What is this course about?
Existing model risk frameworks assume a model you built, can inspect, and can validate deterministically. A general-purpose language model is none of those. This course covers inventory and tiering for a model you did not train, conceptual soundness review under that constraint, monitoring when the vendor updates the model underneath you, and examination-ready documentation.
Who is this course for?
- Model risk management staff
- Independent validation teams
- Chief risk officers and risk committee members
- Internal audit covering model risk
What do I need before starting?
- Model risk management experience
- Familiarity with your institution's validation standards
What will I be able to do afterwards?
- Fit generative AI into an existing model risk framework honestly
- Inventory and tier AI systems where the model is general-purpose
- Conduct conceptual soundness review for a model you did not train
- Design monitoring for a model that changes on a vendor's schedule
- Produce documentation that survives an examination
What does each module cover?
Why doesn't the existing framework fit?
45 minThe assumptions a traditional model risk framework makes that a general-purpose LLM violates.
Objectives
- Identify the framework assumptions generative AI breaks
- Decide whether to extend or create a parallel framework
- Communicate the gap to the risk committee
Topics
Activity. Map your framework's assumptions against a generative AI use case and find the breaks.
How do you inventory and tier AI systems?
50 minModel inventory when the same underlying model serves many different-risk uses.
Objectives
- Define the inventory unit for general-purpose models
- Tier by use rather than by model
- Capture the attributes validation requires
Topics
Activity. Inventory and tier five AI uses sharing one underlying model.
How do you assess conceptual soundness?
55 minSoundness review when you did not train the model and cannot inspect its weights.
Objectives
- Adapt conceptual soundness review to a third-party model
- Assess fitness for the specific use
- Document the limits of what you could review
Topics
Activity. Conduct a conceptual soundness review for one use and document its limits.
How do you validate a non-deterministic model?
55 minOutcome analysis and benchmarking when the same input can produce different outputs.
Objectives
- Design validation for non-deterministic output
- Build a representative test set
- Set acceptance criteria that mean something
Topics
Activity. Design and run a validation producing defensible acceptance evidence.
What happens when the vendor updates the model?
50 minOngoing monitoring and the change management problem a hosted model creates.
Objectives
- Detect model changes you were not told about
- Define what constitutes a material change
- Trigger revalidation appropriately
Topics
Activity. Build change detection and define your material change criteria.
How do you provide effective challenge?
45 minIndependent validation and effective challenge where the validators may know less than the builders.
Objectives
- Structure independent validation for AI systems
- Build validator capability
- Ensure challenge is genuinely effective
Topics
Activity. Run an effective challenge session on a colleague's AI use case.
How do you manage third-party model risk?
45 minVendor and fourth-party risk when the model provider sits behind your vendor.
Objectives
- Assess vendor and fourth-party model risk
- Require adequate transparency contractually
- Handle concentration risk across the industry
Topics
Activity. Map the model supply chain for one vendor-provided AI capability.
Building the documentation package
50 minThe workshop module: an examination-ready package for one AI use case.
Objectives
- Assemble the complete documentation package
- Anticipate examiner questions
- Identify and disclose the gaps
Topics
Activity. Assemble the package and have a colleague examine it.
What is the capstone project?
Model risk documentation package for one AI use case
Produce a complete model risk package: use-based inventory and tiering, conceptual soundness review with documented limits, non-deterministic validation with acceptance evidence, change detection and materiality criteria, and a supply chain assessment.
Deliverable: An examination-ready package with gaps disclosed rather than hidden.
How are learners assessed?
- Validation must produce defensible acceptance evidence for non-deterministic output
- Soundness review must state honestly what could not be assessed
- Package examined by a colleague playing an examiner
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for financial services.
Where does the course material come from?
Every module is grounded in primary sources โ the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- Supervision and Regulation Letters
Federal Reserve
Index of supervisory guidance including SR 11-7 on model risk management.
- FFIEC
Federal Financial Institutions Examination Council
Examination expectations for model and technology risk.
- AI Risk Management Framework
NIST
AI-specific risk structure mapped into the model risk framework.
- NIST AI 600-1, Generative AI Profile
NIST
Generative-AI-specific risks the validation must address.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- SR 11-7 remains the reference guidance and its deep link has moved; cite the Federal Reserve SR letters index and name SR 11-7 in prose rather than shipping a URL that will 404 again.
- Module 3 must be honest that conceptual soundness review of a third-party model is severely limited. Documenting the limits is the deliverable; pretending to a full review is worse than admitting the gap.
- Module 4's non-deterministic validation has no settled industry standard. Present the approaches and their trade-offs rather than asserting one is correct.
- Have an experienced model validator review the course. Validation practice is set by examination experience, not by framework documents.
- Module 5's vendor change problem is the strongest argument for controlling the model. Make the point analytically rather than as a pitch.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter โ you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM โ Claude, GPT, Llama, Gemini, Command โ and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped โ including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the AI Model Risk Management for Financial Institutions course cover?
Existing model risk frameworks assume a model you built, can inspect, and can validate deterministically. A general-purpose language model is none of those. This course covers inventory and tiering for a model you did not train, conceptual soundness review under that constraint, monitoring when the vendor updates the model underneath you, and examination-ready documentation. It runs 6.5 hours across 8 modules across 8 modules, at advanced level, and closes with a capstone: Model risk documentation package for one AI use case.
Who should take AI Model Risk Management for Financial Institutions?
It is written for Model risk management staff, Independent validation teams, Chief risk officers and risk committee members, Internal audit covering model risk. Prerequisites: Model risk management experience; Familiarity with your institution's validation standards.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere โ cloud, private VPC, on-premise, or fully air-gapped โ and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for financial services teams that cannot send work to a public AI tool.
How do we get access to AI Model Risk Management for Financial Institutions?
Request access and we will set it up for your cohort โ hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for financial services cost on ibl.ai?
There is no per-seat pricing โ you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.