Model Risk Manager
Risk, audit and assurance, a senior role
What does Model Risk Manager do?
Oversees the risk that models produce incorrect, unstable, biased or misused results: identification, tiering, independent challenge, approval for defined uses, monitoring, controlled change and retirement.
What it decides: Which systems count as models, what validation each tier needs, and which findings block deployment.
The competencies employers name
- Model risk management and independent challengecore, depth expected
Classifies models by tier, sets validation requirements, challenges data, methodology and performance evidence, and reports aggregate exposure.
14 graded topics teach this
- AI evaluation and testing designcore, depth expected
Designs tests for factuality, robustness, fairness, safety and abuse resistance with rubrics, baselines and thresholds, and says what a score misses.
12 graded topics teach this
- Post-deployment monitoring and drift detectioncore, depth expected
Sets performance metrics, thresholds and review triggers after launch, and treats a model change, a vendor update or new data as a reason to re-check.
12 graded topics teach this
- Model failure modes and bias recognitioncore, depth expected
Recognizes hallucination, drift, skew, brittleness and biased outcomes, and knows how each one enters a system.
10 graded topics teach this
- AI inventory and use-case intakerequired, working knowledge
Finds every AI system in use, records owner, purpose, data and risk tier, and keeps the record alive as tools change.
13 graded topics teach this
- AI risk register and treatment trackingrequired, working knowledge
Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.
12 graded topics teach this
- How models work, at a governance depthrequired, depth expected
Explains training, tokens, context windows, embeddings, retrieval and fine-tuning well enough to ask an engineer a precise question and spot weak evidence.
18 graded topics teach this
- Executive and board communication on AI riskrequired, working knowledge
Turns technical uncertainty into a one-page decision: material risks, trends, exceptions, remediation, and what the board is being asked to accept.
10 graded topics teach this
- AI vendor due diligence and third-party riskpreferred, working knowledge
Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.
5 graded topics teach this
- NIST AI RMF in practicepreferred, working knowledge
Runs GOVERN, MAP, MEASURE and MANAGE as a cycle with evidence, builds current and target profiles, and applies the generative AI profile.
3 graded topics teach this
Where it is taught
Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.
- Certified AI Practitioner: Workplace Foundations21 topics
- Certified AI Governance Professional (CAIGP)18 topics
- Certified Agentic AI Governance Professional (CAAGP)13 topics
- EU AI Act Implementation Expert13 topics
- The AI Lobbyist: Certified AI Policy Strategist10 topics
- Certified AI Transformation Professional (CATP)10 topics
- Certified AI Data Governance Professional (CADGP)5 topics
Check your readiness for this role
Add what you already have (optional)
Roles that feed into it
- AI Model Validator
- Quantitative Analyst
- Data Scientist
- Credit Risk Analyst
- Technology Risk Professional
Where it leads
- Head of Model Risk
- Chief Risk Officer, AI risk edition
Backgrounds that reach it fastest
What postings tend to name
Frameworks: SR 11-7, NIST AI RMF, ISO/IEC 42001.
Credentials often listed: FRM, PRM, CRISC, AIGP, ISO/IEC 42001 training. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.
Questions
- Does model risk management apply outside banking?
- Yes. The discipline matured in banking and insurance, and AI adoption is carrying its practices into healthcare, technology, government and any organization whose decisions rest on a model.