Model risk
Model risk
Model risk is the chance that a detection model, such as a transaction monitoring or screening model, performs poorly and produces incorrect or misleading outputs. In AML terms, that usually means missing genuine risk, generating excessive false positives, or both. US regulatory guidance, SR 11-7, frames it as risk that can arise even when a model is technically sound, if it’s poorly understood, poorly implemented, or over-relied upon.
Key takeaways
- Model risk is the chance a detection model performs poorly, even when it’s technically well built.
- US guidance SR 11-7 (Federal Reserve/OCC, 2011) is the reference framework most AML model risk programmes are built around.
- SR 11-7 rests on three pillars: sound development, independent validation, and board-level governance.
- “Effective challenge” means critical, independent review from people who can actually identify a model’s limitations.
- Common drivers include poor data quality, wrong assumptions at build time, and model drift as real-world behaviour shifts.
- Similar principles now shape supervisory expectations well beyond the US, including the Bank of England’s SS1/23.
On this page
What model risk actually isWhere model risk comes fromSR 11-7 and the three pillars of model risk managementWhat “effective challenge” means in practiceModel risk vs model validationManaging model risk in an AML programmeFAQsRead more
What model risk actually is
Model risk isn’t just the risk that a model has a coding error. It covers any way a model’s design, data, or use can lead to decisions that are wrong, whether that’s a monitoring system missing real laundering activity or a screening tool burying analysts in false positives.
Crucially, a model can be technically correct and still create model risk, if the people relying on it don’t understand its limitations or treat its output as more certain than it is.
Where model risk comes from
Common sources include poor-quality or incomplete input data, assumptions baked in at build time that no longer hold, and model drift, where the real-world behaviour a model was trained or calibrated on gradually shifts without the model being updated to match.
SR 11-7 and the three pillars of model risk management
SR 11-7, issued jointly by the Federal Reserve and the Office of the Comptroller of the Currency in April 2011, is the reference framework most US model risk programmes are built around, and its influence extends well beyond American banks. It rests on three pillars: sound model development and implementation, effective challenge through independent validation, and governance with clear board-level accountability.
What “effective challenge” means in practice
Effective challenge means critical, objective review by people who didn’t build the model and can genuinely identify its limitations and assumptions, not a rubber-stamp sign-off. It’s the mechanism through which model risk actually gets managed, rather than just documented.
Model risk vs model validation
Model validation is the practical activity that manages model risk. Model risk is the problem; validation is one of the main tools used to find and reduce it, alongside good governance and ongoing monitoring.
Managing model risk in an AML programme
A working programme keeps a full inventory of every model in use, assesses risk proportionate to how much weight a model carries in decision-making, and assigns clear governance and validation ownership independent of the team that built or runs the model day to day.
Frequently asked questions
What is model risk?
Model risk is the chance that a detection model performs poorly and produces incorrect or misleading outputs, whether that means missing genuine risk or generating excessive false positives. It can arise even in a technically sound model if it’s poorly understood or over-relied upon.
What is SR 11-7?
SR 11-7 is supervisory guidance on model risk management issued jointly by the Federal Reserve and the OCC in April 2011. It sets out expectations for model development, independent validation, and governance for US-regulated banks.
What does “effective challenge” mean?
Effective challenge means critical, independent review of a model by people who didn’t build it and can genuinely identify its limitations and assumptions, rather than a routine sign-off.
Is model risk only a US concept?
The term originates in US supervisory guidance, but the underlying principles now shape expectations well beyond the US, including frameworks such as the Bank of England’s SS1/23.
How is model risk different from model validation?
Model risk is the underlying problem: the chance a model performs poorly. Model validation is one of the main tools used to identify and reduce that risk through independent testing.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 5 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Model risk is the chance that a detection model, such as a transaction monitoring or screening model, performs poorly and produces incorrect or misleading outputs. In AML terms, that usually means missing genuine risk, generating excessive false positives, or both. US regulatory guidance, SR 11-7, frames it as risk that can arise even when a model is technically sound, if it’s poorly understood, poorly implemented, or over-relied upon.