The OSFI-FCAC Risk Report on AI uses and risks, published on 24 September 2024 by the Office of the Superintendent of Financial Institutions and the Financial Consumer Agency of Canada, is the regulators' joint survey of how Canadian federally regulated financial institutions use AI and what risks follow. It reports that about 30% of institutions used AI in 2019, about 50% in 2023, and 70% expected to by 2026, and it groups the risks into internal (data governance, model risk and explainability, legal and reputational, third-party, operational and cyber) and external (cyber and fraud, business, credit, market and liquidity). It is not guidance and creates no new obligations; the regulators say their existing technology-neutral guidance on model risk, third-party risk, cybersecurity and operational resilience already applies to AI.
OFFICIAL TEXT: osfi-bsif.gc.ca ↗ · FINAL · OSFI
| Document | OSFI-FCAC AI Risk Report (2024) — OSFI-FCAC Risk Report - AI Uses and Risks at Federally Regulated Financial Institutions |
| Issued by | Office of the Superintendent of Financial Institutions (Canada) — federal prudential supervisor of banks, insurers, and trust and loan companies; works with the Financial Consumer Agency of Canada (FCAC) on consumer protection |
| Type | Report |
| Status | Final |
| Published | Sep 24, 2024 |
| Applies to | Federally regulated financial institutions in Canada, including banks. It is a risk report, not guidance: OSFI and FCAC say the practices it describes 'are not meant to serve as guidance'. It draws on the December 2023 OSFI-FCAC voluntary questionnaire on AI and quantum computing preparedness |
| Official source | osfi-bsif.gc.ca ↗ |
| Use cases | Model risk management · Third-party & vendor AI · Cybersecurity · Generative & agentic AI · Data & privacy · AI governance (general) |
What are the key points of OSFI-FCAC AI Risk Report (2024)?
- Source data is the AI/Quantum questionnaire OSFI and FCAC sent in December 2023; the report also draws on external publications.
- Adoption: approximately 30% of institutions used AI in 2019 and 50% in 2023, with 70% expected to by 2026; 75% of responding institutions plan to invest in AI over the next three years.
- Top AI use cases are operational efficiency, customer engagement, document creation and fraud detection; the top risks respondents cite are data privacy and security, model risk, legal risk and business risk.
- Section 3.1 (data governance) says data-related risks are viewed as a top concern, spanning data privacy, governance and quality; section 3.2 says AI model risk is elevated by complexity and opacity and that gen AI is harder to explain than traditional ML.
- Section 3.4 (third-party risks) says most institutions rely on third-party providers for AI models and systems, flags concentration risk and cloud dependency, and says institutions are responsible for the results of third-party AI systems used to sell or promote their products and services.
- Section 3.5 and section 4 cover operational and cybersecurity risks, including data poisoning, data leakage, evasion attacks and model extraction, and external threats from generative AI such as deepfakes, synthetic identities and AI-written phishing.
- Section 4.4 notes possible credit, market and liquidity effects, including AI-driven herding in trading and AI agents moving deposits; section 5 warns that risk management can lag the pace of AI adoption and that managing AI only inside individual risk frameworks leaves gaps.
- The regulators state that their existing guidance on model risk, third-party risk, cybersecurity and operational resilience is technology-neutral and applies; the practices listed are not meant to serve as guidance.
What did OSFI-FCAC AI Risk Report (2024) change for banks?
It is the regulators' joint statement of AI risk on the evidence of an industry questionnaire, and it preceded the final Guideline E-23 (September 2025), the FIFAI II report (March 2026) and the 2026 technology risk bulletins on frontier and generative AI. For banks it is the clearest statement of what OSFI expects supervisors to ask about, while creating no new obligations.
What does the OSFI-FCAC AI risk report expect of banks?
The OSFI-FCAC Risk Report of 24 September 2024 sets no new obligations, but it tells banks what the two regulators will treat as the main AI risks and which existing guidance applies. It groups internal AI risks into data governance, model risk and explainability, legal, ethical and reputational risk, third-party risk, and operational and cyber risk, and external risks into cyber and fraud threats, business and strategic risk, and credit, market and liquidity effects. It warns that risk management can lag AI adoption, that addressing AI only inside separate risk frameworks leaves gaps, and that institutions remain responsible for the results of third-party AI systems. The regulators say their existing technology-neutral guidance on model risk, third-party risk, cybersecurity and operational resilience applies, and that the practices in the report are 'not meant to serve as guidance'.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Section 3.1 — Data governance risks | OSFI | Treat data privacy, governance and quality as a top AI concern across the data lifecycle, and set standards for the fidelity of any synthetic data used in AI systems. | Published 24 September 2024 |
| Section 3.2 — Model risk and explainability | OSFI | Make AI models explainable enough to inform users, customers, compliance and governance, recognising that gen AI is harder to explain than traditional ML. | Published 24 September 2024 |
| Section 3.3 — Legal, ethical and reputational risks | OSFI | Prioritise consumer privacy and consent, disclose when AI affects customers, proactively assess bias, and take responsibility for bias in third-party models. | Published 24 September 2024 |
| Section 3.4 — Third-party risks | OSFI | Manage concentration, cloud and open-source dependencies; ensure third-party AI activity meets the institution's own standards; and answer for the results of third-party AI systems used to sell or promote products. | Published 24 September 2024 |
| Section 3.5 — Operational and cybersecurity risks | OSFI | Apply robust safeguards around AI systems against data poisoning, data leakage, evasion attacks and model extraction, and plan for AI malfunctions that quickly become financial risks. | Published 24 September 2024 |
| Section 5 — Pitfalls in AI risk management | OSFI | Keep risk governance in step with adoption, bring business lines not traditionally under model governance into scope, and avoid managing AI risk only inside individual risk frameworks. | Published 24 September 2024 |
| Guideline E-23 — Model Risk Management (2027) | OSFI | The finalised OSFI model risk guideline that follows from the report's model risk findings and covers AI/ML explicitly. | Effective 1 May 2027 |
The report is an early building block of OSFI's AI position. Its executive summary says OSFI and FCAC are 'monitoring the evolving risk landscape and advocating for responsible AI adoption', cites the 2022 FIFAI EDGE principles (Explainability, Data, Governance, Ethics), and acknowledges Government of Canada AI codes of conduct and directives that apply to the use of AI in finance.
Its value for banks is as a supervisory preview. The 2026 FIFAI II report cites it for the finding that data-related risks are a 'top concern', and the 2026 OSFI technology bulletins on frontier and generative and agentic AI build on its third-party, cyber and operational themes. Consumer-protection consequences sit with FCAC's own legal framework, which the report mentions without restating.
WHAT THIS MEANS IN PRACTICE
- Use the report's risk taxonomy as a checklist when mapping AI use cases to your enterprise risk framework, so AI risk is not owned only by model risk or cyber.
- Document who is accountable for AI used in business lines that were never subject to model governance.
- Assess third-party AI providers for concentration, cloud outage exposure and open-source components, and record what you can and cannot verify about their models.
- Decide how you test for bias given the data dilemma the report describes, and how you disclose AI use to customers.
Is the OSFI-FCAC AI risk report binding?
No. The report says the mitigation practices it presents are not meant to serve as guidance. It does state that OSFI's and FCAC's existing frameworks, including guidance on model risk, third-party risk, cybersecurity and operational resilience, are technology-neutral and already cover many prudential areas that AI affects.
What does the OSFI-FCAC report say about AI adoption at Canadian financial institutions?
Based on the AI/Quantum questionnaire, about 30% of institutions used AI in 2019 and about 50% in 2023, with 70% expected to use it by 2026. The top use cases are operational efficiency, customer engagement, document creation and fraud detection, and most institutions rely on third parties for AI solutions.
Does the OSFI-FCAC report apply to banks?
It addresses federally regulated financial institutions, which includes banks. Deposit-taking institutions are named as expanding AI use in algorithmic trading, liquidity management, credit risk and compliance monitoring, and fraud detection is cited as a top application for many of them.
How does the report relate to OSFI Guideline E-23?
The report identified model risk and explainability as heightened by AI and pointed to existing model risk guidance. OSFI then published the final Guideline E-23 on 11 September 2025, effective 1 May 2027, which names AI/ML in its model definition and sets explicit expectations for explainability, data and monitoring.
| Date | Document | Status |
|---|---|---|
| Mar 23, 2026 | OSFI FIFAI II report (AGILE framework) — FIFAI II: AI Risks and Opportunities: Adopting an AGILE Framework in Canadian Financial Services | Final |
| Sep 11, 2025 | OSFI Guideline E-23 — Guideline E-23 – Model Risk Management (2027) | Final |
| Apr 24, 2023 | OSFI Guideline B-10 — Third-Party Risk Management Guideline | In force |
| Jul 24, 2026 | Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) | In force |
| Jun 24, 2026 | RBI draft Guidance on Regulatory Principles for Model Risk Management — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments) | Proposed |
| Jun 10, 2026 | FSB AI sound practices consultation (June 2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report | Proposed |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning