Insights on Crypto Payments, Infrastructure, and Operations

Model Risk

Pronunciation: MAH-dul RISK

Definition

Model risk is the possibility of harmful decisions or estimates caused by flawed models, data, assumptions, implementation, interpretation, or use. Model Risk must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner. Decision-makers use Model Risk to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified.

Overview

Model risk affects statistical, financial, fraud, compliance, pricing, forecasting, and machine-learning systems. A model may be conceptually wrong, trained on poor data, incorrectly implemented, applied outside its intended population, or misunderstood by decision-makers.

Performance can deteriorate through drift, adversarial behavior, feedback loops, hidden bias, missing variables, or changing markets. Apparent accuracy may conceal poor calibration, unstable segments, or labels created by earlier model decisions.

Organizations should inventory models, define owners and intended use, validate independently, monitor drift and outcomes, control changes, and maintain fallback procedures. High-impact decisions need explainability, human escalation, and challenge processes appropriate to the risk. Material models should have independent approval before production use and after significant change.

Model risk is the possibility of harmful decisions or estimates caused by flawed models, data, assumptions, implementation, interpretation, or use. Model risk comes from the entire decision system, including data, assumptions, implementation, use, monitoring, and human interpretation.

For Model Risk, the assessment should evaluate the possibility of harmful decisions or estimates caused by flawed models, data, assumptions, implementation, interpretation, or use. The assessment record should separate observed evidence supporting the possibility of harmful decisions or estimates caused by flawed models, data, assumptions, implementation, interpretation, or use from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility of harmful decisions or estimates caused by flawed models, data, assumptions, implementation, interpretation, or use have changed enough to require a new rating, treatment, or approval.

Decision-makers should use findings about the possibility of harmful decisions or estimates caused by flawed models, data, assumptions, implementation, interpretation, or use to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.

Key Takeaway

Model risk comes from the entire decision system, including data, assumptions, implementation, use, monitoring, and human interpretation.

Sources

  1. NIST Documentation: Cyberframework — NIST (2026-07-30)
  2. FATF Documentation: Virtual Assets — FATF (2026-07-30)