Model Risk Management
The discipline of identifying, measuring, and mitigating the risks that arise from relying on a model's outputs to make or influence business decisions, including the risk that a model is wrong, biased, or degrades over time.
What It Is
Model risk management originated in financial-services regulation, most notably the Federal Reserve and OCC’s SR 11-7 guidance (issued 2011, revised 2026), and is now applied more broadly, often voluntarily outside of banking, to AI and LLM systems used in business decisions. Worth noting: the 2026 revision of SR 11-7 explicitly states that generative AI and agentic AI models are not yet within its formal scope, so applying these principles to LLM-based systems today is a matter of adopting sound practice, not meeting an existing regulatory mandate.
It covers validating a model before it’s relied upon, monitoring for performance drift over time, and having a defined response when a model’s outputs prove unreliable.
It evaluates the business risk of relying on a model’s output in a specific context, which is a different question from whether the model performs well on a generic benchmark.
In B2B Commerce Context
In B2B commerce, models increasingly influence pricing and credit decisions directly, which makes their risk profile a business concern, not just a technical one.
A practical example:
This is distinct from simply checking a model’s accuracy once at launch; it’s an ongoing practice tied to how the business itself is changing.
When You Need It
- A model influences pricing, credit, or approval decisions directly.
- You operate in a regulated environment where decisions need to be explainable and auditable.
- There's been a material change to the model, its training data, or the business context it operates in.
- You want a defined process for what happens when a model's outputs prove unreliable.
Assign business ownership of the risk, not just technical ownership of the model.
What It Is Not
- Model risk management is not the same as LLM benchmarking. Benchmarking evaluates a model's raw capability; model risk management evaluates the business risk of relying on its outputs in your specific context.
- It is not a one-time model validation exercise, it needs to continue as the model, its data, and the business context evolve.
- It is not purely a data science concern. Business owners of the decisions a model informs share responsibility for the risk.
Comparison
| Attribute | Model Risk Management | Standard QA Testing |
|---|---|---|
| Focus | Business risk of relying on model outputs | Technical correctness of the system |
| Timeframe | Ongoing, tied to business and data changes | Typically pre-release |
| Ownership | Shared between business and technical teams | Primarily technical/QA teams |
| Trigger for review | Market shift, data drift, material change | Code or feature change |
See also
Ready to see it in action?
Book a demo of OroCommerce
See how agentic workflows fit into complex B2B commerce, with a walkthrough tailored to your stack.