Banking Law And Monetary Policy Transmission Legal Framework Kuwait .

Banking Law and Model Risk Management in Spain

1. Introduction

Model risk management in Spanish banking concerns the legal, regulatory and governance controls applied when banks use mathematical, statistical, econometric or artificial-intelligence models to make or support financial decisions.

Banks increasingly use models for:

credit scoring;

probability of default calculations;

loss-given-default estimates;

capital requirements;

IFRS 9 expected-credit-loss calculations;

market and counterparty risk;

stress testing;

anti-money-laundering monitoring;

fraud detection;

pricing;

liquidity management;

customer profiling; and

automated lending decisions.

A model can create risk when its design, assumptions, data, implementation or use produces inaccurate or inappropriate results.

Spanish model-risk regulation does not come from one statute called a “Model Risk Management Act.” It arises from a combination of Spanish banking legislation, EU prudential regulation, ECB supervision, Banco de España supervision, GDPR, consumer-protection rules and, increasingly, EU artificial-intelligence regulation.

Spanish credit institutions operate within the Single Supervisory Mechanism (SSM). Significant institutions are directly supervised by the European Central Bank, working with national authorities including Banco de España. Banco de España expressly identifies investigations of internal models used to calculate capital requirements for credit, counterparty, market and operational risks as part of banking supervision.

 

2. What Is Model Risk?

Model risk is broadly the possibility of financial, regulatory or customer harm caused by decisions based on incorrect, poorly designed or improperly used models.

Suppose a Spanish bank develops a mortgage model predicting the probability that borrowers will default.

The model could create risk because:

historical data are incomplete;

important variables are excluded;

assumptions are unrealistic;

economic conditions change;

the model is incorrectly coded;

employees use the model outside its intended purpose;

discriminatory variables influence outcomes;

model performance deteriorates; or

management treats model outputs as unquestionable facts.

Model risk therefore involves much more than mathematical accuracy.

It is fundamentally a governance risk.

 

3. Spanish Regulatory Structure

Several layers of regulation govern model risk in Spain.

At national level, important legislation includes Law 10/2014 on the organisation, supervision and solvency of credit institutions and its implementing framework.

At EU level, major sources include:

Capital Requirements Regulation (CRR);

Capital Requirements Directive (CRD);

ECB supervisory requirements;

EBA technical standards and guidelines;

GDPR;

Digital Operational Resilience Act (DORA); and

EU Artificial Intelligence Act where applicable.

Spanish banking supervision has operated within the SSM since November 2014. Banco de España states that supervision seeks to ensure that banks are adequately capitalised, comply with applicable rules and manage their businesses and risks prudently.

 

4. Internal Capital Models

One of the clearest areas of legally regulated model risk involves internal models used for regulatory capital.

Instead of relying entirely on standardised regulatory calculations, qualifying banks may use approved internal approaches for certain risks.

For credit risk, this traditionally includes internal ratings-based methodologies.

The model may estimate variables such as:

PD – Probability of Default: probability that the borrower will default.

LGD – Loss Given Default: expected percentage loss following default.

EAD – Exposure at Default: expected exposure when default occurs.

These calculations can affect regulatory capital.

A model that systematically underestimates risk may therefore cause a bank to hold insufficient capital.

That explains why supervisors closely examine internal models.

 

5. Supervisory Approval

Banks cannot simply create their own regulatory capital model and use it without satisfying the applicable prudential requirements.

Internal-model frameworks are subject to supervisory scrutiny.

Banco de España explains that its supervisory activities include specific investigations of internal models and, where appropriate, their authorisation for calculating capital requirements relating to credit, counterparty, market and operational risks.

Consequently, model governance becomes directly connected with regulatory capital law.

 

6. ECB Guide to Internal Models

The ECB's internal-model framework is particularly important for significant Spanish banks.

It addresses matters such as:

model governance;

internal validation;

internal audit;

model changes;

credit-risk modelling;

market-risk modelling;

counterparty-credit-risk models;

data quality; and

supervisory expectations.

The ECB has continued refining its supervision of internal models, including changes intended to make model supervision more efficient while maintaining prudential safeguards.

A Spanish bank therefore needs a structured model-management system rather than treating each model as an isolated statistical exercise.

 

7. Model Inventory

Good governance begins with identifying the models actually used by the institution.

A bank should maintain an appropriate inventory covering important models such as:

mortgage scoring;

SME credit scoring;

corporate ratings;

expected-credit-loss calculations;

market-risk calculations;

liquidity forecasts;

fraud models;

AML models; and

AI-based customer assessment.

The inventory allows management to identify which models create the greatest regulatory and financial exposure.

Models can then be classified according to materiality and risk.

 

8. Model Development

A model should have a clearly defined purpose.

Developers should identify:

what the model predicts;

what data it uses;

the target population;

assumptions;

limitations;

statistical methodology;

circumstances in which it should not be used; and

expected performance.

For example, a model developed from Spanish residential mortgage data may perform poorly if suddenly applied to unsecured SME lending.

Using a technically accurate model outside its intended scope can itself create model risk.

 

9. Independent Validation

Development and validation should be meaningfully separated.

The team that creates a model should not be the only group deciding whether that model is reliable.

Independent validation may examine:

conceptual soundness;

methodology;

input data;

assumptions;

statistical performance;

calibration;

stability;

implementation;

limitations; and

actual outcomes.

This provides an important control against developer bias and unnoticed technical errors.

 

10. Backtesting

Models must also be compared with actual outcomes.

Suppose a credit model predicts that only 2% of a category of borrowers will default.

If actual defaults repeatedly reach 7%, the difference requires investigation.

The institution may need to:

recalibrate the model;

change assumptions;

introduce conservative adjustments;

restrict its use; or

replace it.

EU prudential regulation expressly contains technical requirements concerning backtesting and profit-and-loss attribution for internal market-risk approaches. Banco de España's prudential regulatory materials identify these rules as part of the supervisory framework.

 

11. Stress Testing

Historical performance alone is insufficient.

Banks must consider how models behave under adverse conditions.

Stress scenarios may include:

recession;

unemployment increases;

falling property prices;

rapid interest-rate movements;

liquidity shocks;

market volatility; and

sector-specific crises.

Banco de España itself uses multiple empirical and theoretical models for financial-risk analysis, credit analysis and banking stress testing, illustrating the central role of modelling in modern prudential supervision.

 

12. Model Changes

Models cannot remain permanently unchanged.

A model developed in one economic environment may become unreliable after substantial changes in:

interest rates;

customer behaviour;

property markets;

technology;

regulation; or

macroeconomic conditions.

Banks therefore need policies determining when changes amount to minor adjustments and when they constitute material model changes requiring stronger governance or supervisory involvement.

 

13. Credit Scoring and GDPR

Model risk becomes particularly important when models make decisions about individuals.

Consider an online Spanish bank using an algorithm to decide whether a consumer receives a €15,000 personal loan.

The model evaluates information and produces a credit score.

If the bank automatically refuses the application because of that score, Article 22 GDPR can become highly relevant.

The GDPR provides protections concerning decisions based solely on automated processing, including profiling, where those decisions produce legal effects or similarly significantly affect individuals.

This principle has generated major CJEU litigation.

 

14. Case Law

There are not six major Spanish Supreme Court judgments expressly labelled “banking model risk management.” The most legally relevant jurisprudence therefore comes from the Court of Justice of the European Union, whose interpretations of EU law apply in Spain.

These judgments provide concrete legal rules for credit-scoring models, automated decision-making, data quality, transparency and customer rights.

Case 1 — SCHUFA Holding (Scoring), Case C-634/21, CJEU, 7 December 2023

This is one of the most important European judgments concerning credit-risk models.

SCHUFA generated probability values predicting whether individuals would meet future payment obligations.

Financial institutions could then use those scores when deciding whether to provide credit.

The CJEU held that automated generation of a probability value can itself fall within GDPR Article 22 where that score plays a determining role in a third party's decision.

The Court noted that an insufficient probability value could, in practice, lead almost automatically to rejection of a consumer's loan application.

Importance for Spanish banks

A bank cannot necessarily escape automated-decision obligations merely by saying:

“The algorithm only produced a score; the bank made the decision.”

The practical influence of the score matters.

If the model effectively determines whether credit is granted, GDPR protections can apply.

 

Case 2 — CK v Dun & Bradstreet Austria, Case C-203/22, CJEU, 27 February 2025

This judgment significantly developed the law of explainable credit models.

The dispute concerned automated creditworthiness scoring and the individual's right under GDPR Article 15(1)(h) to obtain meaningful information concerning the logic involved.

The CJEU held that the explanation must allow the individual to understand the procedure and principles actually applied and how the person's data were used to produce the relevant result.

Simply supplying an extremely complicated mathematical formula is not sufficient.

Nor must the controller necessarily provide every technical step of an algorithm.

Instead, information must be meaningful, transparent and understandable.

Importance for Spanish banks

A Spanish bank using sophisticated machine-learning credit models must consider explainability at the design stage.

A model may be statistically excellent yet legally problematic if meaningful explanations of significant automated decisions cannot be provided.

 

Case 3 — Nowak v Data Protection Commissioner, Case C-434/16, CJEU, 20 December 2017

The Court adopted an important interpretation of what can constitute personal data.

Information is personal data where, because of its content, purpose or effect, it is linked to an identifiable person.

Model-risk significance

Model governance cannot focus only on raw customer information such as name, address and salary.

Analytical information, assessments and model-generated information concerning identifiable individuals can also fall within the data-protection framework.

This is particularly relevant for internal ratings and customer-risk profiles.

 

Case 4 — YS and Others, Joined Cases C-141/12 and C-372/12, CJEU, 17 July 2014

These cases considered access to personal data and the distinction between underlying personal information and legal analysis.

The Court differentiated personal data concerning an individual from the reasoning or analysis through which an authority reaches a conclusion.

Model-risk significance

The distinction is relevant when banks receive requests concerning automated assessments.

Banks must distinguish between:

personal data used by the model;

generated personal assessments;

underlying algorithms;

internal methodologies; and

legally protected confidential information.

The later Dun & Bradstreet judgment develops this area further by requiring meaningful information about automated logic without automatically requiring disclosure of every technical detail.

 

Case 5 — Österreichische Post, Case C-300/21, CJEU, 4 May 2023

The case concerned compensation under GDPR Article 82.

The CJEU held that infringement of the GDPR alone does not automatically establish a right to compensation. Damage and a causal relationship must also exist.

At the same time, EU law does not establish a general minimum seriousness threshold before non-material damage can qualify.

Model-risk significance

Suppose a Spanish bank operates a defective automated model that unlawfully profiles customers.

Regulatory non-compliance and civil compensation are related but separate questions.

For damages, the claimant must establish the relevant damage and causal connection.

This means model-risk management should consider litigation exposure, not merely regulatory fines.

 

Case 6 — UI v Österreichische Post, Case C-154/21, CJEU, 12 January 2023

This case concerned the GDPR right of access and disclosure of recipients of personal data.

The Court held, in principle, that individuals may be entitled to know the actual recipients to whom their personal data have been disclosed, subject to the circumstances recognised by the GDPR.

Model-risk significance

Modern banking models frequently depend on external ecosystems involving:

credit bureaus;

cloud providers;

analytics companies;

fraud-detection providers;

external data suppliers; and

fintech partners.

Model governance therefore extends beyond models developed completely inside the bank.

Banks need appropriate control over external data and third-party model arrangements.

 

Case 7 — Wirtschaftsakademie Schleswig-Holstein, Case C-210/16, CJEU, 5 June 2018

The Court adopted a functional approach to joint responsibility for personal-data processing.

An organisation does not necessarily avoid data-protection responsibility simply because another company supplies the technology used for processing.

Model-risk significance

This is relevant where a Spanish bank purchases an AI or scoring solution from an external vendor.

Outsourcing technical development does not automatically outsource the bank's legal responsibilities.

The bank still needs to understand:

the data used;

model purpose;

performance;

controls;

privacy implications; and

allocation of responsibilities.

 

Case 8 — Google Spain SL and Google Inc. v AEPD and Mario Costeja González, Case C-131/12, CJEU, 13 May 2014

This landmark case arose directly from Spain and established major principles concerning the application of EU data-protection rights to data processing and search engines.

Although it was not a banking-model case, it demonstrated that organisations performing sophisticated automated processing can have independent responsibilities concerning personal information.

Model-risk significance

For Spanish banks, the broader lesson is that technologically automated processing remains subject to substantive data-protection rights.

Calling a process an “algorithm,” “score” or “AI model” does not place it outside ordinary legal accountability.

 

15. What These Cases Mean Together

These judgments establish several important principles for Spanish banking models.

First, credit scoring can constitute automated decision-making when the score effectively determines the lending outcome.

Second, customers may have rights to meaningful explanations concerning automated decisions.

Third, mathematical complexity does not eliminate transparency obligations.

Fourth, model-generated information can fall within personal-data regulation.

Fifth, outsourcing models or data processing does not automatically eliminate the bank's legal responsibilities.

Finally, defective model governance can create both supervisory and private-law consequences.

 

16. Artificial Intelligence Models

AI creates an additional layer of model risk.

Traditional credit models might use relatively transparent statistical relationships.

Machine-learning models can involve hundreds or thousands of variables and complex interactions.

This creates risks involving:

explainability;

bias;

discrimination;

data quality;

model drift;

cybersecurity;

overfitting;

incorrect outputs; and

excessive dependence on automated recommendations.

The regulatory issue is therefore not whether AI may ever be used.

The question is whether it is developed, validated, monitored and governed consistently with the legal requirements applicable to its particular use.

 

17. Human Oversight

Human review is especially important where model outputs affect customers significantly.

However, merely placing an employee between the model and the final decision does not necessarily create meaningful human oversight.

Consider:

Model says: reject loan.

Employee says: reject loan without examining anything.

Formally, a human clicked the final button.

Substantively, the algorithm determined the outcome.

The reasoning in SCHUFA C-634/21 makes the actual importance of the automated score highly relevant.

Effective human oversight should therefore involve genuine authority and sufficient information to question or override the model where appropriate.

 

18. Data Quality

A sophisticated model built on unreliable data remains unreliable.

Banks should therefore establish controls concerning:

accuracy;

completeness;

representativeness;

historical depth;

missing observations;

data lineage;

unusual values;

reconciliation; and

permitted use.

Poor data can generate both prudential and customer-protection problems.

For example, an incorrect default record can cause a perfectly functioning credit algorithm to reach an incorrect result.

 

19. Model Bias and Discrimination

Models may unintentionally create discriminatory outcomes.

A model might not directly use a protected characteristic but may rely on another variable strongly correlated with it.

Model governance should therefore examine both model design and actual outcomes.

Banks should consider:

whether variables are legally permissible;

whether training data contain historical biases;

whether particular customer groups experience systematically different outcomes;

whether differences have legitimate explanations; and

whether corrective controls are required.

This becomes increasingly important as banking models move from traditional regression techniques toward machine learning.

 

20. Third-Party Models

Spanish banks increasingly obtain models from technology vendors.

Examples include:

fraud-detection engines;

AML software;

cloud analytics;

credit-scoring systems;

biometric systems; and

generative-AI applications.

The institution should not treat a vendor's model as a black box that falls outside internal governance.

Appropriate controls can include:

vendor due diligence;

technical documentation;

performance testing;

data-quality assessment;

contractual audit rights;

cybersecurity requirements;

change-management controls;

exit arrangements; and

ongoing monitoring.

 

21. Model Drift

A model may be accurate when created but become progressively less reliable.

This phenomenon is often called model drift.

Suppose a consumer-credit model was calibrated during a period of low inflation and low interest rates.

After significant macroeconomic changes, borrower behaviour may change.

Relationships that previously predicted default may therefore weaken.

The bank should monitor actual outcomes and recalibrate or replace models where necessary.

Banco de España's own analytical work emphasises the continuing development and adaptation of financial-risk models as economic conditions evolve.

 

22. Governance Structure

A mature Spanish banking model-risk framework normally involves several organisational levels.

Model owners

Responsible for the business use of the model.

Model developers

Design and implement the methodology.

Independent validators

Challenge assumptions, methodology and performance.

Risk management

Maintains institution-wide model-risk standards.

Internal audit

Evaluates whether the overall governance framework operates effectively.

Senior management

Ensures that material model weaknesses receive appropriate attention.

Board

Exercises oversight over material risk within the institution's governance framework.

The objective is to prevent important models from operating without clear ownership and accountability.

 

23. Model Documentation

Documentation should allow an appropriately qualified independent person to understand the model.

It should normally cover:

purpose;

methodology;

data;

assumptions;

variables;

limitations;

development;

validation;

performance;

changes;

approvals; and

circumstances requiring escalation.

Documentation becomes particularly important during supervisory examinations.

 

24. Model Risk and Capital

Errors in regulatory models can affect the amount of capital maintained by a bank.

Suppose an internal model materially underestimates mortgage default risk.

That can produce underestimated risk-weighted assets and therefore inadequate regulatory capital.

Supervisors may respond by requiring remediation, restricting model use, imposing conservatism or requiring alternative calculations depending upon the applicable prudential rules.

This explains why internal models receive direct supervisory scrutiny rather than being treated merely as internal management tools.

 

25. Model Risk and IFRS 9

Model risk is also central to expected credit losses under IFRS 9.

Banks estimate expected losses using forward-looking information.

Relevant assumptions can concern:

probability of default;

loss given default;

exposure;

macroeconomic scenarios;

unemployment;

interest rates; and

property prices.

Small changes in assumptions can materially affect impairment allowances.

Banks therefore need governance around scenario selection, model overlays and management adjustments.

 

26. Example

Suppose a Spanish bank launches an AI mortgage model.

The system analyses 150 variables and automatically assigns applicants a score from 0 to 1,000.

Applicants below 450 are normally rejected.

Several risks immediately arise.

Prudential risk: Does the model accurately predict defaults?

Validation risk: Has an independent team tested it?

Data risk: Are input variables reliable?

GDPR risk: Does the system constitute automated decision-making?

Explainability risk: Can the bank meaningfully explain an adverse decision?

Bias risk: Does the model create unjustified differences between customer groups?

Operational risk: Has the production implementation been correctly coded?

Third-party risk: Does an external technology supplier control important parts of the algorithm?

The principles from SCHUFA and Dun & Bradstreet are particularly relevant to the automated-decision and explainability questions.

The bank therefore cannot evaluate the model solely by asking whether its predictive accuracy is high.

A legally sustainable model must also operate within an adequate governance framework.

 

27. Supervisory Consequences

Weak model-risk management can lead to supervisory intervention.

Depending upon the problem and applicable legal framework, authorities may require:

model remediation;

stronger governance;

additional validation;

revised assumptions;

limitations on model use;

more conservative calculations;

additional controls; or

other supervisory measures.

Banco de España describes Spanish supervision as combining continuous off-site supervision, on-site inspections and investigations of internal models.

This means model governance is subject to practical supervisory examination rather than being merely theoretical compliance.

 

28. Conclusion

Model risk management has become a central part of Spanish banking law because modern banking increasingly depends on models.

Spain does not regulate model risk through one standalone statute. Instead, the framework combines Spanish banking legislation, the CRR/CRD prudential regime, ECB and Banco de España supervision, GDPR, operational-resilience requirements and the developing EU framework governing artificial intelligence.

The regulatory approach can be summarised through a simple lifecycle:

Identify → Develop → Validate → Approve → Implement → Monitor → Backtest → Challenge → Correct → Retire.

The case law adds an important customer-rights dimension.

SCHUFA (C-634/21) establishes that credit scoring can constitute automated decision-making when the score effectively determines the lending outcome.

CK v Dun & Bradstreet (C-203/22) establishes that customers must receive meaningful and understandable information about the logic of relevant automated decision-making; simply presenting a complicated mathematical formula is insufficient.

Nowak, YS, Österreichische Post, Wirtschaftsakademie and Google Spain further demonstrate that personal data, profiling, accountability, access rights and damages can interact with model governance.

For Spanish banks, therefore, effective model-risk management requires much more than statistically accurate algorithms. It requires reliable data, independent validation, appropriate human oversight, transparent customer treatment, continuous monitoring, documented governance and effective supervisory compliance.

As banks expand their use of machine learning and artificial intelligence, these requirements make model governance an increasingly important intersection between prudential banking law, technology regulation and individual data-protection rights in Spain.

LEAVE A COMMENT