An internal AI audit team at a bank is evaluating the scope of their AI model audit universe. A business unit argues that their rule-based credit scoring system, which was built by data scientists using statistical analysis, should be excluded because it is 'not really AI.' How should the audit team respond?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because SR 11-7's broad definition of 'model' captures any quantitative method that applies statistical or mathematical techniques to transform inputs into quantitative estimates, which includes rule-based scoring systems built through statistical analysis. The 'AI' label is irrelevant to model risk applicability.
Full explanation below image
Full Explanation
B is correct because SR 11-7's broad definition of 'model' captures any quantitative method that applies statistical or mathematical techniques to transform inputs into quantitative estimates, which includes rule-based scoring systems built through statistical analysis. The 'AI' label is irrelevant to model risk applicability. The audit team should include it under model risk oversight. Excluding rule-based systems (A) would leave a significant category of quantitative decision tools unmonitored. The ML-only criterion (C) is not the regulatory standard. Deferring to technology (D) abdicates the audit team's independent classification responsibility.