A
AcadiFi
MO
ModelScopeNia2026-05-20
ciaCIA Part 2Model Risk ManagementEngagement Planning

How should internal audit scope a first-time model risk audit?

48 upvotes
AcadiFi TeamVerified Expert
AcadiFi Certified Professional

Start with the model universe, not with model math. Internal audit should understand what counts as a model, who owns the inventory, how models are risk-tiered, which models affect important decisions, and which criteria apply to development, validation, approval, monitoring, change control, and issue remediation.

For a first-time audit, a practical scope is to assess the design of the model risk management framework and then test a small sample of higher-risk models. The sample should connect policy requirements to evidence: inventory record, intended use, validation, approval, implementation, monitoring, exceptions, and remediation.

The CIA point is that internal audit owns assurance over governance and controls. It should use specialists where technical depth is needed, but it should not become the team that approves or operates the model.

🔍

Master CIA Part 2 with our CIA Course

45 lessons · 90+ hours· Expert instruction

#model-risk#audit-scope#model-inventory#risk-tiering