Quant Memo
Core

Model Risk Management

Model risk management is the discipline of treating a firm's own models as a source of risk in their own right, one that needs oversight independent of the people who built them.

Prerequisites: Internal Models vs the Standardised Approach

A bank prices its derivatives book, calculates its regulatory capital, decides who gets a loan, and forecasts its own losses under stress — all using models. Every one of those models is a simplification built on assumptions, and every one of them can be wrong in ways that aren't obvious from the outside. Model risk management is the set of practices for treating "the model might be wrong" as its own risk category, with its own governance, rather than trusting a model just because it produced an official-looking number.

Model risk management assumes every model is wrong in some way and asks how much that matters — it's a governance discipline for finding a model's weaknesses before the market does, not a one-time approval stamp.

What the discipline actually involves

Regulatory guidance (in the US, the Federal Reserve's SR 11-7) frames model risk management around three pillars: development, where a model is built and documented so its assumptions and limitations are explicit; validation, where a team independent of the model's developers tests it — checking it against out-of-sample data, alternative models, and known edge cases — before it's used for anything material; and ongoing monitoring, where the model's live performance is tracked against reality, so drift or a changed environment gets caught rather than discovered after a loss. Every model in active use is also expected to have an inventory entry and an owner accountable for it.

development validation monitoring
Model risk management is a loop, not a checkpoint — monitoring feeds problems back into development, which triggers re-validation.

Worked example

A bank's credit-scoring model, built and validated on pre-pandemic data, is put into ongoing monitoring. Two years later, monitoring flags that the model's predicted default rates have drifted meaningfully from realized defaults across a specific borrower segment — young borrowers with thin credit files — that behaved differently in the post-pandemic economy than the training data implied. Because the monitoring caught the drift, the model is flagged for re-validation and adjustment before it drives a large volume of mispriced lending, rather than after.

What this means in practice

Model risk management is why a validation team's job is explicitly adversarial toward the model — their incentive is to find where it breaks, not to confirm it works. It's also why large institutions maintain a full model inventory: a model nobody remembers exists, quietly feeding into a decision, is one of the most common ways model risk actually materializes, precisely because nobody is watching it.

A model that's been "working fine for years" is not evidence it's low-risk — many of the most damaging model failures (in mortgage pricing before 2008, for instance) were models that performed well for years under the conditions they were built for, then failed exactly when conditions changed.

Related concepts

Further reading

  • Federal Reserve SR 11-7, 'Guidance on Model Risk Management'
ShareTwitterLinkedIn