For financial institutions

Find it yourself, while it's still fixable.

A finding raised by your validator becomes a remediation item, a board conversation, and a line in next year's exam. The same condition, found three months earlier by your own team, is just a task. VetALM puts an AI reader on your documentation and runs the validator's evidence pass on your schedule.

  • No model re-computation. AI reads what you already report
  • Every extracted figure carries a citation to its source cell
  • Your team decides what's a real issue. Nothing publishes without a reviewer
vetalm.com / engagements / 2026 ALM Review
The VetALM findings screen showing detected issues with severity, explanation, citations, and regulatory mapping.

Validation readiness

The conditions that become findings.

None of these are exotic. They're the ordinary consequences of a model that's been running for a few years while the people and priorities around it changed. They are also what an independent reviewer is trained to look for first, and what VetALM's AI reader is pointed at across your whole document set.

The study nobody refreshed

A deposit study from 2022 still driving betas and decay rates in 2026, with a policy that requires a refresh every twenty-four months. AI pulls both dates out of the documents. A deterministic rule compares them. The result is unarguable and high severity, and it was trivially avoidable if someone had checked.

The override with no memo

An assumption set to something other than what the study recommended, because someone had a reason at the time. A language model reads across the study, the config, and the committee minutes looking for that reason. If it isn't written down anywhere, the validator can only record that it isn't.

The board saw a different number

The figure in the ALCO package doesn't tie to the model output it came from. AI extracts both numbers with a citation to the exact cell or paragraph, and the comparison is arithmetic from there. Usually it's a version mismatch, occasionally something worse. Either way it's a governance finding.

Limits that aren't actually monitored

The policy states limits, the model doesn't have them loaded, and nothing is breaching because nothing is checking. A control gap rather than a risk result.

Last year's finding, still open

A prior-period item marked for remediation that the current evidence shows unchanged. Repeat findings escalate. They read as a remediation-tracking failure, not just a technical one.

The document you can't produce

Forty-four documents a thorough validation expects. AI classifies what you upload against that list, so you see the gaps without sorting the folder yourself. Knowing which ones you'd struggle to hand over is a useful morning's work, and the checklist is the first screen of the product.

Independent benchmark

Does an outside model agree with yours?

Your vendor's model produces a number. Your validator will ask whether an independent model produces a similar one. You can know the answer before they ask.

A second opinion on your rate risk.

AI reads the account-category rollups out of your own ALM report appendix. From there it is ordinary financial mathematics, not AI: the challenger engine independently produces economic value of equity and twelve-month net interest income across the parallel shock set, then puts its answer next to yours.

  • Divergence past tolerance is flagged with the scenario and metric that caused it
  • A disagreement on the direction of exposure escalates immediately. That's the one worth a phone call to your vendor
  • Adjust betas, decay rates, and the curve to see which assumption is driving the gap
  • Every run is stored with its inputs, so you can show your work later

A divergence isn't automatically an error in your model. It can just as easily point at an assumption worth documenting. Knowing which, before someone else asks, is the point.

The challenger model workbench comparing independently computed EVE and NII against reported results across rate shocks.
Reported and challenger NII moving in opposite directions under upward shocks, flagged as opposed.

When to use it

Three points in the year where it pays.

Ahead of a validation

Run it sixty to ninety days before your validator starts. Close what you can, document what you can't, and walk into the kickoff knowing what they'll find.

Ahead of an exam

Interest-rate risk and model governance are standing exam topics. An evidence-backed self-assessment, with citations, is a better answer than a binder.

After a model or vendor change

A new version, a re-parameterization, or a conversion is where assumptions quietly drift from their documentation. Re-run and compare against the prior engagement's record.

The Extractions tab: extracted fields with values, confidence scores, and source evidence locators.
Every assumption in your model documentation, extracted by AI with the cell it came from. A tie-out you can hand to anyone.

Questions institutions ask

Independence, self-assessment, and what this isn't.

Does this count as our independent validation?

No, and we'd steer you away from anyone who says otherwise. Independence requires a party outside the model's ownership and use, which a tool your own team runs cannot supply. That is true no matter how good the AI is. VetALM is for self-assessment and readiness. If your validator chooses to use it as well, that's their engagement and their sign-off.

Do you need access to our ALM model or core system?

No. AI reads the documents you already produce: policy, shock reports, deposit studies, assumption documentation, config exports, board packages, and back-testing evidence. Nothing connects to your model or core.

What if the challenger disagrees with our vendor's model?

That's information, not a verdict. Two models built on different conventions will differ, and the useful question is whether the gap is explainable. The workbench lets you flex betas, decay rates, and the curve to see which assumption drives it. That is usually the conversation worth having with your vendor anyway.

Our documentation is messy. Is that a problem?

It's the normal case, and it's partly the point. The document checklist will show you exactly which of the forty-four expected items you can't currently produce, which is often the most actionable output of a first run.

How much of this is AI, and where does it stop?

AI does the reading. It classifies each document, extracts every figure with a citation to the cell or paragraph it came from, reads across the full corpus for contradictions no single rule anticipates, and drafts the workpaper prose. Deterministic code does everything else: the twelve detection rules are fixed comparison logic, the challenger model is ordinary financial mathematics, and the audit trail is recorded, not generated. Findings from the language model must cite their evidence or stay quiet, and every finding requires a human reviewer's sign-off before it appears in a deliverable.

Who on our team would use this?

Typically model risk or the ALCO/treasury function, with internal audit as a reader. Roles are enforced server-side, so read-only access for the people who need visibility without edit rights is straightforward.

Know what they'll find.

We'll walk through a complete engagement on a sample bank dataset: the document checklist, the AI-extracted assumptions, the challenger benchmark, and the findings with their citations. Then we'll talk about running it on yours.

  • 30-minute guided walkthrough, no slideware
  • No connection to your model or core system
  • Documents encrypted, tenant-isolated, never used for training

Prefer email? Reach us at sales@vetalm.com.