RP-006: Model Validation vs. Model Audit — A Methodological Comparison
Executive Summary
Key Takeaways
- ✓ Model audit and model validation answer categorically different questions — mechanical correctness versus methodological and assumption appropriateness — rather than being two intensities of the same exercise.
- ✓ Audit is amenable to deterministic, systematic, repeatable methodology because mechanical correctness is a checkable structural property. Validation inherently involves judgement, since appropriateness is contextual to the model's specific purpose.
- ✓ A model can pass audit and fail validation (calculating exactly as designed, on an inappropriate design) or fail audit and pass validation (a sound methodological approach, undermined by a formula error) — the two results are independent.
- ✓ Because the two disciplines test independent properties, using either exercise as a substitute for the other leaves a corresponding risk category completely unaddressed, not merely under-addressed.
Institutional publication. Not peer-reviewed.
Abstract¶
This paper compares model validation and model audit as distinct methodological disciplines within financial model risk management, treating them as answering categorically different questions rather than representing two intensities of the same underlying exercise.
1. The Two Questions¶
Model audit asks: does this model, as built, calculate what it claims to calculate? This is a question about mechanical correctness — whether the formulas, references, and structural logic actually implement the calculation the model's labels and documentation claim they implement, independent of whether that calculation is the right one to be running.
Model validation asks: is the modelling approach and are the assumptions chosen appropriate for this model's specific intended purpose? This is a question about fitness for purpose — whether the methodology itself, correctly implemented, is the right methodology given what the model is being used to decide.
2. Why Audit Admits a Deterministic Methodology and Validation Does Not¶
Mechanical correctness is a structural property: a formula either does or does not implement a stated calculation correctly, and this can be checked systematically against a fixed methodology applied consistently to every formula in the model. This is precisely what makes audit amenable to a deterministic, rule-based engine — the kind FMAE's own Rule Engine & Rule Packs implements — since the check does not require judgement about the model's purpose, only about whether its internal logic is self-consistent and free of the specific structural defects a rule targets.
Appropriateness, by contrast, is inherently contextual. The same modelling choice — a simplified discount rate assumption, a particular treatment of working capital — can be entirely appropriate for one decision (an early-stage feasibility screen) and inappropriate for another (a binding financial close). Validation therefore inherently involves judgement in a way audit, as defined here, does not.
3. Independence of Outcomes¶
Because the two disciplines test different properties, their outcomes are independent rather than correlated in any necessary direction:
- A model can pass audit and fail validation: every formula calculates exactly as its author intended, but the underlying modelling approach — perhaps an oversimplified treatment of a material risk — is not appropriate for the decision the model supports.
- A model can fail audit and pass validation: the chosen methodology is sound and well-suited to the model's purpose, but a formula error (a hardcoded value, a broken reference, an inconsistent row) undermines the model's actual calculated output regardless of how sound the underlying approach is.
This independence is the methodological basis for treating audit and validation as complementary rather than substitutable exercises — each addresses a risk the other does not test for at all.
4. Practical Implication¶
For a model supporting a genuinely material decision, relying on only one of the two disciplines leaves the other risk category completely untested, not merely less thoroughly tested. This is a direct extension of the buyer-facing comparison already published on the Knowledge Centre's Audit vs Validation page, restated here in methodological rather than commercial register.
Related Reading¶
- Audit vs Validation — the Knowledge Centre's buyer-facing treatment of this same distinction.
- FMAE Rule Engine & Rule Packs — the execution model that makes deterministic audit, specifically, possible.
How OXXON tests thisRun a free structural check with FMAE
Frequently Asked Questions
What is the core methodological difference between model audit and model validation?
Audit tests whether a model's formulas and structure calculate correctly, given whatever assumptions and approach the model uses. Validation tests whether the chosen assumptions and modelling approach are appropriate for the model's specific intended purpose, independent of whether the resulting formulas are mechanically correct.
Why is audit more amenable to a deterministic, repeatable methodology than validation?
Mechanical correctness is a structural property checkable against a defined methodology applied consistently to every formula. Appropriateness of a modelling approach is inherently contextual and judgement-based — the same modelling choice can be appropriate for one purpose and inappropriate for another.
Can a model pass one discipline and fail the other?
Yes, in both directions. A model can calculate exactly as its author intended (passing audit) while resting on an approach unsuited to its purpose (failing validation). Conversely, a model can use an entirely sound and appropriate methodology (passing validation) while containing a formula error that causes it to calculate incorrectly (failing audit).
Related Articles
FMAE Rule Taxonomy
Every rule in the FMAE structural rule pack declares a category attribute at the point it is defined in source — this is not a classification imposed on the rules afterward for documentation purposes, it is the classification the engine itself uses. Six categories cover all 26 rules — Structural (18 rules), Assumptions Governance (1), Integrity Controls (2), Structural Hygiene (1), Aggregation Logic (1), and Model Governance (3). This page publishes that taxonomy as the FMAE equivalent of a control catalog's classification scheme, cross-linked to the Rule Reference page for each member rule.
FMAE Scoring Engine — SM-2.0 Methodology
FMAE computes a model's risk score as 100 minus the triggered rules' combined weight, normalized against a fixed basis, currently 207.0 under the active SM-2.0 methodology. SM-1.0, the engine's original scoring basis (170.0, covering R001–R021), is retained as a frozen historical reference rather than deleted from the record. Five rules — R001, R002, R004, R006, and R023 — are critical-override rules. If any of them triggers, the resulting letter grade is capped so a model cannot be graded A or B regardless of how high its numeric score is. This page documents the exact formula, the versioning between SM-1.0 and SM-2.0, and a fully worked example.