PRA Supervisory Statement SS1/23 — Model Risk Management
UK Prudential Regulation Authority supervisory statement setting expectations for model risk management at banks, building societies, and PRA-designated investment firms. 5 principles covering model identification and classification, governance (board accountability, model risk committee, independent validation), model development and implementation (documentation, testing, performance monitoring), model use and ongoing monitoring, and risk mitigation and reporting. Effective 17 May 2024 with proportionate application.
Controls: 102
Total Mappings: 194
Publisher: Prudential Regulation Authority (PRA) Version: 2023 (effective 2024) AC (7) AT (3) AU (12) CA (6) CM (10) CP (5) IA (3) IR (3) MP (1) PE (3) PL (6) PM (12) PS (6) RA (4) SA (9) SC (3) SI (9)
AC Access Control
| Control | Name | PRA SS1/23 References |
|---|---|---|
| AC-01 | Policy and Procedures | P-IT.1 |
| AC-02 | Account Management | P2.4P-IT.1 |
| AC-03 | Access Enforcement | P3.3P3.6P-IT.1 |
| AC-05 | Separation of Duties | P2.2P2.4P4.1P-IT.1 |
| AC-06 | Least Privilege | P2.4P3.3P3.6P4.4P-IT.1 |
| AC-17 | Remote Access | P-IT.1 |
| AC-24 | Access Control Decisions | P-IT.1 |
AT Awareness and Training
AU Audit and Accountability
| Control | Name | PRA SS1/23 References |
|---|---|---|
| AU-01 | Policy and Procedures | P-IT.2 |
| AU-02 | Event Logging | P3.2P3.4P4.3P4.4P-IT.2 |
| AU-03 | Content of Audit Records | P3.2P4.3P4.4P-IT.2 |
| AU-05 | Response to Audit Logging Process Failures | P5.3 |
| AU-06 | Audit Record Review, Analysis, and Reporting | P3.4P3.6P4.5P5.2P-IT.2 |
| AU-07 | Audit Record Reduction and Report Generation | P-IT.2 |
| AU-08 | Time Stamps | P-IT.2 |
| AU-09 | Protection of Audit Information | P-IT.2 |
| AU-10 | Non-repudiation | P3.2P4.4P-IT.2 |
| AU-11 | Audit Record Retention | P5.5P-IT.2 |
| AU-12 | Audit Record Generation | P3.3P3.4P-IT.2 |
| AU-14 | Session Audit | P-IT.2 |
CA Security Assessment and Authorization
CM Configuration Management
| Control | Name | PRA SS1/23 References |
|---|---|---|
| CM-01 | Policy and Procedures | P3.1 |
| CM-02 | Baseline Configuration | P3.3P-IT.3 |
| CM-03 | Configuration Change Control | P3.3P3.4P4.4P5.5 |
| CM-04 | Impact Analyses | P3.3P3.4 |
| CM-05 | Access Restrictions for Change | P3.3P3.4 |
| CM-06 | Configuration Settings | P3.3P-IT.3 |
| CM-08 | System Component Inventory | P1.1P1.3P5.5P-IT.3 |
| CM-09 | Configuration Management Plan | P3.3P3.4 |
| CM-12 | Information Location | P1.1P3.2 |
| CM-13 | Data Action Mapping | P1.1P3.2 |
CP Contingency Planning
IA Identification and Authentication
IR Incident Response
MP Media Protection
| Control | Name | PRA SS1/23 References |
|---|---|---|
| MP-06 | Media Sanitization | P5.5 |
PE Physical and Environmental Protection
PL Planning
PM Program Management
| Control | Name | PRA SS1/23 References |
|---|---|---|
| PM-01 | Information Security Program Plan | P2.1P2.2P2.3 |
| PM-02 | Information Security Program Leadership Role | P2.1P2.2 |
| PM-03 | Information Security and Privacy Resources | P2.1 |
| PM-04 | Plan of Action and Milestones Process | P4.5 |
| PM-05 | System Inventory | P1.1 |
| PM-06 | Measures of Performance | P4.5P5.2 |
| PM-09 | Risk Management Strategy | P1.2P2.1P3.5P5.1P5.4 |
| PM-10 | Authorization Process | P2.2P2.3 |
| PM-11 | Mission and Business Process Definition | P1.2P1.3P3.6 |
| PM-13 | Security and Privacy Workforce | P2.1 |
| PM-14 | Testing, Training, and Monitoring | P2.3P4.1P5.2P5.3 |
| PM-29 | Risk Management Program Leadership Roles | P2.1 |
PS Personnel Security
RA Risk Assessment
SA System and Services Acquisition
| Control | Name | PRA SS1/23 References |
|---|---|---|
| SA-03 | System Development Life Cycle | P3.1P5.5 |
| SA-04 | Acquisition Process | P1.3 |
| SA-05 | System Documentation | P3.1P3.5 |
| SA-08 | Security and Privacy Engineering Principles | P3.1 |
| SA-10 | Developer Configuration Management | P3.1P3.3P3.4 |
| SA-11 | Developer Testing and Evaluation | P3.3P4.2P4.3 |
| SA-15 | Development Process, Standards, and Tools | P3.1P3.3 |
| SA-16 | Developer-provided Training | P3.3 |
| SA-17 | Developer Security and Privacy Architecture and Design | P3.1P3.5 |
SC System and Communications Protection
SI System and Information Integrity
| Control | Name | PRA SS1/23 References |
|---|---|---|
| SI-01 | Policy and Procedures | P3.2 |
| SI-04 | System Monitoring | P5.2P5.3 |
| SI-05 | Security Alerts, Advisories, and Directives | P5.3 |
| SI-06 | Security and Privacy Function Verification | P3.2P4.3P5.2 |
| SI-07 | Software, Firmware, and Information Integrity | P3.2P4.3 |
| SI-10 | Information Input Validation | P3.2P4.3 |
| SI-11 | Error Handling | P3.2 |
| SI-12 | Information Management and Retention | P3.2P5.5 |
| SI-15 | Information Output Filtering | P3.2 |