What this is.
Position in the architecture · Operational Machinery
Specification · Deposited. 10.5281/zenodo.22285045, CC BY 4.0.
The claim.
A model that has not been independently validated may be operated. Its outputs are not evidence of anything to a party outside the team that built it. That is the whole of the framework’s claim, and everything in it exists to make the moment at which a model’s fitness becomes a matter of record identifiable in time.
Six steps.
Inventory establishes what exists. Pre-validation establishes what the builder claims. Independent validation tests the claim by someone who did not make it. Approval binds a named person to the decision. Monitoring watches the assumptions the approval rested on. Revalidation returns when those assumptions move. Each step produces a record, and the record is the artifact the next step consumes.
Two roles, never one person.
The head of model risk owns the discipline. The named approving executive owns each approval. They must not be the same person for the same model, because independence is the property the framework exists to establish and a discipline that permits the builder to approve the build has not established it. Where a Sharia Supervisory Board holds binding approval power, validation carries a second and independent track, specified jointly with SACF.
Which institutions, and on whose authority.
Model risk management is where a supervisor already expects a written discipline, so this framework bites hardest where one exists — and the two instruments do not cover the same ground. OSFI Guideline E-23, effective 1 May 2027, applies to all federally regulated financial institutions in Canada, insurers included. In the United States, SR 26-2, issued 17 April 2026, superseded SR 11-7 and SR 21-8 and is expected to be most relevant to banking organizations with over thirty billion dollars in total assets; it does not reach insurance. Where an institution also has a Sharia Supervisory Board with binding approval power, validation carries a second and independent track.
Where it bites · Banking and capital markets · Insurance
The record of its own revisions.
A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.
Change history
- 2026-08-30 · entry v1.0 — First registry entry
- 2026-09-15 · entry v2.0 — Specification status moves from `source-treatment` to `deposited` on the deposit of the MESA MRM Framework specification, whose concept DOI the entry now carries
- 2026-09-15 · entry v2.0 — Definition reconciled with that specification, which states the principle of 1.2 in its operative form and governs
- 2026-09-15 · entry v2.0 — The `missing` limitation recording no validation report template and no worked example is closed by Annexes B and C of that specification
- 2026-09-15 · entry v2.0 — The asserted supervisory-alignment limitation is amended to record the informative crosswalk at its Annex A and is NOT closed by it
- 2026-09-15 · entry v2.0 — The supply edge to REG-06 now carries the revalidation trigger register at G5, resolving the question routed to this registry at 6.3 of that specification
Limitations recorded in the registry
- Alignment with supervisory model risk expectations. The source treatment contains no written crosswalk to current Canadian or United States supervisory guidance, and an institution MUST perform that crosswalk against the primary sources in force in its jurisdiction. The deposited specification carries an informative crosswalk at its Annex A, which states its own date of reading, creates no obligation on either supervisor and no presumption in the institution's favour, and does not transfer the obligation. The limitation therefore stands.
- Specifies the discipline, not the statistical or behavioural methods a validator applies within it.
What would show this to be wrong. MESA MRM is falsified if institutions operating the six steps with genuine second-line independence are found to approve unfit models at the same rate as institutions in which the building team validates its own work. The framework's entire claim rests on independence changing the outcome, and evidence that it does not would leave a process with no defensible reason to exist.
What this does not claim.
Asserted. Alignment with supervisory model risk expectations. The source treatment contains no written crosswalk to current Canadian or United States supervisory guidance. An institution relying on this for supervisory alignment must perform that crosswalk against the primary sources in force in its own jurisdiction.
Missing. No published validation report template and no worked validation example. The discipline is specified; the artifact it produces is not exemplified.
Scope. It specifies the discipline, not the statistical or behavioural methods a validator applies within it. It does not tell a validator how to validate.
Citation.
Cite this work. MESA MRM Framework, version 1.0. 10.5281/zenodo.22285045. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.
In the practice.
- Governed production AI, the discipline this framework belongs to
- Defensible AI, the family and the register
- AI Governance and Compliance Frameworks for the Middle East, the source treatment
- Model risk, the service this framework is applied through
- AI governance in the wiring, on where governance actually lives