Guarding against large policy errors under model uncertainty