close
breadcrumb right arrowGlossary
breadcrumb right arrowModel Risk Management (MRM)
Model Risk Management (MRM)

Banks have run formal Model Risk Management programs for decades, originally for credit scoring and risk models: independent validation before a model goes live, ongoing monitoring for performance drift, and clear documentation of what the model does and doesn't reliably do. Regulators (in the US, guidance like SR 11-7) require this for any model materially affecting business decisions.

As AI agents take on more consequential decisions, approving payments, flagging fraud, many regulated organizations are extending their existing MRM frameworks to cover them: independent validation of the AI system's behavior, ongoing monitoring for accuracy drift, and clear documentation of its known limitations, the same rigor previously reserved for traditional statistical models.

Frequently Asked Questions

Why does MRM matter more for AI agents than earlier automation?

Because an AI agent's behavior can be less predictable and harder to fully specify in advance than rule-based automation, which makes independent validation and ongoing monitoring more important, not less, than for a simpler deterministic system.

What does "independent validation" mean in an MRM context?

A team separate from the one that built or deployed the model reviews and tests it before it goes live, and periodically afterward, specifically to avoid the conflict of interest in a team validating its own work.

Does MRM apply to every AI use case, or just the highest-stakes ones?

Most frameworks scale rigor to the stakes involved, a low-risk internal tool gets lighter oversight than a model directly influencing credit decisions or regulatory reporting, following a tiered approach rather than treating every model identically.

How does model drift get detected under an MRM program?

By continuously monitoring the model's real-world performance against defined benchmarks and flagging when accuracy or behavior shifts meaningfully from its validated baseline, rather than assuming a model that passed validation once will perform identically indefinitely.