AI Model Risk Is Operational Risk: Extend Your ORM Framework, Don’t Rebuild It

Financial services firms already have a mature discipline for exactly this problem. It’s called model risk management, it predates the current AI wave by well over a decade, and most firms deploying AI right now are quietly building a parallel, weaker version of it from scratch instead of just extending what they already have.

Model risk management — the SR 11-7 tradition in the US, mirrored in various forms across EU and UK supervisory guidance — exists because financial firms have used quantitative models for credit decisions, trading, and risk calculation for decades, and regulators learned the hard way that models fail silently, confidently, and expensively if nobody is independently checking them. The discipline it built is genuinely mature: independent model validation separate from the team that built the model, defined model risk tiers based on materiality and complexity, ongoing performance monitoring against a baseline, and a documented inventory of every model in production with its owner, its purpose, and its validation status.

Why AI should slot into this, not sit beside it

An AI system making or materially influencing a decision — credit scoring, fraud detection, underwriting support — is, structurally, exactly what model risk management was built to govern. It has inputs, it produces outputs that affect real decisions, it can degrade in ways that aren’t visible from the outside, and it needs independent validation by people who didn’t build it. Treating it instead as a new category requiring a bespoke “AI governance” programme, disconnected from the existing model risk function, produces two governance regimes doing overlapping work with different rigour, different reporting lines, and no shared inventory — the classic failure mode of parallel structures nobody designed to talk to each other.

Free · 4 minutes

Would you survive contact with a determined attacker — or an auditor?

Fourteen questions on access, patching, detection, and recovery — the basics that prevent most real incidents, and the ones most often assumed rather than verified. Banded finding on screen, full sheet by email.

The extension isn’t seamless, and pretending otherwise would be its own mistake. Generative and agentic AI systems have real properties traditional model risk frameworks weren’t built for: non-deterministic outputs that can vary for identical inputs, emergent behaviour that’s harder to bound than a regression coefficient, and performance that can drift in ways a traditional back-testing regime doesn’t naturally catch. The right move is extending the existing framework’s principles — independent validation, tiered materiality, ongoing monitoring, a single inventory — to cover these new properties, not discarding the framework because AI feels unfamiliar.

What the extension actually requires

Concretely: fold AI systems into the existing model inventory rather than maintaining a separate one, using the same materiality tiering logic already applied to traditional models. Extend independent validation to include AI-specific tests — adversarial robustness, output consistency across repeated runs, bias testing appropriate to the use case — run by the same validation function, not a separate AI ethics committee operating in isolation from it. Extend ongoing monitoring to catch AI-specific degradation patterns, like drift in output distribution or a rising rate of low-confidence responses, using the same escalation path a traditional model’s performance breach would trigger.

This also solves the board-reporting problem that plagues separate AI governance programmes: a board already receives a model risk report it understands, with a track record of taking it seriously. Adding AI systems to that existing report, in the same format, with the same escalation logic, gets AI risk taken exactly as seriously as every other model risk on the books — rather than as a novel, poorly-understood category competing for attention against a framework the board has trusted for years.

Where the parallel-structure problem actually shows up

A retail bank built a dedicated AI governance committee, entirely separate from its long-established model risk function, to oversee a new AI-driven credit pre-screening tool. The AI committee approved the tool using its own bespoke checklist, genuinely thoughtful but built from scratch, covering bias testing and explainability. Nobody thought to route the tool through the existing model risk validation process, because the AI committee had been explicitly set up to handle exactly this. The gap surfaced eighteen months later, during a routine model risk audit that discovered the credit tool sat entirely outside the bank’s official model inventory — meaning the tool materially affecting credit decisions had never been through the independent validation process every other credit model in the bank was required to pass, simply because it had been built and governed by a parallel structure nobody had reconciled against the original one.

Extending an existing model risk management framework to cover AI systems, rather than building a parallel governance structure, is exactly the kind of framework integration a technology control assessment is built to scope and implement.

The fix, once the gap is visible, is rarely a new committee. It’s usually a single meeting between whoever owns model risk and whoever owns AI governance, walking the AI inventory against the existing model risk tiers, and agreeing that from this point forward there is one inventory, one validation process, and one report — not two structures quietly competing for the same underlying risk.

One specific, high-stakes category of that risk is covered in confidentiality risk when LLMs touch privileged material.

Extending an existing model risk management framework to cover AI systems, rather than building a parallel governance structure, is exactly the kind of framework integration a technology control assessment is built to scope and implement.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming