When a bank uses artificial intelligence or machine learning to approve credit, price derivatives, detect money laundering or make operational decisions, that system is a model subject to federal supervision. The interagency model risk management guidance—known as SR 11-7—and the OCC's 2023 update establish what governance, validation and oversight are required. The guidance does not prescribe technology choices. It assigns accountability for understanding what the model does, how it can fail, and whether its outputs remain sound as circumstances change.
Why model risk management matters to the business
A model is any quantitative method, system or approach that applies statistical, economic, financial or mathematical theories to process input data into outputs that inform business decisions. When these outputs influence credit underwriting, capital calculations, stress testing, fair lending assessments or operational risk measurement, errors can produce material financial loss, regulatory sanctions or reputational damage.
Machine learning introduces distinct challenges. Training data may embed historical bias. Feature relationships can shift without warning. Model complexity may resist straightforward interpretation. When an algorithm declines a loan application or triggers a suspicious activity report, the institution must be able to explain the basis, defend the fairness and demonstrate ongoing control.
Supervisors examine whether model risk management is commensurate with the model's materiality and complexity. Weaknesses discovered during examination can result in findings that require board reporting, additional capital allocation or restrictions on model use until deficiencies are remediated.
What the guidance requires
SR 11-7 establishes three core components: governance, model development and implementation, and validation. The OCC's 2023 update clarified how these principles apply when the underlying method is machine learning rather than a conventional statistical model.
Governance and oversight
Board and senior management must establish a framework that identifies all models, assigns ownership, sets risk tolerances and defines approval authorities. This includes a model inventory that catalogues each system by purpose, materiality and risk tier. High-risk or complex models require board-level or board-committee approval before deployment and after material changes.
The framework must also establish policies for model development standards, validation scope and frequency, exception handling and version control. When a third party supplies a model—such as a vendor credit scoring algorithm or a cloud-based fraud detection service—the institution retains accountability for validation and ongoing performance monitoring.
Development and implementation
Development requires documentation of purpose, theoretical soundness, data sources, assumptions, limitations and intended use. For machine learning models, this extends to feature engineering choices, hyperparameter tuning, training and test datasets, and performance metrics selected to evaluate accuracy, stability and fairness.
Implementation controls include version management, change logs, user access restrictions and automated monitoring of model inputs and outputs. When a model moves from development to production, the transition must be governed by a documented approval process that confirms validation is complete and operational controls are in place.
Validation requirements
Validation is an independent assessment of whether the model is sound for its intended purpose and whether it performs as expected. The guidance specifies three elements: evaluation of conceptual soundness, ongoing monitoring and outcomes analysis.
Evaluation of conceptual soundness examines whether the methodology is appropriate given the product, risk and market conditions. For a credit risk model, this means assessing whether the algorithm correctly identifies default probability and whether the training data reflect the population to which the model will be applied. For machine learning, it includes testing for overfitting, checking that feature importance aligns with economic intuition, and confirming that the model behaves predictably under stress.
Ongoing monitoring compares model predictions to actual outcomes. If a loan approval model forecasts a five percent default rate and the realized rate is eight percent, the divergence must be investigated, explained and addressed through recalibration or redevelopment. Monitoring also tracks input data quality, detects distribution shifts and flags anomalies that may indicate model degradation.
Outcomes analysis evaluates whether the model produces results consistent with its design objectives and whether those results meet regulatory standards for fairness and transparency. This is particularly relevant for models subject to fair lending requirements, where disparate impact must be measured and explained.
Validation must be performed by a qualified, independent function. Independence means the validators do not report to the business line that uses the model and did not develop the model themselves. Qualifications include technical expertise in statistics, machine learning or the relevant financial domain.
AI and machine learning considerations
The OCC's 2023 guidance clarified that machine learning models are subject to the same governance and validation standards as traditional models, but the methods used to satisfy those standards must account for the technology's characteristics.
Black-box algorithms—those whose internal logic resists straightforward interpretation—require additional validation rigor. Validators must employ techniques such as sensitivity analysis, feature importance ranking or surrogate models to understand how inputs influence outputs. If interpretability cannot be achieved to a degree consistent with the model's risk, the model may not be suitable for high-stakes decisions.
Training data quality and representativeness receive heightened scrutiny. If the dataset used to train a lending model underrepresents certain demographic groups, the resulting algorithm may produce biased outcomes that violate fair lending standards. Validation must test whether the model performs consistently across populations and whether its predictions remain accurate as market conditions evolve.
Ongoing monitoring becomes more demanding when models learn continuously or adapt automatically. Any automated retraining process must include controls that trigger human review before updated parameters are deployed to production.
Who owns what inside the organization
The guidance assigns specific accountability to defined roles, but many institutions struggle to translate these requirements into clear ownership.
The board or a board committee must approve the model risk management framework, receive regular reporting on model performance and findings, and ensure that material model risk is appropriately identified and managed. For models classified as high risk, the board or committee reviews and approves deployment and any subsequent material changes.
Senior management translates board-level policy into operational practice. This includes establishing the model inventory, assigning model owners, ensuring validation resources are adequate and independent, and overseeing remediation when validation identifies deficiencies.
Model owners—typically business line leaders—are accountable for a model's ongoing performance, appropriate use and compliance with policy. They initiate development, sponsor validation and ensure that monitoring is performed and findings are addressed.
The validation function must be independent, appropriately staffed and positioned with sufficient authority to challenge model developers and business owners. Independence is compromised if validators report to the same executive who oversees the models they are reviewing.
The problem many institutions face is not the absence of capable staff but the lack of a single executive accountable for the entire framework. Model development may sit in quantitative finance. Validation may report to enterprise risk. IT may control the production environment. Legal may own fair lending analysis. When each function operates in isolation, gaps emerge in version control, change management, exception tracking and board reporting.
This is where [virtual CISO (vCISO) leadership](/vciso/) provides structure. A vCISO establishes the connective tissue between technical model validation, business model ownership, risk committee oversight and regulatory positioning, ensuring that governance is not an assortment of policies but a functioning system with defined decision rights and escalation paths.
Relationship to AI and emerging technology governance
Model risk management for AI is a component of broader AI governance, not a substitute for it. The interagency guidance addresses the quantitative and operational dimensions—validation, monitoring, performance measurement—but does not cover all the risks introduced when an institution adopts machine learning at scale.
AI governance must also address vendor dependency, data provenance, third-party model transparency, ethical use policies, intellectual property protection and incident response when an algorithm produces an unexpected or harmful outcome. If an institution uses a large language model to draft customer communications, a computer vision system to process documents or a reinforcement learning algorithm to optimize trading, each presents governance questions that extend beyond the model risk management framework.
The two frameworks share common elements: inventory, risk classification, change control, independent review and executive reporting. A well-structured governance programme integrates them rather than maintaining parallel processes. The model risk management inventory becomes part of the AI system catalogue. Model validation findings feed into the broader technology risk assessment. Board reporting covers both model performance and emerging AI use cases that may not yet meet the definition of a model but still carry material risk.
Practical next steps for leadership
The following sequence provides a starting point for institutions that need to strengthen model risk management for AI and machine learning.
First, confirm that the model inventory is complete and current. Many institutions discover during examination that models are in production use without having been formally catalogued, validated or approved. The inventory should include vendor-supplied models, models embedded in third-party platforms and any algorithm that influences a material business decision, even if it was not developed by the quantitative risk team.
Second, assess whether the validation function is independent and whether validators possess the skills required to evaluate machine learning models. Independence is structural, not aspirational. If validators report to the same executive who oversees model development or the business line that uses the models, independence does not exist. If validators lack training in machine learning techniques, they cannot perform adequate review.
Third, review whether high-risk models have been subject to board or board-committee approval and whether ongoing performance is reported at appropriate intervals. If model performance metrics are not reaching the board, or if reporting is limited to summary statistics without context or trend analysis, governance is incomplete.
Fourth, examine change management and version control practices. If a model can be updated, retrained or recalibrated without a documented approval process, validation findings and monitoring controls become ineffective. Every material change must trigger re-validation before the updated model is deployed.
Fifth, confirm that third-party models are subject to the same governance and validation standards as internally developed models. The fact that a vendor supplies a model does not transfer accountability. The institution must validate the vendor model's conceptual soundness, monitor its performance and ensure that its outputs meet regulatory standards.
Sixth, integrate model risk management with broader AI governance. If the institution is developing an AI governance framework, model risk management should be incorporated as a component rather than maintained separately. If no AI governance framework exists, consider whether the expanding use of machine learning warrants one.
Where these steps reveal gaps in ownership, independence or expertise, the missing element is often executive accountability. Model risk management requires someone at the leadership level who can translate regulatory expectations into operational practice, establish decision rights across functions, ensure that validation findings are acted upon and report to the board on the state of model risk.
Heights Consulting Group provides this executive ownership through [virtual CISO services](/vciso/). A vCISO establishes the governance structure, defines roles and escalation paths, positions the institution's approach with examiners, and delivers the reporting that boards and audit committees require. If your institution is facing an examination, responding to findings or expanding AI use without clear accountability, a confidential consultation can clarify the path forward. Reach out to Heights to discuss your specific situation.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: AI and Emerging Technology Governance
Governance for how your organization adopts artificial intelligence: approved uses, data handling boundaries, review before deployment, and accountability for the output.