SS1/23, published with Policy Statement PS6/23 on 17 May 2023 and effective from 17 May 2024, is the PRA's model risk management standard and the UK's closest equivalent to SR 11-7. It sets five principles — model identification and risk classification, governance, development and use, independent validation, and risk mitigants — covering all models used to inform business decisions, including vendor models, and includes a sub-principle on identifying and managing risks from AI and machine learning techniques. It applies formally to banks with internal-model permissions and assigns overall MRM accountability to a named Senior Management Function holder.
| Document | PRA SS1/23 — Supervisory Statement 1/23: Model risk management principles for banks |
| Issued by | Bank of England, Prudential Regulation Authority, and Financial Conduct Authority |
| Type | Guidance |
| Status | In force |
| Published | May 17, 2023 |
| Effective | May 17, 2024 |
| Applies to | UK-incorporated banks, building societies and PRA-designated investment firms with internal-model approval for credit risk (IRB), market risk (IMA) or counterparty credit risk (IMM); other firms are expected to apply it proportionately |
| Official source | bankofengland.co.uk ↗ |
| Use cases | Model risk management · Credit scoring & underwriting · Third-party & vendor AI · Generative & agentic AI · AI governance (general) |
What are the key points of PRA SS1/23?
- Five principles: (1) model identification and model risk classification, (2) governance, (3) model development, implementation and use, (4) independent model validation, (5) model risk mitigants.
- Scope is all models informing business decisions, regardless of technology, whether in-house or vendor-supplied, including models used for financial reporting.
- Sub-principle requires firms to identify and manage the risks of AI in modelling techniques such as machine learning to the extent that it applies to models generally.
- Accountability for the overall MRM framework must be allocated to the most appropriate SMF holder under the Senior Managers regime.
- Effectiveness of MRM for financial reporting must be reported to the audit committee.
- Proportionate implementation across model tiers and across firms; formal scope is internal-model banks, with others expected to apply it proportionately.
- In October 2025 the PRA held CRO roundtables with 21 firms on applying SS1/23 to AI/ML, covering risk appetite, model tiering, explainability, overfitting, validation and monitoring.
What did PRA SS1/23 change for banks?
Before SS1/23 the PRA had no consolidated model-risk standard; UK banks often borrowed SR 11-7. SS1/23 made model risk a standalone discipline with named senior-manager accountability, and by deliberately covering AI/ML and vendor models it became the main channel through which the PRA supervises AI in banks. The BoE/PRA told government in April 2026 they intend to build on it further in 2026 using supervisory insights on good practice.
Does SS1/23 apply to machine learning and AI models?
Yes. It covers all models used to inform business decisions regardless of technology and includes a sub-principle on identifying and managing AI/ML risks; the PRA has since run roundtables on applying it to AI.
Which banks must comply with SS1/23?
Formally, UK-incorporated banks, building societies and PRA-designated investment firms with IRB, IMA or IMM internal-model approvals; other firms are expected to apply the principles proportionately.
How does SS1/23 compare with SR 11-7?
Both are principles-based supervisory statements on model risk covering development, validation and governance; SS1/23 additionally names an accountable SMF holder, requires audit-committee reporting, and explicitly addresses AI/ML.
| Date | Document | Status |
|---|---|---|
| Jul 14, 2026 | HM Treasury Financial Services AI Adoption Plan (Jul 2026) — Financial Services AI Adoption Plan | Final |
| Jun 5, 2026 | 2026 BoE/FCA AI survey — The Bank of England and FCA's 2026 AI Survey | Final |
| May 15, 2026 | BoE/FCA/HMT joint statement on frontier AI and cyber resilience (May 2026) — The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience | In force |
| Apr 1, 2026 | BoE response to Treasury Committee AI inquiry (Apr 2026) — Response to TSC inquiry report on AI in financial services | Final |
| Apr 1, 2026 | BoE/PRA plan for safe AI innovation (Apr 2026) — Letter from Sarah Breeden and Sam Woods to the Chancellor and Secretaries of State on enabling safe AI innovation | Final |
| Jan 28, 2026 | DSIT/DBT strategic letters to regulators (Jan 2026) — How will regulators enable safe AI-powered innovation: joint letter from DSIT Secretary of State and DBT Secretary of State | Final |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →