Irony
I spent years in rooms making sure things didn’t get missed. This week the framework that started it all was quietly retired. Replaced by something which felt different. Just a few days earlier, a few of us had just published a paper arguing we need more, not less.
Quite ironic.
Week 15 of life post-MAS. (Links to past weeks in my newsletter.)
The familiar. A bunch of folks I am working with on a paper on AI and work. Discussing course projects with some MBA students I met a week ago. Some folks planning an AI programme for undergrads. Recording an interview with the head of an AI testing company for one of my courses. A collaborator from the legal AI space. A bunch of folks from the AI manpower development space I arranged a meeting for. A reporter I met in earlier weeks.
New connections. The ex-head of a banking regulator. Folks from the governance and AI functions of a global bank at a talk I gave. Folks from an AI and law society in Japan. A market risk veteran. A wealth manager who I thought was surprisingly advanced in using AI agents. Folks from a leading risk management technology company wanting to talk about advisory.
The contrast between the start of the week and the end was not something I expected.
My favorite job
Of all the roles I had, supervising model risk management was the one I loved most. If I had not been promoted, I suspect I would still be doing the same job today.
The job was far from glamorous. It was painstaking and often tedious work. And the eyes of most folks, even in MAS, would glaze over once you start talking to them about the technical details of models. But it had a clarity that some other areas didn’t. And I loved doing something that bosses would usually not have too many opinions on, due to its technical nature.
I remember what it felt like to find something that shouldn’t have been missed. The quiet satisfaction of the discipline working. Of the questions mattering.
That feeling stayed with me long after I left that job. It shaped the AI risk management guidelines I wrote.
And last week, a group of us, Lukasz, Agus, Tanveer, like-minded folks who have lived in this space for a while, tried to extend that discipline into the agentic world, in a paper on model risk management for Agentic AI.
And I was encouraged by the reception. Both online and offline. I did a talk for a global bank in the middle of the week, and I could tell they were asking the same questions and arriving at similar conclusions. That good risk management mattered, but that we needed to rethink it.
The retirement
SR 11-7 was released in 2011. It became the global standard for model risk management. Every major bank built their model governance around it. While we did not have its equivalent in Singapore, I spent years working with its principles, and liking the discipline that it started.
This week it was quietly retired.
I’m not sure about its successor. But I could feel a shift when I read between the lines. It seems milder than some of the other model risk management guidelines that had come out over the past few years - UK’s SS 1/23, Canada’s E-23.
And on Generative AI and Agentic AI, which I thought model risk management needed to be updated for, it says - out of scope.
That contrast - this shift in the scope of model risk management the same week we released a paper on model risk management for Agentic AI - landed quite hard for me.
The tension
There’s always a tension between regulation and innovation. The conventional wisdom is that regulation slows things down. Sometimes unnecessarily. I don’t disagree. There’s plenty of illogical rules around the world.
But unbridled innovation is also a recipe for disaster. And once that disaster strikes, it can deal a greater setback to innovation than any regulation.
Just look back to the Great Financial Crisis. That was arguably started by poor risk management for just one relatively simple model - the Gaussian copula. The models we have today in finance, particularly due to AI, are way more complex.
But what to do.
One of my friends said that we just have to move on. Go beyond regulation and focus on first principles.
I guess we just have to.