Summary Model risk management (MRM) is the discipline of identifying, measuring, monitoring and controlling the risks that models introduce. A workable framework is scaled to the firm's model estate and to the materiality of decisions the models drive.
Policy and scope The policy defines what counts as a model, the lifecycle stages, roles across the three lines, and the standards each stage must meet. Ambiguity about scope is a common source of gaps.
Inventory A single, current inventory of models — with owner, tier, use, dependencies and status — is the foundation. Multiple partial inventories are effectively no inventory.
Tiering Tiering by materiality of decisions and complexity of methodology drives the intensity of validation, monitoring and governance. Uniform treatment wastes effort at the low end and under-controls at the high end.
Lifecycle Development, validation, approval, deployment, monitoring, change and retirement are governed stages, each with defined evidence and sign-off.
Monitoring Ongoing monitoring — performance, stability, data — is the difference between one-time validation and durable control.
Limitations MRM is a probabilistic discipline. Its purpose is to contain and inform, not eliminate, model failure.
Related expertise See [Model Risk and Validation](/expertise/model-risk).
Frequently asked questions
What should risk leaders know about policy and scope?
The policy defines what counts as a model, the lifecycle stages, roles across the three lines, and the standards each stage must meet. Ambiguity about scope is a common source of gaps.
What should risk leaders know about inventory?
A single, current inventory of models — with owner, tier, use, dependencies and status — is the foundation. Multiple partial inventories are effectively no inventory.
What should risk leaders know about tiering?
Tiering by materiality of decisions and complexity of methodology drives the intensity of validation, monitoring and governance. Uniform treatment wastes effort at the low end and under-controls at the high end.
What should risk leaders know about lifecycle?
Development, validation, approval, deployment, monitoring, change and retirement are governed stages, each with defined evidence and sign-off.
What should risk leaders know about monitoring?
Ongoing monitoring — performance, stability, data — is the difference between one-time validation and durable control.