Loading site navigation and page content

Updated By Ernest Louw
The Central Bank of the UAE Model Management Standards are not limited to credit models or regulatory capital. They apply to all models used by licensed UAE banks to support decisions, including risk, pricing, valuation, forecasting, fraud, marketing and artificial intelligence models. The standards are in force and set minimum requirements for how those models are governed, developed, implemented, used, monitored and independently validated.
For banks, the practical question is no longer whether a model policy exists. It is whether the inventory is complete, model risk drives prioritisation, ownership is real, monitoring limits lead to action and an independent party can reproduce the evidence behind a decision.
The Model Management Standards, or MMS, apply to all licensed banks in the UAE, including Islamic banks. UAE branches and subsidiaries of foreign institutions must apply them at a minimum. More stringent requirements from a parent regulator should be applied where relevant on a model-by-model basis.
The scope covers statistical, deterministic and expert-based models. The CBUAE’s non-exhaustive list includes IFRS 9 models, rating and scorecard models, PD, LGD and EAD models, stress testing, valuation, pricing, IRRBB, liquidity, capital forecasting, budgeting, fraud, AML, marketing and artificial intelligence.
| Model area | Examples | Typical model-risk question |
|---|---|---|
| Credit and IFRS 9 | Ratings, scorecards, PD, LGD, EAD, ECL and macroeconomic models | Are data, calibration, forward-looking assumptions and overrides controlled and independently tested? |
| Market, valuation and ALM | VaR, xVA, exposure, pricing, NPV, EVE, NII and liquidity models | Are market data, methodology, implementation and sensitivity understood and monitored? |
| Capital and stress testing | Capital forecasting, concentration and regulatory or internal stress models | Do scenarios, dependencies and management actions remain credible under stress? |
| Business and financial planning | Budgeting, forecasting, profitability and marketing models | Are outputs used only for the approved purpose, with known limitations? |
| AI, fraud and AML | Artificial intelligence, alerting, classification and decision-support models | Can the bank explain the method, data, performance, bias controls, usage and human oversight? |
The MMS contains the minimum standards. In the CBUAE text, requirements expressed with “must” are mandatory, while “should” is strongly recommended. The accompanying Model Management Guidance, or MMG, expands on technical practice for specific model types. Alternative approaches to the MMG may be possible, but deviations should be justified and are subject to supervisory review.
A compliance review should therefore map each control to the exact MMS article and use the MMG to assess the quality of technical implementation. Treating the Guidance as optional background misses the CBUAE’s expectation that departures are reasoned and documented.
The CBUAE identifies seven components: model governance, data management, model development, model implementation, model usage, performance monitoring and independent validation. These are connected parts of one life cycle, not separate policy documents.
The bank must maintain a comprehensive framework for every model used in decision-making. The board remains ultimately accountable for appropriate model use and management. The Chief Risk Officer is responsible for ensuring that model risk is identified, measured, monitored, reported and mitigated across the institution, not only within the risk function.
A Model Oversight Committee must cover the full model population, remain separate from existing risk-management committees and meet at least quarterly. A majority of its members must not represent business lines. Material modelling decisions must be transparent, justified and documented, with ultimate board approval. The committee must decide whether a model remains in use, needs an adjustment, should be recalibrated or redeveloped, or should be withdrawn.
Each model needs an internal owner with enough seniority to be accountable for its decisions and life-cycle steps. A consultant can perform work, but cannot become the accountable owner.
The model inventory is the control centre of the framework. It must include internal and third-party models, models currently in production and archived models previously used after implementation of the MMS. Each model needs a unique identifier and references to the evidence for every life-cycle stage.
Models must be grouped by model risk, which the MMS defines as the combination of model materiality and the uncertainty surrounding the results. At a minimum, banks must use Tier 1 and Tier 2, with Tier 1 representing the more critical models. The bank can retain a more detailed internal scale, but models below Tier 2 are treated as Tier 2 for regulatory purposes. IFRS 9 models for large portfolios and capital forecasting models must be Tier 1.
| Inventory field | Why it matters |
|---|---|
| Unique model ID, name and version | Prevents confusion between models, calibrations and implementations |
| Purpose, approved use and prohibited use | Defines the decisions the model can and cannot support |
| Owner, developer, validator, user and data owner | Makes accountability and independence visible |
| Tier, materiality and model uncertainty assessment | Supports the model-risk assessment that drives prioritisation, review depth and escalation |
| Methodology, data sources and system location | Connects design to implementation and production |
| Development, approval, monitoring and validation dates | Shows whether the life cycle is current |
| Limit breaches, findings and remediation | Connects model performance to action |
| Third-party involvement and contracts | Records external dependencies without outsourcing accountability |
The CBUAE describes accurate and representative historical data as the backbone of financial models. Banks need a formal data management framework with identified sources, regular collection, data-quality review, secure storage, controlled access and suitable systems.
The minimum quality checks include completeness, accuracy, consistency, timeliness, uniqueness and traceability. Data sets should have accountable owners, documented limitations and quality indicators. External data does not avoid these controls. The bank must show that external data is relevant and representative of its portfolio and business model.
Development must follow a documented, iterative process. Depending on model type, that process covers data preparation and exploration, transformation, sampling, methodology, construction, model selection, calibration, pre-implementation validation and impact analysis.
The most sophisticated method is not automatically the right method. The CBUAE expects methodology to be consistent, transparent and manageable. If a bank cannot implement, explain, monitor and validate a complex method, the complexity itself becomes a control problem.
Pre-implementation validation is independent from development and should test whether the model is fit for purpose, economically intuitive, technically sound and ready to support decisions. The depth should reflect materiality, with comprehensive review for Tier 1 models.
Implementation is a separate life-cycle stage. It requires project governance, specifications, roles, a rollback plan and user acceptance testing. The CBUAE requires at least two rounds of UAT, with test cases and results retained while the model remains in production. Successful UAT requires sign-off from all identified stakeholders, and the Model Oversight Committee must approve the test plan and results. The model must not be changed while UAT is in progress.
Spreadsheets are not recommended for material models used in regular decision-making. Where they are used, the bank needs logical construction, traceable formulae, controlled inputs, instructions, protection, consistency checks, maker-checker review and version control.
A good model can still create risk when it is used for the wrong decision. The approved use should identify users, frequency, inputs, output destinations, interpretation, limitations and override governance.
Input and output overrides are permitted within controls, but they must be documented, justified, approved and monitored. Models whose inputs or outputs are frequently and materially overridden must not be considered fit for purpose and must be recalibrated or replaced. Commercial disappointment is not a reason to ignore an approved model output.
Monitoring asks whether the model continues to perform as intended as the economy, market, portfolio and usage change. Each model needs relevant metrics, limits, reporting and escalation. Monitoring reports must be presented to the Model Oversight Committee at least quarterly, and reports containing limit breaches must be discussed.
Independent validation is broader. It must cover qualitative and quantitative review and end with a clear judgement on whether the model is suitable for decision-making. A descriptive review is not a validation. Findings should be graded by severity, tracked and linked to remediation.
Article 10.5 Table 2 gives strongly recommended upper review periods for common model types rather than universal mandatory maxima. A bank may justify a less frequent review, subject to CBUAE assessment. Models not listed in the table need a schedule appropriate to their nature and model risk. High-severity findings require immediate tactical action. Banks should aim to resolve them fully within six months, and the MMS sets an absolute maximum of 12 months. A high-severity finding that remains unresolved after six months must be reported to the board and CBUAE.
Using a vendor, group model or consultant does not transfer responsibility. The bank remains accountable for methodology, calibration, data, implementation, use and financial consequences. It must understand the contribution, assess whether the model is suitable for the UAE portfolio and retain enough internal skill to challenge it.
Where a third party provides the development methodology, subsequent validation must be performed by a different internal or external party. If a ready-calibrated external model is used because internal data is insufficient, the bank must demonstrate that the calibration is representative. Where sufficient internal data can be collected, external calibration must be temporary and the bank must begin collecting historical and future internal data immediately.
The MMS scope expressly includes artificial intelligence. Machine-learning systems fall within scope when they meet the MMS definition of a model and support decision-making. In practical terms, the standards provide no basis for exempting a model merely because its method is complex or described as a black box. It still needs an approved purpose, owner, inventory record, data controls, development evidence, implementation testing, monitored limits, override governance and independent validation.
As implementation practice, banks should also consider training and validation data, variable or feature selection, stability, explainability appropriate to the decision, bias or segmentation concerns, human review, change control and performance drift. These are sensible ways to meet the broader MMS expectations, but the Rulebook does not state them as separate AI-specific requirements. Control depth should reflect model risk and the consequences of the decision, not the novelty of the technology.
| Question | Evidence to retain |
|---|---|
| Is every decision-support model recorded? | Reconciled inventory covering internal, vendor, group, spreadsheet, expert and AI models |
| Is each model tiered by model risk? | Approved methodology covering model materiality, model uncertainty and the resulting tier rationale |
| Does each model have an accountable internal owner? | Named owner, role description, committee records and escalation path |
| Is approved usage clear? | Purpose, users, inputs, outputs, limitations and override policy |
| Can data be traced and reproduced? | Source map, data dictionary, quality reports, lineage and access controls |
| Is development independently challenged before use? | Development document, impact analysis and pre-implementation validation |
| Was implementation tested? | Specifications, rollback plan, two UAT rounds, sign-offs and production tests |
| Do monitoring limits lead to action? | Metric history, breaches, committee decisions and remediation |
| Is validation independent and complete? | Qualitative and quantitative validation with a clear conclusion |
| Are third-party and AI models governed to the same standard? | Contracts, knowledge transfer, local suitability, validation independence and retained internal expertise |
Lux supports model inventory and tiering exercises, model-risk framework design, independent validation, IFRS 9 model review, monitoring frameworks, remediation and governance for third-party and AI models. An engagement can cover the full framework or a defined model population.
For expected credit loss modelling and validation, see our IFRS 9 ECL services. Banks can also contact Lux for an independent MMS gap assessment or validation review.
The current source for requirements is the CBUAE Model Management Standards and Guidance in the official Rulebook. Banks should map their controls to the exact articles and confirm any subsequent CBUAE updates.
The MMS and MMG apply to all banks licensed by the CBUAE, including Islamic banks. UAE branches and subsidiaries of foreign institutions must apply them at a minimum, with more stringent parent-regulator requirements considered where relevant.
Artificial intelligence appears expressly within the non-exhaustive model scope. A machine-learning system is also in scope when it meets the MMS definition of a model and supports decision-making. It then requires ownership, inventory, data controls, documented development, implementation testing, controlled usage, monitoring and independent validation.
Banks must group models by model risk, which the MMS defines as the combination of model materiality and model uncertainty. Banks must use at least Tier 1 and Tier 2, with Tier 1 representing more critical models. The bank may use more internal tiers. IFRS 9 models for large portfolios and capital forecasting models must be classified as Tier 1.
No. Validation must remain independent from development. If a third party provides a methodology to develop a model, the subsequent validation must be performed by a different internal or external party.
Monitoring reports must be presented to the Model Oversight Committee at least quarterly. For validation and review, Article 10.5 Table 2 gives strongly recommended upper periods for common model types, not universal mandatory maxima. A less frequent review requires justification and is subject to CBUAE assessment. Models absent from the table need a schedule appropriate to their nature and model risk.
The MMS states that “must” requirements are mandatory and “should” requirements are strongly recommended. The MMG uses “should”. Alternative technical approaches may be considered, but deviations should be clearly justified and are subject to CBUAE supervisory review.
We combine global expertise with local on-the-ground presence to provide auditor-ready valuations and risk consulting. Explore our core services:
GCC insurers grew revenue and profit in H1 2026, but investment-led earnings, solvency deficits and accounting reclassifications reveal uneven capital resilience across the region.
Comparing actuarial consulting firms across Africa and the Middle East by team size, office footprint, service breadth, independence, resident workforce, qualifications, and multi-standard coverage. A framework for CFOs and Chief Actuaries evaluating external partners.
When hostilities between the US, Israel, and Iran escalated in late February, the fallout for pension funds landed much closer to home than the Strait of Hormuz.