HƯỚNG DẪN xã hội

Mô hình quản lý rủi ro (SR 11-7) và AI

SR 11-7 là hướng dẫn giám sát năm 2011 của Cục Dự trữ Liên bang về quản lý rủi ro mô hình, được ban hành cùng với Bản tin OCC 2011-12.

  • đọc 4 phút
  • Cập nhật lần cuối
Trên trang nàyđọc 4 phút
  1. Tổng quan
  2. Lặn sâu
  3. Tác động chiến lược
  4. The Future of Model Risk Management (SR 11-7) and AI
  5. Triển khai trong thế giới thực
  6. Rủi ro & lan can
  7. Lộ trình thực hiện
  8. Tiếp tục khám phá
  9. Câu hỏi thường gặp

Tổng quan

It expects banks to develop, validate, govern and monitor the models they rely on. Banks now apply it to machine learning and large language models, which strains traditional validation because these models are often opaque, supplied by vendors and non-deterministic. The guidance matters because a bank using AI for credit, fraud, compliance or customer service has to show supervisors it understands and controls how those models can fail.

Lặn sâu

SR 11-7 was issued in April 2011 by the Federal Reserve together with the OCC, and the FDIC adopted it in 2017. It defines a model broadly: a quantitative method, system or approach that applies statistical, economic, financial or mathematical theories to turn input data into quantitative estimates. A model has an input part, a processing part and a reporting part. Model risk comes from two sources: fundamental errors in the model, and using a sound model incorrectly or outside its intended purpose. The guidance rests on three pillars. The first is sound development, implementation and use. The second is validation, which has three core elements: evaluating conceptual soundness, ongoing monitoring (including process verification and benchmarking), and outcomes analysis such as back-testing. The third is governance: board and senior management oversight, written policies, a complete model inventory, and documentation detailed enough that someone unfamiliar with the model could understand how it works. Throughout, the guidance calls for "effective challenge," meaning critical review by people who are objective, informed, competent and influential enough to force changes. Vendor models get no exemption. Banks are expected to get appropriate documentation from vendors. Where proprietary details are withheld, banks should rely more on sensitivity analysis, benchmarking and outcomes testing. A common misconception is that SR 11-7 doesn't reach AI because it predates modern machine learning. Its definition is technology-neutral, and supervisors have treated AI as within scope. Banks usually either classify generative AI tools as models or govern them under a broader AI risk framework that uses the same validation principles. Related references include the OCC's 2021 Comptroller's Handbook booklet on model risk management and the NIST AI Risk Management Framework, released in January 2023. For credit decisions, adverse action notice requirements under the Equal Credit Opportunity Act still apply when the model is complex.

Tác động chiến lược

Rủi ro và an toàn

Những tác hại thảm khốc và thường ngày của AI đều phụ thuộc vào việc ai hiểu được rủi ro và ai có thể hành động.

Quyết định rõ ràng hơn

Kiến thức công cộng và chuyên môn định hình liệu chính sách an toàn mạnh mẽ có khả thi về mặt chính trị hay không.

Phá vỡ sự thổi phồng

Những lời giải thích rõ ràng làm giảm sự thu hút bởi sự cường điệu, PR trong phòng thí nghiệm và sân khấu đạo đức mơ hồ.

The Future of Model Risk Management (SR 11-7) and AI

Banks are expanding model inventories and building evaluation methods for generative AI. Supervisors have discussed AI governance in speeches and requests for information, but whether formal updates to model risk guidance will come, and what they would say, remains uncertain. The core principles in SR 11-7 (know the model's purpose, test it independently, document its limits, monitor it over time) apply well to LLMs even where specific methods are still being worked out. Expect the most attention on vendor transparency and continuous monitoring.

Triển khai trong thế giới thực

A bank adds a vendor LLM that summarizes customer complaints to its model inventory, assigns it a risk tier, and gives it to an independent validation team before production use.

Validators build a labeled set of several hundred complaints to measure how often the LLM's summaries leave out an issue that must be escalated for regulatory reasons. They set an acceptable error threshold before approving the tool.

A machine learning credit model goes through outcomes analysis against actual defaults, plus fair lending testing. Explanation methods help produce the specific adverse action reasons lenders must give applicants.

A monitoring dashboard tracks shifts in input data and samples LLM output quality every week. When the vendor releases a new model version, the dashboard triggers a targeted revalidation.

Rủi ro & lan can

  • Xử lý rủi ro hiện hữu như khoa học viễn tưởng trong khi khả năng lại phức tạp.

  • Nhầm lẫn giữa an toàn sản phẩm bề mặt với sự liên kết dưới quyền tự chủ cao.

  • Chỉ để lại những khán giả không phải người Anh và không có chuyên môn với những nguồn chất lượng thấp.

Lộ trình thực hiện

  1. Tách biệt các tác hại của sản phẩm, sử dụng sai và rủi ro mất kiểm soát/sai lệch.

  2. Hỏi bằng chứng nào sẽ thay đổi quan điểm của bạn về thời gian và mức độ nghiêm trọng.

  3. Ưu tiên các nguồn chính và đánh giá cụ thể hơn các tuyên bố tiếp thị.

  4. Xác định một lộ trình hành động: sự nghiệp, chính sách, nguồn tài trợ hoặc kỹ năng - không chỉ là nhận thức.

Tiếp tục khám phá

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Model Risk Management (SR 11-7) and AI quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Bắt đầu bài kiểm tra

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Câu hỏi thường gặp

What is Model Risk Management (SR 11-7) and AI?

SR 11-7 is the Federal Reserve's 2011 supervisory guidance on model risk management, issued jointly with OCC Bulletin 2011-12. It expects banks to develop, validate, govern and monitor the models they rely on. Banks now apply it to machine learning and large language models, which strains traditional validation because these models are often opaque, supplied by vendors and non-deterministic. The guidance matters because a bank using AI for credit, fraud, compliance or customer service has to show supervisors it understands and controls how those models can fail.

Tài liệu OCC nào được ban hành cùng với SR 11-7 của Cục Dự trữ Liên bang vào năm 2011?

OCC ban hành hướng dẫn tương tự như Bản tin 2011-12 nên hai tài liệu này thường được trích dẫn cùng nhau.

Ba yếu tố cốt lõi của việc xác nhận theo SR 11-7 là gì?

Việc xác thực bao gồm xem thiết kế có hợp lý hay không, liệu mô hình có tiếp tục hoạt động như dự kiến ​​hay không và kết quả đầu ra của nó so với kết quả thực tế như thế nào.

SR 11-7 yêu cầu điều gì để xem xét được coi là "thử thách hiệu quả"?

Thử thách hiệu quả có nghĩa là những phân tích có tính phê phán được thực hiện bởi những người có năng lực và độc lập, những phát hiện của họ thực sự dẫn đến những thay đổi.

Ngân hàng nên xử lý mô hình nhà cung cấp có thông tin độc quyền bị giữ lại như thế nào?

Các mô hình của nhà cung cấp vẫn được xác nhận. Khi không có thông tin chi tiết nội bộ, việc kiểm tra hành vi và kết quả đầu ra sẽ có trọng lượng hơn.

Theo hướng dẫn, phần nào trong số này là một phần trong ranh giới mô hình của ứng dụng LLM để quản lý thay đổi?

Lời nhắc, dữ liệu truy xuất, tham số, công cụ và rào chắn đều định hình đầu ra, vì vậy việc thay đổi chúng được tính là thay đổi mô hình.