AI Economy

The Model Risk Register: How Mid-Market Banks Are Extending Operational Risk Frameworks to Cover Embedded AI Vendors

The FY Times Editorial · 31/08/2026 · 7 min read

Risk management team in a mid-market bank reviewing a model risk register dashboard that tracks AI vendor models, with charts and risk ratings on a large screen.

Mid-market banks are not waiting for regulators to force the issue. Faced with rapid adoption of AI tools from vendors such as Salesforce, Microsoft, and a growing list of fintech specialists, they are extending their operational risk frameworks to cover embedded AI vendors. The result is a new discipline: the model risk register.

This case study examines how mid-market banks are adapting their risk management practices, what this means for AI vendors, and the broader commercial implications for the financial services sector.

What Changed: The Rise of the Model Risk Register

Historically, model risk management (MRM) was the preserve of large banks with dedicated quantitative teams. The Federal Reserve's SR 11-7 guidance, issued in 2011, set the standard for model risk management, but it applied primarily to large, systemically important banks. Mid-market banks, with assets typically between $10 billion and $100 billion, often had lighter-touch MRM frameworks, focusing on credit risk models and basic stress testing.

However, the past two years have seen a marked shift. Mid-market banks are now embedding AI tools across their operations: chatbots for customer service, machine learning for fraud detection, natural language processing for document review, and predictive analytics for credit decisions. These tools are rarely built in-house. Instead, they are procured from vendors who offer AI as part of a broader software platform or as a standalone service.

The problem is that these AI tools are not traditional software. They are models that learn from data, and their outputs can be unpredictable. A chatbot might hallucinate a product feature; a fraud detection model might generate false positives that harm customer experience; a credit scoring model might inadvertently discriminate against certain groups. These are model risks, not just software risks.

In response, mid-market banks are extending their operational risk frameworks to include a model risk register. This register is a centralised log of all AI models in use, including those embedded in vendor software. It records the model's purpose, the vendor, the data inputs, the validation status, and the risk rating. It is a living document, updated as models change or as new risks emerge.

Why It Matters: The Shift from Vendor Management to Model Governance

For years, banks managed AI vendors under their third-party risk management (TPRM) programmes. This involved due diligence on the vendor's financial stability, security practices, and compliance with regulations. But TPRM is not designed to assess the quality of a model's outputs. It does not ask whether the model is biased, whether it is stable under stress, or whether it can be explained to a regulator.

By moving AI vendors into the model risk register, banks are signalling a change in how they view these tools. They are no longer just software providers; they are model developers. This has significant implications for both banks and vendors.

For banks, the model risk register forces a more rigorous approach to AI adoption. Each model must be validated before it goes live, and then monitored on an ongoing basis. This is a significant resource commitment, especially for mid-market banks with limited data science teams. Some banks are responding by building internal validation capabilities, while others are outsourcing validation to specialist firms.

For vendors, the shift means that their AI products will be subject to greater scrutiny. Banks will ask for model documentation, validation reports, and evidence of ongoing monitoring. Vendors that cannot provide this will find it harder to sell to mid-market banks. This is a commercial opportunity for vendors that can demonstrate robust model governance, and a threat to those that cannot.

How Mid-Market Banks Are Implementing the Register

The implementation of a model risk register varies by bank, but there are common patterns emerging. Most banks start by inventorying all AI models in use, including those embedded in vendor software. This is often harder than it sounds, because AI can be hidden inside larger platforms. For example, a customer relationship management (CRM) system might include an AI-powered lead scoring feature that the bank did not explicitly purchase.

Once the inventory is complete, banks assign a risk rating to each model. This rating is based on the potential impact of a model failure, the complexity of the model, and the degree of human oversight. High-risk models, such as those used for credit decisions or anti-money laundering, require more rigorous validation and monitoring than low-risk models, such as those used for marketing.

Next, banks establish a validation process. This involves testing the model against historical data, checking for bias, and assessing its performance under different scenarios. For vendor models, banks often rely on the vendor's own validation, but they may also conduct independent testing, especially for high-risk models.

Finally, banks set up ongoing monitoring. This includes tracking model performance metrics, reviewing model outputs for anomalies, and re-validating models when they are updated or when new data becomes available. The model risk register is updated accordingly, providing a clear audit trail for regulators.

Commercial Impact: What This Means for AI Vendors

The extension of model risk frameworks to embedded AI vendors has direct commercial consequences. Vendors that sell AI to mid-market banks will need to invest in model governance capabilities. This includes producing model documentation, providing validation support, and offering transparency into how their models work.

Some vendors are already responding. For example, major cloud providers like Microsoft and Amazon Web Services offer AI governance tools that help customers manage model risk. Fintech vendors are also adapting, with some providing model risk reports as part of their standard offering.

However, the burden is not just on vendors. Banks are also changing their procurement processes. They are asking more questions about AI during vendor due diligence, and they are including model risk requirements in contracts. This is leading to longer sales cycles and higher compliance costs for vendors, but it is also creating a barrier to entry for less sophisticated competitors.

For mid-market banks, the commercial impact is twofold. On one hand, the model risk register adds operational cost. Banks must hire or train staff to manage the register, and they may need to invest in validation tools. On the other hand, the register reduces the risk of regulatory fines and reputational damage, which can be far more costly.

Risks and Unknowns: The Limits of the Model Risk Register

The model risk register is not a panacea. There are several risks and unknowns that banks and vendors must consider.

First, the register is only as good as the inventory. If a bank misses an AI model embedded in a vendor platform, that model is not covered. This is a particular risk with large, complex software suites where AI features are added without the bank's explicit knowledge.

Second, validation is not foolproof. Models can behave differently in production than in testing, especially when they encounter new types of data. The model risk register can track this, but it cannot prevent it.

Third, there is a question of regulatory expectations. While SR 11-7 is well-established, it is not clear how regulators will apply it to AI models, especially those from third-party vendors. Some regulators are issuing new guidance, such as the European Union's AI Act, but the landscape is still evolving. Banks may find that their model risk register meets current expectations but not future ones.

Finally, there is the challenge of model explainability. Many AI models, particularly deep learning models, are 'black boxes' that are difficult to interpret. This makes it hard to validate them or to explain their decisions to regulators. The model risk register can document the model, but it cannot make it more explainable.

FY Outlook: What Happens Next

Over the next 12 to 24 months, we expect the model risk register to become standard practice across mid-market banks. This will be driven by several factors: increasing regulatory attention, growing AI adoption, and the practical need to manage risk.

We also expect to see more standardisation in how model risk is assessed. Industry bodies, such as the Risk Management Association, are developing frameworks that mid-market banks can adopt. This will reduce the burden on individual banks and create a more consistent approach.

For AI vendors, the message is clear: model governance is now a competitive differentiator. Vendors that invest in transparency and validation will win deals; those that do not will be left behind. This is an opportunity for vendors to build trust and to command premium pricing.

For banks, the model risk register is not just a compliance exercise. It is a way to ensure that AI delivers value without introducing unacceptable risk. Banks that embrace this discipline will be better positioned to scale their AI initiatives and to respond to regulatory expectations.

Conclusion: A Necessary Evolution

The model risk register is a practical response to a real problem. As mid-market banks embed AI vendors into their operations, they cannot rely on traditional vendor management alone. They need a framework that treats AI as a model, with all the risks that entails.

The shift is not without costs, but it is a necessary evolution. It protects banks from regulatory and reputational harm, and it creates a more transparent market for AI vendors. For those who are willing to adapt, the model risk register is not a burden but a strategic advantage.