Skip to content

FRM Part II · FRM Exam Part II · Supervisory Guidance on Model Risk Management

A bank buys a proprietary credit-scoring model from an external vendor. The vendor declines to disclose the source code, citing intellectual property. Under supervisory guidance on model risk management (SR 11-7), what is the most appropriate expectation of the bank?

The bank should still validate the vendor model as far as it can, using vendor developmental evidence, outcomes analysis, benchmarking and monitoring, plus contingency plans. Vendor opacity does not transfer responsibility, so the bank cannot simply rely on the vendor's own validation or leave the model out of its inventory.

  1. AAccept the vendor's validation report in place of any internal validation, since the bank cannot inspect the code
  2. BExclude the model from the model inventory because the bank does not own it
  3. CValidate the model as far as possible, using developmental evidence from the vendor, outcomes analysis, and benchmarking, and put in place contingency plansCorrect
  4. DRestrict the model to use only in non-material decisions regardless of its performance

Explanation

Supervisory guidance expects banks to validate vendor models as thoroughly as feasible even when the code is a black box. This means obtaining developmental evidence, running ongoing monitoring, outcomes analysis and benchmarking, and having contingency plans. Relying only on the vendor's report is wrong because the bank remains responsible for model risk.

Did you get it right without looking?

One question tells you little. A timed set on Supervisory Guidance on Model Risk Management shows your real accuracy, how long you take and where you lose marks.

More Supervisory Guidance on Model Risk Management questions