OCC Bulletin 2011-12 and Federal Reserve SR 11-7 — the foundational guidance on Model Risk Management — solve this in principle by requiring institutions to tier models according to their risk, then scale validation rigor, documentation, and monitoring frequency to that tier. In practice, building a tiering methodology that is both rigorous and defensible is a significant undertaking, and keeping it consistent across dozens or hundreds of models is even harder. That's the gap RiskInMind's new Model Risk Tiering Calculator is built to close.
Why tiering is the highest-leverage thing an MRM function can get right
Automate Regulatory Model Risk Governance
Examine models against 32 qualitative criteria and resolve risk Tiers with pre-deployment checklists per OCC 2011-12 guidelines.
Model risk management resources are finite. Independent validation is expensive and slow; every hour a validator spends on a low-impact reporting model is an hour not spent on the credit scoring engine that touches every loan decision. Regulators know this, which is why SR 11-7 doesn't ask institutions to validate everything with equal intensity — it asks them to calibrate effort to risk, and to be able to explain that calibration when asked.
Getting tiering wrong cuts both ways. Under-tiering a high-impact model means it gets a light review it doesn't deserve, and a flaw can sit undetected until it shows up in losses, a fair lending complaint, or a regulatory finding. Over-tiering low-impact models burns scarce validation capacity on things that don't move the needle, which starves the models that actually matter. A consistent, documented, defensible tiering framework is what lets a credit union or community bank with a three-person model risk team cover a fifty-model inventory without either outcome.
What the calculator actually does
RiskInMind's tiering tool operationalizes a three-part framework — Materiality, Reliance, and Intrinsic Risk — that maps directly onto SR 11-7's expectations and gives every model a defensible numeric score and a final tier.
Materiality captures how much would actually be at stake if the model were wrong. The calculator scores it across five dimensions: financial impact (does the model touch capital calculations, large portfolios, or P&L?), regulatory and compliance impact (does it feed BSA/AML, fair lending, or regulatory reporting?), reputational impact, operational impact, and strategic impact. Each dimension is rated High, Medium, or Low.
Reliance captures how dependent the institution actually is on the model's output in practice — a model that's automated end-to-end with no human override and no fallback is riskier than the same model used as one input among several, with a human in the loop. This is scored across four dimensions: degree of automation versus human intervention, availability of viable alternatives if the model fails, how consequential and time-sensitive the decisions it feeds are, and how well users actually understand its limitations.
Intrinsic Risk is the most granular layer and rolls up five sub-components, each with its own set of dimensions: model methodology (how complex, novel, or "black box" is the underlying approach?), model outcomes (what's the potential impact if the outputs are wrong?), model usage (how broadly and automatically is it deployed?), data quality and applicability (is the underlying data accurate, current, and representative?), and model implementation (how complex is the technical build, integration, and deployment?). Altogether, Intrinsic Risk spans 23 granular dimensions.
The math behind the score
Each granular dimension gets scored numerically — 4 points for High, 3 for Medium, 1 for Low — and the calculator sums them into aggregate scores for each category:
| Category | Dimensions | Score Range | Low | Medium | High |
|---|---|---|---|---|---|
| Materiality | 5 | 5–20 | 5–12 | 13–17 | 18–20 |
| Reliance | 4 | 4–16 | 4–9 | 10–13 | 14–16 |
| Intrinsic Risk | 23 (5 sub-components) | 23–92 | 23–57 | 58–80 | 81–92 |
From there, the framework builds the final tier in two steps. First, Materiality and Intrinsic Risk combine into a preliminary tier using a simple matrix — for example, Medium materiality crossed with High intrinsic risk lands at High preliminary risk, while Low materiality with Low intrinsic risk stays Low. Second, the Reliance score adjusts that preliminary tier upward where warranted: a model that's already Medium risk but that the institution leans on heavily, with automated decisions and no real fallback, gets upgraded to High. A Low-risk preliminary model with even Medium reliance gets bumped to Medium. Nothing gets tiered down based on reliance — high dependence only ever pushes risk up, never down.
What it looks like in practice
Run a model through the calculator and you get a Model Risk Classification Certificate — a clean, one-page regulatory assessment report mapped to the OCC 2011-12 / SR 11-7 framework. Here's a real example from a Credit Scoring Neural Network assessed through the tool: Materiality scored 15 out of 20 (Medium), Reliance scored 12 out of 16 (Medium), and Intrinsic Risk scored 70 out of 92 (Medium) — broken down as 15/20 on Methodology, 15/20 on Outcomes, 15/20 on Usage, 12/16 on Data Lineage, and 13/16 on Implementation. The result: Tier 2, Medium Risk, with a governance posture note specifying that the model requires formal independent validation, detailed specifications, and bi-annual performance reviews.
That last part is what makes the certificate actually useful day to day — it doesn't just hand back a score, it translates the score into a concrete governance expectation the validation team and the board can act on.
Why this matters more for credit unions and community banks than anyone else
Large banks can staff dedicated model risk teams that build and maintain bespoke tiering methodologies. Most credit unions and community banks can't. They're running the same OCC 2011-12 / SR 11-7 exam expectations on a fraction of the headcount, often with one or two people wearing the model risk hat alongside other compliance duties.
For that audience, a structured calculator does three things a spreadsheet or informal judgment call can't:
It makes the tiering process consistent across every model in the inventory, so two models with similar risk profiles land in the same tier regardless of who assessed them or when. It produces documentation on the spot — the certificate itself is exam-ready evidence that the institution applied a rigorous, quantitative methodology rather than an ad hoc one. And it directly answers the resource-allocation question examiners actually care about: not just "did you validate your models," but "how did you decide how much validation each model needed, and can you show your work."
Try it
The calculator is live at riskinmind.ai/calculators/model-risk-tier. If your institution is sitting on a model inventory that hasn't been formally tiered — or one that was tiered years ago and never revisited — it's a fast way to get a defensible starting point, and a much better use of your validation team's time than another round of manual triage.