SR 11-7 frames model risk management around three pillars: robust model development, ongoing validation, and governance with clear accountability. For CS-204, the controls that gate production sit in the first two pillars.
An independent validation covering conceptual soundness, outcomes analysis, and monitoring design is required prior to deployment, performed by staff independent of model development. Development documentation must let a third party reproduce the model without recourse to the developers.
Because CS-204 informs consumer credit decisions, fair lending testing and a documented effective challenge record should be attached to the validation package. Your MRM policy also requires Tier-1 models to carry a board approved risk rating, which CS-204 currently lacks.
Summary
Bottom line: CS-204 cannot be promoted until independent validation is complete and a board approved Tier-1 rating is issued.
- check_circleIndependent validation is mandatory pre-production.
- check_circleReproducible development documentation must accompany the package.
- check_circleFair lending testing required for consumer-credit use.
- check_circleOpen blocker: no board approved risk rating on file.
Bullets
- SR 11-7 three-pillar framework
- Development, validation, governance
- Pre-production gates for CS-204
- Independent validation, reproducible documentation
- Consumer-credit considerations
- Fair lending testing, effective challenge
- Open blocker: Tier-1 board rating
Sign-off must come from a validation function that is independent of model development. Developers may support the exercise but cannot own the validation conclusion or the effective-challenge record.
Draft, updating as the run completes. Articles 9–15 map cleanly onto existing model-risk controls in most areas. Two obligations have no current internal control and are flagged below.
| EU AI Act obligation | Internal control | Status |
|---|---|---|
| Art. 9 · Risk management system | MRM-STD-01 model risk framework | Mapped |
| Art. 10 · Data and data governance | DATA-GOV-03 data quality and lineage | Mapped |
| Art. 11 · Technical documentation | CS-204 development record v4 | Mapped |
| Art. 12 · Record-keeping and logging | None | Gap |
| Art. 13 · Transparency to deployers | MODEL-CARD-02 disclosure pack | Mapped |
| Art. 14 · Human oversight | None | Gap |
| Art. 15 · Accuracy and robustness | MRM-STD-02 validation standard | Mapped |
Two gaps to close. Article 12 needs a defined automatic logging and retention control for the model's decisions, and Article 14 needs a documented human-oversight procedure for the credit-decisioning use of CS-204.
Summary
Bottom line: five of seven obligations under Articles 9 to 15 are already covered; two require new controls before deployment.
- check_circleMapped: risk management, data governance, documentation, transparency, accuracy.
- check_circleGap: Article 12 logging and retention control.
- check_circleGap: Article 14 human-oversight procedure.
Bullets
- Coverage of Articles 9 to 15
- Five obligations mapped to existing controls
- Gaps
- Art. 12 logging, Art. 14 human oversight
- Recommended next steps
- Draft two controls, re-run mapping
What's in the baseexpand_more
Casesexpand_more
Subscription updatesexpand_more
Agentsexpand_more
Recommendationsexpand_more
Nothing waiting
No recommendations, gaps, or conflicts need you right now. The agents keep watching, and new items will appear here.
The queue did not load
Something went wrong loading the curation queue. This is usually temporary. Retry, and if it persists, check the platform status.
Coverage heat map
Coverage matrix
Knowledge graph
Topic map
Validity landscape
Topographic
Coverage radar
Framed reading
account_treeInspect
Items
Update pipeline
DEV applies automatically on release. On UAT and PROD an available version waits for your review: the content changelog and the recombination impact show before anything commits.
Licensed packs
Consolidated knowledge bases
Peopleexpand_more
Vault visibilityexpand_more
Casesexpand_more3 open
Activity logexpand_more
Top queriesexpand_more
No sources match
No sources match the current search and filters. Clear them to see the full set, or add a source.
Sources did not load
The source list could not be loaded. This is usually temporary. Retry, and if it persists, check the platform status.
Recipe as coderecipe.yaml
scope: domain: Risk & Compliance dimensions: [geography, framework, time, sector, authority, topic] sources: - id: fed-sr-11-7 tier: T1 monitor: weekly - id: occ-mrm tier: T1 monitor: weekly collection: web: managed discovery intranet: managed crawler exclude: [/archive, opinion-blogs] governance: veracity_gate: 0.7 pii_detect: on_ingestion pii_default: redact pii_purposes: [kyc, onboarding] warrant: on_answer
Components
Version history
Promotion
Service health
Environments & knowledge bases
Risk & Compliance
expand_morePRODActivity
Answer pipeline
Workers
Markets & Treasury
expand_morePRODActivity
Answer pipeline
Workers
Risk & Compliance
UATActivity
Answer pipeline
Workers
Markets & Treasury
UATActivity
Answer pipeline
Workers
Sandbox
DEVActivity
Answer pipeline
Workers
Subscribed virtual experts
Update pipeline
The admin sees the technical envelope only: version, size, compatibility, and the schedule window. The content changelog is the steward's to review at apply time.
Upgrade application policy
Applying an expert upgrade promotes its recipe and content; the apply is preview-first and warranted, and runs through Migration. The base stays queryable while it applies. On UAT and PROD the admin stages availability and the steward applies after reviewing the content changelog.
Promotion pipeline
Recipe state by environment
Applying a recipe can trigger re-embedding or index migrations; those run as background jobs under Operations, and the base stays queryable while they run.
Migration history
Recipe as coderecipe.yaml
scope: domain: Risk & Compliance dimensions: [geography, framework, time, sector, authority, topic] sources: - id: fed-sr-11-7 tier: T1 monitor: weekly collection: web: managed discovery intranet: managed crawler exclude: [/archive, opinion-blogs] governance: veracity_gate: 0.7 pii_detect: on_ingestion warrant: on_answer
Components
Recipe per knowledge base
Charges this period
Circuit breakers
Autonomy & budgets
Agent tokens
Agent repository grants
Environments
Code repository & promotion keys
Promotion path
Backups & restore
Re-embedding
Migrations
Discovery plane
A one-way governed seam pushes policy outward and pulls only candidate finds back; ingestion in the knowledge plane decides what is accepted. The grounded-search provider sits behind the seam and is not exposed to tenants.
Per-user usage today
Query usage
Validity warrant production
Managed secrets
Warrant-signing key
Warrants are read-only here. The auditor verifies the chain and exports with selective disclosure. Each warrant is issued by the system at the moment of an answer, decision, or access, and cannot be altered after the fact.
Coverage by section
A gap is a disclosure the base cannot yet warrant. The auditor flags it as a case to the steward, who owns the fix. The auditor does not curate the evidence.
Conflict mapdownload
Open conflicts
Decay terraindownload
Validity over time
Decaying premises
The auditor reads the full trail across every role, the one place where the administrator's operations and the steward's curation are recorded side by side. Reading the trail does not grant access to the knowledge content itself.
Sample & working paperstuneMethod: risk-weightedeventPeriod: Q2 2026
Findings register
Assemble a package
Sealing hashes the bundle and signs it with the governance key. A regulator can verify the signature and chain without access to the live base.
Packages
Pack at a glance
Recent activity
Sources
Review queue
Reference databases
How-to guides
Cut a release
Release history
These figures are reported by the Corvair marketplace. The partner runs on its own tenancy and has no connection to any customer tenancy, so it never sees a subscriber's local content, queries, or audit trail.
Status vocabulary is shared across roles: published when a release reaches the marketplace, available when a subscriber's admin stages it for an environment, applied when their steward recombines it into the base.