Home › Cybersecurity & GRC Career Guides › Model Risk Management Skills
Model Risk Management Skills

Model risk management is the oldest and most rigorous of the AI governance disciplines, and most people arriving at AI governance from other routes do not realize it already exists, with decades of supervisory expectation behind it.
Where it comes from
US banking supervisors issued SR 11-7 in 2011, and it remains the reference text. It defines model risk as the potential for adverse consequences from decisions based on incorrect or misused model output, and it names two sources: a model may be fundamentally wrong, or it may be right and used for something it was never built for.
That second source is the one that generalizes best to AI. A model performing exactly as designed, applied to a population it was not developed on, is a governance failure with no technical defect anywhere in it.
Three lines, and why independence is the point
Model developers own the model. An independent validation function challenges it, reporting outside the development chain. Internal audit assesses whether the framework itself works.
Validation must be able to conclude that a model should not be used, and to make that stick. A validation function that reports to the head of the team building the models is decorative, and supervisors say so directly.
What validation covers
Conceptual soundness first: is the chosen approach appropriate for the problem, and are the assumptions defensible. This is where most serious findings originate, and it requires understanding the business problem rather than only the mathematics.
Then outcomes analysis, comparing predictions against what actually happened. Then ongoing monitoring, because a model that validated well in 2024 may be operating in a different world now. And a model inventory, which sounds administrative and is the control everything else depends on, since you cannot govern models you cannot list.
The inventory is where most programs, in banks and elsewhere, are quietly weakest.
What machine learning changed
The framework holds up better than people expect. What strains is the detail.
Conceptual soundness is harder to assess when the model has no interpretable structure to inspect. Documentation standards written for a regression struggle with a system whose behavior depends on training data nobody can fully characterize. Change management assumed models change rarely, and a continuously retrained model breaks that assumption entirely. Third-party models, where you cannot see inside, are now the common case rather than the exception.
Being able to name a specific strain like that, rather than saying "we applied the framework to AI", is what distinguishes a candidate who has actually done it.
Why it is worth knowing outside banking
Every organization now standing up AI governance is rebuilding something close to SR 11-7, usually without knowing it. Inventory, tiering by materiality, independent challenge, documented validation, ongoing monitoring. ISO/IEC 42001 and the NIST AI RMF describe the same shape in newer vocabulary.
People with model risk backgrounds are consequently in demand well beyond financial services, and the transferable claim is straightforward: this discipline solved the governance problem twenty years before anyone called it AI governance.
Where to go next
- Browse the jobs that use these skills
- Follow a career roadmap into the role you want
- Hiring for this? Start from a job description template
- Free certification study games, 592 practice questions
Frequently Asked Questions
What is model risk management?
The discipline of governing the risk that decisions based on model output turn out badly, either because the model is wrong or because it is being used for something it was not built for. It originates in financial services and predates AI governance by decades.
What is SR 11-7?
Supervisory guidance issued by US banking regulators in 2011 that remains the reference text for model risk management. It defines model risk, sets expectations for independent validation, and establishes the inventory, documentation and monitoring practices the discipline is built on.
What does model validation cover?
Conceptual soundness, meaning whether the approach suits the problem and the assumptions hold. Outcomes analysis comparing predictions against reality. Ongoing monitoring. And the model inventory, which sounds administrative but is the control everything else depends on.
Why must validation be independent?
Because it has to be able to conclude that a model should not be used, and make that stick. A validation function reporting to the head of model development cannot do that, and supervisors say so directly.
How does machine learning strain the framework?
Conceptual soundness is harder to assess without interpretable structure. Documentation standards written for regression models struggle with systems whose behavior depends on training data nobody can fully characterize. Change management assumed models change rarely, which continuous retraining breaks. And third-party models you cannot inspect are now the common case.
What is a model inventory and why does it matter?
A complete record of models in use, their owners, purposes and materiality tiers. It matters because you cannot govern what you cannot list, and it is quietly the weakest control in most programs.
Do model risk skills transfer outside banking?
Strongly. Organizations standing up AI governance are rebuilding the same structure of inventory, materiality tiering, independent challenge, documented validation and monitoring. ISO/IEC 42001 and the NIST AI RMF describe the same shape in newer language.
What is the difference between model validation and AI audit?
Validation assesses whether a specific model is conceptually sound and performs as intended. AI audit is broader, covering governance, documentation, oversight, monitoring and impact as well as performance.
What jobs require model risk management skills?
Model risk manager, model validation analyst, quantitative analyst in validation, AI governance roles at financial institutions, and internal audit covering the model risk framework.
More in this series
- 9 Essential Data Governance Skills for the AI Era
- 10 Internal Audit Skills for Modern Assurance Careers
- 12 Transferable GRC Skills You May Already Have
- Technical vs. Nontechnical GRC Skills: What Employers Actually Need
- AI Governance Skills Employers Actually Hire For
- GRC Analyst Skills: What the Job Actually Requires
- Compliance Analyst Skills
- Risk Assessment Skills
- Controls Testing Skills
- Policy Writing Skills
- Regulatory Change Management Skills
- Third-Party Risk Skills
- AI Impact Assessment Skills
- AI Auditing Skills
- AI Evaluation and Testing Skills for Governance Careers
- Data Lineage Skills
- Data Quality Skills
- Privacy Engineering Skills
- AI Security Skills
- AI Incident Response Skills
- Governance Program Management Skills
- Stakeholder Communication Skills
- Executive Risk Reporting Skills
- Evidence Documentation Skills
- Control Mapping Skills
- Framework Crosswalking Skills
- Vendor Due Diligence Skills
- Responsible AI Skills
- GRC Tools and Automation Skills
- How to Build the 9 Data Governance Skills: A 12-Month Career Plan
- Founder of ExecSearches and GRC Careers
- Executive search across corporate, higher education, financial services, and nonprofit sectors
- Focus on AI governance and GRC hiring
- More than a decade in risk advisory and internal audit in financial services
- Led SOX and regulatory audits for Citi, Goldman Sachs, Morgan Stanley, and McKesson
- Public Accounting Certification, Cornell University