Skip over navigation

Model Risk Management

The discipline of identifying, measuring, and mitigating the risks that arise from relying on a model's outputs to make or influence business decisions, including the risk that a model is wrong, biased, or degrades over time.

Created Sep 10, 2026
AI governance

What It Is

Model risk management originated in financial-services regulation, most notably the Federal Reserve and OCC’s SR 11-7 guidance (issued 2011, revised 2026), and is now applied more broadly, often voluntarily outside of banking, to AI and LLM systems used in business decisions. Worth noting: the 2026 revision of SR 11-7 explicitly states that generative AI and agentic AI models are not yet within its formal scope, so applying these principles to LLM-based systems today is a matter of adopting sound practice, not meeting an existing regulatory mandate.

It covers validating a model before it’s relied upon, monitoring for performance drift over time, and having a defined response when a model’s outputs prove unreliable.

It evaluates the business risk of relying on a model’s output in a specific context, which is a different question from whether the model performs well on a generic benchmark.

In B2B Commerce Context

In B2B commerce, models increasingly influence pricing and credit decisions directly, which makes their risk profile a business concern, not just a technical one.

A practical example:

A pricing or credit-risk model that recommends discount thresholds or flags at-risk accounts needs ongoing validation, if the underlying customer base or market shifts, the model's recommendations can quietly become less reliable, and model risk management is the practice of catching that before it costs revenue or creates compliance exposure.

This is distinct from simply checking a model’s accuracy once at launch; it’s an ongoing practice tied to how the business itself is changing.

When You Need It

  • A model influences pricing, credit, or approval decisions directly.
  • You operate in a regulated environment where decisions need to be explainable and auditable.
  • There's been a material change to the model, its training data, or the business context it operates in.
  • You want a defined process for what happens when a model's outputs prove unreliable.

Assign business ownership of the risk, not just technical ownership of the model.

What It Is Not

  • Model risk management is not the same as LLM benchmarking. Benchmarking evaluates a model's raw capability; model risk management evaluates the business risk of relying on its outputs in your specific context.
  • It is not a one-time model validation exercise, it needs to continue as the model, its data, and the business context evolve.
  • It is not purely a data science concern. Business owners of the decisions a model informs share responsibility for the risk.

Comparison

Attribute Model Risk Management Standard QA Testing
Focus Business risk of relying on model outputs Technical correctness of the system
Timeframe Ongoing, tied to business and data changes Typically pre-release
Ownership Shared between business and technical teams Primarily technical/QA teams
Trigger for review Market shift, data drift, material change Code or feature change

See also

Ready to see it in action?

Book a demo of OroCommerce

See how agentic workflows fit into complex B2B commerce, with a walkthrough tailored to your stack.

Book a demo

Share

Back to top