Skip to content

FRM Exam Part II · Governance

Credit Risk Reporting, Monitoring and Model Governance

Updated 11 October 2026 · Fact-checked

Credit risk governance means watching the portfolio continuously, reporting it clearly to management and the board, and controlling the models behind ratings and capital. Models are validated independently, tested for discrimination and calibration, challenged effectively, and reviewed on a set cycle. Exam questions ask you to match a weakness to the right control.

Understand Credit Risk Reporting, Monitoring and Model Governance

A bank does not finish managing credit risk when a loan is approved. It must keep watching the borrower and the portfolio. Ongoing monitoring tracks things like covenant compliance, past-due status, rating migration, watch lists, limit usage, concentrations and early warning signals. The goal is to spot deterioration early, while the bank can still act.

Management reporting turns that data into decisions. Good reports are accurate, timely, clear and suited to the reader. The board sees high-level risk against appetite. Senior risk committees see concentrations, limit breaches, migration and loss trends. Credit officers see account detail. Reports should show exceptions and the action being taken, not just numbers. Data aggregation standards such as BCBS 239 support this.

Credit models, such as rating models and PD, LGD and EAD estimates, can be wrong. Model risk is the loss or poor decision that comes from a model that is wrong or misused. The US supervisory guidance SR 11-7 says model risk comes from fundamental errors in the model and from incorrect or inappropriate use. Its core ideas are sound development, independent validation, effective challenge and strong governance.

Validation of a rating system has several parts. Discriminatory power asks whether the model ranks borrowers correctly, so riskier ones get worse grades. Common tools are the ROC curve, AUC, the accuracy ratio and the Gini coefficient. Calibration asks whether predicted PDs match realized default rates, usually tested by backtesting grade PDs against observed defaults. Stability and data quality checks complete the picture. Also review the process, documentation and how the ratings are used in decisions.

Governance assigns roles. The board and senior management set policy and approve key models. Model developers and owners build and use the models. Validators must be independent of development and have enough competence and standing to challenge. Internal audit, as the third line, checks the whole process. Under the Basel internal ratings-based approach, banks must validate their rating systems, document them, and have the process reviewed independently. Weak governance shows up as stale models, unreviewed overrides, or validation done by the developers themselves.

Key formulas to remember

Accuracy ratio (Gini)
AR = 2 × AUC − 1
Measures discriminatory power. AUC of 0.5 gives AR = 0 (no power); AUC of 1 gives AR = 1 (perfect).
Binomial backtest of a grade PD
Expected defaults = N × PD; standard deviation = √(N × PD × (1 − PD))
Compare observed defaults with this range. It assumes independent defaults, so correlation makes it too strict (too many false alarms).
Calibration vs discrimination
Discrimination = ranking; Calibration = level of PD
A model can rank well yet have PDs that are too low. Check both.
SR 11-7 model risk sources
Model risk = fundamental errors + incorrect or inappropriate use
Validation needs independence, and effective challenge needs competence, influence and incentives.

How to solve Credit Risk Reporting, Monitoring and Model Governance questions

Use this method for any question on monitoring, reporting or model governance.

  1. 1Identify what is being tested: monitoring, reporting, validation of a rating model, or governance roles.
  2. 2Find the failure or weakness in the scenario, such as stale data, no independence, poor calibration or an unchallenged override.
  3. 3Decide if the issue is discrimination, calibration, stability, data quality, use of the model, or governance.
  4. 4If numbers are given, compute the expected count or AUC-based ratio and compare with the observed result.
  5. 5Match the control to the weakness: independent validation, backtesting, benchmarking, overrides review, or escalation to the board.
  6. 6Check roles: who should own, validate, approve and audit?
  7. 7Pick the option that fixes the root cause, not just the symptom.

Quickest way: Weakness-to-control matching

When to use it: Use when the question is a short scenario with four plausible controls.

  1. Underline the one failing element in the stem.
  2. Ask: ranking, level, process or independence?
  3. Ranking problem points to AUC or accuracy ratio; level problem points to PD backtesting.
  4. Independence problem points to a separate validation function and effective challenge.
  5. Eliminate options that only add more reports or data without fixing the cause.

Common mistakes in Credit Risk Reporting, Monitoring and Model Governance

  • Confusing discrimination with calibration

    Both are called accuracy and both use default data.

    Fix: Discrimination is how well grades rank risk. Calibration is whether PD levels match realized defaults.

  • Letting developers validate their own model

    It seems efficient because they know the model best.

    Fix: SR 11-7 expects validation independent of development and use, with ability to challenge.

  • Treating a high AUC as proof the model is fine

    One strong statistic feels conclusive.

    Fix: A model can rank well but understate PDs. Also test calibration, stability, data and use.

  • Reading binomial backtest results as exact

    The formula looks precise.

    Fix: It assumes independent defaults. With default correlation, more breaches can occur by chance, so interpret with care.

  • Thinking validation is one-off at approval

    Candidates link validation only to model launch.

    Fix: Validation is ongoing, with periodic review and triggers such as market changes or performance drift.

  • Assuming reports should show as much data as possible

    More information seems safer.

    Fix: Good reports are clear, timely and decision-focused, tailored to the reader, and highlight exceptions and actions.

Worked examples

Example 1

A bank has 400 borrowers in rating grade 4 with a PD of 2%. Over the year, 14 default. Assuming independence, is the observed count consistent with the PD at roughly two standard deviations?

Show the solution
  1. Expected defaults = 400 × 0.02 = 8.
  2. Standard deviation = √(400 × 0.02 × 0.98) = √7.84 = 2.8.
  3. Two standard deviations above the mean = 8 + 5.6 = 13.6.
  4. Observed 14 is above 13.6, so it lies just outside the range.
  5. Because defaults are usually correlated, treat this as a warning to investigate calibration, not as proof.

Answer: 14 defaults exceeds the roughly 13.6 upper bound, so the 2% PD looks too low and calibration should be reviewed.

Example 2

A rating model has an AUC of 0.82. Validation finds that its predicted portfolio PD is 1.5% while realized default rate has been 2.4% for three years. The model developers also performed the validation. Give the accuracy ratio and the main findings.

Show the solution
  1. Accuracy ratio = 2 × 0.82 − 1 = 0.64.
  2. An AR of 0.64 shows good ranking power.
  3. Predicted 1.5% against realized 2.4% shows PDs are too low: a calibration weakness.
  4. Validation by the developers breaks the independence expectation in SR 11-7.
  5. Remedies: recalibrate PDs, and have an independent function revalidate.

Answer: AR = 0.64, so discrimination is good, but calibration is poor and validation lacks independence.

Exam tips

  • Always separate discrimination from calibration; many options exploit this.
  • When you see a developer validating their own model, think independence and effective challenge.
  • For SR 11-7 questions, remember model risk comes from errors and from misuse.
  • Compute AR = 2 × AUC − 1 quickly and check sign and range.
  • In reporting questions, favour clear, timely, tailored reports with exceptions and actions.

Practice questions from Governance

Credit Risk Reporting, Monitoring and Model Governance: frequently asked questions

What is the difference between model validation and model governance?

Validation is the technical testing of a model's design, performance and use. Governance is the framework of policies, roles, approvals and oversight around all models. Validation is one key control inside governance.

What does SR 11-7 require for credit models?

It sets supervisory expectations for model risk management in US banks. Key ideas are sound development and use, independent validation, effective challenge and board and senior management oversight. FRM tests these ideas, not exact wording.

How do you validate an internal rating system under Basel?

You test discriminatory power, calibration against realized defaults, stability and data quality, and review the rating process and use. Banks must also document the system and have it reviewed independently.

What should a credit risk report to the board contain?

It should show portfolio risk against appetite, concentrations, rating migration, limit breaches, loss trends and actions taken. It should be concise, accurate and timely rather than overloaded with detail.