Model risk
Under the operational risk, competent authorities should assess model risk, with specific regard to internal non-regulatory models (e.g. AI models, product pricing, setting and monitoring risk limits, ICAAP/ILAAP models, recovery options).
For the assessment of model risk, competent authorities should consider:
to what extent and for which purposes the institution uses models to make decisions and the business significance of such decisions. Competent authorities should determine the business/activity for which the institution makes significant use of models and assess the potential impact of model risk through, amongst others, sensitivity and scenario analyses or stress testing; and
the soundness of control mechanisms (in terms of methods, frequency, follow-up, etc.), including a model approval process, regular reviews performed and the institution’s level of awareness of model deficiencies or market and business developments.
When models are used for decision-making purposes (e.g. product pricing, AI models, evaluation of financial instruments, client profiling), competent authorities should assess whether there is a sound internal validation process and/or model-review process to identify and mitigate model risk (other than regulatory models).
When conducting the model risk assessment, competent authorities should consider the assessment of other risks to capital and risks to liquidity and funding, in particular with respect to the adequacy of methodologies used for measuring risk, pricing and evaluating assets and/or liabilities. The results of such an assessment should inform the findings on operational risk.