Advisory

Your board is attesting to models nobody has reviewed.

Model inventories, tiering, validation standards and independent validation — for institutions now running more models than anyone has a complete picture of.

Model risk governance and oversight

Context

What you are facing

Ten years ago your institution ran two models. It now runs a dozen or more — expected credit loss, application and behavioural scoring, collections prioritisation, asset and liability management, transaction monitoring, risk-based pricing, capital planning, and whatever the data team built last quarter.

Very few institutions here can produce a complete list of them. Fewer can say which are material, which have been independently reviewed, when each was last recalibrated, or who owns the one that decides which customers get credit.

Meanwhile a board is asked to attest to the soundness of models it cannot inspect, and increasingly a supervisor is asking how that attestation was reached. The honest answer, at most institutions, is that it was not reached at all.

Model inventory and governance framework
Validation reports and model documentation

Deliverables

What we deliver

Concrete outputs, not activities.

Model risk policy and framework

Proportionate to your institution, drawing on established supervisory practice without importing a large-bank apparatus you cannot staff.

Model inventory

A complete register of what you run, who owns it, what it decides and what it was last tested against. Most institutions find things they had forgotten.

Model tiering

Materiality-based classification, so validation effort goes where the exposure is rather than being spread evenly.

Validation standards

What a validation must cover for each tier, so the work is comparable between models and between years.

Independent validation

Of specific models: conceptual soundness, data and assumptions, implementation testing, outcomes analysis and effective challenge of the judgements underneath.

Board and committee reporting

Model risk in a form directors can govern, rather than a technical appendix nobody reads.

On independence

We build models, we sell a platform that runs them, and we validate models. Those three activities together create a self-review risk, so we govern it explicitly: we do not review or validate our own models. Where we have performed a validation, the model was designed by another vendor or built in-house by the institution.

We would rather state that than be asked.

Independent model validation
Model risk governance implementation

Methodology

How we work

Step 01 of 04

Next step

Start with the inventory.

Two to three weeks produces a complete register of your models, tiered by materiality, and a view of which need validating first. It is the cheapest work on this page and it tends to change the conversation.