Skip to content

Model Risk Management and SR 11-7 for AI

ماڈل رسک مینجمنٹ اور SR 11-7 برائے AI

35 min read

Three ways to see it

  1. SR 11-7 defines a model as 'a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories' to turn inputs into outputs. Every modern AI system fits. The guidance organises model risk into three lines of defence. First line: model developers and users who own the model. Second line: an independent model validation function. Third line: internal audit which checks both. It demands a model inventory, regular validation cycles, documented limitations, and clear escalation when models drift or fail.

  2. Way one to apply SR 11-7 to AI: build the inventory first. Every AI in production should be on a single list with owner, purpose, data sources, model type, vendor, last validation date, and risk tier. Pakistani banks typically discover, on building the list, that they have ten times more AI in production than the official IT inventory shows. Shadow AI is the first thing model risk management surfaces.

  3. Way two: independent validation. The team that builds a model cannot be the team that validates it. Validation tests conceptual soundness (is the approach reasonable), ongoing monitoring (does it still perform), and outcomes analysis (what happened when we used it). For a Pakistani bank, the validation function does not need to be enormous; one independent quantitative analyst reporting to the Chief Risk Officer can validate the bank's top ten models seriously. Without that role, every model is implicitly validated by its creator.

Quick check

Quick check: what makes modern AI different from a rule-based program?

The why-tree

Why-tree level one: why three lines of defence? Because the team that builds is naturally optimistic. Independent validation challenges optimism. Audit confirms the challenge happened. Without all three, optimism wins.

Try this with Claude

AI-edge prompt to try: 'You are a model risk validator. For my credit scoring model trained on Pakistani consumer data, design a quarterly outcomes analysis. List ten test cuts (province, gender, income band, etc.) and the metric I should report for each. Output as markdown.' Use as a starter set.

Sources

Sources and further reading. Federal Reserve and OCC, Supervisory Letter SR 11-7 Guidance on Model Risk Management (2011). PRA Bank of England, SS1/23 model risk management principles. State Bank of Pakistan, Risk Management Guidelines. Basel Committee, Newsletter on artificial intelligence and machine learning. Anthropic, Responsible Scaling Policy. McKinsey, Model risk management in financial services 2023.