AI Regulation Tracker · UK (BoE / PRA / FCA) · Guidance

What does PRA SS1/23 say about AI in banking?

Published May 17, 2023 · Last reviewed Sep 2, 2026

SS1/23, published with Policy Statement PS6/23 on 17 May 2023 and effective from 17 May 2024, is the PRA's model risk management standard and the UK's closest equivalent to SR 11-7. It sets five principles — model identification and risk classification, governance, development and use, independent validation, and risk mitigants — covering all models used to inform business decisions, including vendor models, and includes a sub-principle on identifying and managing risks from AI and machine learning techniques. It applies formally to banks with internal-model permissions and assigns overall MRM accountability to a named Senior Management Function holder.

OFFICIAL TEXT: bankofengland.co.uk · IN FORCE · UK (BOE / PRA / FCA)

DocumentPRA SS1/23Supervisory Statement 1/23: Model risk management principles for banks
Issued byBank of England, Prudential Regulation Authority, and Financial Conduct Authority
TypeGuidance
StatusIn force
PublishedMay 17, 2023
EffectiveMay 17, 2024
Applies toUK-incorporated banks, building societies and PRA-designated investment firms with internal-model approval for credit risk (IRB), market risk (IMA) or counterparty credit risk (IMM); other firms are expected to apply it proportionately
Official sourcebankofengland.co.uk
Use casesModel risk management · Credit scoring & underwriting · Third-party & vendor AI · Generative & agentic AI · AI governance (general)

What are the key points of PRA SS1/23?

  • Five principles: (1) model identification and model risk classification, (2) governance, (3) model development, implementation and use, (4) independent model validation, (5) model risk mitigants.
  • Scope is all models informing business decisions, regardless of technology, whether in-house or vendor-supplied, including models used for financial reporting.
  • Sub-principle requires firms to identify and manage the risks of AI in modelling techniques such as machine learning to the extent that it applies to models generally.
  • Accountability for the overall MRM framework must be allocated to the most appropriate SMF holder under the Senior Managers regime.
  • Effectiveness of MRM for financial reporting must be reported to the audit committee.
  • Proportionate implementation across model tiers and across firms; formal scope is internal-model banks, with others expected to apply it proportionately.
  • In October 2025 the PRA held CRO roundtables with 21 firms on applying SS1/23 to AI/ML, covering risk appetite, model tiering, explainability, overfitting, validation and monitoring.
  • Amended 23 April 2026 (LIAF01/26): the expectations are not conditions for internal model approval, newly permitted internal-model firms have 12 months to comply, and internal-model firms assess stress-test models against SS1/23 rather than SS3/18 alone.

What did PRA SS1/23 change for banks?

Before SS1/23 the PRA had no consolidated model-risk standard; UK banks often borrowed SR 11-7. SS1/23 made model risk a standalone discipline with named senior-manager accountability, and by deliberately covering AI/ML and vendor models it became the main channel through which the PRA supervises AI in banks. The BoE/PRA told government in April 2026 they intend to build on it further in 2026 using supervisory insights on good practice.

What does PRA SS1/23 require, and how do its model risk management principles apply to AI and machine-learning models?

Supervisory Statement 1/23, 'Model risk management principles for banks', is the Prudential Regulation Authority's model risk management standard. Published with Policy Statement 6/23 on 17 May 2023, in force since 17 May 2024 and amended on 23 April 2026, it sets five principles: model identification and model risk classification; governance; model development, implementation and use; independent model validation; and model risk mitigants. Its formal scope is UK-incorporated banks, building societies and PRA-designated investment firms with internal-model permissions for credit, market or counterparty credit risk, but the PRA expects every firm to apply it proportionately. The model definition covers all models that inform business decisions regardless of technology, including vendor models and models used for financial reporting, and a sub-principle requires firms to identify and manage the risks that arise from artificial intelligence and machine-learning techniques. Accountability for the whole MRM framework must be allocated to a named Senior Management Function holder.

RuleAuthorityWhat it requiresApplies
Principle 1 — Model identification and model risk classificationUK (BoE / PRA / FCA)A firm-wide definition of a model, a complete model inventory, and a risk-based tiering of every model by materiality and complexity that drives the intensity of every other principle.Since 17 May 2024
Principle 2 — GovernanceUK (BoE / PRA / FCA)Board-approved MRM policy and risk appetite, responsibility for the overall framework allocated to the most appropriate SMF holder, and reporting on the effectiveness of MRM for financial reporting to the audit committee.Since 17 May 2024
Principle 3 — Model development, implementation and useUK (BoE / PRA / FCA)Documented development standards, data quality and suitability assessments, testing, controls over implementation and use, and management of the specific risks of AI and machine-learning techniques as they apply to models generally.Since 17 May 2024
Principle 4 — Independent model validationUK (BoE / PRA / FCA)Validation independent of development, proportionate to tier, before use and periodically thereafter, with ongoing monitoring, effective challenge and findings tracked to closure; vendor models are validated like in-house ones.Since 17 May 2024
Principle 5 — Model risk mitigantsUK (BoE / PRA / FCA)Governed post-model adjustments and overlays, restrictions on use, escalation and exception processes, and the ability to fall back when a model is found deficient.Since 17 May 2024
LIAF01/26 — amendment to SS1/23UK (BoE / PRA / FCA)Clarifies that SS1/23 expectations are not conditions for internal model approval; a firm that first receives an internal-model permission has 12 months from the grant to comply. Internal-model firms now assess stress-test models against SS1/23 rather than SS3/18 alone.From 23 Apr 2026
PRA AI/ML model-risk roundtable (Oct 2025)UK (BoE / PRA / FCA)The PRA's current thinking, from two CRO roundtables with 21 firms on 20 and 22 October 2025, on applying SS1/23 to AI and ML: risk appetite, model tiering, explainability, overfitting, validation and monitoring.Nov 2025
Bank of England AI roundtables (summary, Feb 2026)UK (BoE / PRA / FCA)Three sector roundtables in late 2025, published 16 February 2026: firms called SS1/23 'pragmatic in enabling responsible AI adoption', asked for no AI-specific rules, and said traditional validation 'wouldn't be sustainable' for generative and agentic systems.Feb 2026

SS1/23 is the UK's closest counterpart to the US interagency model risk guidance, but it differs in three ways that matter for AI. First, accountability is personal: the framework must be owned by a named SMF holder under the Senior Managers regime. Second, scope is deliberately technology-neutral — the definition captures any quantitative method that applies statistical, economic, financial or mathematical theories and techniques to process input data into an output used for business decisions, which brings machine-learning models, vendor-supplied scoring engines and generative tools that influence decisions inside the inventory. Third, the AI/ML sub-principle sits inside the framework rather than beside it: firms must identify and manage the risks of AI techniques to the extent the principles apply to models generally, so explainability, data provenance, drift and overfitting become validation questions, not a separate programme.

Compliance in practice runs on the model lifecycle. Identification and tiering (Principle 1) decide how much development documentation, validation depth and monitoring frequency each model gets; the PRA expects the tiering to consider materiality, complexity and, for AI, opacity. Independent validation (Principle 4) is where the October 2025 roundtable found the most inconsistency: several firms were applying core SS1/23 expectations unevenly where AI models introduce opacity, uncertainty and faster rates of change, and the PRA's slides set out its thinking on explainability, overfitting and ongoing monitoring as validation requirements. Model risk mitigants (Principle 5) — overlays, use restrictions, escalation — are what let a firm keep using a model whose limitations are known while remediation proceeds.

Two 2026 developments change the picture. The 23 April 2026 low-impact amendments (LIAF01/26) make explicit that SS1/23 is not a condition of internal-model approval and give newly permitted firms 12 months to comply, while folding stress-test model risk under SS1/23 for internal-model firms. And the Bank's February 2026 summary of its AI roundtables records that firms want SS1/23 applied, not replaced: the challenge they raised is that the traditional 'inputs to outputs' understanding at the heart of validation does not scale to generative AI and agentic systems, so risk management must move toward testing, monitoring and guardrails around outcomes. The PRA and Bank told Parliament in April 2026 that they intend to build on SS1/23 during 2026 using supervisory insights on good practice.

WHAT THIS MEANS IN PRACTICE

  • SS1/23 compliance requirements start with the inventory: if a generative AI tool, a vendor fraud score or a spreadsheet influences a business decision, it is a model and needs a tier, an owner and a validation plan.
  • SS1/23 model validation for AI/ML models must cover data provenance, explainability, overfitting and drift monitoring — the PRA's October 2025 slides treat these as ordinary validation questions at the right tier.
  • Genai and agentic systems are in scope; the PRA's own summary says traditional validation will not be sustainable for them, so build outcome testing, monitoring and guardrails (Principle 5 mitigants) into the design rather than waiting for a validation exception.
  • Name the SMF holder for model risk and give the audit committee the required report on MRM effectiveness for financial reporting — both are examinable evidence under Principle 2.
  • Regulatory expectations for firms outside the formal scope are proportionate application, not exemption; the PRA reads SS1/23 as the benchmark for all banks' model controls.
  • New internal-model firms have 12 months from permission to comply (LIAF01/26); everyone else has been expected to comply since 17 May 2024, with self-assessment and remediation plans available to supervisors.

Does SS1/23 apply to machine learning and AI models?

Yes. It covers all models used to inform business decisions regardless of technology and includes a sub-principle on identifying and managing AI/ML risks; the PRA has since run roundtables on applying it to AI.

Which banks must comply with SS1/23?

Formally, UK-incorporated banks, building societies and PRA-designated investment firms with IRB, IMA or IMM internal-model approvals; other firms are expected to apply the principles proportionately.

How does SS1/23 compare with SR 11-7?

Both are principles-based supervisory statements on model risk covering development, validation and governance; SS1/23 additionally names an accountable SMF holder, requires audit-committee reporting, and explicitly addresses AI/ML.

DateDocumentStatus
Jul 14, 2026HM Treasury Financial Services AI Adoption Plan (Jul 2026)Financial Services AI Adoption PlanFinal
Jun 5, 20262026 BoE/FCA AI surveyThe Bank of England and FCA's 2026 AI SurveyFinal
May 15, 2026BoE/FCA/HMT joint statement on frontier AI and cyber resilience (May 2026)The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilienceIn force
Apr 1, 2026BoE response to Treasury Committee AI inquiry (Apr 2026)Response to TSC inquiry report on AI in financial servicesFinal
Apr 1, 2026BoE/PRA plan for safe AI innovation (Apr 2026)Letter from Sarah Breeden and Sam Woods to the Chancellor and Secretaries of State on enabling safe AI innovationFinal
Jan 28, 2026DSIT/DBT strategic letters to regulators (Jan 2026)How will regulators enable safe AI-powered innovation: joint letter from DSIT Secretary of State and DBT Secretary of StateFinal

Which banks' AI programmes does PRA SS1/23 reach?

3 of the 100 largest US banks profiled on this site cite PRA SS1/23 among the documents their AI work answers to.

Follow every document these regulators publish

the daily brief · six sourced stories · in your inbox by 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning