Model risk management for PRA-regulated banks.
SS1/23 sets the PRA's expectations for firms with internal model approval: five principles, model risk treated as a discipline in its own right, a named senior manager accountable, and an annual self-assessment the board has to be able to interrogate. The model definition reaches deterministic methods and AI and machine learning alike — and from April 2026, stress testing models too.
What SS1/23 is
A supervisory statement with a narrow gate and a wide reach: it binds fewer firms than people assume, and more of their models than they expect.
SS1/23, “Model risk management principles for banks”, was published by the Prudential Regulation Authority on 17 May 2023 and took effect on 17 May 2024. It sets out what the PRA expects of a firm’s model risk management framework, in five principles.
The gate is narrow. It reaches UK-incorporated banks, building societies and PRA-designated investment firms that hold internal model approval for regulatory capital — IRB for credit risk, the Internal Model Approach for market risk, or the Internal Model Method for counterparty credit risk. Without one of those permissions you are outside it.
The definition inside the gate is wide. A model is a quantitative method applying statistical, economic, financial or mathematical techniques and assumptions to turn input data into output — and it expressly covers deterministic methods and AI and machine learning. Firms that scope only their statistical models leave spreadsheets, rules engines and vendor scores outside a framework that should hold them.
Two things distinguish SS1/23 from its international siblings. Model risk is to be managed as a risk discipline in its own right, with a designated senior management function accountable for the framework. And every year the firm produces a self-assessment against the five principles, with gaps, owners and dates — which is the document a supervisor reads first.
Published 17 May 2023. Newly permitted firms get 12 months from the grant of internal model approval.
Stress test model risk management now assessed against SS1/23 too, per the April 2026 amendment.
Who does SS1/23 apply to
-
Firms with internal model approval
The test, and the whole test. UK-incorporated banks, building societies and PRA-designated investment firms permitted to use internal models for regulatory capital.
-
IRB — credit risk
Internal Ratings Based approaches. The largest model population in most firms, and usually the first one tiered.
-
IMA — market risk
The Internal Model Approach, including the valuation and risk models that feed it.
-
IMM — counterparty credit risk
The Internal Model Method. Exposure models sit alongside the credit ones in a single inventory, not a separate register.
-
Newly permitted firms
A firm first granted internal model permission has 12 months from the grant to comply — confirmed by the PRA in April 2026.
-
Firms without those permissions
Outside the supervisory statement. Many adopt it anyway as good practice, and a supervisor is unlikely to object — but it is a choice, not an obligation.
The five principles of SS1/23
Numbered as the PRA numbers them, because everyone in the conversation — supervisor, adviser and your own committee papers — says “Principle 3”.
Model identification and model risk classification
You cannot govern what you have not found. A firmwide definition, a complete inventory, and a risk tiering that then drives how much rigour each model gets.
- A model definition applied consistently firmwide
- A complete inventory, reconciled to what is running
- Risk tiering on materiality, complexity and uncertainty
- Deterministic methods inside the definition, not beside it
- Vendor and third-party models on the same register
- A route by which a new model actually gets recorded
Governance
Model risk treated as a risk discipline in its own right, with a named senior manager accountable and a board that hears about it in a form it can act on.
- A designated SMF accountable for the framework
- Board oversight of model risk appetite
- Policies, standards and roles written down
- Model risk reported alongside other risk types
- Independent challenge resourced, not just named
- An escalation route that has been used at least once
Model development, implementation and use
The build standards: data, testing, documentation and the controlled path into production — plus honest limits on what the model may be used for.
- Data quality and lineage evidenced, not asserted
- Development testing against the intended use
- Documentation a successor could rebuild from
- Implementation testing in the live environment
- Change control with re-approval triggers
- Stated limitations and out-of-scope uses
Independent model validation
Validation with the authority and the standing to disagree, scaled to the model’s tier, covering conceptual soundness as well as outcomes.
- Independence of judgement, not only of reporting line
- Scope and depth scaled by risk tier
- Conceptual soundness challenged, not confirmed
- Outcomes analysis and benchmarking
- Findings tracked to closure with owners and dates
- Revalidation on a defined cycle and on change
Model risk mitigants
What you do about the risk you cannot remove — including the governance of post-model adjustments, which is where a quiet overlay becomes a supervisory finding.
- Post-model adjustments identified and justified
- PMAs approved, time-bound and reviewed
- Compensating controls where a weakness is known
- Monitoring with thresholds that fire
- Aggregate model risk understood, not only per model
- A plan to retire each mitigant, not to keep it
Vendor and third-party models
Not a sixth principle — an application of all five. A bought model is your model risk, and the supervisor asks you rather than your supplier.
- On the inventory and tiered like your own
- Documentation obtained before deployment, not after
- Validation possible without full source disclosure
- Change and version notification contractually secured
Annual self-assessment
The artefact that proves the framework is alive. An assessment against each principle, with gaps, owners and dates, reviewed by the accountable SMF and the board.
- Assessed against each of the five principles
- Gaps recorded with owners and target dates
- Reviewed by the accountable SMF and the board
- Comparable year on year, so progress is visible
The last two rows are not principles. Vendor models and the annual self-assessment cut across all five, so they are marked rather than numbered — but they are on the page because they are the two things firms most often leave until the supervisor asks. The self-assessment in particular is not a summary of the framework; it is part of it.
Tier your models, then calibrate the rigour
Classification on materiality, complexity and uncertainty — and then a control set that visibly differs between the tiers, or the classification has bought you nothing.
Highest model risk
Regulatory capital models and anything whose failure moves a published number or a solvency position.
- Full independent validation before use
- Annual revalidation at minimum
- Board-visible reporting
- Tight change control and re-approval
Material but contained
Meaningful business impact within a portfolio, product or process, without firmwide consequence.
- Independent review scoped to the risk
- Periodic revalidation on a defined cycle
- Monitoring with escalation thresholds
- Documented approval to deploy
Lower model risk
Limited impact, readily overridden, or informing a decision a person still makes and owns.
- Proportionate review, not full validation
- Inventory entry with a named owner
- Light monitoring against expectations
- Re-tiered if the use changes
Three tiers is a pattern, not a requirement. SS1/23 asks for model risk classification proportionate to materiality, complexity and uncertainty, and expects it to drive the intensity of the controls. It does not prescribe how many bands you use or where the boundaries sit. Most firms land on three; if you do, be ready to say why yours are where they are — that answer is the control, not the label.
Where most model risk programmes fall short
Firms that have run model validation for a decade still meet SS1/23 with these eight. The first two are scope failures, which is what makes the rest invisible.
The inventory is not reconciled
A register maintained by one person, updated when someone remembers, and never checked against production. Every downstream activity inherits its gaps silently.
The model definition is too narrow
SS1/23 reaches deterministic methods and AI and ML alike. Firms that scope only statistical models leave spreadsheets, rules engines and vendor scores outside the framework.
Validation cannot actually say no
A function that reports independently but has no standing to block a release is not independent in the sense the principle means. The test is whether it has ever stopped anything.
Post-model adjustments are invisible
Overlays applied in the reporting cycle, justified informally, never time-bound and never retired. Principle 5 exists largely because of this pattern.
Tiering does not change the treatment
Every model tiered, then every model governed the same way. If Tier 3 receives the Tier 1 programme, the tiering is a label rather than a control.
The self-assessment is a slide
An annual paper that asserts compliance without gaps, owners or dates. A self-assessment with no findings is read as a self-assessment that was not performed.
Vendor models are taken on trust
A bought model with no documentation cannot be tiered, validated or monitored — and the supervisor asks you about it, not your supplier.
Model risk is not reported as a risk
Discussed inside a validation committee and nowhere else. The principle expects model risk to sit alongside credit, market and operational risk in the firm’s own reporting.
How iDharma supports SS1/23
Inventory, tiering, validation, monitoring, revalidation and attestation in one audit-logged workflow — each piece answering a named principle.
Model inventory and tiering
A firmwide inventory with every model tiered against materiality, complexity and uncertainty, so the governance each one receives scales with the risk it carries rather than with who owns it.
Addresses: Principle 1
Independent validation reports
A fixed six-section report — purpose and scope, conceptual soundness, data review, outcomes analysis, findings and conclusion — with evidence links, findings logged by severity and lifecycle stage, and validators independent of the people who built the model.
Addresses: Principles 3 and 4
Ongoing monitoring
Metric thresholds — PSI, AUC and the measures that suit the model — with warn, high and critical severities and a configured action per breach: notify, or notify and flag for revalidation.
Addresses: Principle 3
Revalidation triggers
A breach, a material change, a tier increase or a scheduled review opens a validation task on its own, with an append-only log of what changed, when, and who was told.
Addresses: Principle 4
Attestation roll-up
A per-tier status — blocked or clear — across tiering currency, validation coverage, monitoring activity and open findings, so the accountable SMF and the board sign something they can defend.
Addresses: Principle 2
Machine-to-machine ingestion
Scoped ingestion tokens feed live model metrics in automatically, so monitoring reflects production behaviour rather than a quarterly upload — which is the only way drift on an AI or ML model is caught in time.
Addresses: Principles 3 and 4
Every tiering decision, validation, breach and revalidation is timestamped and audit-logged. That trail is the point: it is what turns a framework you operate into a framework you can evidence, and it is what the PRA asks to see during supervisory engagement. A control with no record of having run is, to a supervisor, a control that did not.
Supervisory consequences, not penalties
SS1/23 is a supervisory statement, not a rulebook chapter with a fine attached. What a weak framework costs you shows up in supervision and in capital.
Supervisory findings
Raised through ongoing supervision and through the annual self-assessment you submit, with remediation expected on the PRA’s timetable rather than yours.
Capital consequences
Model risk weakness can feed a Pillar 2A assessment or a scalar on the affected models. This is the consequence that shows up in the numbers.
Permissions at risk
In a persistent case, restrictions on model use or a review of the internal model permission itself — which for an IRB firm is the outcome that actually hurts.
No penalty figure appears on this page because there is none to quote. Any number you see attached to SS1/23 belongs to a different regime. The pressure here is a finding you remediate on the PRA’s timetable, a scalar you carry in your capital, and — at the end of the escalation — a permission somebody reopens.
SS1/23 requirements, mapped to what we build
Twelve requirements with the principle each belongs to, and the artefact that discharges it. Paired, so every claim on this page can be checked against the expectation beside it — including the capabilities above.
- Firmwide model definition Principle 1
- A definition your teams can apply, with worked calls on the borderline cases: spreadsheets, rules engines, vendor scores and AI-assisted steps.
- Model inventory Principle 1
- A register reconciled to production, with owner, tier, purpose, status, dependencies and vendor provenance against every entry.
- Risk tiering methodology Principle 1
- A tiering scheme applied across the estate, with the borderline calls documented and the treatment each tier actually receives written down.
- SMF accountability Principle 2
- The accountable senior manager identified, their responsibilities mapped, and the reporting line into the board evidenced rather than assumed.
- Model risk appetite Principle 2
- An articulated appetite with measures, so “within appetite” is a statement somebody can test rather than a sentence in a policy.
- Development standards Principle 3
- Data, testing, documentation and change-control standards, each with the evidence the stage has to leave behind.
- Validation methodology Principle 4
- A methodology scaled by tier, a findings register with owners and dates, and the independence argument written rather than asserted.
- Post-model adjustment governance Principle 5
- A PMA register with justification, approval, expiry and a retirement plan for each adjustment currently in force.
- Monitoring and thresholds Principle 5
- Metrics per model with thresholds, owners and an escalation route — and for AI and ML, drift and data-quality checks that run unprompted.
- Vendor model governance Cross-cutting
- The documentation set to demand from a supplier, and the contractual hooks that make change notification and validation access enforceable.
- Annual self-assessment Cross-cutting
- The assessment against all five principles, with gaps, owners and dates, in a form the SMF can sign and the board can interrogate.
- Stress test model risk From 23 Apr 2026
- The stress-testing model population assessed against SS1/23 alongside the rest, following the PRA’s April 2026 amendment.
SS1/23 already covers your AI and ML models
No separate register, no separate committee, no waiting for an AI-specific rule. The framework you already owe is the one that governs them.
The PRA wrote the model definition to be technology-neutral, and said so deliberately. A method is in scope because of what it does — processing input data into output that a decision relies on — not because of the mathematics inside it. Machine learning is named; so are deterministic methods.
That cuts both ways. An opaque method is not excluded from the framework, and it is not excused from it either. What changes with an AI or ML model is not whether the principles apply but how much work each one takes: the harder the model is to interpret, the more weight falls on documentation, validation and monitoring to carry the assurance the method cannot supply on its own.
The practical consequence for most firms is a staffing question before it is a technical one. A validation function built entirely from traditional quantitative modellers will approve models it is not equipped to challenge — which is a Principle 4 failure wearing the appearance of a Principle 4 process.
What SS1/23 asks for AI and ML
- Inventory and tier them like any other model. There is no separate AI register and no separate committee.
- Explainability proportionate to the tier. The harder the method is to interpret, the more the rest of the framework has to carry.
- Data quality and lineage evidenced. Training data provenance is a Principle 3 question, not a data-science courtesy.
- Validation staffed to assess the method. A validation function of traditional quants will pass models it cannot actually challenge.
- Monitoring for drift, not just for outcomes. A model can stop being sound with no change to its code.
- Human review with authority to override. And a record of what the reviewer saw before they decided.
What supervisor-ready looks like
Four tests, phrased the way a supervisor asks them. Deliberately not four percentages — a coverage score in this position is a claim about a product, and none of these four is ours to score.
Complete and reconciled
One register, reconciled to production, every entry owned — including vendor models and the deterministic ones.
Applied and consequential
A tier on every model, built from the stated factors, visibly changing how much validation and monitoring each one gets.
Independent and current
Tier 1 validated and in date, findings tracked to closure, and at least one occasion where validation stopped something.
Honest and dated
Assessed against all five principles with real gaps, owners and target dates — signed by the accountable SMF.
Frequently asked questions
Scope, the model definition, tiering, and what a weak framework actually costs.
Who does SS1/23 apply to?
UK-incorporated banks, building societies and PRA-designated investment firms that hold internal model approval to calculate regulatory capital — for credit risk under the IRB approaches, market risk under the Internal Model Approach, or counterparty credit risk under the Internal Model Method. If you do not hold one of those permissions, the supervisory statement does not bind you.
When did it take effect?
It was published on 17 May 2023 and took effect on 17 May 2024, so it has been live for over two years. A firm newly granted internal model permission has 12 months from the grant to comply — the PRA confirmed that in April 2026.
What changed in April 2026?
Through the Low Impact Amendments finalisation, effective 23 April 2026, firms with internal model approval are expected to assess their stress test model risk management practices against SS1/23. The PRA also clarified that the expectations are not conditions of internal model approval.
We have no internal model permission. Should we adopt it anyway?
Many firms do, and no supervisor is going to object to a proportionate model risk framework. Treat it as good practice you have chosen rather than an obligation you are meeting, and scale it to your actual model population.
Does it apply to insurers?
No. SS1/23 is a banking supervisory statement. Insurers using internal models sit under the Solvency II model requirements, which are a separate regime with their own approval process.
What counts as a model?
The definition is deliberately wide: quantitative methods that apply statistical, economic, financial or mathematical techniques and assumptions to process input data into output. It expressly reaches deterministic methods and AI and machine learning — so a rules engine or a scored spreadsheet can be squarely inside it.
Does SS1/23 require three tiers?
No. It requires model risk classification proportionate to materiality, complexity and uncertainty, and expects the classification to drive the intensity of the controls. Three tiers is what most firms land on, not a requirement — and if you use it, be ready to say why the boundaries sit where they do.
How independent must validation be?
Independent enough to assess conceptual soundness and outcomes without a stake in the result, with standing to disagree. A separate reporting line helps and is not sufficient on its own; the practical test is whether validation has ever stopped a release.
What does Principle 5 want from post-model adjustments?
That every overlay is identified, justified, approved, time-bound, monitored and given a plan to retire it. PMAs that live indefinitely without review are the single most common Principle 5 finding, and usually the fastest thing to fix.
Are vendor models in scope?
Yes, and they are yours to govern. They belong on the inventory, get tiered like your own, and need enough documentation from the supplier to validate and monitor. Where the vendor will not provide it, that is a finding against you, not against them.
What happens if our framework is weak?
The PRA does not fine for this. The consequences are supervisory and they escalate: findings through ongoing supervision, then a capital consequence through Pillar 2A or a model scalar, and in a persistent case restrictions on model use or a review of the permission itself.
How does SS1/23 compare with SR 11-7 and OSFI E-23?
They are the same object for three supervisors. Inventory, tiering, development standards, independent validation and ongoing monitoring are common to all three; SS1/23 is distinctive for its explicit SMF accountability, its treatment of post-model adjustments, and the annual self-assessment. A firm running any one of them is most of the way to the others.
Where do readiness programmes lose the most time?
Discovery, every time. Firms consistently underestimate the model population outside the places they already look, and tiering, validation and monitoring are all blocked until the inventory can be trusted.
What does an iDharma SS1/23 readiness review cost and how long does it take?
It is scoped before you are charged. The variables are the size of the model estate, how much of the inventory already exists, and whether AI and ML models are in the population; we tell you the shape of all three after a short scoping call.
Read it at source
The scope test, the five principles and the April 2026 amendment on this page came off the Bank of England’s own publications. Where a call turns on the wording, go to them.
Primary sources
Bank of England and the PRA. External links.
Related on this site
The same object for other supervisors, and the AI frameworks that sit beside it.
- OSFI E-23 Model risk across five lifecycle stages, effective 1 May 2027
- SR 11-7 Rescinded Apr 2026 — replaced by SR 26-2 and OCC 2026-13
- NIST AI RMF Govern, Map, Measure and Manage, assessed end to end
- AI governance policy templates The document set behind the framework, mapped obligation by obligation
- Every framework we audit against The full catalog, by region and kind
Ready to operationalise SS1/23?
A readiness review gives you the model inventory, the tiering with its treatment set, the validation methodology, the PMA register and a self-assessment your SMF can actually sign — scoped before you are charged.
This page is guidance on how we scope an SS1/23 readiness review, not regulatory advice. SS1/23 is principles-based, so more of it is arguable than a rulebook chapter would be; where a call is genuinely open we say so in writing rather than pick the convenient answer.
From Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
Read the notesWhat Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
Read the notesWhat an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Read the guide