Skip to main content
Category: Risk Assessment & Analysis

Model Risk

Simply put

Model risk is the possibility of harm or loss that arises when an organization relies on a model that produces incorrect, inaccurate, or misleading results, or when a model is used inappropriately. Because models are used to measure, value, or predict quantitative information, poor model performance or misuse can lead to adverse decisions and outcomes. The term originated largely in financial contexts such as valuation and risk measurement, though it is now applied more broadly.

Formal definition

As commonly defined, model risk is the potential for adverse outcomes stemming from decisions based on models that are insufficiently accurate, that perform inadequately, or that are misused. It has historically been framed in the context of financial risk measurement and valuation models, where it is described as the risk of error due to inadequacies in those models. Note that model risk should be distinguished from model performance degradation: performance degradation is one possible source of model risk, but model risk also encompasses risks arising from model misuse, incorrect application, and flawed design, and it concerns the downstream consequences (such as loss) rather than the model's technical metrics alone. Precise definitions and scope vary across sources and sectors, and the framing here is drawn from general and financial-context descriptions rather than a single authoritative standard.

Why it matters

Model risk matters because organizations increasingly make consequential decisions—valuations, risk measurements, predictions, and quantitative assessments—on the basis of model outputs. When a model produces incorrect, inaccurate, or misleading results, or when it is applied outside the conditions for which it was designed, the resulting decisions can lead to adverse outcomes and loss. The concept is important precisely because the harm is downstream: it is not the model's internal metrics that create the risk, but the reliance placed on the model's outputs in real decisions.

The term originated largely in financial contexts, where it has been described as the risk of error due to inadequacies in financial risk measurement and valuation models. In that setting, insufficient attention to model risk has long been treated as a source of potential loss, which is why financial institutions developed dedicated model risk management practices. As models have spread into broader enterprise and AI applications, the concept has been applied more widely, though precise definitions and scope continue to vary across sources and sectors.

Who it's relevant to

Model risk managers and validation teams
Those responsible for identifying, measuring, monitoring, and controlling model risk rely on a precise understanding of its scope—distinguishing risks from inadequate accuracy, flawed design, and misuse from mere performance metrics. Understanding that model risk concerns downstream consequences helps focus oversight on how model outputs feed decisions, not only on technical accuracy.
Financial institution risk and compliance professionals
The concept has deep roots in financial risk measurement and valuation, where inadequacies in models are treated as a source of potential loss. Professionals in this setting encounter model risk as a long-established discipline, though they should note that definitions and regulatory treatment vary and should be scoped to their own jurisdiction.
Data scientists and model developers
Those who build and maintain models contribute to model risk through design choices and through documenting appropriate use conditions. Because misuse and incorrect application are sources of model risk independent of technical performance, developers need to communicate the limits of a model's intended use, not only its accuracy.
Enterprise and AI governance stakeholders
As the concept has been applied beyond finance to broader enterprise and AI contexts, governance stakeholders encounter model risk as part of oversight structures for model use. They should be aware that scope and definitions vary across sectors, and that governance measures reduce and manage model risk rather than eliminate it.

Inside Model Risk

Fundamental model error
Risk arising when a model has inherent design flaws, incorrect assumptions, or is built on unsound theory or methodology, such that its outputs are inaccurate even when used as intended.
Incorrect or inappropriate use
Risk that a model, even if fundamentally sound, is applied to purposes, populations, or conditions for which it was not designed or validated, producing misleading results.
Data quality and input risk
Risk stemming from inaccurate, incomplete, biased, or unrepresentative data used to develop, calibrate, or run the model, which can propagate into unreliable outputs.
Implementation risk
Risk introduced when a conceptually sound model is coded, deployed, or integrated into systems incorrectly, creating a gap between design and operational behavior.
Adverse consequences
The potential for financial loss, poor business or strategic decisions, reputational harm, or regulatory issues resulting from erroneous or misused model outputs; model risk is commonly framed in terms of these downstream impacts.
Scope of 'model'
The definition of what constitutes a model determines the boundaries of model risk. In many frameworks, particularly banking supervisory guidance such as SR 11-7, a model is a quantitative method that applies assumptions to produce estimates; the precise scope can vary by institution and sector.

Common questions

Answers to the questions practitioners most commonly ask about Model Risk.

Is model risk the same as a model performing poorly or degrading over time?
No. Model performance degradation is one possible source of model risk, but it is not the whole concept. Model risk, as commonly defined, refers to the potential for adverse consequences arising from decisions based on incorrect or misused model outputs. A model can perform well on its intended metrics and still generate model risk if it is applied outside its intended use, misinterpreted, or relied upon in decisions it was never designed to support. Conversely, degradation is a performance issue that becomes a model risk concern principally because of the potential adverse consequences it creates.
Does having strong AI governance mean an organization has eliminated its model risk?
No. Governance structures, policies, and oversight are measures that reduce and manage model risk; they do not eliminate it. Even well-controlled models retain residual risk after controls are applied. AI governance (the organizational structures, policies, and accountability for AI systems) and model risk management (the identification, measurement, monitoring, and control of risks from model use) overlap but are distinct. Governance can create the conditions for effective model risk management, but the two should not be treated as interchangeable, and neither reduces risk to zero.
How do organizations typically distinguish inherent model risk from residual model risk in practice?
In many frameworks, inherent risk refers to the risk associated with a model before controls are applied, while residual risk refers to what remains after mitigation and controls. Practically, teams often assess inherent risk based on factors such as model complexity, materiality of the decisions supported, and degree of reliance, then document the controls applied and reassess the remaining exposure as residual risk. The specific factors, rating scales, and thresholds used vary by organization and, in regulated sectors such as banking, may be shaped by applicable supervisory guidance.
Where does responsibility for managing model risk usually sit across the lines of defense?
Under a commonly used three-lines model, the first line (typically model owners, developers, and business users) owns and manages the risk day to day; the second line (often an independent model risk or validation function) provides oversight, challenge, and independent assessment; and the third line (internal audit) provides independent assurance over the overall framework. These roles are frequently separated to preserve independence, but exact allocation of responsibilities differs across organizations, and how strictly the separation is enforced can depend on sector expectations and firm size.
How is model risk typically monitored on an ongoing basis rather than only at deployment?
Ongoing monitoring commonly involves tracking indicators that may signal changing exposure, such as shifts in input data, changes in the environment in which the model operates, and comparison of outcomes against expectations. Many programs define triggers or thresholds that prompt review, revalidation, or escalation. The intent is to detect when a model may no longer be operating within its intended conditions of use. The specific metrics, frequency, and escalation paths vary by model materiality and organizational policy, and monitoring reduces rather than removes the possibility of undetected issues.
What should be documented to support the identification and control of model risk?
Documentation frequently covers the model's intended use and limitations, assumptions, data sources, methodology, the results of validation activities, identified risks, applied controls, and any residual risk that remains. This documentation supports independent review, monitoring, and accountability, and helps ensure the model is used within its intended scope. The depth and formality of documentation typically scale with the materiality of the model and, in regulated contexts, may be influenced by applicable supervisory expectations rather than a single universal standard.

Common misconceptions

Model risk is the same as poor model performance or accuracy degradation.
Model risk is broader than performance. It encompasses fundamental design errors, misuse, data problems, and implementation flaws, as well as the adverse consequences of relying on model outputs. Performance degradation over time is one contributor to model risk, not a synonym for it.
Managing model risk is identical to AI governance.
The two overlap but are distinct. Model risk management typically focuses on identifying, measuring, monitoring, and controlling risks arising from specific model use, while AI governance concerns the broader organizational structures, policies, roles, and oversight for AI systems. Governance can encompass model risk management, but the terms should not be collapsed.
A validated model has no model risk.
Validation reduces and helps manage model risk but does not eliminate it. Residual risk typically remains due to changing conditions, evolving data, potential misuse, and inherent limitations, which is why ongoing monitoring is generally emphasized rather than one-time approval.

Best practices

Define clearly and document what qualifies as a 'model' within your organization, since the scope of the definition determines what falls under model risk management and this can vary by sector and institution.
Assess model risk across multiple dimensions, including fundamental design soundness, data quality, implementation fidelity, and appropriateness of use, rather than treating it solely as an accuracy or performance question.
Distinguish inherent risk from residual risk when documenting a model, and describe controls as measures that reduce or manage risk rather than eliminate it.
Maintain ongoing monitoring of models in production, since model risk can increase as data, business conditions, or use cases change over time after initial validation.
Establish clear accountability for model use and controls, coordinating model risk management activities with broader AI governance structures without conflating the two functions.
Document intended use, assumptions, and limitations for each model so that inappropriate application to unsuitable purposes or populations can be identified and constrained.