Skip to content

FRM Exam Part II · Supervisory Guidance on Model Risk Management

Vendor Models and Model Risk Aggregation under SR 11-7

Updated 11 October 2026 · Fact-checked

Under SR 11-7, a vendor model is a model, so the bank must validate it, monitor it and own the risk, even when the vendor keeps the code secret. Aggregation means combining model inventory, tiering, validation findings and limitations into one firm-wide report for senior management and the board.

Understand Vendor Models and Model Risk Aggregation

A model is a quantitative method that turns inputs into estimates. SR 11-7 says model risk is the chance of adverse consequences from decisions based on incorrect or misused model outputs. It comes from two places: fundamental errors in the model, and incorrect or inappropriate use.

A vendor model is built by a third party, such as a pricing library, credit scoring engine or VaR system. The bank cannot always see the code or the exact methods, because they are proprietary. But SR 11-7 does not relax its standards. Using a vendor model does not transfer the model risk. The bank is still responsible for it.

Because the bank cannot fully open the black box, it leans on other tools. These include developmental evidence from the vendor, testing with the bank's own data, benchmarking against other models, sensitivity analysis, outcomes analysis and ongoing monitoring. It also needs contingency plans if the vendor changes the model, withdraws it or fails. Contracts should allow access to enough documentation and testing information. Vendor changes must be tracked, and the bank should customise or calibrate the model to its own portfolio and use.

A firm has many models, so risk must be seen as a whole. The bank keeps a model inventory listing every model, including vendor models, with owner, purpose, status and validation date. Models are tiered by materiality and complexity: how much exposure depends on them, how important the decisions are, and how uncertain the outputs are. Higher tiers get deeper and more frequent validation.

Aggregate reporting then gives the board and senior management a firm-wide view. It covers inventory size, tier mix, overdue validations, open findings, known limitations, use of overlays or adjustments, and the models that matter most. SR 11-7 stresses that aggregate model risk depends on interaction and dependencies between models, and on the common assumptions and data they share. Simply adding up individual model scores is not enough.

Key formulas to remember

Model risk (SR 11-7)
Model risk = risk of adverse consequences from decisions based on incorrect or misused model outputs
Two sources: fundamental errors, and incorrect or inappropriate use.
Vendor model principle
Vendor model = same SR 11-7 standards as an in-house model
Responsibility cannot be outsourced. The bank must understand, validate and monitor the model.
Materiality-based tiering (rule of thumb)
Tier ↑ as exposure, decision importance and model uncertainty ↑
Higher tier means more frequent, deeper validation and tighter oversight. SR 11-7 requires a risk-based approach but does not set fixed tiers.
Aggregate view
Aggregate model risk ≠ simple sum of individual model risks
Consider shared inputs, assumptions and dependencies between models, and offsetting or compounding errors.

How to solve Vendor Models and Model Risk Aggregation questions

Use this sequence for any scenario on vendor models or aggregate model risk.

  1. 1Identify whether the model is in-house or vendor, and what decision it supports.
  2. 2Apply the principle that SR 11-7 expectations are the same for vendor models; the bank owns the risk.
  3. 3List the available validation tools given limited transparency: vendor evidence, own-data testing, benchmarking, sensitivity analysis, outcomes analysis, monitoring.
  4. 4Check governance items: inventory entry, owner, documented use, change control, contract rights to information, contingency plan.
  5. 5Judge materiality and complexity to assign or test the tier and the validation frequency.
  6. 6For aggregation, ask what the board needs: inventory, tier mix, overdue validations, open findings, limitations, shared assumptions.
  7. 7Match the answer to the option that keeps accountability with the bank and uses a risk-based approach.

Quickest way: Three-question filter

When to use it: When time is short and options look similar.

  1. Does the option let the bank escape responsibility because the model is from a vendor? If yes, reject it.
  2. Does it apply validation proportionate to materiality? Prefer that over uniform or minimal treatment.
  3. For reporting, does it give firm-wide, decision-useful information, including limitations and dependencies? Prefer that over a raw count or sum.

Common mistakes in Vendor Models and Model Risk Aggregation

  • Thinking vendor validation replaces the bank's own validation.

    The vendor supplies a thick validation pack, so it feels sufficient.

    Fix: Vendor evidence is an input only. The bank must still test on its own data, portfolio and use.

  • Saying proprietary code means a vendor model is exempt from SR 11-7.

    Students confuse limited transparency with limited responsibility.

    Fix: Opacity increases the need for outcomes analysis, benchmarking, sensitivity tests and contingency plans.

  • Tiering only by model complexity.

    Complex models look riskiest.

    Fix: Tier by materiality and complexity together. A simple model driving large exposures can be high tier.

  • Treating aggregate model risk as the sum of individual scores.

    Adding numbers feels rigorous.

    Fix: Consider interactions, common data and assumptions, and concentration on a single vendor.

  • Forgetting ongoing monitoring after approval.

    Validation seems like a one-time event.

    Fix: Vendor updates, data drift and changed use require continued monitoring and revalidation.

Worked examples

Example 1

A bank licenses a vendor credit scoring model. The vendor refuses to disclose the source code and offers a summary validation report. Which approach best meets SR 11-7? A) Rely on the vendor report because the code is proprietary. B) Exempt the model from validation and track it only in procurement records. C) Validate with the bank's own data, benchmark it, run sensitivity and outcomes analysis, and monitor it ongoing. D) Replace it with an in-house model immediately.

Show the solution
  1. Principle: vendor models are held to the same SR 11-7 standards, and the bank owns the risk.
  2. A relies fully on vendor evidence and is insufficient. B ignores validation. D is not required by SR 11-7 and is unnecessary.
  3. C uses tools that work despite limited transparency: own-data testing, benchmarking, sensitivity and outcomes analysis, plus monitoring.

Answer: C

Example 2

A risk committee receives a model risk report that only states 240 models in the inventory and 12 overdue validations. The chief risk officer wants the report to reflect aggregate model risk properly. What should be added?

Show the solution
  1. The report gives counts but no materiality context.
  2. Add the tier mix and which high-tier models are overdue or have open findings.
  3. Add known limitations, overlays and the main shared data and assumptions across models, including reliance on specific vendors.
  4. Add the effect on key decisions, so management can judge exposure, not only numbers.
  5. State that this is a judgement-based view, not a simple sum of scores.

Answer: Add tiering, open findings on material models, limitations and adjustments, and dependencies such as shared assumptions and vendor concentration, so the board sees firm-wide model risk rather than a count.

Exam tips

  • Whenever a vendor is mentioned, test each option against 'the bank retains responsibility'.
  • Expect options that over-rely on vendor reports or on proprietary-code exemptions; these are usually wrong.
  • Link tiering to materiality and complexity, and validation intensity to tier.
  • For aggregation questions, choose answers with firm-wide, decision-useful content and dependencies.
  • Watch for words like 'only' and 'always'; SR 11-7 is principles-based and risk-based.

Practice questions from Supervisory Guidance on Model Risk Management

Vendor Models and Model Risk Aggregation: frequently asked questions

Does SR 11-7 apply to vendor models?

Yes. It expects the bank to manage vendor models with the same rigour as internal ones. The bank cannot hand model risk to the vendor.

How do you validate a vendor model when you cannot see the code?

Use the vendor's developmental evidence, then test with your own data, benchmark against alternatives, run sensitivity and outcomes analysis, and monitor continuously. Contracts should secure information and change notices, and you need a contingency plan.

What is model risk tiering?

It ranks models by materiality and complexity so validation effort matches risk. Higher-tier models get deeper and more frequent validation and closer oversight.

What should aggregate model risk reporting include?

It should include the inventory, tier mix, overdue validations, open findings, known limitations, adjustments, and dependencies between models. The aim is to let senior management and the board judge firm-wide exposure.