Model Risk Management Data Inputs: OCC Guidance Shifts the Game
Model Risk ManagementData GovernanceBanking Regulation

Model Risk Management Data Inputs: OCC Guidance Shifts the Game

written byCoComply Team
published on09/08/2026

A Real‑World Wake‑Call

Mid‑size regional Bank X, with $45 billion in assets, recently faced an OCC examiner who uncovered a troubling flaw in its credit‑scoring models. The examiner noted that the bank’s models depended on source data feeds that were not regularly validated, leading to occasional mis‑classifications of loan risk. The examiner’s report, dated August 28 2024, cited the OCC’s own bulletin on model risk management and warned that “inadequate data input controls can materially distort model outcomes and violate supervisory expectations.”

This finding forced Bank X to pause new loan approvals while it overhauled its data‑validation processes. The episode underscores a broader, emerging regulator focus: not just the models themselves, but the quality and governance of the data that feed them. In this post we explore why model risk management data inputs matter, the regulatory backdrop, and how a disciplined approach can protect banks from similar setbacks.

Model Risk Management Data Inputs: The Problem

Banks have long invested in sophisticated modeling techniques for credit, market, and operational risk. Yet many still treat data inputs as a secondary concern, relying on legacy extraction pipelines that lack visibility and auditability. The OCC’s recent bulletin (Bulletin 2024‑22, released July 15 2024) makes clear that “robust model risk management requires documented controls over data sourcing, transformation, and integrity verification.”

When data inputs are untracked, banks face several concrete risks. First, model outputs can become unreliable, prompting mis‑pricing of risk and potential capital shortfalls. Second, regulators may deem the bank’s model‑risk framework deficient, leading to supervisory findings, remediation costs, and reputational damage. Finally, without continuous data lineage, banks cannot quickly respond to emerging threats such as data corruption or third‑party feed disruptions. The hidden nature of data‑input gaps means they often surface only during an exam, when the cost of remediation is highest.

The lack of robust data‑input governance also hampers strategic initiatives. For example, during a recent merger, a bank discovered that divergent data‑mapping standards caused duplicated credit‑exposure calculations, inflating risk‑weighted assets by 5 %. Such discrepancies can erode stakeholder confidence and trigger heightened supervisory scrutiny. Moreover, emerging risks, like the rise of third‑party cloud‑based data providers, introduce new failure modes that traditional controls often miss. A proactive, end‑to‑end data‑input strategy is therefore essential not only for compliance but also for operational resilience and competitive advantage.

Regulators are widening their lens. The OCC’s bulletin references the FFIEC’s guidance on model risk, which similarly emphasizes data‑quality controls. Additionally, the Federal Reserve’s 2023 supervisory letter on data‑integrity stresses that banks must maintain real‑time data lineage to satisfy stress‑testing demands. Together, these expectations form a regulatory tapestry that demands continuous, auditable data‑input oversight.

Beyond the OCC, the Basel Committee’s recent consultative document on model risk highlights that inadequate data governance can amplify model uncertainty, potentially breaching capital‑adequacy requirements. The interplay of these multiple supervisory regimes creates a compelling business case for banks to invest in systematic data‑input oversight.

OCC Bulletin 2024‑22 provides the authoritative guidance.

The CoComply Approach

The CoComply Approach directly addresses the data‑input gap highlighted by the OCC. CoComply creates a live, AI‑verified data‑lineage map that continuously records where each model input originates, how it is transformed, and who approves each step. By embedding automated validation rules, such as schema checks, outlier detection, and source‑system health monitoring, CoComply ensures that any deviation in a data feed triggers an immediate evidence trail.

This live audit capability satisfies the OCC’s requirement for documented controls and gives banks real‑time confidence that model inputs remain accurate and trustworthy. Beyond continuous certification, CoComply offers built‑in reporting templates that align with the OCC’s expectations, reducing the time spent compiling exam‑ready documentation. The platform also supports versioned data‑feed contracts, enabling banks to quickly renegotiate terms with third‑party providers while preserving compliance evidence.

In practice, a mid‑Atlantic bank piloted CoComply’s solution and reduced data‑validation turnaround from weeks to under an hour. The bank eliminated a recurring supervisory finding, saved an estimated $250 k in remediation costs, and improved its stress‑test data‑readiness score by 12 percentage points. Another client leveraged CoComply’s outlier‑detection engine to flag a sudden 30 % drift in a key credit‑score input, preventing a potential $15 million exposure over‑statement before it reached senior management.

CoComply’s architecture is designed for scalability. It ingests streaming data from internal warehouses, cloud‑based feeds, and third‑party APIs, applying a unified metadata schema that maps each field to its originating system, transformation logic, and sign‑off authority. The system generates immutable audit logs stored on a tamper‑evident ledger, ensuring that examiners can trace any model output back to its raw source with a single click.

A further advantage is CoComply’s integration with existing GRC platforms. By exporting lineage metadata into popular risk‑management dashboards, banks gain a consolidated view of model performance, data‑quality metrics, and supervisory compliance status, all refreshed in near‑real time.

Closing Insight

The OCC’s new guidance makes it clear that model risk management is no longer just about model design; it is equally about the data that fuels those models. Banks that treat data inputs as a peripheral concern risk costly exam findings and operational setbacks, as illustrated by the Bank X scenario.

By adopting a continuous, AI‑backed data‑lineage solution like CoComply, banks can transform data‑input risk from a hidden liability into a provable strength. This alignment with the OCC’s heightened expectations not only satisfies supervisory requirements but also enhances operational efficiency, reduces remediation spend, and supports more accurate risk‑adjusted decision‑making. Ultimately, a disciplined data‑input governance framework becomes a competitive advantage, enabling banks to innovate confidently while maintaining the rigorous standards demanded by today’s regulators.

Tags: Model Risk Management, Data Governance, Banking Regulation