Law / United Arab Emirates

Model Management Standards: governance, validation and monitoring of the models a bank uses to decide, including artificial intelligence models

Model Management Standards

In force.

An AI sector rules rule binding private bodies.

Enforcement body
Central Bank of the UAE
Instrument type
a regulation made under an act
Obligation class
Governance
Audit expectation
periodic
Who audits it
Internal independent, Independent third party, Self
Where the report goes
Kept, Filed with regulator

As of .

What it requires

  • It reaches you if you are a bank licensed by the Central Bank of the UAE, including an Islamic bank and a UAE branch or subsidiary of a foreign bank, and you employ models to support decision-making, a scope that the Standards say covers all types of models and lists in Table 1 with Artificial Intelligence among the commonly employed model types (Sections 2.1 and 2.4): define a comprehensive model management framework that covers all models used to make decisions, and incorporate Model Risk in your risk framework so that it is identified, measured, monitored, reported and mitigated through a formal process (Sections 3.1.2 and 3.1.3).
  • Establish a Model Oversight Committee accountable for all significant modelling decisions at each step of the model life-cycle, with the Board bearing responsibility for modelling decisions with material implications and defining your appetite for Model Risk (Sections 3.1.6 and 3.1.8(i)).
  • Take responsibility for all modelling decisions, model outputs and related financial consequences, even if third parties are involved (Section 3.1.10).
  • Establish a clear, approved and controlled policy to govern overrides of model results, which applies to all models (Section 3.5.3).
  • Monitor the performance of your models on a regular basis, present monitoring reports to the Model Oversight Committee at least every quarter, and follow a clear process in which that Committee decides whether to continue using a model with further monitoring or to suspend it and work on remediation (Sections 3.6.1, 3.6.4 and 3.6.7).
  • Validate all your models independently on a regular basis based on model type, with a validation that excludes the development team from the assessment of the model, that does not report to the business lines, and that covers both a qualitative and a quantitative validation (Sections 3.7.1, 3.7.5 and 3.7.7).
  • Document, record, track and report validation findings across all models to Senior Management and the Board at least once a year (Section 3.7.9).
  • Have your internal audit function assess the regulatory compliance and the overall effectiveness of the model management framework as part of its regular auditing process (Section 3.1.9).

If you get it wrong

Penalty structure

Article 137(1) of the Central Bank Law lets the Central Bank, on establishment of a violation of the standards it issues in implementation of the Law, impose one or more sanctions on a Licensed Financial Institution, including a fine not exceeding AED 200,000,000, a fine of one to ten times the unjust enrichment, and withdrawal of the license.

Rule
Fixed only
As of
Currency
AED
Fixed cap
200,000,000

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

The Model Management Standards of the Central Bank of the UAE and the accompanying Model Management Guidance apply to all licensed banks in the UAE, which they call institutions, and the scope covers Islamic institutions. The Standards state that UAE branches or subsidiaries of foreign institutions must at a minimum apply them.

The Standards state that, throughout the document, the requirements associated with must are mandatory, while those associated with should are strongly recommended as robust modelling practice. The Standards apply to all types of models employed by institutions to support decision-making, and Table 1 of the Standards, a non-exhaustive list of the most commonly employed model types in UAE institutions, includes Artificial Intelligence.

The Standards state that they are effective one day after their publication date. The Standards require all institutions to submit the outcome of a self-assessment of the gaps between their practice and the Standards, and the plan to meet the requirements, to the CBUAE no later than six months from the effective date of the Standards.

The Standards state that institutions which repeatedly fall short of the requirements and do not demonstrate continuous improvement will face greater scrutiny and could be subject to formal enforcement action by the CBUAE.

Article 137 of the Central Bank Law provides that, on establishment of a violation by a Licensed Financial Institution of the regulations, decisions, rules, standards or instructions issued by the Central Bank in implementation of the Law, the Central Bank decides at its own discretion to impose one or more sanctions, which include a fine on the violating Licensed Financial Institution not exceeding 200,000,000 Dirhams.

The Standards require institutions to define a comprehensive model management framework to ensure that models are used effectively for decision-making and that Model Risk is appropriately understood and mitigated, covering all models used to make decisions within the institution. The Standards require Model Risk to be incorporated in the risk framework of institutions and managed through a formal process that identifies, measures, monitors, reports and mitigates this risk.

The Standards require institutions to establish a Model Oversight Committee accountable for all significant modelling decisions related to each step of the model life-cycle. The Standards state that the Board bears the responsibility of all modelling decisions with material implications for the institution and must define the appetite of the institution for Model Risk.

The Standards require institutions to take responsibility for all modelling decisions, model outputs and related financial consequences, even if third parties are involved. The Standards require the internal audit function to assess the regulatory compliance and the overall effectiveness of the model management framework as part of its regular auditing process.

The Standards require institutions to establish a clear, approved and controlled policy to govern overrides of model results, and the requirement applies to all models. The Standards require institutions to implement a process to monitor the performance of their models on a regular basis, and to present monitoring reports to the Model Oversight Committee on a regular basis, at least every quarter.

The Standards state that, on the production of monitoring reports, a clear process must be followed to decide whether to continue using a model with further monitoring or suspend it and work on remediation, and that the Model Oversight Committee must make this decision. The Standards require institutions to implement a process to validate independently all their models on a regular basis based on model types.

The Standards state that validation must be independent by virtue of excluding the development team from involvement in the assessment of the model, and that validation teams must not report to the business lines. The Standards state that the validation scope must cover both a qualitative validation and a quantitative validation. The Standards require validation findings across all models to be documented, recorded, tracked and reported to Senior Management and the Board at least once a year.

When LexLint raises it

When your app profile says your app provides financial services or makes high-risk automated decisions.

Back to the example  ·  Lint your app