VIRTICUSDiscuss your situation

Credit Risk

Credit models a supervisor can read: scorecards, affordability and impairment

The models a lender’s decisions and its provisions rest on — application and behavioural scorecards, affordability, IFRS 9 expected credit loss and the forecasts behind it — built for UK banks and lenders. The model is the easy half. What gets examined is the record of how it was built: what it is for, what it was fitted on, where it stops being valid, and what it cannot see. Both are handed over, and the firm owns them.

Twenty years across banks, financial services, government and international advisory.

Risk Audit Flow

Live

Data inputs

Origin & lineage

Reviewing

Model behaviour

Logic & drift

–

Controls

Approval paths

–

Decision gate

Override check

–

Output review

Audit trail

–

Review area 1 of 5

An audit is only worth its conclusion when every area was examined. An area nobody reached is reported as unknown, never as cleared.

The shift

The score became the decision

Who is lent to, how much and at what price is now decided by an estimate rather than by somebody reading a file. That moved credit model risk out of the analytics team and onto the list of things a board is asked to evidence control of.

The gap

Two risks, and one model answering them

CONC 5.2A asks two questions: will the customer repay, and can they afford to without harm. A scorecard answers the first. Firms that let it stand in for the second have an affordability decision with no model behind it.

The standard

A model you can fail on purpose

State what the model claims, define what wrong would look like, then produce the case that breaks it — before the validation function does. A model nobody has seen fail is a model nobody has tested.

What we build

The models a lending decision and its provision rest on

Four models, one buyer. Each is fitted, tested against a written failure definition, and handed over with the record of how it was built.

Application and behavioural scorecards

Credit risk at origination and through the life of the account. Weight-of-evidence scorecards where the points have to be explainable, with a gradient-boosted challenger fitted alongside so the cost of that explainability is a measured number rather than an assumption.

Affordability and income resilience

The question a scorecard does not answer: the risk to the customer of not being able to repay. Assessed over the term, on rate and inflation paths, rather than on the month the application arrived.

IFRS 9 expected credit loss

Staging and the significant-increase-in-credit-risk test, forward-looking scenarios and their weights, and post-model adjustments held as a named, dated list rather than a plug. What gets challenged is the movement between periods, so that is what the model is built to explain.

Impairment and balance-sheet forecasting

Driver-based, with an interval on every figure and the point where the short and long horizons meet checked rather than smoothed over. A five-year point forecast with no interval is not a forecast anybody can defend.

The deliverable

The firm owns the model, the code and the record.

A firm that cannot run, inspect and change its own credit model without us cannot evidence control of it. Everything below is handed over in a form somebody else can pick up.

Purpose and approved use

What the model is for, and what would be a use beyond it.

Population and exclusions

The sample, the windows, and every row that did not make it, counted.

Assumptions, named

Including the ones nobody can verify — reject inference above all — with their effect shown rather than absorbed.

Operating boundaries

The range the parameters were estimated over, so extrapolation is a flagged condition and not a silent one.

Limitations

What the model cannot see, written by the people who built it.

Tier, and the monitoring it demands

Materiality and complexity, and the cadence of review that follows from them.

How engagements are shaped

Start with a review of the model you already run

Most lenders have more model than record. The first step reads what exists and says where it stands, on documentation alone — no production data and no system access.

Start here

Model review

Fixed fee, one model

  • One scorecard, affordability or ECL model, read cold
  • Development record checked against the six items above
  • Written verdict, with what is missing named
  • Documentation only: no production data, no system access

Then

Build

Scoped on the decision, not the technique

  • Built and tested against a written failure definition
  • Challenger fitted alongside where explainability costs
  • The full development record, handed over
  • The firm owns the model, the code and the record

Ongoing

Monitoring support

On the cadence the tier demands

  • Performance read on a set cycle
  • Boundary breaches surfaced, not smoothed
  • Re-fit when the population moves
  • Independent review stays with the firm or a third party

What we cannot be

We cannot build your model and be its independent validation.

PRA SS1/23 Principle 4 makes independence the control, and extends it to the independent review of monitoring reports. A validation performed by the party that built the model does not satisfy it, and neither does a monitoring reading performed by them. A firm buying a build from us has bought a model and the record of how it was made — not its own independent validation, which has to come from its validation function or a third party.

One scope question worth settling early: SS1/23 binds firms with internal model approval for regulatory capital. A standardised-approach lender sits outside it and is welcome to adopt the principles voluntarily — which changes who signs, and what an unmet expectation means.

Where this hands over: the expected credit loss figure a firm files is regulatory reporting work; the controls around a credit decision that need no model at all are models & controls; and the pipeline that runs the model every day is AI & automation.

Seeing one

Worked models are shown by invitation, not published

Every one of them fits itself in the browser over a constructed population, so what you are looking at is arithmetic running rather than a screenshot of a result — and none of it is any firm’s data. Every enquiry is treated in confidence.