Enterprise / high-volume plans available on request.
Anonymous users get 10 free calls/day without a key.
Free resource
UK PRA SS1/23 Model Risk Management Checklist
SS1/23 has been in effect for UK banks since May 2024 — the Bank of England's own equivalent of the Fed's
SR 11-7, deliberately technology-neutral but explicitly bringing AI and machine learning into scope. This
checklist maps its five principles to the AI-specific evidence a validator or PRA examiner actually expects
to see. Enter your work email to unlock it; it prints cleanly to PDF from your browser.
Enter your work email to unlock the full checklist
Unlock above to view all 20 checklist items across the 5 SS1/23 principles.
1 · Model Identification & Risk Classification
Model inventory — a documented, firm-wide list of every model in scope, including AI/ML models, with a clear definition of what counts as a "model" under your firm's own policy.
AI/ML flag — models with AI or machine learning characteristics are specifically tagged in the inventory, since SS1/23 expects these to be identifiable for targeted scrutiny.
Risk-based tiering — each model classified by materiality and reliance, with AI models assessed for additional risk factors: explainability, data provenance, and fairness.
Model risk on par with other risk types — evidence that model risk is integrated into the firm's overall risk management framework at the same level as credit and market risk, not siloed separately.
2 · Governance
Board and senior management accountability — a named senior individual with clear accountability for model risk, consistent with the PRA's Senior Managers Regime expectations.
Model risk policy — a written policy covering the full model lifecycle, explicitly addressing how AI/ML models are governed differently where warranted.
Model risk appetite statement — a documented statement of the firm's tolerance for model risk, with AI-specific considerations where the firm's AI use is material.
Reporting to committee/board — evidence that model risk, including AI-specific findings, is reported upward on a defined cadence, not just documented at the working level.
3 · Model Development, Implementation & Use
Development standards — documented standards for model development that address data quality, methodology selection, and — for AI/ML models — data provenance (where training data came from and how it was validated).
Explainability documentation — for AI/ML models, documentation of how the model's outputs can be explained to a validator, examiner, or affected customer, appropriate to the model's complexity and use.
Fairness assessment — for models affecting customer outcomes, documented assessment of whether the model produces unfair or disparate outcomes across customer groups.
Intended use and limitations — a clear statement of what the model is approved for, with explicit boundaries on use cases it was not validated against.
Implementation testing — evidence the model was tested in its actual production environment, not just validated on a development dataset.
4 · Independent Model Validation
Independence from development — validation performed by a function or individual independent of the team that built the model, consistent with SS1/23's effective-challenge expectation.
Validation scope for AI/ML — validation methodology explicitly covers the AI-specific risk areas (explainability, data provenance, fairness, accountability) the PRA has flagged as needing particular attention, not just standard model accuracy testing.
Ongoing/periodic re-validation — a defined schedule for re-running validation, and defined triggers (model change, data drift, performance degradation) that force re-validation outside that schedule.
Written validation outcome — a formal report with a clear conclusion on the model's fitness for its intended use, retained as evidence for supervisory review.
5 · Model Risk Mitigants
Model limits and overlays — documented controls (limits, manual overlays, human-in-the-loop review) applied where a model's known limitations warrant them.
Model performance monitoring — ongoing monitoring against defined thresholds, with an escalation path when a model breaches them.
Contingency arrangements — a documented fallback process for when a model is unavailable, degraded, or found to be materially wrong in production.
Third-party/vendor model coverage — the same governance, validation, and monitoring expectations applied to vendor-supplied AI models as to internally built ones, since SS1/23 does not exempt third-party models.
Need this filled in, not just outlined?
We build the ground-truth test suite, run the independent validation, and write the report your model risk file can cite — sections 3 and 4 above, done for your specific model.
This checklist is educational, not legal advice — SS1/23 applies proportionately based on firm size and
complexity, and PRA supervisory expectations evolve. Confirm your specific obligations with qualified counsel.
See our disclaimer for more.