Models can't be re-baselined
The training data was never versioned. Twelve months in, you can't reproduce the model the regulator approved, and without that baseline, you can't approve a new one either.
ML-driven underwriting with explainability in the architecture and model-risk evidence (CP24/2 · SR 11-7 · SS1/23) as a primary deliverable.
Every workload reads from the same versioned feature store and ships the explainability a supervisory college expects. Start with the model costing you most.
Most ML underwriting stalls on the engineering around the model, not the model itself, four gaps that compound until supervisory review says no.
Compliance is not a model feature. It's the feature store and the audit trail.
Most vendor builds fail one test: the model card doesn't match the actual training run.
The training data was never versioned. Twelve months in, you can't reproduce the model the regulator approved, and without that baseline, you can't approve a new one either.
Production features drift away from the training distribution and the model degrades silently. By the time anyone notices, six months of bad underwriting decisions are already baked in.
SHAP or LIME is bolted on after launch, inconsistent from one decision to the next. The adverse-action notices it generates fail FCA conduct review when they're examined.
The model card is drafted in the final two weeks before launch. The supervisory college rejects it because it doesn't match the actual training run it claims to describe.
Not features: outcomes a chief risk officer, head of credit, or model-validation lead can defend in the room.
Each approval and decline is bound to per-decision feature attributions and a reason code, consistent across decisions, not a notebook plot. Adverse-action notices pass FCA conduct review because they say exactly why.
A decoupled serving layer lets you shadow-score a challenger against the incumbent, promote on evidence, and lift approvals without lifting losses, 23% more approvals at the same default rate in year one.
A versioned, point-in-time-correct feature store is the audit trail; the model is just the surface. Twelve months on, you can reproduce the exact model the regulator approved, and detect the drift that would otherwise degrade it silently.
Model-risk evidence is a primary deliverable, not a final-stage scramble. Every release ships a model card that matches the actual training run, formatted to CP24/2, SR 11-7, or PRA SS1/23: 100% first-pass clearance at second-line review.
Not features: four reasons a chief risk officer or model-validation lead can defend in the room.
CP24/2, SR 11-7 & SS1/23 evidence is a primary deliverable, not a late scramble.
Per-decision SHAP and reason codes, consistent and ready for FCA review.
A phased path from data audit to a supervisory-cleared production model.
Versioned data and code make the approved model always reproducible.
Five stages, each with a bounded output you can hold us to. The model-risk evidence is built alongside the model, never a final-stage scramble.
We review the data estate, map the regulatory surface (CP24/2, SR 11-7, SS1/23), and commit to a bounded scope and a costed roadmap, not an open-ended retainer.
The versioned, point-in-time-correct feature store goes live, the training pipeline is made reproducible (DVC + Git), and the first model is trained against hold-out and temporal validation.
The decisioning API and SHAP-at-scale explainability service go live, shadow-scoring the new model against the incumbent so promotion is on evidence, not faith.
The model card (matching the actual training run), the validation report, and the SS1/23 / CP24/2 supervisory-review pack are produced and signed off by second-line risk.
Continuous drift monitoring with PSI alerts, automated quarterly post-market surveillance, and additional models added under the same evidence and re-approval workflow.
Success stories
BritonOne Technology is a full-cycle engineering company that builds and operates production software for regulated estates. Since 2017, we have shipped programmes that clear audit on the first pass across banking, insurance, wealth, healthcare, and biotech. Our teams pair deep domain knowledge with disciplined engineering, treating compliance, security, and resilience as first-class deliverables. From architecture through to live operations, we stay accountable for the systems we build, measuring success by uptime, audit outcomes, and defensible business results.
Anonymised under MNDA, verifiable on reference call. Each quote is from a senior owner who carried the engagement through second-line review.
“BritonOne Technology shipped the only underwriting model where the model card matched the actual training run. That sounds basic; it's not. Most vendor builds we've seen fail that test, and fail their supervisory review because of it.”
