Skip to content

FRM Exam Part II · Supervisory Guidance on Model Risk Management

Model Risk Governance, Policies and Controls under SR 11-7

Updated 11 October 2026 · Fact-checked

Model risk governance is the framework that sets who owns model risk and how it is controlled. Under SR 11-7, the board sets risk appetite and oversight, senior management implements policies, and internal audit checks the process. Policies, a complete model inventory and documentation let a third party understand each model.

Understand Governance, Policies and Controls

A model is a quantitative method that turns inputs into estimates. Model risk is the chance of adverse consequences from decisions based on models that are wrong or misused. SR 11-7 (the US Federal Reserve and OCC supervisory guidance) names two causes: fundamental errors in the model, and incorrect or inappropriate use.

Model risk cannot be removed. It is managed like other risks: with clear ownership, written rules and independent checks. Governance is the layer that makes the other parts of model risk management (development, validation, use) work together.

The board of directors sets the bank's overall risk appetite for model risk and ensures the framework is in place. It does not review individual models. It expects regular reports and makes sure resources and authority are adequate. Senior management carries out the board's direction. It establishes policies and procedures, assigns responsibilities, ensures compliance, and creates a strong validation function with real authority. It also reports to the board on the overall level of model risk.

Controls sit around the models. Policies define what counts as a model, standards for development, validation and use, and the roles involved. A model inventory lists all models in use or under development, including vendor models. For each it records purpose, products and uses, owner, developer, validation status, limitations and usage restrictions. Documentation must be detailed enough that an informed third party can understand how the model works, its assumptions and its limits.

Internal audit is the independent third check. It does not validate models. It assesses whether the whole model risk framework, including validation, is working as designed, and whether staff follow policy. In a three lines of defense view, model owners and developers are first line, independent model risk management and validation sit in the second line, and internal audit is the third line. Staff and incentives matter too: validators need competence, influence and independence from model development.

Key formulas to remember

Model risk definition (SR 11-7)
Model risk = adverse consequences from decisions based on incorrect or misused model outputs
Two sources: fundamental errors in the model, and incorrect or inappropriate use.
Board responsibility
Board = sets risk appetite + ensures framework + reviews reports
Board does not validate or approve every model.
Senior management responsibility
Senior management = policies + procedures + roles + compliance + validation resources + reporting to board
Day-to-day implementation of the framework.
Internal audit responsibility
Internal audit = independent assessment of the whole framework, including validation activity
Checks that validation is done and policies are followed; does not replace validation.
Model inventory content
Inventory = all models (incl. vendor) + purpose + owner + developer + validation status + limitations + uses
Must be comprehensive and kept current.
Documentation standard
Documentation detailed enough for an informed third party to understand the model
Covers theory, assumptions, data, limitations and testing.

How to solve Governance, Policies and Controls questions

Governance questions are about assigning the right task to the right party. Use the same sorting approach each time.

  1. 1Read the scenario and identify the failing or described activity: oversight, policy setting, development, validation, use, or independent review.
  2. 2Match it to a role: board (appetite, oversight), senior management (policies, resources, reporting), model owner or developer (first line), validation (independent challenge), internal audit (framework review).
  3. 3Check independence: the person reviewing must not be the one building or using the model for the same decision.
  4. 4If the question concerns inventory or documentation, test the option against completeness: all models, vendor models included, with owner, purpose, status and limitations.
  5. 5Look for scope words such as 'all', 'only' and 'individual'. The board does not approve each model; audit does not validate.
  6. 6Eliminate options that put a task with the wrong party, then pick the answer that matches SR 11-7 wording.
  7. 7Confirm the answer addresses the root cause, which is usually weak ownership, weak challenge or incomplete records.

Quickest way: Role-matching shortcut

When to use it: Use when the question asks who is responsible for something or what a governance gap is.

  1. Board = appetite and oversight. Senior management = policies and implementation. Audit = independent check of the framework.
  2. Ask: is the task about setting direction, doing, challenging, or checking the checkers?
  3. Reject any option where audit validates models or the board reviews individual models.
  4. If the issue is missing models in a list, answer inventory; if a new analyst cannot understand a model, answer documentation.

Common mistakes in Governance, Policies and Controls

  • Saying internal audit validates models

    Both are 'independent' functions, so they get blended.

    Fix: Validation challenges the model. Audit evaluates whether the validation process and wider framework work and are followed.

  • Giving the board a hands-on role in approving each model

    Students think top accountability means top involvement.

    Fix: The board sets appetite, ensures the framework and reviews reports. Senior management handles detailed implementation.

  • Leaving vendor models out of the inventory

    Students link inventory to models built in-house.

    Fix: Inventory covers all models in use or development, including vendor and third-party models.

  • Treating documentation as optional if validation is strong

    Validation feels like the real control.

    Fix: Without adequate documentation validation, continuity and audit become unreliable. Documentation must let an informed third party understand the model.

  • Placing model developers in the second line

    Mixing up technical and control roles.

    Fix: Owners and developers are first line. Independent model risk management and validation are second line. Audit is third.

  • Assuming strong models remove the need for governance

    Focus on accuracy over use and oversight.

    Fix: Model risk also arises from misuse, so governance, limits and monitoring are always required.

Worked examples

Example 1

A bank's board receives no report on model performance, and models are used without written standards. Which action by senior management best addresses the gap?
A) Have the board validate each model
B) Establish model risk policies and procedures and regular reporting to the board
C) Ask internal audit to redevelop the models
D) Remove vendor models from use

Show the solution
  1. Identify the gap: no written standards (policies) and no board reporting.
  2. Senior management is responsible for establishing policies and procedures and reporting overall model risk to the board.
  3. A fails because the board does not validate individual models.
  4. C fails because audit is independent and does not build models.
  5. D is not a response to the gap described.

Answer: B

Example 2

During an inspection, a supervisor finds that a bank's inventory lists only internally developed models, and one vendor credit scoring model has no known owner. Which is the most accurate conclusion?
A) The inventory is deficient because it must include all models, including vendor models, with owners and status
B) The inventory is acceptable because vendor models are validated by the vendor
C) The inventory is deficient only if the vendor model is large
D) Internal audit should own the vendor model

Show the solution
  1. Recall the inventory standard: all models in use or development, including vendor models.
  2. Each entry should record owner, purpose, validation status and limitations.
  3. Vendor validation does not remove the bank's responsibility, so B is wrong.
  4. Size is not a stated condition, so C is wrong.
  5. Audit is independent and should not own models, so D is wrong.

Answer: A

Exam tips

  • Expect role-assignment MCQs: practise sorting tasks among board, senior management, validation and audit.
  • Watch for distractors that give audit or the board an operational task.
  • Remember vendor models are inside the inventory and the policy scope.
  • Link governance failures to the case studies: weak challenge and oversight, not just wrong maths.
  • Use the three lines of defense language when the stem mentions first, second or third line.

Practice questions from Supervisory Guidance on Model Risk Management

Governance, Policies and Controls in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Governance, Policies and Controls: frequently asked questions

What does SR 11-7 require the board to do?

The board sets the bank's risk appetite for model risk and makes sure an effective framework exists. It reviews reports and ensures adequate resources and authority. It does not review each model.

What must a model inventory contain?

It should list all models in use or under development, including vendor models. Records typically cover purpose, owner, developer, validation status, limitations and usage restrictions. It must be kept up to date.

How does internal audit differ from model validation?

Validation is an independent challenge of a specific model. Internal audit assesses whether the overall framework, including validation, works as designed and is followed. Audit sits in the third line.

Why is documentation emphasised?

Good documentation lets an informed third party understand the model's design, assumptions and limits. It supports validation, continuity when staff leave, and audit review.