When Model Risk Management Meets Generative AI
Summary
The article explains how traditional model risk management frameworks are being stretched by generative AI systems that change with prompts, retrieval updates, and vendor model swaps. It highlights how U.S., U.K., and EU regulatory approaches are converging on a need for provable lineage, tamper-evident logging, and independently verifiable records. The piece argues that conventional documentation is no longer enough because validators cannot reliably reconstruct what a generative model did after the fact. It presents Mickai’s Open Audit Record as a solution that signs actions before execution and stores them in an append-only, hash-chained ledger that can be checked offline. The article positions verifiable lineage as the key control for regulated enterprises adopting generative AI.