Risk AssessmentCritical riskConsensus useful

AI Playbook for Regulatory Examination Response — Model Risk Management

The OCC has issued a Matter Requiring Attention (MRA) following a targeted review of your credit loss forecasting models. The MRA cites inadequate model validation documentation, use of a model outside its approved scope, and failure to remediate two prior findings within the required timeframe. Your board model risk committee meets in 10 days.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: The OCC has issued a Matter Requiring Attention (MRA) following a targeted review of your credit loss forecasting models.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Regulatory Examination Response — Model Risk Management".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • OCC MRA letter with specific findings - Model inventory and validation status log - Prior examination findings (two open items) - SR 11-7 compliance self-assessment - Model use register showing approved vs. actual scope

Attachments: Spreadsheets (Spreadsheets)

The Prompt

You are a model risk management officer preparing a board-level response to an OCC MRA on credit loss forecasting models.  I am attaching: - OCC MRA letter with specific findings - Model inventory and validation status log - Prior examination findings (two open items) - SR 11-7 compliance self-assessment - Model use register showing approved vs. actual scope

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Map each OCC finding to the specific model, validation gap, and responsible owner — produce a findings register with severity classification and current remediation status.
2. Analyze the model use register to identify all instances where models were used outside their approved scope — assess whether the out-of-scope use materially affected any credit decisions or regulatory capital calculations.
3. Review the SR 11-7 self-assessment against the OCC findings to identify gaps in your internal assessment that should have caught these issues before examination.
4. Develop a remediation plan with specific milestones, owners, and completion dates for each MRA finding — structured to meet OCC's expected response timeline.
5. Draft the board model risk committee briefing — including a root cause analysis, remediation plan summary, and the governance changes being implemented to prevent recurrence.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Multi-model consensus on MRA finding severity and regulatory exposure
  • Model use scope violation register with capital impact flags
  • SR 11-7 gap analysis against OCC findings
  • Remediation milestone plan with owner assignments
  • Draft board briefing with model-agreement score on risk classification

Review before you act

  • Validate this output against source files before relying on it: Map each OCC finding to the specific model, validation gap, and responsible owner — produce a findings register with severity classification and current remediation status.
  • Validate this output against source files before relying on it: Analyze the model use register to identify all instances where models were used outside their approved scope — assess whether the out-of-scope use materially affected any credit decisions or regulatory capital calculations.
  • Validate this output against source files before relying on it: Review the SR 11-7 self-assessment against the OCC findings to identify gaps in your internal assessment that should have caught these issues before examination.
  • Validate this output against source files before relying on it: Develop a remediation plan with specific milestones, owners, and completion dates for each MRA finding — structured to meet OCC's expected response timeline.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Regulatory Examination Response — Model Risk Management, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface multi-model consensus on mra finding severity and regulatory exposure; model use scope violation register with capital impact flags; sr 11-7 gap analysis against occ findings; remediation milestone plan with owner assignments. Those are comparison artifacts — they only exist if more than one model runs. Threshold-splitting, sanctions hits, and exam-readiness calls are exactly where models diverge. Record the split and the human resolution.

US FederalBanking Regulation and Model RiskRisk AssessmentCriticalSpreadsheets

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.