Your Thresholds Are a Model: How Prudential Model Risk Expectations Are Reaching Financial Crime Detection in 2026


Model risk management arrived in banking through the capital stack. The discipline grew up around credit risk models, market risk models, valuation models and stress testing, because those were the models whose failure showed up directly in regulatory capital and in the accounts. The apparatus that grew with it, an inventory, a tiering scheme, independent validation, ongoing performance monitoring and a named owner for every model, was designed with those uses in mind and staffed by people fluent in them.
Financial crime detection sat outside that apparatus for most of its history, largely by accident. Transaction monitoring was understood as a rules engine, screening as a matching algorithm, customer risk rating as a scorecard, and none of them looked like the quantitative objects the model risk policy described. The people who tuned them reported into compliance, the artefacts they produced were tuning papers rather than validation reports, and the second line function that challenged them was financial crime assurance.
That separation is closing. The Prudential Regulation Authority's principles for model risk management, set out in supervisory statement SS1/23, established an expectation that firms identify what they use as models, classify them by materiality, govern them through a defined lifecycle, validate them independently and monitor them in use. The wording of those principles is not confined to capital and valuation, and the supervisory direction of travel is that models used to make consequential decisions about customers and transactions fall within the same frame. This post sets out what that means for a monitoring estate, what is settled and what is not, and where the genuinely difficult questions sit.
What Is Changing
The first change is definitional, and it is the one most likely to catch institutions out. A model, under the principles, is a quantitative method that applies statistical, economic, financial or mathematical techniques to input data in order to produce an output used in decision making, and the framing extends to deterministic approaches where the risk is material. Read against that definition, a transaction monitoring scenario with a value threshold and a lookback period is a model. A screening algorithm with a fuzzy match tolerance is a model. A customer risk rating scorecard with weighted factors is a model. A machine learning alert triage or hibernation layer is unambiguously a model. Institutions that have been maintaining a model inventory containing forty capital and pricing models are discovering that a complete inventory contains several hundred entries, most of them in financial crime, and that nobody has ever owned them in the sense the policy means.
The second change is the standard of evidence. Financial crime tuning has historically been documented in a way that would not survive independent validation: a threshold set during an implementation years ago on the advice of a vendor, adjusted once after a supervisory finding, with the rationale living in an analyst's memory and a spreadsheet on a shared drive. Model risk expectations require the assumptions, the data used, the testing performed, the limitations identified and the approval to be documented and challengeable, and require that challenge to come from someone independent of the people who built it. Below the line testing and above the line testing are recognisable as validation activities, but they are usually performed by the same team that set the thresholds, which is precisely the arrangement the principles are designed to prevent.
The third change concerns vendor-supplied models, which is most of the estate. A bank running a purchased monitoring platform, a purchased screening engine and a purchased risk scoring model frequently cannot open any of them. The feature definitions are proprietary, the training data is the vendor's, and the documentation supplied is a product manual rather than a model development document. The principles do not exempt third party models; the expectation is that the firm understands the model well enough to use it responsibly, tests it on its own data, understands its limitations and monitors its performance in its own environment. That obligation cannot be discharged by a vendor's assurance letter, and the practical consequence is that model validation becomes a procurement requirement rather than an afterthought.
Timelines and What Is Still Uncertain
It is worth being precise about the status of each claim in this area, because the market is not. What is settled is that the PRA has published model risk management principles for banks covering identification and classification, governance, development and use, independent validation and risk mitigants, and that the definition of a model in those principles is broad rather than confined to capital and valuation. Also settled, in the sense of long-standing supervisory expectation rather than new instrument, is that financial crime systems must be calibrated to the firm's risk assessment, tested, and demonstrably effective, which is a theme in Financial Conduct Authority financial crime publications, in Joint Money Laundering Steering Group guidance and in Wolfsberg Group material on programme effectiveness.
What is guidance rather than rule is the detail of how validation should be performed for detection systems, where no supervisory text prescribes a method. What is direction of travel, observable in the questions supervisors are asking rather than in any published requirement, is the pulling of transaction monitoring, screening, fraud scoring and machine learning uplift models into the same inventory, tiering and validation regime as prudential models. What is speculation is anything about scope extension beyond the current perimeter, any prescribed frequency of revalidation for detection models, and any harmonised European position. Unresolved within all of that is whether a rules engine is a model at all, which sounds academic and is not: if a deterministic scenario set is in scope the validation burden multiplies, and if it is not, institutions have an incentive to keep detection deterministic and unexplained. The reasonable working assumption is that materiality rather than technique determines the answer. This post asserts no commencement or application dates, because none can be responsibly stated and institutions have been misled by confident timelines before. Separately, the treatment of financial crime systems under the European Union's artificial intelligence framework was covered in this series between 8 and 12 November 2027; the subject here is prudential model governance, a different regime with different drivers, and the two should not be conflated.
What It Means Operationally
The first operational consequence is inventory, and it is larger than it looks. Building a complete financial crime model inventory means cataloguing every scenario, every threshold set, every segmentation, every screening configuration, every risk rating scorecard and every analytical layer, then assigning each a tier based on the consequence of it failing. Tiering matters more than completeness: an institution that tiers honestly can concentrate independent validation on the twenty models that carry the risk, while an institution that tiers by convenience ends up either validating everything superficially or validating the wrong things thoroughly. Ownership is the harder part, because most of these objects have a maintainer and no owner, and the principles require a named individual accountable for the model's performance in use.
The second consequence is that undocumented calibration becomes a finding. Every threshold whose rationale cannot be reconstructed is now an unvalidated model parameter, and the honest remediation is not to invent a justification retrospectively but to re-derive the calibration on current data, document the derivation, and record the approval. That work is substantial in an estate that has accreted scenarios over a decade, and it produces an uncomfortable interim position in which the institution knows its documentation is inadequate and cannot fix it quickly. Supervisors respond considerably better to a tiered remediation plan with dates than to a defensive account of why the thresholds are probably fine.
The third consequence falls on people and organisational design. Model validation functions are staffed with quantitative specialists who understand credit and market risk and typically know very little about money laundering typologies, sanctions matching or fraud vectors. Financial crime teams understand the typologies and rarely have the statistical training to produce or withstand a validation. The arrangements that work pair a validator with a financial crime subject matter expert on every material model, the validation function owning the standard and the financial crime function owning the risk interpretation. Hand the estate wholly to model validation and you get technically competent reports that miss the point; leave it wholly with compliance and you get documents that do not meet the standard.
The fourth consequence is contractual and sits with procurement. If a purchased model must be validated, the institution needs contractual rights to the artefacts that make validation possible: feature and logic documentation to a defined standard, performance data by segment, notification and impact assessment when the vendor changes the model, the ability to test on its own data before deployment, and audit rights that can actually be exercised. Very little of this is in the standard paperwork, and it is far cheaper to negotiate at selection than at renewal. The same applies to outsourced arrangements in which labelling and alert disposition are performed outside the institution, because those labels are model inputs and their production is now part of the model's control environment.
Conclusion
The direction here is clear even though the destination is not. Institutions that make consequential decisions about customers using quantitative methods will be expected to know which methods they use, how material each one is, who owns it, whether it works, and who checked. That expectation was built for capital models and is being applied, unevenly and without a great deal of tailored guidance, to detection systems that were never designed to be validated. The friction is real, and complaining about it is not a strategy.
The practical advice is to start with the inventory and the tiering, because everything else depends on them, and to be honest in both. Concentrate independent validation where failure would matter, re-derive the calibrations that cannot be explained, pair quantitative validators with financial crime expertise rather than choosing between them, and put the model documentation and change notification rights into vendor contracts at the next renewal. None of that requires knowing when a formal expectation will crystallise. All of it costs materially more once it has.
Suggested Next Steps
Build a complete financial crime model inventory covering scenarios, thresholds, segmentations, screening configurations, risk rating scorecards and analytical layers, and tier each entry by the consequence of failure rather than by convenience.
Identify every calibration whose rationale cannot be reconstructed from documentation, and plan re-derivation on current data with recorded approval, sequenced by tier and with dates you can defend.
Establish paired validation teams in which a quantitative validator owns the standard and a financial crime specialist owns the risk interpretation, and separate both from the team that sets the thresholds.
Add model documentation, segment performance data, change notification and impact assessment, and pre-deployment testing rights to vendor contracts at the next renewal or selection, and treat outsourced alert labelling as part of the model control environment.
Sources: Prudential Regulation Authority supervisory statement SS1/23 on model risk management principles for banks; Financial Conduct Authority financial crime guide and thematic publications on transaction monitoring and sanctions systems and controls; Joint Money Laundering Steering Group guidance on monitoring and testing; Wolfsberg Group statements on effectiveness and on transaction monitoring; European Banking Authority guidelines on internal governance and on money laundering and terrorist financing risk factors; Basel Committee on Banking Supervision principles for effective risk data aggregation and risk reporting; Bank for International Settlements work on the use of artificial intelligence in supervision and regulation; Digital Operational Resilience Act requirements on third party arrangements; TrustSphere Risk Index, April 2026.
TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai



Comments