Law / United Kingdom

Model risk management principles for banks

PRA Supervisory Statement SS1/23

Guidance, not a law: the Prudential Regulation Authority's reading of Fundamental Rule 5: effective risk strategies and risk management systems. It binds nobody by itself; the law it reads does.

Guidance on an AI sector rules rule, addressed to private bodies.

Criminal exposure
No
Private right of action
No
Instrument type
guidance published by a regulator
Obligation class
Governance
Audit expectation
periodic
Who audits it
Internal independent, Self
Where the report goes
Produced on request

As of .

What the regulator expects

  • It reaches you if you are a UK-incorporated bank, building society or PRA-designated investment firm with permission to use an internal model to calculate regulatory capital requirements for credit risk, market risk or counterparty credit risk. The PRA says the expectations do not apply to a firm without that permission or to a third-country firm operating in the UK through a branch, though such a firm may find the principles useful, and credit unions, insurers and reinsurers are not in scope. The statement sets out expectations and no rule of its own, so each line below states what the PRA expects of a firm.
  • Adopt the statement's definition of a model as the scope of your model risk management framework, keep a complete and accurate firm-wide inventory of models in use, under development and decommissioned, and assign each model a risk-based tier by materiality and complexity, considering where necessary alternative and unstructured data and the model's interpretability, explainability, transparency and potential for designer or data bias (Principle 1).
  • Have the board approve the model risk management policy, set a model risk appetite and receive regular reports on the firm's model risk profile against it, allocate responsibility for the framework to the relevant Senior Management Function holder or holders and reflect it in their Statements of Responsibilities, document roles and responsibilities for each stage of the model lifecycle, and, for third-party vendor models, satisfy yourself that they have been validated to the same standards as your own and validate your own use of them (Principle 2).
  • Have Internal Audit periodically assess the effectiveness of the framework across the model lifecycle and compliance with internal policies, and report its findings to the board and relevant committees on a timely basis (Principle 2.5).
  • Develop models under documented standards: a clear statement of purpose and design objectives, development data shown to be suitable, representative and free of inappropriate bias and used in compliance with data privacy and other relevant data regulations, development testing against the design objectives including for material changes in dynamic models that adapt, recalibrate or change autonomously, justified and recorded expert-judgement adjustments, and documentation detailed enough for an independent third party to understand and replicate the model (Principle 3).
  • Have a validation function that gives an objective, unbiased and critical opinion on models and operates independently from model development and from model owners, demonstrated through separate reporting lines if you have approval to use internal models for regulatory capital; subject all models to independent review, monitor model performance against thresholds and revalidate periodically at a frequency set by model tier (Principle 4).
  • Have established policies and procedures for model risk mitigants when models under-perform: a consistent firm-wide process for post-model adjustments with independent review of all of them, consideration of restrictions on a model's use when significant deficiencies are found, and, for material models, defined exceptions and escalation procedures (Principle 5).
  • Make a report on the effectiveness of model risk management for financial reporting available to the audit committee on a regular basis, and at least annually, and on a timely basis for the external auditor's assessment (paragraph 3.8).
  • Conduct a self-assessment of your framework against the principles, update it at least annually, prepare remediation plans for shortfalls and review them regularly, document both and share them with the board, and be able to provide them to the PRA on request, though you are not expected to share them with it routinely (paragraphs 1.6 to 1.8).

Who enforces it

Enforcement body

Prudential Regulation Authority, as supervisor of the firms the statement reaches. The statement carries no enforcement action of its own.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Supervisory Statement 1/23, Model risk management principles for banks, sets out the Prudential Regulation Authority's expectations for banks' management of model risk. It is relevant to all regulated UK-incorporated banks, building societies and PRA-designated investment firms with internal model approval to calculate regulatory capital requirements.

Internal model approval here means approval to use internally developed models to calculate regulatory capital requirements for credit risk (Internal Ratings Based approaches), market risk (Internal Model Approach) or counterparty credit risk (Internal Model Method). The expectations do not apply to firms which do not have permission to use internal models to calculate regulatory capital, or to third-country firms operating in the UK through a branch.

The PRA says those firms may find the principles useful and are welcome to consider them to manage model risk within their firm. Credit unions, insurers and reinsurers are not in scope. The policy statement that published it says all firms regardless of size are already expected to manage the risks associated with models, as they would with any risk they are exposed to. The statement took effect on . The current version was published and took effect on .

That version clarifies that the expectations are not conditions for internal model approval. Firms that first receive permission to use an internal model to calculate regulatory capital have 12 months from the grant of that permission to comply. The PRA made that amendment without consultation because it considers that the amendment clarifies the existing policy and does not change it.

The statement rests on five principles: model identification and model risk classification, governance, model development, implementation and use, independent model validation, and model risk mitigants. It defines a model as a quantitative method that applies statistical, economic, financial or mathematical theories, techniques and assumptions to process input data into output, and the input and the output can be quantitative or qualitative.

Where deterministic quantitative methods such as decision-based rules or algorithms are not classified as models but have a material bearing on business decisions and are complex, firms should consider whether to apply the relevant aspects of the framework to them.

The PRA expects firms to identify and allocate responsibility for the model risk management framework to the relevant Senior Management Function holder or holders, and says firms should ensure those holders' Statements of Responsibilities are updated to reflect it.

The Bank of England's page for the statement says the principles support firms in identifying and managing the risks associated with the use of artificial intelligence in modelling techniques such as machine learning to the extent that it applies to the use of models more generally. The policy statement says the model definition is intended to bring recommendation systems in client services and other AI and machine learning that deliver qualitative output within the scope of the policy.

When rating a model's complexity, the statement says the assessment may also consider, where necessary, the use of alternative and unstructured data and measures of the model's interpretability, explainability, transparency and potential for designer or data bias. It expects model development testing for material changes in dynamic models, meaning models able to adapt, recalibrate or otherwise change autonomously in response to new inputs.

In October 2025 the PRA presented the statement as setting out principles-based expectations for all model types, including models that use artificial intelligence and machine learning. Self-assessments against the principles should be updated at least annually, and remediation plans should be reviewed and updated on a regular basis. Firms are not expected to share the remediation plans or self-assessment routinely with the PRA, but should be able to provide them upon request.

The statement sets no rule of its own: the PRA's page on its policy publications says supervisory statements do not set absolute requirements, which are contained in rules. The policy statement that published it refers to Fundamental Rule 5 in the Fundamental Rules Part of the PRA Rulebook in the same paragraph as its statement that all firms are already expected to manage the risks associated with models.

The policy statement also refers to the Risk Control Part of the PRA Rulebook, Risk Committee section, paragraph 3.1, where it says the risk committee plays an active role in advising on risk appetite and overseeing the implementation of that strategy.

Back to the example  ·  Lint your app