Model risk & agent governance baseline (SR 26-2)
The platform's model-risk governance baseline is Federal Reserve SR 26-2, which supersedes SR 11-7. Older pages that cite SR 11-7 describe controls that remain valid; SR 26-2 is the current reference for scope and terminology.
Scope split under SR 26-2
- Quantitative models are in scope. Every model that informs a trading, risk, or allocation decision is governed under the model-risk framework below: inventory, materiality tiering, and independent validation.
- GenAI / agentic AI is outside SR 26-2's scope and is instead governed by
the platform's own AI-risk framework: the typed promotion gate
(
StrategyPromotionRequest— the single money-plane crossing), hash-lockedAgentSpecversions, per-run budgets and tool allowlists, immutable audit trails, and human-in-the-loop approval (step-up-MFA-gated; agents can submit but never self-approve).
Confirm the scope interpretation with counsel before any go-live.
Quant model-risk controls
| Control | Mechanism | Where |
|---|---|---|
| Model inventory | data.risk.model_inventory — inventory + materiality tiering | QAP data-plane tool |
| Materiality tiering | Tier drives validation depth and revalidation cadence | model inventory records |
| Independent validation | Validator must differ from producer; gate DENYs otherwise | PromotionGateChain step 5 (gate_independence) |
| Effective challenge | ValidationVerdict / RiskDecision / RiskReport contracts | QAP cross-plane contracts |
| Overfitting controls | pbo > 0.5 unrepresentable; DSR deflation; CPCV with purging/embargo | StrategyCandidate + research plane |
| Change management | Hash-locked spec versions; immutable registry rows | agent_spec_versions et al. |
Pre-trade control checklist (SEA 15c3-5 / MiFID II RTS 6)
Every live or paper trading deployment MUST verify before go-live:
- Kill switch — platform-wide halt reachable by operators; engaged kill-switch DENYs promotion and halts in-flight runs.
- Pre-trade risk limits — per-order price/size limits, per-strategy and per-tenant credit/exposure caps enforced deterministically in the order path (no LLM on the order path).
- Duplicate/erroneous order controls — idempotent order intents
(
intent_id), fail-closed on orphaned or cross-tenant orders. - Message throttles — venue-level rate/participation caps.
- Direct market access controls — only gate-approved strategies may emit exchange orders; advisory agents mint drafts requiring human approval.
- Audit retention — order, decision, and entitlement audit records with multi-year retention (WORM where applicable).
- Annual review — RTS 6-style annual self-assessment of the algorithmic trading controls above, recorded in the compliance evidence map.