Agents / Model Risk Management
Assurance Agent
Runs the automated check battery on every submitted model and composed workflow: performance against the declared benchmarks, fairness tests across customer segments, explainability outputs, security and supply-chain scan of the artefact, PII leakage in prompts for GenAI assets, and licence scan of third-party components. Assembles the check report for Model Risk.
An agent executes the process end to end and logs what it did. No human is in the path, because there is no discretion to exercise and no consequence to carry.
- Acts for
- Model Risk & Governance
- Action class
- read-only
- Decisions / 30d
- 61
- Safe-state returns / 30d
- 1
Processes covered
- Automated assurance: performance, fairness, explainability, security, PII in prompts, licences
- Conformance testing of composed workflows
- Data residency and GenAI screening checks
Stages:Build & validateDeploy & integrateOperate & charge back
Memory
Retains check reports for the life of the asset version; purged on retirement.
Safe state
Marks the check as 'not run' and blocks routing to validation when any scanner is unavailable or the PII-in-prompt screen fails, rather than passing the stage.
Reviewer time per case: 0 min with this agent, 75 without.
Ownership and sensitivity
Who approves access
- Owner, Model Risk Management, Dr. Kavitha Subramaniam
Business-sensitive. Models and data products scoped to named business units.
Entitlement per business unit, approved by the owner; conditions attach.
Tools
- Artefact and container scanner
- SBOM, signature and licence scanner
- Benchmark harness
- Fairness and explainability suite
- PII-in-prompt screen
- Check-report writer
Data access scope
- Read-only: artefacts, SBOMs, evaluation datasets referenced in the manifest
- Read-only: check reports of comparable validated models
- Write: check report attached to the case only
Guardrails
- A failed security, licence or PII check blocks routing to validation automatically
- Never modifies an artefact; findings are reported, not fixed
- Anomaly flags always show the comparable set they were judged against
Human-in-the-loop
- The Model Risk validator reads the check report before any validation opinion
Orchestration
Every tool call is scoped by the declared data access above; the orchestrator cannot reach systems outside it. Owning business unit: Group Data & AI.
Live demo run
Watch the agent execute a real scenario step by step, every tool call, validation, and human checkpoint is traced and auditable. Typical run: ~6.9s.
Used in workflows
- Onboard an approved vendor modelactive
- Publish and validate a modelactive
- Promote a model to productionactive
- Periodic revalidationactive
Retiring this asset would require these chains to be re-pointed first.
Audit
Updated 2026-07-30. Run traces retained 24 months for audit under the platform governance policy.
Community · 0 threads
Questions, findings and requests from the business units that use this asset. Owners reply here; threads with upvotes surface to the owning team's inbox.