Model Tiering
Executive Summary
Key Takeaways
- ✓ Model tiering classifies financial models into risk categories that determine the governance standards applied to each.
- ✓ It allows organisations to apply governance resources proportionately, concentrating oversight on high-risk models.
- ✓ Tier assignment should be based on scored criteria across financial materiality, complexity, usage breadth, decision type, regulatory reliance, and verifiability.
- ✓ Tiers should be reviewed periodically and whenever a model's risk profile changes materially.
- ✓ Governance actions must be tied directly to tier classification; a framework that assigns tiers but does not differentiate governance treatment provides no benefit.
Definition¶
Model tiering is the process of classifying financial models into risk-based categories — tiers — that determine the level of governance oversight, validation rigour, documentation standards, and review frequency applied to each model. Higher-tier models, which are more complex, more material to decision-making, or more difficult to verify, receive more intensive governance than lower-tier models.
Model tiering allows organisations to apply governance resources proportionately. Without tiering, an organisation must either apply heavy governance to every model (impractical) or apply light governance to every model (insufficient for high-risk models). Tiering resolves this by concentrating oversight where it matters most.
Why It Matters¶
Not all financial models carry the same risk. A complex project finance model used to commit $500 million of capital carries fundamentally different risk from a simple operational scheduling tool. Treating them identically is both inefficient and analytically unsound.
Model tiering creates a framework in which:
- High-materiality, high-complexity models receive rigorous independent validation, frequent review cycles, and comprehensive documentation requirements
- Low-materiality, low-complexity models receive proportionate oversight that does not consume disproportionate governance resources
- The organisation's aggregate risk exposure is understood and managed at the portfolio level
- Governance resources are allocated where they deliver the greatest reduction in model risk
Tiering is also a prerequisite for effective model inventory management: an inventory without tier classification cannot drive proportionate governance actions.
Technical Background¶
Common Tiering Frameworks¶
Most model tiering frameworks use three or four tiers. The exact number of tiers is less important than the consistency of the classification criteria. A common three-tier framework:
| Tier | Risk Level | Characteristics | Governance Requirements |
|---|---|---|---|
| Tier 1 (High) | Material | Used for significant capital allocation decisions, regulatory reporting, or transaction execution; complex; difficult to verify by inspection; used by many users | Independent validation required; comprehensive documentation; frequent review cycle; change management process; senior sign-off |
| Tier 2 (Medium) | Moderate | Informs decisions but not at the highest materiality threshold; moderate complexity; used by a defined team | Peer review or limited independent review; standard documentation; regular review cycle; change log required |
| Tier 3 (Low) | Low | Operational or analytical tools; low financial impact; simple and easy to verify; single user | Self-certification; basic documentation; periodic review; no formal change management |
Some organisations add a Tier 0 or Critical tier for models that are operationally critical and whose failure could cause immediate financial loss or regulatory breach.
Classification Criteria¶
Tiers are typically assigned based on a scored assessment across multiple dimensions:
Financial materiality: The size of the financial decision the model informs, or the magnitude of potential financial loss if the model is wrong.
Complexity: The number of calculations, the depth of interdependencies, the use of macros or external data connections, and the difficulty of verifying the model by manual inspection.
Usage breadth: Whether the model is used by a single analyst or by many users across multiple teams or entities. Broader usage amplifies the impact of any error.
Decision type: Whether the model informs a reversible or irreversible decision. A model used to commit capital to a long-term infrastructure project informs an irreversible decision; a model used to prepare a weekly operational report informs a reversible one.
Regulatory or contractual reliance: Whether the model's outputs are used in regulatory reporting, compliance testing, or contractual obligations (such as covenant compliance calculations).
Verifiability: Whether a non-expert user or an independent reviewer can verify the model's outputs by inspection. A simple model with transparent logic and clear documentation is more verifiable than a complex model with embedded macros and undocumented assumptions.
A scoring approach — assigning points in each dimension and summing to a total score — provides an objective basis for tier classification and ensures consistency across the model population.
Dynamic Tiering¶
Model tiers are not permanent. A model's tier should be reassessed when:
- Its scope or purpose changes materially
- It is adopted for use in a higher-stakes context than originally intended
- Its user population changes significantly
- A material change is made to the model
- Periodic review reveals that its risk profile has changed
The model inventory should record the current tier assignment and the date of the most recent tiering assessment.
Tiering in Regulated Contexts¶
For regulated financial institutions, model tiering aligns with the risk-based approach to model risk management specified by relevant regulatory guidance. The tier classification determines which models are subject to formal independent validation requirements and the frequency of those reviews.
Note: Specific regulatory requirements for model tiering vary by jurisdiction and institution type. Practitioners should refer to the applicable guidance from their regulatory authority.
Tiering in Non-Regulated Contexts¶
Infrastructure funds, private equity firms, development companies, and corporate treasury functions that are not subject to formal model risk regulation are increasingly adopting tiering frameworks voluntarily. The motivation is practical risk management rather than regulatory compliance: a tier framework makes governance costs defensible and ensures that high-risk models receive adequate attention.
Audit Considerations¶
1. Framework Existence and Documentation¶
Confirm whether the organisation has a documented model tiering framework with defined criteria and tier descriptions. An undocumented approach to tiering is not consistently applicable.
2. Classification Consistency¶
Review a sample of models across the inventory and assess whether their tier classifications are consistent with the framework's criteria. Systematic inconsistency — particularly systematic underclassification of high-risk models — is a material governance finding.
3. Governance Actions Triggered¶
Confirm that the tier classification triggers the appropriate governance actions. A Tier 1 model that has not been independently validated, or that has not been reviewed within its scheduled cycle, indicates a gap between the tiering framework and its implementation.
4. Re-classification Process¶
Confirm whether there is a defined process for re-classifying models when their risk profile changes. Models that have grown in scope or are being used in higher-stakes contexts but have not been re-classified are operating outside their governance framework.
5. Tiering Review Frequency¶
Models should be periodically reviewed for continued appropriateness of their tier classification. Confirm whether the tiering review is built into the organisation's model governance cycle.
Common Errors¶
| Error | Description | Risk |
|---|---|---|
| No tiering framework | Models governed without tier distinction | Governance resources misallocated |
| Undocumented criteria | Tiers assigned without defined classification rules | Classifications are inconsistent and subjective |
| Systematic underclassification | High-risk models assigned to low tiers | Inadequate governance for material models |
| Tier not linked to governance actions | Tier assigned but does not drive different treatment | Framework exists on paper only |
| No re-classification process | Model tiers not reviewed as models evolve | Stale classifications that no longer reflect actual risk |
Best Practices¶
Define the tiering criteria quantitatively where possible. A scoring rubric produces more consistent and defensible classifications than narrative descriptions alone.
Require sign-off on tier classifications by a function that is independent of the model owner — typically the model governance function or a model risk committee. This prevents model owners from systematically underclassifying their own models to reduce governance burden.
Use the tier distribution as a management information metric: what proportion of the model population is at each tier, and is this distribution consistent with the organisation's risk profile? An organisation with many Tier 1 models and inadequate validation resources has a structural risk management gap.
Review tier classifications at each annual inventory review, and trigger an immediate reclassification review whenever a model's purpose, scope, or user population changes materially.
Continue Reading¶
Prerequisites¶
- What Is Financial Model Governance? — the parent pillar
Related Pillars¶
Related Glossary¶
How OXXON tests thisRun a free structural check with FMAE
Frequently Asked Questions
How many tiers should a model governance framework have?
Three tiers (High, Medium, Low) is the most common framework and is sufficient for most organisations. Four tiers can be appropriate for large organisations with a wide range of model complexity. More than four tiers typically creates unnecessary complexity without additional precision.
Who decides a model's tier?
The model owner typically proposes the tier classification. The model governance function or a model risk committee should review and approve the classification, particularly for Tier 1 models. Self-classification without independent review creates a conflict of interest.
Does the tier classification affect who can use the model?
It can. Some organisations restrict use of Tier 1 models to qualified users with specific training or authorisation. More commonly, the tier classification affects validation, documentation, and change management requirements rather than access rights.
What happens if a model is used above its tier?
If a model classified as Tier 3 is used to inform a Tier 1 decision without being reclassified, it is operating outside its governance framework. The organisation is exposed to model risk without the compensating controls that the decision's materiality warrants. This is a governance gap that should be identified and remedied.
Related Articles
Model Governance
Model governance is the organisational framework through which an institution defines, implements, and enforces policies and controls for the development, approval, use, validation, change, and retirement of financial models. It establishes accountability for model quality, a structured process for model oversight, and a documented record of model use and validation history. Effective model governance ensures that decisions made using financial models are based on outputs that have been developed to an appropriate standard, validated by a party independent of the developer, and used within the bounds for which they were designed.
Model Inventory
A model inventory (also referred to as a model register or model catalogue) is a centralised, maintained register of all financial models in active use within an organisation. It records, for each model, the information required to govern it effectively: its purpose, owner, developer, validation status, approved use cases, material limitations, and review schedule. The model inventory is the foundational document of a model governance framework. Without a complete inventory, an organisation cannot systematically apply governance controls, cannot assess its aggregate model risk exposure, and cannot demonstrate oversight to investors, lenders, or regulators.
Model Validation
Model validation is the structured, independent process of assessing whether a financial model is conceptually sound, mathematically correct, implemented as intended, and fit for its approved purpose. It is conducted by a reviewer who is independent of the model's developer and produces a documented assessment of the model's strengths, limitations, and any findings requiring remediation. Model validation is a component of model governance. The governance framework defines when validation is required, who conducts it, and what the validation must assess. The validation itself is the technical execution of that requirement.
What Is Model Risk?
Model risk is the risk that a decision is wrong not because the underlying business or investment case was flawed, but because the model used to evaluate it was. It is a distinct category of risk from market risk, credit risk, or operational risk, and it applies to any organisation that relies on a financial model, spreadsheet or otherwise, to support a material decision. Most published model risk content addresses statistical and regulatory capital models used inside banks. This page defines model risk specifically as it applies to Excel based financial models, the kind used every day for investment decisions, lending, and transaction evaluation, which is a related but distinct problem from the quantitative model risk literature most search results return.
Model Materiality
Model materiality is the threshold at which an error, deviation, limitation, or uncertainty in a financial model is considered significant enough to affect a decision, require remediation, or warrant disclosure. A finding is material if, had it been known, it would or could have changed a decision made using the model's outputs. Model materiality is a judgement — it depends on the purpose of the model, the magnitude of the finding, and the sensitivity of the key outputs to the finding. The same error may be material in one context and immaterial in another.
What Is Financial Model Governance?
Financial model governance is the set of policies, roles, and controls an organisation puts in place to manage the risk that comes from relying on financial models for material decisions. It is the organisational layer that sits above any individual financial model audit: governance determines when a model gets audited, who owns that decision, how versions are tracked, and what happens to findings once they exist. Most published governance content online is written for large, tier one banks operating under formal regulatory regimes. A private equity firm, a family office, or a mid market corporate finance team rarely has that scale of infrastructure, and does not need it, but still carries real exposure if no governance exists at all. This page defines governance at the level that actually applies to most organisations relying on Excel models, not just the largest ones.