Skip to content

FRM Part II · FRM Exam Part II

Case Study: Model Risk and Model Validation for FRM Part II

Model risk is the chance of loss or poor decisions because a model is wrong, misused or misunderstood. To solve questions, identify the source (data, specification, implementation, use), link it to a case or control, then name the fix: independent validation, governance under SR 11-7, or a buffer for uncertainty.

What this chapter covers

This chapter is about what goes wrong when banks and funds rely on quantitative models, and how firms find, control and size that risk. It starts with the sources and types of model risk: bad data, wrong assumptions, coding errors, and models used outside their intended purpose. It then uses two well-known failures, the JPMorgan London Whale losses and Long-Term Capital Management (LTCM), to show how those sources play out in real firms.

The second half covers the defences. You learn the model validation process and its techniques, then the governance structure set out in the US supervisory guidance SR 11-7. The chapter ends with how firms mitigate model risk and try to put a number on it, for example through conservative adjustments or capital buffers.

The chapter links to many other parts of Part II. VaR and expected shortfall in market risk, credit scoring and rating models, operational risk and resilience, and valuation in investment management all depend on models. Questions here are usually case-like: you read a short scenario and pick the weakness or the right control. Knowing this chapter helps you read model-based questions in every other topic more carefully.

Model risk questions are applied and scenario-driven, so they reward clear thinking more than memorised formulas. The vocabulary is compact, and once you can classify a failure by source and match it to a control, you can answer most questions quickly. The same logic also helps you in market, credit and operational risk questions that quietly test whether a model is fit for purpose. For a four-hour paper with 80 questions, that is good value for a modest amount of study time.

Case Study: Model Risk and Model Validation: topics in the order to study them

  1. 1Sources and Types of Model RiskIt gives you the classification (data, specification, implementation, use) that every later topic builds on.
  2. 2Model Risk Case Studies: London Whale and LTCMCases make the sources concrete, and you can then tag each failure to a cause and a missed control.
  3. 3Model Validation Process and TechniquesNow that you know what can fail, you learn how validators test for it: conceptual review, data checks, replication and backtesting.
  4. 4Model Risk Governance and SR 11-7 GuidanceGovernance sets who owns, validates and approves models, so it makes most sense after you know what validation does.
  5. 5Mitigating and Quantifying Model RiskIt pulls everything together: controls to reduce model risk and methods to estimate its size, so study it last.

How to prepare Case Study: Model Risk and Model Validation

Treat this as a reasoning chapter. Your goal is to look at a scenario and quickly say what failed, why, and which control would have caught it.

  1. Read the sources of model risk and write a one-line example of each: data, specification, implementation and use.
  2. For London Whale and LTCM, build a short note per case: what the model or process was, what failed, and which control was missing. Do not memorise every detail of the events.
  3. List the validation activities and match each to the problem it detects, such as backtesting for predictive accuracy and benchmarking for alternative-model comparison.
  4. Learn the SR 11-7 structure in plain words: model development and use, validation, and governance with policies, roles and inventory. Remember the idea of effective challenge.
  5. Study mitigation and quantification together. Know that you can reduce risk through controls and limits, and size it through adjustments, buffers or scenario analysis.
  6. Practise scenario MCQs. For each, name the source, the control, and why the other three options fail.
  7. Last week, redo the questions you missed and re-read your case notes and validation list.

Common mistakes in Case Study: Model Risk and Model Validation

  • Treating model risk as only a maths or coding problem.

    Fix: Always check all four sources. Ask who uses the model, for what, and under which controls.

  • Memorising case stories without linking them to causes.

    Fix: For each case, write the source of model risk, the control that failed, and the lesson in one line each.

  • Confusing validation with development testing.

    Fix: Remember that validation is independent and challenges the model. Developer testing does not replace it.

  • Assuming good backtesting results prove the model is sound.

    Fix: Backtesting is only one part of outcomes analysis. A model can pass and still have wrong assumptions or be used for the wrong purpose.

  • Mixing up mitigating model risk and quantifying it.

    Fix: Mitigation reduces the chance or impact of errors. Quantification estimates how large the exposure to model error is. Decide which one the question asks for.

  • Treating SR 11-7 as a list of banned practices.

    Fix: Read it as a framework of principles for development, validation and governance, built around effective challenge and clear accountability.

Last-day revision: Case Study: Model Risk and Model Validation

  • Model risk is loss or bad decisions from a model that is wrong, misused or misunderstood.
  • Main sources: poor data, wrong specification or assumptions, implementation errors, and misuse outside intended scope.
  • A model can be sound in theory and still fail because of how it is used.
  • London Whale: a VaR model change and weak oversight let the risk in the credit portfolio be understated.
  • LTCM: models relied on historical relationships and assumed enough liquidity, and leverage magnified the losses when markets moved against it.
  • Validation includes conceptual soundness review, data and implementation checks, and outcomes analysis such as backtesting.
  • Benchmarking compares model output with an alternative model or an independent estimate.
  • Validation must be independent of model development and be able to give effective challenge.
  • SR 11-7 expects a model inventory, clear roles, documentation and ongoing monitoring.
  • Senior management and the board are responsible for the overall model risk framework.
  • Mitigation includes limits, conservative adjustments, overlays and use restrictions.
  • Quantifying model risk is hard; common approaches use alternative models, parameter uncertainty and stress or scenario analysis.

Case Study: Model Risk and Model Validation practice questions

Case Study: Model Risk and Model Validation in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Case Study: Model Risk and Model Validation: frequently asked questions

What is model risk in FRM Part II?

It is the risk of loss or poor decisions caused by errors in a model or by its misuse. The errors can come from data, assumptions, implementation or use. Questions usually ask you to spot the source or choose the right control.

Do I need to know every detail of London Whale and LTCM?

No. You need the key model-related failures, the control weaknesses and the lessons. Focus on why the models misled management and what governance or validation should have done.

What is SR 11-7 and why does it matter?

SR 11-7 is US supervisory guidance on model risk management. It covers model development and use, validation, and governance. Exam questions test ideas such as independent validation, effective challenge, documentation and a model inventory.

How long should I spend on this chapter?

It is a conceptual chapter, so most candidates can cover it faster than calculation-heavy ones. Allow time for reading, case notes and scenario practice. Spend extra time if you are new to validation or governance language.