Model Risk Manager interview questions
What does a Model Risk Manager interview ask?
One question per competency the role leans on, 10 in all, the core ones first. Interviewers are not testing whether you know the frameworks; they are testing whether you have run the practice. Answer each with a case, a decision and the evidence: what the situation was, what you decided and why, and what the evidence showed afterwards.
- 1. Model risk management and independent challenge, core to the role
Explain independent challenge of a model to someone who built it. What do you challenge, and what do you leave to the developers?
A strong answer shows: Classifies models by tier, sets validation requirements, challenges data, methodology and performance evidence, and reports aggregate exposure.
- 2. AI evaluation and testing design, core to the role
Design the evaluation for a customer-service model before launch. What do you test, against what data, and what result blocks the release?
A strong answer shows: Designs tests for factuality, robustness, fairness, safety and abuse resistance with rubrics, baselines and thresholds, and says what a score misses.
- 3. Post-deployment monitoring and drift detection, core to the role
A model has been in production for a year. What do you monitor, what threshold triggers a review, and who gets the alert?
A strong answer shows: Sets performance metrics, thresholds and review triggers after launch, and treats a model change, a vendor update or new data as a reason to re-check.
- 4. Model failure modes and bias recognition, core to the role
Tell me about a time a model was confidently wrong. How did you notice, and what did you change afterwards?
A strong answer shows: Recognizes hallucination, drift, skew, brittleness and biased outcomes, and knows how each one enters a system.
- 5. AI inventory and use-case intake, required
How would you find every AI system in use across an organization, including the ones nobody registered, and keep that inventory current?
A strong answer shows: Finds every AI system in use, records owner, purpose, data and risk tier, and keeps the record alive as tools change.
- 6. AI risk register and treatment tracking, required
How do you keep an AI risk register from becoming a list nobody reads? What makes a risk entry actionable?
A strong answer shows: Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.
- 7. How models work, at a governance depth, required
Explain how a large language model produces an answer, at the depth a governance decision needs and no deeper.
A strong answer shows: Explains training, tokens, context windows, embeddings, retrieval and fine-tuning well enough to ask an engineer a precise question and spot weak evidence.
- 8. Executive and board communication on AI risk, required
Brief a board on an AI risk in two minutes. What do you say, and what do you leave out?
A strong answer shows: Turns technical uncertainty into a one-page decision: material risks, trends, exceptions, remediation, and what the board is being asked to accept.
- 9. AI vendor due diligence and third-party risk, preferred
A business unit wants to buy an AI tool next week. What do you ask the vendor, what evidence do you require, and what would make you say no?
A strong answer shows: Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.
- 10. NIST AI RMF in practice, preferred
Show me how you would apply the NIST AI RMF to one real system, function by function, without turning it into a checklist.
A strong answer shows: Runs GOVERN, MAP, MEASURE and MANAGE as a cycle with evidence, builds current and target profiles, and applies the generative AI profile.
Where the answers come from
Each question is graded on GAGE before any interviewer asks it: every topic is passed by explaining it back, and a passed explanation can be defended out loud. That record is the case you bring into the room. Check which of these 10 you can already answer from proof.