Models now make decisions that people used to make. Who gets credit, and at what price. Which applications get flagged. Which claims get paid without a human ever reading them. Which transactions get blocked.
Machine learning libraries, vendor decisioning platforms and generative AI have collapsed the cost of production. The cost of verification has not moved. In a large bank, establishing whether a model still works belongs to a model risk team. In most other financial services firms, it belongs to nobody.
Regulators have noticed, and they are not moving in one direction. In April 2026 the US banking agencies replaced SR 11-7 with a lighter, risk-based framework and placed generative and agentic AI explicitly outside its scope. Two weeks later APRA wrote to every bank, insurer and superannuation trustee it regulates and said close to the opposite: governance is lagging adoption, point-in-time assurance is not keeping up with systems that drift, and risk and internal audit functions must be capable of independently reviewing AI.
If your firm is not APRA-regulated, none of that binds you directly. It reaches you anyway. Warehouse funders are APRA-regulated banks, and APRA now expects them to see through their supply chains. Auditors ask who validated the provisioning model. Boards ask who checked the pricing engine, because directors' duties do not have a technology carve-out. The question always arrives from outside, and it is always the same question: who reviewed the model, and what did they find?
The methodology is published in full, because the methodology is not the secret. What an independent review adds is not the checklist. It is the independence.