A regional bank's risk management team is onboarding a new ML-based credit scoring model. The Chief Risk Officer references SR 11-7 guidance and instructs the team to complete a formal model validation before deployment. According to the Federal Reserve's SR 11-7 guidance on model risk management, which of the following statements BEST describes the three-component framework for model validation?
Select an answer to reveal the explanation.
Short Explanation and Infographic
SR 11-7 is the rulebook every bank model has to pass through, and it's built on three legs: Does the math make sense? Is it performing as expected in the real world? Are the outcomes what we predicted? And critically — the people checking your model can't be the same people who built it. Independence isn't optional. Think of it like having an outside auditor review your financial statements — the Fed wants a real second set of eyes, not a rubber stamp from the developer's own team.
Full explanation below image
Full Explanation
The Federal Reserve's SR 11-7 (Supervisory Guidance on Model Risk Management, 2011) establishes the authoritative framework for managing risk from model use at financial institutions. It defines a three-component model validation process:
(1) Conceptual soundness: Evaluation of the model's theoretical foundation, methodology, and assumptions. For an ML credit scoring model, this includes assessing whether the chosen algorithm is appropriate for the prediction task, whether the feature set has economic rationale, and whether the training procedure avoids look-ahead bias or data leakage.
(2) Ongoing monitoring: Continuous tracking of model performance after deployment, including population stability indices (PSI) for input distributions, Gini coefficients and KS statistics for discriminatory power over time, and comparison of predicted vs. actual default rates across demographic and product segments.
(3) Outcomes analysis (backtesting): Periodic comparison of model-predicted outcomes with actual realized outcomes to detect model drift, regime changes, or systematic mis-estimation. For credit models, this includes vintage analysis of cohorts originated under the model.
Option A is incorrect because SR 11-7 is not limited to stress testing models, and it does not prescribe regulatory capital adequacy as a validation component. SR 11-7 applies broadly to any model used in business decision-making, risk management, or financial reporting.
Option C is incorrect because SR 11-7 does not set specific quantitative performance thresholds such as minimum AUC values. It mandates that institutions establish their own performance standards appropriate to the model's purpose and risk materiality.
Option D is critically incorrect. SR 11-7 explicitly covers a broad scope of models, stating: 'The guidance applies to any quantitative method, however simple or complex.' The OCC and Federal Reserve have issued subsequent guidance (2021 AI Risk Management principles) reinforcing that ML and AI models used in internal credit decisioning fall squarely within the SR 11-7 framework, regardless of whether they contribute to regulatory capital calculations.