SD-14.4 — Model Governance & AI Governance

Business Domain: BD-14 Enterprise Risk, Control & Assurance (Cross-cutting — corporate) · Applies: BOTH

Purpose

Governs the lifecycle, validation and responsible use of the models and AI systems the firm runs. SD-14.4 owns the firm-wide model and AI inventory, the independent validation of models before and during use, and the governance of how AI is used across the firm. The buy-side runs models everywhere — risk models, valuation models, alpha models, allocation optimisers — and increasingly AI systems; a flawed model used unchallenged is a firm-level risk. SD-14.4 is the independent governance over them. It does not build or use the models — the front office, BD-07 and BD-08 do that; SD-14.4 independently governs and validates them.

Service Operations

  • Maintain the model and AI inventory — the firm-wide register of every model and AI system, its owner, its use and its risk tier.
  • Validate models independently — independently validate models before deployment and on a periodic cycle — the methodology, the assumptions, the performance.
  • Govern the model lifecycle — control model development, change, deployment, monitoring and retirement under a documented governance process.
  • Govern AI use — assess AI systems for risk, explainability and bias, and maintain the firm’s AI-use policy and ethical-AI standards.
  • Report model and AI risk — report the model and AI risk position to risk governance and the board.

Inputs and outputs

  • Inputs: the models and AI systems built and used across the firm — the risk models (BD-07), the valuation models (BD-08), the alpha and quant models (BD-02), the allocation optimisers (BD-01/BD-05); the model-governance regulation.
  • Outputs: the model and AI inventory, validation findings, the model-governance regime and the AI-use policy — consumed by every domain that runs a model, SD-14.1 and the governing bodies.

Entities

  • Consumes: E-19 Risk Measurement (any risk_typemodel_id is the hook to the model behind each measurement, applied across market, credit / counterparty, liquidity, concentration, scenario / stress and climate partitions) and the model-bearing records across the model.
  • Owns: the firm-wide model and AI inventory — a process artefact; a Model entity is an open extension.

Standards

  • SR 11-7 — the supervisory guidance on model risk management.
  • The EU AI Act, the NIST AI Risk Management Framework and the FINOS AI Governance Framework.
  • The model-validation practice the model-risk literature defines.

Open extensions

  • A Model entity — the validated, inventoried model as an owned record.
  • The model-risk-tiering and AI-risk-assessment sub-model.
  • The Service-Operation-level input/output contracts.

Built from open-investment-model v0.3.0 · f7452ad