Skip to content
Request Demo

Model Governance

Glossary Term • Intermediate • 7 min read

Audience
Model Developers • Auditors
Last Reviewed
July 2026
Updated
Version 1.0

Executive Summary

Model governance is the organisational framework through which an institution defines, implements, and enforces policies and controls for the development, approval, use, validation, change, and retirement of financial models. It establishes accountability for model quality, a structured process for model oversight, and a documented record of model use and validation history. Effective model governance ensures that decisions made using financial models are based on outputs that have been developed to an appropriate standard, validated by a party independent of the developer, and used within the bounds for which they were designed.

Key Takeaways

  • Model governance is the framework through which an organisation manages the lifecycle of its financial models.
  • It includes model inventory, tiering, validation, change control, documentation, and audit trail requirements.
  • Effective model governance reduces model risk by imposing controls at development, validation, use, and retirement.
  • Governance failures most commonly manifest as incomplete inventories, self-validation, stale documentation, and bypassed change control processes.
  • Model governance is both a risk management requirement and, for regulated institutions, a regulatory expectation.

Definition

Model governance is the organisational framework through which an institution defines, implements, and enforces policies and controls for the development, approval, use, validation, change, and retirement of financial models. It establishes accountability for model quality, a structured process for model oversight, and a documented record of model use and validation history.

Effective model governance ensures that decisions made using financial models are based on outputs that have been developed to an appropriate standard, validated by a party independent of the developer, and used within the bounds for which they were designed.

Why It Matters

Financial models are used to make decisions that commit capital, structure debt, price transactions, manage risk, and report to regulators and boards. The quality of these decisions is directly dependent on the reliability of the models that inform them. Without a governance framework, organisations face:

  • Model risk: The risk of financial loss or poor decision-making resulting from errors in model development, implementation, or use
  • Single points of failure: Models understood only by their developer, with no documentation or succession plan
  • Version proliferation: Multiple versions of the same model in circulation with no single authoritative source
  • Undisclosed limitations: Models applied to purposes or inputs outside the bounds for which they were built
  • Regulatory exposure: Failure to demonstrate adequate oversight of models used in regulated decisions

For regulated financial institutions, model governance is also a regulatory expectation. For non-regulated organisations such as infrastructure funds, developers, and investment managers, model governance is a risk management and fiduciary responsibility.

Note: Specific regulatory requirements for model governance vary by jurisdiction and institution type. Practitioners in regulated industries should refer to the applicable guidance from their relevant regulatory authority.

Technical Background

The Model Lifecycle

A model governance framework addresses the full lifecycle of a model:

Stage Description Governance Requirement
Development Model is built by a developer to address a specific business need Development standards; peer review; documentation
Validation Independent review of the model's conceptual soundness, mathematical accuracy, and implementation Validated by a party independent of the developer
Approval Model is formally approved for use, typically by a model risk committee or equivalent Documented approval; defined use boundaries
Use Model is deployed for its approved purpose Use within approved scope; change control
Change Model is modified after initial approval Change management process; re-validation where required
Review Periodic reassessment of model performance and continued fitness for purpose Scheduled review cycle; outcome testing
Retirement Model is decommissioned when it is no longer required Documentation of retirement; output archiving

Core Components of a Model Governance Framework

1. Model Inventory A model inventory is the central register of all models in use within an organisation. It records each model's purpose, owner, developer, validation status, approved use cases, and material limitations. Without a complete inventory, an organisation cannot implement governance consistently. See Model Inventory.

2. Model Tiering Model tiering classifies models by their risk materiality to the organisation. Higher-tier models (those used for capital allocation decisions, regulatory reporting, or transaction execution) attract more stringent governance requirements than lower-tier models. See Model Tiering.

3. Validation Model validation is the process of independently assessing a model's design, assumptions, implementation, and outputs. Validation is conducted by a function or team that is independent of the model developer. See Model Validation.

4. Change Control Any modification to a model after initial approval must follow a defined change management process. Changes are classified by materiality — minor changes may be approved by the model owner; significant changes require re-validation.

5. Documentation Standards Every model should have documentation that describes its purpose, the methodology used, the key assumptions and their sources, the limitations of the model, and the approved use cases. Documentation is a prerequisite for validation and for handover when the model owner changes.

6. Access and Version Control Model governance requires that only the current approved version of a model is available for operational use, that access is controlled to prevent unauthorised modification, and that a version history is maintained.

7. Audit Trail An audit trail records all changes made to a model over time, who made them, and when. It enables post-hoc reconstruction of what the model contained at any given point.

Model Governance in Different Institutional Contexts

Banking and financial services: Regulated institutions operate under specific model risk management frameworks issued by their relevant regulatory authority. These frameworks typically define minimum standards for model development, validation, and documentation, and require a formal model risk function.

Note: Regulatory requirements in this area vary by jurisdiction. Practitioners should refer to the applicable guidance from their regulatory authority.

Infrastructure funds and project finance: Model governance for infrastructure funds and project finance teams focuses on the models used for investment appraisal, debt structuring, and lender reporting. Governance requirements are driven by investor and lender expectations rather than regulatory mandate, but are no less rigorous in practice.

Corporate and private organisations: Organisations that use financial models for capital allocation, M&A, and strategic planning are not typically subject to regulatory model governance requirements. Best practice frameworks from the banking sector are increasingly adopted voluntarily as investor expectations rise.

Model Risk vs Model Governance

Model risk is the risk of loss or error arising from a model failure. Model governance is the framework through which model risk is managed. The two concepts are related: effective model governance reduces model risk by imposing controls at every stage of the model lifecycle.

Audit Considerations

When assessing an organisation's model governance framework, the following elements should be examined:

1. Inventory Completeness

Confirm that the model inventory is complete. A governance framework applied to only some models — particularly if the highest-risk models are excluded — provides limited assurance.

2. Tiering Appropriateness

Confirm that model tiering classifications are appropriate. A model used for a significant capital allocation decision that is classified as low-tier receives less oversight than its risk level warrants.

3. Validation Independence

Confirm that validation is conducted by a function or team that is independent of the model developer. Validation by the developer's manager or by a member of the same team does not constitute independent validation.

4. Change Control Effectiveness

Review the change log for a sample of models and confirm that changes were processed through the required change management procedure. Informal changes that bypass the change control process are a common governance failure.

5. Documentation Currency

Confirm that model documentation is current and reflects the current version of the model. Documentation that describes a prior version of the model is misleading and provides no assurance about the current model.

Common Errors

Error Description Risk
Incomplete inventory Not all models are registered Ungoverned models operate outside the framework
Self-validation Model developer validates their own model No independent check on design or implementation
Stale documentation Documentation describes a previous model version Governance record is inaccurate
Change bypass Material model changes made without following change management procedure Unapproved changes operate without oversight
No tiering All models treated equally High-risk models receive insufficient scrutiny
Framework without enforcement Governance policies exist but are not enforced Paper governance with no operational effect

Best Practices

Implement model governance as a risk management function with clear ownership — typically the Chief Financial Officer, Chief Risk Officer, or a dedicated Model Risk Committee. Governance frameworks that are owned by the modelling team lack the independence needed for effective oversight.

Establish the model inventory as a living document that is updated whenever a new model is built, modified, or retired. An inventory that is updated only at audit time is always stale.

Apply tiering rigorously. The governance overhead applied to a complex investment model used for a billion-dollar capital decision should be materially greater than that applied to a simple operational tool. Proportionality makes governance sustainable.

Treat model documentation as a mandatory deliverable, not an optional extra. A model without documentation cannot be validated, cannot be handed over, and cannot be retired cleanly.


Continue Reading

Prerequisites

How OXXON tests thisRun a free structural check with FMAE

Frequently Asked Questions

Is model governance required by regulation?

For regulated financial institutions, model governance requirements are embedded in the risk management expectations of relevant regulatory authorities in many jurisdictions. For non-regulated organisations, model governance is a best practice driven by fiduciary responsibility and investor expectations. Practitioners should refer to applicable regulatory guidance in their jurisdiction.

What is the difference between model governance and model validation?

Model validation is one component of model governance. Governance is the overarching framework; validation is the specific activity of independently reviewing a model's design, assumptions, and outputs. A model governance framework defines when, how, and by whom validation is conducted.

How large does an organisation need to be to require model governance?

Model governance is proportionate to the complexity and materiality of the models in use, not to the size of the organisation. An infrastructure fund managing a small number of very complex models may require more rigorous governance than a large organisation using many simple operational tools.

Can Excel-based models be governed effectively?

Yes, though Excel's native capabilities for version control, access management, and change logging are limited. Organisations governing Excel-based models typically supplement Excel with external version control systems, access controls, and governance documentation held separately from the model file.

Related Articles

Model Inventory

A model inventory (also referred to as a model register or model catalogue) is a centralised, maintained register of all financial models in active use within an organisation. It records, for each model, the information required to govern it effectively: its purpose, owner, developer, validation status, approved use cases, material limitations, and review schedule. The model inventory is the foundational document of a model governance framework. Without a complete inventory, an organisation cannot systematically apply governance controls, cannot assess its aggregate model risk exposure, and cannot demonstrate oversight to investors, lenders, or regulators.

Model Tiering

Model tiering is the process of classifying financial models into risk-based categories — tiers — that determine the level of governance oversight, validation rigour, documentation standards, and review frequency applied to each model. Higher-tier models, which are more complex, more material to decision-making, or more difficult to verify, receive more intensive governance than lower-tier models. Model tiering allows organisations to apply governance resources proportionately. Without tiering, an organisation must either apply heavy governance to every model (impractical) or apply light governance to every model (insufficient for high-risk models). Tiering resolves this by concentrating oversight where it matters most.

Model Validation

Model validation is the structured, independent process of assessing whether a financial model is conceptually sound, mathematically correct, implemented as intended, and fit for its approved purpose. It is conducted by a reviewer who is independent of the model's developer and produces a documented assessment of the model's strengths, limitations, and any findings requiring remediation. Model validation is a component of model governance. The governance framework defines when validation is required, who conducts it, and what the validation must assess. The validation itself is the technical execution of that requirement.

Model Handover

Model handover is the structured process by which responsibility for a financial model — including operational ownership, update obligations, and decision-making authority — is formally transferred from one individual or team to another. It encompasses the transfer of the model file, all associated documentation, version history, and the knowledge required to operate the model correctly and safely. Model handover occurs in several contexts: when a staff member leaves an organisation, when a project transitions from development to operations, when an advisory firm concludes an engagement and returns a model to the client, or when model ownership is reassigned within a team.

What Is Model Risk?

Model risk is the risk that a decision is wrong not because the underlying business or investment case was flawed, but because the model used to evaluate it was. It is a distinct category of risk from market risk, credit risk, or operational risk, and it applies to any organisation that relies on a financial model, spreadsheet or otherwise, to support a material decision. Most published model risk content addresses statistical and regulatory capital models used inside banks. This page defines model risk specifically as it applies to Excel based financial models, the kind used every day for investment decisions, lending, and transaction evaluation, which is a related but distinct problem from the quantitative model risk literature most search results return.

What Is Financial Model Governance?

Financial model governance is the set of policies, roles, and controls an organisation puts in place to manage the risk that comes from relying on financial models for material decisions. It is the organisational layer that sits above any individual financial model audit: governance determines when a model gets audited, who owns that decision, how versions are tracked, and what happens to findings once they exist. Most published governance content online is written for large, tier one banks operating under formal regulatory regimes. A private equity firm, a family office, or a mid market corporate finance team rarely has that scale of infrastructure, and does not need it, but still carries real exposure if no governance exists at all. This page defines governance at the level that actually applies to most organisations relying on Excel models, not just the largest ones.

Request Demo