Model validation
Model validation
Model validation is the independent testing of a detection model, checking that it works as intended and performs well on real data, both before it goes live and on an ongoing basis afterward. It’s the practical mechanism through which a firm delivers the “effective challenge” that regulatory guidance such as SR 11-7 expects. Validation is carried out by people who didn’t build the model, not the model’s own developers.
Key takeaways
- Model validation is independent testing, not a self-check by the team that built the model.
- SR 11-7 frames validation around three elements: conceptual soundness, ongoing monitoring, and outcomes analysis.
- Above-the-line testing checks the alerts a system did generate; below-the-line testing checks the transactions it didn’t flag.
- Below-the-line testing is how firms catch false negatives a pure alert review would never surface.
- Validation should happen before a model goes live and periodically afterward, not as a one-off exercise.
- Weak or missing validation is a recurring theme in AML enforcement findings tied to transaction monitoring failures.
On this page
What model validation actually checksWhy validation has to be independentThe three core elements of validationAbove-the-line and below-the-line testingValidation before launch vs ongoing validationWhat weak validation looks like to a regulatorFAQsRead more
What model validation actually checks
Validation asks three related questions: is the model’s underlying logic sound, does it keep performing as expected once it’s running, and do its actual outputs match what really happened when checked against real transactions and outcomes.
Why validation has to be independent
A team that built a model has a natural blind spot toward its own assumptions. Independent validators, people or teams separate from development, are far more likely to catch flaws the builders talked themselves past, which is why SR 11-7 treats independence as a core requirement, not a nice-to-have.
The three core elements of validation
Regulatory guidance frames validation around three elements: conceptual soundness, reviewing the theory and logic behind the model’s design; ongoing monitoring, checking the model keeps performing as intended over time; and outcomes analysis, comparing what the model predicted against what actually happened.
Above-the-line and below-the-line testing
Above-the-line testing reviews the alerts a monitoring system actually generated, checking whether they were accurate and well-calibrated. Below-the-line testing does the opposite: it samples transactions the system did not flag, to check whether genuine risk slipped through unnoticed. Both matter. A validation that only looks at generated alerts can look thorough while still missing the risk a below-the-line sample would catch.
Validation before launch vs ongoing validation
A model needs validating before it goes live, to catch design flaws before they affect real decisions, and periodically afterward, since data patterns and criminal behaviour both shift over time. A model validated once at launch and never revisited is a common finding in AML enforcement actions tied to transaction monitoring failures.
What weak validation looks like to a regulator
Supervisors typically flag validation that’s performed by the same team that built the model, validation that only reviews above-the-line alerts, and validation documentation that can’t show what was actually tested or when it was last refreshed.
Frequently asked questions
What is model validation?
Model validation is the independent testing of a detection model, checking that it works as intended on real data, both before it goes live and periodically afterward.
Who should perform model validation?
Validation should be carried out by people or teams independent of whoever built and runs the model day to day, so they can identify flaws without the blind spots that come from having built it themselves.
How often should a model be validated?
A model should be validated before it goes live and then periodically afterward, since data patterns and the behaviour a model is trying to detect both change over time.
What is above-the-line testing?
Above-the-line testing reviews the alerts a monitoring system actually generated, checking whether they were accurate and well-calibrated.
What is below-the-line testing?
Below-the-line testing samples transactions the system did not flag, checking whether genuine risk slipped through unnoticed. It’s the main way firms catch false negatives.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 5 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Model validation is the independent testing of a detection model, checking that it works as intended and performs well on real data, both before it goes live and on an ongoing basis afterward. It’s the practical mechanism through which a firm delivers the “effective challenge” that regulatory guidance such as SR 11-7 expects. Validation is carried out by people who didn’t build the model, not the model’s own developers.