| Current-state assessment | Maturity, control gaps, evidence review and risk-ranked findings | Assessment report and findings register | Assess | Policies, model artefacts, interviews and audit evidence | Model risk / fraud leadership |
| Model inventory and taxonomy | Models, rules, vendor scores, owners, uses, dependencies and risk tiers | Register, data dictionary and ownership matrix | Assess / design | Product, platform and model lists | Model governance office |
| Governance standard | Lifecycle requirements, roles, approvals, exceptions and evidence | Policy or operating standard | Design | Risk appetite, policy hierarchy and legal review | Risk and compliance |
| Validation framework | Scope, independence, testing domains, reporting and approval criteria | Standard, templates and review checklist | Design | Model methodologies and validation expectations | Independent validation function |
| Monitoring framework | Metrics, baselines, thresholds, frequency, escalation and reporting | Monitoring catalogue and dashboard specification | Design / implement | Performance data, risk appetite and operational capacity | Fraud analytics and operations |
| Change-control workflow | Impact assessment, testing, approval, versioning and emergency changes | Workflow, templates and control records | Implement | Release process and tooling access | Engineering / MLOps |
| Training and transition pack | Role guidance, procedures, training, reporting calendar and handover | Playbook, workshops and operational pack | Transition | Named owners and attendance | Governance lead |