Model Risk Management
Also known as: SR 11-7; OCC 2011-12
Federal Reserve and OCC supervisory guidance establishing the foundational US framework for identifying, assessing, and controlling model risk in financial institutions.
Model Risk Management (MRM) refers to the comprehensive framework for managing the risks arising from the use of quantitative models in financial institutions, codified principally in OCC Bulletin 2011-12 / Federal Reserve Supervisory Letter SR 11-7 'Supervisory Guidance on Model Risk Management' (issued April 4, 2011, jointly applicable to OCC-regulated banks and Federal Reserve-supervised banks and bank holding companies). Model risk is defined as the potential for adverse consequences from decisions based on incorrect or misused model outputs and reports — arising from fundamental errors in model design or implementation, or from inappropriate use of correctly-implemented models. The framework rests on three pillars: (1) model development, implementation, and use (including robust development practices, comprehensive documentation, and ongoing operation monitoring); (2) model validation (independent and effective challenge of model conceptualization, design, implementation, and outputs); and (3) governance, policies, and controls (board and senior-management oversight, model inventory, ownership accountability, risk reporting). MRM applicability has expanded substantially since 2011, with extensions through SR 21-8 (June 2021, COVID-period model adjustments), broader regulatory expectations for model-using institutions of all sizes, and ongoing supervisory engagement with AI/ML model risk.
Core components
- Model definition: 'a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates' — covering specifically including but not limited to credit-risk models, market-risk models, asset-liability management models, capital models (CCAR/DFAST stress tests), anti-money-laundering models, valuation models, operational-risk models, increasingly AI/ML models
- Three pillars: model development, implementation, and use (robust process, documentation, monitoring, performance tracking)
- model validation (independent challenge)
- governance (oversight, inventory, accountability)
- Effective Challenge: SR 11-7's central concept that validation provides 'critical analysis' by 'objective, informed parties' who are 'separated from the model development process'
- Independence requirement: validation function organizationally separate from model development, with appropriate authority and access
- Three components of validation: evaluation of conceptual soundness
- ongoing monitoring (process verification and benchmarking)
- outcomes analysis (back-testing)
- Model inventory: comprehensive list with risk tiering (typically high/medium/low risk based on materiality and complexity) determining validation-frequency and -depth expectations
- Documentation requirements: model purpose, methodology, data, assumptions, limitations, testing, and ongoing performance
- Vendor model treatment: applicability of MRM standards to externally-developed models, with specific guidance on validation of vendor methodology
- AI/ML extensions: ongoing supervisory engagement with machine-learning-specific risks including explainability, drift, training-data biases, retraining frequency
- Stress-testing model context: CCAR (Comprehensive Capital Analysis and Review) and DFAST (Dodd-Frank Act Stress Tests) impose particular MRM expectations on capital-stress-test models
Primary use case
Foundational supervisory framework for model risk in OCC-regulated and Federal Reserve-supervised financial institutions; applicability has expanded across financial services to bank holding companies, savings and loan holding companies, large credit unions (NCUA related guidance), and through industry diffusion to insurance companies (NAIC Own Risk and Solvency Assessment ORSA), asset managers, and broader financial-services-firms; internal model-risk function design template for banks establishing or maturing MRM programs; examination reference for OCC and Federal Reserve examiners reviewing MRM compliance; third-party model-risk reference for banks using vendor models, with substantial vendor-management implications; intellectual foundation for AI/ML model governance in regulated financial services, with industry working groups (Bank Policy Institute, Risk Management Association, ABA) developing AI-specific MRM extensions; academic and professional reference in financial-services model-risk, validation methodology, and post-2008-crisis regulatory-reform literature.
Common criticisms
- MRM as defined by SR 11-7 has been substantially debated in its application to AI and machine-learning models — the 2011 framework was developed for the relatively stable, interpretable, statistically-grounded models characteristic of pre-AI banking (logistic regression, Cox proportional hazards, GARCH, Monte Carlo simulation), and applying it to high-dimensional opaque ML models (gradient-boosted trees, deep neural networks, large language models) requires substantial methodological extension that supervisory guidance has only partially provided
- the 'effective challenge' principle's operationalization for ML models — where model validators may have limited capacity to 'challenge' deep neural networks at the conceptual-soundness level the SR 11-7 framework anticipates — produces persistent industry debate, with practitioners noting validation often becomes outcome-monitoring rather than substantive challenge
- documentation burden under MRM has been substantially documented as substantial, with model documentation, validation reports, and inventory maintenance consuming significant resources — community banks and smaller institutions have argued the burden is disproportionate to actual model-risk profile
- the model-vs-non-model boundary has been contested — the SR 11-7 definition is broad and supervisory practice varies on whether spreadsheet calculations, decision rules, and other quantitative approaches require full MRM treatment
- vendor-model validation faces practical constraints — banks frequently lack access to vendor model methodology details making substantive validation challenging, with vendor cooperation varying widely
- 'paper compliance' concern: documentation can exist while substantive validation is weak, with examination ratings sometimes turning on documentation completeness rather than substantive risk management
- OCC and Federal Reserve coordination on MRM expectations is substantial but FDIC and CFPB MRM expectations for their regulated populations are less developed, producing inconsistent supervisory expectations across regulators
- international interoperability with PRA Supervisory Statement SS1/23 (UK), EBA model risk guidance, OSFI Canadian guidance produces parallel frameworks for multinational firms
- ongoing AI/ML evolution outpaces supervisory guidance update cycle, creating documented gap between leading-edge model deployment and validated MRM coverage.
Lineage
- Siblings
- OCC Heightened Standards, OCC Risk Governance Framework, Three Lines Model