Regulatory Gap: Why Model Risk Management Is Structurally Ill-Suited to Govern AI-Driven Code Transformation
Overview
Model Risk Management (MRM), set out in the Federal Reserve's SR 11-7 and OCC Bulletin 2011-12, governs quantitative models in banking.
Original abstract (English)
Model Risk Management (MRM), set out in the Federal Reserve's SR 11-7 and OCC Bulletin 2011-12, governs quantitative models in banking. AI vendors now offer tools for rewriting production code, including COBOL-to-Java modernization, raising a scope question for the estimation-oriented definition of a model. Through structured assumption-violation mapping, this paper identifies five structural gaps in relying on MRM alone: definition, validation, documentation, monitoring, and third-party risk management. Classifying an underlying LLM as a model leaves a separate task of specifying assurance for the particular software transformation it produces. The paper proposes a complementary Transformation Risk Management (TRM) framework organized around behavioral provenance, scoped functional-equivalence certification, transformation audit trails, rollback architecture, and concentration risk assessment.