- Compliance & Regulation, Risk, Talent & Workforce, Technology
Share
Banks increasingly depend on models and analytical tools to support important decisions—from current expected credit losses and asset/liability management to cybersecurity applications, non-model tools, and emerging AI systems. That makes model risk management part of how institutions understand, challenge, and control the tools shaping risk across the enterprise.
ProSight’s Annual Survey on Model Risk Management, conducted by the Model Validation Consortium (MVC) before the release of SR 26-2, shows an MRM function in transition. The work is becoming more targeted and risk-based, while core principles such as independence, effective challenge, and accountability remain central.
“The foundations of sound model risk management practices endure regardless of a change in emphasis on particular models or the frequency and completeness of assessments,” said Will Kutteh, director of ProSight’s MVC.
Senior leaders can start with five questions:
Is our MRM function independent enough to challenge the business? More than half of survey respondents said their institutions do very well or extremely well at understanding the importance of MRM independence. Most establish that independence through reporting lines into an independent control group such as risk management. The structure matters because effective challenge and the authority to effect change remain central as institutions take on more responsibility for defining and managing model risk exposure.
Are we focusing validation where the risk is highest? SR 26-2 is expected to change the depth and frequency of validation, especially for lower-risk models. Nearly one in three institutions do not subject their lowest-risk models to calendar-based validations, favoring change-driven validation instead. The executive priority is to ensure the highest-risk models receive the right level of attention, while lower-risk tools remain visible enough to identify when their materiality changes.
Do we have enough people to govern growing complexity? A more targeted approach does not automatically reduce the workload. Respondents across bank sizes said they lacked the full-time employees needed to reach their ideal operating state, including for internal and external MRM teams. “As the number and complexity of models grow, institutions need more manpower to responsibly evaluate and report on the risk,” Kutteh said.
How much black-box vendor risk are we accepting? Third-party dependence remains one of the clearest pressure points. Eighty-eight percent of respondents said their institutions outsource some part of the model lifecycle to a third party, yet just 2% said vendors do very well or extremely well at describing black-box components. Even so, 96% said they had terminated zero vendor relationships for MRM deficiencies in the past three years.
Who is responsible for AI oversight? Generative and agentic AI are excluded from SR 26-2, and 59% of respondents said their institutions record AI systems separately from other models. Separate inventories can help clarify ownership, but the risk still needs governance. Explainability was the top challenge to validating AI systems, cited by 67% of respondents.
The takeaway: Model risk touches third-party oversight, AI governance, cybersecurity tools, staffing, regulatory expectations, and accountability across the enterprise. Senior leaders should be asking whether the institution can explain, challenge, monitor, and control the analytical tools shaping key risk and business decisions.
Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.