0% found this document useful (0 votes)
4 views7 pages

How Ai Changing Model Risk Management

This document discusses how AI is transforming Model Risk Management (MRM) in financial institutions, emphasizing the need for a shift from traditional frameworks to dynamic, risk-based practices. It highlights the complexities of AI, such as unstructured data and continuous model evolution, necessitating enhanced governance, validation, and monitoring tailored to AI-specific risks. The paper advocates for a tiered approach to governance and validation that aligns with regulatory expectations and promotes efficient AI adoption while managing associated risks.

Uploaded by

iyad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views7 pages

How Ai Changing Model Risk Management

This document discusses how AI is transforming Model Risk Management (MRM) in financial institutions, emphasizing the need for a shift from traditional frameworks to dynamic, risk-based practices. It highlights the complexities of AI, such as unstructured data and continuous model evolution, necessitating enhanced governance, validation, and monitoring tailored to AI-specific risks. The paper advocates for a tiered approach to governance and validation that aligns with regulatory expectations and promotes efficient AI adoption while managing associated risks.

Uploaded by

iyad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

How AI is changing

model risk
management

[Link]
Executive Summary
This paper is the first in a multi‑part series. outcome‑focused controls that right‑size validation
Upcoming papers will dive deeper into and monitoring, manage frequent retraining
classification, risk tiering, independent validation, updates, and integrate third‑party oversight while
continuous monitoring, change management enabling AI adoption.
for fine‑tuned models, retrieval‑augmented Not all AI tools are models. Treating every AI use
generation (RAG), and third‑party AI (Artificial case as a model over‑governs, inflates cost, and
Intelligence) oversight—providing practical tools to creates bottlenecks. Institutions must classify
help you scale AI responsibly and cost‑effectively. AI functions, separate decisioning models from
As AI adoption accelerates, Model Risk must assistive tools, and tier risk so heavy governance
adapt to AI’s unique factors: opaque mechanisms, is reserved for high‑impact, high‑risk decisions.
unstructured inputs, dynamic behavior, and This tiered approach cuts time‑to‑value, reduces
continual change. Institutions must move from control cost, and enables safe scale—while
periodic, checklist reviews to dynamic, risk‑based, meeting evolving regulatory expectations.

Traditional MRM Frameworks are Insufficient to


Address AI Risks
Applying traditional Model Risk principles to AI
systems becomes significantly more complex—
and in some cases infeasible—because these
systems process unstructured data, adapt
behavior over time, rely on mechanisms that resist
traditional explanation, and can have a nearly
infinite number of uses. Traditional frameworks
were built for statistical and econometric models:
mostly parametric, interpretable via coefficients
and clear causal structures, enabling human
challenge. Related regulatory guidance has
emphasized conceptual soundness, data quality,
methodological rigor, diagnostic testing, outcomes
evaluation, and ongoing performance monitoring.
For AI, those assumptions break. Post‑hoc
explainability replaces direct interpretability;
continuous drift detection replaces static
monitoring; and frequent retraining and data
refreshes make change management central.
Utilizing traditional frameworks and timelines for
AI can be costly and slow, turning Model Risk into
a bottleneck to AI development and use.

1 How AI is Changing Model Risk Management

© 2026 KPMG LLP, a Delaware limited liability partnership, and its subsidiaries are part of the KPMG global organization of independent member
firms affiliated with KPMG International Limited, a private English company limited by guarantee. All rights reserved. USCS035344-1A
Transforming Model Risk Management Practices
Model Risk for AI requires a practical shift
from predominantly point‑in‑time controls to
Development
continuous, risk‑based practices across four AI development is inherently different than
pillars: governance, development, validation, traditional statistical modeling. It often
and monitoring. Financial institutions need to leverages advanced ML and deep learning, uses
update these pillars to address AI‑specific risks unstructured data (text, images, audio), and
(e.g., bias, explainability, and model drift) and to depends on multiple abstraction layers and large
strengthen oversight of third‑party AI so models datasets for pattern recognition. Development
remain accurate, reliable, and compliant as they should confront three realities: complexity and
evolve. The goal is outcome‑focused control that opacity, data quality and bias, and accuracy in
right‑sizes effort by risk tier, reduces manual dynamic environments.2
overhead, and shortens cycle time—managing risk
A disciplined, efficient development process
without over‑engineering.
emphasizes reproducibility, gated promotion, and
secure operational practices: model registries with
Risk Based Governance versioning; reproducible pipelines; canary releases
AI models necessitate governance that is and rollback criteria; immutable audit trails; and
transparent, accountable, and calibrated to risk. An change classification (material vs. immaterial).
effective approach starts with clear definitions and Data governance must enforce lineage, consent,
taxonomy: distinguish AI models from traditional usage restrictions, proxy detection for protected
models, categorize by functionality (e.g., tabular classes, and policy for synthetic data. Robustness
ML, NLP/LLMs, RAG, computer vision), potential and safety testing—covering adversarial resilience,
impact, data types, and associated risks. Not all prompt‑injection resistance for LLMs, and content
models are AI—and not all AI is high risk—so safety filters—should be built into the pipeline.
classification drives efficiency. The aim is to reduce rework and cycle time while
improving model quality.
Risk tiering then prioritizes effort by evaluating
criteria such as operational significance, customer
impact, data sensitivity, opacity, retraining
frequency, and vendor dependency. Tiering
enables institutions to allocate resources, avoid
box‑checking, and cut time and cost.
Context matters. Use cases like credit underwriting
or fraud detection have distinct risk profiles.
Governance should align to business objectives
while safeguarding against domain‑specific risks.
Given AI’s dynamic nature, governance must
include continuous monitoring and periodic
re‑validation to detect and address behavior
changes quickly, mitigating drift through real‑time
data assessments and performance checks.1
As institutions rely more on vendor‑provided AI,
robust third‑party governance becomes critical.
Strengthen the interface between Model Risk
and Third‑Party Risk Management (TPRM)—with
TPRM as the tip of the spear. Capture AI use via
vendor attestations, upgrade due diligence, refine
contractual provisions (transparency, audit rights,
incident SLAs, change controls), and establish
continuous capability monitoring. Done well, this
reduces duplication, speeds onboarding, and
lowers oversight costs.2
How AI is Changing Model Risk Management 2

© 2026 KPMG LLP, a Delaware limited liability partnership, and its subsidiaries are part of the KPMG global organization of independent member
firms affiliated with KPMG International Limited, a private English company limited by guarantee. All rights reserved. USCS035344-1A
Validation Frameworks Ongoing Monitoring
Validation must evolve from static, checklist‑driven AI models can degrade quickly; quarterly or
reviews to outcome‑focused, right‑sized testing annual reviews won’t suffice. Monitoring should
tailored to each model’s risk tier. Enhanced be real‑time or near‑real‑time, automated, and
frameworks include: event‑driven.5 Track performance (calibration,
AUC/PR‑AUC), data quality and drift (population
• Explainability: For high‑stakes decisions,
stability, concept drift), and prediction
implement layered explainability—global
distributions. Monitor fairness by segment
(feature importance, partial dependence), local
over time and set alert thresholds. For LLM/
(SHAP/LIME), and decision narratives that
RAG, add groundedness scores, retrieval
support disclosures (e.g., adverse action). Aim
health, hallucination/toxicity rates, PII detection,
for meaningful insight sufficient for customer
latency/SLOs, and prompt/template change
and regulator understanding.
audit. Automation reduces manual effort,
• Drift and dynamic retraining: AI systems retrain shortens detection‑to‑action time, and lowers
and evolve. Establish ongoing validation operating cost.
processes with drift detection that identifies
deviations from the validated baseline. Define
retraining triggers, materiality thresholds, and
validation gates before promotion; avoid
accumulating “validation debt” that slows
delivery and increases risk.4
• LLM/RAG‑specific validation: Evaluate
faithfulness/groundedness (answers supported
by retrieved sources), hallucination rates,
toxicity and PII leakage, jailbreak/prompt‑
injection resilience. For retrieval, measure
precision/recall, MRR/nDCG, corpus coverage,
and freshness. Right‑size these tests to the
model’s impact to control cost and time.
• Bias and fairness testing: Assess outputs across
demographic groups and protected
characteristics. Select metrics that fit the
use case (e.g., equalized odds for fraud,
adverse impact ratio and demographic parity
considerations for credit), document thresholds
and trade‑offs, and reassess periodically.3
Focus on demonstrable fairness outcomes, not
exhaustive metric catalogues that add cost
without insight.

3 How AI is Changing Model Risk Management

© 2026 KPMG LLP, a Delaware limited liability partnership, and its subsidiaries are part of the KPMG global organization of independent member
firms affiliated with KPMG International Limited, a private English company limited by guarantee. All rights reserved. USCS035344-1A
Regulatory Expectations are Evolving
The regulatory landscape is shifting toward Against this backdrop, the priority for financial
principle based, risk proportional expectations institutions is to manage AI model risk effectively
rather than blanket prescriptive rules. In many and cost efficiently. That means right sizing
jurisdictions and use cases, requirements are controls to each model’s risk tier, streamlining
clarifying—and in some cases relaxing—with validation and documentation, automating
greater emphasis on demonstrable outcomes continuous monitoring, and integrating third party
such as fairness, transparency, appropriate human oversight to avoid duplication and unnecessary
oversight, and sound documentation.6 While states cost. Designing flexible, outcome driven controls
continue to advance diverse regimes, a federal positions institutions to meet current obligations
approach is evolving alongside them, and timing, today and adapt as the federal framework takes
scope, and harmonization remain uncertain.7 shape—managing risk pragmatically without
over engineering.

Strategic Implications and Future Outlook


Transforming Model Risk for AI is an organizational validation. Uplift documentation standards with
change, not a process tweak. Institutions should standardized artifacts (model cards, data cards,
recruit or outsource specialized talent (data change logs). Deploy real‑time monitoring tailored
science, ML engineering, explainability, AI ethics), to AI, and integrate cloud‑based AIOps to manage
and implement monitoring platforms, automated scale. Clarify accountabilities and decision rights;
testing frameworks, and governance workflows set risk appetite for AI; and prioritize transparency
built for dynamic AI. The objective is clear: reduce in development. Institutions that move quickly will
cycle time, cut the cost of control, and avoid take cost out, accelerate safe deployment, grow
bottlenecks that slow AI delivery. revenue, and attract more customers.
Conduct targeted assessments against AI
requirements to identify gaps in governance and

Conclusion
AI is reshaping decisioning—and Model Risk strengthen governance and independent
must keep pace. The path forward is not choosing validation to address bias, explainability, and
between traditional and AI‑enabled methods, but drift; establish continuous monitoring; and
integrating the strengths of both into risk‑based, integrate oversight of third‑party AI. Drawing on
continuous, and outcome‑focused practices. deep financial services experience and proven
Financial institutions that modernize Model tools, we build regulator‑ready operating models,
Risk will manage AI risk more effectively and documentation, and training so organizations can
cost‑efficiently, speed innovation, and strengthen scale AI responsibly while maintaining confidence
trust with customers and regulators. Those that with regulators, boards, and customers. We serve
cling to periodic, checklist‑driven control will face GSIBs, super‑regional, regional, and local banks—
growing bottlenecks and missed opportunities. and we help clients reduce control costs and
time‑to‑value while improving risk outcomes.
KPMG helps financial institutions operationalize
this evolution. We assess current practices;

How AI is Changing Model Risk Management 4

© 2026 KPMG LLP, a Delaware limited liability partnership, and its subsidiaries are part of the KPMG global organization of independent member
firms affiliated with KPMG International Limited, a private English company limited by guarantee. All rights reserved. USCS035344-1A
Sources
1
Precisely, “Opening the Black Box: Building Transparent AI Governance Frameworks” by Sue Pawlak
(August 12 2025)
2
MineOS, “AI Governance Framework: Key Principles & Best Practices” by Gal Golan (May 20, 2025)
3
Stanford Institute for Human‑Centered Artificial Intelligence, The 2025 AI Index Report (2025)
4
Databricks, “Introducing the Databricks AI Governance Framework (DAGF v1.0)” (2025)
5
National Institute of Standards and Technology (NIST), Artificial Intelligence Risk Management Framework
(AI RMF 1.0) (Report No. NIST AI 100‑1, January 2023)
6
Colorado General Assembly, “SB24‑205: Consumer Protections for Artificial Intelligence” (May 17, 2024)
7
Reuters, “US Senate strikes AI regulation ban from Trump megabill” by David Morgan & David
Shepardson (July 1, 2025)

5 How AI is Changing Model Risk Management How AI is changing model risk management 5

© 2026 KPMG LLP, a Delaware limited liability partnership, and its subsidiaries are part of the KPMG global organization of independent member
firms affiliated with KPMG International Limited, a private English company limited by guarantee. All rights reserved. USCS035344-1A
Contacts
Adam Levy Kevin Lowery
Principal Managing Director
FS Risk, Regulatory, and FS Risk, Regulatory, and
Compliance Services Compliance Services
KPMG LLP KPMG LLP
E: adamlevy@[Link] E: klowery@[Link]

Ben Harden Abigail Holden


Managing Director Managing Director
FS Risk, Regulatory, and FS Risk, Regulatory, and
Compliance Services Compliance Services
KPMG LLP KPMG LLP
E: bharden@[Link]

Kelly Combs Liming Brotcke


Managing Director Director
FS Risk, Regulatory, and FS Risk, Regulatory, and
Compliance Services Compliance Services
KPMG LLP KPMG LLP
E: lbrotcke@[Link]

Jacob Armstrong Sakineh Tavakkoli


Director Director
FS Risk, Regulatory, and FS Risk, Regulatory, and
Compliance Services Compliance Services
KPMG LLP KPMG LLP
E: jacobarmstrong1@[Link] E: stavakkoli@[Link]

Some or all of the services described herein The information contained herein is of a general nature and is not intended to address
the circumstances of any particular individual or entity. Although we endeavor to provide
may not be permissible for KPMG audit accurate and timely information, there can be no guarantee that such information is
clients and their affiliates or related entities. accurate as of the date it is received or that it will continue to be accurate in the future.
No one should act upon such information without appropriate professional advice after a
thorough examination of the particular situation.

© 2026 KPMG LLP, a Delaware limited liability partnership, and its subsidiaries are part
Learn about us: [Link] of the KPMG global organization of independent member firms affiliated with KPMG
International Limited, a private English company limited by guarantee. All rights reserved.
The KPMG name and logo are trademarks used under license by the independent member
firms of the KPMG global organization. USCS035344-1A

You might also like