Regulation · PRA SS1/23

PRA SS1/23: model risk management, explained

PRA SS1/23 sets out the Prudential Regulation Authority's principles for model risk management — expecting banks to treat model risk as a risk discipline in its own right, with a governed model inventory, independent validation and ongoing monitoring across the whole model landscape.

What is SS1/23?

SS1/23 is the PRA's supervisory statement on model risk management principles. It frames model risk as a distinct risk type and asks firms to identify every model they rely on, classify it by risk, govern it, validate it independently and monitor it in use — rather than managing models informally, model by model.

It took effect on 17 May 2024 (published via PS6/23 in May 2023). Its expectations apply specifically to banks, building societies and PRA-designated investment firms that hold internal-model approval for regulatory capital — though other firms, including insurers, may adopt the principles voluntarily, and insurers separately validate internal models under Solvency II. Firms should confirm the exact scope and proportionality against the PRA's published SS1/23 and PS6/23.

What SS1/23 expects firms to do

The supervisory statement is built around five principles spanning identification, governance, development, validation and mitigation — and expressly extends to models using AI and machine learning. In outline:

Identification & tieringMaintain a complete model inventory and classify each model by materiality and risk, so effort is proportionate to the risk a model carries.
Governance & accountabilityClear board and senior-management accountability for model risk, with policies, roles and a firm-wide framework rather than local, ad-hoc practice.
Development, implementation & useSound standards for data, methodology, documentation and testing, and controls over how models are actually used and by whom.
Independent validationA validation function independent of development that assesses conceptual soundness, data and performance — initially and on an ongoing basis.
Monitoring & mitigantsOngoing monitoring of model performance and disciplined use of post-model adjustments and other mitigants where models fall short.

What it means for the models — and vendors — you rely on

SS1/23 covers the whole model landscape, including third-party and vendor models. A bought-in analytics model is still your model risk: it belongs in the inventory, needs validation evidence, and has to be monitored in use like any internally-built one.

Abgalis is built to sit comfortably inside that discipline — transparent about what its models do, able to supply validation and monitoring evidence, and designed to keep the firm's own model-risk function in control. The accountability for classification, validation sign-off and use stays with the firm; Abgalis is the analytics layer beneath it, not a substitute for the validation function. For how this lands on a balance sheet, see Abgalis for banks.

PRA SS1/23 — questions firms ask

What is PRA SS1/23?

SS1/23 is the PRA's supervisory statement setting out principles for model risk management. It treats model risk as a distinct risk type and sets out five principles — expecting firms to identify and tier their models, govern them, develop and use them to sound standards, validate them independently and monitor them in use. It took effect on 17 May 2024. Firms should confirm scope against the PRA's published materials.

Who does SS1/23 apply to?

Its expectations took effect on 17 May 2024 and apply specifically to banks, building societies and PRA-designated investment firms that hold internal-model approval for regulatory capital (IRB, IMA or IMM). Other firms, including insurers, may adopt the principles voluntarily; insurers separately validate internal models under Solvency II. Firms should confirm their own scope against the PRA's policy statement.

What are the principles in outline?

In outline they span model identification and risk tiering, governance and accountability, development/implementation/use standards, independent validation, and ongoing monitoring with disciplined mitigants such as post-model adjustments. The PRA's text is the authoritative statement of the principles.

Does SS1/23 cover vendor and third-party models?

Yes — the model-risk discipline extends to bought-in and third-party models, not just internally developed ones. A vendor model belongs in the inventory, needs validation evidence and must be monitored in use, with the firm retaining accountability for it.

How does Abgalis fit a firm's model risk management?

Abgalis is designed to be transparent about what its models do and to supply validation and monitoring evidence, so it can be brought into the inventory and governed like any other model. It is an analytics layer; it does not replace the firm's independent validation function or its ownership of model-risk decisions.

Does Abgalis validate our models for us?

No. Independent validation under SS1/23 must sit with the firm's own validation function, independent of model development. Abgalis can provide transparency, documentation and monitoring evidence that support that work, but the validation judgement and sign-off remain the firm's.

This page is a general explainer, not legal, regulatory or actuarial advice. Firms should refer to the PRA's published SS1/23 and accompanying policy statement and take their own advice. Abgalis is a risk data and analytics provider and is not a regulated or authorised firm; it does not perform independent model validation on a firm's behalf.

See everything.
Before it happens.

Discover how ABGALIS can unify your enterprise risk landscape into a single, living digital twin — with foresight across every domain.

Your data is handled in accordance with GDPR. We never share your information. Privacy Policy

Download Research Paper

Enter your details to access our peer-quality research from the Abgalis Risk Intelligence Lab.

Your data is handled in accordance with GDPR. We never share your information.