A capital markets bank is, in many respects, a model-dependent institution. Pricing models value complex derivatives. Risk models calculate sensitivities, VaR, and capital requirements. Credit models estimate counterparty default probabilities. XVA models determine the funding, credit, and capital adjustments embedded in derivative prices. When these models are wrong — when they are based on flawed assumptions, implemented incorrectly, or used outside their intended scope — the consequences can be severe and rapid. Model risk governance exists to identify, measure, and mitigate this risk.
What Is Model Risk
Model risk is defined as the risk of adverse consequences arising from decisions based on incorrect or misused models. The US Federal Reserve's SR 11-7 guidance — the most influential regulatory statement on model risk management — defines a model as a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories or techniques to transform input data into quantitative estimates. This definition is deliberately broad: it captures not just the sophisticated Black-Scholes variants used to price exotic options, but also spreadsheet-based calculations used in regulatory reporting and simpler tools used in risk management.
The consequences of model failure are well-documented in financial history. The London Whale episode at JPMorgan Chase in 2012 involved a credit risk model that significantly understated the risk of a large synthetic credit portfolio; the CIO desk accumulated a position far larger than its measured risk metrics suggested was appropriate, ultimately crystallising losses of over $6 billion. Knight Capital's 2012 failure — losing $440 million in 45 minutes — resulted from an algorithm deployed in production without adequate testing, not strictly a model validation failure but a close analogue: a quantitative tool causing catastrophic losses because it was not fit for purpose in the context it was used.
The Model Inventory
Model risk management begins with knowing what models the firm uses. A model inventory is the complete, maintained list of all models in scope — their owners, their purpose, the products or processes they support, when they were last validated, and their current validation status. In a large capital markets bank, the model inventory can contain hundreds or thousands of models, ranging from the core interest rate derivatives pricing library to bespoke spreadsheets used for specific regulatory calculations.
Maintaining the inventory requires active governance. New models must be registered before use. Changes to existing models — even apparently minor parameter changes — must be captured. Retired models must be decommissioned from the inventory. The inventory is typically owned by the Model Risk Management (MRM) function, a second-line team independent of the trading and risk teams that use the models.
Independent Validation
The core of model risk management is independent validation: an assessment of a model by people who did not build it, conducted before the model is used in production and periodically thereafter. SR 11-7 requires that validation be conducted by staff with the appropriate technical skills who are independent of the model development function. Independence is essential — a developer validating their own model is not validation, it is review.
A full model validation typically comprises four components:
Conceptual Soundness
The validator assesses whether the model's theoretical foundations are appropriate for its intended purpose. For a derivatives pricing model, this means evaluating whether the underlying stochastic process (e.g., the interest rate model, the volatility surface specification) is theoretically sound, whether the model's assumptions are reasonable given the market it is applied to, and whether the numerical implementation of the mathematics is correct. Conceptual soundness review requires the validator to have deep technical knowledge — a reviewer who does not understand the mathematics cannot assess whether the mathematics is appropriate.
Back-Testing
Back-testing assesses whether the model's predictions are consistent with historical outcomes. For a pricing model, this might involve comparing the model's predicted prices against observed market prices for comparable instruments over a historical period. For a risk model, it involves comparing predicted losses (e.g., VaR forecasts) against actual P&L outturns. Statistical tests — chi-squared tests, traffic light tests of VaR exception counts — provide objective criteria for assessing model performance.
Benchmarking
Benchmarking compares the model's outputs against an independent alternative — a different model, a market consensus, or a simplified analytical approximation. If the primary pricing model produces significantly different prices from a benchmark, the validator must explain why. Persistent, unexplained divergences between the primary model and its benchmark are a red flag that warrants deeper investigation.
Sensitivity Analysis
Sensitivity analysis tests how the model's outputs respond to changes in its inputs and parameters. A well-behaved model should produce outputs that respond smoothly and in an economically intuitive direction to changes in market inputs. Instability — outputs that change discontinuously, or that respond in counterintuitive ways to parameter changes — indicates potential model errors or inappropriate parameterisation.
Model Limitations and the Model Use Statement
No model is perfect. Every model involves simplifying assumptions, operates within a range of conditions under which it is reliable, and produces estimates that are subject to uncertainty. A key output of the validation process is the articulation of model limitations — the conditions under which the model may produce unreliable results and the risks that are not captured by the model's framework.
These limitations must be communicated to model users. SR 11-7 requires that model users understand the model's purpose, limitations, and appropriate use. A trader who applies a model designed for vanilla interest rate derivatives to an exotic structured product is misusing the model — and the model risk governance framework must have controls to prevent this.
Where model limitations are material, the firm may apply model reserves — a valuation adjustment that reflects the uncertainty in the model's output. For regulatory capital purposes, model risk add-ons may be required where internal models are used and validation reveals significant uncertainties. The size of the model reserve is itself a quantitative judgment that requires governance and documentation.
Model Risk Appetite and Governance
The board sets the firm's model risk appetite — the level and types of model risk it is willing to accept in pursuit of its business objectives. This appetite is expressed in the model risk policy (which specifies validation requirements, approval thresholds, and escalation processes) and in quantitative statements about the maximum permissible size of model reserves and the coverage of the model inventory.
The Model Risk Committee (or equivalent governance body) oversees the model risk framework. It approves new models, reviews validation findings, escalates significant model failures, and monitors the inventory coverage and validation status. MRM reports to the CRO, and model risk is a standing item on the board risk committee's agenda.
Regulators assess model risk governance as part of their supervisory review of a bank's risk management. The ECB's Targeted Review of Internal Models (TRIM) — a multi-year supervisory assessment of the internal models used by European banks for capital purposes — found widespread deficiencies in model validation practices and imposed material capital add-ons on firms with inadequate governance. The PRA conducts similar assessments of UK firms. Model risk is no longer a purely internal concern; it is a regulatory focus with direct capital implications.