Model risk policy and framework
Proportionate to your institution, drawing on established supervisory practice without importing a large-bank apparatus you cannot staff.
Advisory
Model inventories, tiering, validation standards and independent validation — for institutions now running more models than anyone has a complete picture of.
Context
Ten years ago your institution ran two models. It now runs a dozen or more — expected credit loss, application and behavioural scoring, collections prioritisation, asset and liability management, transaction monitoring, risk-based pricing, capital planning, and whatever the data team built last quarter.
Very few institutions here can produce a complete list of them. Fewer can say which are material, which have been independently reviewed, when each was last recalibrated, or who owns the one that decides which customers get credit.
Meanwhile a board is asked to attest to the soundness of models it cannot inspect, and increasingly a supervisor is asking how that attestation was reached. The honest answer, at most institutions, is that it was not reached at all.
Deliverables
Concrete outputs, not activities.
Proportionate to your institution, drawing on established supervisory practice without importing a large-bank apparatus you cannot staff.
A complete register of what you run, who owns it, what it decides and what it was last tested against. Most institutions find things they had forgotten.
Materiality-based classification, so validation effort goes where the exposure is rather than being spread evenly.
What a validation must cover for each tier, so the work is comparable between models and between years.
Of specific models: conceptual soundness, data and assumptions, implementation testing, outcomes analysis and effective challenge of the judgements underneath.
Model risk in a form directors can govern, rather than a technical appendix nobody reads.
We build models, we sell a platform that runs them, and we validate models. Those three activities together create a self-review risk, so we govern it explicitly: we do not review or validate our own models. Where we have performed a validation, the model was designed by another vendor or built in-house by the institution.
We would rather state that than be asked.
Methodology
Step 01 of 04
What models exist, what they decide, and what governance currently applies to them.
The deepen motion — where existing clients extend.
Next step
Two to three weeks produces a complete register of your models, tiered by materiality, and a view of which need validating first. It is the cheapest work on this page and it tends to change the conversation.