Banks use models to estimate credit losses, detect fraud, price products and support many other decisions. Model risk arises when a model is wrong, misused or relied on beyond what its design and evidence can support.
Model risk depends on decisions and consequences
A technically sophisticated model can still create risk if its data are weak, assumptions no longer hold, outputs are misunderstood or users apply it to the wrong purpose. The impact depends on how much the institution relies on the result and what could happen if it is wrong.
Banks therefore classify models by materiality and risk. A tool informing a major credit or capital decision generally warrants more rigorous controls than a low-impact analytical aid.
Governance begins with knowing what is in use
A model inventory records each model’s purpose, owner, users, data, limitations and control status. Clear classification helps the bank decide what approval, documentation, validation and monitoring are proportionate to the risk.
Third-party models still require oversight. A vendor may supply technology or expertise, but the bank remains responsible for understanding how the model is used in its own decisions.
Independent validation provides effective challenge
Validation examines the design, data, implementation, performance and limitations of a model. Effective challenge means reviewers have enough independence, skill and authority to question assumptions and require changes.
Validation is not a one-time approval. Models need ongoing performance monitoring, outcome analysis and review when products, customers, data or operating conditions change.
Not every AI system falls under the same guidance
The Federal Reserve’s revised 2026 model-risk guidance applies to traditional statistical and quantitative models, including non-generative and non-agentic AI models. It expressly excludes generative AI and agentic AI from that guidance’s scope.
That exclusion does not mean those systems are risk-free or ungoverned. Banks still need controls appropriate to their use, including data protection, testing, human oversight, cybersecurity, third-party management and accountability.
The control framework should follow the use case
The same technology can create very different risks depending on whether it summarizes internal documents, flags possible fraud or influences a customer decision. Governance should consider purpose, autonomy, data sensitivity, reversibility and potential harm.
The practical question is not only whether a system is called a model or AI. It is what the system does, how its output is used and which controls are needed for that level of risk.
Read the primary material
Banking Explained prioritizes regulators, official publications and first-party announcements.
