What is Model Risk Management?
Model risk management is the governance process for identifying, measuring, monitoring, validating, and controlling risks arising from the design, use, and change of AI and other models. It matters because regulators expect firms to demonstrate that model outputs are reliable, explainable where needed, and subject to effective oversight throughout the model lifecycle.
In Depth
In practice, model risk management covers the full lifecycle of a model: intake and classification, development standards, independent validation, testing for bias and performance, approval, periodic review, change control, and retirement. For AI systems, it also typically includes oversight of training data quality, drift, human review, vendor dependencies, and documentation showing what the model is intended to do and where it should not be used.
For compliance teams, the key issue is proving that the organization can control model-related harm such as inaccurate decisions, unfair outcomes, operational disruption, and regulatory breaches. Financial regulators have long treated model risk management as a core control area, and AI governance frameworks such as ISO/IEC 42001, the NIST AI RMF, and sectoral guidance in banking and insurance align closely with these expectations; in the EU, similar controls are also relevant to high-risk systems under the EU AI Act, especially around risk management, testing, monitoring, and post-market oversight.
Related Frameworks
Related Topics
Related Terms
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy