor about human teams years before anyone had to ask it about agents.
The extension to AI is mine, not theirs, and both instruments are about capital models rather than software. But put the two together and the shape is hard to miss: the requirement lives in separate staff (ECB), and it is not satisfied by two things of the same kind checking each other (HKMA). An institution arguing that an agent writing and an agent reviewing preserves independence is arguing against reasoning its own supervisors have already published — in a narrower setting, about people, but on precisely these two points.
The institutions that will answer this well are the ones already asking what their evidence of independence actually consists of.
Arriving, not yet arrived: Singapore — and a second Canadian instrument
Singapore belongs in the conversation but not in the table above, and the difference is worth being precise about.
- MAS Guidelines on AI Risk Management were issued for consultation on 13 November 2025. Comments closed 31 January 2026, the final text has not been issued, and MAS proposed a 12-month transition after issuance. They are a strong signal of direction and they are not yet a requirement.
- MAS Information Paper ID 18/24 (5 December 2024) is published and final — but it is expressly a “good practices” paper from a mid-2024 thematic review of selected banks, not a rule. What it observed is nonetheless the most useful sentence in it: most banks required independent validation only for AI of higher risk materiality, with peer review for the rest.
That is the second supervisor in this set to publish what it actually found rather than what it wants, and it found a partial separation — applied where materiality was high, relaxed where it was not.
Canada, meanwhile, is about to say it twice. OSFI’s draft ILAAP guideline (21 May 2026; consultation closes 19 August 2026) extends the same expectation into liquidity risk: institutions “should establish strong model governance frameworks for ILST and other liquidity risk models, in line with Guideline E-23 – Model Risk Management” (¶30), with supervisory reviews focused on “how institutions ensure independence and rigor in their validation processes” (¶31). It is a draft, so it earns a mention here and not a row in the table. But note what it does: it carries E-23’s separation requirement into liquidity models a full year before E-23 itself is in force. OSFI is not waiting for its own effective date, and neither should anyone reading this.
Why Hong Kong is quoted twice above but is not a sixth row
Because the honest answer is more specific than “yes” or “no.”
The HKMA has AI guidance for banks — the Big Data Analytics and AI guiding principles, and 2024 circulars on generative AI in customer-facing use — but those are built on fairness, transparency and accountability. They are not a model-risk independence regime. There is no HKMA model-risk-management module. If you find a secondary source citing one — I found several pointing at “SPM SB-1” — check it: SB-1 is Supervision of Regulated Activities of SFC-Registered Authorized Institutions, and has nothing to do with models.
What Hong Kong does have is CA-G-4, quoted twice above, which is a genuine and precisely-worded independence requirement — and is scoped to credit risk rating systems under the IRB approach for capital adequacy. That is narrower than the six instruments in the table, which is why it earns quotation rather than a row. It happens to contain the sharpest sentence in the entire set.
The general point is worth making explicitly: a jurisdiction can require the separation without having a model-risk framework that says so in general terms. If you operate in one, the requirement is likely to be sitting inside your capital rules rather than under a heading with “model risk” in it.
One thing the CRR does not say
While we are on capital rules — a caution, because this is an easy citation to get wrong and I nearly did.
The Capital Requirements Regulation is often reached for as the EU’s model-independence authority. It does not support that. CRR Article 190(1) requires the credit risk control unit to be “independent from the personnel and management functions responsible for originating or renewing exposures” — that is independence from the business, not from model development. The same article then makes that unit “responsible for the design or selection, implementation, oversight and performance of the rating systems.” It develops the models. Article 185 requires validation but says nothing about who performs it relative to whoever built it.
So the development-versus-validation separation for euro-area banks is a supervisory expectation in the ECB guide, not a provision of the CRR. If you cite the regulation for it, someone will read the article and you will lose the room. Cite the guide.
The dates that bind
Worth having correct, because at least one of them moved recently and a lot of published material has not caught up:
| Regime | Binding from |
|---|---|
| FINMA Guidance 08/2024 | In force — no compliance date |
| PRA SS1/23 (UK) | In force — 17 May 2024 |
| ECB guide to internal models | In force — February 2024 |
| HKMA SPM CA-G-4 (IRB rating systems) | In force — V.3, 18 Jul 2025 |
| SR 26-2 (Fed / OCC / FDIC) | In force — issued 17 Apr 2026 |
| EU AI Act — Art. 4 literacy · Art. 50 transparency | 2 Feb 2025 · 2 Aug 2026 |
| OSFI E-21 | 1 Sep 2026 |
| OSFI E-23 | 1 May 2027 |
| EU AI Act Annex III high-risk | 2 Dec 2027 |
| MAS AI Risk Management Guidelines | not issued — consultation closed 31 Jan 2026 |
| OSFI ILAAP Guideline (extends E-23 to liquidity models) | draft — consultation closes 19 Aug 2026 |
That Annex III row is the one to check your own materials against. Those obligations were widely expected on 2 August 2026. They were deferred to 2 December 2027 by Regulation (EU) 2026/1744, in force 27 July 2026. The scope did not change — only the clock. Any asset still asserting August 2026 is stale, and the correction is worth making quietly before someone else makes it for you.
Note what the deferral does to the running order: three of the six are already in force, and the EU instrument everyone is preparing for is the last one to arrive.
The question this leaves open
Every institution reading this already has an independent review function. The requirement is not new and the function is not missing.
What is new is that the thing being reviewed is increasingly produced by a system that could just as easily perform the review — and that the evidence of independence, which used to be a byproduct of two different humans doing two different jobs, now has to be produced deliberately or not at all.
So the question worth sitting with is not are we compliant. It is narrower and harder: what would we actually put in front of a supervisor to show that our review was independent of our development?
If the answer is an org chart, it is worth finding out now rather than at the examination.
I work with engineering and risk leaders on exactly this question — where the human gate sits, and what evidence proves it held. curiochat.ai/consulting
Every quotation above was read at the cited location in the primary source on 3 August 2026. Nothing here is legal advice; it is an engineer’s reading of published supervisory texts, and your counsel’s reading is the one that counts.