Skip to main content
Category: Management System Governance

Enterprise-Wide Model Risk Framework

Also known as: Enterprise-Wide Model Risk Management Framework, Enterprise-Wide MRM Framework
Simply put

An enterprise-wide model risk framework is the organization-level structure of policies, roles, and processes an institution uses to identify, manage, and oversee the risks that arise from using models across its entire business, rather than in isolated pockets. It aims to ensure that model risk is understood and controlled consistently throughout the organization, typically using a risk-based approach that focuses more attention on higher-risk models. Such frameworks are most developed in financial institutions, where regulators have set expectations for how they should work.

Formal definition

As commonly defined in supervisory guidance, an enterprise-wide model risk framework is the institution-level governance and control architecture through which model risk is identified, measured, monitored, and managed consistently across all business lines and model uses, typically applying a risk-based (proportional) approach that calibrates controls to a model's assessed risk. In the financial-sector context, guidance such as OSFI's Guideline E-23 sets out principles-based expectations for effective enterprise-wide model risk management (MRM), and framework materials commonly emphasize that model risk should be well understood and managed across the enterprise, governed appropriately, and embedded within broader enterprise risk management (ERM) processes. Note that this term denotes the overarching framework for managing model risk (identification, measurement, monitoring, and control of risks arising from model use) and should be distinguished from AI governance more broadly and from general ERM, which addresses the full range of enterprise risks; the specific expectations, effective dates, and applicability of any given instrument are jurisdiction- and sector-specific and should be confirmed against the issuing authority's text.

Why it matters

As institutions deploy models across lending, capital adequacy, fraud detection, pricing, and increasingly AI-driven functions, managing model risk in isolated pockets leaves the organization exposed to inconsistent controls, undetected concentrations of risk, and gaps that no single business line owns. An enterprise-wide model risk framework matters because it seeks to ensure that model risk is understood and managed consistently across all business lines rather than depending on the varying practices of individual teams. Supervisory materials in the financial sector, such as OSFI's Guideline E-23, articulate expectations that model risk be well understood and managed across the enterprise, governed appropriately, and managed using a risk-based approach.

The practical significance is that an enterprise-wide view allows an institution to calibrate the intensity of its controls to the assessed risk of each model, directing more oversight to higher-risk uses. Commentary on OSFI's E-23 frames such a framework as a tool for fostering a culture of risk-aware innovation by embedding model risk management within broader enterprise risk management processes. This embedding is important because it treats model risk not as a standalone technical concern but as one component of the full range of enterprise risks the organization tracks and reports on.

It should be emphasized that a framework of this kind is a means of managing and reducing model risk, not eliminating it, and that its specific expectations, applicability, and effective dates are jurisdiction- and sector-specific. The most developed expectations sit in financial services; institutions in other sectors may adapt similar structures voluntarily, but they should not assume that financial-sector supervisory guidance applies to them or is interchangeable with AI governance instruments or general enterprise risk management.

Who it's relevant to

Model risk managers and validation teams
Those responsible for identifying, measuring, and monitoring model risk rely on the framework to define consistent standards, ownership, and risk-based prioritization across the institution's model inventory, rather than managing risk model-by-model in isolation.
Compliance officers and risk governance functions
Professionals overseeing adherence to supervisory expectations, such as those in OSFI's Guideline E-23 for institutions within its scope, use the framework to demonstrate that model risk is governed appropriately and embedded within broader enterprise risk management. They should confirm applicability, scope, and effective dates against the issuing authority's text.
Board members and senior management
Those accountable for enterprise-level risk oversight depend on the framework to provide a consistent, organization-wide view of model risk and to support risk-aware decision-making, including where models support innovation.
Auditors and independent review functions
Internal and external reviewers assess whether the framework operates as designed across business lines, whether the risk-based approach is applied consistently, and whether model risk management is genuinely integrated into enterprise risk management rather than existing only on paper.
Data scientists and model developers
Practitioners who build and deploy models operate within the framework's policies and controls, with the intensity of documentation, testing, and oversight typically scaled to the assessed risk of the model they are developing.

Inside Enterprise-Wide Model Risk Framework

Model Inventory
A centralized, maintained record of models in use across the organization, typically capturing ownership, purpose, risk tier, and lifecycle status. In many frameworks the inventory is treated as a foundational control, since risks cannot be managed for models that are not identified. Coverage often extends beyond statistical models to certain AI/ML systems, though the boundary of what counts as a 'model' can be contested and firm-specific.
Risk Tiering / Materiality Assessment
A method for classifying models by their inherent risk and materiality, so that oversight intensity is proportionate. This commonly considers factors such as decision impact, exposure, and complexity. Note the distinction between inherent risk (before controls) and residual risk (after controls are applied).
Governance Structure and Roles
The organizational arrangements—committees, policies, and defined accountabilities—that establish oversight of models. This element is where model risk management intersects with broader AI governance, but the two are not identical: governance provides the accountability and oversight structures, while model risk management focuses on identifying, measuring, monitoring, and controlling model-specific risk.
Three Lines of Defense
A common allocation of responsibilities in which the first line (model owners/developers) owns and manages risk, the second line (independent risk oversight, including validation) challenges and monitors it, and the third line (internal audit) provides independent assurance over the framework. These lines are distinct and should not be collapsed into one another; independence expectations differ by line.
Model Validation
An independent set of activities assessing whether a model is conceptually sound and performing as intended for its purpose. Validation is distinct from verification: validation asks whether the right model was built for the intended use, while verification typically checks whether the model was implemented correctly against specification. Historically framed in guidance such as SR 11-7 / OCC 2011-12 (U.S. banking supervisory guidance), though scope varies by sector.
Ongoing Monitoring
Continuous or periodic tracking of model behavior in production to detect issues over time. This addresses model performance degradation (deterioration in accuracy or stability) as a component of, but not synonymous with, broader model risk, which also includes risks from incorrect use or fundamental design flaws.
Policies, Standards, and Documentation
The written requirements defining how models are developed, validated, approved, used, and retired, together with the documentation evidencing compliance. Documentation supports auditability and independent challenge but does not by itself reduce underlying model risk.
Change Management and Lifecycle Controls
Controls governing model development, approval, deployment, modification, and decommissioning, so that changes are subject to appropriate review commensurate with risk tier.

Common questions

Answers to the questions practitioners most commonly ask about Enterprise-Wide Model Risk Framework.

Is an enterprise-wide model risk framework the same thing as AI governance?
No, though the two overlap. A model risk framework is typically oriented around the identification, measurement, monitoring, and control of risks arising from the use of models, an approach historically shaped by guidance such as SR 11-7 in the U.S. banking context. AI governance, by contrast, more broadly addresses organizational structures, policies, accountability, and oversight for AI systems. An enterprise-wide model risk framework may be one component supporting AI governance, but the two are not interchangeable, and collapsing them can obscure gaps in either the risk-control dimension or the accountability-and-oversight dimension.
Does implementing an enterprise-wide model risk framework eliminate model risk?
No. A framework is a set of measures intended to reduce, manage, and provide visibility into model risk, not to eliminate it. Even well-designed frameworks leave residual risk after controls are applied, and models remain subject to performance degradation, changing conditions, and limitations in validation. Framing a framework as risk-reducing rather than risk-eliminating is important for setting accurate expectations with management, boards, and, where relevant, regulators.
How does an enterprise-wide framework typically organize accountability across the organization?
Many frameworks are described using a three-lines-of-defense structure, in which the first line generally owns and operates models, the second line provides independent oversight and challenge (often including model validation and model risk management functions), and the third line provides independent assurance, commonly through internal audit. The specific allocation of roles varies by organization and sector, and firms should document who is responsible for development, validation, approval, monitoring, and escalation rather than assume a single standard mapping applies.
How should an organization decide what counts as a model within scope of the framework?
Scoping usually begins with a working definition of what constitutes a model in the organization's context, followed by an inventory that captures those items and their intended uses. Because definitions of a model can differ across firms and sectors, organizations typically document their own criteria and consider borderline cases such as certain calculators, tools, or automated processes explicitly. The inventory commonly supports risk tiering, ownership assignment, and coverage checks, and firms should note where their definition may exclude items that others would treat as models.
How is risk tiering commonly used within an enterprise-wide model risk framework?
Risk tiering is often used to calibrate the intensity of controls to the inherent risk of a model, so that higher-risk models receive more rigorous validation, more frequent monitoring, and higher levels of approval, while lower-risk models receive proportionate treatment. Tiering criteria vary but frequently consider factors such as materiality of use, complexity, and potential impact. It is important to distinguish inherent risk, assessed before controls, from residual risk, which remains after controls are applied, since tiering typically informs how much control effort is warranted.
What ongoing activities does a framework typically require after a model is approved and deployed?
Beyond initial validation and approval, frameworks commonly call for ongoing monitoring, periodic review or revalidation, and escalation and remediation processes when issues arise. Monitoring is frequently used to detect model performance degradation over time, which is a distinct concern from the broader category of model risk. Frameworks also typically address documentation, change management, and handling of exceptions or limitations. The specific cadence and depth of these activities are usually tied to the model's risk tier and to the organization's own policies rather than to a single universal requirement.

Common misconceptions

An enterprise-wide model risk framework is the same thing as AI governance.
They overlap but are not interchangeable. AI governance concerns the organizational structures, policies, and accountability for AI systems broadly, while model risk management focuses specifically on identifying, measuring, monitoring, and controlling risks arising from model use. A model risk framework may be one input to, or component of, an organization's AI governance, but neither fully contains the other.
Implementing the framework eliminates model risk.
A framework is a set of measures intended to reduce and manage risk, not eliminate it. Even well-controlled models carry residual risk, and controls address inherent risk without reducing it to zero.
A single regulation or standard defines what an enterprise-wide model risk framework must contain everywhere.
Expectations are sector- and jurisdiction-specific. Instruments such as SR 11-7 / OCC 2011-12 originate as U.S. banking supervisory guidance and are not universally applicable, and they differ in nature and scope from voluntary standards or other regulatory instruments. Framework design in one sector should not be assumed to satisfy requirements in another.

Best practices

Maintain a complete and current model inventory as a prerequisite control, and define clearly which AI/ML systems fall within the framework's scope so coverage gaps are visible and deliberate.
Apply risk-based tiering so that validation depth, documentation, and monitoring intensity are proportionate to a model's inherent risk and materiality, and distinguish inherent from residual risk in your assessments.
Preserve independence between the three lines of defense, ensuring validation and audit functions are not performing or approving their own first-line development work.
Treat validation and verification as separate activities, and pair them with ongoing monitoring that specifically tracks performance degradation over time rather than relying on point-in-time approval.
Document policies, model development, validation outcomes, and change decisions to support independent challenge and auditability, while recognizing documentation evidences controls rather than reducing underlying risk on its own.
Scope the framework to the applicable jurisdiction and sector, and use qualified internal language when regulatory treatment is evolving or contested rather than presenting proposed expectations as settled requirements.