Enterprise-Wide Model Risk Framework
An enterprise-wide model risk framework is the organization-level structure of policies, roles, and processes an institution uses to identify, manage, and oversee the risks that arise from using models across its entire business, rather than in isolated pockets. It aims to ensure that model risk is understood and controlled consistently throughout the organization, typically using a risk-based approach that focuses more attention on higher-risk models. Such frameworks are most developed in financial institutions, where regulators have set expectations for how they should work.
As commonly defined in supervisory guidance, an enterprise-wide model risk framework is the institution-level governance and control architecture through which model risk is identified, measured, monitored, and managed consistently across all business lines and model uses, typically applying a risk-based (proportional) approach that calibrates controls to a model's assessed risk. In the financial-sector context, guidance such as OSFI's Guideline E-23 sets out principles-based expectations for effective enterprise-wide model risk management (MRM), and framework materials commonly emphasize that model risk should be well understood and managed across the enterprise, governed appropriately, and embedded within broader enterprise risk management (ERM) processes. Note that this term denotes the overarching framework for managing model risk (identification, measurement, monitoring, and control of risks arising from model use) and should be distinguished from AI governance more broadly and from general ERM, which addresses the full range of enterprise risks; the specific expectations, effective dates, and applicability of any given instrument are jurisdiction- and sector-specific and should be confirmed against the issuing authority's text.
Why it matters
As institutions deploy models across lending, capital adequacy, fraud detection, pricing, and increasingly AI-driven functions, managing model risk in isolated pockets leaves the organization exposed to inconsistent controls, undetected concentrations of risk, and gaps that no single business line owns. An enterprise-wide model risk framework matters because it seeks to ensure that model risk is understood and managed consistently across all business lines rather than depending on the varying practices of individual teams. Supervisory materials in the financial sector, such as OSFI's Guideline E-23, articulate expectations that model risk be well understood and managed across the enterprise, governed appropriately, and managed using a risk-based approach.
The practical significance is that an enterprise-wide view allows an institution to calibrate the intensity of its controls to the assessed risk of each model, directing more oversight to higher-risk uses. Commentary on OSFI's E-23 frames such a framework as a tool for fostering a culture of risk-aware innovation by embedding model risk management within broader enterprise risk management processes. This embedding is important because it treats model risk not as a standalone technical concern but as one component of the full range of enterprise risks the organization tracks and reports on.
It should be emphasized that a framework of this kind is a means of managing and reducing model risk, not eliminating it, and that its specific expectations, applicability, and effective dates are jurisdiction- and sector-specific. The most developed expectations sit in financial services; institutions in other sectors may adapt similar structures voluntarily, but they should not assume that financial-sector supervisory guidance applies to them or is interchangeable with AI governance instruments or general enterprise risk management.
Who it's relevant to
Inside Enterprise-Wide Model Risk Framework
Common questions
Answers to the questions practitioners most commonly ask about Enterprise-Wide Model Risk Framework.