Model RiskApril 9, 20269 min read

Model risk under SR 11-7: a guide to model risk management

SR 11-7 is the US supervisory guidance that defines model risk management for banks. It frames model risk as the potential for adverse consequences from model errors or misuse, and demands validation, governance and an inventory.

ABy GeneSecure
The short answer

SR 11-7 is supervisory guidance issued in 2011 by the US Federal Reserve and the Office of the Comptroller of the Currency (as OCC 2011-12) that sets the expectations for model risk management at banking organisations. It defines a model as a quantitative method that turns input data into estimates, and defines model risk as the potential for adverse consequences from decisions based on models that are wrong or used incorrectly. SR 11-7 rests on three pillars. The first is robust model development, implementation and use — sound design, documentation and testing. The second is effective validation: an independent, ongoing challenge to a model's conceptual soundness, an analysis of its ongoing performance (including benchmarking and back-testing), and an outcomes analysis. The third is sound governance, policies and controls — a model inventory, clearly assigned roles, board and senior-management oversight, and effective challenge. A guiding principle is 'effective challenge': critical analysis by objective, competent parties with the authority and incentive to push back. Although it targets banks, SR 11-7 has become the de facto global standard for managing model risk, increasingly extended to machine-learning and AI models.

How SR 11-7 defines a model and its risk

SR 11-7 defines a model broadly: any quantitative method, system or approach that applies statistical, economic, financial or mathematical theories to turn input data into quantitative estimates. That sweeps in credit scorecards, valuation models, capital and stress-testing engines, ALM models, AML transaction monitoring and, increasingly, machine-learning models.

Model risk is the risk of adverse consequences — financial loss, poor decisions, reputational or regulatory harm — from models that have fundamental errors or are used incorrectly or for purposes they were not designed for. The guidance is explicit that even a technically sound model creates risk if it is applied in the wrong context.

Pillar one: development, implementation and use

Sound model risk management starts at development. A model should rest on defensible theory, use appropriate data, and be documented thoroughly enough that an independent party could understand and reproduce it. Testing should probe the model's behaviour, limitations and sensitivity to assumptions before it ever goes live.

SR 11-7 stresses that documentation is not bureaucracy — it is what makes a model maintainable and reviewable when its original developers have moved on. 'Use' matters too: the people relying on a model's output must understand its assumptions and limitations.

Pillar two: validation and effective challenge

Validation is the independent set of activities that verify a model works as intended. SR 11-7 describes three core elements: an evaluation of conceptual soundness (is the design and theory sound?), ongoing monitoring (is it still performing, via benchmarking and process verification?), and outcomes analysis (do its outputs match reality, via back-testing?).

Underpinning all of this is 'effective challenge' — critical analysis by parties who are independent of model development, technically competent, and given the standing and incentive to challenge. Validation must be genuinely independent; a model owner cannot validate their own model. The depth of validation should scale with the model's materiality and complexity.

Pillar three: governance, the inventory and roles

The third pillar is the organisational machinery: board and senior-management oversight, written policies, defined roles (owners, developers, validators, control functions), and — at the centre — a comprehensive model inventory. The inventory records every model in use, its purpose, owner, validation status, limitations and risk tier.

A current inventory is what lets an institution answer the questions examiners ask: which models are in use, when were they last validated, which have open findings, and which feed regulatory numbers. Without it, model risk management is unmanageable at scale.

From SR 11-7 to AI governance

SR 11-7 predates the machine-learning wave, but its principles travel well. Conceptual soundness, ongoing monitoring, outcomes analysis, independent challenge and a living inventory are exactly the controls a regulator wants to see around an ML or AI model — plus newer concerns like data drift, explainability and bias.

The practical challenge is volume and pace. A modern institution may have hundreds or thousands of models, and AI development moves faster than annual validation cycles. Running the model inventory, validation workflow, monitoring and evidence on one governed platform — rather than spreadsheets and email — is what makes SR 11-7-grade governance sustainable as model populations grow.

FAQ

Common questions, answered.

What evaluation teams want to know before a demo — answered plainly.

SR 11-7 is supervisory guidance issued in 2011 by the US Federal Reserve and the OCC that sets out expectations for model risk management at banks, covering model development, validation, and governance.

Robust model development, implementation and use; effective validation (conceptual soundness, ongoing monitoring and outcomes analysis); and sound governance, policies and controls — including a model inventory and clear roles.

Effective challenge is critical analysis of a model by objective, competent parties who are independent of its development and have the authority and incentive to push back on its design, assumptions and use. It is the principle that makes validation meaningful.

SR 11-7 predates modern machine learning, but its principles are widely applied to AI/ML models. Regulators expect the same validation, monitoring and governance, extended with controls for issues like data drift, explainability and bias.

See this run on your data.

Book a 30-minute walkthrough and we'll show GeneSecure handling the exact framework you just read about — grounded in your own risk graph.

Model risk under SR 11-7: a guide to model risk management | GeneSecure