Chapter 3 Study Guide

Model Risk Regulations and Guidance in the United States, European Union, and United Kingdom

Use this guide to see the chapter as one story: financial innovation increased model use; crises exposed model risk; regulation evolved; SR 11-7 (SR 26-2) became the organizing framework for modern MRM.

Regulatory history SR 11-7 (SR 26-2) OCC 2011-12 PRA SS1/23 ECB EGIM / TRIM EBA NIST AI RMF

1. The chapter in one picture

Financial innovation
More models
Model failures
Assumptions & misuse
Financial crises
Losses become systemic
Regulatory response
Validation & governance
Modern MRM
SR 11-7 (SR 26-2) + global frameworks
Key idea: MRM regulation grew incrementally. It did not begin with one rule; it matured as institutions and supervisors learned from real model failures.

2. From model innovation to model-risk regulation

Focus on the lesson learned from each event, not on memorizing dates.

1973 · Black-Scholes
Models become central to modern finance.
Lesson: assumptions matter.
1987 · Black Monday
Portfolio insurance magnifies market stress.
Lesson: liquidity, feedback loops, tail risk.
1994 · Orange County
Leverage + model dependence + weak governance.
Lesson: model use and governance matter.
1998 · LTCM
Sophisticated models fail under stress and leverage.
Lesson: validation and stress testing.
2004–05 · Basel II / BCBS
Internal models become embedded in regulatory capital.
Lesson: validation becomes supervisory infrastructure.
2008–09 · GFC
Structured-credit models underestimate correlated defaults and tail risk.
Lesson: model failure can become systemic.
2011 · SR 11-7 (SR 26-2)
MRM becomes a formal enterprise discipline.
Lesson: govern the whole model lifecycle.
2020s · AI / ML / GenAI
Model scope expands again.
Lesson: MRM must remain dynamic.

3. Why SR 11-7 (SR 26-2) is the anchor of modern MRM

Before

Guidance existed around specific model types, capital models, validation, and supervisory review, but MRM was not yet organized as one coherent enterprise framework.

After

SR 11-7 (SR 26-2) organizes model risk around the full lifecycle: development, implementation, use, validation, monitoring, governance, documentation, issues, and oversight.

1. GovernanceBoard, senior management, policies, accountability
2. Development & UseSound design, implementation, fit-for-purpose use
3. ValidationIndependent, objective, risk-based challenge
4. MonitoringPerformance, outcomes, changes, limitations
5. Inventory & DocumentationKnow what models exist and how they are controlled
SR 26-2 update: The chapter presents SR 26-2 as evolutionary rather than revolutionary: it preserves the architecture of SR 11-7 (SR 26-2), while making the framework more explicitly risk-based, tailored, and proportionate. It also gives greater clarity on model-risk drivers, materiality, scope, monitoring flexibility, and exclusions.

4. US, UK, and EU: same destination, different routes

All three seek safer model use and stronger governance, but they emphasize different dimensions of control.

DimensionUnited StatesUnited KingdomEuropean Union
Core frameworkSR 11-7 (SR 26-2) / OCC 2011-12PRA SS1/23ECB EGIM / TRIM, EBA, CRR / CRD
ScopeBroad model universeBroad enterprise MRM for large firmsStrongest focus on regulatory capital models
Signature strengthLifecycle governance + independent validationBoard accountability + model risk appetiteTechnical scrutiny + model approval
Regulatory stylePrinciples + supervisory guidancePrinciples-based supervisory expectationsPrescriptive technical review
Student memory aidEnterprise frameworkTop-down ownershipTechnical rigor
Compare, do not isolate: the frameworks differ in scope and emphasis, but converge on governance, validation, documentation, lifecycle control, and accountability.

5. The impact of SR 11-7 (SR 26-2)

MRM became enterprise risk

Model risk moved beyond a technical validation issue and became part of institutional risk governance and board oversight.

Three Lines became operational

Development/business ownership, independent risk challenge, and internal audit gained distinct responsibilities and escalation paths.

Validation became independent

Conceptual soundness, monitoring, outcomes analysis, benchmarking, limitations, and effective challenge became standard expectations.

Lifecycle governance became standard

Models are controlled from development through use, monitoring, change, remediation, and retirement.

Inventory and tiering became core controls

Institutions need a centralized inventory, ownership, validation status, materiality, and risk-based prioritization.

Global practice changed

The chapter treats the US framework as a global benchmark whose ideas are echoed in UK and EU practice.

6. Four cases — four regulatory lessons

Black Monday

What failed? Assumptions about normal markets, liquidity, and feedback effects.

MRM lesson: stress testing, assumption testing, tail risk.

Orange County

What failed? Overreliance on leveraged strategies and weak model-risk governance.

MRM lesson: user understanding, governance, limits.

LTCM

What failed? Sophisticated models used with extreme leverage under stressed market conditions.

MRM lesson: independent validation, stress testing, model misuse.

Subprime CDO crisis

What failed? Correlation, tail, housing, and diversification assumptions.

MRM lesson: conceptual soundness, data, validation, systemic model risk.

7. Classroom activities

10-minute group exercise: Build the regulation

Divide the class into four groups. Give each group one case: Black Monday, Orange County, LTCM, or Subprime CDOs. Ask:

  1. What went wrong?
  2. Was the problem model design, model use, governance—or several?
  3. Which SR 11-7 (SR 26-2) control would have helped?
Boardroom exercise

You are the board risk committee of a global bank. Your US, UK, and EU regulators examine the same model.

Which regulator is most likely to focus on enterprise governance, board accountability, or technical model approval?

8. Think → Test → Apply

Think

Why did modern MRM emerge after decades of successful quantitative finance?

Because greater model use increased both benefits and exposure to model errors, misuse, common assumptions, and correlated failures. Repeated crises made the risk visible.

Why is a mathematically correct model still capable of creating model risk?

Because the model can be used outside its intended purpose, under conditions where assumptions fail, or with poor governance, data, implementation, or controls.

Why does the chapter treat SR 11-7 (SR 26-2) as foundational?

Because it organizes MRM as an end-to-end enterprise discipline rather than a narrow model-validation exercise.

Test

1. Which statement best describes SR 11-7 (SR 26-2)?

2. Which comparison is closest to the chapter?

Apply

Jupyter idea: Regulation timeline

Create a timeline linking each crisis to the MRM control it helped motivate: stress testing, validation, governance, monitoring, or documentation.

Jupyter idea: US / UK / EU matrix

Code a simple comparison matrix for scope, validation rigor, governance, model risk appetite, technical scrutiny, and enforcement.