← Frameworks / Model Risk Management

PRA Supervisory Statement SS1/23 — Model Risk Management

UK Prudential Regulation Authority supervisory statement setting expectations for model risk management at banks, building societies, and PRA-designated investment firms. 5 principles covering model identification and classification, governance (board accountability, model risk committee, independent validation), model development and implementation (documentation, testing, performance monitoring), model use and ongoing monitoring, and risk mitigation and reporting. Effective 17 May 2024 with proportionate application.

Clause Title SP 800-53 Controls
P-IT.1 Access controls on model code, parameters, and execution environments
P-IT.2 Audit trails of model runs, parameter changes, and approvals
P-IT.3 IT infrastructure supporting model execution environments
P1.1 Model identification and model inventory
P1.2 Model risk classification and tiering
P1.3 Scope and definition of models subject to MRM framework
P2.1 Board and senior management accountability for MRM
P2.2 Three lines of defence for model risk management
P2.3 MRM policy, standards, and procedures
P2.4 Roles and responsibilities — model owners, developers, validators, users
P3.1 Model development standards and documentation
P3.2 Data quality and integrity for model inputs
P3.3 Model implementation controls — code review, testing, version control
P3.4 Model change management
P3.5 Model limitations and assumptions documentation
P3.6 Model use — ensuring models used within intended purpose
P4.1 Independent model validation — scope, frequency, and depth
P4.2 Challenger models and benchmarking
P4.3 Validation of model inputs, processing, and outputs
P4.4 Post-model adjustments and expert overlays governance
P4.5 Validation findings tracking and remediation
P5.1 Compensating controls for model limitations
P5.2 Model performance monitoring — backtesting and outcome analysis
P5.3 Escalation and early warning indicators
P5.4 Stress testing of models
P5.5 Model retirement and decommissioning