SS1/23, published with Policy Statement PS6/23 on 17 May 2023 and effective from 17 May 2024, is the PRA's model risk management standard and the UK's closest equivalent to SR 11-7. It sets five principles — model identification and risk classification, governance, development and use, independent validation, and risk mitigants — covering all models used to inform business decisions, including vendor models, and includes a sub-principle on identifying and managing risks from AI and machine learning techniques. It applies formally to banks with internal-model permissions and assigns overall MRM accountability to a named Senior Management Function holder.
OFFICIAL TEXT: bankofengland.co.uk ↗ · IN FORCE · UK (BOE / PRA / FCA)
| Document | PRA SS1/23 — Supervisory Statement 1/23: Model risk management principles for banks |
| Issued by | Bank of England, Prudential Regulation Authority, and Financial Conduct Authority |
| Type | Guidance |
| Status | In force |
| Published | May 17, 2023 |
| Effective | May 17, 2024 |
| Applies to | UK-incorporated banks, building societies and PRA-designated investment firms with internal-model approval for credit risk (IRB), market risk (IMA) or counterparty credit risk (IMM); other firms are expected to apply it proportionately |
| Official source | bankofengland.co.uk ↗ |
| Use cases | Model risk management · Credit scoring & underwriting · Third-party & vendor AI · Generative & agentic AI · AI governance (general) |
What are the key points of PRA SS1/23?
- Five principles: (1) model identification and model risk classification, (2) governance, (3) model development, implementation and use, (4) independent model validation, (5) model risk mitigants.
- Scope is all models informing business decisions, regardless of technology, whether in-house or vendor-supplied, including models used for financial reporting.
- Sub-principle requires firms to identify and manage the risks of AI in modelling techniques such as machine learning to the extent that it applies to models generally.
- Accountability for the overall MRM framework must be allocated to the most appropriate SMF holder under the Senior Managers regime.
- Effectiveness of MRM for financial reporting must be reported to the audit committee.
- Proportionate implementation across model tiers and across firms; formal scope is internal-model banks, with others expected to apply it proportionately.
- In October 2025 the PRA held CRO roundtables with 21 firms on applying SS1/23 to AI/ML, covering risk appetite, model tiering, explainability, overfitting, validation and monitoring.
- Amended 23 April 2026 (LIAF01/26): the expectations are not conditions for internal model approval, newly permitted internal-model firms have 12 months to comply, and internal-model firms assess stress-test models against SS1/23 rather than SS3/18 alone.
What did PRA SS1/23 change for banks?
Before SS1/23 the PRA had no consolidated model-risk standard; UK banks often borrowed SR 11-7. SS1/23 made model risk a standalone discipline with named senior-manager accountability, and by deliberately covering AI/ML and vendor models it became the main channel through which the PRA supervises AI in banks. The BoE/PRA told government in April 2026 they intend to build on it further in 2026 using supervisory insights on good practice.
What does PRA SS1/23 require, and how do its model risk management principles apply to AI and machine-learning models?
Supervisory Statement 1/23, 'Model risk management principles for banks', is the Prudential Regulation Authority's model risk management standard. Published with Policy Statement 6/23 on 17 May 2023, in force since 17 May 2024 and amended on 23 April 2026, it sets five principles: model identification and model risk classification; governance; model development, implementation and use; independent model validation; and model risk mitigants. Its formal scope is UK-incorporated banks, building societies and PRA-designated investment firms with internal-model permissions for credit, market or counterparty credit risk, but the PRA expects every firm to apply it proportionately. The model definition covers all models that inform business decisions regardless of technology, including vendor models and models used for financial reporting, and a sub-principle requires firms to identify and manage the risks that arise from artificial intelligence and machine-learning techniques. Accountability for the whole MRM framework must be allocated to a named Senior Management Function holder.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Principle 1 — Model identification and model risk classification | UK (BoE / PRA / FCA) | A firm-wide definition of a model, a complete model inventory, and a risk-based tiering of every model by materiality and complexity that drives the intensity of every other principle. | Since 17 May 2024 |
| Principle 2 — Governance | UK (BoE / PRA / FCA) | Board-approved MRM policy and risk appetite, responsibility for the overall framework allocated to the most appropriate SMF holder, and reporting on the effectiveness of MRM for financial reporting to the audit committee. | Since 17 May 2024 |
| Principle 3 — Model development, implementation and use | UK (BoE / PRA / FCA) | Documented development standards, data quality and suitability assessments, testing, controls over implementation and use, and management of the specific risks of AI and machine-learning techniques as they apply to models generally. | Since 17 May 2024 |
| Principle 4 — Independent model validation | UK (BoE / PRA / FCA) | Validation independent of development, proportionate to tier, before use and periodically thereafter, with ongoing monitoring, effective challenge and findings tracked to closure; vendor models are validated like in-house ones. | Since 17 May 2024 |
| Principle 5 — Model risk mitigants | UK (BoE / PRA / FCA) | Governed post-model adjustments and overlays, restrictions on use, escalation and exception processes, and the ability to fall back when a model is found deficient. | Since 17 May 2024 |
| LIAF01/26 — amendment to SS1/23 ↗ | UK (BoE / PRA / FCA) | Clarifies that SS1/23 expectations are not conditions for internal model approval; a firm that first receives an internal-model permission has 12 months from the grant to comply. Internal-model firms now assess stress-test models against SS1/23 rather than SS3/18 alone. | From 23 Apr 2026 |
| PRA AI/ML model-risk roundtable (Oct 2025) | UK (BoE / PRA / FCA) | The PRA's current thinking, from two CRO roundtables with 21 firms on 20 and 22 October 2025, on applying SS1/23 to AI and ML: risk appetite, model tiering, explainability, overfitting, validation and monitoring. | Nov 2025 |
| Bank of England AI roundtables (summary, Feb 2026) ↗ | UK (BoE / PRA / FCA) | Three sector roundtables in late 2025, published 16 February 2026: firms called SS1/23 'pragmatic in enabling responsible AI adoption', asked for no AI-specific rules, and said traditional validation 'wouldn't be sustainable' for generative and agentic systems. | Feb 2026 |
SS1/23 is the UK's closest counterpart to the US interagency model risk guidance, but it differs in three ways that matter for AI. First, accountability is personal: the framework must be owned by a named SMF holder under the Senior Managers regime. Second, scope is deliberately technology-neutral — the definition captures any quantitative method that applies statistical, economic, financial or mathematical theories and techniques to process input data into an output used for business decisions, which brings machine-learning models, vendor-supplied scoring engines and generative tools that influence decisions inside the inventory. Third, the AI/ML sub-principle sits inside the framework rather than beside it: firms must identify and manage the risks of AI techniques to the extent the principles apply to models generally, so explainability, data provenance, drift and overfitting become validation questions, not a separate programme.
Compliance in practice runs on the model lifecycle. Identification and tiering (Principle 1) decide how much development documentation, validation depth and monitoring frequency each model gets; the PRA expects the tiering to consider materiality, complexity and, for AI, opacity. Independent validation (Principle 4) is where the October 2025 roundtable found the most inconsistency: several firms were applying core SS1/23 expectations unevenly where AI models introduce opacity, uncertainty and faster rates of change, and the PRA's slides set out its thinking on explainability, overfitting and ongoing monitoring as validation requirements. Model risk mitigants (Principle 5) — overlays, use restrictions, escalation — are what let a firm keep using a model whose limitations are known while remediation proceeds.
Two 2026 developments change the picture. The 23 April 2026 low-impact amendments (LIAF01/26) make explicit that SS1/23 is not a condition of internal-model approval and give newly permitted firms 12 months to comply, while folding stress-test model risk under SS1/23 for internal-model firms. And the Bank's February 2026 summary of its AI roundtables records that firms want SS1/23 applied, not replaced: the challenge they raised is that the traditional 'inputs to outputs' understanding at the heart of validation does not scale to generative AI and agentic systems, so risk management must move toward testing, monitoring and guardrails around outcomes. The PRA and Bank told Parliament in April 2026 that they intend to build on SS1/23 during 2026 using supervisory insights on good practice.
WHAT THIS MEANS IN PRACTICE
- SS1/23 compliance requirements start with the inventory: if a generative AI tool, a vendor fraud score or a spreadsheet influences a business decision, it is a model and needs a tier, an owner and a validation plan.
- SS1/23 model validation for AI/ML models must cover data provenance, explainability, overfitting and drift monitoring — the PRA's October 2025 slides treat these as ordinary validation questions at the right tier.
- Genai and agentic systems are in scope; the PRA's own summary says traditional validation will not be sustainable for them, so build outcome testing, monitoring and guardrails (Principle 5 mitigants) into the design rather than waiting for a validation exception.
- Name the SMF holder for model risk and give the audit committee the required report on MRM effectiveness for financial reporting — both are examinable evidence under Principle 2.
- Regulatory expectations for firms outside the formal scope are proportionate application, not exemption; the PRA reads SS1/23 as the benchmark for all banks' model controls.
- New internal-model firms have 12 months from permission to comply (LIAF01/26); everyone else has been expected to comply since 17 May 2024, with self-assessment and remediation plans available to supervisors.
Does SS1/23 apply to machine learning and AI models?
Yes. It covers all models used to inform business decisions regardless of technology and includes a sub-principle on identifying and managing AI/ML risks; the PRA has since run roundtables on applying it to AI.
Which banks must comply with SS1/23?
Formally, UK-incorporated banks, building societies and PRA-designated investment firms with IRB, IMA or IMM internal-model approvals; other firms are expected to apply the principles proportionately.
How does SS1/23 compare with SR 11-7?
Both are principles-based supervisory statements on model risk covering development, validation and governance; SS1/23 additionally names an accountable SMF holder, requires audit-committee reporting, and explicitly addresses AI/ML.
| Date | Document | Status |
|---|---|---|
| Jul 14, 2026 | HM Treasury Financial Services AI Adoption Plan (Jul 2026) — Financial Services AI Adoption Plan | Final |
| Jun 5, 2026 | 2026 BoE/FCA AI survey — The Bank of England and FCA's 2026 AI Survey | Final |
| May 15, 2026 | BoE/FCA/HMT joint statement on frontier AI and cyber resilience (May 2026) — The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience | In force |
| Apr 1, 2026 | BoE response to Treasury Committee AI inquiry (Apr 2026) — Response to TSC inquiry report on AI in financial services | Final |
| Apr 1, 2026 | BoE/PRA plan for safe AI innovation (Apr 2026) — Letter from Sarah Breeden and Sam Woods to the Chancellor and Secretaries of State on enabling safe AI innovation | Final |
| Jan 28, 2026 | DSIT/DBT strategic letters to regulators (Jan 2026) — How will regulators enable safe AI-powered innovation: joint letter from DSIT Secretary of State and DBT Secretary of State | Final |
Which banks' AI programmes does PRA SS1/23 reach?
3 of the 100 largest US banks profiled on this site cite PRA SS1/23 among the documents their AI work answers to.
Follow every document these regulators publish
the daily brief · six sourced stories · in your inbox by 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning