The MESA MRM Framework: A Six-Step Model Risk Management Discipline for AI Systems

An institution that runs models can usually say which of them work. It is much less often able to say who decided that they work, on what evidence, for what use, and until when. The second set of facts is the one a supervisor, a board or an incident review asks for. Model risk machinery built for analytic rigour tends not to produce it, because it was built to reach a verdict rather than to record a permission. This specification defines a six-step model risk management discipline for AI systems: inventory, pre-validation, independent validation, approval, monitoring and revalidation, in that order. Each step carries entry conditions naming the framework that supplies them, one accountable role, a defined return path, and one evidence artifact. It rests on a single principle, and the principle is why the steps are ordered as they are. A validation is not a property of the model. It is a bounded permission, held by the institution, over a stated use, for a stated period. A validated model has not acquired an attribute it carries into any future use; it has been granted a permission whose boundaries were written down, and everything after step three tests whether those boundaries still hold. Two accountable loci are named, and the separation between them is the framework's structural claim. The head of model risk is accountable for the discipline across all six steps. A named approving executive is accountable for one permission at step four. The one arrangement the framework forbids is the same individual holding both roles for the same model. It is entry REG-02 of the Defensible AI Framework Registry, and with this record every registry entry that was marked source-treatment now has a standalone specification. Annex A is informative and it dates. It crosswalks the six steps to two supervisory instruments, one of which is not yet in force. A crosswalk is a reading of two documents at a moment and both documents change, so the annex states its own verification date and states the institution's obligation to re-verify against the primary sources in force where it operates. It creates no obligation on either supervisor and no presumption in the institution's favour. What has not been tested is stated rather than implied. No institution unconnected to the author has been observed operating the six steps, and Sections 2 through 7 are architectural claims. The central claim is untested and the comparison is not obvious: the framework asserts that separating the two accountable loci changes the outcome relative to a discipline where one person holds both, that has not been measured, and the alternative is not a straw man, because a single strong head of model risk with unquestioned authority to refuse may refuse more often than a separated pair in which each assumes the other is holding the line. It is also calibrated to institutions that can staff it — at least five appointments, three outside the team that builds the model — and it does not say which compressions preserve its properties. It is a specification, not a certification scheme, and no conformity assessment body operates against it.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-15
DOI
https://doi.org/10.5281/zenodo.22285046
Primary Topic
Ethics and Social Impacts of AI
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

The MESA MRM Framework: A Six-Step Model Risk Management Discipline for AI Systems

Nabeel A. Khan
Zenodo (CERN European Organization for Nuclear Research)
Ethics and Social Impacts of AI
article

The MESA MRM Framework: A Six-Step Model Risk Management Discipline for AI Systems

Nabeel A. Khan
article en

Abstract

An institution that runs models can usually say which of them work. It is much less often able to say who decided that they work, on what evidence, for what use, and until when. The second set of facts is the one a supervisor, a board or an incident review asks for. Model risk machinery built for analytic rigour tends not to produce it, because it was built to reach a verdict rather than to record a permission. This specification defines a six-step model risk management discipline for AI systems: inventory, pre-validation, independent validation, approval, monitoring and revalidation, in that order. Each step carries entry conditions naming the framework that supplies them, one accountable role, a defined return path, and one evidence artifact. It rests on a single principle, and the principle is why the steps are ordered as they are. A validation is not a property of the model. It is a bounded permission, held by the institution, over a stated use, for a stated period. A validated model has not acquired an attribute it carries into any future use; it has been granted a permission whose boundaries were written down, and everything after step three tests whether those boundaries still hold. Two accountable loci are named, and the separation between them is the framework's structural claim. The head of model risk is accountable for the discipline across all six steps. A named approving executive is accountable for one permission at step four. The one arrangement the framework forbids is the same individual holding both roles for the same model. It is entry REG-02 of the Defensible AI Framework Registry, and with this record every registry entry that was marked source-treatment now has a standalone specification. Annex A is informative and it dates. It crosswalks the six steps to two supervisory instruments, one of which is not yet in force. A crosswalk is a reading of two documents at a moment and both documents change, so the annex states its own verification date and states the institution's obligation to re-verify against the primary sources in force where it operates. It creates no obligation on either supervisor and no presumption in the institution's favour. What has not been tested is stated rather than implied. No institution unconnected to the author has been observed operating the six steps, and Sections 2 through 7 are architectural claims. The central claim is untested and the comparison is not obvious: the framework asserts that separating the two accountable loci changes the outcome relative to a discipline where one person holds both, that has not been measured, and the alternative is not a straw man, because a single strong head of model risk with unquestioned authority to refuse may refuse more often than a separated pair in which each assumes the other is holding the line. It is also calibrated to institutions that can staff it — at least five appointments, three outside the team that builds the model — and it does not say which compressions preserve its properties. It is a specification, not a certification scheme, and no conformity assessment body operates against it.

Zenodo (CERN European Organization for Nuclear Research)
Instituto Superior Manuel Teixeira Gomes (PT)
Peace, Justice and strong institutions
Openalex Percentile: Top 7%
Ethics and Social Impacts of AI
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.