A
AcadiFi
GO
GovernanceMira2026-05-20
ciaCIA Part 2GovernanceWorkpaper Evidence

What evidence supports model risk governance in an audit file?

46 upvotes
AcadiFi TeamVerified Expert
AcadiFi Certified Professional

Good evidence shows that model risk decisions were assigned, reviewed, approved, monitored, and escalated. Examples include the model risk policy, model inventory, risk-tiering rationale, validation report, approval minutes, limitation notices, monitoring reports, threshold breach logs, change tickets, and issue remediation records.

The auditor should also connect governance evidence to actual use. For example, if a model was approved only for new consumer loans, internal audit should test whether the business also used the score for renewals, collections, or cross-sell decisions.

Governance is not proved by a committee name alone. The audit file should show what criteria applied, what decision was made, what evidence supported it, who owned follow-up, and whether the model stayed within approved use.

🔍

Master CIA Part 2 with our CIA Course

45 lessons · 90+ hours· Expert instruction

#model-governance#audit-evidence#committee-approval#issue-remediation