Skip to content

Capstone: a one-page model risk assessment

اختتامی پراجیکٹ: ایک صفحے کا ماڈل رسک جائزہ

40 min read

Three ways to see it

  1. A working one-page model risk assessment has seven sections. Model identity: name, owner, version, purpose. Inputs: data sources and refresh cadence. Methodology: model family and high-level approach. Performance: key metrics, when last measured. Risks: top three model risks (drift, bias, opacity, etc.) with severity. Mitigations: what is being done about each. Sign-off: model owner, validator, CRO, dates. Each section gets two to four lines.

  2. Way one to do this fast: start from the SR 11-7 inventory if it exists. If your bank has any model inventory, pull the row for your chosen model and expand. Each cell in the inventory row corresponds to a section in the one-page assessment. If there is no inventory, this one-pager will become the seed for one.

  3. Way two: write the risks in plain language. 'This model has a 12 percent disparate decline rate against female applicants in our SME book, controlling for declared revenue' is a usable risk. 'Fairness risk' is not. Plain risks attract plain mitigations and plain accountability.

Quick check

Quick check: what makes modern AI different from a rule-based program?

The why-tree

Why-tree level one: why one page, not forty? Because forty pages mean no one reads. Risk assessment is useful only if read.

Try this with Claude

AI-edge prompt to try: 'Acting as an SR 11-7 model validator, draft a one-page model risk assessment for the credit scoring model I describe. Identify three top risks specifically relevant to a Pakistani consumer bank and propose mitigations.' Edit before sending.

Sources

Sources and further reading. Federal Reserve SR 11-7 (2011). PRA SS1/23. State Bank of Pakistan Risk Management Guidelines. Basel Committee Newsletter on AI/ML. ECOA, Regulation B, CFPB fair lending materials. Anthropic Responsible Scaling Policy. NIST AI Risk Management Framework 1.0 and Generative AI Profile.

Previous lesson