AI Regulation Tracker · OSFI · Guidance

What does OSFI Guideline E-23 say about AI in banking?

Published Sep 11, 2025 · Last reviewed Oct 5, 2026

Guideline E-23 is the Office of the Superintendent of Financial Institutions' (OSFI) final model risk management guideline. OSFI published it on 11 September 2025 and it takes effect for all federally regulated financial institutions, including banks, on 1 May 2027. It revises the 2017 deposit-taking-institutions version of E-23 and extends scope to all models at all FRFIs, with a model definition that expressly includes AI/ML methods. It sets three outcomes (enterprise-wide understanding of model risk, a risk-based approach, and lifecycle governance) and twelve numbered principles, and requires an inventory and risk rating for every model with non-negligible risk, including vendor and third-party models. It is supervisory guidance rather than statute, and OSFI states it applies in proportion to the institution's size and risk.

OFFICIAL TEXT: osfi-bsif.gc.ca ↗ · FINAL · APPLIES FROM MAY 1, 2027 · OSFI

DocumentOSFI Guideline E-23 — Guideline E-23 – Model Risk Management (2027)
Issued byOffice of the Superintendent of Financial Institutions (Canada) — federal prudential supervisor of banks, insurers, and trust and loan companies; works with the Financial Consumer Agency of Canada (FCAC) on consumer protection
TypeGuidance
StatusFinal · applies from May 1, 2027
PublishedSep 11, 2025
EffectiveMay 1, 2027
Applies toAll federally regulated financial institutions (FRFIs) in Canada: banks, foreign bank branches (to the extent consistent with Guideline E-4), life insurance and fraternal companies, property and casualty companies, and trust and loan companies. Banks are fully in scope. The guideline applies on a risk basis, proportional to an institution's size, strategy, risk profile, nature, scope and complexity of operations, and interconnectedness
Official sourceosfi-bsif.gc.ca ↗
Use casesModel risk management · Credit scoring & underwriting · Generative & agentic AI · Third-party & vendor AI · AI governance (general)

What are the key points of OSFI Guideline E-23?

  • Three outcomes: (1) model risk is well understood and managed across the enterprise, (2) model risk is managed using a risk-based approach, (3) model governance covers the entire model lifecycle. Principles are numbered 1.1 to 1.3, 2.1 to 2.3 and 3.1 to 3.6.
  • Section A.4 defines a model as 'an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI/ML methods, which processes input data to generate results'. OSFI kept the definition deliberately broad after stakeholders asked for it to be narrowed.
  • Principle 2.1 requires institutions to identify and track all models in use or recently decommissioned, including vendor and third-party models; only models with non-negligible inherent risk go into the model inventory, and Appendix 1 lists the minimum fields (for example model ID, risk rating, owner, developer, origin, version, dependencies, data sources, limitations, next review date).
  • Principle 2.2 requires a model risk rating based on inherent risk, using quantitative and qualitative factors including 'model complexity or level of autonomy', reliability of data inputs and customer impacts; externally developed models are rated on a standalone basis.
  • Principle 2.3 ties the frequency and intensity of review, documentation, approval authority, monitoring and re-rating to the risk rating, and says the 'extensive use of advanced AI/ML techniques should have correspondingly mature governance and oversight'.
  • Principle 3.2 on model data requires data that is accurate, relevant and representative, compliant, traceable and timely, and flags that AI/ML models 'can easily mirror unwarranted data relationships'; Principle 3.3 requires explainability requirements that vary with purpose, autonomy, regulation and customer impact.
  • Principle 3.4 requires review independent of development, with specific attention to AI/ML methods, explainability and third-party models; Principle 3.6 requires monitoring for AI/ML 'autonomous decision making, autonomous re-parametrization, and the elevated potential for model drift', plus contingency plans and decommissioning standards.
  • Third-party models fall under the MRM framework (Principle 1.2, 'pursuant to our Guideline B-10') and OSFI's response letter says institutions must also ensure third-party models receive validation and monitoring commensurate to model risk; OSFI declined to add a grace period for validating third-party model updates.

What did OSFI Guideline E-23 change for banks?

The 2017 Guideline E-23 covered enterprise-wide model risk at deposit-taking institutions. The 2027 version applies to all models at all FRFIs, names AI/ML in the model definition, adds explainability, bias, data-governance and self-learning-model expectations, and moves to a risk-rating and inventory approach with proportional application. Canada's banks now have a published date (1 May 2027) to have AI/ML models inventoried, rated, reviewed and monitored under a single framework. OSFI had consulted on a draft from 20 November 2023 to 22 March 2024 and lengthened the proposed implementation period from twelve months to May 2027.

What does OSFI Guideline E-23 require of banks?

OSFI Guideline E-23 (Model Risk Management, 2027) expects each federally regulated bank to run an enterprise-wide model risk management (MRM) framework from 1 May 2027. The framework must identify every model in use, including AI/ML and vendor models, keep an inventory of those with non-negligible inherent risk, assign each a risk rating that drives the depth of review, documentation, approval and monitoring, and govern the whole lifecycle from design and data through independent review, deployment, monitoring and decommissioning. The guideline sets three outcomes and principles 1.1 to 3.6, applies proportionally to the institution's size and complexity, and singles out explainability, bias, self-learning behaviour, model drift and third-party black-box models for specific attention. It is guidance, not statute, and OSFI's own letter says only models that carry risk to the institution need full lifecycle governance.

RuleAuthorityWhat it requiresApplies
Principles 1.1 to 1.3 — Enterprise-wide MRMOSFISenior management defines MRM roles and accountability, staffs MRM with the skills needed 'particularly for novel technologies, like AI', reports model risk to the board, maintains an MRM framework aligned to risk appetite (including externally sourced models under B-10), and deploys models only where they meaningfully contribute to decisions.Effective 1 May 2027
Principle 2.1 — Model identification and inventoryOSFIPeriodically identify all models in use or recently decommissioned, including vendor and third-party models, triage for non-negligible inherent risk, and keep an accurate enterprise-level inventory with the Appendix 1 fields.Effective 1 May 2027
Principle 2.2 — Model risk ratingOSFIAssign every model a rating from quantitative and qualitative factors (including level of autonomy and customer impact), review it on trigger events, and rate externally developed models on a standalone basis.Effective 1 May 2027
Principle 2.3 — Risk management intensityOSFILet the inherent risk rating set the frequency and scope of review, documentation, approval authority, monitoring and re-rating, and make governance of advanced AI/ML 'correspondingly mature'.Effective 1 May 2027
Principle 3.1 — Policies, procedures and controlsOSFIMaintain documented lifecycle policies with defined stakeholder responsibilities, independence and flexibility for evolving technology, particularly given the opaque, 'black box' and autonomous nature of many AI/ML models.Effective 1 May 2027
Principle 3.2 — Model dataOSFIUse data that is accurate, relevant and representative, compliant, traceable and timely; run data-quality checks and document the provenance of synthetic and proxy data.Effective 1 May 2027
Principle 3.3 — Model developmentOSFISet standards for documentation, methodology and data selection, explainability (varying with purpose, autonomy, regulation and customer impact), performance criteria and monitoring criteria.Effective 1 May 2027
Principle 3.4 — Model review and approvalOSFIReview models independently of development for conceptual soundness, data, explainability, novel AI/ML methods and third-party components, and record the approval decision and residual-risk assessment.Effective 1 May 2027
Principles 3.5 and 3.6 — Deployment, monitoring and decommissionOSFIDeploy under change control, assess cyber and operational risks before go-live, monitor performance, drift and operational factors (including AI/ML autonomous re-parametrization), plan for model failure, and decommission with stakeholder notice and retention of the retired model.Effective 1 May 2027

E-23 is the model risk anchor of OSFI's AI position. OSFI has no separate AI rulebook for banks: its September 2024 OSFI-FCAC risk report says its frameworks on model risk, third-party risk, cybersecurity and operational resilience are technology-neutral and already cover AI, and its 2026 technology risk bulletins on frontier and generative and agentic AI point institutions back to E-23, B-10, B-13 and E-21. The July 2026 bulletin explicitly refers institutions to E-23 for 'enterprise-wide model risk management' expectations where AI models heighten model risk.

Scope is the main change from the 2017 version. OSFI says it left the definition of a model 'intentionally broad' and, asked whether low-risk generative AI uses such as document summarisation can be excluded from high-risk requirements, answered that institutions are 'empowered to make risk-intelligent decisions' when setting model risk ratings. Only models carrying non-negligible risk must be stored in the inventory and subjected to full lifecycle governance, so the practical workload depends on the rating methodology the bank builds. On third-party models, OSFI's letter says institutions should follow B-10 principles and ensure third-party models receive validation and monitoring commensurate to their risk, and that an exceptions policy may permit limited, specific use before validation is complete.

E-23 sits alongside, not above, the other OSFI guidelines it cross-refers to: B-10 for third parties, and B-13 and E-21 for technology, cyber and operational risks assessed before deployment (Principle 3.5). Internationally, it is the Canadian counterpart of the PRA's SS1/23 and, like SS1/23, treats AI as a model-risk question inside one framework, but unlike SS1/23 it names AI/ML in the definition.

WHAT THIS MEANS IN PRACTICE

  • Build the inventory first: survey every business line, including areas that never used models before, and capture vendor and embedded generative AI tools, then triage for non-negligible risk.
  • Define a model risk rating methodology that includes autonomy, explainability needs, data reliability and customer impact, and document how low-risk AI uses are exempted and tracked.
  • Set explainability and bias-testing standards per rating tier, and decide in advance how self-learning models are judged to have 'materially changed'.
  • Bring vendor models into scope: validate and monitor them commensurate with risk, link the work to B-10 third-party reviews, and settle an exceptions policy for models used before validation is complete.
  • Plan against 1 May 2027: run a gap assessment now, prioritise high-risk models, and include model-failure contingency plans and decommissioning standards in the framework.

When does OSFI Guideline E-23 take effect?

OSFI published the final Guideline E-23 on 11 September 2025 and states that it takes effect for all federally regulated financial institutions on 1 May 2027. OSFI's response letter says the date was extended from the twelve months proposed in the draft because stakeholders asked for more time, and that many institutions had already started work on the reforms.

Does OSFI Guideline E-23 apply to AI and machine learning models?

Yes. The model definition in section A.4 expressly includes AI/ML methods, the overview cites the 'surge in artificial intelligence / machine learning (AI/ML) models', and several principles carry AI-specific expectations on explainability, bias, data, self-learning models and monitoring for drift. OSFI refers to the OECD definition of an AI system for the purposes of the guideline.

Does Guideline E-23 apply to banks?

Yes. Banks and foreign bank branches are listed in the sector field, and the scope covers all FRFIs. It applies on a risk basis proportional to size, strategy, risk profile, complexity and interconnectedness, so a smaller bank with few models is expected to do less than a large bank with extensive AI/ML use.

Is OSFI Guideline E-23 binding, and what happens if a bank does not comply?

E-23 is a principles-based supervisory guideline that sets out OSFI's expectations; it is not a statute or regulation, and the text does not set penalties. OSFI uses its guidelines in supervision, so an institution that falls short should expect supervisory follow-up rather than a fixed fine specified in the guideline.

How does E-23 compare with the PRA's SS1/23?

Both are principles-based model risk standards covering inventory, tiering or rating, validation, monitoring and third-party models. E-23 names AI/ML in its model definition and in several principles, whereas SS1/23 does not use the words 'artificial intelligence' or 'machine learning' and reaches AI through its general tiering and dynamic-model provisions. E-23 applies to all FRFIs on a proportional basis; SS1/23 applies formally to UK banks with internal-model approval.

DateDocumentStatus
Mar 23, 2026OSFI FIFAI II report (AGILE framework) — FIFAI II: AI Risks and Opportunities: Adopting an AGILE Framework in Canadian Financial ServicesFinal
Sep 24, 2024OSFI-FCAC AI Risk Report (2024) — OSFI-FCAC Risk Report - AI Uses and Risks at Federally Regulated Financial InstitutionsFinal
Apr 24, 2023OSFI Guideline B-10 — Third-Party Risk Management GuidelineIn force
Jul 24, 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)In force
Jun 24, 2026RBI draft Guidance on Regulatory Principles for Model Risk Management — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments)Proposed
Jun 10, 2026FSB AI sound practices consultation (June 2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation reportProposed

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning