Skip to main content
Security & Compliance7 min read

OSFI E-23: Canada's Model Risk Rules Meet AI

July 2026By ChatGPT.ca Team

Last updated: July 24, 2026 · Informational, not legal advice

Quick answer

OSFI's finalized Guideline E-23 (Model Risk Management) takes effect May 1, 2027 and explicitly brings AI and machine-learning models — including vendor and third-party models — under formal governance at federally regulated financial institutions. Core requirements: an enterprise-wide model inventory, risk ratings with proportionate controls, full lifecycle management, and accountable governance. If you sell AI into banks or insurers, these duties flow into your contracts; 2026 is the preparation window.

Why Is E-23 the Most Important AI Rule Nobody Talks About?

With the federal AI act (AIDA) dead since January 2025, Canada's only binding AI rules live in sector and privacy law. E-23 is the sharpest of them: a prudential regulator telling the country's largest AI adopters exactly how AI models must be inventoried, validated, and monitored. It reaches beyond banks — every fintech and AI vendor selling into a federally regulated institution inherits its requirements through vendor risk management, and its framework doubles as the best available blueprint for AI governance in any Canadian enterprise.

What Changed From the Old E-23?

  • "Model" now explicitly includes AI/ML — not just traditional quantitative and statistical models. Generative AI used in decisions or risk processes is in scope.
  • Third-party and vendor models count. A model you bought is still your model risk — institutions must inventory, assess, and monitor vendor AI, which is how the requirements reach suppliers.
  • Risk-based proportionality. Every model gets a risk rating; controls scale with materiality, so a marketing copy assistant and an underwriting model are governed differently — but both are governed.
  • Full lifecycle expectations — design, independent review, deployment, ongoing monitoring for drift and performance, and orderly decommissioning.

How Should You Prepare in 2026?

  1. Build the AI/model inventory now — including shadow AI: the departmental ChatGPT workflows and vendor tools nobody registered. This is the longest, least glamorous task.
  2. Risk-rate what you find — materiality of decisions, customer impact, data sensitivity — and match controls to the rating.
  3. Formalize lifecycle checkpoints — who validates a model before deployment, who monitors it, what triggers re-validation or retirement.
  4. Fix vendor contracts — documentation, performance evidence, and change-notification clauses for every AI supplier.
  5. Assign accountable owners — E-23 expects named accountability, not a committee with no throat to choke.

For the broader rulebook that applies alongside E-23 — PIPEDA, Quebec Law 25, and provincial rules — see the Canadian AI compliance hub and our AI governance guide for regulated industries.

Frequently Asked Questions

What is OSFI Guideline E-23?

E-23 is the Office of the Superintendent of Financial Institutions' guideline on model risk management. The finalized version, published in 2025 with an effective date of May 1, 2027, sets expectations for how federally regulated financial institutions govern models across their whole lifecycle — and it explicitly expands the definition of "model" to include AI and machine learning, including third-party and vendor models.

Who does E-23 apply to?

Federally regulated financial institutions (FRFIs): banks, federally incorporated trust and loan companies, and insurance companies. If you are a fintech, MGA, or service provider selling AI-powered products to those institutions, E-23 reaches you indirectly — your FRFI clients must treat your models as part of their model inventory and will push due-diligence, documentation, and monitoring requirements into your contracts.

Does E-23 cover generative AI like ChatGPT and Claude?

Yes, where they meet the definition of a model used in decision-making or risk processes. E-23's risk-based approach means a customer-facing generative AI assistant or an LLM used in underwriting support needs to be inventoried, risk-rated, and governed proportionally to its materiality — the same lifecycle discipline as a credit-scoring model, scaled to the risk.

What does E-23 actually require?

Four pillars: an enterprise-wide model inventory (know every model in use, including vendor AI), risk ratings for each model driving proportionate controls, lifecycle management (design, validation, deployment, ongoing monitoring, and decommissioning), and clear governance — accountable owners, independent review, and documentation an examiner can follow.

When do we need to be ready?

The guideline takes effect May 1, 2027. That sounds distant, but building a complete model inventory — including every team's AI tools and vendor models — plus risk-rating and validation processes typically takes 12-18 months in a mid-size institution. 2026 is the preparation window; institutions that start at the deadline will be retrofitting governance onto AI already in production.

We're not a bank — why does E-23 matter to us?

Two reasons. First, if you sell AI-powered software or services into banks or insurers, E-23 compliance requirements will land in your vendor contracts. Second, E-23 is the most concrete AI-governance blueprint any Canadian regulator has published — inventory, risk-rating, lifecycle, accountability — and it is a sensible template for any organization deploying AI at scale, regulated or not.

Get AI insights for Canadian businesses

Weekly tips on ChatGPT, automation, and cost-saving strategies. No spam, unsubscribe anytime.

Related Articles

Security & Compliance

Agentjacking: The New Security Risk in AI Agents

July 16, 2026Read more →
Security & Compliance

Do You Know Where Your AI Comes From? Model Provenance and Why It Matters

July 3, 2026Read more →
Security & Compliance

AI Agents Are Now the #1 Enterprise Security Risk: What Your Business Should Do

June 30, 2026Read more →
AI
ChatGPT.ca Team

AI consultants with 100+ custom GPT builds and automation projects for 50+ Canadian businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.

Stay ahead of AI in Canada

Weekly case studies, new tools, and ROI playbooks for Canadian SMEs. One email, zero spam.