FRM Exam Part II · Supervisory Guidance on Model Risk Management
Model Validation and Effective Challenge Under SR 11-7
Updated 11 October 2026 · Fact-checked
Model validation is an independent check that a model is sound, performs as intended and is used properly. SR 11-7 builds it on three parts: evaluation of conceptual soundness, ongoing monitoring, and outcomes analysis including back-testing. Effective challenge is the critical review by competent, independent, influential people who can force changes.
Understand Model Validation and Effective Challenge
A model is a quantitative method that turns inputs into estimates. Model risk is the chance of loss or poor decisions because a model is wrong or misused. SR 11-7 treats validation as the main control against it.
Validation is the set of activities that check a model does what it should. SR 11-7 groups it into three core elements:
- Evaluation of conceptual soundness: Is the design, theory, data and assumptions sensible? You review documentation, the developmental evidence, the choice of variables and methods, and test assumptions and limitations. Sensitivity analysis and comparison with alternative approaches support this.
- Ongoing monitoring: Does the model still work after implementation? You check that it is appropriately used, that inputs and the environment have not drifted, and that parameters and processes are sound. Benchmarking against other models sits here.
- Outcomes analysis: Do model outputs match actual results? Back-testing is one form: it compares forecasts with realised outcomes over time. Other forms include comparing against benchmarks and analysing overrides.
Effective challenge is the guiding principle. It means critical analysis by objective, informed people who can identify model limits and assumptions and who have the incentives, competence and influence to get issues fixed. Independence from model development and use matters, and so does the standing to escalate. A validator who is outranked or lacks expertise gives only a weak challenge.
Validation is not a one-off. SR 11-7 expects it before use and then periodically, with the frequency set by the model's risk. It expects more frequent review when conditions change materially. Validation should be done by staff not responsible for development or use, and with enough authority. Where the model is a vendor product, the bank still validates it as far as it can.
Key formulas to remember
- Three core elements of validation (SR 11-7)
- Validation = conceptual soundness + ongoing monitoring + outcomes analysis
- Back-testing belongs to outcomes analysis. Benchmarking is used in ongoing monitoring and outcomes analysis.
- Effective challenge requirements
- Competence + independence + influence (incentives and standing)
- All three are needed. Challenge can come from validators, internal audit or other informed staff.
- Back-test comparison
- Forecast vs realised outcome over time
- Tests accuracy against what actually happened. Benchmarking instead compares against another model.
- Validation frequency
- Periodic, risk-based, plus event-driven review
- SR 11-7 gives no fixed interval. Higher risk and material change mean more frequent review.
How to solve Model Validation and Effective Challenge questions
Use this method for any question on validation or effective challenge.
- 1Identify what the question describes: design review, post-implementation checking, or comparison of outputs with results.
- 2Map it to the element: conceptual soundness, ongoing monitoring or outcomes analysis.
- 3Separate back-testing (vs realised outcomes) from benchmarking (vs another model or estimate).
- 4For governance questions, test the three effective challenge traits: competence, independence, influence.
- 5Check who performs the work: independent of development and use.
- 6For frequency, tie it to model risk and material changes, not a fixed number of years.
- 7Eliminate options that say validation is only done once, only by developers, or only statistical.
Quickest way: Match the activity to the element
When to use it: Short scenario MCQs where one activity is described and you must label it.
- Look for the key verb: reviews theory or assumptions means conceptual soundness.
- Tracks inputs, drift or use after go-live means ongoing monitoring.
- Compares forecasts with actuals means outcomes analysis or back-testing.
- Compares with another model means benchmarking.
- If governance appears, pick the answer with independence, competence and authority to escalate.
Common mistakes in Model Validation and Effective Challenge
Treating back-testing and benchmarking as the same
Both compare model output with something.
Fix: Back-testing compares to realised outcomes. Benchmarking compares to another model or estimate.
Saying validation is only statistical testing
Candidates focus on back-test numbers.
Fix: Conceptual soundness review of theory, data and assumptions is a core element, not optional.
Assuming validators must be a separate department
Independence is confused with organisational structure.
Fix: What matters is independence from development and use, with competence and influence. Structure can vary.
Quoting a fixed validation interval
Students want a number.
Fix: SR 11-7 is risk-based: periodic review plus earlier review when conditions change materially.
Thinking a good back-test proves the model is sound
Outcomes are seen as the final proof.
Fix: Back-tests have limited power and a model can pass for the wrong reasons. Use all three elements together.
Worked examples
Example 1
A validator checks whether a bank's credit scoring model uses sensible variables, reviews its documentation and tests its assumptions. Which element of validation is this, and why?
Show the solution
- The work is about design, theory, data and assumptions.
- It does not compare outputs with actual results or monitor performance after go-live.
- This matches evaluation of conceptual soundness.
Answer: Evaluation of conceptual soundness, because it reviews the model's design, variables, documentation and assumptions.
Example 2
A risk team compares its VaR model's one-day forecasts with actual trading P&L over the past year and also with forecasts from a simpler alternative model. Classify each comparison.
Show the solution
- Comparing forecasts with actual P&L uses realised outcomes. This is outcomes analysis, specifically back-testing.
- Comparing with a simpler alternative model uses another estimate, not realised outcomes. This is benchmarking.
- Both help validation, but they answer different questions: accuracy against reality versus consistency with an alternative.
Answer: Comparison with actual P&L is back-testing (outcomes analysis). Comparison with the alternative model is benchmarking.
Exam tips
- Know the three elements by name and be able to place any described activity in one of them.
- Questions often hinge on back-testing versus benchmarking. Check what the comparison is against.
- For effective challenge, expect answers listing independence, competence and influence. Weak answers drop one.
- Avoid answers with fixed validation frequencies. The correct framing is risk-based and event-driven.
Practice questions from Supervisory Guidance on Model Risk Management
- A developer selects a model's input data for a mortgage prepayment model and finds that the available history covers only a low-rate period.…
- Under the supervisory guidance on model risk management (SR 11-7), which of the following best describes the definition of a 'model'?
- Which element is most important for a bank's model inventory to support aggregate model risk management that includes vendor models?
- Under the supervisory guidance on model risk management (SR 11-7), which of the following best describes the primary source from which model…
- Under supervisory guidance, a bank's model outputs are routinely overridden by loan officers. What is the most appropriate management respon…
Model Validation and Effective Challenge: frequently asked questions
What is effective challenge in SR 11-7?
It is critical analysis of a model by objective, informed people who can identify its limits and assumptions. They must have the competence, independence and influence to get issues addressed.
What is the difference between back-testing and benchmarking?
Back-testing compares model forecasts with realised outcomes. Benchmarking compares model outputs with those of another model or estimate. Both support validation but test different things.
How often should models be validated?
SR 11-7 does not set a fixed interval. Validation occurs before use and then periodically, with frequency based on model risk. It should also be repeated when material changes occur.
What does conceptual soundness review involve?
It assesses the quality of model design and construction. You review documentation, data, variables, methods and assumptions, and use tests such as sensitivity analysis to understand limitations.