Model lifecycle analysis • Is model development centralized or not?
• Is model implementation centralized or not?
• Acceptance tests of models in a production environment: who conducts them, is there an acceptance
process for the test results, who is the approving party?
• Who decides to start using models in decision-making? Are there dedicated committees?
• Is validation a mandatory component of the model management lifecycle?
• Is there regular monitoring of models?
• Who makes the decision to replace / retire a model?
• Is there regular model / model risk reporting? Who prepares is and who receives it?
Model inventory • Does the bank have a model registry?
• Who is responsible for the registry and its completeness?
• Model classification by materiality: how many levels, which criteria are used?
• Who is responsible for determining / reviewing significance of models?
• Does the bank assess the financial impact of the models?
Model management governance • Who do the modelers, validators, employees responsible for monitoring, and A/B testing et cetera report
to?
• Can validation / monitoring exceptions be escalated to the bank's governing bodies?
• Are there dedicated committees on model risk? Who are their members (e.g. in terms of the level of
corporate leadership), how often do they meet?
Scope of model validation • What is the ratio of validation staff to the number of models / number of developers?
• What areas does the validation function handle other than models? E.g. process validation, IT validation,
stress model testing
• Are any of the following included in the validation perimeter: verification of data at the source, checking
the assembly code of data marts, computational (non-model-based) algorithms?
• Are expert models/adjustments subject to validation?
• What is the frequency of validation? In which cases can the frequency be increased?
• Are all models covered by validation?
• Is the extent of validation the same for all types of models, or are there differences?
• Does the validation process include ad hoc analytics on models?
• Is alternative modeling conducted? How often? Are there any criteria?
• Are services such as auto-ml or optimization algorithms subject to validation?
• Who approves the validation reports? Is the implementation of validation team’s recommendations
monitored?
Scope of model monitoring • Are all models subject to monitoring?
• What is the frequency of monitoring?
• Are there dashboards with monitoring results? Who has access to them?
• What reporting is generated for model monitoring? Who are these reports submitted to?
• What is the process for handling negative monitoring results? Who is notified? Is there an approved plan of
action for such cases?
Scope of A/B testing • Which models are tested?
• What is the frequency of testing?
• What action is taken based on the test results?
Model risk events documentation • Is there a system for collecting data on model risk events?
• Who is responsible for recording the identified events?
• Who assesses losses from the event? Who verifies the assessment?
• Are major model risk loss events reviewed by any of the bank’s committees?
• Are there key risk indicators (CRI) of model risk?
• Which areas are covered by CRIs?
• Who approves CRIs?
• Is model risk considered a significant risk under the bank-wide risk assessment framework?
• Are model risk indicators included in risk appetite?
Internal regulations • What are the criteria for significant economic changes?
• Is there is a separate procedure for monitoring/validating models when such changes occur?
Model management during periods of • Criteria for significant economic changes
significant macroeconomic change • • There is a separate procedure for monitoring/validating
• models
Local regulatory requirements to model • What are the requirements for the governance structure of the model risk management system?
risk management • What are the requirements for classification for the materiality of models?
• What kind of reporting is submitted to the regulator (ad hoc requests included)?
Local regulatory requirements to • What are its aims?
management of AI risk • What has already been put into practice?
• What are the consequences of non-compliance?
Risk management system for AI risk • Who, in terms of units and reporting lines (e.g. risk management, IT), is responsible for managing them?
• Is a separate AI risk management procedure being developed, or is it included in the management of model
or it risks?
• Are external LLM models (e.g. ChatGPT, Llama, DeepSeek) subject to internal validation?