A risk model is only good if it can be refuted. In risk management, it is often demanded that models be “adequate.” For internal audit, supervision, and governance, however, a more precise question arises: how can this adequacy be concretely verified? A risk model is not robust simply because it sounds plausible, is formally documented, or is accepted by experts. It is robust when it is already traceable today which assumptions were made, which risk drivers were selected, how these relate to one another, and how the model's parameters were methodically derived. This explicitly includes that figures, distributions, and dependencies rest on traceable sources, data, or well-founded procedures, and not on implicit or unverifiable stipulations. In this context, capability of being validated does not mean forecast accuracy alone. It means that a model can be examined in a differentiated way. That covers the selection of risk drivers, their representation, the assumed causal relationships, and the concrete parametrization. Such a model is not globally “right” or “wrong”; instead, it allows targeted, expert-level review of individual elements, and thus precise refinement wherever assumptions, data, or relationships do not hold up. This point is central, particularly from an audit perspective. Models that work exclusively with aggregated assessments, implicit assumptions, or untraceable expert judgments evade any meaningful review. They deliver results, but no differentiated justification. Learning processes therefore inevitably stay blurred. Quantitative risk models create a different quality here. They make it possible to check assumptions, drivers, relationships, and parameters separately at every level, to analyze deviations in a targeted way, and to develop models further step by step. This capacity for further development does not arise in the abstract but very concretely, from the fact that individual model components can be reviewed, adjusted, and improved without having to call the entire model into question at once. For audit and governance, this creates clear added value: risk models become verifiable, transparent, and capable of targeted further development, because they can be systematically reviewed and improved at the expert level. A risk model that can be refuted is thus a sign of strength: the precondition for risk management to be capable of learning, connectable, and audit-proof.

This post was originally published on LinkedIn. View and join the discussion there