A financial institution's model risk team discovers that a third-party AI vendor has updated their credit scoring model without notification. What control should the model risk framework include to prevent this risk?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because third-party model risk requires contractual controls — specifically change notification requirements and the institution's right to review vendor model changes — combined with independent performance monitoring to detect unauthorized changes. A restricts vendor choice unnecessarily.
Full explanation below image
Full Explanation
B is correct because third-party model risk requires contractual controls — specifically change notification requirements and the institution's right to review vendor model changes — combined with independent performance monitoring to detect unauthorized changes. A restricts vendor choice unnecessarily. C is overly broad. D is a technical monitoring control but insufficient without contractual rights.