How SR 11-7 defines a model and its risk
SR 11-7 defines a model broadly: any quantitative method, system or approach that applies statistical, economic, financial or mathematical theories to turn input data into quantitative estimates. That sweeps in credit scorecards, valuation models, capital and stress-testing engines, ALM models, AML transaction monitoring and, increasingly, machine-learning models.
Model risk is the risk of adverse consequences — financial loss, poor decisions, reputational or regulatory harm — from models that have fundamental errors or are used incorrectly or for purposes they were not designed for. The guidance is explicit that even a technically sound model creates risk if it is applied in the wrong context.
Pillar one: development, implementation and use
Sound model risk management starts at development. A model should rest on defensible theory, use appropriate data, and be documented thoroughly enough that an independent party could understand and reproduce it. Testing should probe the model's behaviour, limitations and sensitivity to assumptions before it ever goes live.
SR 11-7 stresses that documentation is not bureaucracy — it is what makes a model maintainable and reviewable when its original developers have moved on. 'Use' matters too: the people relying on a model's output must understand its assumptions and limitations.
Pillar two: validation and effective challenge
Validation is the independent set of activities that verify a model works as intended. SR 11-7 describes three core elements: an evaluation of conceptual soundness (is the design and theory sound?), ongoing monitoring (is it still performing, via benchmarking and process verification?), and outcomes analysis (do its outputs match reality, via back-testing?).
Underpinning all of this is 'effective challenge' — critical analysis by parties who are independent of model development, technically competent, and given the standing and incentive to challenge. Validation must be genuinely independent; a model owner cannot validate their own model. The depth of validation should scale with the model's materiality and complexity.
Pillar three: governance, the inventory and roles
The third pillar is the organisational machinery: board and senior-management oversight, written policies, defined roles (owners, developers, validators, control functions), and — at the centre — a comprehensive model inventory. The inventory records every model in use, its purpose, owner, validation status, limitations and risk tier.
A current inventory is what lets an institution answer the questions examiners ask: which models are in use, when were they last validated, which have open findings, and which feed regulatory numbers. Without it, model risk management is unmanageable at scale.
From SR 11-7 to AI governance
SR 11-7 predates the machine-learning wave, but its principles travel well. Conceptual soundness, ongoing monitoring, outcomes analysis, independent challenge and a living inventory are exactly the controls a regulator wants to see around an ML or AI model — plus newer concerns like data drift, explainability and bias.
The practical challenge is volume and pace. A modern institution may have hundreds or thousands of models, and AI development moves faster than annual validation cycles. Running the model inventory, validation workflow, monitoring and evidence on one governed platform — rather than spreadsheets and email — is what makes SR 11-7-grade governance sustainable as model populations grow.