Risk

Model Risk Management: A Career Path for People Who Question Other People's Models

Model risk management sits between quant finance and traditional risk work: independent validators who test whether a bank's models actually do what their builders claim. Here is what the job involves, who gets hired, and how the career progresses.

Two-color print illustration of a balance scale weighing a stack of documents against a certificate with a wax seal.

A bank's credit scoring model has been in production for two years, approving small-business loans in under a minute. The developers built it on three years of pre-pandemic data and it has performed well on every metric they report. A model validator pulls the last eighteen months of outcomes and finds something the developers' dashboard never surfaces: the model's accuracy has quietly degraded for a specific segment, newly formed businesses with thin credit histories, because the population the model now scores looks less and less like the population it was trained on. Nothing crashed. No alert fired. The model just got worse at its job while reporting that everything was fine. Catching that gap before it shows up in loan losses is what model risk management is for.

It is a distinct discipline from the credit risk, market risk, or operational risk teams that most people picture when they hear "risk management." Model risk managers do not decide whether to make a loan or approve a trade. They decide whether the model that makes that recommendation can be trusted, and by how much.

What model risk management actually is

Banks and other regulated financial institutions run hundreds to thousands of models: credit scoring, fraud detection, anti-money-laundering transaction monitoring, capital and stress-testing models, pricing and valuation models, and increasingly machine-learning models for underwriting and marketing. Each one embeds assumptions that can be wrong, data that can drift, and code that can contain errors no one has found yet. Model risk is the risk that a decision made using a flawed model turns out to be wrong, at scale, before anyone notices.

In U.S. banking, this function exists in something close to its current form because of supervisory guidance, most notably the Federal Reserve and OCC's joint guidance on model risk management, which set an expectation that banks maintain an inventory of every model in use, assign each one a risk tier, and subject higher-tier models to independent validation before deployment and periodically afterward. That guidance is the reason almost every bank above a certain size has a model risk function with its own budget and reporting line, separate from the teams that build the models.

The independence is the point. A model validation team reports up a different chain than model development, usually into the second line of defense alongside compliance and other risk functions, precisely so that the people grading a model's fitness are not the people whose bonus depends on it being approved.

What the work looks like day to day

A validator's core deliverable is the validation report, and most of the job is the work that produces it.

  • **Documentation review.** Before touching any numbers, you read the model's technical documentation: what problem it solves, what data trained it, what assumptions it makes, and what its known limitations are. Thin or outdated documentation is itself a finding, because a model no one can explain is a model no one can govern.
  • **Conceptual soundness review.** You evaluate whether the modeling approach fits the problem. A logistic regression for a binary default outcome is defensible; the same technique forced onto a problem with strong nonlinear interactions is a design flaw, whatever its backtested accuracy looks like today.
  • **Replication and benchmarking.** For higher-risk models, you rebuild all or part of the model independently from the same data and compare outputs, or you build a simpler challenger model and check whether the production model earns its added complexity.
  • **Outcomes analysis and backtesting.** You compare the model's predictions against what actually happened, on a schedule (often quarterly or annually depending on the model's tier) and look specifically for degradation in subpopulations, not just the aggregate number.
  • **Sensitivity and stress testing.** You perturb inputs to see how much the output moves, and you check the model's behavior at the edges of its data, not just in the well-populated middle where it was easiest to fit.
  • **Writing the finding and assigning a rating.** Every validation ends in a rating, commonly something like low, moderate, or high residual risk, along with specific findings that come with a required remediation timeline. A high-risk finding on a capital model can trigger a formal restriction on how the model may be used until it is fixed.

None of this happens in isolation. A validator spends real time in meetings with model developers defending or revising findings, and a validation report that developers cannot follow or dispute on the merits has failed at its actual purpose, which is to change how the model gets used.

The skills that actually matter

The field attracts people who assume it requires a PhD in statistics, and some validation teams do hire almost exclusively from that pool, particularly for market-risk and capital models where the mathematics is genuinely advanced. But a large share of model risk work, especially on the consumer credit and operational side, rewards a different combination: enough quantitative fluency to read a regression output or a model's performance metrics critically, strong technical writing, and the same evidence discipline that shows up across audit and compliance work.

The skills that separate a validator who gets taken seriously from one who gets talked past by developers:

  • Comfort reading code and statistical output without needing someone to translate it, even if you could not have built the model yourself.
  • The ability to state a technical finding in one sentence a business stakeholder can act on, the same discipline that shows up in writing an internal audit finding that actually drives a fix.
  • Willingness to hold a position under pushback from people who built the model and are certain it is fine. A validator who folds under a confident developer is not doing the job.
  • Working knowledge of the business the model serves. A credit model validator who does not understand underwriting will miss conceptual flaws no statistical test would catch.

How people actually get in

Entry paths split roughly three ways. Quantitative graduates, statistics, economics, financial engineering, applied math, join directly into validation teams as analysts and learn the regulatory and governance side on the job. Model developers move into validation after a few years of building models, trading a narrower technical role for one with broader exposure across a bank's model inventory, though some banks require a cooling-off period before someone can validate a model type they previously built, to preserve independence. And risk, audit, or compliance professionals with strong analytical backgrounds move in laterally, particularly into governance-heavy parts of the function such as maintaining the model inventory, running the risk-tiering process, or coordinating remediation tracking, roles that need less deep quantitative training and more of the same evidence-and-process discipline that carries across the wider risk and audit world.

For someone outside quant finance who wants in, the realistic entry point is rarely a senior validator seat on a capital model. It is a model risk governance analyst role, or a junior validator seat on lower-tier models such as marketing or vendor-scoring models, where the statistics are simpler and the job is mostly about rigor, documentation, and the willingness to ask an uncomfortable question of the person who built the thing.

Where the career goes

A validation analyst who is good at the work typically moves to senior validator within two to three years, taking ownership of the bank's highest-tier models: capital, stress testing, and enterprise-wide credit models. From there the path splits. Some validators move into model risk management leadership, running the governance framework, the inventory, and the reporting to the board's risk committee. Others move toward specialization, becoming the bank's go-to expert on a model class such as machine-learning underwriting models or anti-money-laundering detection models, a track that increasingly commands a premium as regulators scrutinize AI-driven decisioning more closely. A smaller group moves the other direction, back into model development or into a broader quantitative risk role, using the validation background as a credential that they understand not just how to build a model but how it will be judged.

The constant across all of those paths is the same tension the job starts with: staying close enough to the model to actually understand it, without getting close enough to lose the independence that makes your judgment worth anything.