# BaFin/Bundesbank ML in risk models results: Machine learning in risk models – Characteristics and supervisory priorities: Responses to the consultation paper

Source: https://www.bankingnewsai.com/ai-regulation/documents/bafin-bundesbank-ml-risk-models-2022
Last updated: Oct 5, 2026

On 18 February 2022 BaFin and the Deutsche Bundesbank published the responses to their joint consultation paper 'Machine learning in risk models – Characteristics and supervisory priorities', which the Bundesbank dates 15 July 2021 as Consultation 11/2021. The paper confirms that supervisors will not define machine learning but will tailor supervisory practice to the characteristics of the method in a technology-neutral way. Respondents broadly agreed that existing Pillar 1 and Pillar 2 rules are sufficient, with explainability and model adaptivity left as areas needing further discussion. It is non-binding and does not change the requirement for supervisory approval of internal models.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [BaFin](https://www.bankingnewsai.com/ai-regulation/bafin) |
| Type | Report |
| Status | Final |
| Published | Feb 18, 2022 |
| Applies to | Banks and insurers supervised by BaFin and the Bundesbank that use machine-learning methods in Pillar 1 internal models for regulatory own funds requirements or in Pillar 2 risk management. The paper focuses on solvency supervision and is a summary of consultation feedback and next steps, not a binding rule. |
| Official text | https://www.bafin.de/SharedDocs/Downloads/EN/Aufsichtsrecht/dl_Ergebnisse_machinelles_Lernen_Risikomodelle_en.html |

## Key points

- Consultation paper published in July 2021 (Bundesbank page: 15 July 2021, Consultation 11/2021); responses paper published 18 February 2022; the Bundesbank and BaFin are the joint publishers.
- Scope: ML in internal models for regulatory own funds requirements (Pillar 1), described as an exception to the principle that algorithms need no supervisory approval, and ML in risk management under Pillar 2.
- Feedback came from banking and insurance associations, individual insurers and banks, management consultancies and technology firms; ML is already used for money laundering and fraud detection and credit-process analyses, but only a few Pillar 1 risk models use it so far, and it is often used as a support or challenger tool.
- Characteristics approach: no strict definition of ML; supervision and inspection intensity follow characteristics in three dimensions — methodology and data basis (complexity and model risk), use of the output (significance in risk management) and, per the consultation paper, in-house development versus outsourcing and IT infrastructure. Respondents broadly agreed and said outsourcing and IT infrastructure are not ML-specific.
- Section III.1: respondents largely agree that technology-neutral, risk-oriented regulation provides a sufficient framework; banks assess the ML-related requirements of EBA/GL/2020/06 as appropriate, technology-neutral and risk-oriented.
- Section III.2: data quality and representativeness, overfitting risk and 'believing in data' are the main data issues; respondents saw no new or special data requirements for ML.
- Section III.3: explainability is a central criterion; most respondents think only the final output, not every intermediate step, must be explainable; explainable-AI methods are not seen as a panacea and respondents said supervisory standards for them are premature.
- Section III.4 and IV: the line between model maintenance and model change is unclear for adaptive ML; respondents asked for a clearer definition of model change and faster approval. Supervisors say the results start a dialogue with firms and feed into the Commission's Digital Finance Strategy and work with other European supervisors.

## What changed for banks

The paper did not create new requirements. It confirmed that BaFin and the Bundesbank would supervise ML in risk models through existing technology-neutral Pillar 1 approval and Pillar 2 risk-management rules, scaled to characteristics such as complexity, explainability and adaptivity, and it identified explainability and model change as the open questions for further supervisory dialogue — the same questions the EBA later pursued on machine learning for IRB models.

## Use cases it governs

- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)
- [Credit scoring & underwriting](https://www.bankingnewsai.com/ai-regulation/by-use-case#credit-underwriting)
- [AML / KYC](https://www.bankingnewsai.com/ai-regulation/by-use-case#aml-kyc)
- [Fraud detection](https://www.bankingnewsai.com/ai-regulation/by-use-case#fraud)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)

## What do BaFin and the Bundesbank expect from banks using machine learning in risk models?

BaFin and the Bundesbank do not set new ML-specific rules. Their February 2022 responses paper confirms that supervisors will not define machine learning but will gear supervisory and inspection practice to the characteristics of the method used, mainly its methodology and data basis, which determine complexity and model risk, and the importance of its output within risk management. Pillar 1 internal models still require supervisory approval under existing technology-neutral rules, and Pillar 2 ML use falls under principles-based risk-management requirements such as MaRisk. In practice, respondents and supervisors converge on representative, high-quality data, explainability of the final output, a clear separation of modelling and validation, and clear model governance, including a clearer line between model maintenance and model change for adaptive ML.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Section I — Pillar 1 internal models: supervisory approval remains | [BaFin](https://www.bankingnewsai.com/ai-regulation/bafin) | ML methods used in internal models for regulatory own funds requirements remain subject to prudential inspection and approval, as an exception to the rule that algorithms are not approved. | Published 18 February 2022; non-binding | [BaFin/Bundesbank ML in risk models results](https://www.bankingnewsai.com/ai-regulation/documents/bafin-bundesbank-ml-risk-models-2022) |
| Section II — Characteristics rather than a definition | [BaFin](https://www.bankingnewsai.com/ai-regulation/bafin) | Supervisory practice and inspection intensity are oriented to whether and how strongly ML characteristics are present, in particular methodology, data basis and use of the output. | Published 18 February 2022; non-binding | [BaFin/Bundesbank ML in risk models results](https://www.bankingnewsai.com/ai-regulation/documents/bafin-bundesbank-ml-risk-models-2022) |
| Section III.1 — Existing technology-neutral rules apply | [BaFin](https://www.bankingnewsai.com/ai-regulation/bafin) | Pillar 1 approval rules and Pillar 2 principles-based risk-management and IT requirements are the framework for ML; banks consider the ML-related requirements of EBA/GL/2020/06 appropriate. | Referenced in the February 2022 responses paper | [EBA Guidelines on loan origination and monitoring (EBA/GL/2020/06)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2020-06-loan-origination-monitoring) |
| Section III.2 — Data quality and representativeness | [BaFin](https://www.bankingnewsai.com/ai-regulation/bafin) | Data must be as representative as possible and its quality ensured on an ongoing basis during development, validation and application, with attention to overfitting. | Published 18 February 2022; non-binding | [BaFin/Bundesbank ML in risk models results](https://www.bankingnewsai.com/ai-regulation/documents/bafin-bundesbank-ml-risk-models-2022) |
| Section III.3 — Explainability | [BaFin](https://www.bankingnewsai.com/ai-regulation/bafin) | Explainability is a central criterion for model choice and validation; respondents consider explainability of the final output sufficient and say XAI methods are themselves models with weaknesses. | Published 18 February 2022; non-binding | [BaFin/Bundesbank ML in risk models results](https://www.bankingnewsai.com/ai-regulation/documents/bafin-bundesbank-ml-risk-models-2022) |
| Section III.4 — Adaptivity and model change | [BaFin](https://www.bankingnewsai.com/ai-regulation/bafin) | Changes to Pillar 1 models must be notified and, where applicable, approved; the line between maintenance and model change for ML is contested, and the need for high-frequency adaptivity should be justified. | Published 18 February 2022; non-binding | [BaFin/Bundesbank ML in risk models results](https://www.bankingnewsai.com/ai-regulation/documents/bafin-bundesbank-ml-risk-models-2022) |
| Section IV — Outlook | [BaFin](https://www.bankingnewsai.com/ai-regulation/bafin) | Results start a supervisory dialogue and are to be fed into the European Commission's Digital Finance Strategy work and discussed with other European supervisors. | Published 18 February 2022; non-binding | [official text](https://www.bundesbank.de/en/homepage/machine-learning-in-risk-models-characteristics-and-supervisory-priorities-793670) |

The results paper complements, rather than replaces, the June 2021 BDAI principles: the two are meant to give clarity on the development and application of ML in supervision-relevant Pillar 1 and Pillar 2 models. Because Pillar 1 models are approved under existing rules, supervisors say they want to preserve the ability to monitor risk models, and they flag explainability and adaptivity as the issues where views diverge most.

At EU level the EBA ran a parallel consultation on ML for IRB models, which the results paper cites; the EBA's discussion paper and its 2023 follow-up report are tracked separately on this site.

### What this means in practice

- Classify each ML model by complexity and by how its output is used in risk management to anticipate supervisory intensity.
- Keep Pillar 1 ML models inside the model-approval and model-change notification process, and define what counts as maintenance versus change.
- Document training data representativeness and test for overfitting before moving ML models into production.
- Decide per use case how much explainability is needed and whether XAI tools are part of validation.
- Preserve independence between modelling and validation even where data-science and modelling teams are merged.

## FAQ

### Is the BaFin and Bundesbank machine-learning paper binding?

No. It summarises responses to a consultation and sets out next steps. The consultation paper proposed supervisory practice based on the characteristics of ML methods, and the results paper says the findings are the basis for dialogue with firms.

### Do banks need approval to use machine learning in risk models?

For internal models used to calculate regulatory own funds requirements (Pillar 1), yes: the paper describes these as an exception to the rule that algorithms do not require supervisory approval, and the approval procedures apply technology-neutrally, including where ML is used. ML used in Pillar 2 risk management is not subject to approval, but existing principles-based requirements such as MaRisk remain applicable.

### Does the paper define machine learning?

No. The consultation paper proposed forgoing a definition and gearing supervisory practice to the characteristics of the specific method; the responses reaffirmed this, noting that any definition would be insufficient given the variety of methods and that no clear line separates ML from traditional procedures.

### How does this compare with the EBA's work on machine learning for IRB models?

The paper footnotes the EBA consultation on machine learning for internal ratings-based models. Both treat ML under existing technology-neutral internal-model rules; see the EBA discussion paper and follow-up report for the EU-level analysis.

## Related documents

- [BaFin guidance on ICT risks in the use of AI](https://www.bankingnewsai.com/ai-regulation/documents/bafin-ai-ict-risk-guidance-2025) — Guidance on ICT Risks in the Use of AI at Financial Entities (Dec 18, 2025)
- [BaFin BDAI principles paper](https://www.bankingnewsai.com/ai-regulation/documents/bafin-ai-principles-2021) — Big data and artificial intelligence: Principles for the use of algorithms in decision-making processes (Jun 15, 2021)
- [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://www.bankingnewsai.com/ai-regulation/documents/eu-digital-omnibus-ai-regulation-2026-1744) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (Jul 24, 2026)
- [RBI draft Guidance on Regulatory Principles for Model Risk Management](https://www.bankingnewsai.com/ai-regulation/documents/rbi-model-risk-management-guidance-2026) — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments) (Jun 24, 2026)
- [FSB AI sound practices consultation (June 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-ai-sound-practices-consultation-2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report (Jun 10, 2026)
- [2026 BoE/FCA AI survey](https://www.bankingnewsai.com/ai-regulation/documents/uk-ai-in-financial-services-survey-2026) — The Bank of England and FCA's 2026 AI Survey (Jun 5, 2026)
- [Hill House oversight testimony (Jun 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fdic-testimony-oversight-prudential-regulators-2026) — Statement of Chairman Travis Hill: Oversight of Prudential Regulators (Jun 4, 2026)
- [IOSCO FR/02/2026](https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026) — Supervisory Toolkit for AI Use in Capital Markets: Final Report (May 25, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://www.bafin.de/SharedDocs/Downloads/EN/Aufsichtsrecht/dl_Ergebnisse_machinelles_Lernen_Risikomodelle_en.html) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/bafin-bundesbank-ml-risk-models-2022
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
