AI Governance, Risk & Red Teaming
Proficient · M21 · lesson 21 of 31 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Model Risk Tiering, Inventory & Periodic Review Cadence: 2026 Playbook
📖
now learning

Model Risk Tiering, Inventory & Periodic Review Cadence: 2026 Playbook

15 min

The Acme Bank Chief Risk Officer arrived at the May 2026 board risk committee meeting with two slides ready and a list of seven AI systems she expected to discuss. The chair opened with a question that was not on the agenda: "How many AI systems are in production right now: across the bank, all subsidiaries, all jurisdictions?" The CRO answered the question that always works on day one of an AI program: "I'll get back to you next week." The chair did not smile. "The 2026 PRA Dear CEO letter says boards must demonstrate active oversight of the firm's AI portfolio. I'd like the number, the tiering, and the next-review-due-date for every Tier 1 model, by Friday. The internal-audit director is on the line and will be testing that number against shadow-IT scans on Monday." That conversation became Acme Bank's model-inventory crisis, and it is the conversation playing out in 2026 across every regulated firm that delayed its AI inventory beyond the EU AI Act August 2026 high-risk operative date. This lesson is the discipline that makes "I'll get back to you next week" obsolete: the four-tier model-risk tiering rubric, the 24-field inventory schema, the scheduled-and-trigger-based review cadence, the seven drift signals, the federated-inventory pattern that aligns ISO 42001 A.4 with EU AI Act Article 71 with CycloneDX 1.7 ML-BoM, and the cross-walk that makes a single inventory record satisfy SR 11-7, PRA SS1/23, NIST AI RMF, ISO 42001, and the EU AI Act simultaneously.

Tiering Rubric - Criticality, Consumer Impact, Autonomy, Reversibility, Four Tiers

Model-risk tiering is the gateway control. Without tiering, a firm cannot defensibly allocate validation budget, review cadence, or escalation thresholds. The 2026 tiering rubric that satisfies SR 11-7 risk-rating expectations, PRA SS1/23 risk-tiering principles, and EU AI Act risk-classification logic operates on four weighted dimensions and produces four tiers.

Dimension 1 - Criticality. Does the model materially affect a decision the bank is regulated for? A loan decision, an adverse-action letter, a credit-scoring output, an AML alert, a fraud-suppression decision, a capital-allocation input. These are criticality-high. A marketing-copy generator that produces draft copy a human approves before publication is criticality-low. Criticality is weighted at 35% of the composite score in the Acme rubric because it is the dimension most aligned with supervisor expectations on materiality.

Dimension 2 - Consumer impact. Does the model directly affect a natural person's access to credit, employment, housing, education, healthcare, or essential services. I.e., does it trigger EU AI Act Annex III high-risk classification or US ECOA / FCRA / Title VII / ADA exposure? Consumer impact is weighted at 30% because it directly correlates with Article 27 FRIA obligations, Charter Article 21 non-discrimination exposure, and fundamental-rights penalty escalation under Article 99(3). A model with consumer impact crosses into mandatory-Article-27-FRIA territory; one without consumer impact is governed by lighter-touch controls.

Dimension 3 - Autonomy. Does the system act on its own (Tier 3 ACT or Tier 4 AUTONOMOUS per lesson 049) or only suggest (Tier 1 SUGGEST or Tier 2 CONFIRM)? Autonomy is weighted at 20% because agentic blast-radius is a 2026 supervisory focus area: OWASP Agentic Top 10 + MITRE ATLAS techniques apply, kill-switch design is required, and the audit committee is expected to know how many agents are operating above Tier 2. An agent that books appointments, sends emails, or makes API calls under its own authority carries autonomy-high weight; a copilot that drafts and asks a human to send carries autonomy-low.

Dimension 4 - Reversibility. How hard is it to undo an erroneous output? An adverse-action letter sent to a customer is reversible (the bank can recall and re-issue). A funds-transfer initiated by an agent is partially reversible (only if discovered within the recall window). An AML SAR filed with the regulator is irreversible (the filing is a regulatory submission). Reversibility is weighted at 15% because it determines how much pre-deployment validation must absorb (irreversible actions cannot rely on post-action correction) and whether human-in-the-loop is mandatory rather than optional.

The four tiers. Composite scores out of 100 map to four tiers. Tier 1 (score 75-100), highest scrutiny. Annex III high-risk classification, direct consumer impact, agentic or partially agentic, irreversible or hard-to-reverse outputs. Full Model Risk Management discipline applies: Independent Model Validation (IMV per lesson 068), Article 27 Fundamental Rights Impact Assessment, Article 11 + Annex IV technical documentation, Article 71 EU database registration where deployer-registration is required, Article 9 risk management throughout lifecycle, quarterly review with explicit CRO sign-off, mandatory pre-deployment 2L approval, mandatory event-based re-validation on substantial modification. Tier 2 (score 50-74), high-risk or material business risk without all Tier 1 dimensions present. IMV required pre-deployment, annual review baseline, trigger-based re-validation, system card + model card + monitoring KPIs, but lighter on the FRIA/registration overhead if not in Annex III. Tier 3 (score 25-49): medium-risk supportive AI such as internal coding assistants, summarisation tools, knowledge-base search. Lightweight validation (1L self-assessment + 2L spot-check sampling), biannual review, model card + monitoring KPIs, no mandatory FRIA. Tier 4 (score 0-24): low-risk productivity tools: text-rephrasing, calendar-suggestion, draft-meeting-notes. Policy compliance + annual attestation by the model owner; no MRM resource allocation beyond inventory presence.

Worked sample scores. The Acme tiering scorecard applied to five real-world examples. (1) Hiring AI: Criticality 90, Consumer Impact 100, Autonomy 30 (Tier 1 SUGGEST with human decision), Reversibility 60 (rejection can be reconsidered if challenged). Composite: 90×0.35 + 100×0.30 + 30×0.20 + 60×0.15 = 31.5 + 30 + 6 + 9 = 76.5 → Tier 1. (2) Credit-scoring agent: Criticality 95, Consumer Impact 100, Autonomy 75 (Tier 3 ACT with bounded budget), Reversibility 40 (declines hard to reverse). Composite: 33.25 + 30 + 15 + 6 = 84.25 → Tier 1. (3) Customer-service chatbot handling ECOA-related queries: Criticality 60, Consumer Impact 70, Autonomy 30 (Tier 1-2 with human escalation), Reversibility 70 (responses correctable). Composite: 21 + 21 + 6 + 10.5 = 58.5 → Tier 2. (4) Internal coding assistant bank-wide: Criticality 30 (productivity), Consumer Impact 10 (no direct consumer touch), Autonomy 20 (suggestions only), Reversibility 90 (developer reviews). Composite: 10.5 + 3 + 4 + 13.5 = 31 → Tier 3. (5) GitHub Copilot org-wide enterprise rollout: Criticality 25, Consumer Impact 5, Autonomy 15, Reversibility 95. Composite: 8.75 + 1.5 + 3 + 14.25 = 27.5 → Tier 3 (just above the Tier 4 boundary because of license-scope risk and IP-bleed considerations). A pure text-rephrasing tool would score below 25 and fall into Tier 4.

The tiering committee. Acme operates a monthly tiering committee chaired by the Director of MRM with attendance from the Chief AI Officer, the Chief Compliance Officer, the DPO, and a legal partner. Every new AI system proposed for deployment is tiered by the committee using the four-dimension scorecard. The committee's tiering decision is the gateway: Tier 1 requires CRO sign-off before validation begins; Tier 2 requires Director-of-MRM sign-off; Tier 3 and Tier 4 require Manager-level sign-off. The tiering decision is recorded in the inventory entry and is itself subject to challenge: if a 1L disputes a Tier 1 designation, escalation to the CRO is the path. Tiering is reviewed annually for in-production systems and triggered for re-tiering on substantial modification (a Tier 3 system that adds agentic capability may need re-tiering to Tier 2 or Tier 1).

The 24-Field Model Inventory Schema - Federated Source of Truth

The inventory is the bank's answer to the board chair's question. The 2026 schema has 24 fields because the regulator-readiness drill requires answers across four overlapping regimes (EU AI Act, NIST RMF, ISO 42001, SR 11-7) in a single record. Acme's schema, drawn from ISO 42001 A.4 (resources management) requirements and EU AI Act Article 71 + Article 72 + Article 11 documentation expectations, is the de-facto 2026 industry pattern.

The 24 fields. (1) system_id: unique stable identifier, never reused, used across all artefacts (model card, FRIA, validation report, incident log). (2) business_owner, named accountable executive in the business line. (3) model_owner_first_line, 1L technical owner accountable for build and first-line monitoring. (4) mrm_validator_second_line, 2L validator name (or "pending" pre-validation). (5) tier, Tier 1/2/3/4 per the scorecard above, with composite score recorded. (6) annex_iii_category, which EU AI Act Annex III category applies (or "not high-risk"). (7) provider_vs_deployer_status, provider / deployer / both, with rationale. (8) article_25_status, 25(1)(a) substantial-modification, 25(1)(b) high-risk repurposing, 25(1)(c) own-name placement, or "n/a", the field that captures provider-flip exposure. (9) base_model + version: vendor, model family, specific version, deployment endpoint (cloud or self-hosted). (10) fine_tune_dataset_ref, pointer to the data lineage record for any fine-tune. (11) system_prompt_version, git hash of the current production system prompt with link to change history. (12) rag_corpus_ref, pointer to the RAG corpus catalogue with version + last-refresh date. (13) embedding_model, vendor + version + dimensionality of the embedding model used in retrieval. (14) tools_list, enumeration of tools and functions with sensitivity tier (R / W-B / W-Br / R-X) per lesson 049. (15) memory_layer_y/n, yes/no with pointer to memory schema if yes. (16) autonomy_tier, Tier 1 SUGGEST / Tier 2 CONFIRM / Tier 3 ACT / Tier 4 AUTONOMOUS per lesson 049. (17) fria_filed_y/n + ref, yes/no with reference to the Article 27 FRIA filing for high-risk systems with consumer impact. (18) annex_iv_doc_ref, pointer to the Article 11 + Annex IV technical documentation package (mandatory for providers of high-risk; cross-walked for deployers). (19) ce_marking_status, for providers: applied / pending / not applicable. (20) iso_42001_in_scope, yes/no with pointer to the AIMS scope statement entry. (21) last_imv_date, date of last Independent Model Validation report, with link to the report. (22) next_review_due, scheduled next review per the tier cadence rules, with link to the calendar entry. (23) incident_log_ref: pointer to the Article 73 incident-log entries linked to this system (zero, one, or many). (24) retire_or_substantial_modification_status, active / retired / pending substantial modification / under review, the field that captures lifecycle state.

Federated inventory pattern. The 2026 reality is that no single tool holds all 24 fields. The federated pattern lets four sources of truth synchronise into one inventory view. Source 1, Model card as source of truth for technical fields (9, 10, 11, 12, 13, 14, 15, 16, 18), the model card is published in a model-registry tool (Weights & Biases Registry, MLflow Model Registry, Hugging Face Hub, an internal equivalent), git-versioned, hash-pinned, and read into the inventory dashboard. Source 2 - CycloneDX 1.7 ML-BoM for component bill-of-materials evidence: the ML-BoM enumerates base model, fine-tune data, embedding model, RAG corpus version, dependencies, and licenses; it is generated automatically from CI/CD and feeds fields 9, 10, 12, 13. Source 3 - ISO 42001 A.4 AIMS register for organisational governance fields (1, 2, 3, 4, 5, 6, 7, 8, 17, 20, 24): the AIMS register lives in the GRC platform and is the authoritative source for ownership, tiering, Annex III mapping, provider/deployer status, and lifecycle state. Source 4, Tickets-of-substantial-modification (Article 43) + incident log (Article 73) for change and incident fields (21, 22, 23), these tickets live in the change-management and incident-response systems respectively. The inventory dashboard reads from all four sources, federates the view, and runs a daily consistency check. Discrepancy = audit finding by definition.

Article 71 EU database registration as inventory-of-record. For high-risk AI systems that the EU AI Act requires to be registered in the EU database under Article 71, the database entry is the public-facing version of the inventory record. A subset of the 24 fields (system_id, provider/deployer status, Annex III category, intended purpose, instructions for use, deployer member-state details) is filed; the internal inventory carries the full set. The inventory record's system_id is the same as the Article 71 registration ID, making the inventory the bridge between internal MRM and the public EU register.

Discovery and shadow AI. A 2026 inventory that captures only IT-approved AI systems is incomplete. The discovery layer scans (a) network egress for known LLM API endpoints (api.openai.com, api.anthropic.com, gemini.googleapis.com, and equivalents) per cost-centre tag, (b) browser-extension and IDE-plugin manifests for AI-assistant install patterns, (c) SaaS-vendor invoices for AI features turned on, and (d) source-code repositories for SDK imports. Discovered systems that are not in the inventory are flagged for the 1L owner to either add to inventory (with tiering committee review) or retire. Acme's June 2026 discovery sweep added 23 previously-unknown AI systems to the inventory, 4 of which scored into Tier 2 and 1 into Tier 1, requiring backfill of pre-deployment validation.

Review Cadence - Scheduled, Trigger-Based, Annual Recertification, Seven Drift Signals

The review cadence is what turns the inventory from a static register into a living oversight discipline. Three drivers fire reviews; seven signals trigger event-based re-evaluation; one annual recertification cycle closes the loop.

Scheduled cadence per tier. Tier 1, quarterly review with explicit CRO sign-off on the residual-risk position. Tier 2, annual review with Director-of-MRM sign-off. Tier 3, biannual review (every two years) with Manager-of-MRM sign-off. Tier 4, annual attestation by the model owner (lightweight; no MRM review). The scheduled cadence is the calendar baseline; the next_review_due field on every inventory row drives the calendar.

Event-based triggers. Five trigger conditions fire a re-evaluation outside the scheduled cadence. (1) Substantial modification per Article 3(23) + Article 43(4), a change that affects compliance with the EU AI Act's high-risk requirements or alters the intended purpose. For a high-risk system, substantial modification re-opens conformity assessment. The change-management ticket flagged with "substantial modification" automatically fires a 2L review, a tiering committee re-tier decision if scope changed, and a re-validation cycle. (2) Material incident per Article 73, any serious-incident report under Article 73 (and equivalent regimes, SR 11-7 operational risk, PRA SS1/23 incident escalation) automatically fires a re-evaluation of the affected system. A Tier 2 system that produces a reportable incident may be re-tiered to Tier 1 pending root-cause completion. (3) Upstream model upgrade, when the underlying foundation-model vendor releases a new version (Claude 4 → Claude 4.5; GPT-5 → GPT-5.1; Gemini 2.5 → Gemini 3.0), every inventory row that references the upstream model fires a re-validation trigger because the underlying behaviour may have shifted materially. The vendor-version polling component of monitoring (weekly) is what catches this. (4) Regulator inquiry: any examination, supervisory letter, regulatory request for information, or peer-firm horizontal-review finding that touches a class of system triggers a same-class review across the inventory. The 2026 Fed horizontal review on LLM-as-judge contamination triggered Acme to review all six judge-using systems within four weeks. (5) Material drift detected, any of the seven drift signals (next paragraph) crossing the alert threshold fires a review and (if the threshold remains crossed for the defined dwell-time) a re-validation.

Seven drift signals. (1) Input distribution drift, the production input distribution diverges from the validation input distribution (measured via Population Stability Index on input features or embedding-distance for unstructured inputs). PSI > 0.2 fires investigation; PSI > 0.3 fires re-validation. (2) Output distribution drift: the production output distribution shifts (length, sentiment, refusal pattern, structural format). Especially relevant for LLM outputs where the input may stay constant but the model upgrade or system-prompt change moves the output. (3) Performance drift: accuracy, hallucination rate (RAGAS Faithfulness drop), latency p95/p99 degradation. For a Tier 1 hiring AI, an accuracy drop of 2pp across protected classes fires a fairness investigation immediately. (4) Refusal-rate drift, the model starts refusing more (or fewer) queries than at validation. A jump in refusal-rate may indicate upstream guardrail changes (Anthropic's safety-classifier updates can shift refusal patterns), an injection campaign in production, or a prompt-engineering drift. (5) RAG-retrieval relevance drift, the relevance of retrieved documents drops measured via NDCG@k or human-labelled relevance sampling. RAG-retrieval drift often signals corpus drift (the corpus accumulated stale content) or embedding-model drift (the embedding model was updated). (6) User-feedback-loop drift, the user-feedback signals (thumbs-up/down, "Was this helpful?", correction-pattern frequency) shift outside historical bands. Useful as a fast-path leading indicator. (7) Fairness-slice drift, per-protected-class performance metrics diverge across slices, even if aggregate performance is stable. For Annex III consumer-impact systems, fairness-slice drift is a Tier 1 immediate-attention signal.

Annual recertification cycle. Each model owner re-attests their inventory entry every year on a rolling calendar (the system_id's quarter-of-year determines the attestation month, balancing 2L workload across the year). The attestation re-confirms each of the 24 fields is current, the system is still in scope, the next_review_due is correct, and any incidents or substantial modifications have been logged. The 2L audits a sample of attestations (10% in 2026 for Tier 1+2; 5% for Tier 3) for accuracy. The 3L (Internal Audit) audits the 2L's sampling process annually, a 3L finding that the 2L sampled too few Tier 1 attestations is the finding the audit committee will read first.

Worked Example - Acme Inc 2026 Inventory, 17 Entries, Five Deep Walks

Acme Inc operates 17 AI systems in production as of May 2026 after the June 2026 discovery sweep added 5 to the pre-sweep total of 12. The full inventory entries are stored in the AIMS register; five are deep-walked here to illustrate the schema across all four tiers.

Entry 1 - Acme.LoanDefaultOutreach v2.1 (Tier 1). Agentic loan-default outreach system. system_id = ACME-AI-007; business_owner = SVP Consumer Lending; model_owner = AI Engineering Director; mrm_validator = MRM Senior Validator (rotating); tier = 1 (composite 89); annex_iii_category = III.5(b) creditworthiness; provider_vs_deployer = deployer (uses Claude 4 + custom system prompt + RAG); article_25_status = n/a (no own-name placement, no high-risk repurposing); base_model = Claude 4 Opus v2026-03; system_prompt_version = git hash a3f2b91; rag_corpus_ref = hardship-program-catalogue v4.2 (last refresh 2026-05-01); embedding_model = voyage-3 dim 1024; tools = [tier R: customer-account-read; tier W-B: outreach-scheduler-create; tier R-X: hardship-program-enrol, restricted to Tier 2 CONFIRM only]; memory_layer = yes (conversation memory per outreach campaign, 90-day TTL); autonomy_tier = Tier 3 ACT for standard outreach within budget; fria_filed = yes ref FRIA-ACME-007-2026Q1; annex_iv_doc_ref = ANN-IV-ACME-007-v3; ce_marking = n/a (deployer not provider); iso_42001_in_scope = yes scope-entry SC-007; last_imv = 2026-04-15; next_review_due = 2026-07-15 (quarterly Tier 1 cadence); incident_log = INC-2026-04-22 (single moderate-severity false-positive cluster, root-caused, remediated); retire_status = active (substantial modification candidate Q3 2026 for adding agentic budget-renegotiation feature, pending FRIA refresh and IMV).

Entry 2 - Acme.HiringAI v1.4 (Tier 1). CV-screening AI for early-career hiring. system_id = ACME-AI-002; business_owner = Chief People Officer; model_owner = People Analytics Lead; mrm_validator = MRM Senior Validator; tier = 1 (composite 80); annex_iii_category = III.4(a) employment selection; provider_vs_deployer = deployer (uses GPT-5 with custom prompt + rubric-based scoring); article_25_status = n/a; base_model = GPT-5 v2026-02; system_prompt_version = git hash 7e1c4a8; rag_corpus_ref = n/a (no RAG); embedding_model = n/a; tools = [tier R: ats-search-by-id only]; memory_layer = no; autonomy_tier = Tier 1 SUGGEST (recruiter reviews every recommendation); fria_filed = yes ref FRIA-ACME-002-2026Q1; annex_iv_doc_ref = ANN-IV-ACME-002-v4; ce_marking = n/a; iso_42001 = yes SC-002; last_imv = 2026-02-10; next_review_due = 2026-05-10 (quarterly Tier 1); incident_log = empty; retire_status = active.

Entry 3 - Acme.ServiceAssist v1.0 (Tier 2). Customer-service chatbot for retail-banking general queries (no high-risk decisioning; escalates to human on regulated topics). system_id = ACME-AI-011; business_owner = SVP Customer Experience; model_owner = CX AI Lead; mrm_validator = MRM Validator; tier = 2 (composite 58.5); annex_iii_category = not high-risk (escalates on Annex III topics); provider_vs_deployer = deployer; article_25_status = n/a; base_model = Claude 4 Sonnet v2026-03; system_prompt_version = git hash 9b2e7f1; rag_corpus_ref = customer-faq-and-account-policies v8.3 (last refresh 2026-04-28); embedding_model = voyage-3 dim 1024; tools = [tier R: account-balance-read, transaction-history-read, branch-locator]; memory_layer = no; autonomy_tier = Tier 1 SUGGEST (response always shown; human escalation on triggers); fria_filed = n/a; annex_iv_doc_ref = lightweight tech-doc TD-011-v2; ce_marking = n/a; iso_42001 = yes SC-011; last_imv = 2026-01-20; next_review_due = 2027-01-20 (annual Tier 2); incident_log = empty; retire_status = active.

Entry 4 - Acme.CopilotInternal (Tier 3). Org-wide enterprise coding assistant for software engineers. system_id = ACME-AI-015; business_owner = CTO; model_owner = Developer Productivity Lead; mrm_validator = MRM Analyst (sampling-based); tier = 3 (composite 31); annex_iii_category = not high-risk; provider_vs_deployer = deployer (vendor-supplied Copilot Enterprise); article_25_status = n/a; base_model = GitHub Copilot v2026-Q2 (multi-model backend); system_prompt_version = vendor-managed; rag_corpus_ref = code-context from current repo only (no external knowledge base); embedding_model = vendor-internal; tools = [tier R: repo-read-current-file only, no write tools at IDE level]; memory_layer = no; autonomy_tier = Tier 1 SUGGEST (developer accepts/rejects suggestions); fria_filed = n/a; annex_iv_doc_ref = lightweight TD-015-v1; ce_marking = n/a; iso_42001 = yes SC-015; last_imv = 2026-03-01 (lightweight 2L spot-check); next_review_due = 2028-03-01 (biannual Tier 3); incident_log = empty; retire_status = active.

Entry 5 - Acme.MarketingCopyDraft (Tier 4). Marketing-copy draft generator for internal use; all output reviewed by a marketing copywriter and compliance before publication. system_id = ACME-AI-018; business_owner = CMO; model_owner = Marketing Operations Manager; mrm_validator = none required; tier = 4 (composite 18); annex_iii_category = not high-risk; provider_vs_deployer = deployer; article_25_status = n/a; base_model = GPT-5 v2026-02; system_prompt_version = git hash 2d8a3e9; rag_corpus_ref = brand-guidelines v1.2; embedding_model = n/a; tools = none; memory_layer = no; autonomy_tier = Tier 1 SUGGEST; fria_filed = n/a; annex_iv_doc_ref = n/a; ce_marking = n/a; iso_42001 = yes SC-018; last_imv = n/a (Tier 4 no IMV requirement); next_review_due = 2027-05-15 (annual attestation only); incident_log = empty; retire_status = active.

Trigger response example. On 2026-04-22, a moderate-severity incident in Acme.LoanDefaultOutreach v2.1 (Entry 1), a cluster of 18 outreach emails sent to customers in a recently-renamed hardship program category, producing confusion about the program's status. Root cause: RAG corpus refresh on 2026-04-20 introduced new category names without updating the system-prompt category mapping. Trigger fired: material incident + substantial-modification of corpus. Response: (a) the 2L convened within 24 hours; (b) the corpus was rolled back; (c) the system-prompt was updated and re-validated; (d) the 18 affected customers received correction emails within 48 hours; (e) the incident was logged in the Article 73 register and a precautionary serious-incident notification was filed with the AI Office given the consumer-impact dimension; (f) the IMV report was annotated with the root-cause finding and the corpus-change-control gap; (g) a process change was implemented requiring system-prompt re-validation when corpus category names change. Total elapsed time from detection to fully-remediated: 6 calendar days. The audit committee reviewed the case at its May meeting and the board risk committee included it in its quarterly metric on incident-to-resolution time.

Periodic Review Report Template, Cross-Walks, Regulator Readiness

The periodic review report is the artefact each scheduled review produces: the document that the auditor, the regulator, and the audit committee will read to confirm oversight is active. Acme's 10-section template is the 2026 industry pattern.

The 10-section periodic review report. (1) System identifier and tier: system_id, current tier, prior tier (if changed), composite score, and tiering decision date. (2) Period under review. Start and end date of the review period, prior review date, current review date. (3) Inventory delta, every field in the 24-field schema that changed during the period, with link to the change record. (4) Incident summary: every Article 73 incident, every drift-alert, every customer complaint linked to the system, with severity and resolution status. (5) Substantial modifications, every Article 43(4) substantial modification ticket, with the re-validation status. (6) Monitoring KPI summary: every monitoring KPI with target, observed, breach count, and trend chart. (7) Drift-signal summary: each of the seven drift signals with measured value, threshold, and breach count. (8) Validation activities: any IMV refresh, any 2L spot-check, any 3L audit finding affecting the system. (9) Residual-risk reassessment, confirmation that residual risk remains within accepted bounds, or escalation if not. (10) Sign-off, Tier 1: CRO signature; Tier 2: Director MRM; Tier 3: Manager MRM; Tier 4: model-owner attestation only.

Cross-walk to EU AI Act. The inventory + tiering + review-cadence discipline operationalises seven articles. Article 9 ongoing risk management is the review cadence itself. Article 11 + Annex IV technical documentation is field 18 (annex_iv_doc_ref). Article 17 quality management system is the AIMS register (ISO 42001 A.4) and the federated inventory. Article 26(5) post-market monitoring for deployers is the monitoring KPI + drift signal summary in the review report. Article 27 FRIA is field 17, refreshed alongside the inventory entry for consumer-impact systems. Article 43(4) substantial-modification trigger is review-cadence driver (1). Article 71 EU database registration is field-set extraction for high-risk systems. Article 72 post-market monitoring system is the federated inventory + monitoring infrastructure. Article 73 serious incident reporting is field 23 + review report section 4. Penalty exposure for failure: Article 99(3) up to €15 million or 3% of worldwide annual turnover for breaches of Articles 9, 17, 26, 27, 71, 72.

Cross-walk to NIST AI RMF. Govern 1.1 (legal and regulatory requirements understood) is captured in fields 6, 7, 8 (Annex III category, provider/deployer status, Article 25 status). Govern 1.2 (characteristics of trustworthy AI integrated into policies and procedures) is the tiering rubric and the four-tier control allocation. Govern 4.1 (organisational accountability) is fields 2-4 (named owners). Map 1.1-1.5 (context and risk mapping) is the tiering committee output. Manage 1.1 (risk-management response) is the tier-specific control allocation (full MRM vs lightweight vs attestation). Manage 2.1 (resources allocated) is the validator-to-system staffing model. Manage 4.1 (post-deployment monitoring) is the drift-signal infrastructure. Manage 4.3 (incident response and recovery) is fields 23 + 24 plus the review report section 4. NIST AI 600-1 12 GenAI risk applicability is per-tier: Tier 1 systems explicitly address all 12 risks with mitigations; Tier 4 systems address only the applicable subset.

Cross-walk to ISO 42001. A.3 leadership is the named ownership in fields 2-4 plus the audit-committee oversight. A.4 resources management is the AIMS register (the inventory itself). A.5 impact assessment is fields 17 + 6 (FRIA + Annex III category). A.6 lifecycle management is fields 21, 22, 24 (last IMV, next review due, lifecycle state). A.10 third-party is field 7 (provider/deployer status) plus the procurement record for vendor base models.

Cross-walk to SR 11-7 / PRA SS1/23 / OCC 2011-12. The model-risk inventory has been an SR 11-7 expectation since 2011; the 2026 expansion is the LLM/agentic field set. SR 11-7's inventory expectation aligns to the 24-field schema's 1-5 + 21-24 fields; PRA SS1/23 Principle 2 ("Governance") aligns to fields 2-5; OCC 2011-12 aligns to the validation cadence (fields 21-22). Failure to maintain an effective inventory is SR 11-7 MRA territory; persistent failure is MRIA territory and consent-order escalation. PRA SS1/23 section 166 skilled-person review is the equivalent escalation in the UK.

The 24-48 hour regulator-readiness drill. The 2026 emerging expectation, and the one the Acme CRO faced from the board chair, is that the firm can produce the full model inventory within 24-48 hours of a supervisory request. The drill is tested quarterly via tabletop exercises: a hypothetical letter from the regulator asks for "all Tier 1 and Tier 2 AI systems in production with named owners, last-validation-date, and next-review-due." The drill is timed; the 2L runs it; the audit committee sees the result. Acme's May 2026 drill produced the full inventory in 7 hours (against a 48-hour target). Firms that cannot produce the inventory in 48 hours are flagged in the next supervisory cycle; firms that produce it in under 8 hours are considered inventory-mature.

Penalty exposure summary. Article 99(3) up to €15M or 3% of worldwide annual turnover for breaches of Article 9 (risk management), Article 17 (QMS), Article 26 (deployer obligations), Article 27 (FRIA), Article 71 (registration), Article 72 (post-market monitoring). SR 11-7 MRA → MRIA → consent order territory for inadequate inventory. PRA SS1/23 section 166 skilled-person review territory for governance gaps. The inventory + tiering + review-cadence triad is what defends against all three escalation paths simultaneously, and one well-designed federated inventory satisfies five frameworks at once.

Key Takeaways

  • The four-dimension tiering rubric, Criticality (35%), Consumer Impact (30%), Autonomy (20%), Reversibility (15%), produces four tiers with calibrated control allocation: Tier 1 (score 75-100) full MRM + IMV + Article 27 FRIA + quarterly review with CRO sign-off; Tier 2 (50-74) IMV + annual review with Director MRM; Tier 3 (25-49) lightweight validation + biannual review with Manager MRM; Tier 4 (0-24) policy compliance + annual attestation by model owner. Worked sample scores: hiring AI 76.5 → Tier 1; credit-scoring agent 84.25 → Tier 1; ECOA-aware customer chatbot 58.5 → Tier 2; internal coding assistant 31 → Tier 3; GitHub Copilot enterprise 27.5 → Tier 3.
  • The 24-field inventory schema is the federated source of truth spanning system_id, named owners (business, 1L, 2L), tier + composite score, Annex III category, provider/deployer status, Article 25 substantial-modification status, base model + version, fine-tune dataset, system prompt git hash, RAG corpus + embedding, tools list with sensitivity tier, memory layer, autonomy tier per lesson 049, FRIA reference, Annex IV doc, CE marking, ISO 42001 scope, last IMV date, next review due, incident log reference, and lifecycle state. No single tool holds all 24 fields; the federation of model-card-as-source-of-truth + CycloneDX 1.7 ML-BoM + ISO 42001 A.4 AIMS register + substantial-modification + incident-log tickets is the 2026 pattern.
  • Article 71 EU database registration is the public-facing version of the inventory for high-risk systems; the internal inventory record's system_id is the same as the Article 71 registration ID, making the inventory the bridge between internal MRM and the public EU register.
  • Review cadence has three drivers: scheduled by tier (Tier 1 quarterly, Tier 2 annual, Tier 3 biannual, Tier 4 annual attestation); five event-based triggers (Article 43(4) substantial modification, Article 73 material incident, upstream model upgrade, regulator inquiry, material drift detected); and annual recertification where each model owner re-attests their entry on a rolling calendar and the 2L audits a 10% sample for Tier 1+2 and 5% for Tier 3.
  • Seven drift signals fire event-based re-evaluation: input distribution drift (PSI > 0.2 investigation, > 0.3 re-validation), output distribution drift, performance drift (accuracy/hallucination/latency), refusal-rate drift, RAG-retrieval relevance drift (NDCG@k), user-feedback-loop drift, and fairness-slice drift. Fairness-slice drift on a Tier 1 consumer-impact system is the Tier-1 immediate-attention signal that an examiner will test on inspection.
  • Discovery and shadow AI are first-class. A 2026 inventory that captures only IT-approved systems is incomplete. Network egress scanning for known LLM endpoints, browser-extension and IDE-plugin manifests, SaaS-vendor AI-feature invoices, and source-code SDK imports are the four discovery sources. Discovered systems missing from inventory are flagged for tiering or retirement. Acme's June 2026 sweep added 23 systems including 4 Tier 2 and 1 Tier 1.
  • The 10-section periodic review report (system identifier + tier; period under review; inventory delta; incident summary; substantial modifications; monitoring KPI summary; drift-signal summary; validation activities; residual-risk reassessment; sign-off by tier) is the artefact every scheduled review produces, and the document the regulator will read first.
  • One inventory record satisfies five frameworks. EU AI Act Articles 9, 11, 17, 26(5), 27, 43(4), 71, 72, 73 align to inventory fields and review cadence; NIST AI RMF Govern 1.1+1.2+4.1, Map 1-5, Manage 1.1+2.1+4.1+4.3 align to tiering + ownership + drift monitoring; NIST AI 600-1's 12 GenAI risks apply per-tier; ISO 42001 A.3+A.4+A.5+A.6+A.10 align to leadership + AIMS register + impact assessment + lifecycle + third-party; SR 11-7 + PRA SS1/23 + OCC 2011-12 map to inventory + tiering + validation cadence. Penalty exposure: Article 99(3) up to €15M / 3% worldwide turnover; SR 11-7 MRA → MRIA → consent order; PRA section 166. The 24-48 hour regulator-readiness drill is the 2026 readiness gate, Acme's May 2026 drill produced the full inventory in 7 hours against a 48-hour target.