PRA SS1/23: Model Risk Management Principles for Banks
SS1/23 applies to UK-incorporated banks, building societies, and PRA-designated investment firms that have internal model approval to calculate regulatory capital requirements under Internal Ratings Based (credit risk), Internal Model Approach (market risk), or Internal Model Method (counterparty credit risk) approaches. It sets out five principles the PRA expects firms to embed as a strategic model risk discipline in its own right, comparable in spirit to SR 11-7/SR 26-2 but issued independently by the UK's prudential regulator.
PRA SS1/23 is the Bank of England Prudential Regulation Authority's supervisory statement setting out five model risk management principles for UK banks with internal model approval for credit, market, or counterparty credit risk. It took effect May 17, 2024 and explicitly extends to risks from AI and machine learning modeling techniques.
- Issuing body
- Bank of England Prudential Regulation Authority
- Official reference
- www.bankofengland.co.uk/prudential-regulation/publication/20
What it covers
- Principle 1: Model identification and model risk classification
- Principle 2: Governance, including clear accountability for model risk at an appropriately senior level
- Principle 3: Model development, implementation, and use
- Principle 4: Independent model validation
- Principle 5: Model risk mitigants
- Explicitly extends to identifying and managing risks from AI and machine learning modeling techniques
Adoption status
SS1/23 was published in May 2023 and took effect twelve months later, on May 17, 2024, giving firms a transition period to embed the five principles. It remains current PRA supervisory expectation as of this site's publication date. The PRA has continued engaging with industry on model risk since, including a November 2025 roundtable specifically on AI and machine learning technologies in modeling.
Reference only. This page explains what PRA SS1/23 covers; it is not a claim that Model Risk Directory or any listed vendor satisfies it. Verify alignment directly against the issuing body's own current text before relying on it.
Sources. source 1 · source 2 · source 3. Data as of 2026-07. See methodology.