Governance, risk and compliance

SmartSuite for the Model Risk Manager

The Model Risk Manager runs the model risk management framework: the model inventory, tiering, validation schedule and the findings that follow. They make sure every model, statistical or AI, is validated independently, used within its approved scope and monitored for performance.

What you own

  • Maintain the model inventory with risk tiers and owners
  • Set the model validation standards and schedule
  • Coordinate independent validation and track validation findings
  • Monitor ongoing model performance and use within approved scope
  • Govern model changes and re-validation triggers
  • Report model risk posture to the risk committee

Where the role sits

Each name opens that role's page.

Reports to

Chief Risk Officer

Chief Risk Officer

See the role
Chief Data and AI Officer

Chief Data and AI Officer

See the role

Direct reports

Model Validator

Model Validator

See the role

Works closely with

Model Owner

Model Owner

See the role
AI Risk Officer

AI Risk Officer

See the role
AI Governance Lead

AI Governance Lead

See the role
Internal Auditor

Internal Auditor

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

ai-governance

Touches

contributes or approves

risk, issues-actions, reporting

Depends on

consumes its output

audit, compliance

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

No items found.

Suites that serve this role

How SmartSuite supports this role

AI governance. Provides a model registry with tiering, assessment templates and task routing so validation and monitoring run on a schedule rather than by request.

Risk management. Scores model risk and links validation findings to the enterprise risk register.

Issues and actions. Tracks validation findings and remediation with owners, evidence and closure sign-off.

Reporting. Reports model inventory coverage, overdue validations and open findings to the risk committee.

Industry reference

The Federal Reserve and OCC's SR 11-7 / OCC 2011-12 guidance defines model risk management: an inventory, independent validation, ongoing monitoring and governance for every model's intended use. The UK PRA's SS1/23 (2023) sets equivalent principles for banks, and actuaries follow ASOP 56 on modelling.

The scope now includes AI. NIST's AI RMF and ISO/IEC 42001 extend validation and monitoring to machine-learning systems, and the EU AI Act makes high-risk systems subject to conformity assessment. Insurers apply the NAIC's 2023 AI model bulletin; healthcare models that inform care fall under FDA device guidance; public bodies follow OMB AI guidance.

In their words

Related roles

Chief Risk Officer

Chief Risk Officer

See the role
Chief Data and AI Officer

Chief Data and AI Officer

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.