PRA SS1/23 model risk, explained.
The PRA's model-risk management principles are now the bar UK banks are held to for how they identify, own and validate their models — increasingly AI models. Here is what SS1/23 requires, and how AIssure maps your AI estate to its five principles.
What SS1/23 is
Supervisory Statement SS1/23, "Model risk management principles for banks", sets out the Prudential Regulation Authority's expectations for how UK banks manage the risk that their models are wrong, misused or misunderstood. It has been effective since 17 May 2024, and it applies to UK-incorporated banks, building societies and PRA-designated investment firms — not, for example, insurers.
SS1/23 is framed as principles, not prescriptive rules. That matters for AI: the statement is deliberately model-agnostic, so a machine-learning model that estimates a credit loss and a traditional statistical model sit under the same framework. As firms move material decisions onto AI, SS1/23 has become the reference point for how those models must be governed. You can read the statement on the Bank of England site.
The five principles
SS1/23 organises its expectations into five principles that run the length of a model's life — from knowing it exists to validating it in production.
| Principle | Focus | What it expects |
|---|---|---|
| Principle 1 | Model identification & risk tiering | A firm maintains a complete inventory of its models and classifies each by the risk it carries, so oversight is proportionate to materiality. AI and machine-learning models are models for this purpose. |
| Principle 2 | Governance | A board-approved framework assigns clear ownership and accountability for model risk, with policies, roles and management information that let senior management see and challenge it. |
| Principle 3 | Development, implementation & use | Models are developed, tested, documented and used to a defined standard across their lifecycle, with limitations understood and controls around how outputs feed decisions. |
| Principle 4 | Independent validation | A validation function independent of model development provides effective challenge — confirming a model is fit for purpose before use and on an ongoing basis, not merely at build time. |
| Principle 5 | Model risk mitigants | Where models carry residual risk, firms apply mitigants and post-implementation monitoring — and SS1/23 expects the ongoing monitoring itself to be independently validated. |
The thread running through Principles 4 and 5 is independence. SS1/23 does not merely ask that models be validated; it asks that the validation — including the validation of ongoing monitoring — be independent of the teams that build and run the models. That expectation is precisely where an independent assessment earns its standing.
How AIssure maps to it
AIssure treats your AI and machine-learning models as models in the SS1/23 sense and maps them to the five principles, one control at a time. For each model in scope, the assessment:
- Checks it is identified and risk-tiered (Principle 1) — present in an inventory and classified by materiality.
- Tests the governance around it (Principle 2) — named ownership, board-approved policy, and management information a supervisor would accept.
- Assesses development, implementation and use (Principle 3) against a defined standard.
- Provides the independent validation (Principles 4 and 5) SS1/23 expects — a third-line opinion over model governance and the ongoing monitoring of models in production.
Every finding is traced to source on a regulatory knowledge graph of 14,000+ provisions, so the board pack reads as "the statement says", not "the analyst recalls". The assessment is point-in-time and independent: it consumes the outputs of the monitoring your second line already runs, and never operates the models it assesses — the separation that lets a third-line opinion stand as evidence.
A firm that runs a model cannot objectively attest to it. That is the whole reason SS1/23 asks for independent validation — and the reason AIssure attests to your model governance but never operates, monitors or remediates it. The result is certification-ready evidence, never a claim to have certified you.
Related
Regulations & standards
The eight jurisdictions and the instruments within them.
→ By roleFor the CRO
Absolute defensibility under SMCR accountability.
→ The moatThe regulatory knowledge graph
How the citation trail is built, versioned and verified.
→ FrameworkAssessment frameworks
The maturity assessment and ISO deep dive behind the board pack.
→PRA SS1/23 — the questions we get.
What model-risk and validation teams ask about SS1/23 and how AIssure maps to it.
Does SS1/23 apply to AI and machine-learning models?
Yes. SS1/23 is deliberately model-agnostic: its definition of a model is broad enough to capture statistical, machine-learning and AI approaches. If an AI system produces a quantitative estimate that feeds a material decision, it falls within the model-risk framework the PRA expects — which is why the rise of AI has made SS1/23 the reference point for how UK banks govern their models.
Who does SS1/23 apply to, and when did it take effect?
It applies to UK-incorporated banks, building societies and PRA-designated investment firms (not, for example, insurers), and it has been effective since 17 May 2024. The PRA sets out its expectations as five principles rather than prescriptive rules, so firms implement them proportionately to the scale and complexity of their model estate.
What does 'independent validation' actually require?
Principle 4 expects a validation function independent of model development to provide effective challenge — confirming a model is fit for purpose before it is used and on an ongoing basis. Principle 5 extends that expectation to the ongoing monitoring of models in production. The common thread is independence: the people who build and run a model cannot be the only people who attest to it.
How does AIssure help with SS1/23?
AIssure maps your AI and machine-learning models to the five principles and provides the independent, point-in-time assessment SS1/23's validation expectations point to — a third-line opinion over your model governance, with every finding traced to source. It consumes the outputs of the monitoring you already run; it does not operate the models it assesses, which is what keeps the opinion independent.
Start with a thirty-minute read on your readiness.
A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.