Treat model risk as a risk discipline
Model risk is the possibility of adverse consequences from errors, weaknesses or inappropriate use of model outputs. Managing it therefore requires more than periodic technical validation. The institution needs clear ownership, risk appetite, classification, lifecycle controls and escalation routes that connect modelling choices to business consequences.
The PRA's SS1/23 frames model risk management as a discipline in its own right. That framing matters because it moves accountability beyond individual modelling teams and into the senior management and board structures that approve strategy, capital and risk-taking.
Start with a decision-use inventory
A model inventory should identify more than code and owners. It should record the decisions supported, users, data dependencies, key assumptions, limitations, change history and downstream systems. Models embedded in spreadsheets, vendor platforms and end-user tools can be material even when they are not labelled models by their developers.
Materiality should reflect potential financial impact, regulatory significance, customer consequences and the degree of reliance placed on the output. A tiering method then determines validation scope, monitoring frequency, approval authority and the urgency assigned to findings.
Make independent challenge consequential
Effective validation assesses conceptual soundness, data, implementation, performance, limitations and use. The validator should be able to challenge whether the model is suitable for the decision—not merely whether calculations reproduce the developer's specification.
Findings require severity, ownership, target dates and compensating controls. Acceptance of a limitation should be explicit, time-bound and made by an authority with the mandate to own the resulting risk. Repeated extensions without new evidence should be visible in senior reporting.
Report what changes decisions
Board reporting should prioritise exposure to model risk: material models outside appetite, overdue high-severity findings, performance deterioration, unapproved use, concentration in shared data or vendors, and limitations affecting capital or customer outcomes.
In 2026 the PRA clarified the relationship between broader SS1/23 expectations and stress-testing model governance. The practical lesson is that institutions should avoid parallel governance systems where one coherent model-risk framework can support accountability across use cases.