PRA SS1/23 · MODEL RISK · ANNUAL

If you hold an internal model permission, this is yours.

Live since 17 May 2024. Five principles for firms with internal model approval, and an annual self-assessment a senior manager owns.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Five principles, and one signature under all of them
Model inventory Risk tiering Independent validation Post-model adjustments Annual self-assessment

Our promise

“A principle is a heading. The model file is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $25,000, and nothing is charged until you approve it.

Each additional system
$6,000
Re-audit, same scope
$16,000
Renewal, every twelve months
$21,000 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

SS1/23, in three chapters

The Rule

The PRA published SS1/23 in May 2023 and it took effect a year later. It reaches UK firms holding internal model approval, and sets out five principles: identification, governance, development and use, independent validation, and the mitigants that sit behind all four of them.

The Gap

Discovery is where these programmes lose time, every single time. The inventory is maintained rather than reconciled, the definition is drawn too narrowly to catch spreadsheets and vendor scores, and the tiering labels everything but changes nothing that follows from it.

The Office

Our review starts at the register and works outward from it. We reconcile the inventory against production, check that the tiering actually changes the treatment, test whether validation has standing to disagree, and leave the annual self-assessment in a state somebody can sign.

What counts as a model?

Wider than the things you call models.

A quantitative method turning input data into output — it expressly reaches deterministic methods and AI.

Inside the definition № 01
  • Statistical, economic, financial and mathematical methods
  • Deterministic methods — rules engines and spreadsheets
  • AI and machine learning, inventoried like anything else
  • Vendor and third-party models, on your own register
SS1/23 · iDharma · Presented for review
Who it reaches № 02
  • IRB — credit risk, usually the largest population in the firm
  • IMA — market risk, with the valuation models that feed it
  • IMM — counterparty credit risk, on the same inventory
  • No internal model permission — free to adopt it anyway
SS1/23 · iDharma · Presented for review
Whose duty is it

The model may be theirs. The model risk is yours.

You

The firm holding the permission

SS1/23 attaches to the firm with internal model approval, and inside that firm to a named senior manager. The inventory, the tiering, the validation, the post-model adjustments and the annual self-assessment are all yours, and none of them can be held by somebody else on your behalf.

Your supplier

The people who built the model

Carries no expectation of its own here - the statement is addressed to the firm. Many vendors document their models well and will supply what they have. The difficulty is not the quality of that work; it is that it stops at the edge of what they are willing to disclose, and that edge is theirs alone to set.

The catch

A bought model is your model risk

Vendor models belong on the inventory, get tiered like your own, and need enough documentation to validate and monitor. Where a supplier will not provide it, that is a finding against you rather than against them - so the hooks have to be written into the contract before anything is deployed.

What most firms assume

“It is a vendor model, so the documents are theirs.”

What the supervisor does

Asks you. A missing document is a finding on you.

It is the most common finding we write up.

  • Who it is for
  • Model risk management
  • Independent validation
  • Chief risk officers
  • Credit & market risk
  • Internal audit
  • The accountable SMF
What weakness costs
A printed sheet headed Audit Analysis on a dark desk, carrying a bar chart, a trend line and a doughnut chart, with a calculator to one side and the edge of a laptop behind it.
01 There is no fine for a weak framework. There is a finding, then a capital consequence, then a conversation about the permission itself — which is expensive in a different currency.
02

Findings arrive through ongoing supervision and through the self-assessment you submit — remediated on the PRA’s timetable.

03

Model risk weakness can feed a Pillar 2A assessment or a scalar on the affected models. That is the one that shows up in the numbers.

04

In a persistent case: restrictions on model use, or a review of the internal model permission. For an IRB firm that is the outcome that bites.

The 60-second check

Three questions. Then you’ll know.

No email, no signup. A starting point, not a determination.

0 of 3

IM permission -

This is the whole test. SS1/23 reaches UK-incorporated banks, building societies and PRA-designated investment firms permitted to use internal models for regulatory capital. Without one of those permissions it does not bind you.

Definition width -

The definition is deliberately wide. Quantitative methods that turn input data into output - expressly including deterministic methods, AI and machine learning. Scope it narrowly and everything downstream inherits the omission in silence.

What exists today -

One with no findings reads as one that was not performed. Against all five principles, with real gaps, owners and target dates, reviewed by the accountable SMF and by the board.

The sequence

Four moments, and one of them repeats.

Nothing is submitted on a date, so the only thing that recurs is the one artefact somebody senior has to put a signature under.

  1. In force

    17 May 2024

    Published a year earlier and live since. It is the standard your supervisor has read you against for two years.

  2. Self-assess

    Every year

    Against all five principles, with real gaps, owners and dates, reviewed by the accountable SMF and board.

  3. Stress testing

    23 April 2026

    The Low Impact Amendments bring stress test model risk practices inside exactly the same set of expectations.

  4. Newly permitted

    12 months

    A firm first granted internal model permission has a year from the grant to comply. The PRA confirmed it in 2026.

The trap

Every principle downstream of the register inherits its gaps in silence. Tiering, validation and monitoring are all blocked until the inventory can be trusted — so a programme that starts anywhere else spends its first quarter discovering that it has to start again.

Expectation & coverage

What the statement expects, what we ship

12 expectations, and the artefact that answers each one, in the PRA’s numbering.

Firmwide model definition Principle 1 - deterministic and AI/ML included
A definition your teams can apply, with worked calls on the borderline cases: spreadsheets, rules engines, vendor scores and AI-assisted steps.
Model inventory Principle 1 - reconciled, not maintained
A register reconciled to production, with owner, tier, purpose, status, dependencies and vendor provenance against every entry.
Risk tiering methodology Principle 1 - materiality, complexity, uncertainty
A tiering scheme applied across the estate, with the borderline calls documented and the treatment each tier actually receives written down.
SMF accountability Principle 2 - a named senior manager
The accountable senior manager identified, their responsibilities mapped, and the reporting line into the board evidenced rather than assumed.
Model risk appetite Principle 2 - reported as a risk in its own right
An articulated appetite with measures, so "within appetite" is a statement somebody can test rather than a sentence in a policy.
Development standards Principle 3 - data, testing, documentation, change
Data, testing, documentation and change-control standards, each with the evidence the stage has to leave behind.
Validation methodology Principle 4 - independent, and scaled by tier
A methodology scaled by tier, a findings register with owners and dates, and the independence argument written rather than asserted.
Post-model adjustment governance Principle 5 - the quiet overlay problem
A PMA register with justification, approval, expiry and a retirement plan for each adjustment currently in force.
Monitoring and thresholds Principle 5 - including drift on AI and ML
Metrics per model with thresholds, owners and an escalation route - and drift and data-quality checks that run unprompted.
Vendor model governance Cross-cutting - an application of all five
The documentation set to demand from a supplier, and the contractual hooks that make change notification and validation access enforceable.
Annual self-assessment Cross-cutting - the artefact that proves it is alive
The assessment against all five principles, with gaps, owners and dates, in a form the SMF can sign and the board can interrogate.
Stress test model risk From 23 April 2026
The stress-testing model population assessed against SS1/23 alongside the rest, following the PRA's April 2026 amendment.
The engagement

Your model estate, independently reviewed

From an IRB rating model to a scored spreadsheet.

  1. Inventory

    The model population reconciled to production, vendor and deterministic included.

  2. Tier and test

    Tiering applied, validation and monitoring checked against what each tier gets.

  3. Sign off and self-assess

    You see the draft first. Then the assessment the SMF can sign, gaps and dates.

Request a readiness review
An auditor in a charcoal suit and open-collared white shirt, with silver hair, standing against a warm pale wall and pointing into the open space alongside.
Monitoring that runs, not a quarterly upload.
Struck in your favour

Why firms choose iDharma for SS1/23

Genuinely independent

We build and resell no models, and we take no fee that is tied to what the review finds.

Written to the numbers

Every finding names the principle it answers, in the numbering your committee uses.

One review, three rules

SS1/23, SR 11-7 and OSFI E-23 are one estate and one piece of work, and not three of them.

We start at discovery

The inventory is where these programmes lose time, so it is where our scope always begins.

Four marks, struck on every review.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

SS1/23 readiness review

The full review against all five principles, written in the PRA's own numbering so your committee reads it in the order it already thinks in: each one assessed with the evidence behind it, the cross-cutting vendor and self-assessment questions answered, and every gap carrying an owner and a date the SMF can sign under.

Register

Model inventory

A register reconciled to production with owner, tier, purpose, status, dependencies and vendor provenance against every single entry.

Standard

Tiering methodology

The scheme, the factors behind it, the borderline calls documented, and the treatment each tier actually receives written down.

Procedure

Validation methodology

Scope and depth scaled by tier, a findings register with owners and dates, and the independence argument written rather than asserted.

Register

PMA register

Every post-model adjustment with its justification, approval, expiry and a plan to retire it rather than to keep it indefinitely.

Spec

Monitoring specification

Metrics per model with thresholds, severities and a configured action per breach - plus drift checks for the AI and ML population.

Assessment

Annual self-assessment

The assessment against all five principles, comparable year on year, with gaps and dates the SMF can put a signature under.

Format & fee

Real numbers, upfront.

Scope
Set by the statement, not by us
Input
Your model estate and its records
Re-assess
Each self-assessment — $21,000 against your known baseline

The statement fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this review
SS1/23 · Named engagement $25,000 flat
  • Inventory reconciled to production
  • Tiering that changes the treatment
  • Validation and PMA governance reviewed
  • Annual self-assessment, ready to sign
Show your hand

Four things you have to be able to produce

These are a supervisor’s four questions. Each is either true of your framework on the day it is asked, or it is not.

The register,
reconciled

One inventory checked against production, with every entry owned - vendor models and the deterministic methods included, not kept on a separate list beside it.

The tier,
with teeth

A tier on every model, built from materiality, complexity and uncertainty, and visibly changing how much validation and monitoring each one gets.

The stop,
on record

Validation in date on Tier 1, findings tracked to closure, and at least one occasion on which it stopped something going out of the door. That last part is the real test.

The paper,
honest

A self-assessment against all five principles with real gaps, owners and dates. One that comes back with no findings is read as one that was never performed at all.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Reach, what counts as a model, tiers, weakness. Answered straight.

Request this review
Who does SS1/23 apply to?

UK-incorporated banks, building societies and PRA-designated investment firms that hold internal model approval - IRB, IMA or IMM. If you do not hold one of those permissions, the supervisory statement does not bind you.

What counts as a model?

The definition is deliberately wide, and it expressly reaches deterministic methods and AI and machine learning - so a rules engine or a scored spreadsheet can be squarely inside it.

Does SS1/23 require three tiers?

No. It requires classification proportionate to materiality, complexity and uncertainty, and expects it to drive the intensity of the controls. Three tiers is what most firms land on, not a requirement.

What happens if our framework is weak?

The PRA does not fine for this. The consequences escalate: supervisory findings, then a capital consequence through Pillar 2A or a model scalar, and in a persistent case restrictions on model use or a review of the permission.

How does SS1/23 compare with SR 11-7 and OSFI E-23?

They are the same object for three supervisors. SS1/23 is distinctive for its explicit SMF accountability, its treatment of post-model adjustments, and the annual self-assessment. A firm running any one is most of the way to the others.

Get started

Request an SS1/23 readiness review

Tell us the shape of the model estate and we come back within one business day.

What we need from you

Nothing you do not already have. Most of this comes out of your model governance records in an afternoon, and we tell you exactly which extracts before you commit.

  1. Which internal model permissions you hold
  2. Roughly how large the model population is
  3. Your model inventory, if one already exists
  4. How much of it came from a vendor, and what they sent
  5. Whether AI or ML models sit in the population

What happens next

  1. We agree the scope with you first.
  2. Four to eight weeks, longer for a large inventory.
  3. Nothing is charged until you approve the scope.
Request a readiness review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • SS1/23 and PS6/23, Bank of England
  • Low Impact Amendments, April 2026
In force
17 May 2024
Amended
23 April 2026

What it means

  • General information about what the statement expects — not regulatory advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • Drawn from the Bank of England’s own publications rather than from summaries, but not line-checked against SS1/23 or the April 2026 amendment. No penalty figure appears anywhere on this page, because the PRA does not fine for this.
  • On an engagement we work from the statement itself. Use this as a starting point for a scoping conversation, not as your final word.

Something on this page out of date?

Tell us