0% found this document useful (0 votes)
7 views14 pages

Model Risk Management in AI

This white paper discusses the evolution of Model Risk Management (MRM) in the context of Generative and Agentic AI systems, emphasizing the need for continuous governance rather than periodic validation due to increased opacity and autonomy in AI models. It proposes a governance-centric MRM framework that includes dynamic guardrails, real-time monitoring, and human oversight to ensure safe deployment in regulated financial environments. A case study on Moody's Early Warning System illustrates the practical application of these concepts, highlighting the integration of traditional and advanced AI models while maintaining robust governance and risk mitigation strategies.

Uploaded by

Prabhu Heins
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views14 pages

Model Risk Management in AI

This white paper discusses the evolution of Model Risk Management (MRM) in the context of Generative and Agentic AI systems, emphasizing the need for continuous governance rather than periodic validation due to increased opacity and autonomy in AI models. It proposes a governance-centric MRM framework that includes dynamic guardrails, real-time monitoring, and human oversight to ensure safe deployment in regulated financial environments. A case study on Moody's Early Warning System illustrates the practical application of these concepts, highlighting the integration of traditional and advanced AI models while maintaining robust governance and risk mitigation strategies.

Uploaded by

Prabhu Heins
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

White Paper

Model Risk
Authors
Nils Grevenbrock
Zhengpu Zhao
Management in
Nihil Patel
the Age of AI
Acknowledgements
We are extremely grateful to James Abstract
Alexander, Armen Mirozoyan, and
Anamaria Pieschacon. Model Risk Management (MRM) must evolve from periodic validation to
continuous governance as Generative and Agentic Artificial Intelligence (AI)
systems introduce opacity, stochasticity, and autonomy that break
traditional supervisory assumptions. This paper outlines a governance-
centric MRM paradigm, proposing practical controls—such as dynamic
guardrails, real-time monitoring, Human-in-the-loop (HITL) oversight, and
third-party risk mitigation—to ensure safe, compliant, and resilient
deployment of AI systems for regulated financial domains.
Table of Contents

1 Introduction 3
2 The Evolution of Models: From Traditional Models to AI Systems 4
3 Operationalizing Risk Mitigation 6
4 Case Study: Operationalizing MRM on AI Systems 8
5 Conclusion 10
6 References 11
6.1 Regulatory and Supervisory Guidance 11
6.2 Academic and Industry Research 12

Model Risk Management in the Age of AI 2


Introduction

1 Introduction

Traditional Model Risk Management (MRM) frameworks were built for deterministic, transparent models under
full control. Supervisory frameworks such as the Supervisory Regulation 11-7 (SR 11-7), introduced by the Federal
Reserve and the Office of the Comptroller of the Currency in 2011 assumed models with defined inputs, predictable
outputs1, and clear interpretability2.
These conditions enabled static validation cycles and well-understood governance practices.
Generative AI (GenAI) and agentic AI systems break these assumptions by introducing opacity, stochasticity,
and autonomy. The large language models (LLMs) internal structure functions as a black box, offering limited
interpretability, producing nondeterministic outputs, and relying on a third-party infrastructure that might change
without notice. Agentic systems further increase complexity by enabling autonomous decision-making under
uncertainty.
Static validation is no longer sufficient; MRM must shift to continuous governance. While supervisory
frameworks (such as SR 11-7) still stand at a high level, their application must evolve. Institutions need dynamic
guardrails instead of static thresholds, real-time observability rather than periodic checks, and human-in-the-loop
oversight for high stake decisions.
Managing third-party risk and monitoring the entire system's outputs and behaviors must become core
components of governance. Monitoring models to approved versions and maintaining fallback models can mitigate
the risk of unexpected vendor changes. Continuous, system-level monitoring through behavioral testing and anomaly
detection ensures that the AI system remains aligned with intended objectives and provides resilience against
performance drift or unintended behaviors. Also, monitoring must extend beyond individual model components to the
entire system, focusing on monitoring inputs, outputs, and emergent behaviors rather than internal mechanics alone.
This paper first traces model evolution across three generations, then proposes operational strategies for model risk
management, including a case study. Finally, the paper concludes with actionable steps institutions should consider.

1
Traditional models yield deterministic estimates, whereas generative AI models (for example, LLM) sample from learned distributions, introducing
intrinsic stochasticity.
2
Moody's adheres to Pérez-Cruz et al. (BIS, 2025), distinguishing interpretability (understanding model mechanics) from explainability (justifying
outputs), though terms are often used interchangeably.

Model Risk Management in the Age of AI 3


The Evolution of Models: From Traditional Models to AI Systems

2 The Evolution of Models: From


Traditional Models to AI Systems

Models have evolved through three generations, trading transparency, determinism, and control for
performance and capability.3 Each step, from traditional scorecards and structural models to Machine Learning
(ML) models to GenAI-based systems, introduces new risks that challenge conventional validation frameworks. Table
1 summarizes how risks and mitigation strategies evolve across generations.
Table 1: The Evolution of Models in the Age of AI

Generation 1: Traditional models are deterministic, transparent, and fully controlled. These models, such as
logistic regressions, rely on well-understood relationships and structured data. Inputs and outputs are predictable.
Risks, such as model misspecification or parameter instability, are traceable and manageable through established
MRM techniques.

Model Risk Management in the Age of AI 4


The Evolution of Models: From Traditional Models to AI Systems

EXAMPLE

Historical data shows a company's financial leverage ratio correlates with a company's credit risk. This relationship can be modeled via logistic
regression. The estimated coefficient of this logistic regression can be observed and interpreted. From this we can derive statements such as "If
the financial leverage ratio of a company goes up by x%, on average, the credit risk increases by y%."

Generation 2: Machine Learning models deliver higher predictive power but reduce interpretability. Techniques
like Random Forest can uncover complex patterns in the data beyond what could be incapsulated in traditional
models but introduce opacity due to the possibly vast number of parameters and complex non-linearities. In these
situations, it is almost impossible to connect model outputs back to parsimonious human-understandable rules
operating on inputs. Meanwhile, ML models remain as deterministic functions that modelers typically control and
maintain,4 much like traditional models.

EXAMPLE

A Random Forest model can be trained to find complex patterns in credit default data that traditional linear, or structural (non-linear) models
cannot capture. How the model arrives at a prediction, for example, a combination of firms' financial leverage and firm size contributing to the
increase in a company's credit risk, often is not inherently interpretable.

Generation 3: Generative and Agentic AI Systems5 add stochastic behaviors and autonomy. LLMs6 deliver the
capability to operate on vast multimodal data (text, audio, video, image) at scale, often approaching or exceeding
expert-level performance.
Agentic systems allow for autonomous action under uncertainty to achieve a goal. Together, LLM-based agentic
systems, though powerful, introduce stochasticity (in other words, the same input can yield different outputs),
outsourced control (for example, if vendors like OpenAI are changing how a specific LLM works), and low
transparency and interpretability.
Risks include behavioral drift (agents may take unanticipated paths to reach a goal), adversarial prompts, and goal
misalignment—each underscoring the need for MRM to evolve.

EXAMPLE

A LLM agent operating for a bank, harnessed with access to unstructured context (for example, company financials, internal bank feeds, news
articles), and a set of tools (for example, external APIs) can dynamically interpret the large data landscape. These agents can deliver real-time
credit risk insights and can be used as part of an autonomous lending decision for small businesses, including narratives beyond traditional
models' capabilities.

Each model generation comes with its own risk and its own risk mitigation techniques. Each generation expands
model capabilities, from structured prediction to pattern recognition to reasoning and autonomous actions over
unstructured data. But this pattern progressively sacrifices a portion of the transparency, determinism, and the
controls on which traditional validation frameworks depend. As a result, Model Risk Management must fundamentally
rethink its governance, its development, and its validation approaches.

3
Performance gains are incremental improvements; capability gains shift what is infeasible to feasible.
4
Modelers typically have full control of model inference hardware, as well as random seeds if applicable.
5
It is worth noting that not all Generation 3 models are equally complex and dynamic. Generation 3 systems range from autonomous agentic systems
to LLM-augmented workflows, along with hybrids and intermediaries.
6
We adopt "LLM" as an umbrella term referring broadly to large generative models—including multimodal and diffusion-based architectures—not
solely text-based language models.

Model Risk Management in the Age of AI 5


Operationalizing Risk Mitigation

3 Operationalizing Risk Mitigation

Managing model risk now demands continuous governance, not periodic validation. While frameworks (such as the
SR 11-7) still serve as the gold standard for traditional models, their application must adapt to the complexity and
opacity of AI systems. Institutions need dynamic controls embedded across the model lifecycle. Table 2 illustrates
how risk mitigation strategies evolve across generations.
Table 2: Validation and Model Risk Management by Model Generation

Generation 1: Traditional models rely on established MRM practices. Deterministic models like logistic regression
are governed through clear documentation, independent validation, stress testing, and periodic backtesting. Risks
such as misspecification or parameter instability are traceable and manageable through classical statistical tests and
diagnostic analysis.

EXAMPLE

Backtesting a credit risk scorecard against historical default data.

Model Risk Management in the Age of AI 6


Operationalizing Risk Mitigation

Generation 2: Explainability and robustness within deterministic boundaries. ML models remain deterministic;
the same input yields the same output but also introduce opacity through non-linearities and large parameter sets.
The following list is non-exhaustive. Mitigation strategies include:7
• Post-hoc explainability tools (for example, SHAP, LIME)8 to interpret predictions.
• Controlled deployment for specific, well-understood use cases.
• Human-in-the-loop oversight is essential for high-stakes decisions.

Periodic validation still works because model behavior is stable unless retrained. The challenge is interpretability, not
unpredictability. Regulatory guidance is evolving to accommodate these methods, though practices are still working
toward standardization across institutions.9

EXAMPLE

A credit risk Random Forest model uses SHAP values to show which features drive a borrower's credit risk.

Generation 3: Behavioral oversight and autonomy controls for non-deterministic systems. LLM-based agentic
systems introduce stochastic outputs, autonomy, and vendor dependency, risks that invalidate static model validation
cycles. Mitigation strategies must include:
• Behavioral testing through adversarial prompts (for example, what happens if altering a prompt sent to an agent);
goal alignment checks to monitor the outcome of reasoning and autonomous decision-making.
• Continuous observability through real-time tracing and immutable audit trails of AI output and agentic steps (for
example, tool calls or decision paths); implementation of dynamic constraints and guardrails, kill-switches (for
example, if an agent takes clearly defined unintended actions), and escalation triggers (for example, what
happens if unintended actions were taken?).
• Vendor risk (for example, from LLM providers) needs to be reduced by methods including fixing models to
approved versions (version pinning) and maintaining backup models (with prompts/orchestrations) as fallback.

EXAMPLE

AI system passes all adversarial behavior tests ("red teaming"), aligns with credit risk expert expectations, and operates within predictable
output variability. Deployment enforces monitoring and logging of all steps when generating real-time credit insights. Human-in-the-loop
authorizes operation and maintains governance oversight.

Monitoring shifts from periodic to real-time and ongoing monitoring, as behavior can change due to vendor updates,
emergent agent decisions, or simply model stochasticity. Governance must explicitly justify AI use due to its greater
monitoring requirements.

7
A non-exhaustive list.
8
The SHapley Additive exPlanations (SHAP) method quantifies the contribution of each feature to a model's prediction by computing Shapley values,
offering consistent and locally accurate explanations. The Local Interpretable Model-agnostic Explanations (LIME) method approximates complex
models locally with interpretable ones (like linear models) to explain individual predictions by perturbating input data and observing changes in output.
9
See BIS (2025), Occasional Paper (No 24), "Managing explanations: how regulators can address AI explainability".

Model Risk Management in the Age of AI 7


Case Study: Operationalizing MRM on AI Systems

4 Case Study: Operationalizing MRM


on AI Systems

Generation 3 systems may unlock a step-function change in capability, but the go/no-go decision hinges on
whether MRM can be redesigned around accountability, enforceable control boundaries, and continuous
evidence of behavior. Accordingly, we present a case study of Moody's Early Warning System (EWS) that
operationalizes the Generation 3 governance controls in Table 2 that would not be addressed by traditional (SR 11-7)
MRM frameworks.
Moody's EWS links traditional Generation 1 models for credit risk with Generation 2 models, news articles clustering
algorithms, and with Generation 3 models, using LLMs to extract events from the news.
Specifically, the system converts news events into financial statement impacts and then feeds them downstream into
Generation 1 credit risk models. The most critical steps are attributing firm relevant reports in news articles and
clustering them into coherent events—areas where Generations 2 and 3 methods deliver a step change in accuracy,
but also increase the need for measurable performance, accountable controls, and robust third party/API dependency
management with defined fallback paths.

Figure 1: Moody's News-powered Early Warning System


The real-time EWS begins with an Attribution step using LLMs (Generation 3 model) that converts unstructured
news articles into quantified firm-specific impacts. Because this Generation 3 component is non-deterministic and
not inherently interpretable, we treat its performance as observable behavior that must be continuously monitored
rather than assumed stable across validation cycles.
To ensure reliable performance, MRM combines expert review with quantitative measures. Specifically, we compare
the AI's results to those of our internal subject matter experts using an expert-labeled dataset to assess how well the
system recalls key statements. We also evaluate how closely the AI's rankings align with expert judgments and track

Model Risk Management in the Age of AI 8


Case Study: Operationalizing MRM on AI Systems

the variability in results across multiple runs. This process helps us define acceptable levels of randomness in the
AI's output.
In production, structured output schemas and controlled sampling (such as adjusting temperature) help reduce
variance. Continuous monitoring of extraction volumes, distributions, and variability provides ongoing evidence and
triggers expert review (human-in-the-loop) when the system's behavior falls outside the validated range, capturing
changes to the underlying models and unexpected behavior caused by their stochastic nature.
Changes to the prompt or to the model are governed through version control and revalidation, for example, a pipeline
migrates from GPT-5-mini to a fine-tuned version of GPT-5-nano.
Downstream, a Clustering algorithm leveraging Generation 2 models (for example, K-means) deterministically
groups incidence statements into coherent events. Using automated separation or tightness metrics (for example,
Jaccard) complemented by periodic expert coherence review, we monitor cluster distributions over time with explicit
revalidation triggers when upstream embeddings or material parameters change.
Moody's uses financial accounting models and general additive models (Generation 1) to translate news signals
into credit risk estimates and early warning signals.10
As an integration with a Generation 1 model, validation focuses on the interface layer rather than revalidating core
model mechanics already covered by Moody's existing MRM framework. Governance centers on input integrity,
output reasonableness, and integration reliability; before invoking the credit risk model, inputs are validated for
completeness, consistency, bounds, and format compliance. Outputs are checked for range and directional
consistency (for example, alignment of credit risk movements with input changes). End-to-end integration and
regression testing ensures consistent outputs for fixed inputs and establishes clear control boundaries, so the overall
EWS remains governable end-to-end even when upstream components are partially stochastic.11
This example demonstrates that significant capability gains from Generation 2, and Generation 3 can be
realized without sacrificing end-to-end governability, provided controls are built around measured behavior,
continuous monitoring, clear control boundaries, and human-in-the-loop steps. The result is a governance approach
that is practical to operate, and that produces ongoing evidence suitable for internal oversight and supervisory
expectations.

10
Detailed component metrics and triggers are provided in the appendices.
11
Because the EWS operates as a predefined pipeline rather than an autonomous agent, this case study focuses on governing stochastic components
within a bounded workflow. If the EWS outputs are used within an agentic decisioning layer, that layer should be governed under agentic-system MRM
guidance.

Model Risk Management in the Age of AI 9


Conclusion

5 Conclusion

Frameworks such as SR 11-7 remain relevant, but governance must evolve for AI. The three pillars of SR 11-7
(governance, development and implementation, and validation) still stand. What changes is the emphasis: governance
must shift from static oversight to dynamic, continuous control. This includes setting dynamic guardrails instead of
fixed thresholds, defining acceptance levels for third-party model risk, contingency plans, escalation triggers, and
clear criteria for human-in-the-loop intervention.
Governance must justify the use of Machine Learning or Artificial Intelligence (such as agentic systems with
large language models). The questions expand beyond "Is the model sound?" to include "Is AI justified here?", "What
decisions will it inform?", and "Is the model's behavior stable?". As risks increasingly emerge from interactions
between components and autonomous decision-making, monitoring must shift from isolated model elements to
holistic system-level oversight.
The validator's role becomes more frequent, complex, and consequential. As modeling becomes commoditized,
validators need new competencies. The same is true for decision makers playing a greater role in model governance.
Prompt engineering, agentic context design, testing a system's behavior, observability infrastructure, and adversarial
robustness assessment are skills that must be understood at various levels of an organization. Institutions must
invest in upskilling teams to master these capabilities.
The pace of AI adoption will not slow; supervisory measures must respond. With undeniable performance gains
and new capabilities, firms have strong incentives to adopt advanced models. Those firms that rebalance MRM
toward explicit gatekeeping, scope of governance, and outcome-focused oversight, will deploy AI responsibly and will
capture its benefits. Those that do not adopt these practices, risk either forgoing valuable capabilities or bearing risks
they do not fully understand.

Model Risk Management in the Age of AI 10


References

6 References

6.1 Regulatory and Supervisory Guidance


• Board of Governors of the Federal Reserve System and Office of the Comptroller of the Currency (2011). SR 11-7:
Supervisory Guidance on Model Risk Management. April 4, 2011. Available at: [Link]
supervisionreg/srletters/[Link]
• Prudential Regulation Authority (2023). SS1/23: Model Risk Management Principles for Banks. Bank of England,
May 17, 2023. Available at: [Link]
model-risk-management-principles-for-banks-ss
• Financial Stability Board (2025). Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the
Financial Sector. October 10, 2025. Available at: [Link]
intelligence-and-related-vulnerabilities-in-the-financial-sector/
• Office of the Comptroller of the Currency (2021). Comptroller's Handbook: Model Risk Management. Version 1.0,
August 2021. Available at: [Link]
handbook/files/model-risk-management/[Link]
• Office of the Comptroller of the Currency, Board of Governors of the Federal Reserve System, and Federal Deposit
Insurance Corporation (2023). Interagency Guidance on Third-Party Relationships: Risk Management. June 6,
2023. Federal Register 88 FR 37920.
• National Institute of Standards and Technology (2023). Artificial Intelligence Risk Management Framework (AI
RMF 1.0). NIST AI 100-1, January 26, 2023. Available at: [Link]
• National Institute of Standards and Technology (2024). Artificial Intelligence Risk Management Framework:
Generative Artificial Intelligence Profile. NIST AI 600-1, July 26, 2024. Available at: [Link]
nistpubs/ai/[Link]
• European Parliament and Council of the European Union (2024). Regulation (EU) 2024/1689 laying down
harmonized rules on artificial intelligence (Artificial Intelligence Act). June 13, 2024.
• European Banking Authority (2023). Machine Learning for IRB Models: Follow-up Report. EBA/REP/2023/28,
August 4, 2023. Available at: [Link]
follow-report-use-machine-learning-internal
• Basel Committee on Banking Supervision (2022). Newsletter on Artificial Intelligence and Machine Learning.
BCBS Newsletter No. 27, March 16, 2022. Available at: [Link]

Model Risk Management in the Age of AI 11


References

• U.S. Department of the Treasury (2024). Artificial Intelligence in Financial Services: Report on the Uses,
Opportunities, and Risks. December 19, 2024. Available at: [Link]
jy2760

6.2 Academic and Industry Research


• Lundberg, S.M. and Lee, S.-I. (2017). "A Unified Approach to Interpreting Model Predictions." Advances in Neural
Information Processing Systems 30 (NeurIPS 2017), 4765–4774.
• Ribeiro, M.T., Singh, S., and Guestrin, C. (2016). "'Why Should I Trust You?': Explaining the Predictions of Any
Classifier." Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data
Mining, 1135–1144. DOI: 10.1145/2939672.2939778
• Bracke, P., Datta, A., Jung, C., and Sen, S. (2019). "Machine Learning Explainability in Finance: An Application to
Default Risk Analysis." Bank of England Staff Working Paper No. 816. Available at: https://
[Link]/working-paper/2019/machine-learning-explainability-in-finance-an-application-to-
default-risk-analysis
• Bank for International Settlements, Financial Stability Institute (2021). "Humans Keeping AI in Check: Emerging
Regulatory Expectations in the Financial Sector." FSI Insights No. 35. Available at: [Link]
[Link]
• Pérez-Cruz, F., Prenio, J., Restoy, F., and Yong, J. (2025). "Managing Explanations: How Regulators Can Address AI
Explainability." BIS FSI Occasional Paper No. 24, September 2025. Available at: [Link]
[Link]
• OpenAI (2023). Practices for Governing Agentic AI Systems. Available at: [Link]
[Link]

Model Risk Management in the Age of AI 12


Contact Us
[Link]

Documentation
Information Web: [Link]
Customer Portal: [Link]

Model Risk Management in the Age of AI 13


CREDIT RATINGS ISSUED BY MOODY'S CREDIT RATINGS AFFILIATES ARE THEIR CURRENT OPINIONS OF THE RELATIVE FUTURE CREDIT RISK OF ENTITIES,
CREDIT COMMITMENTS, OR DEBT OR DEBT-LIKE SECURITIES, AND MATERIALS, PRODUCTS, SERVICES AND INFORMATION PUBLISHED OR OTHERWISE MADE
AVAILABLE BY MOODY’S (COLLECTIVELY, “MATERIALS”) MAY INCLUDE SUCH CURRENT OPINIONS. MOODY’S DEFINES CREDIT RISK AS THE RISK THAT AN
ENTITY MAY NOT MEET ITS CONTRACTUAL FINANCIAL OBLIGATIONS AS THEY COME DUE AND ANY ESTIMATED FINANCIAL LOSS IN THE EVENT OF DEFAULT OR
IMPAIRMENT. SEE APPLICABLE MOODY’S RATING SYMBOLS AND DEFINITIONS PUBLICATION FOR INFORMATION ON THE TYPES OF CONTRACTUAL FINANCIAL
OBLIGATIONS ADDRESSED BY MOODY’S CREDIT RATINGS. CREDIT RATINGS DO NOT ADDRESS ANY OTHER RISK, INCLUDING BUT NOT LIMITED TO: LIQUIDITY
RISK, MARKET VALUE RISK, OR PRICE VOLATILITY. CREDIT RATINGS, NON-CREDIT ASSESSMENTS (“ASSESSMENTS”), AND OTHER OPINIONS INCLUDED IN
MOODY’S MATERIALS ARE NOT STATEMENTS OF CURRENT OR HISTORICAL FACT. MOODY’S MATERIALS MAY ALSO INCLUDE QUANTITATIVE MODEL-BASED
ESTIMATES OF CREDIT RISK AND RELATED OPINIONS OR COMMENTARY PUBLISHED BY MOODY’S ANALYTICS, INC. AND/OR ITS AFFILIATES. MOODY’S CREDIT
RATINGS, ASSESSMENTS, OTHER OPINIONS AND MATERIALS DO NOT CONSTITUTE OR PROVIDE LEGAL, COMPLIANCE, INVESTMENT, FINANCIAL OR OTHER
PROFESSIONAL ADVICE, AND MOODY’S CREDIT RATINGS, ASSESSMENTS, OTHER OPINIONS AND MATERIALS ARE NOT AND DO NOT PROVIDE
RECOMMENDATIONS TO PURCHASE, SELL, OR HOLD PARTICULAR SECURITIES. MOODY’S CREDIT RATINGS, ASSESSMENTS, OTHER OPINIONS AND MATERIALS
DO NOT COMMENT ON THE SUITABILITY OF AN INVESTMENT FOR ANY PARTICULAR INVESTOR. MOODY’S ISSUES ITS CREDIT RATINGS, ASSESSMENTS AND
OTHER OPINIONS AND PUBLISHES OR OTHERWISE MAKES AVAILABLE ITS MATERIALS WITH THE EXPECTATION AND UNDERSTANDING THAT EACH INVESTOR
WILL, WITH DUE CARE, MAKE ITS OWN STUDY AND EVALUATION OF EACH SECURITY THAT IS UNDER CONSIDERATION FOR PURCHASE, HOLDING, OR SALE.
MOODY’S CREDIT RATINGS, ASSESSMENTS, OTHER OPINIONS, AND MATERIALS ARE NOT INTENDED FOR USE BY RETAIL INVESTORS AND IT WOULD BE
RECKLESS AND INAPPROPRIATE FOR RETAIL INVESTORS TO USE MOODY’S CREDIT RATINGS, ASSESSMENTS, OTHER OPINIONS OR MATERIALS WHEN MAKING
AN INVESTMENT DECISION. IF IN DOUBT YOU SHOULD CONTACT YOUR FINANCIAL OR OTHER PROFESSIONAL ADVISER.
ALL INFORMATION CONTAINED HEREIN IS PROTECTED BY LAW, INCLUDING BUT NOT LIMITED TO, COPYRIGHT LAW, AND NONE OF SUCH INFORMATION MAY
BE COPIED OR OTHERWISE REPRODUCED, REPACKAGED, FURTHER TRANSMITTED, TRANSFERRED, DISSEMINATED, REDISTRIBUTED OR RESOLD, OR STORED
FOR SUBSEQUENT USE FOR ANY SUCH PURPOSE, IN WHOLE OR IN PART, IN ANY FORM OR MANNER OR BY ANY MEANS WHATSOEVER, BY ANY PERSON
WITHOUT MOODY’S PRIOR WRITTEN CONSENT. FOR CLARITY, NO INFORMATION CONTAINED HEREIN MAY BE USED TO DEVELOP, IMPROVE, TRAIN OR RETRAIN
ANY SOFTWARE PROGRAM OR DATABASE, INCLUDING, BUT NOT LIMITED TO, FOR ANY ARTIFICIAL INTELLIGENCE, MACHINE LEARNING OR NATURAL
LANGUAGE PROCESSING SOFTWARE, ALGORITHM, METHODOLOGY AND/OR MODEL.
MOODY’S CREDIT RATINGS, ASSESSMENTS, OTHER OPINIONS AND MATERIALS ARE NOT INTENDED FOR USE BY ANY PERSON AS A BENCHMARK AS THAT
TERM IS DEFINED FOR REGULATORY PURPOSES AND MUST NOT BE USED IN ANY WAY THAT COULD RESULT IN THEM BEING CONSIDERED A BENCHMARK.
All information contained herein is obtained by MOODY’S from sources believed by it to be accurate and reliable. Because of the possibility of human or mechanical
error as well as other factors, however, all information contained herein is provided “AS IS” without warranty of any kind. MOODY'S adopts all necessary measures so
that the information it uses in assigning a credit rating or assessment is of sufficient quality and from sources MOODY'S considers to be reliable including, when
appropriate, independent third-party sources. However, MOODY’S is not an auditor and cannot in every instance independently verify or validate information received in
the credit rating or assessment process or in preparing its Materials.
To the extent permitted by law, MOODY’S and its directors, officers, employees, agents, representatives, licensors and suppliers disclaim liability to any person or entity
for any indirect, special, consequential, or incidental losses or damages whatsoever arising from or in connection with the information contained herein or the use of or
inability to use any such information, even if MOODY’S or any of its directors, officers, employees, agents, representatives, licensors or suppliers is advised in advance
of the possibility of such losses or damages, including but not limited to: (a) any loss of present or prospective profits or (b) any loss or damage arising where the
relevant financial instrument is not the subject of a particular credit rating or assessment assigned by MOODY’S.
To the extent permitted by law, MOODY’S and its directors, officers, employees, agents, representatives, licensors and suppliers disclaim liability for any direct or
compensatory losses or damages caused to any person or entity, including but not limited to by any negligence (but excluding fraud, willful misconduct or any other type
of liability that, for the avoidance of doubt, by law cannot be excluded) on the part of, or any contingency within or beyond the control of, MOODY’S or any of its
directors, officers, employees, agents, representatives, licensors or suppliers, arising from or in connection with the information contained herein or the use of or
inability to use any such information.
NO WARRANTY, EXPRESS OR IMPLIED, AS TO THE ACCURACY, TIMELINESS, COMPLETENESS, MERCHANTABILITY OR FITNESS FOR ANY PARTICULAR PURPOSE
OF ANY CREDIT RATING, ASSESSMENT, OTHER OPINION OR INFORMATION IS GIVEN OR MADE BY MOODY’S IN ANY FORM OR MANNER WHATSOEVER.
Moody’s Investors Service, Inc., a wholly-owned credit rating agency subsidiary of Moody’s Corporation (“MCO”), hereby discloses that most issuers of debt securities
(including corporate and municipal bonds, debentures, notes and commercial paper) and preferred stock rated by Moody’s Investors Service, Inc. have, prior to
assignment of any credit rating, agreed to pay Moody’s Investors Service, Inc. for credit ratings opinions and services rendered by it. MCO and all MCO entities that
issue ratings under the “Moody’s Ratings” brand name (“Moody’s Ratings”), also maintain policies and procedures to address the independence of Moody’s Ratings’
credit ratings and credit rating processes. Information regarding certain affiliations that may exist between directors of MCO and rated entities, and between entities
who hold credit ratings from Moody’s Investors Service, Inc. and have also publicly reported to the SEC an ownership interest in MCO of more than 5%, is posted
annually at [Link] under the heading “Investor Relations — Corporate Governance — Charter and Governance Documents - Director and Shareholder Affiliation
Policy.”
Moody's SF Japan K.K., Moody's Local AR Agente de Calificación de Riesgo S.A., Moody’s Local BR Agência de Classificação de Risco LTDA, Moody’s Local MX S.A. de
C.V, I.C.V., Moody's Local PE Clasificadora de Riesgo S.A., Moody's Local PA Calificadora de Riesgo S.A., Moody’s Local CR Calificadora de Riesgo S.A., Moody’s Local
ES S.A. de CV Clasificadora de Riesgo, Moody’s Local RD Sociedad Calificadora de Riesgo S.R.L. and Moody’s Local GT S.A.(collectively, the “Moody’s Non-NRSRO
CRAs”) are all indirectly wholly-owned credit rating agency subsidiaries of MCO. None of the Moody’s Non-NRSRO CRAs is a Nationally Recognized Statistical Rating
Organization.
Additional terms for Australia only: Any publication into Australia of this document is pursuant to the Australian Financial Services License of MOODY’S affiliate,
Moody’s Investors Service Pty Limited ABN 61 003 399 657AFSL 336969 and/or Moody’s Analytics Australia Pty Ltd ABN 94 105 136 972 AFSL 383569 (as applicable).
This document is intended to be provided only to “wholesale clients” within the meaning of section 761G of the Corporations Act 2001. By continuing to access this
document from within Australia, you represent to MOODY’S that you are, or are accessing the document as a representative of, a “wholesale client” and that neither you
nor the entity you represent will directly or indirectly disseminate this document or its contents to “retail clients” within the meaning of section 761G of the Corporations
Act 2001. MOODY’S credit rating is an opinion as to the creditworthiness of a debt obligation of the issuer, not on the equity securities of the issuer or any form of
security that is available to retail investors.
Additional terms for India only: Moody’s credit ratings, Assessments, other opinions and Materials are not intended to be and shall not be relied upon or used by any
users located in India in relation to securities listed or proposed to be listed on Indian stock exchanges.
Additional terms with respect to Second Party Opinions and Net Zero Assessments (as defined in Moody’s Ratings Rating Symbols and Definitions): Please note that
neither a Second Party Opinion (“SPO”) nor a Net Zero Assessment (“NZA”) is a “credit rating”. The issuance of SPOs and NZAs is not a regulated activity in many
jurisdictions, including Singapore. EU: In the European Union, each of Moody’s Deutschland GmbH and Moody’s France SAS provide services as an external reviewer in
accordance with the applicable requirements of the EU Green Bond Regulation. JAPAN: In Japan, development and provision of SPOs and NZAs fall under the category
of “Ancillary Businesses”, not “Credit Rating Business”, and are not subject to the regulations applicable to “Credit Rating Business” under the Financial Instruments
and Exchange Act of Japan and its relevant regulation. PRC: Any SPO: (1) does not constitute a PRC Green Bond Assessment as defined under any relevant PRC laws or
regulations; (2) cannot be included in any registration statement, offering circular, prospectus or any other documents submitted to the PRC regulatory authorities or
otherwise used to satisfy any PRC regulatory disclosure requirement; and (3) cannot be used within the PRC for any regulatory purpose or for any other purpose which is
not permitted under relevant PRC laws or regulations. For the purposes of this disclaimer, “PRC” refers to the mainland of the People’s Republic of China, excluding
Hong Kong, Macau and Taiwan.

© 2026 Moody's Corporation, Moody's Investors Service, Inc., Moody's Analytics, Inc. and/or their licensors and affiliates (collectively, "MOODY'S"). All rights reserved.

You might also like