Calibrated to GCC central bank frameworks · CBUAE · SAMA · CBB · QCB · CBK · CBO
Model risk and the CBUAE Model Management Standards
What do the CBUAE Model Management Standards require a bank to build? The structural shifts in the Standards, data quality, model drift and independent validation, the model lifecycle, and how all of it applies to AI and machine learning models.
5 articles in this topic
Read in this order.
- 31 May 2026 CBUAE Model Management Standards — the structural shifts that get under-appreciated The CBUAE Model Management Standards, in force since late 2022, reshaped how UAE banks govern quantitative models. Most requirements are tractable. A small number of structural shifts — governance separation, third-party dependency, data ownership — is where the work sits.
- 4 Jun 2026 Data quality under CBUAE MMS — the six dimensions that get tested in supervision Under CBUAE MMS, the defensibility of any risk model depends on the data feeding it. The standard specifies six data quality dimensions and requires the data management function to be functionally separate from operational risk data. Where the largest gaps usually sit.
- 27 May 2026 Model drift and the case for independent validation Models degrade as portfolios evolve, macro relationships weaken, and policy changes accumulate. A model defensible two years ago can become indefensible without code changing. What drift looks like, why developer-led monitoring misses it, and what independent validation covers.
- 29 Oct 2026 Model risk management as a continuous discipline — beyond the validation cycle Many institutions treat MRM as a series of validation events. Between cycles, models operate without governance oversight. The CBUAE MMS requires something different: a lifecycle framework with continuous monitoring, tiered governance, and clear ownership throughout.
- 15 Oct 2026 Model risk management for AI and machine learning models: the explainability obligation under CBUAE MMS ML-based credit scoring carries real model risk. Under CBUAE MMS, algorithmic models require independent validation, but limited interpretability, feature drift and vendor opacity make that validation materially harder than for traditional scorecards.
Where this becomes work