Model risk management in Germany
A model that prices a loan, measures capital or scores a credit application has to withstand a supervisor reading it. In Germany the duty comes from MaRisk, BaFin's minimum requirements for risk management, and for a bank under European Central Bank supervision from the ECB guide to internal models. Since the EU AI Act took effect, a credit scoring model carries a second set of obligations on top of the banking ones.
What model risk is and where the German duty comes from
Model risk is the loss a firm takes because a model is wrong or is used outside what it was built for. A pricing model calibrated on a decade of falling rates misstates a portfolio when rates rise, and a scorecard trained on applicants who were approved says nothing reliable about the ones who were refused.
German banks work from MaRisk, which BaFin issues as a circular and not as a statute. AT 4.1 ties the risk-bearing capacity calculation to methods the institution can explain, and AT 4.3.2 requires the risk quantification procedures to be reviewed regularly for how appropriate they are. For a significant institution the European Central Bank adds its guide to internal models, which sets out what supervisors read when they review a model for capital purposes.
Where model risk comes from
Five places produce almost every model failure, and a bank that names them can test for them. The data is wrong, incomplete or no longer representative of the population the model is applied to. The assumptions are flawed or the calibration is out of date. The method is unsuitable for the question, which no amount of fitting repairs. The implementation carries a coding error that the formula does not. Or the output is read as something it does not say.
The sixth, and the one supervisors ask about most, is use outside the tested range. A model built to rank applicants within one product gets applied to another, a stress scenario is run with parameters the calibration never saw, and the number that comes out looks exactly as authoritative as a valid one. Public failures followed this shape: value-at-risk models that treated 2008 correlations as impossible, and JPMorgan's 2012 losses in the synthetic credit portfolio known as the London Whale, where a spreadsheet model in use understated the position's risk.
How a bank tests a model: backtesting, challengers and stress
Four techniques carry most of the testing. Backtesting compares what the model predicted against what happened. A challenger model, built by someone else or on a simpler specification, gives the result a reference point. Sensitivity analysis moves one input at a time to show which assumption the output actually depends on. Stress testing runs the model at the edges of its range and past them, which is where a model stops being conservative.
Monitoring sits next to validation and runs continuously. The population the model scores drifts away from the development sample, and the shift is measurable with the population stability index or a Kolmogorov-Smirnov test on the score distribution before anybody notices a performance drop. Model validation in banking sets out the method and the thresholds in detail.
Independent validation and who signs off
Validation belongs to someone who did not build the model. MaRisk puts the development of the procedures and the review of them in separate hands, and the review reports to management without passing through the unit whose model is under review. In practice a bank runs a validation function in the second line of defense, and the method it follows is a document of its own.
Sign-off reaches the management body. Under MaRisk the overall responsibility for risk management stays with the managing directors, so a model that fails its own tolerance and keeps running is a management decision, documented as one. The internal audit function then checks whether the validation itself was done properly, which is a third look at the same model.
The model inventory as the first thing a supervisor asks for
Before a supervisor reads one model it asks which models exist. A complete register with an owner, a purpose and a last validation date per entry answers that question; an incomplete one turns the review into an argument about scope. MaRisk AT 4.3.1 requires processes and responsibilities to be documented and kept current, which is what makes the register a duty and not a convenience.
Two kinds of entry are missed most often. Spreadsheet models built by a business unit never pass through model governance, and a model embedded in a purchased application belongs to the bank's risk even though a provider wrote it. The register that holds AI and models in finance treats both as in scope.
IFRS 9 loss models and the judgment inside them
An IFRS 9 expected credit loss model is where accounting and model risk meet. The standard asks for a forward-looking loss estimate, so the model takes a macroeconomic forecast as an input and the choice of scenario moves the provision. The Deutsche Bundesbank supervises how institutions apply the standard and treats the significant increase in credit risk test, which decides when an exposure moves to stage two, as a modeling choice that has to be justified.
Post-model adjustments are the part that attracts questions. When a bank overlays a management judgment on the model output, the overlay needs the same documentation as the model, including when it will be removed. Credit risk work in German banks sits on these numbers, and the Basel III output floor limits how far internal models may reduce capital below the standardized calculation.
AI and machine learning models under the EU AI Act
Two uses in finance are high-risk under the AI Act. Annex III of Regulation (EU) 2024/1689 lists AI systems used to evaluate the creditworthiness of natural persons or establish their credit score, and systems used for risk assessment and pricing in life and health insurance. A deployer of such a system carries obligations on human oversight, logging and monitoring that run next to MaRisk, not instead of it.
BaFin published guidance on ICT risks in the use of AI systems in December 2025. Its position is that an AI system is part of ICT risk management under DORA and creates no separate regime, with testing scaled to how critical the system is. A model that decides nothing on its own and a model that refuses a loan application therefore sit at different points on the same scale. Machine learning in finance and the AI Act in finance cover the wider picture.
What is model risk management in banking?
Model risk management is the set of controls a bank runs so that its models are fit for the decisions taken with them: a register of every model in use, independent validation of each one, limits on use outside the tested range, and a route to management when a model breaks its tolerance. In Germany the requirement comes from MaRisk, and for banks under European Central Bank supervision from the ECB guide to internal models.
Who supervises models in German banks?
BaFin supervises model risk at less significant institutions and issues MaRisk, which states the duty. The European Central Bank supervises models at significant institutions directly and approves internal models used for capital, with the Deutsche Bundesbank carrying out on-site examinations. Where a model scores consumer credit, the AI Act adds obligations that the market surveillance structure for AI enforces, not BaFin's banking supervision alone.
How often does a model have to be validated?
Once a year for the models that matter, plus whenever something happens that invalidates the last review. MaRisk sets no single interval and asks instead for a review appropriate to the model, so a bank writes the cycle into its own policy by risk tier. A market break, a data source that changes definition, or a provider updating a purchased model are the usual triggers for an unscheduled revalidation.
Model risk management and Finance Loop
Finance Loop is the meeting place for the people who build, validate and supervise models in German finance. Finance Loop events bring model risk officers, quants from the second line and AI governance leads together with the supervisors and auditors who read their reports.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.