Risk AssessmentHigh riskComparison recommended

AI Playbook for Model Risk Inventory

A $14B regional bank has deployed AI models across 11 business lines in the past 18 months—credit decisioning, fraud detection, customer service, collections, and HR screening among them. The OCC has issued guidance on model risk management and the bank's Chief Risk Officer needs a complete model inventory before the next examination.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: A $14B regional bank has deployed AI models across 11 business lines in the past 18 months—credit decisioning, fraud detection, customer service, collections, and HR screening among them.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Model Risk Inventory".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • Business line AI deployment register (11 lines, self-reported)
  • Vendor contracts for all third-party AI tools
  • Internal model development documentation where available
  • OCC Bulletin 2011-12 and SR 11-7 requirements
  • Prior examination findings related to model risk

Attachments: Multiple attachments (Spreadsheets, Documents)

The Prompt

You are an AI governance specialist building a model risk inventory for a $14B regional bank ahead of an OCC examination. I am attaching:

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Classify each model by risk tier: Tier 1 (credit, compliance, regulatory impact), Tier 2 (operational, customer-facing), Tier 3 (internal tools, low stakes).
2. Identify models that lack documentation required under SR 11-7: conceptual soundness review, ongoing monitoring, outcome testing.
3. Flag any third-party AI vendor contracts that do not include model explainability, audit rights, or validation access provisions.
4. Assess which models have direct fair lending or ECOA exposure and whether adverse action notice procedures are in place.
5. Prepare the model inventory in the format the OCC expects and identify the top 5 examination risks.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Tiered model risk inventory in OCC-expected format
  • Documentation gap list by model
  • Third-party contract risk flags
  • Fair lending and ECOA exposure map
  • Top 5 examination risk summary

Review before you act

  • Validate this output against source files before relying on it: Classify each model by risk tier: Tier 1 (credit, compliance, regulatory impact), Tier 2 (operational, customer-facing), Tier 3 (internal tools, low stakes).
  • Validate this output against source files before relying on it: Identify models that lack documentation required under SR 11-7: conceptual soundness review, ongoing monitoring, outcome testing.
  • Validate this output against source files before relying on it: Flag any third-party AI vendor contracts that do not include model explainability, audit rights, or validation access provisions.
  • Validate this output against source files before relying on it: Assess which models have direct fair lending or ECOA exposure and whether adverse action notice procedures are in place.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Model Risk Inventory, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface tiered model risk inventory in occ-expected format; documentation gap list by model; third-party contract risk flags; fair lending and ecoa exposure map. Those are comparison artifacts — they only exist if more than one model runs. Risk-tier assignments and 'high-risk system' calls vary with how a model reads a use-case description. Comparison exposes those classification fights before they reach an exam.

AI GovernanceInventory and Regulatory FitRisk AssessmentHighMultiple attachments

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.