AI Regulation Tracker · UK (BoE / PRA / FCA) · Guidance

What does PRA SS1/23 say about AI in banking?

Published May 17, 2023 · Last reviewed Sep 2, 2026

SS1/23, published with Policy Statement PS6/23 on 17 May 2023 and effective from 17 May 2024, is the PRA's model risk management standard and the UK's closest equivalent to SR 11-7. It sets five principles — model identification and risk classification, governance, development and use, independent validation, and risk mitigants — covering all models used to inform business decisions, including vendor models, regardless of technology. The text does not use the words 'artificial intelligence' or 'machine learning'; it reaches AI through tiering factors for 'newly advanced approaches or technologies' (unstructured data, interpretability, explainability, bias) and testing of dynamic models that change autonomously. It applies formally to banks with internal-model permissions and assigns overall MRM accountability to a named Senior Management Function holder.

OFFICIAL TEXT: bankofengland.co.uk ↗ · IN FORCE · UK (BOE / PRA / FCA)

DocumentPRA SS1/23 — Supervisory Statement 1/23: Model risk management principles for banks
Issued byBank of England, Prudential Regulation Authority, and Financial Conduct Authority
TypeGuidance
StatusIn force
PublishedMay 17, 2023
EffectiveMay 17, 2024
Applies toUK-incorporated banks, building societies and PRA-designated investment firms with internal-model approval for credit risk (IRB), market risk (IMA) or counterparty credit risk (IMM); the expectations do not apply to other firms, which the PRA says may find the principles useful
Official sourcebankofengland.co.uk ↗
Use casesModel risk management · Credit scoring & underwriting · Third-party & vendor AI · Generative & agentic AI · AI governance (general)

What are the key points of PRA SS1/23?

  • Five principles: (1) model identification and model risk classification, (2) governance, (3) model development, implementation and use, (4) independent model validation, (5) model risk mitigants.
  • Scope is all models informing business decisions, regardless of technology, whether in-house or vendor-supplied, including models used for financial reporting.
  • AI and ML are addressed through general principles, not by name: Principle 1.3(c) complexity factors for 'newly advanced approaches or technologies' (alternative and unstructured data; interpretability, explainability, transparency and potential for designer or data bias) and Principle 3.3(c) testing of material changes in dynamic models that adapt or recalibrate autonomously. The PRA's publication page summarises this as a sub-principle on AI in modelling techniques such as machine learning.
  • Accountability for the overall MRM framework must be allocated to the most appropriate SMF holder under the Senior Managers regime.
  • Effectiveness of MRM for financial reporting must be reported to the audit committee.
  • Proportionate implementation across model tiers and across firms; the expectations apply only to internal-model banks, and the PRA says other firms may find the principles useful.
  • In October 2025 the PRA held CRO roundtables with 21 firms on applying SS1/23 to AI/ML, covering risk appetite, model tiering, explainability, overfitting, validation and monitoring.
  • Amended 23 April 2026 (LIAF01/26): the expectations are not conditions for internal model approval, newly permitted internal-model firms have 12 months to comply, and internal-model firms assess stress-test models against SS1/23 rather than SS3/18 alone.

What did PRA SS1/23 change for banks?

Before SS1/23 the PRA had no consolidated model-risk standard; UK banks often borrowed SR 11-7. SS1/23 made model risk a standalone discipline with named senior-manager accountability, and by covering all models regardless of technology, including vendor models, it became the main channel through which the PRA supervises AI in banks. The BoE/PRA told government in April 2026 they intend to build on it further in 2026 using supervisory insights on good practice.

What does PRA SS1/23 require, and how do its model risk management principles apply to AI and machine-learning models?

Supervisory Statement 1/23, 'Model risk management principles for banks', is the Prudential Regulation Authority's model risk management standard. Published with Policy Statement 6/23 on 17 May 2023, in force since 17 May 2024 and amended on 23 April 2026, it sets five principles: model identification and model risk classification; governance; model development, implementation and use; independent model validation; and model risk mitigants. Its formal scope is UK-incorporated banks, building societies and PRA-designated investment firms with internal-model permissions for credit, market or counterparty credit risk, and the PRA says other firms may find the principles useful. The model definition covers all models that inform business decisions regardless of technology, including vendor models and models used for financial reporting, and, without naming artificial intelligence or machine learning, its tiering principle (1.3(c)) weighs unstructured data, interpretability, explainability, transparency and bias for newly advanced approaches, while Principle 3.3(c) requires testing of material changes in dynamic models that adapt or recalibrate autonomously. Accountability for the whole MRM framework must be allocated to a named Senior Management Function holder.

RuleAuthorityWhat it requiresApplies
Principle 1 — Model identification and model risk classificationUK (BoE / PRA / FCA)A firm-wide definition of a model, a complete model inventory, and a risk-based tiering of every model by materiality and complexity that drives the intensity of every other principle.Since 17 May 2024
Principle 2 — GovernanceUK (BoE / PRA / FCA)Board-approved MRM policy and risk appetite, responsibility for the overall framework allocated to the most appropriate SMF holder, and reporting on the effectiveness of MRM for financial reporting to the audit committee.Since 17 May 2024
Principle 3 — Model development, implementation and useUK (BoE / PRA / FCA)Documented development standards, data quality and suitability assessments, testing (including of material changes in dynamic models that adapt, recalibrate or change autonomously), and controls over implementation and use.Since 17 May 2024
Principle 4 — Independent model validationUK (BoE / PRA / FCA)Validation independent of development, proportionate to tier, before use and periodically thereafter, with ongoing monitoring, effective challenge and findings tracked to closure; vendor models are validated like in-house ones.Since 17 May 2024
Principle 5 — Model risk mitigantsUK (BoE / PRA / FCA)Governed post-model adjustments and overlays, restrictions on use, escalation and exception processes, and the ability to fall back when a model is found deficient.Since 17 May 2024
LIAF01/26 — amendment to SS1/23 ↗UK (BoE / PRA / FCA)Clarifies that SS1/23 expectations are not conditions for internal model approval; a firm that first receives an internal-model permission has 12 months from the grant to comply. Internal-model firms now assess stress-test models against SS1/23 rather than SS3/18 alone.From 23 Apr 2026
PRA AI/ML model-risk roundtable (Oct 2025)UK (BoE / PRA / FCA)The PRA's current thinking, from two CRO roundtables with 21 firms on 20 and 22 October 2025, on applying SS1/23 to AI and ML: risk appetite, model tiering, explainability, overfitting, validation and monitoring.Nov 2025
Bank of England AI roundtables (summary, Feb 2026) ↗UK (BoE / PRA / FCA)Three sector roundtables in late 2025, published 16 February 2026: firms called SS1/23 'pragmatic in enabling responsible AI adoption', asked for no AI-specific rules, and said traditional validation 'wouldn't be sustainable' for generative and agentic systems.Feb 2026

SS1/23 is the UK's closest counterpart to the US interagency model risk guidance, but it differs in three ways that matter for AI. First, accountability is personal: the framework must be owned by a named SMF holder under the Senior Managers regime. Second, scope is deliberately technology-neutral — the definition captures any quantitative method that applies statistical, economic, financial or mathematical theories and techniques to process input data into an output used for business decisions, which brings machine-learning models, vendor-supplied scoring engines and generative tools that influence decisions inside the inventory. Third, AI sits inside the framework rather than beside it: the text never names AI or machine learning, but its tiering factors for newly advanced approaches (unstructured data, interpretability, explainability, bias) and its testing of dynamic models that change autonomously make these ordinary model risk questions, not a separate programme.

Compliance in practice runs on the model lifecycle. Identification and tiering (Principle 1) decide how much development documentation, validation depth and monitoring frequency each model gets; the PRA expects the tiering to consider materiality, complexity and, for AI, opacity. Independent validation (Principle 4) is where the October 2025 roundtable found the most inconsistency: several firms were applying core SS1/23 expectations unevenly where AI models introduce opacity, uncertainty and faster rates of change, and the PRA's slides set out its thinking on explainability, overfitting and ongoing monitoring as validation requirements. Model risk mitigants (Principle 5) — overlays, use restrictions, escalation — are what let a firm keep using a model whose limitations are known while remediation proceeds.

Two 2026 developments change the picture. The 23 April 2026 low-impact amendments (LIAF01/26) make explicit that SS1/23 is not a condition of internal-model approval and give newly permitted firms 12 months to comply, while folding stress-test model risk under SS1/23 for internal-model firms. And the Bank's February 2026 summary of its AI roundtables records that firms want SS1/23 applied, not replaced: the challenge they raised is that the traditional 'inputs to outputs' understanding at the heart of validation does not scale to generative AI and agentic systems, so risk management must move toward testing, monitoring and guardrails around outcomes. The PRA and Bank told Parliament in April 2026 that they intend to build on SS1/23 during 2026 using supervisory insights on good practice.

WHAT THIS MEANS IN PRACTICE

  • SS1/23 compliance requirements start with the inventory: if a generative AI tool, a vendor fraud score or a spreadsheet influences a business decision, it is a model and needs a tier, an owner and a validation plan.
  • SS1/23 model validation for AI/ML models must cover data provenance, explainability, overfitting and drift monitoring — the PRA's October 2025 slides treat these as ordinary validation questions at the right tier.
  • Genai and agentic systems are in scope; the PRA's own summary says traditional validation will not be sustainable for them, so build outcome testing, monitoring and guardrails (Principle 5 mitigants) into the design rather than waiting for a validation exception.
  • Name the SMF holder for model risk and give the audit committee the required report on MRM effectiveness for financial reporting — both are examinable evidence under Principle 2.
  • Firms without internal-model permission are outside the formal scope; the PRA says they may find the principles useful and are welcome to consider them.
  • New internal-model firms have 12 months from permission to comply (LIAF01/26); everyone else has been expected to comply since 17 May 2024, with self-assessment and remediation plans available to supervisors.

Does SS1/23 apply to machine learning and AI models?

Yes. It covers all models used to inform business decisions regardless of technology. The text does not name AI or machine learning, but its tiering factors for newly advanced approaches (unstructured data, interpretability, explainability, bias) and its testing expectations for dynamic models that change autonomously apply to them; the PRA has since run roundtables on applying it to AI.

Which banks must comply with SS1/23?

Formally, UK-incorporated banks, building societies and PRA-designated investment firms with IRB, IMA or IMM internal-model approvals. The expectations do not apply to other firms, though the PRA says they may find the principles useful.

How does SS1/23 compare with SR 11-7?

Both are principles-based supervisory statements on model risk covering development, validation and governance; SS1/23 additionally names an accountable SMF holder, requires audit-committee reporting, and addresses AI-relevant complexity (unstructured data, explainability, bias, dynamic models) without naming AI or ML.

How does PRA SS1/23 compare?

DateDocumentStatus
Sep 30, 2026Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew BaileyFinal
Sep 2, 2026FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026) — Frontier AI and Cyber ResilienceIn force
Jul 14, 2026HM Treasury Financial Services AI Adoption Plan (Jul 2026) — Financial Services AI Adoption PlanFinal
Jun 5, 20262026 BoE/FCA AI survey — The Bank of England and FCA's 2026 AI SurveyFinal
May 15, 2026BoE/FCA/HMT joint statement on frontier AI and cyber resilience (May 2026) — The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilienceIn force
Apr 1, 2026BoE response to Treasury Committee AI inquiry (Apr 2026) — Response to TSC inquiry report on AI in financial servicesFinal

Which banks' AI programmes does PRA SS1/23 reach?

3 of the 120 largest US banks profiled on this site cite PRA SS1/23 among the documents their AI work answers to.

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning