Model Validation, Tiering and Independent Review Expectations


Model validation is a critical component of AI governance in financial services. It involves testing and assessing AI systems to ensure they perform as intended and align with regulatory expectations. In practice, this means conducting regular checks on model outputs, data quality, and performance metrics. For example, a credit scoring model must be validated against historical data to confirm it accurately identifies credit risk. The validation process must also consider potential bias or discrimination, particularly in models used for lending or investment decisions. Financial institutions must maintain records of these validation activities, including any adjustments or retraining of models. The FCA expects firms to validate models not only at the point of deployment but also through ongoing monitoring. This includes reviewing model performance against changing market conditions or data patterns.
Model Tiering
Model tiering is a framework that categorises AI models based on their risk level and impact on business operations. Firms must apply this approach to ensure appropriate governance and oversight. Models are typically grouped into tiers such as high, medium, or low risk. A high-risk model, such as one used for automated trading or customer risk assessment, requires more rigorous validation, documentation, and oversight. In contrast, a low-risk model, such as one used for data categorisation or basic reporting, may have lighter governance requirements. The tiering approach helps firms allocate resources efficiently and focus attention on models that pose the greatest risk. For example, a bank might classify its fraud detection system as high risk due to its potential impact on customer accounts and regulatory compliance. The classification process must be reviewed periodically, especially when models are updated or redeployed. Firms must also ensure that the governance processes align with the risk level of each model.
- High-risk models require detailed documentation, frequent validation, and senior oversight
- Medium-risk models may have moderate validation and monitoring
- Low-risk models can have lighter governance but must still meet basic compliance standards
Independent Review Expectations
Independent reviews play a central role in ensuring AI systems are compliant and properly governed. These reviews must be conducted by individuals or teams not directly involved in the design or deployment of the AI system. The purpose is to provide an objective assessment of the model’s effectiveness, fairness, and adherence to regulatory requirements. For example, an independent review of a credit approval model might examine whether the system treats all customer groups fairly and whether it complies with anti-discrimination laws. The review must also confirm that the model’s outputs are explainable and traceable. Firms must maintain records of these reviews, including any recommendations or corrective actions taken. The FCA expects these reviews to be conducted at regular intervals, such as annually or after significant model updates. In some cases, firms may be required to involve external auditors or specialists to carry out these reviews. The results of these reviews must be reported to senior management and, where required, to regulators.
As of 2 August 2026, firms must ensure that AI systems meet transparency obligations under EU AI Act Article 50. This includes providing machine-readable information for generative AI systems placed on the market before that date. The Digital Omnibus on AI, which came into force on 27 July 2026, also introduces new requirements for high-risk AI systems. These obligations apply to models used in financial services, such as those for credit scoring or investment advice. Firms must ensure that these systems are reviewed and updated to meet the new standards. The timeline for compliance is strict, with high-risk models needing to meet new requirements by 2 December 2027. The AI management system standard ISO/IEC 42001:2023 provides a framework for implementing these controls. Firms that adopt this standard must ensure that their AI governance processes are aligned with the standard’s clause-based approach. The first UKAS-accredited certification body, BSI, became operational in January 2026, offering firms a path towards certification. The certification process involves an assessment of governance, risk management, and data handling practices. Firms must also ensure that their AI systems meet the AI literacy duties introduced by the EU AI Act, which apply to staff who interact with AI systems. These duties must be implemented through training and awareness initiatives, with records of these efforts maintained for regulatory scrutiny.
