Skip to main content
Promotional banner for the pentest readiness checklist
Should You Tier Your Model Risk Program by Materiality?Regulatory Obligations Management
4 min readFor Internal Auditors

Should You Tier Your Model Risk Program by Materiality?

The revised interagency model risk guidance issued on April 17, 2026, by the FDIC, OCC, and Federal Reserve presents a critical decision for banking compliance teams: should you govern all models with uniform rigor, or should you tier your oversight based on model materiality?

Some argue that differentiated governance creates gaps and compliance risks. Others insist that proportionate oversight is the only sustainable path forward, and that the guidance itself endorses this approach.

This isn't just an academic debate. Your decision impacts how you allocate validation resources, structure your model inventory, and defend your program during examinations.

The Case for Uniform Governance

Applying consistent oversight to all models has three main advantages.

First, materiality assessments can be subjective and manipulated. A model deemed "low materiality" today might become critical tomorrow due to changes in portfolio composition or market conditions. Relying on tiering means betting that your materiality classifications will remain accurate and that teams won't downgrade models to avoid validation.

Second, examiner expectations may not align with your internal risk ratings. A model you consider low-risk might attract regulatory scrutiny if it involves compliance-sensitive areas like fair lending, BSA/AML, or capital adequacy. The guidance states that model purpose, whether it supports regulatory requirements or financial risk management, drives materiality. If you're using a lighter approach for a model informing regulatory calculations, you're exposed.

Third, uniform governance simplifies operations. You avoid multiple validation procedures, different documentation standards, and complex workflows. Everyone knows the standard. Every model is validated with the same rigor, leaving no room for interpretation or shortcuts.

Banks under heightened scrutiny often treat every model as material until proven otherwise, adopting this approach to avoid compliance issues.

The Case for Materiality-Based Tiering

The counterargument is compelling and aligns with the guidance.

The agencies describe materiality as "the primary lens for governance rigor," defined by model exposure (output significance to business decisions) and model purpose (regulatory obligations or other uses). High-materiality models require "comprehensive and rigorous oversight," while lower-materiality models can be monitored with lighter practices.

This approach acknowledges that banks operate hundreds or thousands of models. Applying identical validation protocols to both a credit decision engine and a branch staffing calculator is impractical and not risk-proportionate.

Tiered governance aligns resources with actual risk. If you're spending the same validation budget on low-impact models as on those driving capital allocation or loan pricing, you're misallocating effort. Differentiated oversight lets you focus technical review, independent challenge, and continuous monitoring where it matters most.

Operationally, uniform governance across extensive model inventories often leads to validation backlogs, outdated documentation, and models running past review dates. A tiered approach with clear criteria and documented rationale is more defensible than a uniform standard you can't execute.

Where Practitioners Actually Land

Most banking organizations are implementing tiered governance, but with safeguards.

They're documenting materiality criteria in policy, requiring senior risk committee approval for tier assignments, and building mandatory escalation triggers. A low-materiality model still gets ongoing monitoring. If performance deteriorates or usage changes, it gets reclassified and fully validated.

They're also defining tiers around regulatory sensitivity, not just business impact. Any model informing capital calculations, fair lending decisions, or BSA/AML scoring gets elevated treatment regardless of portfolio size. The guidance's emphasis on model purpose as a materiality driver is taken seriously.

Vendor models are another area where tiering is common but controversial. Banks apply lighter validation to third-party tools with established track records and transparent methodologies, while subjecting proprietary or black-box vendor models to the same rigor as internally developed systems. The guidance's requirement to "develop understanding of vendor model conceptual soundness" and "conduct ongoing monitoring" applies regardless of tier, but the depth and frequency vary.

The gap between AI and traditional model risk adds another layer of tiering. Generative AI and agentic AI models are excluded from this guidance's scope, but governance must still exist. Banks are building parallel AI governance frameworks with their own materiality tiers, risk assessments, and control libraries, recognizing that the risk profile of a customer service chatbot differs from an AI agent making credit recommendations.

Our Take

Tiered governance is the right approach if you can defend your materiality criteria under examination pressure.

The guidance allows for differentiation. Use it. But document your tier definitions precisely, tie them to measurable factors (portfolio exposure, regulatory purpose, data sensitivity), and build review cycles that reassess materiality as conditions change. A model's tier should not be static.

The tradeoff is complexity. You need systems to track tier assignments, trigger escalations when usage patterns shift, and produce reports showing examiners how you're managing aggregate model risk across tiers. A centralized, governed repository linking models to validation status, controls, and business impact is essential.

If you can't build that infrastructure, default to uniform governance. A simple standard you can execute beats a sophisticated framework you can't sustain. But if you're operating at scale, with hundreds of models and finite validation resources, proportionate oversight isn't just practical, it's what the agencies expect you to do.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like