Solution · Model risk management
11
Validator independence, enforced rather than asserted.
An SR 26-2 shaped model inventory derives each model’s tier, schedules validation from it, and requires a validator distinct from the developer at sign-off.
The shape of the problem · 01
What this actually feels like.
- 01The model inventory is a spreadsheet, and each tier is whatever someone typed in.
- 02Validation dates live in a calendar reminder that nobody owns.
- 03Effective challenge is asserted in a memo, and nobody can show who validated what.
- 04AI features turn up inside vendor products before anyone has registered them.
How Zovos handles it · 02
Five steps, one graph.
Every step writes back to the same controls, policies, and issues your team already owns. There is no second source of truth.
- 01InventoryRegister each model in the inventory, with SR 26-2 lineage from development through use captured on the model workpaper.
- 02TierA risk scorer derives the tier from the model’s attributes, so nobody enters it by hand. The tier drives validation cadence and oversight.
- 03ValidateValidation is scheduled from the tier, and sign-off requires a validator distinct from the model’s developer.
- 04Review biasRecord bias and fair-lending reviews against the model, with the methodology and the results your partner produced, so the fairness evidence stays with the governance record.
- 05Register AIThe AI systems registry inventories AI use cases, including AI inside software you bought, with risk tiering and a maker-checker go-live gate. AI governance maps to the NIST AI RMF and ISO/IEC 42001.
What changes · 03
What the product does instead.
Tiering
The tier is derived by a scorer rather than entered as a label.
Independence
Validation sign-off requires a validator distinct from the developer.
Guidance
Built to SR 26-2 / OCC 2026-13, the successor to SR 11-7.
AI coverage
AI systems are registered and tiered alongside models and mapped to the NIST AI RMF and ISO/IEC 42001.
Want to see this on your library?
Bring a control library, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.