Where AI-driven decisioning meets model risk management
Banks have run a formal model risk management discipline for over a decade under supervisory guidance like SR 11-7: every model — including, now, AI and machine learning models used for credit decisioning, fraud detection, and trading — is expected to sit in an inventory, be independently validated, and be subject to "effective challenge" from people who didn't build it. That structure already exists in most regulated institutions. What AIC maps is whether an AI-assisted decision has actually been run through that structure, honestly, or just labelled as if it had.
What AIC maps, and against what
AIC maps AI-driven decisioning in financial services against the model risk management discipline institutions are already expected to run — model inventory, independent validation, and governance — applied specifically to AI and machine learning models used in credit, fraud, and trading decisions. This is a governance mapping, not a substitute for regulatory model validation or a bank's own SR 11-7 programme.
The established concept, and its AI equivalent
| Established | AI equivalent | What it means here |
|---|---|---|
| Model inventory | AI/ML model inventory | Every AI model used in a consequential decision is logged, tracked, and known to exist — not shadow-deployed. |
| Effective challenge | Independent AI validation | Critical review of an AI model by technically competent people who didn't build it, empowered to flag it. |
| Back-testing / outcomes analysis | Ongoing AI performance monitoring | The model's real-world outcomes are checked against what it predicted, on an ongoing basis, not just at launch. |
| Conceptual soundness review | AI development documentation | The reasoning and evidence behind why the model should work is documented, not just the fact that it does. |
| Governance & policy ownership | Named accountable owner | A specific, accountable person or function owns the AI model's use in the decision — consistent with AIC's named-human-accountability principle. |
The safety measures a subject demonstrates
Model inventory entry
The AI system is logged as a model, with its purpose, scope, and owner documented — not deployed informally.
Independent validation function
Someone outside the model's development team has reviewed and challenged it before and after deployment.
Documented conceptual soundness
There is a written basis for why the model is expected to perform as intended, reviewable by a third party.
Ongoing monitoring and back-testing
Model outcomes are tracked against predictions on a continuing basis, with a defined escalation path when they diverge.
Named accountable owner
A specific individual, not a committee or vendor, is accountable for the AI-assisted decision's governance.
Where this mapping has limits
SR 11-7 was written in 2011, before modern generative and agentic AI existed, and its application to those systems is still actively being worked out by supervisors — the "Minimum Viable Governance" concept referenced by regulators in 2026 is an emerging extension, not settled guidance. SR 11-7 is also US-centric; Basel III operates at the international capital-adequacy level and doesn't itself specify AI model governance in the same detail, and other jurisdictions (the EU, UK, South Africa) apply different supervisory expectations. AIC's mapping draws on the SR 11-7 structure as the clearest, most established reference point available, not as a claim that it is the universal or final standard for AI model risk.
Reviewed 2026-09-01.