Reference · 20 terms
Model risk management glossary
Plain-English definitions covering SR 11-7/SR 26-2 vocabulary, independent validation terminology, and the procurement vocabulary that governs model risk management firm sourcing. Written for model risk, quantitative, and internal audit teams who need the vocabulary before a first call.
Core Concepts 3
Effective challenge
Critical analysis by objective, informed parties who can identify a model's limitations and assumptions and produce appropriate changes. SR 11-7 introduced effective challenge as the guiding principle of model risk management; it requires the reviewer to have genuine independence, technical competence, and organizational influence to effect change.
Related: Model validation, Three lines of defense, Model risk management
Model risk
The potential for adverse consequences from decisions based on incorrect or misused model outputs and reports. Model risk increases with greater model complexity, higher uncertainty about inputs and assumptions, broader scope of use, and larger potential financial or reputational impact if the model is wrong.
Related: Model risk management, Effective challenge, Model tiering
Model risk management
Also: MRM
The discipline of identifying, measuring, and controlling model risk across an institution's full model inventory, encompassing model development and use, independent validation, and governance, policies, and controls. Rooted in SR 11-7 (2011) and now SR 26-2 (2026) in the US.
Related: Model risk, Model validation, Model governance
Governance 8
Model change management
The formal process for reviewing, approving, testing, and documenting changes to an existing model, whether a minor recalibration or a substantive redesign, so that changes go through appropriate governance and, where material, trigger revalidation rather than bypassing controls.
Related: Model governance, Model validation, Model inventory
Model documentation
The written record of a model's purpose, theory, design, data sources, assumptions, limitations, and testing, maintained so that a party unfamiliar with the model's construction can understand how it works and evaluate its soundness. Complete documentation is a prerequisite for effective independent validation, not a substitute for it.
Related: Model validation, Conceptual soundness, Model governance
Model governance
The policies, roles, committee structures, and controls an institution puts in place to oversee its model risk management program: who owns the inventory, who approves new models, how validation findings are escalated, and how the board and senior management maintain oversight. One of SR 11-7/SR 26-2's three foundational pillars, alongside model development/use and independent validation.
Related: Model risk management, Three lines of defense, Model inventory
Model inventory
A centralized, maintained record of every model in use across an institution, including each model's purpose, owner, risk tier, and validation status and history. SR 26-2 places renewed emphasis on capturing vendor and third-party models in the inventory, given growing reliance on externally developed tools.
Related: Model tiering, Model governance, Model risk management
See: model risk management software, model risk management framework
Model risk appetite
A board- or senior-management-approved statement of how much model risk an institution is willing to accept in pursuit of its business objectives, used to guide model tiering thresholds, validation resourcing, and escalation criteria for identified model limitations.
Related: Model tiering, Model governance, Model risk
Model tiering
Also: Model risk classification
Classifying models by risk level, based on factors such as financial materiality, complexity, and reliance placed on the model's output, so that validation depth, frequency, and monitoring intensity scale with actual risk rather than applying uniformly across every model in the inventory.
Related: Model inventory, Model risk, Model governance
Third line of defense (model risk)
Also: Internal audit (model risk)
In the three-lines structure applied to model risk management, the third line is internal audit: it independently assesses whether the overall MRM program, governance, inventory discipline, validation function, is working as designed, rather than validating individual models itself. Distinct from the second-line model validation function, which reviews specific models.
Related: Three lines of defense, Effective challenge, Model governance
Three lines of defense
Also: Three lines model
A governance structure in which the first line (model owners/developers) builds and operates models, the second line (an independent risk or model validation function) provides effective challenge and oversight, and the third line (internal audit) independently assesses whether the overall model risk management program itself is functioning as intended.
Related: Effective challenge, Model validation, Model governance
Validation Techniques 9
Backtesting
A statistical technique that compares a model's historical predictions against what actually occurred, used to assess predictive accuracy over time. Backtesting is a specific, quantitative form of outcomes analysis, common in credit scoring, market risk (e.g. Value-at-Risk), and capital models.
Related: Outcomes analysis, Model validation, Ongoing monitoring
Benchmarking (model risk)
Comparing a model's outputs against alternative data, models, or theoretical results to identify differences and understand their sources. In independent model validation, benchmarking often uses a challenger model, an alternative model built to test whether the primary model's results hold up under comparison.
Related: Model validation, Champion-challenger, Conceptual soundness
Champion-challenger
A benchmarking approach in which an institution's production model (the champion) is compared against one or more alternative models (challengers) built independently, often using different methodology, to test whether the champion's results are reasonable and to surface potential weaknesses.
Related: Model validation
Conceptual soundness
An evaluation of the quality of a model's design and construction, including whether its underlying theory, assumptions, data, and methodology are appropriate for its intended business use. Conceptual soundness review is one of the three core techniques of independent model validation, alongside ongoing monitoring and outcomes analysis.
Related: Model validation, Outcomes analysis
Model validation
Also: Independent model validation
The set of processes and activities intended to verify that a model is performing as intended, in line with its design and business uses, and to identify potential limitations and assumptions. Validation is meant to be performed by staff independent from model development, providing effective challenge.
Related: Effective challenge, Conceptual soundness, Outcomes analysis
Ongoing monitoring
Continuous or periodic tracking of a model's performance after deployment, checking that it continues to work as intended as data, markets, or usage patterns evolve, distinct from a full periodic revalidation. Includes outcomes analysis, backtesting, and monitoring of key performance indicators between formal validation cycles.
Related: Outcomes analysis, Backtesting, Model validation
Outcomes analysis
Comparing a model's actual outputs and predictions against real subsequent outcomes to check ongoing accuracy and performance. Outcomes analysis, closely related to backtesting, is a core ongoing-monitoring component of independent model validation.
Related: Backtesting, Model validation, Ongoing monitoring
Sensitivity analysis
Testing how a model's outputs change in response to variations in individual inputs or assumptions, used to identify which factors most influence a model's results and where it may be unstable or overly reliant on a single assumption. A standard technique within conceptual soundness review.
Related: Conceptual soundness, Model validation
Use test
An assessment of whether a model is actually being used the way it was designed and validated to be used, and whether that use remains within the model's intended scope and limitations. A model validated for one purpose but repurposed for another without revalidation is a common source of model risk.
Related: Model validation, Model risk, Conceptual soundness
No terms match your search. Try a different word, or ask us directly.
Model risk management sourcing brief
Occasional emails when we publish a new guide, framework update, or glossary update. No spam, unsubscribe anytime.
Single opt-in. We store only your email to send these updates. See ourprivacy notice. This is procurement information, not a compliance guarantee or legal advice.