Last updated:
PRA Supervisory Statement SS1/23 sets out the Bank of England's five model risk management principles for UK banks. Published on 17 May 2023 and effective from 17 May 2024, it applies to UK-incorporated banks, building societies and PRA-designated investment firms that hold internal model approval. It covers AI and machine learning models, and it does not apply to insurers.
Who does SS1/23 apply to?
SS1/23 applies to regulated UK-incorporated banks, building societies and PRA-designated investment firms that hold internal model approval to calculate regulatory capital requirements. That means firms using the Internal Ratings Based approach for credit risk, the Internal Model Approach for market risk, or the Internal Model Method for counterparty credit risk. The PRA chose the word "banks" in the title deliberately, to make clear that the expectations do not apply to insurers or reinsurers. Firms without internal model approval fall outside the scope, though the PRA has encouraged them to treat the principles as good practice.
What are the five principles of SS1/23?
Model identification and model risk classification. Maintain a model definition, a complete model inventory, and a risk-tiering approach.
Governance. Board accountability, clear roles, and an approved model risk management framework and policy.
Model development, implementation and use. Standards for design, testing, documentation and change control.
Independent model validation. Validation independent of development, proportionate to the model's risk tier.
Model risk mitigants. Compensating controls and post-model adjustments where model limitations are known.
Does SS1/23 cover AI and machine learning?
Yes. The PRA's model definition is deliberately broad and captures AI and machine-learning models used for in-scope purposes. A firm cannot treat an ML credit model as exempt because a data science team built it instead of a modelling function. The two principles that cause most difficulty with AI are Principle 1, which requires identifying models that were never registered as models, and Principle 4, which requires validating systems whose behaviour is not analytically tractable. This is the same discovery problem that an AI inventory exists to solve.
How does SS1/23 compare to the US approach?
SS1/23 is principles-based and applies from a defined date to a defined population. Its US counterpart, SR 11-7, was superseded in April 2026 by SR 26-2, which moved further toward proportionality and, unlike SS1/23, expressly excluded generative and agentic AI from scope. Firms operating on both sides of the Atlantic now face a real divergence, where a UK ML model can be in scope under SS1/23 while its US equivalent sits outside SR 26-2.
Real world example:
A UK bank with IRB permission reviews an ML-based credit decisioning model against SS1/23. Under Principle 1 it registers the model in its inventory and tiers it as high risk. Under Principle 2 the framework is board-approved with a named Senior Manager accountable. Independent validation under Principle 4 finds that the model's performance degrades for thin-file applicants. Under Principle 5 the bank applies a post-model adjustment and a manual referral rule for that segment until the model is retrained, documenting the limitation instead of leaving it unaddressed.




