Skip to main content

Model Risk Manager

Risk, audit and assurance, a senior role

What does Model Risk Manager do?

Oversees the risk that models produce incorrect, unstable, biased or misused results: identification, tiering, independent challenge, approval for defined uses, monitoring, controlled change and retirement.

What it decides: Which systems count as models, what validation each tier needs, and which findings block deployment.

The competencies employers name

  • Model risk management and independent challengecore, depth expected

    Classifies models by tier, sets validation requirements, challenges data, methodology and performance evidence, and reports aggregate exposure.

    14 graded topics teach this

  • AI evaluation and testing designcore, depth expected

    Designs tests for factuality, robustness, fairness, safety and abuse resistance with rubrics, baselines and thresholds, and says what a score misses.

    12 graded topics teach this

  • Post-deployment monitoring and drift detectioncore, depth expected

    Sets performance metrics, thresholds and review triggers after launch, and treats a model change, a vendor update or new data as a reason to re-check.

    12 graded topics teach this

  • Model failure modes and bias recognitioncore, depth expected

    Recognizes hallucination, drift, skew, brittleness and biased outcomes, and knows how each one enters a system.

    10 graded topics teach this

  • AI inventory and use-case intakerequired, working knowledge

    Finds every AI system in use, records owner, purpose, data and risk tier, and keeps the record alive as tools change.

    13 graded topics teach this

  • AI risk register and treatment trackingrequired, working knowledge

    Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.

    12 graded topics teach this

  • How models work, at a governance depthrequired, depth expected

    Explains training, tokens, context windows, embeddings, retrieval and fine-tuning well enough to ask an engineer a precise question and spot weak evidence.

    18 graded topics teach this

  • Executive and board communication on AI riskrequired, working knowledge

    Turns technical uncertainty into a one-page decision: material risks, trends, exceptions, remediation, and what the board is being asked to accept.

    10 graded topics teach this

  • AI vendor due diligence and third-party riskpreferred, working knowledge

    Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.

    5 graded topics teach this

  • NIST AI RMF in practicepreferred, working knowledge

    Runs GOVERN, MAP, MEASURE and MANAGE as a cycle with evidence, builds current and target profiles, and applies the generative AI profile.

    3 graded topics teach this

Where it is taught

Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.

Check your readiness for this role

Add what you already have (optional)
Signed in? Every topic you have passed already counts as proof.

Roles that feed into it

  • AI Model Validator
  • Quantitative Analyst
  • Data Scientist
  • Credit Risk Analyst
  • Technology Risk Professional

Where it leads

Backgrounds that reach it fastest

What postings tend to name

Frameworks: SR 11-7, NIST AI RMF, ISO/IEC 42001.

Credentials often listed: FRM, PRM, CRISC, AIGP, ISO/IEC 42001 training. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.

Questions

Does model risk management apply outside banking?
Yes. The discipline matured in banking and insurance, and AI adoption is carrying its practices into healthcare, technology, government and any organization whose decisions rest on a model.