Skip to main content
Category: Roles & Accountability

Model Governance

Also known as: AI model governance, ML model governance
Simply put

Model governance is the set of policies, roles, and controls an organization uses to oversee how its models are built, checked, put into use, monitored, and eventually retired. It is meant to make sure models are used responsibly and consistently across their lifecycle, rather than to guarantee that models are error-free or risk-free.

Formal definition

Model governance, as commonly defined across the evidence, refers to the end-to-end framework of policies, procedures, roles, and controls through which an organization establishes, implements, and maintains oversight of models throughout their lifecycle, including development, validation, deployment, monitoring, and retirement. In practice it also encompasses controls over access, policy enforcement, and activity tracking for models and their associated artifacts. It is frequently discussed alongside model risk management (MRM), and in some sources model governance is characterized as the set of activities, policies, and procedures that formalize model and model risk management activities for implementation; however, model governance and model risk management are distinct concepts and should not be treated as interchangeable. Model governance denotes the organizational structures and accountability mechanisms for oversight, whereas MRM refers to the identification, measurement, monitoring, and control of risks arising from model use. The precise scope, required components, and terminology vary by sector, organization, and applicable regulatory context, and the evidence provided does not establish a single authoritative definition or any binding legal requirement.

Why it matters

As organizations increasingly rely on models to inform or automate decisions, the absence of clear oversight structures can allow inconsistent practices, undocumented changes, and unmonitored deployments to accumulate across the model lifecycle. Model governance addresses this by defining who is accountable, what policies apply, and how activity is tracked, so that models are built, validated, deployed, monitored, and eventually retired in a consistent and documented way. It is a mechanism for reducing and managing risk rather than eliminating it; establishing governance does not by itself guarantee that a model is error-free or that its performance will remain stable over time.

Who it's relevant to

Model risk managers
For those responsible for identifying, measuring, monitoring, and controlling model risk, governance provides the surrounding policies, roles, and controls that formalize how those risk activities are implemented and overseen. Practitioners should be careful to distinguish governance structures from the risk management activities they support, as the two are related but not interchangeable.
Compliance officers and auditors
Governance frameworks define documented policies, accountability, and activity tracking that support review of whether models are handled consistently across their lifecycle. Because the required components vary by sector and applicable regulatory context, and the evidence here establishes no single binding definition, these professionals typically need to map governance controls to the specific obligations relevant to their organization.
Data scientists and ML engineers
Governance shapes how models are built, validated, deployed, monitored, and retired, and in machine learning operations contexts it often relies on reproducible and automated data and ML pipelines. It also introduces controls over access and policy enforcement that affect day-to-day development and deployment work.
Policy and oversight leadership
For those setting organizational structures and accountability mechanisms, model governance is the vehicle through which oversight responsibilities are assigned and maintained. Its scope and terminology vary by organization, so leadership should define governance in terms suited to their sector and applicable context rather than assuming a universal standard.

Inside Model Governance

Governance Structure and Accountability
The organizational arrangements that assign roles, responsibilities, and decision rights for AI and model oversight, often including a board or senior management mandate, committees, and designated owners. This element addresses who is accountable for models rather than the technical measurement of model risk itself.
Policies, Standards, and Procedures
Documented expectations governing how models are developed, approved, deployed, monitored, and retired. In many frameworks these codify controls and expected practices, though their specific content varies by jurisdiction and sector.
Lines of Defense
A commonly used control model that separates responsibilities across first line (model owners and developers who own the risk), second line (independent oversight such as model risk management or compliance), and third line (internal audit providing independent assurance). These lines are distinct roles and should not be collapsed into one another.
Model Inventory and Lifecycle Tracking
A maintained record of models in use, typically capturing ownership, purpose, risk tier, and lifecycle status. This supports oversight but is a governance artifact and is separate from the substantive validation of any individual model.
Validation and Review Regimes
Governance-mandated processes requiring independent assessment of models. Validation (assessing whether a model is fit for its intended purpose) is conceptually distinct from verification (confirming a model was built to specification), and governance defines when and how each is performed.
Monitoring and Ongoing Oversight
Requirements for tracking model behavior over time, including performance and risk indicators. Governance establishes the obligation to monitor; the detection of model performance degradation is an operational outcome distinct from the broader concept of model risk.
Documentation and Reporting
Expectations for recording model design, assumptions, limitations, and oversight decisions, and for escalating and reporting issues to appropriate stakeholders. This supports transparency and accountability rather than directly reducing a model's inherent risk.

Common questions

Answers to the questions practitioners most commonly ask about Model Governance.

Is model governance the same thing as model risk management?
No, though they overlap and are frequently conflated. Model governance typically refers to the organizational structures, policies, roles, and accountability mechanisms that oversee how models are developed, approved, used, and retired. Model risk management, historically framed by supervisory guidance such as SR 11-7 (issued jointly by the U.S. Federal Reserve and, as OCC 2011-12, the OCC), refers more specifically to the identification, measurement, monitoring, and control of risks arising from model use. Governance often provides the framework within which model risk management activities operate, but the two are not interchangeable and experts generally resist collapsing the distinction.
Does having strong model governance eliminate model risk?
No. Governance controls are best understood as measures that reduce or manage risk rather than remove it. Even well-designed oversight structures, approval workflows, and monitoring processes cannot eliminate the possibility of model errors, misuse, or performance issues. Governance aims to make risks visible, assign accountability, and support timely response, but residual risk typically remains after controls are applied.
How does model governance relate to the three lines of defense?
In many organizations, model governance is operationalized across the three lines of defense, which are commonly distinguished as separate functions. The first line typically owns and develops models and manages associated risk directly. The second line commonly provides independent oversight, challenge, and validation activities. The third line, often internal audit, typically provides independent assurance over the overall framework. Governance defines how responsibilities and reporting flow across these lines, though the precise allocation varies by organization and sector.
What role does model inventory play in model governance?
A model inventory is commonly treated as a foundational element of model governance because it provides a documented record of models in use, their purpose, ownership, risk classification, and lifecycle status. Without a reliable inventory, organizations may struggle to apply oversight consistently or to know which models require validation, monitoring, or approval. The scope of what counts as a model for inventory purposes can be contested and may differ between banking contexts and broader enterprise AI settings.
How is validation positioned within a model governance framework?
Validation is typically a distinct governance activity from verification and from ongoing performance monitoring, and experts generally keep these separate. Within many frameworks, validation involves independent assessment of whether a model is conceptually sound and fit for its intended purpose, often performed by a function separate from the model developers. Governance defines who performs validation, its independence requirements, its frequency, and how findings are tracked to resolution, though specific expectations vary by framework and jurisdiction.
How should governance handle model changes and retirement?
Governance frameworks commonly include change management and decommissioning processes so that modifications are reviewed and approved before deployment and so that models no longer in use are formally retired. This typically involves documenting the nature of a change, reassessing risk, and determining whether re-validation is warranted. The rigor applied often scales with the model's risk classification, and practices in this area continue to evolve, particularly for AI systems outside traditional banking model risk contexts.

Common misconceptions

Model governance and model risk management are the same thing.
As commonly distinguished, model governance refers to the organizational structures, policies, and accountability that oversee models, while model risk management is the identification, measurement, monitoring, and control of risks arising from model use. They overlap—governance frames how model risk is managed—but professionals generally do not treat them as interchangeable.
Having a governance framework in place eliminates model risk.
Governance controls are measures intended to reduce or manage risk, not to remove it. Even with strong oversight, residual risk typically remains after controls are applied, and it is distinct from the inherent risk present before controls.
A single set of governance requirements applies universally across all AI and model use.
Governance expectations vary by jurisdiction, sector, and the nature of the instrument involved (binding law, supervisory guidance, or voluntary standard). What applies to banking model risk may differ from expectations for general enterprise AI, so requirements should be scoped to context rather than assumed to be uniform.

Best practices

Maintain a clear separation between the first, second, and third lines of defense so that those who own and build models are not the same parties providing independent oversight or assurance.
Keep a current model inventory that captures ownership, intended purpose, risk tier, and lifecycle status to support consistent oversight across the model population.
Distinguish validation from verification in your review processes, and document the intended use and limitations of each model so assessments address whether the model is fit for purpose.
Establish ongoing monitoring obligations that can surface performance degradation, and route findings through defined escalation and reporting paths to accountable owners.
Scope policies and standards to the applicable jurisdiction and sector, using qualified language where regulatory treatment is evolving or where an instrument is guidance or a voluntary standard rather than binding law.
Document design assumptions, controls applied, and any residual risk that remains after those controls, and communicate this to senior management or the relevant oversight body.