Agentic artificial intelligence is shifting model risk management (MRM) from manual, task-based automation toward end-to-end (E2E) workflows.
Scaling Model Risk Management with Agentic AI
Financial institutions are facing mounting pressure to expand their validation functions. According to Carlos Diaz, associate partner at McKinsey & Co., the scope of models requiring oversight has grown significantly, moving beyond traditional risk models to include a wider array of business applications and analytical tools. This expansion, coupled with rising regulatory expectations and a mandate to manage costs, has pushed firms to seek more efficient validation methods.
While traditional automation has helped streamline repeatable tasks—such as gathering data or drafting initial reports—the integration of agentic AI offers a more comprehensive approach. Unlike static automation, which performs predefined scripts, agentic AI systems can autonomously navigate code libraries, propose testing strategies, and monitor compliance with internal standards.
The Five-Step Reimagined Workflow
McKinsey & Co. outlines a five-step process for integrating agentic AI into the model validation lifecycle:
- Configuration and Planning: Agents utilize standardized taxonomies to draft validation plans tailored to specific model requirements.
- Pipeline Execution: Once a validator approves the plan, agents retrieve necessary testing components and access business reports to enrich the analysis.
- Execution: AI systems perform standard tests and generate initial drafts of technical documentation, including data visualizations and text.
- Review and Quality Assurance: Agents assist in verifying that reports meet internal and regulatory compliance standards.
- Human Oversight: A qualified validator reviews the agent-generated output, providing the final expert judgment required for accountability.
Balancing Efficiency and Defense
The transition to AI-driven validation does not imply a reduction in headcount. Instead, experts suggest that it allows existing teams to focus on complex, high-value tasks rather than manual execution. Dorothee Ancira, head of internal validation at Santander UK, emphasized that the goal is to create capacity for validators to challenge assumptions more effectively and engage with the business context of the models.

Maintaining a robust "second line of defense" remains a priority. To prevent the risk of AI tools validating their own creations, institutions must implement diverse, independent systems. Ancira noted that validation functions must be configured to ensure that the agents used for development are distinct from those used for independent validation.
Regulatory and Operational Readiness
The shift toward agentic AI requires significant investment in human capital and infrastructure. Before deployment, these tools must undergo rigorous pre-development testing and continuous monitoring to ensure accuracy.
Upskilling staff is central to this transformation. As AI becomes embedded in the validation process, validators must become fluent in new technologies to supervise multi-agent systems. Because the human validator remains ultimately accountable for the final output, the integration of AI acts as a support layer rather than a replacement, ensuring that model risk management keeps pace with the increasing complexity of financial technology.
Worth a look