Model validation

Model validation

Model validation

Model validation

Model validation is the independent testing of a detection model, checking that it works as intended and performs well on real data, both before it goes live and on an ongoing basis afterward. It’s the practical mechanism through which a firm delivers the “effective challenge” that regulatory guidance such as SR 11-7 expects. Validation is carried out by people who didn’t build the model, not the model’s own developers.

Key takeaways

  • Model validation is independent testing, not a self-check by the team that built the model.
  • SR 11-7 frames validation around three elements: conceptual soundness, ongoing monitoring, and outcomes analysis.
  • Above-the-line testing checks the alerts a system did generate; below-the-line testing checks the transactions it didn’t flag.
  • Below-the-line testing is how firms catch false negatives a pure alert review would never surface.
  • Validation should happen before a model goes live and periodically afterward, not as a one-off exercise.
  • Weak or missing validation is a recurring theme in AML enforcement findings tied to transaction monitoring failures.

What model validation actually checks

Validation asks three related questions: is the model’s underlying logic sound, does it keep performing as expected once it’s running, and do its actual outputs match what really happened when checked against real transactions and outcomes.

Why validation has to be independent

A team that built a model has a natural blind spot toward its own assumptions. Independent validators, people or teams separate from development, are far more likely to catch flaws the builders talked themselves past, which is why SR 11-7 treats independence as a core requirement, not a nice-to-have.

The three core elements of validation

Regulatory guidance frames validation around three elements: conceptual soundness, reviewing the theory and logic behind the model’s design; ongoing monitoring, checking the model keeps performing as intended over time; and outcomes analysis, comparing what the model predicted against what actually happened.

Above-the-line and below-the-line testing

Above-the-line testing reviews the alerts a monitoring system actually generated, checking whether they were accurate and well-calibrated. Below-the-line testing does the opposite: it samples transactions the system did not flag, to check whether genuine risk slipped through unnoticed. Both matter. A validation that only looks at generated alerts can look thorough while still missing the risk a below-the-line sample would catch.

Worth knowing. Below-the-line testing, sampling transactions the system never flagged, is the only reliable way to catch false negatives. A validation exercise that only reviews generated alerts can look thorough while still missing the risk that matters most.

Validation before launch vs ongoing validation

A model needs validating before it goes live, to catch design flaws before they affect real decisions, and periodically afterward, since data patterns and criminal behaviour both shift over time. A model validated once at launch and never revisited is a common finding in AML enforcement actions tied to transaction monitoring failures.

What weak validation looks like to a regulator

Supervisors typically flag validation that’s performed by the same team that built the model, validation that only reviews above-the-line alerts, and validation documentation that can’t show what was actually tested or when it was last refreshed.

Frequently asked questions

What is model validation?

Model validation is the independent testing of a detection model, checking that it works as intended on real data, both before it goes live and periodically afterward.

Who should perform model validation?

Validation should be carried out by people or teams independent of whoever built and runs the model day to day, so they can identify flaws without the blind spots that come from having built it themselves.

How often should a model be validated?

A model should be validated before it goes live and then periodically afterward, since data patterns and the behaviour a model is trying to detect both change over time.

What is above-the-line testing?

Above-the-line testing reviews the alerts a monitoring system actually generated, checking whether they were accurate and well-calibrated.

What is below-the-line testing?

Below-the-line testing samples transactions the system did not flag, checking whether genuine risk slipped through unnoticed. It’s the main way firms catch false negatives.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 19, 2026 · 5 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: Model validation is the independent testing of a detection model, checking that it works as intended and performs well on real data, both before it goes live and on an ongoing basis afterward. It’s the practical mechanism through which a firm delivers the “effective challenge” that regulatory guidance such as SR 11-7 expects. Validation is carried out by people who didn’t build the model, not the model’s own developers.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.