AI Model Risk Audit for Financial Institutions

Independent audit of AI and machine learning model risk management programs, aligned to SR 11-7, FFIEC guidance, and current supervisory expectations.
Schedule a Consultation

Model Risk Doesn’t Stop at the Spreadsheet

Confidence for examiners. Clarity for the board. Assurance across your AI model inventory.

What We Audit

The model risk management framework financial institutions have followed for over a decade, SR 11-7, was designed with statistical models in mind. AI and machine learning introduce additional complexity: models that learn continuously from data, make decisions through processes that aren’t fully transparent, and evolve in ways that traditional validation frameworks were not built to evaluate.

Regulators have made clear that SR 11-7 principles apply to AI and machine learning models. AuditOne provides independent audits of model risk management programs at financial institutions, with AI and ML specific audit coverage for institutions where AI models represent a significant share of the model inventory.

Model Inventory & Classification

  • Completeness of model inventory for AI and machine learning models
  • Risk-based tiering and classification of AI models
  • Documentation standards: purpose, inputs, outputs, and decision logic
  • Coverage of vendor-provided AI models in the inventory
  • Identification of models in use that are not formally in the inventory

Model Development & Validation

  • Development documentation and methodology for AI/ML models
  • Independent validation coverage and depth relative to model risk tier
  • Explainability and interpretability documentation for decisioning models
  • Bias testing, fairness assessment, and disparate impact evaluation
  • Data governance and data quality controls for model training data

Model Governance & Approval

  • AI model approval workflow and governance oversight
  • Board or committee-level visibility into the AI model portfolio
  • New model approval process, including AI models embedded in vendor products
  • Policies covering acceptable AI model use, prohibited applications, and oversight requirements

Ongoing Monitoring & Performance

  • Performance monitoring for AI models in production
  • Outcome review and feedback loop documentation
  • Model drift detection protocols and retraining triggers
  • Alerting and escalation procedures for model performance degradation
  • Periodic model review and re-validation scheduling

Model Change Management

  • Change management procedures for AI model updates and retraining
  • Version control and documentation for AI model changes
  • Re-validation requirements and thresholds for material model changes
  • Vendor notification requirements when third-party AI models are updated
Scroll to Top

We look forward to hearing from you.

Your Name(Required)
Your Email Address(Required)

How can AuditOne help? Are there certain Internal Audits or Risk Assessments you would like to know more information about?

Please let us know what's on your mind. Have a question for us? Ask away.
Consent(Required)