Skip to main content
Category: Roles & Accountability

Model Risk Manager

Also known as: Manager, Model Risk Management, MRM Manager
Simply put

A Model Risk Manager is a professional responsible for helping an organization identify, assess, and control the risks that can arise when it relies on models to make decisions or predictions. Their work typically includes checking that models are appropriate for their intended use and that models are being monitored over time. The role is most commonly associated with financial institutions, though similar functions can appear in other sectors.

Formal definition

A Model Risk Manager is a practitioner who operates within an institution's model risk management (MRM) function, applying a structured, iterative approach to identifying, assessing, mitigating, and monitoring risks associated with the use of models across the model lifecycle. Responsibilities commonly cited include validating models, verifying that ongoing monitoring of a model's fitness for purpose is adequate, and maintaining or controlling the broader MRM control framework. The role should be understood as distinct from, though related to, AI governance: MRM focuses on the identification, measurement, monitoring, and control of model-specific risk, whereas AI governance addresses organizational structures, policies, and accountability for AI systems. The specific scope, seniority, and reporting lines of the role vary by institution and are frequently defined in the context of financial-services model risk oversight rather than as a single universal standard.

Why it matters

Organizations increasingly rely on models to make or inform decisions, and when a model is used to measure or predict outcomes, errors or inappropriate use can propagate into consequential business, financial, and customer-facing decisions. A Model Risk Manager exists to reduce and manage that exposure by identifying, assessing, and controlling model risk across the model lifecycle. As commonly defined, the role does not eliminate risk; it establishes and maintains controls intended to keep residual risk within acceptable bounds and to ensure that models remain fit for their intended purpose over time.

The function matters most acutely in financial institutions, where model risk oversight has historically been treated as a distinct discipline and where the role is frequently framed around enterprise-level oversight of the full model lifecycle. In these settings, the Model Risk Manager typically supports validation of models and verification that ongoing monitoring of model fitness for purpose is adequate—two related but separate activities that experts are careful not to blur. Weak or absent oversight of these activities can leave an institution relying on models whose performance has degraded or whose use has drifted beyond its original scope.

It is worth noting the boundary of this role. Model risk management focuses on the identification, measurement, monitoring, and control of model-specific risk, whereas AI governance addresses organizational structures, policies, and accountability for AI systems. The two overlap but are not interchangeable, and a Model Risk Manager's mandate is generally scoped to the former, with the precise seniority, scope, and reporting lines varying by institution rather than following a single universal standard.

Who it's relevant to

Financial institutions and their risk functions
The role is most commonly associated with financial institutions, where a Model Risk Manager may be tasked with enterprise-level oversight of model risk across the full model lifecycle. Institutions relying on models to measure or predict outcomes use this function to establish and maintain a control framework around model use.
Model validators and monitoring teams
Practitioners who validate models and who verify that monitoring of model fitness for purpose is adequate work within or alongside the MRM function. The distinction between validation (assessing whether a model is appropriate for its intended use) and ongoing monitoring is central to how these responsibilities are commonly divided.
Governance and compliance professionals
Those responsible for organizational accountability and policy for AI systems interact with the MRM function but should recognize the boundary: AI governance concerns structures, policies, and accountability, while the Model Risk Manager's mandate is typically scoped to identifying, measuring, monitoring, and controlling model-specific risk. The two overlap without being interchangeable.
Organizations outside financial services
While the role is most firmly established in financial services, similar functions can appear in other sectors that rely on models for decisions or predictions. The scope and formality of the role in these settings vary and are less standardized than in the financial-services context where model risk oversight has been more formally developed.

Inside Model Risk Manager

Risk Identification and Measurement
A core function of the model risk manager is identifying sources of model risk and measuring their potential impact. In many frameworks, this includes assessing risk arising both from fundamental model errors and from incorrect or inappropriate use of a model.
Model Validation Oversight
The role typically involves overseeing or coordinating validation activities that evaluate whether a model performs as intended for its stated purpose. Validation (assessing whether the right model was built) is commonly distinguished from verification (confirming the model was built correctly), and the model risk manager should keep these activities distinct.
Monitoring and Ongoing Performance Review
Model risk managers typically track models over time to detect issues such as performance degradation. Model risk (the broader risk of adverse consequences from model use) should not be collapsed into model performance degradation (a decline in accuracy or fit), though the latter can be a driver of the former.
Controls and Risk Mitigation
The function includes establishing or verifying controls that reduce and manage model risk. Such controls are measures that lower risk rather than eliminate it; a distinction between inherent risk (before controls) and residual risk (after controls) is commonly maintained.
Lines of Defense Positioning
Model risk management is frequently situated within a lines-of-defense structure. The model risk manager often operates in a second-line (independent oversight and challenge) capacity, distinct from first-line model developers and owners and from third-line internal audit, though placement can vary by organization.
Reference to Supervisory Guidance
In banking contexts, the role is often informed by supervisory guidance historically associated with the U.S. Federal Reserve and OCC (commonly referenced as SR 11-7 / OCC 2011-12). This guidance applies within its jurisdiction and sector and is not universally applicable to all AI or enterprise model use.
Relationship to AI Governance
Model risk management overlaps with, but is distinct from, AI governance. AI governance concerns organizational structures, policies, accountability, and oversight for AI systems, while model risk management focuses on identifying, measuring, monitoring, and controlling risks from model use. The model risk manager may interface with governance functions without absorbing them.

Common questions

Answers to the questions practitioners most commonly ask about Model Risk Manager.

Is a Model Risk Manager responsible for building and improving model performance?
No. This is a frequent point of confusion. A Model Risk Manager focuses on identifying, measuring, monitoring, and controlling the risks arising from model use, not on developing models or optimizing their predictive performance. Model development and performance tuning typically sit with model owners or developers, who are often part of the first line of defense. The Model Risk Manager, more commonly associated with the second line of defense in many frameworks, provides independent oversight and challenge. Note that model risk and model performance degradation are distinct concepts: a model can perform well statistically yet still create risk through misuse, inappropriate application, or flawed assumptions.
Does having a Model Risk Manager mean the same thing as having AI governance in place?
Not necessarily. AI governance and model risk management are related but distinct, and a Model Risk Manager role generally sits closer to the latter. Model risk management, historically framed by guidance such as SR 11-7 / OCC 2011-12 in the U.S. banking context, concerns the risks of individual models and their use. AI governance refers more broadly to the organizational structures, policies, accountability, and oversight for AI systems. The two overlap—model risk management activities can feed into a governance framework—but appointing a Model Risk Manager does not by itself establish comprehensive AI governance, and the reverse is also true.
Where does a Model Risk Manager typically sit within the three lines of defense?
In many frameworks, a Model Risk Manager is associated with the second line of defense, providing independent oversight, effective challenge, and validation-related functions separate from the model owners and developers who make up the first line. The third line is typically internal audit, which assesses whether the overall framework is functioning. Organizational structures vary, however, and some institutions distribute model risk responsibilities differently, so the exact placement depends on the entity's operating model and applicable expectations.
How does a Model Risk Manager typically approach validation versus verification?
These are distinct activities that experts refuse to blur. Verification generally asks whether a model was built correctly—whether it implements its intended design and specifications accurately. Validation generally asks whether the model is appropriate for its intended purpose and performs as expected, often through independent testing, benchmarking, and effective challenge. A Model Risk Manager is commonly involved in ensuring validation is performed with appropriate independence, though the specific scope of each activity can vary by organization and by the guidance being applied.
How does a Model Risk Manager distinguish inherent risk from residual risk when prioritizing work?
Inherent risk typically refers to the level of risk a model presents before controls are applied, while residual risk refers to the risk that remains after controls and mitigations are in place. A Model Risk Manager commonly uses this distinction to prioritize oversight—higher inherent risk models often warrant more intensive validation and monitoring—and to assess whether existing controls adequately reduce risk. It is important to note that controls reduce or manage risk rather than eliminate it, so residual risk is generally acknowledged rather than assumed to be zero.
What role does a Model Risk Manager play in ongoing monitoring rather than one-time review?
Model risk management is generally treated as a continuous activity rather than a single point-in-time exercise. A Model Risk Manager is often involved in establishing and overseeing ongoing monitoring so that model risk is reassessed as conditions change—for example, when data, usage, or the operating environment shifts. This helps detect issues such as performance degradation over time, though monitoring for degradation should not be conflated with the broader assessment of model risk, which also considers use, assumptions, and limitations. The specific cadence and thresholds typically depend on the risk profile of the model and the organization's policies.

Common misconceptions

The model risk manager's job is to eliminate model risk.
Controls and oversight are intended to reduce and manage model risk, not eliminate it. A residual level of risk typically remains after mitigation.
Model risk management and AI governance are the same function.
They overlap but are distinct. AI governance addresses organizational policies, accountability, and oversight structures, whereas model risk management focuses on the identification, measurement, monitoring, and control of risks from model use. Treating them as interchangeable can obscure important responsibilities.
A model that still performs well presents no model risk.
Model performance and model risk are separate concepts. Model risk can arise from inappropriate use, misapplication, or flawed assumptions even when performance metrics appear acceptable, so strong performance does not by itself indicate low model risk.

Best practices

Maintain a clear distinction between validation (assessing whether the appropriate model was built for its purpose) and verification (confirming the model was implemented correctly), and document each activity separately.
Establish ongoing monitoring to detect performance degradation over time, while treating such degradation as one potential driver of model risk rather than as equivalent to model risk itself.
Preserve independence consistent with a second-line oversight role, keeping model risk management functions distinct from first-line model development and third-line internal audit.
Document both inherent and residual risk for each model so that the effect of controls is transparent and the remaining risk is explicitly acknowledged.
Scope any supervisory guidance you rely on to its correct jurisdiction and sector, and avoid assuming that banking-oriented guidance applies uniformly to all AI or enterprise models.
Coordinate with AI governance functions on shared concerns such as accountability and oversight, without merging the two disciplines or duplicating their respective responsibilities.