Reference · 53 terms
Model risk management glossary
Plain-English definitions covering SR 11-7/SR 26-2 vocabulary, independent validation terminology, and the procurement vocabulary that governs model risk management firm sourcing. Written for model risk, quantitative, and internal audit teams who need the vocabulary before a first call.
Consumer & Decision Models 3
A decision that negatively affects a consumer, such as denying credit or offering less favorable terms. When a model influences the decision, governance teams assess data, performance, explainability, monitoring, and compliance controls around the model's role.
Related: Explainability, Model bias, Model documentation
Also: ECL model, CECL model, IFRS 9 impairment model
A model or linked set of methods used to estimate expected credit losses for accounting or risk purposes. Governance typically covers segmentation, scenarios, forecasts, probability of default, loss given default, exposure, overlays, and outcomes.
Related: Probability of default, Model overlay, Outcomes analysis
Also: PD
An estimate of the likelihood that an obligor or exposure will default over a defined horizon. Validation examines definition, data, segmentation, rank ordering, calibration, conservatism, overrides, and use.
Related: Calibration, Discriminatory power, Expected credit loss model
Core Concepts 8
Critical analysis by objective, informed parties who can identify a model's limitations and assumptions and produce appropriate changes. SR 11-7 introduced effective challenge as the guiding principle of model risk management; it requires the reviewer to have genuine independence, technical competence, and organizational influence to effect change.
Related: Model validation, Three lines of defense, Model risk management
Also: Model interpretability
The extent to which relevant stakeholders can understand a model's behavior, drivers, outputs, and limitations well enough to use, challenge, validate, monitor, and govern it. The needed depth depends on risk and context.
Related: Conceptual soundness, Effective challenge, Model documentation
Also: Model limitations
Known constraints, simplifications, judgments, data boundaries, and conditions that affect where a model is reliable. They should be documented, communicated to users, reflected in approvals, monitored, and mitigated when material.
Related: Model uncertainty, Model documentation, Model approval
The potential for adverse consequences from decisions based on incorrect or misused model outputs and reports. Model risk increases with greater model complexity, higher uncertainty about inputs and assumptions, broader scope of use, and larger potential financial or reputational impact if the model is wrong.
Related: Model risk management, Effective challenge, Model tiering
Also: MRM
The discipline of identifying, measuring, and controlling model risk across an institution's full model inventory, encompassing model development and use, independent validation, and governance, policies, and controls. Rooted in SR 11-7 (2011) and now SR 26-2 (2026) in the US.
Related: Model risk, Model validation, Model governance
Uncertainty arising from limited data, assumptions, estimation, parameter choices, structural simplification, future conditions, and model selection. It can be assessed, communicated, monitored, and mitigated but not always eliminated.
Related: Model limitations and assumptions, Sensitivity analysis, Model risk
The model risk remaining after validation, controls, monitoring, limitations, overlays, restrictions, conservatism, and other mitigants are applied. Management decides whether the residual risk is acceptable within risk appetite.
Related: Model risk appetite, Model risk rating, Model limitations and assumptions
Also: Vendor model, External model
A model, score, parameter, data product, or analytical component obtained from an external provider. The institution remains responsible for due diligence, intended use, limitations, validation, monitoring, change, access, continuity, and exit.
Related: Model inventory, Model validation, Model limitations and assumptions
See: model risk management, best model risk management software, top model risk management firms
Data & Performance 6
Also: Input drift, Population drift
A change in the distribution or characteristics of model inputs over time. Drift does not automatically mean a model has failed, but it can trigger investigation, performance testing, recalibration, restrictions, or redevelopment.
Related: Ongoing monitoring, Population stability index, Model performance
A traceable record of where model data originates, how it is transformed, which controls apply, and where it is consumed. Lineage helps validators reproduce results, assess implementation, and identify upstream dependencies.
Related: Data quality, Model documentation, Model inventory
The fitness of data for a model's intended use, commonly assessed through completeness, accuracy, timeliness, consistency, representativeness, and controlled transformation. Weak data can invalidate otherwise sound methods.
Related: Data lineage, Conceptual soundness, Model limitations and assumptions
Also: Algorithmic bias
Systematic error or differential behavior that can arise from data, design, assumptions, objectives, implementation, or use. Bias assessment should be tied to the model's purpose, affected populations, decisions, and applicable legal requirements.
Related: Data quality, Explainability, Adverse action
Also: Performance threshold, Trigger threshold
A predefined level or condition that prompts review, escalation, restriction, recalibration, or other action when model performance, data, use, or risk changes. Thresholds need rationale, owners, and documented responses.
Related: Ongoing monitoring, Model performance, Exception management
How well a model behaves against defined objectives, outcomes, stability measures, limitations, and business consequences. Performance measures vary by model and should be linked to thresholds and actions.
Related: Backtesting, Calibration, Ongoing monitoring
Governance 13
Also: Model exception
The controlled process for approving, documenting, limiting, monitoring, escalating, and closing deviations from model policy or normal governance requirements. Exceptions should have an owner, rationale, compensating controls, and expiry or review date.
Related: Model risk appetite, Validation finding, Model approval
See: model risk management framework, model risk management software
The formal process for reviewing, approving, testing, and documenting changes to an existing model, whether a minor recalibration or a substantive redesign, so that changes go through appropriate governance and, where material, trigger revalidation rather than bypassing controls.
Related: Model governance, Model validation, Model inventory
The written record of a model's purpose, theory, design, data sources, assumptions, limitations, and testing, maintained so that a party unfamiliar with the model's construction can understand how it works and evaluate its soundness. Complete documentation is a prerequisite for effective independent validation, not a substitute for it.
Related: Model validation, Conceptual soundness, Model governance
The policies, roles, committee structures, and controls an institution puts in place to oversee its model risk management program: who owns the inventory, who approves new models, how validation findings are escalated, and how the board and senior management maintain oversight. One of SR 11-7/SR 26-2's three foundational pillars, alongside model development/use and independent validation.
Related: Model risk management, Three lines of defense, Model inventory
A centralized, maintained record of every model in use across an institution, including each model's purpose, owner, risk tier, and validation status and history. SR 26-2 places renewed emphasis on capturing vendor and third-party models in the inventory, given growing reliance on externally developed tools.
Related: Model tiering, Model governance, Model risk management
See: model risk management software, model risk management framework
Also: Management adjustment, Post-model adjustment
A documented adjustment applied to a model output to address known limitations, unusual conditions, missing factors, or judgment. Overlays require rationale, approval, monitoring, outcomes analysis, and an exit or recalibration plan.
Related: Model limitations and assumptions, Expected credit loss model, Override analysis
The accountable role responsible for a model's appropriate use, documentation, approval, monitoring, limitations, issues, changes, and lifecycle decisions. The owner is distinct from the developer, validator, user, and approver where governance requires separation.
Related: Model governance, Three lines of defense, Model approval
A board- or senior-management-approved statement of how much model risk an institution is willing to accept in pursuit of its business objectives, used to guide model tiering thresholds, validation resourcing, and escalation criteria for identified model limitations.
Related: Model tiering, Model governance, Model risk
Also: Model risk classification
A categorical or scored assessment of a model's inherent risk based on factors such as impact, use, complexity, data, autonomy, customer effects, and regulatory exposure. It drives governance intensity.
Related: Model tiering, Model risk appetite, Residual model risk
See: model risk management framework, model risk management software
Also: Model risk classification
Classifying models by risk level, based on factors such as financial materiality, complexity, and reliance placed on the model's output, so that validation depth, frequency, and monitoring intensity scale with actual risk rather than applying uniformly across every model in the inventory.
Related: Model inventory, Model risk, Model governance
Also: Internal audit (model risk)
In the three-lines structure applied to model risk management, the third line is internal audit: it independently assesses whether the overall MRM program, governance, inventory discipline, validation function, is working as designed, rather than validating individual models itself. Distinct from the second-line model validation function, which reviews specific models.
Related: Three lines of defense, Effective challenge, Model governance
Also: Three lines model
A governance structure in which the first line (model owners/developers) builds and operates models, the second line (an independent risk or model validation function) provides effective challenge and oversight, and the third line (internal audit) independently assesses whether the overall model risk management program itself is functioning as intended.
Related: Effective challenge, Model validation, Model governance
The organizational and practical separation that allows validators to challenge a model without conflicting responsibility or incentive. Independence is supported by reporting lines, authority, funding, access, competence, and conflict controls.
Related: Independent model validation, Three lines of defense, Effective challenge
Model Lifecycle 6
Also: Training sample
The data used to estimate, train, or select a model. Validators examine sampling design, exclusions, time periods, representativeness, leakage, and how development data differs from validation and production populations.
Related: Data quality, Model development, Outcomes analysis
A documented decision by authorized personnel or a committee permitting a model's use under stated conditions. Approval should consider validation, limitations, risk rating, intended use, monitoring, open findings, and compensating controls.
Related: Model risk rating, Validation finding, Exception management
See: model risk management framework, model risk management software
Also: Model retirement
The controlled removal of a model from approved use. Decommissioning addresses replacement, dependent processes, records, access, reporting, residual outputs, historical evidence, and retention obligations.
Related: Model inventory, Model change management, Model owner
See: model risk management framework, model risk management software
The process of defining a model's purpose, selecting data and methods, estimating or training it, testing performance, documenting decisions, and preparing it for controlled implementation and independent review.
Related: Development sample, Conceptual soundness, Model documentation
Also: Model deployment
The translation of an approved model into a production process, system, or decision workflow. Controls test code, data mappings, calculations, interfaces, access, versioning, approvals, fallback, and consistency with the validated design.
Related: Model approval, Model change management, Data lineage
Also: Proxy model
A simpler model used to approximate, explain, benchmark, or replace aspects of another model. Governance should document its purpose, fidelity, limitations, validation, and the decisions that rely on it.
Related: Benchmarking (model risk), Explainability, Champion-challenger
Validation Techniques 17
A statistical technique that compares a model's historical predictions against what actually occurred, used to assess predictive accuracy over time. Backtesting is a specific, quantitative form of outcomes analysis, common in credit scoring, market risk (e.g. Value-at-Risk), and capital models.
Related: Outcomes analysis, Model validation, Ongoing monitoring
Comparing a model's outputs against alternative data, models, or theoretical results to identify differences and understand their sources. In independent model validation, benchmarking often uses a challenger model, an alternative model built to test whether the primary model's results hold up under comparison.
Related: Model validation, Champion-challenger, Conceptual soundness
Also: Model calibration
The degree to which a model's predicted probabilities or values align with observed outcomes. Validation tests calibration at the appropriate segment, horizon, and use case and investigates material underprediction or overprediction.
Related: Backtesting, Outcomes analysis, Probability of default
A benchmarking approach in which an institution's production model (the champion) is compared against one or more alternative models (challengers) built independently, often using different methodology, to test whether the champion's results are reasonable and to surface potential weaknesses.
Related: Model validation
An evaluation of the quality of a model's design and construction, including whether its underlying theory, assumptions, data, and methodology are appropriate for its intended business use. Conceptual soundness review is one of the three core techniques of independent model validation, alongside ongoing monitoring and outcomes analysis.
Related: Model validation, Outcomes analysis
Also: Rank ordering
A model's ability to distinguish observations with different outcomes or risk levels. Common measures depend on the model and use case and must be interpreted alongside calibration, stability, and business consequences.
Related: Calibration, Backtesting, Probability of default
Also: Independent validation
A review performed with sufficient separation from model development, ownership, and use to provide credible challenge. Independence includes reporting lines, authority, competence, incentives, access to evidence, and freedom from conflicting work.
Related: Model validation, Validation independence, Effective challenge
Also: Independent model validation
The set of processes and activities intended to verify that a model is performing as intended, in line with its design and business uses, and to identify potential limitations and assumptions. Validation is meant to be performed by staff independent from model development, providing effective challenge.
Related: Effective challenge, Conceptual soundness, Outcomes analysis
Continuous or periodic tracking of a model's performance after deployment, checking that it continues to work as intended as data, markets, or usage patterns evolve, distinct from a full periodic revalidation. Includes outcomes analysis, backtesting, and monitoring of key performance indicators between formal validation cycles.
Related: Outcomes analysis, Backtesting, Model validation
Comparing a model's actual outputs and predictions against real subsequent outcomes to check ongoing accuracy and performance. Outcomes analysis, closely related to backtesting, is a core ongoing-monitoring component of independent model validation.
Related: Backtesting, Model validation, Ongoing monitoring
Also: Model override
The review of decisions that replace or adjust a model's output. Analysis considers frequency, direction, magnitude, reason, approver, outcome, concentration, and whether patterns indicate model, policy, training, or use problems.
Related: Outcomes analysis, Use test, Model performance
Also: PSI
A measure commonly used to compare how a variable or score distribution has shifted between populations or periods. PSI can flag change but does not by itself diagnose cause, performance impact, or required action.
Related: Data drift, Ongoing monitoring, Model performance
Testing how a model's outputs change in response to variations in individual inputs or assumptions, used to identify which factors most influence a model's results and where it may be unstable or overly reliant on a single assumption. A standard technique within conceptual soundness review.
Related: Conceptual soundness, Model validation, Stress testing
Also: Scenario analysis
The assessment of model behavior, financial impact, or institutional resilience under severe or adverse conditions. Stress tests can challenge assumptions, data, relationships, limits, capital, liquidity, and management actions.
Related: Sensitivity analysis, Benchmarking (model risk), Model uncertainty
An assessment of whether a model is actually being used the way it was designed and validated to be used, and whether that use remains within the model's intended scope and limitations. A model validated for one purpose but repurposed for another without revalidation is a common source of model risk.
Related: Model validation, Model risk, Conceptual soundness
Also: Model finding, Validation issue
A documented weakness, limitation, control gap, or required action identified through validation. Findings usually record severity, evidence, owner, due date, use restrictions, remediation, challenge, and closure approval.
Related: Exception management, Model approval, Effective challenge
Also: Validation cycle
How often a model receives full or targeted validation. Frequency should reflect model risk, use, performance, change, findings, external events, and policy, with trigger-based review supplementing calendar cycles.
Related: Model risk rating, Ongoing monitoring, Model change management
No terms match your search. Try a different word, or ask us directly.
Model risk management sourcing brief
Occasional emails when we publish a new guide, framework update, or glossary update. No spam, unsubscribe anytime.
Single opt-in. We store only your email to send these updates. See ourprivacy notice. This is procurement information, not a compliance guarantee or legal advice.