Model risk

Model risk

Model risk

Model risk

Model risk is the chance that a detection model, such as a transaction monitoring or screening model, performs poorly and produces incorrect or misleading outputs. In AML terms, that usually means missing genuine risk, generating excessive false positives, or both. US regulatory guidance, SR 11-7, frames it as risk that can arise even when a model is technically sound, if it’s poorly understood, poorly implemented, or over-relied upon.

Key takeaways

  • Model risk is the chance a detection model performs poorly, even when it’s technically well built.
  • US guidance SR 11-7 (Federal Reserve/OCC, 2011) is the reference framework most AML model risk programmes are built around.
  • SR 11-7 rests on three pillars: sound development, independent validation, and board-level governance.
  • “Effective challenge” means critical, independent review from people who can actually identify a model’s limitations.
  • Common drivers include poor data quality, wrong assumptions at build time, and model drift as real-world behaviour shifts.
  • Similar principles now shape supervisory expectations well beyond the US, including the Bank of England’s SS1/23.

What model risk actually is

Model risk isn’t just the risk that a model has a coding error. It covers any way a model’s design, data, or use can lead to decisions that are wrong, whether that’s a monitoring system missing real laundering activity or a screening tool burying analysts in false positives.

Crucially, a model can be technically correct and still create model risk, if the people relying on it don’t understand its limitations or treat its output as more certain than it is.

Where model risk comes from

Common sources include poor-quality or incomplete input data, assumptions baked in at build time that no longer hold, and model drift, where the real-world behaviour a model was trained or calibrated on gradually shifts without the model being updated to match.

SR 11-7 and the three pillars of model risk management

SR 11-7, issued jointly by the Federal Reserve and the Office of the Comptroller of the Currency in April 2011, is the reference framework most US model risk programmes are built around, and its influence extends well beyond American banks. It rests on three pillars: sound model development and implementation, effective challenge through independent validation, and governance with clear board-level accountability.

Worth knowing. Even a technically accurate model can create material risk if governance is weak or a team places too much trust in its output without independent challenge. SR 11-7 treats that overreliance as a risk in its own right, not just a technical flaw.

What “effective challenge” means in practice

Effective challenge means critical, objective review by people who didn’t build the model and can genuinely identify its limitations and assumptions, not a rubber-stamp sign-off. It’s the mechanism through which model risk actually gets managed, rather than just documented.

Model risk vs model validation

Model validation is the practical activity that manages model risk. Model risk is the problem; validation is one of the main tools used to find and reduce it, alongside good governance and ongoing monitoring.

Managing model risk in an AML programme

A working programme keeps a full inventory of every model in use, assesses risk proportionate to how much weight a model carries in decision-making, and assigns clear governance and validation ownership independent of the team that built or runs the model day to day.

Frequently asked questions

What is model risk?

Model risk is the chance that a detection model performs poorly and produces incorrect or misleading outputs, whether that means missing genuine risk or generating excessive false positives. It can arise even in a technically sound model if it’s poorly understood or over-relied upon.

What is SR 11-7?

SR 11-7 is supervisory guidance on model risk management issued jointly by the Federal Reserve and the OCC in April 2011. It sets out expectations for model development, independent validation, and governance for US-regulated banks.

What does “effective challenge” mean?

Effective challenge means critical, independent review of a model by people who didn’t build it and can genuinely identify its limitations and assumptions, rather than a routine sign-off.

Is model risk only a US concept?

The term originates in US supervisory guidance, but the underlying principles now shape expectations well beyond the US, including frameworks such as the Bank of England’s SS1/23.

How is model risk different from model validation?

Model risk is the underlying problem: the chance a model performs poorly. Model validation is one of the main tools used to identify and reduce that risk through independent testing.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 19, 2026 · 5 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: Model risk is the chance that a detection model, such as a transaction monitoring or screening model, performs poorly and produces incorrect or misleading outputs. In AML terms, that usually means missing genuine risk, generating excessive false positives, or both. US regulatory guidance, SR 11-7, frames it as risk that can arise even when a model is technically sound, if it’s poorly understood, poorly implemented, or over-relied upon.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.