Regulatory Model Governance
Executive Summary
Key Takeaways
- ✓ A comprehensive model inventory — every model used for a material business or regulatory purpose, regardless of its complexity or the department that built it — is the foundation of regulatory model governance, and an incomplete inventory is the single most common gap regulators identify.
- ✓ A risk-based tiering methodology should assign each inventoried model a review depth and monitoring frequency based on defined criteria (materiality, complexity, regulatory sensitivity), not treat every model identically regardless of its actual consequence profile.
- ✓ A model should complete a formal approval process — validation, sign-off by an appropriately senior and independent authority — before being used in production for a material decision, not retrofitted after the model is already in live use.
- ✓ Ongoing performance monitoring should be built into the governance framework as a recurring requirement, not a one-time validation exercise at initial approval, since a model's performance can degrade as underlying conditions change even without any change to the model itself.
- ✓ End-user-developed models (spreadsheet models built and maintained by a business unit rather than a formal model development function) are frequently underrepresented in bank model inventories despite carrying the same governance requirements as any other model used for a material purpose.
Objective¶
This guide covers how a bank's model governance framework should be structured to satisfy regulatory model risk management expectations, within Banking Model Risk, extending the general Model Governance concept.
The Model Inventory¶
A comprehensive model inventory — every model used for a material business or regulatory purpose, regardless of complexity or which department built it — is the foundation of regulatory model governance. An incomplete inventory is the single most common gap regulators identify in bank model governance frameworks, since a model that has not been inventoried cannot be tiered, approved, or monitored at all.
Risk-Based Tiering¶
Every inventoried model should be assigned a review depth and monitoring frequency through a risk-based tiering methodology, based on defined criteria — materiality of the decision the model supports, structural complexity, and regulatory sensitivity — rather than applying identical governance to every model regardless of its actual consequence profile.
Formal Approval Before Production Use¶
A model should complete its formal approval process — including independent validation and sign-off by an appropriately senior, independent authority — before being used in production for a material decision, not retrofitted after the model is already in live use. Approval performed after the fact provides materially weaker assurance, since business decisions may already have been made on the model's outputs before any independent review has taken place.
Ongoing Performance Monitoring¶
Governance should include recurring ongoing monitoring, not only a one-time validation exercise at initial approval. A model's performance can degrade over time as underlying conditions change — an economic environment shift, a change in the composition of the portfolio it is applied to — even without any change to the model itself, making periodic re-assessment a necessary part of the framework rather than a one-off event.
The End-User-Developed Model Gap¶
Spreadsheet or similarly informal models — built and maintained by a business unit rather than a formal model development function — are frequently underrepresented in bank model inventories, despite carrying the same governance requirements as any formally developed model used for a material purpose. A governance framework's inventory process should specifically capture these end-user-developed models rather than assuming governance requirements apply only to models built by a dedicated model development function.
Common Construction Pitfalls¶
- Maintaining an incomplete model inventory that omits end-user-developed spreadsheet models or models built outside a formal development function.
- Applying identical governance depth to every model regardless of materiality, complexity, or regulatory sensitivity.
- Approving a model for production use after it has already been relied upon for business decisions, rather than before.
- Treating validation as a one-time event at approval rather than building in recurring ongoing performance monitoring.
Continue Reading¶
Prerequisites¶
- Banking Model Risk — the parent guide
- Model Governance
Related Technical Guides¶
Related Glossary¶
How OXXON tests thisRun a free structural check with FMAE
Frequently Asked Questions
What is a model inventory, and why does it matter?
A comprehensive record of every model a bank uses for a material business or regulatory purpose, regardless of its complexity or which department built it — an incomplete inventory is the single most common gap regulators identify in bank model governance frameworks, since a model that isn't inventoried cannot be governed at all.
What is a risk-based tiering methodology?
A framework assigning each inventoried model a review depth and monitoring frequency based on defined criteria such as materiality, complexity, and regulatory sensitivity, so that governance effort is allocated proportionately rather than treating every model — from a simple calculation tool to a core capital model — identically.
When should a model complete its approval process?
Before being used in production for a material decision, not retrofitted after the model is already in live use — an approval process performed after the fact provides weaker assurance, since decisions may already have been made on the model's outputs before any independent review occurred.
Why does ongoing monitoring matter beyond initial validation?
Because a model's performance can degrade over time as underlying conditions change — a change in the economic environment, the composition of the portfolio it is applied to, or market behaviour — even without any change to the model itself, making a one-time validation at approval insufficient on its own.
What are end-user-developed models, and why are they a common governance gap?
Spreadsheet or similarly informal models built and maintained by a business unit rather than a formal model development function, frequently underrepresented in bank model inventories despite carrying the same governance requirements as any formally developed model used for a material purpose — their informal origin does not exempt them from inventory, tiering, or validation.
How does this guide relate to the general Model Governance concept?
This guide extends that general concept with the specific inventory, tiering, approval, and monitoring components that regulatory model governance frameworks in banking typically require.
Related Articles
Banking Model Risk
Model risk in banking is a distinct, heavily formalized discipline, because banks rely on models for decisions with direct regulatory and financial stability consequences — credit decisions, capital adequacy, and liquidity management chief among them. This guide extends the general Model Risk pillar with the banking-specific model taxonomy (credit, valuation, capital, liquidity models), the three-lines-of-defense structure common to bank model risk management frameworks, and why banking model risk management is typically more formalized than in most other industries.
Banking Model Validation
Banking model validation is the independent, second-line function that tests a bank model's conceptual soundness, implementation accuracy, and ongoing performance against actual outcomes. This guide covers the three pillars of a banking model validation exercise: conceptual soundness review (does the model's design make sense for its intended use), implementation testing (does the model as built actually implement its intended design), and outcomes analysis (does the model's output track what actually happens over time) — and why validation is a distinct discipline from a structural audit.
Model Governance
Model governance is the organisational framework through which an institution defines, implements, and enforces policies and controls for the development, approval, use, validation, change, and retirement of financial models. It establishes accountability for model quality, a structured process for model oversight, and a documented record of model use and validation history. Effective model governance ensures that decisions made using financial models are based on outputs that have been developed to an appropriate standard, validated by a party independent of the developer, and used within the bounds for which they were designed.
Model Tiering
Model tiering is the process of classifying financial models into risk-based categories — tiers — that determine the level of governance oversight, validation rigour, documentation standards, and review frequency applied to each model. Higher-tier models, which are more complex, more material to decision-making, or more difficult to verify, receive more intensive governance than lower-tier models. Model tiering allows organisations to apply governance resources proportionately. Without tiering, an organisation must either apply heavy governance to every model (impractical) or apply light governance to every model (insufficient for high-risk models). Tiering resolves this by concentrating oversight where it matters most.
Model Inventory
A model inventory (also referred to as a model register or model catalogue) is a centralised, maintained register of all financial models in active use within an organisation. It records, for each model, the information required to govern it effectively: its purpose, owner, developer, validation status, approved use cases, material limitations, and review schedule. The model inventory is the foundational document of a model governance framework. Without a complete inventory, an organisation cannot systematically apply governance controls, cannot assess its aggregate model risk exposure, and cannot demonstrate oversight to investors, lenders, or regulators.