No black boxes, ready for SS1/23
The PRA's SS1/23 has moved model risk management from policy on paper to demonstrable operating effectiveness. Yields gives UK firms one platform to run an enterprise-wide inventory, automate monitoring and documentation, and give senior management the evidence they need to sign off with confidence.
Trusted by leading financial institutions including HSBC, BNP Paribas, Euroclear, and Banco do Brasil.













The context
What the PRA expects under SS1/23
SS1/23 is the PRA's supervisory statement setting out model risk management principles for UK banks, building societies, and large investment firms. It is no longer enough to have a policy. The regulator now asks to see the evidence, the lineage, and the board-level accountability behind your models.
That expectation has sharpened into a few non-negotiables. Firms need total inventory visibility, capturing everything from complex AI to the material spreadsheets that drive business decisions. Conceptual soundness means the end of the black box, so a model used for credit scoring or fraud must be explainable. And under the Senior Managers and Certification Regime, there is a named person personally accountable if models fail through poor governance. The PRA has also flagged a persistent technology gap, pointing to manual monitoring and inconsistent use of model operating boundaries. That is where Yields comes in.
The Yields approach
How Yields gets you SS1/23 ready
The PRA has signalled that firms relying on manual, paper-based processes will find themselves technically out of compliance as their model landscapes grow. Yields provides the technological bridge, a single source of truth that aligns with the principles of SS1/23 and closes the technology gap the regulator keeps pointing to. Here is how it works.
A multi-tiered enterprise inventory
The PRA wants total visibility, including the relationships between model versions, lineages, and post-model adjustments. Yields uses a flexible data model where traditional and AI models coexist, capturing the rich metadata the PRA expects, including limitations, assumptions, and operating boundaries, all held in relational tables that are easy to interrogate.
Explainability, not black boxes
SS1/23 demands conceptual soundness: you must be able to explain why a model reached a specific decision. Yields provides full governance lineage and reproducibility for every calculation and decision made in the system, so credit, fraud, and other models can be explained and defended rather than trusted blindly.
Automated monitoring and operating boundaries
The regulator has singled out manual monitoring and the inconsistent use of operating boundaries. In Yields you define a model's safe operating zone with predefined statistical benchmarks for drift, accuracy, or sensitivity. When a model breaches its boundary, the platform generates a risk-prioritised alert and guides the user through the follow-up tasks, so a breach triggers action rather than a footnote.
Self-healing documentation
One of the biggest burdens of SS1/23 is the sheer volume of documentation. Yields uses automated pipelines to run analysis and compute monitoring metrics, and uses metadata to automate the generation of development documentation, reducing the manual compliance tax on your developers while keeping evidence current.
Aggregate risk for the board
The PRA expects boards and senior management to understand aggregate model risk, not just individual models. Yields tracks interdependencies to surface clusters of risk, such as a single data quality issue affecting multiple credit models, and translates quantitative results into high-level risk scores, giving the board a single view of the firm-wide health of the model landscape.
Model agnostic, so innovation is not sacrificed
A common fear is that a vendor tool will restrict the quant team. Yields is model agnostic, supporting traditional predictive statistics alongside predictive, generative, and agentic AI without restriction, so compliance never comes at the cost of innovation.
An enterprise inventory, explainable models, automated monitoring, and board-level aggregate reporting. Structured, defensible, and regulator-ready.
See it in action →Governance partner, not just a repository
A vendor the PRA can see through
Under SS1/23, vendors are no longer treated as arms-length third parties. They are part of a firm's material outsourcing, and must meet the same robust governance the bank applies to its own processes, in line with the UK's wider operational resilience framework and the EU's DORA.
Yields is built for that scrutiny. We provide a white-box experience that makes vendor risk assessment straightforward for procurement and compliance teams, with transparent code, calculations, and decision lineages. An API-first structure and support for private network connectivity give your MRM team the same control over Yields as they have over their own internal systems. A cloud-ready architecture can sit fully within your secure IT estate, whether as managed SaaS or within your own environment, so your data stays inside your controlled perimeter.
Why Yields
From paper-based compliance to competitive advantage
SS1/23 is not a hurdle to be cleared. It is a new way of doing business, and the firms that treat it that way turn regulatory pressure into an operational edge. Yields helps you move beyond paper-based compliance to scalable, technology-enabled oversight, delivered as modules that each address a layer of the model risk lifecycle while operating as one integrated platform. Firms that choose a vendor who understands the regulatory spirit as well as the technical requirements do not just manage risk, they gain an advantage.
One integrated platform, delivered as modular capabilities
Model agnostic: traditional, predictive, generative, and agentic AI
White-box, API-first, and deployable inside your secure estate
Turn SS1/23 into demonstrable operating effectiveness
Yields gives you the automated monitoring, data aggregation, and operating boundaries the PRA is looking for, with the lineage and accountability to prove it. Move beyond paper-based compliance to a model risk function that scales with your AI and model landscape, and stays ready whenever the regulator asks.
