Skip to content

FRM Part II · FRM Exam Part II · Supervisory Guidance on Model Risk Management

A bank licenses a credit scoring model from an external vendor. The vendor refuses to disclose source code, citing intellectual property. Under supervisory guidance on model risk management (SR 11-7), what is the most appropriate expectation for the bank?

The bank remains responsible for vendor models. It should obtain developmental evidence from the vendor and validate as far as possible through ongoing monitoring, benchmarking and outcomes analysis, rather than relying only on the vendor's report or excluding the model from inventory.

  1. ARely on the vendor's validation report alone, since the bank cannot access the code
  2. BExempt the model from the bank's model inventory because it is externally developed
  3. CValidate the model to the extent possible, using ongoing monitoring, benchmarking and outcomes analysis, and obtain developmental evidence from the vendorCorrect
  4. DReplace the model with an internally built model because vendor models cannot be used

Explanation

Guidance states that vendor models must still be validated by the bank, and that the bank should require the vendor to provide developmental evidence, testing results and documentation. Where code is proprietary, the bank should lean on benchmarking, sensitivity analysis and outcomes analysis. Relying solely on the vendor's report delegates accountability, which is not acceptable.

Did you get it right without looking?

One question tells you little. A timed set on Supervisory Guidance on Model Risk Management shows your real accuracy, how long you take and where you lose marks.

More Supervisory Guidance on Model Risk Management questions