Skip to main content
Category: Management System Governance

Model Risk Management Framework

Also known as: MRM Framework, MRM framework, model risk management policy and framework, AI model risk management framework
Simply put

A model risk management framework is a structured, organization-wide approach for finding, measuring, and controlling the risks that arise when models are used to make decisions or predictions. It typically covers how models are built, tested, put into use, and monitored over time, and often includes policies designed to help meet regulatory expectations. It is a set of measures intended to reduce and manage model risk rather than eliminate it entirely.

Formal definition

As commonly defined, a model risk management (MRM) framework is a documented, structured approach for identifying, assessing, measuring, controlling, mitigating, and monitoring risks associated with the development, implementation, and use of models, including machine learning models. In many frameworks it encompasses robust model development and use alongside a distinct and independent model validation process, supported by governing policies and defined accountability. The scope and stringency of such frameworks vary by context: in financial institutions they are frequently structured to align with supervisory expectations, while in broader enterprise AI settings the framework may be adapted to different risk profiles. This entry addresses the framework as an organizing structure for managing model risk; it does not detail any specific regulatory instrument's binding requirements, which vary by jurisdiction and issuer and should be assessed separately. Practitioners should note that an MRM framework governs model risk broadly and should not be conflated with model performance monitoring alone, nor with validation, which is one component within it.

Why it matters

Models increasingly drive consequential decisions—credit approvals, capital calculations, fraud detection, pricing, and, more recently, decisions informed by machine learning systems. When a model is flawed, misused, or applied outside the conditions it was built for, the resulting errors can propagate quickly and at scale. A model risk management framework matters because it provides the organizing structure through which an institution can systematically identify where model risk arises, measure its potential impact, and put controls around it. Without such a framework, model risk tends to be managed informally and inconsistently, leaving gaps that surface only after a decision has already caused harm.

A framework is also the mechanism through which accountability and independent challenge are established. As reflected in supervisory guidance for financial institutions, sound model risk management typically begins with robust model development and use, and is paired with a distinct, independent model validation process. Separating those functions helps ensure that the people building a model are not the only ones judging whether it is fit for purpose. For institutions subject to regulatory expectations, a documented framework is frequently the vehicle for demonstrating that those expectations are being addressed, though the specific binding requirements vary by jurisdiction and issuer and must be assessed separately.

Who it's relevant to

Model risk managers and second-line functions
Those responsible for independent oversight of models rely on the framework to define validation activities, accountability, and the boundary between model development and independent challenge. The framework gives them the structure through which model risk is measured and controlled across the lifecycle, distinct from the first-line teams that build and use the models.
Compliance officers and regulatory specialists in financial institutions
For institutions operating under supervisory expectations, a documented MRM policy and framework is often central to demonstrating that model risk is being managed. Because specific binding requirements vary by jurisdiction and issuer, these professionals use the framework to organize practices while assessing applicable regulatory instruments separately.
Data scientists and model developers
Practitioners building models—including machine learning models—work within the framework's expectations for robust development, implementation, and use. Understanding where their work sits within the broader structure helps them prepare models for independent validation rather than treating their own testing as the final word.
Auditors and third-line functions
Internal audit and other independent assurance functions assess whether the framework is designed and operating effectively. They evaluate whether identification, measurement, control, and monitoring activities are actually being carried out as documented, and whether validation genuinely functions independently of development.
Enterprise AI governance teams outside banking
Organizations applying MRM concepts to broader AI and ML use adapt the framework to different risk profiles than those found in regulated financial institutions. For these teams, the framework offers a structured approach to managing model risk, but its scope and stringency should be calibrated to their specific context rather than assumed to mirror financial-sector expectations.

Inside MRM Framework

Governance and Oversight Structure
The organizational arrangements—typically including board and senior management accountability, defined roles, and policies—that establish ownership and oversight of model risk. This element reflects the AI governance dimension that often overlaps with, but remains distinct from, the technical risk activities of a model risk management framework.
Model Inventory
A comprehensive, maintained record of models in use, commonly capturing model purpose, ownership, risk rating, and lifecycle status. As typically defined, the inventory supports scoping and prioritization of validation and monitoring effort.
Model Development and Implementation Standards
Documented expectations for how models are built, tested, and put into production, including data quality, conceptual soundness, and documentation. These standards support later validation by making development assumptions transparent.
Model Validation
An independent set of activities to assess whether a model is sound and performs as intended for its purpose. Validation should be distinguished from verification: validation asks whether the right model was built for the intended use, while verification asks whether the model was built correctly to specification.
Ongoing Monitoring
Processes to track model behavior over time, including performance and stability. This addresses model performance degradation—a decline in how well a model performs—which is related to but distinct from model risk, the broader potential for adverse consequences from model use or misuse.
Risk Rating and Materiality Assessment
Methods for classifying models by risk so that controls are proportionate. Frameworks commonly distinguish inherent risk (risk before controls) from residual risk (risk remaining after controls are applied), and this element informs the intensity of validation and monitoring.
Lines of Defense
An allocation of responsibilities commonly structured as first line (model owners and developers), second line (independent risk management and validation oversight), and third line (internal audit providing independent assurance). These lines are distinct and should not be collapsed into one another.
Documentation and Reporting
Records and communication that make model risk transparent to decision-makers, supporting accountability, review, and, where applicable, regulatory or audit scrutiny.

Common questions

Answers to the questions practitioners most commonly ask about MRM Framework.

Is a model risk management framework the same thing as an AI governance framework?
No, though they overlap. A model risk management framework focuses on identifying, measuring, monitoring, and controlling the risks arising from model use, an approach historically framed by supervisory guidance such as the U.S. Federal Reserve and OCC SR 11-7. AI governance is broader, addressing the organizational structures, policies, accountability, and oversight for AI systems as a whole. Many organizations extend model risk management practices to cover AI, but the two are not interchangeable: a governance framework can encompass functions beyond model risk, and model risk management typically sits within, rather than replacing, an organization's governance arrangements. The exact relationship varies by sector and by the framework an organization adopts.
Does having a model risk management framework in place eliminate model risk?
No. A framework is a set of measures intended to reduce and manage model risk, not to remove it. Even well-designed controls leave residual risk after mitigation, distinct from the inherent risk present before controls are applied. Frameworks help an organization understand, monitor, and respond to model risk over time, but models can still fail, degrade, or be misused. Treating a framework as a guarantee against loss or error is a common misconception; it is better understood as a structure for keeping risk within an organization's stated tolerance.
Who is typically responsible for the different activities in a model risk management framework?
Responsibilities are commonly distributed across what many frameworks describe as three lines of defense, though the exact allocation depends on the organization and its regulatory context. In this common structure, the first line (such as model developers and business owners) owns and manages the risk, the second line (such as an independent model risk or validation function) provides challenge and oversight, and the third line (such as internal audit) provides independent assurance over the framework itself. Keeping these lines distinct—particularly separating those who build models from those who independently validate them—is a frequent point of emphasis. The specific roles and titles vary by institution.
How does validation fit into a model risk management framework, and how is it different from verification?
Validation is typically a core component of a model risk management framework, aimed at assessing whether a model is suitable for its intended use and performing as expected, often through independent review. It is commonly distinguished from verification, which addresses whether a model was implemented correctly and behaves as specified. Professionals frequently blur these terms, but they answer different questions: verification asks 'did we build the model right,' while validation asks 'did we build the right model for the intended purpose.' Both may be documented and repeated over a model's lifecycle, and the precise scope of each can differ by organization and by the guidance being followed.
How should a framework address ongoing monitoring after a model is deployed?
Ongoing monitoring is generally treated as a continuing activity rather than a one-time step, because a model's behavior and environment can change over time. Frameworks commonly distinguish model risk from model performance degradation: monitoring may track whether performance has declined against expectations, but it also considers whether changing conditions, data, or usage introduce risks beyond raw performance metrics. The frequency, thresholds, and triggers for revalidation or remediation are typically calibrated to the model's risk level and intended use, and the specifics vary by organization and sector. This entry does not prescribe particular monitoring metrics or intervals.
How does a framework typically prioritize effort across a large model inventory?
Many frameworks apply a risk-based or tiered approach, directing more intensive controls, validation, and oversight toward higher-risk models and lighter treatment toward lower-risk ones. Prioritization commonly begins with a maintained inventory of models and an assessment of each model's inherent risk before controls, which then informs the depth of review and the residual risk that remains afterward. What counts as higher risk, and how tiers are defined, depends on the organization's risk appetite, sector, and applicable guidance. This entry does not specify a particular tiering scheme, as these differ across institutions and are not standardized across all contexts.

Common misconceptions

A model risk management framework and an AI governance framework are the same thing.
They overlap but are distinct. Model risk management focuses on identifying, measuring, monitoring, and controlling risks arising from model use, historically framed by supervisory guidance such as SR 11-7 / OCC 2011-12 in the U.S. banking context. AI governance concerns the broader organizational structures, policies, accountability, and oversight for AI systems. A framework may address both dimensions without them being interchangeable.
Validation and verification are interchangeable terms.
As commonly defined, they answer different questions. Validation assesses whether a model is appropriate and sound for its intended purpose, while verification checks whether the model was implemented correctly against its specification. Conflating them can leave gaps in either conceptual soundness or implementation correctness.
Implementing a model risk management framework eliminates model risk.
Governance and control measures reduce or manage risk; they do not eliminate it. Even with strong controls, residual risk typically remains, and ongoing monitoring is needed because models can experience performance degradation over time.

Best practices

Maintain a current and comprehensive model inventory with risk ratings so that validation and monitoring effort can be prioritized proportionately to model materiality.
Apply risk-based intensity by distinguishing inherent risk from residual risk, and calibrate the depth of validation and monitoring to the model's assessed risk.
Preserve independence across the lines of defense, keeping model development, independent validation and oversight, and audit assurance as separate functions rather than collapsing them.
Treat validation and verification as separate activities, confirming both that the model is fit for its intended purpose and that it was implemented correctly against specification.
Establish ongoing monitoring to detect model performance degradation over time, recognizing that a model sound at deployment may drift as conditions change.
Document development assumptions, validation findings, and monitoring results so that model risk remains transparent and reportable to accountable decision-makers.