# OSFI Guideline E-23: Guideline E-23 – Model Risk Management (2027)

Source: https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23
Last updated: Oct 5, 2026

Guideline E-23 is the Office of the Superintendent of Financial Institutions' (OSFI) final model risk management guideline. OSFI published it on 11 September 2025 and it takes effect for all federally regulated financial institutions, including banks, on 1 May 2027. It revises the 2017 deposit-taking-institutions version of E-23 and extends scope to all models at all FRFIs, with a model definition that expressly includes AI/ML methods. It sets three outcomes (enterprise-wide understanding of model risk, a risk-based approach, and lifecycle governance) and twelve numbered principles, and requires an inventory and risk rating for every model with non-negligible risk, including vendor and third-party models. It is supervisory guidance rather than statute, and OSFI states it applies in proportion to the institution's size and risk.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) |
| Type | Guidance |
| Status | Final · applies from May 1, 2027 |
| Published | Sep 11, 2025 |
| Effective | May 1, 2027 |
| Applies to | All federally regulated financial institutions (FRFIs) in Canada: banks, foreign bank branches (to the extent consistent with Guideline E-4), life insurance and fraternal companies, property and casualty companies, and trust and loan companies. Banks are fully in scope. The guideline applies on a risk basis, proportional to an institution's size, strategy, risk profile, nature, scope and complexity of operations, and interconnectedness |
| Official text | https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027 |

## Key points

- Three outcomes: (1) model risk is well understood and managed across the enterprise, (2) model risk is managed using a risk-based approach, (3) model governance covers the entire model lifecycle. Principles are numbered 1.1 to 1.3, 2.1 to 2.3 and 3.1 to 3.6.
- Section A.4 defines a model as 'an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI/ML methods, which processes input data to generate results'. OSFI kept the definition deliberately broad after stakeholders asked for it to be narrowed.
- Principle 2.1 requires institutions to identify and track all models in use or recently decommissioned, including vendor and third-party models; only models with non-negligible inherent risk go into the model inventory, and Appendix 1 lists the minimum fields (for example model ID, risk rating, owner, developer, origin, version, dependencies, data sources, limitations, next review date).
- Principle 2.2 requires a model risk rating based on inherent risk, using quantitative and qualitative factors including 'model complexity or level of autonomy', reliability of data inputs and customer impacts; externally developed models are rated on a standalone basis.
- Principle 2.3 ties the frequency and intensity of review, documentation, approval authority, monitoring and re-rating to the risk rating, and says the 'extensive use of advanced AI/ML techniques should have correspondingly mature governance and oversight'.
- Principle 3.2 on model data requires data that is accurate, relevant and representative, compliant, traceable and timely, and flags that AI/ML models 'can easily mirror unwarranted data relationships'; Principle 3.3 requires explainability requirements that vary with purpose, autonomy, regulation and customer impact.
- Principle 3.4 requires review independent of development, with specific attention to AI/ML methods, explainability and third-party models; Principle 3.6 requires monitoring for AI/ML 'autonomous decision making, autonomous re-parametrization, and the elevated potential for model drift', plus contingency plans and decommissioning standards.
- Third-party models fall under the MRM framework (Principle 1.2, 'pursuant to our Guideline B-10') and OSFI's response letter says institutions must also ensure third-party models receive validation and monitoring commensurate to model risk; OSFI declined to add a grace period for validating third-party model updates.

## What changed for banks

The 2017 Guideline E-23 covered enterprise-wide model risk at deposit-taking institutions. The 2027 version applies to all models at all FRFIs, names AI/ML in the model definition, adds explainability, bias, data-governance and self-learning-model expectations, and moves to a risk-rating and inventory approach with proportional application. Canada's banks now have a published date (1 May 2027) to have AI/ML models inventoried, rated, reviewed and monitored under a single framework. OSFI had consulted on a draft from 20 November 2023 to 22 March 2024 and lengthened the proposed implementation period from twelve months to May 2027.

## Use cases it governs

- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)
- [Credit scoring & underwriting](https://www.bankingnewsai.com/ai-regulation/by-use-case#credit-underwriting)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)

## What does OSFI Guideline E-23 require of banks?

OSFI Guideline E-23 (Model Risk Management, 2027) expects each federally regulated bank to run an enterprise-wide model risk management (MRM) framework from 1 May 2027. The framework must identify every model in use, including AI/ML and vendor models, keep an inventory of those with non-negligible inherent risk, assign each a risk rating that drives the depth of review, documentation, approval and monitoring, and govern the whole lifecycle from design and data through independent review, deployment, monitoring and decommissioning. The guideline sets three outcomes and principles 1.1 to 3.6, applies proportionally to the institution's size and complexity, and singles out explainability, bias, self-learning behaviour, model drift and third-party black-box models for specific attention. It is guidance, not statute, and OSFI's own letter says only models that carry risk to the institution need full lifecycle governance.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Principles 1.1 to 1.3 — Enterprise-wide MRM | [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) | Senior management defines MRM roles and accountability, staffs MRM with the skills needed 'particularly for novel technologies, like AI', reports model risk to the board, maintains an MRM framework aligned to risk appetite (including externally sourced models under B-10), and deploys models only where they meaningfully contribute to decisions. | Effective 1 May 2027 | [OSFI Guideline E-23](https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23) |
| Principle 2.1 — Model identification and inventory | [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) | Periodically identify all models in use or recently decommissioned, including vendor and third-party models, triage for non-negligible inherent risk, and keep an accurate enterprise-level inventory with the Appendix 1 fields. | Effective 1 May 2027 | [OSFI Guideline E-23](https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23) |
| Principle 2.2 — Model risk rating | [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) | Assign every model a rating from quantitative and qualitative factors (including level of autonomy and customer impact), review it on trigger events, and rate externally developed models on a standalone basis. | Effective 1 May 2027 | [OSFI Guideline E-23](https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23) |
| Principle 2.3 — Risk management intensity | [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) | Let the inherent risk rating set the frequency and scope of review, documentation, approval authority, monitoring and re-rating, and make governance of advanced AI/ML 'correspondingly mature'. | Effective 1 May 2027 | [OSFI Guideline E-23](https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23) |
| Principle 3.1 — Policies, procedures and controls | [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) | Maintain documented lifecycle policies with defined stakeholder responsibilities, independence and flexibility for evolving technology, particularly given the opaque, 'black box' and autonomous nature of many AI/ML models. | Effective 1 May 2027 | [OSFI Guideline E-23](https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23) |
| Principle 3.2 — Model data | [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) | Use data that is accurate, relevant and representative, compliant, traceable and timely; run data-quality checks and document the provenance of synthetic and proxy data. | Effective 1 May 2027 | [OSFI Guideline E-23](https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23) |
| Principle 3.3 — Model development | [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) | Set standards for documentation, methodology and data selection, explainability (varying with purpose, autonomy, regulation and customer impact), performance criteria and monitoring criteria. | Effective 1 May 2027 | [OSFI Guideline E-23](https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23) |
| Principle 3.4 — Model review and approval | [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) | Review models independently of development for conceptual soundness, data, explainability, novel AI/ML methods and third-party components, and record the approval decision and residual-risk assessment. | Effective 1 May 2027 | [OSFI Guideline E-23](https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23) |
| Principles 3.5 and 3.6 — Deployment, monitoring and decommission | [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) | Deploy under change control, assess cyber and operational risks before go-live, monitor performance, drift and operational factors (including AI/ML autonomous re-parametrization), plan for model failure, and decommission with stakeholder notice and retention of the retired model. | Effective 1 May 2027 | [OSFI Guideline E-23](https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23) |

E-23 is the model risk anchor of OSFI's AI position. OSFI has no separate AI rulebook for banks: its September 2024 OSFI-FCAC risk report says its frameworks on model risk, third-party risk, cybersecurity and operational resilience are technology-neutral and already cover AI, and its 2026 technology risk bulletins on frontier and generative and agentic AI point institutions back to E-23, B-10, B-13 and E-21. The July 2026 bulletin explicitly refers institutions to E-23 for 'enterprise-wide model risk management' expectations where AI models heighten model risk.

Scope is the main change from the 2017 version. OSFI says it left the definition of a model 'intentionally broad' and, asked whether low-risk generative AI uses such as document summarisation can be excluded from high-risk requirements, answered that institutions are 'empowered to make risk-intelligent decisions' when setting model risk ratings. Only models carrying non-negligible risk must be stored in the inventory and subjected to full lifecycle governance, so the practical workload depends on the rating methodology the bank builds. On third-party models, OSFI's letter says institutions should follow B-10 principles and ensure third-party models receive validation and monitoring commensurate to their risk, and that an exceptions policy may permit limited, specific use before validation is complete.

E-23 sits alongside, not above, the other OSFI guidelines it cross-refers to: B-10 for third parties, and B-13 and E-21 for technology, cyber and operational risks assessed before deployment (Principle 3.5). Internationally, it is the Canadian counterpart of the PRA's SS1/23 and, like SS1/23, treats AI as a model-risk question inside one framework, but unlike SS1/23 it names AI/ML in the definition.

### What this means in practice

- Build the inventory first: survey every business line, including areas that never used models before, and capture vendor and embedded generative AI tools, then triage for non-negligible risk.
- Define a model risk rating methodology that includes autonomy, explainability needs, data reliability and customer impact, and document how low-risk AI uses are exempted and tracked.
- Set explainability and bias-testing standards per rating tier, and decide in advance how self-learning models are judged to have 'materially changed'.
- Bring vendor models into scope: validate and monitor them commensurate with risk, link the work to B-10 third-party reviews, and settle an exceptions policy for models used before validation is complete.
- Plan against 1 May 2027: run a gap assessment now, prioritise high-risk models, and include model-failure contingency plans and decommissioning standards in the framework.

## FAQ

### When does OSFI Guideline E-23 take effect?

OSFI published the final Guideline E-23 on 11 September 2025 and states that it takes effect for all federally regulated financial institutions on 1 May 2027. OSFI's response letter says the date was extended from the twelve months proposed in the draft because stakeholders asked for more time, and that many institutions had already started work on the reforms.

### Does OSFI Guideline E-23 apply to AI and machine learning models?

Yes. The model definition in section A.4 expressly includes AI/ML methods, the overview cites the 'surge in artificial intelligence / machine learning (AI/ML) models', and several principles carry AI-specific expectations on explainability, bias, data, self-learning models and monitoring for drift. OSFI refers to the OECD definition of an AI system for the purposes of the guideline.

### Does Guideline E-23 apply to banks?

Yes. Banks and foreign bank branches are listed in the sector field, and the scope covers all FRFIs. It applies on a risk basis proportional to size, strategy, risk profile, complexity and interconnectedness, so a smaller bank with few models is expected to do less than a large bank with extensive AI/ML use.

### Is OSFI Guideline E-23 binding, and what happens if a bank does not comply?

E-23 is a principles-based supervisory guideline that sets out OSFI's expectations; it is not a statute or regulation, and the text does not set penalties. OSFI uses its guidelines in supervision, so an institution that falls short should expect supervisory follow-up rather than a fixed fine specified in the guideline.

### How does E-23 compare with the PRA's SS1/23?

Both are principles-based model risk standards covering inventory, tiering or rating, validation, monitoring and third-party models. E-23 names AI/ML in its model definition and in several principles, whereas SS1/23 does not use the words 'artificial intelligence' or 'machine learning' and reaches AI through its general tiering and dynamic-model provisions. E-23 applies to all FRFIs on a proportional basis; SS1/23 applies formally to UK banks with internal-model approval.

## Related documents

- [OSFI FIFAI II report (AGILE framework)](https://www.bankingnewsai.com/ai-regulation/documents/osfi-fifai-report-2026) — FIFAI II: AI Risks and Opportunities: Adopting an AGILE Framework in Canadian Financial Services (Mar 23, 2026)
- [OSFI-FCAC AI Risk Report (2024)](https://www.bankingnewsai.com/ai-regulation/documents/osfi-fcac-ai-risk-report-2024) — OSFI-FCAC Risk Report - AI Uses and Risks at Federally Regulated Financial Institutions (Sep 24, 2024)
- [OSFI Guideline B-10](https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-b-10) — Third-Party Risk Management Guideline (Apr 24, 2023)
- [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://www.bankingnewsai.com/ai-regulation/documents/eu-digital-omnibus-ai-regulation-2026-1744) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (Jul 24, 2026)
- [RBI draft Guidance on Regulatory Principles for Model Risk Management](https://www.bankingnewsai.com/ai-regulation/documents/rbi-model-risk-management-guidance-2026) — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments) (Jun 24, 2026)
- [FSB AI sound practices consultation (June 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-ai-sound-practices-consultation-2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report (Jun 10, 2026)
- [2026 BoE/FCA AI survey](https://www.bankingnewsai.com/ai-regulation/documents/uk-ai-in-financial-services-survey-2026) — The Bank of England and FCA's 2026 AI Survey (Jun 5, 2026)
- [Hill House oversight testimony (Jun 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fdic-testimony-oversight-prudential-regulators-2026) — Statement of Chairman Travis Hill: Oversight of Prudential Regulators (Jun 4, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/osfi-guideline-e-23
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
