Awujọ Itọsọna

Model Risk Management (SR 11-7) and AI

SR 11-7 is the Federal Reserve's 2011 supervisory guidance on model risk management, issued jointly with OCC Bulletin 2011-12.

  • 4 min ka
  • kẹhin imudojuiwọn
Lori iwe yi4 min ka
  1. Akopọ
  2. Jin Dive
  3. Ipa Ilana
  4. The Future of Model Risk Management (SR 11-7) and AI
  5. Real-World imuse
  6. Awọn ewu & Awọn ọna iṣọ
  7. Ilana Ilana imuse
  8. Tesiwaju Ṣiṣawari
  9. Awọn ibeere ti a beere nigbagbogbo

Akopọ

It expects banks to develop, validate, govern and monitor the models they rely on. Banks now apply it to machine learning and large language models, which strains traditional validation because these models are often opaque, supplied by vendors and non-deterministic. The guidance matters because a bank using AI for credit, fraud, compliance or customer service has to show supervisors it understands and controls how those models can fail.

Jin Dive

SR 11-7 was issued in April 2011 by the Federal Reserve together with the OCC, and the FDIC adopted it in 2017. It defines a model broadly: a quantitative method, system or approach that applies statistical, economic, financial or mathematical theories to turn input data into quantitative estimates. A model has an input part, a processing part and a reporting part. Model risk comes from two sources: fundamental errors in the model, and using a sound model incorrectly or outside its intended purpose. The guidance rests on three pillars. The first is sound development, implementation and use. The second is validation, which has three core elements: evaluating conceptual soundness, ongoing monitoring (including process verification and benchmarking), and outcomes analysis such as back-testing. The third is governance: board and senior management oversight, written policies, a complete model inventory, and documentation detailed enough that someone unfamiliar with the model could understand how it works. Throughout, the guidance calls for "effective challenge," meaning critical review by people who are objective, informed, competent and influential enough to force changes. Vendor models get no exemption. Banks are expected to get appropriate documentation from vendors. Where proprietary details are withheld, banks should rely more on sensitivity analysis, benchmarking and outcomes testing. A common misconception is that SR 11-7 doesn't reach AI because it predates modern machine learning. Its definition is technology-neutral, and supervisors have treated AI as within scope. Banks usually either classify generative AI tools as models or govern them under a broader AI risk framework that uses the same validation principles. Related references include the OCC's 2021 Comptroller's Handbook booklet on model risk management and the NIST AI Risk Management Framework, released in January 2023. For credit decisions, adverse action notice requirements under the Equal Credit Opportunity Act still apply when the model is complex.

Ipa Ilana

Ewu ati ailewu

Ajalu ati awọn ipalara AI lojoojumọ da lori tani o loye awọn ewu ati tani o le ṣe.

Awọn ipinnu diẹ sii

Imọwe ti gbogbo eniyan ati ọjọgbọn ṣe apẹrẹ boya eto imulo aabo to lagbara jẹ iṣe iṣelu ṣee ṣe.

Gige nipasẹ hype

Awọn alaye ti ko o dinku gbigba nipasẹ aruwo, PR lab, ati ile iṣere iṣere aiduro.

The Future of Model Risk Management (SR 11-7) and AI

Banks are expanding model inventories and building evaluation methods for generative AI. Supervisors have discussed AI governance in speeches and requests for information, but whether formal updates to model risk guidance will come, and what they would say, remains uncertain. The core principles in SR 11-7 (know the model's purpose, test it independently, document its limits, monitor it over time) apply well to LLMs even where specific methods are still being worked out. Expect the most attention on vendor transparency and continuous monitoring.

Real-World imuse

A bank adds a vendor LLM that summarizes customer complaints to its model inventory, assigns it a risk tier, and gives it to an independent validation team before production use.

Validators build a labeled set of several hundred complaints to measure how often the LLM's summaries leave out an issue that must be escalated for regulatory reasons. They set an acceptable error threshold before approving the tool.

A machine learning credit model goes through outcomes analysis against actual defaults, plus fair lending testing. Explanation methods help produce the specific adverse action reasons lenders must give applicants.

A monitoring dashboard tracks shifts in input data and samples LLM output quality every week. When the vendor releases a new model version, the dashboard triggers a targeted revalidation.

Awọn ewu & Awọn ọna iṣọ

  • Itoju eewu ayeraye bi sci-fi lakoko awọn agbo ogun agbara.

  • Aabo ọja dada iruju pẹlu titete labẹ adase to gaju.

  • Nlọ kuro ni ti kii ṣe Gẹẹsi ati awọn olugbo ti kii ṣe alamọja pẹlu awọn orisun didara kekere nikan.

Ilana Ilana imuse

  1. Awọn ipalara ọja lọtọ, ilokulo, ati isonu-iṣakoso / awọn eewu aiṣedeede.

  2. Beere ẹri wo ni yoo yi wiwo rẹ pada lori awọn akoko akoko ati idiwo.

  3. Ṣe ayanfẹ awọn orisun akọkọ ati awọn igbelewọn nija lori awọn ẹtọ tita.

  4. Ṣe idanimọ ọna iṣe kan: iṣẹ, eto imulo, igbeowosile, tabi awọn ọgbọn — kii ṣe akiyesi nikan.

Tesiwaju Ṣiṣawari

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Model Risk Management (SR 11-7) and AI quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Bẹrẹ adanwo

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Awọn ibeere ti a beere nigbagbogbo

What is Model Risk Management (SR 11-7) and AI?

SR 11-7 is the Federal Reserve's 2011 supervisory guidance on model risk management, issued jointly with OCC Bulletin 2011-12. It expects banks to develop, validate, govern and monitor the models they rely on. Banks now apply it to machine learning and large language models, which strains traditional validation because these models are often opaque, supplied by vendors and non-deterministic. The guidance matters because a bank using AI for credit, fraud, compliance or customer service has to show supervisors it understands and controls how those models can fail.

Which OCC document was issued alongside the Federal Reserve's SR 11-7 in 2011?

The OCC issued the same guidance as Bulletin 2011-12, so the two documents are often cited together.

What are the three core elements of validation under SR 11-7?

Validation covers whether the design is sound, whether the model keeps performing as intended, and how its outputs compare with actual results.

What does SR 11-7 require for review to count as "effective challenge"?

Effective challenge means critical analysis by capable, independent people whose findings actually lead to changes.

How should a bank handle a vendor model whose proprietary details are withheld?

Vendor models are still validated. When internal details are unavailable, testing of behavior and outputs carries more weight.

According to the guide, which of these is part of an LLM application's model boundary for change management?

Prompts, retrieval data, parameters, tools and guardrails all shape the output, so changing them counts as a model change.