A credit scorecard may compute exactly as designed and still be unsuitable for a new borrower population. A valuation model may use sound mathematics but omit a material source of dependence. A correct spreadsheet formula can act on the wrong rows. Model risk concerns the decision process as well as the equation.
The assigned June 2017 Federal Deposit Insurance Corporation (FDIC) guidance adopts the model-risk framework associated with Federal Reserve Supervision and Regulation (SR) letter 11-7. The discussion here follows that assigned framework rather than claiming it is the complete current rule for every U.S. institution.
A model uses quantitative methods, assumptions, and inputs to produce quantitative estimates. Its components include inputs, processing, and reporting. Expert judgments can enter each component, even when the output is numerical. Pricing, credit, capital, forecasting, and transaction-monitoring systems can all create model risk. A spreadsheet's importance depends on how it is used, not on whether it is called a model.
Model risk is the potential for adverse consequences from decisions based on incorrect or misused outputs. Materiality depends on exposure, complexity, uncertainty, reliance, and available alternatives.
Common mistakes
- Equating correct code with a suitable model. The approach, data, use, and interpretation also need validation.
- Assuming only named models matter. Material spreadsheets and vendor tools can influence decisions just as strongly.
- Calling agreement between models proof. They may share the same flawed assumptions or data.
Bottom line
- Model risk includes methodology, implementation, use, and interpretation.
- Effective challenge requires competence, independence, and influence.
- Validation joins conceptual review, monitoring, and outcomes analysis.
- Inventories and governance must capture dependencies and material end-user tools.
Exam shortcut
Classify the failure before choosing a repair. Wrong assumptions need conceptual challenge; wrong data or units need implementation controls; unsupported applications need scope review. Then follow the output to the actual decision. A model can pass a local test and still fail when data enters, a report leaves, or a user applies it elsewhere.
The full lesson (about 2,859 words, 19 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
Browse all free FRM Part II lessons or jump into free FRM Part II practice questions.