Outsourced Models
Outsourced models are models that an organization obtains from an external party rather than building in-house, such as tools purchased from a vendor or supplied by a service provider. The organization still uses these models to make or support decisions, so it remains responsible for understanding how they work and managing the risks they create, even though it did not develop them. Because much of the internal knowledge about the model sits with the third party, obtaining sufficient information for oversight is often a central challenge.
In model risk management, 'outsourced models' typically refers to models developed, supplied, or operated by third parties—including vendor products, service-provider models, and externally built components—that an institution deploys within its own decision processes. As commonly framed, the use of an external provider does not transfer accountability for model risk: the adopting organization generally remains responsible for validating fitness for its intended use, monitoring ongoing performance, and applying controls, subject to the practical constraint that vendors may limit access to proprietary methodology, data, or code. The scope and treatment of outsourced models are context-dependent and can differ materially between regulated banking environments and general enterprise AI settings; this entry does not assert a single authoritative definition, and the specific meanings of 'outsourcing model' in unrelated commercial domains (for example, IT, trading, or marketing outsourcing arrangements) are out of scope.
Why it matters
Outsourced models create a distinctive risk-management challenge because accountability and knowledge become separated. As commonly framed in model risk management, an institution that adopts a vendor or service-provider model remains responsible for managing the risks that model introduces into its decisions, yet much of the detailed understanding of methodology, data, and code sits with the external provider. This asymmetry means an organization can be held accountable for outcomes it cannot fully inspect, making the sufficiency of information obtained for oversight a recurring central concern.
The stakes are heightened where outsourced models feed decisions with regulatory, financial, or consumer consequences. Because vendors may treat their approaches as proprietary, institutions can struggle to validate fitness for their specific intended use and to monitor ongoing performance—two activities that are not discharged simply by relying on the vendor's own testing. Treating a purchased model as a black box that requires no independent scrutiny is a common error; the fact that a model was not built in-house does not, in most frameworks, transfer the underlying responsibility for its risks.
The appropriate treatment of outsourced models is context-dependent and can differ materially between regulated banking environments and general enterprise AI settings. Because there is no single authoritative definition across all contexts, professionals should be cautious about assuming that expectations from one domain apply unchanged to another.
Who it's relevant to
Inside Outsourced Models
Common questions
Answers to the questions practitioners most commonly ask about Outsourced Models.