← Back to all briefings

Governance · Credibility 50/100 · · 2 min read

Governance Briefing — September 25, 2025

The PRA’s model risk management standard has been live for over a year, and September supervisory reviews are focusing on board ownership, inventory completeness, and challenger model performance evidence.

Executive briefing: Prudential Regulation Authority Supervisory Statement SS1/23 on model risk management took effect on May 17, 2024. By September 2025, UK banks and insurers must demonstrate mature model inventories, lifecycle controls, and governance mechanisms spanning development, validation, use, and retirement. The PRA is testing whether boards are accountable for risk appetite, whether senior management functions have adequate resources, and whether challenger models provide meaningful challenge for material models.

Key compliance checkpoints

  • Inventory coverage. Maintain an end-to-end register capturing model purpose, ownership, materiality tiers, validation cadence, and dependencies as outlined in SS1/23 Chapter 4.
  • Validation independence. Evidence independent model validation with clear documentation of limitations, overrides, and compensating controls, especially for AI/ML models.
  • Board engagement. Deliver quarterly MI to the board covering model risk appetite metrics, breaches, remediation status, and emerging risk themes.

Operational priorities

  • Resource planning. Ensure Senior Management Function 1 or 4 holders have sufficient specialist staff and budget to execute the target operating model described in SS1/23.
  • Challenger effectiveness. Document performance of challenger models, back-testing results, and how findings influence capital, pricing, or provisioning decisions.
  • Policy refresh. Align enterprise policies with SS1/23 terminology, including definitions of model vs. tool, materiality thresholds, and escalation paths.

Enablement moves

  • Implement workflow tooling that enforces approval gates across development, validation, and use stages.
  • Introduce dashboards tracking key risk indicators such as validation backlog, ageing issues, and usage overrides.

Sources

Zeph Tech centralises PRA model inventories, orchestrates validation workflows, and equips boards with model risk analytics.

  • Model risk management
  • Financial regulation
  • Governance
Back to curated briefings