- Compliance & Regulation, Risk, Technology
ProSight’s Model Risk Survey Highlights Core Principles, Challenges As Focus, Regulation Shift
- Professionals Assess Practice Under SR 11-7, Durable Themes for SR 26-2
Michael Bender
Share
This year’s Annual Survey on Model Risk Management (MRM) conducted by ProSight Financial Association’s Model Validation Consortium explores themes top of mind for model risk professionals as changes in regulatory winds push the MRM discipline in new directions.
Conducted before the April release of Revised Guidance on Model Risk Management (SR 26-2), the study describes practice under SR 11-7, elaborating approaches that will be tested as responses to regulators’ new tailored, risk-based guidance take shape.
Importantly, it shows how ironclad principles such as effective challenge, independence, and the authority to effect change—reinforced in SR 26-2—endure in institutions as more responsibility for defining and managing overall model risk exposure shifts their way. In the survey, more than half (54%) of respondents said their institutions do very well or extremely well at understanding the importance of MRM independence.
“The foundations of sound model risk management practices endure regardless of a change in emphasis on particular models or the frequency and completeness of assessments,” said Will Kutteh, director of ProSight’s Model Validation Consortium.
Organizationally, most institutions (89%) establish this independence through reporting lines for MRM reporting into an independent control group such as risk management. Gradually, those lines are moving from the deputy or chief risk officer (54% in 2026 vs. 61% in 2025) to the head of enterprise risk management (31% vs. 27%) or operational risk management (9% vs. 5%).
The survey results also expose the challenges, such as third-party model validation, that remain regardless of new approaches to risk assessment. In this year’s survey, for example, just 2% of respondents said vendors do very well or extremely well at describing the black-box components of their models—consistent with 1% and 3% of respondents in each of the prior two years.
One aspect of MRM sure to change under SR 26-2 is the depth and frequency of model validations, particularly those deemed less risky under current and future classifications. The survey suggests that nearly 1 in 3 institutions do not subject their lowest-risk models to calendar-based validations, indicating a preference for change-driven validations. This trend is likely to continue under new guidance, with institutions focusing effort on validating Tier 1, or the highest risk, models while scaling back testing of less critical ones.
That doesn’t mean staffing needs will ease. In the study, respondents at banks of all sizes said they lacked the FTEs needed to achieve their ideal operating state, including for internal and external MRM teams. Most said they needed more non-validation support staff as well.
“As the number and complexity of models grow, institutions need more manpower to responsibly evaluate and report on the risk,” Kutteh said.
Artificial intelligence oversight will take on a new character under SR 26-2, as both generative and agentic AI have been excluded from the new model risk guidance. That’s consistent with prevailing trends in industry practice as more institutions have moved toward recording AI and AI-related systems in separate inventories from other models.
In the 2026 survey, 59% of respondents said their institutions record AI systems separately versus 14% in the 2025 survey. Likewise, 28% now assign policy/framework responsibility to a separate AI committee/working group versus 4% last year.
Cybersecurity models and non-model tools, meanwhile, remain in the model inventory for most institutions (81%), and those models are validated at least most of the time (72%). Still, 78% of institutions rest responsibility for cybersecurity risk with their IT/information security teams.
MRM’s Expanding Purview
When it comes to oversight of models and non-models under MRM, institutions are discriminating less among quantitative models, qualitative models, and non-model tools. This year, 60% of respondents said their non-model tool programs sit within their MRM policy/program, versus 38% last year, though they continue to identify them separately (72%) from model inventory. At the same time, more than 70% said they don’t distinguish between quantitative and qualitative models in their model inventory, an increase from 55% last year.
In terms of consistency of definitions, institutions have settled these past few years on a set of attributes to describe non-model analytical tools. Those include calculations or logic used for business purposes (72%), the absence of assumptions (49%), and functionality that does not produce estimates or forecasts (68%).
More than half of institutions (62%) survey the enterprise annually to identify new models and verify inventories. For most, the highest-risk models (whether banks use a three-, four-, or five-tier system) sit within Current Expected Credit Losses (CECL) (88%) and asset/liability management (ALM) (80%) processes. For banks with more than $250 billion of assets, high-risk models are spread across everything from stress testing to market risk.
Validation and Review Cadence
Regardless of the number of rating tiers they maintain, more than 75% of responding organizations review their Tier-1 models annually. More than three-quarters of respondents (82%) said a review can trigger a new finding or issue.
More than two-thirds (68%) said those reviews sometimes trigger a model re-validation. If that trigger rating is severe enough, 40% said that their institutions would pause use of the model until the issue is remediated. Otherwise, about three in four said, they conduct full-scope independent validation on Tier-1 models at least every two years.
For lower-tier models, more than half of respondents said they reviewed each tier every 12 months, regardless of the number of tiers they use. About 30% of institutions said they do not validate their lowest risk models—a practice that may expand under new, more flexible SR 26-2 model risk guidance.
“Model purpose, together with model exposure, determines model materiality,” the letter states. “Bank organizations may deem certain models immaterial…in those cases, model risk management may consist of identifying those models and monitoring model performance and conditions under which the use of models may become material to the banking organization in the future.”
For those hoping to expand their model validation capabilities, typical barriers remain. Cost is tops (69%), followed by talent (55%), resources (55%), and technology (18%)—percentages consistent with those in the prior two years.
Model Vendors and the Black Box
When a vendor fails to meet MRM requirements for documentation, validation, or developmental testing, institutions take steps to flag and rectify the situation, including issuing a validation finding (54%), re-evaluating the model’s risk rating (49%), and increasing monitoring frequency (44%). Few, though, stop using the vendor entirely (14%). When asked how many times respondent institutions had terminated a vendor relationship for MRM deficiencies in the past three years, 96% said “zero.”
That’s because the industry has become almost universally dependent on third-party outsourcing for at least part of its model needs. About nine in 10 (88%) respondents said their institutions outsource some part of the model lifecycle to a third party. Even so, the challenge, they say, is that these vendors fall short of expectations in explaining everything from theory and conceptual soundness (61%) to model design and analytics (63%).
And they’re not improving much from previous years, the survey suggests. Vendor contracts often lack language around specific MRM customer obligations. And many third parties don’t provide external, independent validations of their own products.
“Despite raising concerns and pushing back against the opaqueness of third-party MRM practices, institutions are beholden to their providers because building their own capabilities can be cost prohibitive,” Kutteh said.
Almost half of respondents (48%) said that 10% or fewer of their model vendors conduct and provide evidence of independent validation, and 85% of organizations said they received validation reports from 50% or fewer of their model vendors. When it comes to documentation, 84% said they ask for more information from the vendor when documentation is deficient, while another 10% accept the vendor’s claims that the analytics are valid.
The model risk function continues to play an important role in vendor onboarding generally. While vendor management typically takes the lead (96%), model risk (76%) is also closely involved.
AI: A Special Case
How institutions are to manage AI model oversight going forward remains an outstanding question in SR 26-2. The letter expressly separates generative and agentic AI models from inclusion in model risk inventories, leading some to speculate that further clarity is forthcoming.
The position is consistent with industry practice; almost two-thirds (59%) already record these in separate AI inventories. Generative AI is the most widely used technology (75%), with machine learning (71%) close behind. While banks are enthusiastic about the future potential of agentic AI and agentic workflows, only 11% of respondents said their institutions were using them. Overall, only a third (29%) have reached the “operate and monitor” stage with any AI use case, a state where an AI system is continuously used within a well-structured governance environment.
For now, institutions are parsing the treatment of AI systems. While 44% of respondents said they don’t monitor or test individual AI use cases, another 31% said they do it ad hoc. For those AI systems classified as models, 87% of respondent institutions validate them at least sometimes. For those identified as non-model tools, 60% said they are not validating them at all and 40% said they look at them sometimes.
Flagging a potential risk, 42% of respondents said that they never validate AI systems classified in a separate AI inventory, while 38% said they do only sometimes. In the still-early stages of AI in production, institutions are relying heavily on people to validate results in the field.
Human-in-the-loop review (71%) was by far the most common method institutions use to review and control AI. Some do reasonableness testing (22%), hallucination rate testing (10%), and bias/fairness testing (6%). Explainability (67%) remains the top challenge to validating AI systems—reflecting the black-box nature of large language models.
“Evaluating AI models and applying sound risk assessment principles are still very much a work in progress,” Kutteh said.
Conclusion
As the industry adapts to SR 26-2, the survey findings reveal that model risk management is becoming more targeted in its application while remaining firmly anchored in principles such as independence, effective challenge, and accountability.
Institutions are expanding oversight beyond traditional quantitative models to include non-model tools, cybersecurity applications, and emerging AI technologies, even as resource constraints and vendor transparency concerns persist.
At the same time, organizations continue to rely heavily on third parties and are still working to establish consistent approaches for AI governance and validation. Together, the findings depict an MRM function whose responsibilities continue to broaden and evolve while its core mission—ensuring the sound, controlled use of analytical tools across the enterprise—remains unchanged.
Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.