# PRA SS1/23: Supervisory Statement 1/23: Model risk management principles for banks

Source: https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management
Last updated: Sep 2, 2026

SS1/23, published with Policy Statement PS6/23 on 17 May 2023 and effective from 17 May 2024, is the PRA's model risk management standard and the UK's closest equivalent to SR 11-7. It sets five principles — model identification and risk classification, governance, development and use, independent validation, and risk mitigants — covering all models used to inform business decisions, including vendor models, regardless of technology. The text does not use the words 'artificial intelligence' or 'machine learning'; it reaches AI through tiering factors for 'newly advanced approaches or technologies' (unstructured data, interpretability, explainability, bias) and testing of dynamic models that change autonomously. It applies formally to banks with internal-model permissions and assigns overall MRM accountability to a named Senior Management Function holder.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) |
| Type | Guidance |
| Status | In force |
| Published | May 17, 2023 |
| Effective | May 17, 2024 |
| Applies to | UK-incorporated banks, building societies and PRA-designated investment firms with internal-model approval for credit risk (IRB), market risk (IMA) or counterparty credit risk (IMM); the expectations do not apply to other firms, which the PRA says may find the principles useful |
| Official text | https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss |

## Key points

- Five principles: (1) model identification and model risk classification, (2) governance, (3) model development, implementation and use, (4) independent model validation, (5) model risk mitigants.
- Scope is all models informing business decisions, regardless of technology, whether in-house or vendor-supplied, including models used for financial reporting.
- AI and ML are addressed through general principles, not by name: Principle 1.3(c) complexity factors for 'newly advanced approaches or technologies' (alternative and unstructured data; interpretability, explainability, transparency and potential for designer or data bias) and Principle 3.3(c) testing of material changes in dynamic models that adapt or recalibrate autonomously. The PRA's publication page summarises this as a sub-principle on AI in modelling techniques such as machine learning.
- Accountability for the overall MRM framework must be allocated to the most appropriate SMF holder under the Senior Managers regime.
- Effectiveness of MRM for financial reporting must be reported to the audit committee.
- Proportionate implementation across model tiers and across firms; the expectations apply only to internal-model banks, and the PRA says other firms may find the principles useful.
- In October 2025 the PRA held CRO roundtables with 21 firms on applying SS1/23 to AI/ML, covering risk appetite, model tiering, explainability, overfitting, validation and monitoring.
- Amended 23 April 2026 (LIAF01/26): the expectations are not conditions for internal model approval, newly permitted internal-model firms have 12 months to comply, and internal-model firms assess stress-test models against SS1/23 rather than SS3/18 alone.

## What changed for banks

Before SS1/23 the PRA had no consolidated model-risk standard; UK banks often borrowed SR 11-7. SS1/23 made model risk a standalone discipline with named senior-manager accountability, and by covering all models regardless of technology, including vendor models, it became the main channel through which the PRA supervises AI in banks. The BoE/PRA told government in April 2026 they intend to build on it further in 2026 using supervisory insights on good practice.

## Use cases it governs

- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)
- [Credit scoring & underwriting](https://www.bankingnewsai.com/ai-regulation/by-use-case#credit-underwriting)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)

## What does PRA SS1/23 require, and how do its model risk management principles apply to AI and machine-learning models?

Supervisory Statement 1/23, 'Model risk management principles for banks', is the Prudential Regulation Authority's model risk management standard. Published with Policy Statement 6/23 on 17 May 2023, in force since 17 May 2024 and amended on 23 April 2026, it sets five principles: model identification and model risk classification; governance; model development, implementation and use; independent model validation; and model risk mitigants. Its formal scope is UK-incorporated banks, building societies and PRA-designated investment firms with internal-model permissions for credit, market or counterparty credit risk, and the PRA says other firms may find the principles useful. The model definition covers all models that inform business decisions regardless of technology, including vendor models and models used for financial reporting, and, without naming artificial intelligence or machine learning, its tiering principle (1.3(c)) weighs unstructured data, interpretability, explainability, transparency and bias for newly advanced approaches, while Principle 3.3(c) requires testing of material changes in dynamic models that adapt or recalibrate autonomously. Accountability for the whole MRM framework must be allocated to a named Senior Management Function holder.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Principle 1 — Model identification and model risk classification | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | A firm-wide definition of a model, a complete model inventory, and a risk-based tiering of every model by materiality and complexity that drives the intensity of every other principle. | Since 17 May 2024 | [PRA SS1/23](https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management) |
| Principle 2 — Governance | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | Board-approved MRM policy and risk appetite, responsibility for the overall framework allocated to the most appropriate SMF holder, and reporting on the effectiveness of MRM for financial reporting to the audit committee. | Since 17 May 2024 | [PRA SS1/23](https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management) |
| Principle 3 — Model development, implementation and use | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | Documented development standards, data quality and suitability assessments, testing (including of material changes in dynamic models that adapt, recalibrate or change autonomously), and controls over implementation and use. | Since 17 May 2024 | [PRA SS1/23](https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management) |
| Principle 4 — Independent model validation | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | Validation independent of development, proportionate to tier, before use and periodically thereafter, with ongoing monitoring, effective challenge and findings tracked to closure; vendor models are validated like in-house ones. | Since 17 May 2024 | [PRA SS1/23](https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management) |
| Principle 5 — Model risk mitigants | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | Governed post-model adjustments and overlays, restrictions on use, escalation and exception processes, and the ability to fall back when a model is found deficient. | Since 17 May 2024 | [PRA SS1/23](https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management) |
| LIAF01/26 — amendment to SS1/23 | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | Clarifies that SS1/23 expectations are not conditions for internal model approval; a firm that first receives an internal-model permission has 12 months from the grant to comply. Internal-model firms now assess stress-test models against SS1/23 rather than SS3/18 alone. | From 23 Apr 2026 | [official text](https://www.bankofengland.co.uk/prudential-regulation/publication/2026/april/low-impact-amendments-finalisation-april-2026) |
| PRA AI/ML model-risk roundtable (Oct 2025) | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | The PRA's current thinking, from two CRO roundtables with 21 firms on 20 and 22 October 2025, on applying SS1/23 to AI and ML: risk appetite, model tiering, explainability, overfitting, validation and monitoring. | Nov 2025 | [PRA AI/ML model-risk roundtable (Nov 2025)](https://www.bankingnewsai.com/ai-regulation/documents/pra-mrm-roundtable-ai-ml-2025) |
| Bank of England AI roundtables (summary, Feb 2026) | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | Three sector roundtables in late 2025, published 16 February 2026: firms called SS1/23 'pragmatic in enabling responsible AI adoption', asked for no AI-specific rules, and said traditional validation 'wouldn't be sustainable' for generative and agentic systems. | Feb 2026 | [official text](https://www.bankofengland.co.uk/minutes/2026/february/summary-of-ai-roundtables-feb-2026) |

SS1/23 is the UK's closest counterpart to the US interagency model risk guidance, but it differs in three ways that matter for AI. First, accountability is personal: the framework must be owned by a named SMF holder under the Senior Managers regime. Second, scope is deliberately technology-neutral — the definition captures any quantitative method that applies statistical, economic, financial or mathematical theories and techniques to process input data into an output used for business decisions, which brings machine-learning models, vendor-supplied scoring engines and generative tools that influence decisions inside the inventory. Third, AI sits inside the framework rather than beside it: the text never names AI or machine learning, but its tiering factors for newly advanced approaches (unstructured data, interpretability, explainability, bias) and its testing of dynamic models that change autonomously make these ordinary model risk questions, not a separate programme.

Compliance in practice runs on the model lifecycle. Identification and tiering (Principle 1) decide how much development documentation, validation depth and monitoring frequency each model gets; the PRA expects the tiering to consider materiality, complexity and, for AI, opacity. Independent validation (Principle 4) is where the October 2025 roundtable found the most inconsistency: several firms were applying core SS1/23 expectations unevenly where AI models introduce opacity, uncertainty and faster rates of change, and the PRA's slides set out its thinking on explainability, overfitting and ongoing monitoring as validation requirements. Model risk mitigants (Principle 5) — overlays, use restrictions, escalation — are what let a firm keep using a model whose limitations are known while remediation proceeds.

Two 2026 developments change the picture. The 23 April 2026 low-impact amendments (LIAF01/26) make explicit that SS1/23 is not a condition of internal-model approval and give newly permitted firms 12 months to comply, while folding stress-test model risk under SS1/23 for internal-model firms. And the Bank's February 2026 summary of its AI roundtables records that firms want SS1/23 applied, not replaced: the challenge they raised is that the traditional 'inputs to outputs' understanding at the heart of validation does not scale to generative AI and agentic systems, so risk management must move toward testing, monitoring and guardrails around outcomes. The PRA and Bank told Parliament in April 2026 that they intend to build on SS1/23 during 2026 using supervisory insights on good practice.

### What this means in practice

- SS1/23 compliance requirements start with the inventory: if a generative AI tool, a vendor fraud score or a spreadsheet influences a business decision, it is a model and needs a tier, an owner and a validation plan.
- SS1/23 model validation for AI/ML models must cover data provenance, explainability, overfitting and drift monitoring — the PRA's October 2025 slides treat these as ordinary validation questions at the right tier.
- Genai and agentic systems are in scope; the PRA's own summary says traditional validation will not be sustainable for them, so build outcome testing, monitoring and guardrails (Principle 5 mitigants) into the design rather than waiting for a validation exception.
- Name the SMF holder for model risk and give the audit committee the required report on MRM effectiveness for financial reporting — both are examinable evidence under Principle 2.
- Firms without internal-model permission are outside the formal scope; the PRA says they may find the principles useful and are welcome to consider them.
- New internal-model firms have 12 months from permission to comply (LIAF01/26); everyone else has been expected to comply since 17 May 2024, with self-assessment and remediation plans available to supervisors.

## FAQ

### Does SS1/23 apply to machine learning and AI models?

Yes. It covers all models used to inform business decisions regardless of technology. The text does not name AI or machine learning, but its tiering factors for newly advanced approaches (unstructured data, interpretability, explainability, bias) and its testing expectations for dynamic models that change autonomously apply to them; the PRA has since run roundtables on applying it to AI.

### Which banks must comply with SS1/23?

Formally, UK-incorporated banks, building societies and PRA-designated investment firms with IRB, IMA or IMM internal-model approvals. The expectations do not apply to other firms, though the PRA says they may find the principles useful.

### How does SS1/23 compare with SR 11-7?

Both are principles-based supervisory statements on model risk covering development, validation and governance; SS1/23 additionally names an accountable SMF holder, requires audit-committee reporting, and addresses AI-relevant complexity (unstructured data, explainability, bias, dynamic models) without naming AI or ML.

## Compare

- [PRA SS1/23 vs SR 26-2](https://www.bankingnewsai.com/ai-regulation/compare/pra-ss1-23-vs-sr-26-2): PRA SS1/23 vs SR 26-2: UK and US Model Risk Compared

## Related documents

- [Bailey: Frontier AI and the Question of Governance (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-bailey-frontier-ai-governance-2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey (Sep 30, 2026)
- [FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fca-frontier-ai-cyber-resilience-2026) — Frontier AI and Cyber Resilience (Sep 2, 2026)
- [HM Treasury Financial Services AI Adoption Plan (Jul 2026)](https://www.bankingnewsai.com/ai-regulation/documents/hmt-financial-services-ai-adoption-plan-2026) — Financial Services AI Adoption Plan (Jul 14, 2026)
- [2026 BoE/FCA AI survey](https://www.bankingnewsai.com/ai-regulation/documents/uk-ai-in-financial-services-survey-2026) — The Bank of England and FCA's 2026 AI Survey (Jun 5, 2026)
- [BoE/FCA/HMT joint statement on frontier AI and cyber resilience (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/uk-joint-statement-frontier-ai-cyber-resilience-2026) — The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience (May 15, 2026)
- [BoE response to Treasury Committee AI inquiry (Apr 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-pra-response-tsc-ai-inquiry-2026) — Response to TSC inquiry report on AI in financial services (Apr 1, 2026)
- [BoE/PRA plan for safe AI innovation (Apr 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-pra-safe-ai-innovation-plan-letter-2026) — Letter from Sarah Breeden and Sam Woods to the Chancellor and Secretaries of State on enabling safe AI innovation (Apr 1, 2026)
- [DSIT/DBT strategic letters to regulators (Jan 2026)](https://www.bankingnewsai.com/ai-regulation/documents/gov-uk-dsit-dbt-safe-ai-innovation-letter-2026) — How will regulators enable safe AI-powered innovation: joint letter from DSIT Secretary of State and DBT Secretary of State (Jan 28, 2026)

Last reviewed Sep 2, 2026. Cite the official text (https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
