Back to site

Model governance

The control set an SR 11-7 model-risk review asks for, and the evidence that each control is operating.

MRM-01Deterministic, replayable retrieval

Operating

Every record the agent reads is fetched through a typed connector and hashed into the case file. Re-running a case a year later pulls the same evidence set, which is what makes a disposition defensible on examination.

MRM-02Grounded generation with a verifier pass

Operating

Narrative sentences are checked back against retrieved records before release. A sentence that cannot be grounded is dropped, not paraphrased — the failure mode is an incomplete section, never a fabricated one.

MRM-03Mandatory escalation gates

Operating

Sanctions alias matches above the referral threshold, unresolved screening and continuing activity on a previously reported relationship bypass the score entirely and route to a human.

MRM-04Champion / challenger

4.3-rc2 in shadow

A challenger model runs in shadow on live traffic. Promotion requires non-inferior recall on the held-out adjudicated set and MLRO sign-off.

MRM-05Drift monitoring per typology and corridor

Operating

Population stability, disposition mix and QA concurrence are tracked per segment. A segment outside its control band reverts to human routing automatically.

MRM-06No customer data in training

Contractual

Customer records are never used to train or fine-tune shared models. Policy adaptation happens through the institution's own configuration and reviewer feedback, held in the institution's tenant.