Model Risk Rating
A model risk rating is a label or score that an organization assigns to a model to indicate how much risk it could pose if it performs poorly or is used incorrectly. It helps the organization decide how much scrutiny, testing, and oversight a given model needs, with higher-risk models typically receiving more attention. The term is sometimes also called model tiering.
A model risk rating is a categorization or score assigned to an individual model to express its relative level of model risk, commonly used to prioritize and calibrate the intensity of validation, monitoring, and governance activities. In many frameworks the rating is derived from a set of risk attributes assessed through a qualitative or scorecard-based approach, and the practice is frequently termed model tiering. Rating criteria and scales are typically institution-specific rather than fixed by a single authoritative definition, and this entry describes model risk rating as a risk-prioritization mechanism rather than a measure of model performance itself; the two are distinct, since a rating reflects potential adverse consequences of incorrect or misused models rather than observed accuracy.
Why it matters
Model risk rating matters because organizations rarely have the resources to subject every model to the same depth of validation, monitoring, and oversight. By assigning each model a rating or tier that reflects the potential adverse consequences of incorrect or misused models, an institution can prioritize where to concentrate scrutiny, directing more intensive testing and governance toward models whose failure would cause the greatest harm. This risk-based prioritization is a core mechanism for allocating limited model risk management effort in a defensible, consistent way.
A rating also supports accountability and internal consistency. Because rating criteria and scales are typically institution-specific rather than fixed by a single authoritative definition, a documented rating approach gives an organization a repeatable basis for explaining why a given model received the level of oversight it did. It is important to note that a model risk rating reflects the potential adverse consequences of a model performing poorly or being used incorrectly, not the model's observed accuracy or performance. Treating a rating as a measure of how well a model performs is a common error; the two are distinct, and conflating them can lead an organization to under-scrutinize a poorly rated but high-consequence model.
The practical value of a rating depends on how well the underlying criteria capture the ways a model could cause harm. Ratings are a means of reducing and managing model risk by focusing oversight, not a control that eliminates it; a model rated high risk still requires the actual validation, monitoring, and governance activities that the rating is meant to prioritize.
Who it's relevant to
Inside Model Risk Rating
Common questions
Answers to the questions practitioners most commonly ask about Model Risk Rating.