FRM Exam Part II · Governance
Credit Risk Reporting, Monitoring and Model Governance
Updated 11 October 2026 · Fact-checked
Credit risk governance means watching the portfolio continuously, reporting it clearly to management and the board, and controlling the models behind ratings and capital. Models are validated independently, tested for discrimination and calibration, challenged effectively, and reviewed on a set cycle. Exam questions ask you to match a weakness to the right control.
Understand Credit Risk Reporting, Monitoring and Model Governance
A bank does not finish managing credit risk when a loan is approved. It must keep watching the borrower and the portfolio. Ongoing monitoring tracks things like covenant compliance, past-due status, rating migration, watch lists, limit usage, concentrations and early warning signals. The goal is to spot deterioration early, while the bank can still act.
Management reporting turns that data into decisions. Good reports are accurate, timely, clear and suited to the reader. The board sees high-level risk against appetite. Senior risk committees see concentrations, limit breaches, migration and loss trends. Credit officers see account detail. Reports should show exceptions and the action being taken, not just numbers. Data aggregation standards such as BCBS 239 support this.
Credit models, such as rating models and PD, LGD and EAD estimates, can be wrong. Model risk is the loss or poor decision that comes from a model that is wrong or misused. The US supervisory guidance SR 11-7 says model risk comes from fundamental errors in the model and from incorrect or inappropriate use. Its core ideas are sound development, independent validation, effective challenge and strong governance.
Validation of a rating system has several parts. Discriminatory power asks whether the model ranks borrowers correctly, so riskier ones get worse grades. Common tools are the ROC curve, AUC, the accuracy ratio and the Gini coefficient. Calibration asks whether predicted PDs match realized default rates, usually tested by backtesting grade PDs against observed defaults. Stability and data quality checks complete the picture. Also review the process, documentation and how the ratings are used in decisions.
Governance assigns roles. The board and senior management set policy and approve key models. Model developers and owners build and use the models. Validators must be independent of development and have enough competence and standing to challenge. Internal audit, as the third line, checks the whole process. Under the Basel internal ratings-based approach, banks must validate their rating systems, document them, and have the process reviewed independently. Weak governance shows up as stale models, unreviewed overrides, or validation done by the developers themselves.
Key formulas to remember
- Accuracy ratio (Gini)
- AR = 2 × AUC − 1
- Measures discriminatory power. AUC of 0.5 gives AR = 0 (no power); AUC of 1 gives AR = 1 (perfect).
- Binomial backtest of a grade PD
- Expected defaults = N × PD; standard deviation = √(N × PD × (1 − PD))
- Compare observed defaults with this range. It assumes independent defaults, so correlation makes it too strict (too many false alarms).
- Calibration vs discrimination
- Discrimination = ranking; Calibration = level of PD
- A model can rank well yet have PDs that are too low. Check both.
- SR 11-7 model risk sources
- Model risk = fundamental errors + incorrect or inappropriate use
- Validation needs independence, and effective challenge needs competence, influence and incentives.
How to solve Credit Risk Reporting, Monitoring and Model Governance questions
Use this method for any question on monitoring, reporting or model governance.
- 1Identify what is being tested: monitoring, reporting, validation of a rating model, or governance roles.
- 2Find the failure or weakness in the scenario, such as stale data, no independence, poor calibration or an unchallenged override.
- 3Decide if the issue is discrimination, calibration, stability, data quality, use of the model, or governance.
- 4If numbers are given, compute the expected count or AUC-based ratio and compare with the observed result.
- 5Match the control to the weakness: independent validation, backtesting, benchmarking, overrides review, or escalation to the board.
- 6Check roles: who should own, validate, approve and audit?
- 7Pick the option that fixes the root cause, not just the symptom.
Quickest way: Weakness-to-control matching
When to use it: Use when the question is a short scenario with four plausible controls.
- Underline the one failing element in the stem.
- Ask: ranking, level, process or independence?
- Ranking problem points to AUC or accuracy ratio; level problem points to PD backtesting.
- Independence problem points to a separate validation function and effective challenge.
- Eliminate options that only add more reports or data without fixing the cause.
Common mistakes in Credit Risk Reporting, Monitoring and Model Governance
Confusing discrimination with calibration
Both are called accuracy and both use default data.
Fix: Discrimination is how well grades rank risk. Calibration is whether PD levels match realized defaults.
Letting developers validate their own model
It seems efficient because they know the model best.
Fix: SR 11-7 expects validation independent of development and use, with ability to challenge.
Treating a high AUC as proof the model is fine
One strong statistic feels conclusive.
Fix: A model can rank well but understate PDs. Also test calibration, stability, data and use.
Reading binomial backtest results as exact
The formula looks precise.
Fix: It assumes independent defaults. With default correlation, more breaches can occur by chance, so interpret with care.
Thinking validation is one-off at approval
Candidates link validation only to model launch.
Fix: Validation is ongoing, with periodic review and triggers such as market changes or performance drift.
Assuming reports should show as much data as possible
More information seems safer.
Fix: Good reports are clear, timely and decision-focused, tailored to the reader, and highlight exceptions and actions.
Worked examples
Example 1
A bank has 400 borrowers in rating grade 4 with a PD of 2%. Over the year, 14 default. Assuming independence, is the observed count consistent with the PD at roughly two standard deviations?
Show the solution
- Expected defaults = 400 × 0.02 = 8.
- Standard deviation = √(400 × 0.02 × 0.98) = √7.84 = 2.8.
- Two standard deviations above the mean = 8 + 5.6 = 13.6.
- Observed 14 is above 13.6, so it lies just outside the range.
- Because defaults are usually correlated, treat this as a warning to investigate calibration, not as proof.
Answer: 14 defaults exceeds the roughly 13.6 upper bound, so the 2% PD looks too low and calibration should be reviewed.
Example 2
A rating model has an AUC of 0.82. Validation finds that its predicted portfolio PD is 1.5% while realized default rate has been 2.4% for three years. The model developers also performed the validation. Give the accuracy ratio and the main findings.
Show the solution
- Accuracy ratio = 2 × 0.82 − 1 = 0.64.
- An AR of 0.64 shows good ranking power.
- Predicted 1.5% against realized 2.4% shows PDs are too low: a calibration weakness.
- Validation by the developers breaks the independence expectation in SR 11-7.
- Remedies: recalibrate PDs, and have an independent function revalidate.
Answer: AR = 0.64, so discrimination is good, but calibration is poor and validation lacks independence.
Exam tips
- Always separate discrimination from calibration; many options exploit this.
- When you see a developer validating their own model, think independence and effective challenge.
- For SR 11-7 questions, remember model risk comes from errors and from misuse.
- Compute AR = 2 × AUC − 1 quickly and check sign and range.
- In reporting questions, favour clear, timely, tailored reports with exceptions and actions.
Practice questions from Governance
- A bank's board approves a credit risk appetite statement and a credit policy. Which responsibility is most appropriately retained by the boa…
- A bank's credit portfolio manager approves a new large corporate loan, and the business unit that originated it owns the resulting credit ri…
- A bank's board risk committee receives a quarterly credit report. Which of the following reporting features would best support effective boa…
- In a bank using the three lines model, a relationship manager's bonus is based mainly on loan volume originated, and the credit approval uni…
- A bank's board wants to strengthen risk culture. Which action most directly reinforces the 'tone from the top' in a credit risk context?
Credit Risk Reporting, Monitoring and Model Governance: frequently asked questions
What is the difference between model validation and model governance?
Validation is the technical testing of a model's design, performance and use. Governance is the framework of policies, roles, approvals and oversight around all models. Validation is one key control inside governance.
What does SR 11-7 require for credit models?
It sets supervisory expectations for model risk management in US banks. Key ideas are sound development and use, independent validation, effective challenge and board and senior management oversight. FRM tests these ideas, not exact wording.
How do you validate an internal rating system under Basel?
You test discriminatory power, calibration against realized defaults, stability and data quality, and review the rating process and use. Banks must also document the system and have it reviewed independently.
What should a credit risk report to the board contain?
It should show portfolio risk against appetite, concentrations, rating migration, limit breaches, loss trends and actions taken. It should be concise, accurate and timely rather than overloaded with detail.