Quant Memo
Core

Model Inventory and Risk Tiering

The requirement that a firm maintain a single, complete register of every model in use, with each one assigned a risk tier that determines how much scrutiny it gets.

Prerequisites: SR 11-7 and Model Risk Management Guidance

Ask a mid-sized fund how many models are running against client money and you'll often get a shrug before you get a number. There's the flagship signal, sure, but also the volatility filter that gates it, the transaction-cost model that sizes it, the risk model that limits it, and a dozen spreadsheets that adjust all of the above by hand. A model inventory is the fix: one authoritative list of every model in production, who owns it, what it's used for, and — critically — how risky it is if it breaks.

Risk tiering is what makes the inventory useful rather than just a filing exercise. Not every model deserves the same level of oversight. A model that sizes a $2 billion flagship strategy and a model that nudges a small experimental sleeve by a few basis points both belong on the list, but they shouldn't get the same review cycle. Tiering typically weighs three things: how much capital or risk the model touches, how automated its decisions are (does a human check the output before it trades, or does it go straight to the market), and how complex or opaque the model is (a linear regression is easier to sanity-check than a gradient-boosted ensemble). A model that scores high on all three — large capital, fully automated, hard to interpret — lands in the top tier and gets the most frequent independent validation, the most detailed documentation, and the tightest change-control process. A small, human-supervised, simple model can sit in a lower tier with a lighter annual review.

The practical payoff shows up during incidents. When a model starts behaving strangely — say a volatility filter suddenly flags every day as high-risk and halts trading — the first question from risk management is "what tier is this, and who's the model owner?" Without an inventory, that question can take hours to answer while the model keeps running. With one, it's a lookup.

TierCapital at riskAutomationReview cadence
Tier 1HighFully automatedIndependent validation, annual or on change
Tier 2ModeratePartially automatedPeriodic review, 1–2 years
Tier 3LowHuman-in-the-loopLight annual attestation

The inventory also matters for regulators and for the firm's own board. A regulator asking "show me every model that touches client assets" expects a complete list, not a best effort assembled under deadline pressure. Gaps in the inventory — models running that nobody remembered to register — are one of the most common findings in model-risk audits, and they tend to be the models with the least documentation and the least oversight, which is exactly backwards from what a well-run process should produce.

A model inventory is only useful if it's complete and tiered by actual risk — capital exposure, degree of automation, and complexity — so that scarce validation effort goes to the models that can do the most damage, not just the ones someone remembered to list.

The most common failure isn't a bad tiering scheme — it's an incomplete inventory. Ad hoc scripts, spreadsheet macros, and "temporary" models that quietly became permanent are the ones most likely to be missing, and they're rarely low-risk just because they're informal.

Related concepts

Further reading

  • Federal Reserve SR 11-7, Guidance on Model Risk Management
ShareTwitterLinkedIn