Credit Risk
Credit models a supervisor can read: scorecards, affordability and impairment
The models a lender’s decisions and its provisions rest on — application and behavioural scorecards, affordability, IFRS 9 expected credit loss and the forecasts behind it — built for UK banks and lenders. The model is the easy half. What gets examined is the record of how it was built: what it is for, what it was fitted on, where it stops being valid, and what it cannot see. Both are handed over, and the firm owns them.
Twenty years across banks, financial services, government and international advisory.
Risk Audit Flow
LiveData inputs
Origin & lineage
Model behaviour
Logic & drift
Controls
Approval paths
Decision gate
Override check
Output review
Audit trail
Review area 1 of 5
An audit is only worth its conclusion when every area was examined. An area nobody reached is reported as unknown, never as cleared.
The shift
The score became the decision
Who is lent to, how much and at what price is now decided by an estimate rather than by somebody reading a file. That moved credit model risk out of the analytics team and onto the list of things a board is asked to evidence control of.
The gap
Two risks, and one model answering them
CONC 5.2A asks two questions: will the customer repay, and can they afford to without harm. A scorecard answers the first. Firms that let it stand in for the second have an affordability decision with no model behind it.
The standard
A model you can fail on purpose
State what the model claims, define what wrong would look like, then produce the case that breaks it — before the validation function does. A model nobody has seen fail is a model nobody has tested.
What we build
The models a lending decision and its provision rest on
Four models, one buyer. Each is fitted, tested against a written failure definition, and handed over with the record of how it was built.
Application and behavioural scorecards
Credit risk at origination and through the life of the account. Weight-of-evidence scorecards where the points have to be explainable, with a gradient-boosted challenger fitted alongside so the cost of that explainability is a measured number rather than an assumption.
Affordability and income resilience
The question a scorecard does not answer: the risk to the customer of not being able to repay. Assessed over the term, on rate and inflation paths, rather than on the month the application arrived.
IFRS 9 expected credit loss
Staging and the significant-increase-in-credit-risk test, forward-looking scenarios and their weights, and post-model adjustments held as a named, dated list rather than a plug. What gets challenged is the movement between periods, so that is what the model is built to explain.
Impairment and balance-sheet forecasting
Driver-based, with an interval on every figure and the point where the short and long horizons meet checked rather than smoothed over. A five-year point forecast with no interval is not a forecast anybody can defend.
The deliverable
The firm owns the model, the code and the record.
A firm that cannot run, inspect and change its own credit model without us cannot evidence control of it. Everything below is handed over in a form somebody else can pick up.
Purpose and approved use
What the model is for, and what would be a use beyond it.
Population and exclusions
The sample, the windows, and every row that did not make it, counted.
Assumptions, named
Including the ones nobody can verify — reject inference above all — with their effect shown rather than absorbed.
Operating boundaries
The range the parameters were estimated over, so extrapolation is a flagged condition and not a silent one.
Limitations
What the model cannot see, written by the people who built it.
Tier, and the monitoring it demands
Materiality and complexity, and the cadence of review that follows from them.
How engagements are shaped
Start with a review of the model you already run
Most lenders have more model than record. The first step reads what exists and says where it stands, on documentation alone — no production data and no system access.
Start here
Model review
Fixed fee, one model
- One scorecard, affordability or ECL model, read cold
- Development record checked against the six items above
- Written verdict, with what is missing named
- Documentation only: no production data, no system access
Then
Build
Scoped on the decision, not the technique
- Built and tested against a written failure definition
- Challenger fitted alongside where explainability costs
- The full development record, handed over
- The firm owns the model, the code and the record
Ongoing
Monitoring support
On the cadence the tier demands
- Performance read on a set cycle
- Boundary breaches surfaced, not smoothed
- Re-fit when the population moves
- Independent review stays with the firm or a third party
What we cannot be
We cannot build your model and be its independent validation.
PRA SS1/23 Principle 4 makes independence the control, and extends it to the independent review of monitoring reports. A validation performed by the party that built the model does not satisfy it, and neither does a monitoring reading performed by them. A firm buying a build from us has bought a model and the record of how it was made — not its own independent validation, which has to come from its validation function or a third party.
One scope question worth settling early: SS1/23 binds firms with internal model approval for regulatory capital. A standardised-approach lender sits outside it and is welcome to adopt the principles voluntarily — which changes who signs, and what an unmet expectation means.
Where this hands over: the expected credit loss figure a firm files is regulatory reporting work; the controls around a credit decision that need no model at all are models & controls; and the pipeline that runs the model every day is AI & automation.
Seeing one
Worked models are shown by invitation, not published
Every one of them fits itself in the browser over a constructed population, so what you are looking at is arithmetic running rather than a screenshot of a result — and none of it is any firm’s data. Every enquiry is treated in confidence.