Hedge Fund

The Model Was Right, and Then the World Stopped Resembling Its Training Sample

Model risk is the possibility that a model is wrong, used wrongly, or trusted beyond what it can support. It is a recognised discipline in banking because ignoring it has repeatedly been expensive.

↩ Looking BackPart of the 2020 to 2026 retrospective, written in July 2026. The date below marks the 2025 events this piece revisits, not when it was published, so it draws on everything known through mid 2026.
Nathan Xiang·May 14, 2025

What Model Risk Means

Model risk is the risk of loss from decisions based on model outputs. It has three distinct sources, and treating them as one thing is itself a common failure.

The model may be fundamentally wrong, built on assumptions that do not hold. It may be correct but implemented with errors. Or it may be correct and correctly implemented but applied to a situation it was never designed for, which is the most frequent of the three.

Why Every Model Is Wrong Somewhere

A model is a simplification. It captures the relationships judged to matter and discards the rest, and that discarding is what makes it useful. The problem is that the discarded factors are only irrelevant under the conditions in which the model was developed.

The classic example is any model estimating correlation between assets from historical data. In normal periods, diversification works and correlations are moderate. In crises, correlations rise sharply as investors sell everything at once. A risk model calibrated on normal periods will systematically understate risk at precisely the moment risk matters, because the relationship it learned no longer holds.

Models fail together with the thing they are modelling. The conditions that make a model wrong are usually the same conditions that make being wrong expensive.

The Machine Learning Version

More flexible models make this sharper rather than safer. A model with enough parameters can fit historical data almost perfectly, including the noise, which is overfitting. It then performs badly on new data because it learned accidents of the sample rather than durable relationships.

These models also degrade quietly. A traditional model with explicit assumptions can be checked against those assumptions. A model that learned patterns without stating them gives no obvious signal when the patterns stop applying, which is called drift, and detecting it requires deliberate monitoring rather than waiting for complaints.

How the Discipline Responds

Banking regulators require formal model risk management, and the structure is worth knowing because it generalises well beyond finance.

ControlPurpose
Independent validationReviewed by people who did not build it
Documented limitationsStates where the model should not be used
Ongoing monitoringDetects drift before it causes losses
Model inventoryNobody can protect a model nobody knows exists

Independent validation is the load bearing control. The people who built a model are poorly placed to find its flaws, having already convinced themselves. Review by a separate team with authority to reject is what makes the process real rather than procedural.

The Failure That Is Not Technical

The most consequential model failures are usually organisational rather than mathematical. A model produces a number, the number appears in a report, and everyone downstream treats it as a fact rather than an estimate carrying assumptions.

This is why documented limitations matter so much. The person deciding based on a model output is frequently several steps removed from anyone who understands what it assumes, and by then the uncertainty has been stripped away and only the figure remains.

Incentives make it worse. When a model produces favourable results, such as lower capital requirements or higher valuations, the pressure to question it is weak and the pressure to accept it is strong.

What Reasonable Use Looks Like

The practical posture is to treat a model as an argument rather than an answer. Know which assumptions it depends on, test how much the output moves when they change, and pay particular attention to results that are surprisingly favourable, since those are the ones least likely to be examined.

Simplicity has real value here. A simpler model that is understood is frequently safer than a more accurate one that is not, because someone can tell when it stops applying.

The Bottom Line

Model risk is not about arithmetic errors. It is about applying a simplification outside the conditions where the simplification held, and doing so with confidence because the output arrived as a precise number. The defence is knowing the limitations, having them checked by someone independent, and treating a surprisingly good result as a reason for scrutiny rather than celebration.

Explore Teen Biz News →