A large regional bank has deployed a machine learning model to approve or deny consumer credit applications. Under SR 11-7 guidance, the model validation team must conduct an independent review. Which of the following activities is MOST critical to satisfy the SR 11-7 requirement for conceptual soundness validation?
Select all correct answers, then click Submit.
Short Explanation and Infographic
Think of SR 11-7 conceptual soundness like checking whether a recipe makes sense before you ever turn on the oven. You're not asking 'did it bake?'—you're asking 'is this even the right recipe for what we're cooking?' The Fed wants validators to challenge the theory, assumptions, and math underneath the model, not just whether it runs. Option B nails that core requirement.
Full explanation below image
Full Explanation
SR 11-7, issued jointly by the Federal Reserve and OCC, establishes supervisory expectations for model risk management at banking institutions. The guidance defines three pillars of model validation: (1) conceptual soundness, (2) ongoing monitoring, and (3) outcomes analysis.
Conceptual soundness validation—the subject of this question—requires independent reviewers to critically assess whether the model's theoretical foundation is appropriate for its intended use. This includes scrutinizing the choice of modeling methodology (e.g., logistic regression vs. gradient boosting for credit scoring), evaluating the assumptions embedded in the model (e.g., stationarity of economic variables), and verifying that the mathematical relationships encoded in the model are logical and defensible. Option B captures exactly this requirement.
Option A describes software quality assurance—important for operational integrity but not what SR 11-7 means by 'conceptual soundness.' A model can compile and pass unit tests while still being theoretically wrong for the task.
Option C describes data security and retention controls. These are legitimate compliance obligations under GLBA and other frameworks, but they are not part of the SR 11-7 model validation framework.
Option D describes vendor contract management. While third-party model risk management is addressed in SR 11-7 (and more directly in the OCC's third-party risk guidance), uptime SLAs are an operational concern, not a conceptual soundness assessment.
Practitioners should note that SR 11-7 also requires validators to be independent of model developers, possess appropriate expertise, and document findings in a formal validation report—all of which reinforce that this is a substantive technical review, not a procedural checkbox.