Read this if you are at a financial institution.
CECL signifies one of the biggest changes to accounting requirements financial institutions have seen in the modern banking environment. While there are many differences between the incurred loss method and the new current expected credit loss model, the new (or increased) reliance on vendors to produce the loss reserve calculation, host the underlying loan-level detail, and maintain other assumptions and data brings significant change—and risk—to many institutions.
With CECL now fully adopted by all remaining institutions in 2023, and that work currently under review, a theme is emerging across the nation: some financial institutions are placing a significant amount of responsibility in the hands of their vendors. Is it possible to rely on a vendor too much? What are some examples of vendor overreliance, and what might this mean for management and oversight of model risk?
Overreliance on a vendor may look something like this: Management receives vendor documentation and calculation results and does not perform any type of analysis to verify the outputs or further understand vendor-provided template documents that describe what the vendor is doing to create the calculation.
In this example, management is using the vendor’s model design, tools, and documentation without evidencing management’s review, analysis, and challenge. Standard vendor documentation may also lack institution-specific decisions or process steps needed to understand the methodology currently in practice. Without customization or analysis, the model may be open to increased risk. For each change in assumption or data, the next questions management could ask are “How far into the model does that trickle down?” and “Does it affect the end result?”
Interagency supervisory guidance for CECL
There are two important interagency supervisory guidance documents we recommend consulting related to understanding, addressing, and managing CECL model risk: Model Risk Management (FDIC’s FIL 22-2017, FRB’s SR 11-7, and OCC’s 2011-12) and the new Third-Party Risk Management guidance published in June 2023 (FDIC’s FIL-29-2023, FRB’s SR 23-4, and OCC Bulletin 2023-17). Since this article was first published, the regulatory guidance references have been updated to: FDIC’s FIL-15-2026, FRB’s SR 26-2, and OCC’s Bulletin 2026-13.
Within the new Third-Party Risk Management guidance, key sections related to vendor and risk management are “Due Diligence and Third-Party Selection,” “On-Going Monitoring,” and “Governance.” Within the interagency supervisory guidance on model risk management, it states, “Documentation of model development and validation should be sufficiently detailed so that parties unfamiliar with a model can understand how the model operates, its limitations, and its key assumptions. For cases in which a bank uses models from a vendor or other third party, it should ensure that appropriate documentation of the third-party approach is available so that the model can be appropriately validated.”1 “The design, theory and logic underlying the model should be well documented and generally supported by published research and sound industry practice.”2
“The data and other information used to develop a model are of critical importance; there should be rigorous assessment of data quality and relevance, and appropriate documentation. Developers should be able to demonstrate that such data and information are suitable for the model and that they are consistent with the theory behind the approach and with the chosen methodology.”3
The above guidance would include any decisions, elections, choices, or procedural steps that management has made to evolve the model to its current use.
Vendor management: Best practices
Here are some common areas in which vendor overreliance can occur. Review them to assess and improve your vendor management:
- Documentation. Review any vendor-provided documentation, noting differences in how the calculation process or elections were made at your institution, and update the document(s) accordingly. For example, model or data assumptions made at set-up, reasons why management made these choices, including the choice to accept any work or recommendations made by the vendor, or the explanation of any changes or updates management decided to implement.
- Peer groups. Although management may have selected the peer group with the vendor, institutions could be lacking enough testing around what peer information is being used within the model to be confident of its accuracy and completeness. Common tests include confirming the historical loss time period of peer data in use, reconciling the number of financial institutions included within the final peer group list to the peer group loss history included in the calculation, and making sure the loss rates used match underlying call report data, on a sample basis.
- Default settings. Identify and review default settings or values provided by the vendor or built into your calculation tool. Review documentation to ensure that management’s reasons for using them have been explained. Common examples include weightings for different economic scenarios, assumptions for missing maturity dates, defaulting a loss rate to a certain percentage, or weighting the use of peer and financial institution data.
- Remaining life. For institutions using the remaining life or average remaining life method, consider sample testing the calculation of your largest two portfolios to make sure the remaining life calculation is occurring as designed and consistent with acceptable methods.
- Outsourced calculation. Some institutions may be relying on an outside vendor to perform their institution’s allowance for credit losses (ACL) calculation. Interagency guidance reminds management they remain fully responsible and accountable for the process, elections, and outcome. As a result, management teams will be expected to demonstrate an understanding of how everything is working together. We recommend clear documentation of management’s review and testing to support their determination that the outcome is reasonable and accurate. Having controls, such as a reconciliation between the loan data to the core system or verifying the segment totals to the core information, could be beneficial.
CECL resources
Do you need a “source of truth document” that you can call your model document? Check out “Building the whole picture: CECL model documentation” to help get you started.
If you still need assistance or want to discuss any other pain point you might be experiencing, our team of experts is here to help you navigate the requirements as efficiently and effectively as possible. We provide CECL model validation and consulting services. Submit your CECL questions on our Ask the Advisor page or contact our CECL consulting team.
1MRM OCC 2011-12 pdf, pg. 21
2FDIC - Supervisory Guidance on Model Risk Management pg. 5
3FRB - Supervisory Guidance on Model Risk Management (SR letter 11-7 Attachment)