Skip to content

FRM Exam Part II · Case Study: Model Risk and Model Validation

Model Risk Governance and SR 11-7 Guidance Explained

Updated 11 October 2026 · Fact-checked

SR 11-7 is the US supervisory guidance on model risk management. It expects banks to keep a full model inventory, assign clear roles, validate models independently, document everything, and have the board and senior management oversee model risk. To answer questions, match each expectation to its owner and purpose.

Understand Model Risk Governance and SR 11-7 Guidance

A model in SR 11-7 is a quantitative method that turns input data into quantitative estimates. Model risk is the potential for adverse consequences from decisions based on incorrect or misused model outputs. It comes from two sources: the model may have fundamental errors and give wrong outputs, or it may be used incorrectly or outside the purpose it was built for.

SR 11-7 is guidance issued in 2011 by the US Federal Reserve (jointly with the OCC's bulletin). It is not a formula topic. It sets expectations for how banks govern models. FRM Part II tests whether you can name those expectations and apply them to a case.

The guidance rests on three pillars: model development, implementation and use; model validation; and governance, policies and controls. Validation must give effective challenge: critical analysis by objective, informed people with the competence, influence and incentives to identify limitations and push for change.

Governance works through the board and senior management. The board sets the bank's risk appetite for model risk, approves the policy framework and reviews reporting. Senior management carries out the policy, allocates resources and makes sure there are consistent procedures. The bank also keeps a model inventory of all models in use, in development or recently retired, with purpose, owner, inputs, limitations, validation status and dates.

This maps onto the three lines of defense. Model owners and developers (first line) build, use and test their models. Independent validation and model risk management (second line) challenge them. Internal audit (third line) checks that the whole process works. Validators must be independent of development and have enough standing to be heard. Documentation must be detailed enough that a knowledgeable third party could understand the model, its assumptions and limits and could recreate it.

Key formulas to remember

Definition of model risk
Model risk = risk from (1) fundamental model errors + (2) incorrect or inappropriate use of the model
Two sources. Use is as important as the build.
Three pillars of SR 11-7
Development, implementation and use + Validation + Governance, policies and controls
Most questions fit one of these pillars.
Core validation elements
Conceptual soundness + Ongoing monitoring (including benchmarking) + Outcomes analysis (including backtesting)
Validation is more than backtesting. Frequency is at least annual review in practice, set by bank policy.
Effective challenge
Competence + Influence + Incentives + Independence from development
Without influence, validators cannot force fixes.
Model inventory contents
Purpose, owner, users, inputs, limitations, validation status and dates, vendor or in-house
The inventory covers all models, including vendor models and those under development.

How to solve Model Risk Governance and SR 11-7 Guidance questions

Use this approach for any SR 11-7 or model governance question.

  1. 1Identify what the question describes: a development issue, a validation issue or a governance issue.
  2. 2Name the failing element: inventory, documentation, independence, use outside purpose, board oversight, or vendor model control.
  3. 3Assign the responsibility: board, senior management, model owner, validator or internal audit.
  4. 4Recall the SR 11-7 expectation for that element in plain words.
  5. 5Eliminate options that give validators development duties or let developers validate their own work.
  6. 6Pick the answer that fixes the root cause, not just the symptom.

Quickest way: Role-match shortcut

When to use it: When you have under two minutes per question and the options list responsibilities.

  1. Board: sets appetite and approves policy, reviews reports.
  2. Senior management: implements policy and resources.
  3. Developers and owners: build, test, use, document.
  4. Validators: independent challenge, never the builder.
  5. Audit: tests the whole framework.
  6. Pick the option that respects this split.

Common mistakes in Model Risk Governance and SR 11-7 Guidance

  • Treating validation as only backtesting.

    Backtesting is the most visible validation tool in market risk chapters.

    Fix: Remember the three elements: conceptual soundness, ongoing monitoring and outcomes analysis.

  • Letting the model developer validate their own model.

    Developers know the model best, so it seems efficient.

    Fix: Validation needs independence and effective challenge. Developers can test, but that is not validation.

  • Excluding vendor models from the inventory and validation.

    People assume the vendor has already checked the model.

    Fix: Vendor models carry model risk. The bank must validate them as far as it can and document limits.

  • Thinking model risk only comes from coding or math errors.

    The word 'error' suggests a technical flaw.

    Fix: Include misuse: a sound model used for a purpose it was not designed for is still model risk.

  • Placing the board in daily model approval.

    Board oversight is confused with management.

    Fix: The board sets appetite, approves policy and reviews reporting. Management runs the process.

Worked examples

Example 1

A bank's credit scoring model was built by its quant team, tested by the same team, and approved for use. No separate review occurred. Which SR 11-7 expectation is breached, and what is the fix?

Show the solution
  1. The model was built and tested by one team, with no second party.
  2. SR 11-7 requires independent validation giving effective challenge.
  3. The developers lack independence, so their testing counts as development testing, not validation.
  4. The fix is a validation function independent of development, with enough authority and competence to challenge the model and require changes.

Answer: Independent validation and effective challenge were breached. Add an independent validation unit that challenges the model before use.

Example 2

A bank uses a mortgage prepayment model, built for fixed-rate loans, to value adjustable-rate loans. The model passed validation when built. Which source of model risk is this, and what should governance do?

Show the solution
  1. The model was sound for its original purpose, so the issue is not a fundamental error.
  2. It is applied to a different product, which is incorrect or inappropriate use.
  3. Governance should check that the inventory records the intended use and limitations.
  4. Use outside scope should trigger review or revalidation, or the use should be stopped until the model is validated for adjustable-rate loans.

Answer: This is model misuse, the second source of model risk. The model needs revalidation for the new use, or the use should stop, with the inventory and documentation updated.

Exam tips

  • Questions are usually short cases. Find the one governance element that failed.
  • Watch for 'independent' in the options. It is often the deciding word.
  • Know who owns what: board versus management versus validators versus audit.
  • Remember that vendor models and models under development are still in scope.
  • Link SR 11-7 to the three lines of defense when options mention audit or second line.

Practice questions from Case Study: Model Risk and Model Validation

Model Risk Governance and SR 11-7 Guidance: frequently asked questions

What is SR 11-7 in simple terms?

It is US supervisory guidance on how banks should manage model risk. It covers development and use, validation, and governance. It asks for strong inventories, documentation and independent challenge.

Who is responsible for model risk in a bank?

The board sets appetite and approves policy. Senior management implements it. Model owners manage their models, validators challenge them independently, and internal audit checks the framework.

What must a model inventory include?

It should list all models in use, in development or recently retired. Typical details are purpose, owner, inputs, limitations, vendor or in-house status and validation dates.

Does SR 11-7 apply to vendor models?

Yes. Vendor models carry model risk. The bank must validate them as far as possible, understand their limits and document how they are used.