Skip to content

FRM Exam Part II · Supervisory Guidance on Model Risk Management

Model Risk Definition and Sources Under SR 11-7

Updated 11 October 2026 · Fact-checked

SR 11-7 defines a model as a quantitative method, system or approach that applies statistical, economic, financial or mathematical theories to turn input data into quantitative estimates. Model risk is the potential for adverse consequences from decisions based on incorrect or misused model outputs. It arises from fundamental errors in design or implementation, or from inappropriate use.

Understand Model Risk Definition and Sources (SR 11-7)

Start with the definition of a model. In SR 11-7 (the US Federal Reserve and OCC supervisory guidance on model risk management), a model is a quantitative method, system or approach. It applies statistical, economic, financial or mathematical theories, techniques and assumptions to process input data into quantitative estimates. Three parts make up a model: an input component, a processing component and a reporting component that turns results into useful business information.

Model risk is the potential for adverse consequences from decisions based on incorrect or misused model outputs and reports. Adverse consequences include financial loss, poor business or strategic decisions, damage to reputation and regulatory problems. The guidance treats this as a risk to be managed, just like credit or market risk. It is not just a technical nuisance.

SR 11-7 says model risk arises from two main sources. The first is fundamental errors: the model may have errors at any point from design through implementation, and so produces inaccurate outputs when viewed against its design objective and intended business use. Examples are wrong assumptions, poor data, coding bugs or wrong mathematics. The second is incorrect or inappropriate use: a model may be sound but applied outside the purpose, population or conditions it was built for. Using a model built for one portfolio on a different portfolio, or in a market regime it never saw, is misuse.

The guidance also notes that model risk grows with greater model complexity, higher uncertainty about inputs and assumptions, broader use, and larger potential impact. That is why it says risk should be managed by developing sound models, validating them, and using governance and controls. It also stresses that model risk cannot be eliminated, only managed, and that there is no substitute for effective challenge by informed, independent and competent people.

The definition of a model is wide. It also covers quantitative approaches whose inputs are partly qualitative or based on expert judgment, as long as the output is quantitative. It also stresses that a model is a simplified representation of reality, so some error is built in.

Key formulas to remember

Definition of a model (SR 11-7)
Model = inputs → processing (theory and assumptions) → quantitative estimates → reports
Three components: input, processing and reporting. The output must be a quantitative estimate.
Definition of model risk
Model risk = potential adverse consequences from decisions based on incorrect or misused model outputs
Consequences include financial loss, poor decisions and reputational damage.
Two sources of model risk
Model risk = fundamental errors (design, implementation) + inappropriate use
Error means the model is wrong for its stated purpose. Misuse means a sound model is applied wrongly.
Drivers of the level of model risk
Higher complexity, input uncertainty, breadth of use and impact → higher model risk
Used to decide how much validation and control effort a model needs.

How to solve Model Risk Definition and Sources (SR 11-7) questions

Use this method for any question that asks you to classify a situation, define a term or choose the source of model risk.

  1. 1Check whether the item is a model: does it use theory and assumptions to turn inputs into a quantitative estimate? If not, it may not be in scope.
  2. 2Identify the intended purpose and business use of the model. Model risk is always judged against these.
  3. 3Ask whether the model itself is flawed: wrong assumptions, bad data, coding or implementation errors, mathematics. If yes, this is a fundamental error.
  4. 4Ask whether a sound model is being applied outside its design: new product, new population, new market regime, or ignoring known limits. If yes, this is inappropriate use.
  5. 5Identify the adverse consequence: loss, poor decision, reputation or regulatory impact.
  6. 6Link the answer to the drivers: complexity, uncertainty, breadth of use and impact.
  7. 7Pick the option that matches SR 11-7 wording, and reject options that claim model risk can be eliminated or that only the developer is responsible.

Quickest way: Error or misuse in two questions

When to use it: Use when time is short and the question asks you to classify the cause of a model failure.

  1. Ask: was the model wrong for what it was designed to do? If yes, choose fundamental error (design or implementation).
  2. Ask: was the model right for its design but used for something else? If yes, choose inappropriate use.
  3. If both appear, name the one that the question asks about, and remember both lead to the same adverse consequences.

Common mistakes in Model Risk Definition and Sources (SR 11-7)

  • Saying model risk comes only from coding or mathematical errors.

    Students picture model risk as a technical defect.

    Fix: Remember the second source: a correct model used inappropriately also creates model risk.

  • Treating misuse as the same as error.

    Both lead to bad outputs, so they blur together.

    Fix: Error is a flaw in the model against its design objective. Misuse is applying it outside its intended purpose or conditions.

  • Assuming a spreadsheet or simple calculation is never a model.

    Students link models only with complex software.

    Fix: If it applies assumptions to inputs to produce a quantitative estimate, it can fall in scope, whatever the complexity.

  • Believing model risk can be eliminated by good validation.

    Validation sounds like a complete fix.

    Fix: SR 11-7 says model risk is managed, not removed. Models are simplifications, so some risk always remains.

  • Forgetting the reporting component of a model.

    Focus is on inputs and calculations.

    Fix: Recall all three components: input, processing and reporting. Weak reporting can lead to misuse of correct results.

  • Thinking only quantitative inputs count.

    The word quantitative is read as numeric inputs only.

    Fix: The output must be quantitative. Inputs can include qualitative information or expert judgment.

Worked examples

Example 1

A bank builds a retail credit scoring model on prime mortgage borrowers. The code and mathematics are correct and were tested against its design. Management then applies the same model to approve subprime auto loans. Losses are much higher than predicted. Which source of model risk best describes this?

Show the solution
  1. Check the model: the code and mathematics are correct against design, so there is no fundamental error in design or implementation.
  2. Check the use: the model was built for prime mortgage borrowers and is applied to subprime auto loans, a different population and product.
  3. This is application outside the intended purpose, so it is inappropriate use.
  4. The adverse consequence is loss from decisions based on misused model outputs, which matches the model risk definition.

Answer: Inappropriate use (model misuse), not a fundamental model error.

Example 2

A risk team uses a VaR model for a trading desk. Review finds that the model feeds the wrong sign of a sensitivity into the aggregation step, so the VaR is understated. The model is used only for the desk it was designed for. Is this model error or misuse, and which SR 11-7 component is affected?

Show the solution
  1. The model is applied to its intended desk, so the use is appropriate.
  2. The wrong sign is an implementation defect in the processing step, since it corrupts the calculation.
  3. A flaw in implementation against design objective is a fundamental error.
  4. The understated VaR can lead to decisions based on incorrect outputs, which is the adverse consequence in the definition.

Answer: Fundamental error from implementation, in the processing component. It is not misuse.

Exam tips

  • Expect short scenario questions that ask you to label a failure as error or misuse. Decide using design purpose versus actual use.
  • Learn the SR 11-7 wording: a model is a quantitative method that turns input data into quantitative estimates, and model risk comes from incorrect or misused outputs.
  • Reject options saying model risk can be eliminated or that it is only a developer issue.
  • Remember the drivers: complexity, input uncertainty, breadth of use and potential impact. They set how much control a model needs.
  • Watch for options that confuse model risk with market or credit risk. Model risk is about the decision made from the output.

Practice questions from Supervisory Guidance on Model Risk Management

Model Risk Definition and Sources (SR 11-7): frequently asked questions

How does SR 11-7 define a model?

A model is a quantitative method, system or approach that applies statistical, economic, financial or mathematical theories, techniques and assumptions to process input data into quantitative estimates. It has input, processing and reporting components.

What is the difference between model error and model misuse?

Model error is a flaw in the model, such as a wrong assumption or coding bug, so it fails its design objective. Misuse is applying a sound model to a purpose, population or condition it was not built for. Both can cause the same adverse consequences.

Can model risk be eliminated?

No. SR 11-7 treats it as a risk to be managed through sound development, validation, governance and controls. Models are simplified representations of reality, so some risk always remains.

What increases model risk?

Greater complexity, more uncertainty about inputs and assumptions, broader use and larger potential impact all raise it. Higher model risk calls for stronger validation and oversight.