Standards and guidance

PRA SS1/23: Model Risk & AI Agent Review Context

The PRA’s supervisory statement on model risk management principles for banks in its stated scope. The current version is dated April 2026.

How to use this reference

Confirm entity applicability and the relationship to the customer’s model inventory and governance. Evidence collection and engineering tests do not replace independent model validation or the bank’s own responsibilities.

Evidence to discuss

Identify the system scope, control owner, implementation evidence, test results, exceptions and the reviewer responsible for acceptance. Requirements are mapped to the agreed source version; missing and untested controls remain visible.

Source and status

Bank of England current SS1/23

Reference checked on 7 October 2026. This page is an engineering overview, not legal advice or a claim of accreditation, partnership or endorsement.

Model risk review discussion

These are engineering discussion prompts, not a substitute for the source requirements or the appointed reviewer's criteria.

  • Has the bank established how the agent relates to its model inventory and governance?
  • Which assumptions, dependencies and changes need review by the appointed function?
  • What versioned technical tests and unresolved findings support that review?

Use the security review checklist to organise owners, test records and gaps. The assessment method explains how coverage limits are recorded.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.