What is a Model Risk Management?

Model risk management (MRM) is the governance discipline of identifying, measuring, and controlling the risks that arise from relying on a statistical or machine learning model for a business decision, including the risk that the model is wrong, misused, or degrades over time.

MRM originated in banking regulation (the Federal Reserve's SR 11-7 guidance) as a framework covering model development, independent validation, and ongoing monitoring, and it has since expanded into a general practice for any organization deploying AI in consequential decisions. Core activities include documenting a model's intended use and limitations, having someone other than the model's builder validate its performance, and setting thresholds that trigger review when live performance drifts from what was validated. For LLM-based systems, model risk extends beyond a single model's accuracy to include prompt injection risk, hallucination in high-stakes outputs, and cascading failures across multi-step agent chains. Effective MRM programs maintain a model inventory, tier models by decision impact, and require higher scrutiny, human review, tighter guardrails, more frequent revalidation, for models used in regulated or high-consequence workflows.

In practice with Neotask

Neotask tenants operating in regulated industries can require human approval gates on agent actions above a configured risk tier, and Neotask logs which model version handled each decision so a tenant's model risk program has an auditable record to validate against.

Related terms

Start free

Plans

Free

$0/mo

Download without a card and start for free.

Individual

$50/mo

The full personal agent platform for one person.

Enterprise

$200/mo

Multiple workspaces and capacity for larger teams.

Continue