In this article
Browse the research library
Rules and standards
Model risk management
The discipline regulated firms use to keep models honest, applied to AI
Published 9 September 20262 min read
In one paragraph
Model risk management is the discipline regulated firms use to make sure a model is doing what it is meant to: an inventory of every model in use, independent checking by people who did not build it, and clear ownership across its life from development to retirement. It grew out of banking supervision, but the same structure suits AI systems well, because the underlying question, is this model right, and who is checking, is the same one.
Who it applies to
Historically, banks and other regulated financial firms, where supervisors expect a documented model risk management programme. The reference text is SR 11-7, guidance issued jointly by the Federal Reserve and the Office of the Comptroller of the Currency on 4 April 2011 and still current. Supervisors increasingly read this guidance as covering AI and machine-learning models alongside the statistical models it was originally written for, and other supervisors outside US banking hold comparable expectations of the firms they regulate.
What it asks for
- A firm-wide inventory of every model in use, with its purpose and its owner recorded.
- A risk tier assigned to each model, so the depth of checking matches how much is riding on it.
- Independent validation carried out by people who did not build the model, before it is deployed.
- Periodic revalidation after deployment, rather than a one-off check at launch.
- Coverage across the whole lifecycle, from development through deployment to eventual retirement.
- In the EU financial sector, the Digital Operational Resilience Act adds ICT risk management, incident reporting, resilience testing, and oversight of critical third-party providers, a category that includes cloud and AI vendors.
What it looks like in practice
A firm has run a credit scoring model for years under a model risk programme, and now wants to add an AI system that drafts customer responses. Extending the existing inventory and validation process to the new system, rather than treating it as a separate, ungoverned tool, is usually the fastest way to get it into use with the checking a supervisor would expect to see.
Where it stands now
SR 11-7 was issued on 4 April 2011 and remains the current reference text in US banking supervision. The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied in the EU financial sector since 17 January 2025. Dates change; the official text linked below is the authority.
How this connects to our work
For organisations in regulated sectors, managed AI and continuous improvement covers much of the same ground as a model risk management programme: independent checking against a fixed set of questions, and evidence that each system is monitored rather than assumed to be working.
Read the original
Every link goes to the publisher. Dates and status change; the text linked below is the authority.
- SR 11-7, Supervisory Guidance on Model Risk Management (opens in a new tab)
Federal Reserve and OCC · Regulator or statute · 2011
The reference text for model inventories and independent validation.
- Regulation (EU) 2022/2554, Digital Operational Resilience Act (opens in a new tab)
European Union · Regulator or statute · 2022
ICT resilience rules for EU financial entities, applicable since January 2025.