Canada - Model Risk Management (E-23)
Guideline E-23 — Model Risk Management (Office of the Superintendent of Financial Institutions) (final)
Canada
RAI-CA-NA-EMRMOXX-2025Guideline E-23 (final) sets OSFI’s principles-based expectations for enterprise-wide model risk management for federally regulated financial institutions. Published on September 11, 2025, it expands the scope of covered models (explicitly including AI/ML and non-quantitative models), requires a risk-based, proportionate approach, and becomes effective May 1, 2027.
Summary
Read full text ↗Plain English
Overview
Guideline E-23 — Model Risk Management (final) (published by the Office of the Superintendent of Financial Institutions on September 11, 2025) establishes OSFI’s expectations for effective enterprise-wide model risk management (MRM) across federally regulated financial institutions. The document updates the prior E-23 content to reflect the increasing use of artificial intelligence and machine learning (AI/ML) and to broaden the definition of "model" to any system that "processes input data to generate results," thereby covering both quantitative and non-quantitative applications. OSFI frames the guidance as principles-based and risk-proportionate, focusing on governance, lifecycle controls, independent review, data quality, monitoring, and third-party oversight. For the official text, see Guideline E-23 – Model Risk Management (2027) and the accompanying backgrounder at OSFI backgrounder. The guideline sets an effective date of May 1, 2027, to provide an 18‑month transition period for institutions to implement proportional changes to their MRM frameworks.
Definitions
Key terms in E-23 include: "Model" — an application of theoretical, empirical, judgmental assumptions or statistical techniques (including AI/ML) that processes input data to generate results; "Model risk" — risk of adverse outcomes (financial, operational, reputational, legal) from model design, development, deployment or use; "Model inventory" — enterprise-level register of models with non-negligible risk; "Model lifecycle" — the stages of model development, validation, approval, deployment, monitoring and decommissioning; "Model stakeholders" — business, control functions, and others with a legitimate interest in the model’s design, use and oversight. E-23 adopts a risk-based and proportional lens — not all analytical artifacts must be governed with the same intensity; the institution triages models to determine which carry non-negligible inherent model risk and therefore merit full lifecycle governance.
Governance and Institutional Framework
OSFI requires clear governance structures for model risk at the board, senior management, and operational levels. Boards are expected to oversee model risk through risk committees or equivalent and to ensure that senior management puts in place appropriate policies, roles, and responsibilities. Senior management must maintain an enterprise MRM framework, a model inventory, escalation and approval processes for model changes, and resource allocation consistent with model risk. The guideline emphasizes functional separation between developers, owners and independent reviewers (model validation), and requires documented accountability assignments (model owners, model developers, model reviewers). Where relevant, institutions must integrate MRM into broader risk management, compliance and internal control frameworks and reflect the institution’s strategy and risk appetite. For OSFI’s official guidance on scope and governance, see Guideline E-23 (2027) and the explanatory letter to industry.
Key Focus Areas
OSFI’s final Guideline sets expectations across several interdependent focus areas: (1) Model identification and inventory — institutions must identify and maintain an enterprise inventory of models that carry non-negligible inherent risk and capture key metadata (model ID, purpose, owner, developer, origin, version, deployment date, risk rating, approved uses, limitations, review dates, monitoring status and dependencies); (2) Risk-based model classification/rating — institutions must adopt a transparent approach to assigning model risk ratings that reflect complexity, autonomy, data sensitivity, customer impact and systemic interconnectedness; (3) Model lifecycle governance — documented practices for design, development, code controls, testing, independent review/validation, approval (prior to deployment or material changes), production deployment, monitoring, and decommissioning; (4) Independent review and validation — models with non-negligible risk require review by personnel or units independent of development, using testing approaches appropriate to model type and complexity; (5) Data governance — OSFI expects data lineage, quality controls, representativeness checks, and documentation of data sources and preprocessing; (6) Monitoring and performance management — continuous or periodic monitoring plans, performance metrics, and triggers for revalidation or remediation; (7) Third-party and vendor models — due diligence, contractual protections, model access, and oversight for externally sourced or vendor models; (8) AI/ML-specific considerations — attention to model drift, retraining protocols, explainability, fairness, robustness and potential for automation-induced harms; and (9) Reporting and escalation — clear management reporting lines to senior management and the board for material model risks and incidents. These focus areas reflect OSFI’s intent to capture both traditional financial models (capital, provisioning, pricing) and newer risk domains (operational, cyber, climate, HR analytics) where models may influence material outcomes.
Implementation Framework
Implementation is explicitly risk-based and proportionate. Institutions must document their MRM framework and demonstrate how governance, resources and controls scale to model risk. Practical requirements include establishing or updating policies and standards; creating or enhancing a comprehensive model inventory; defining model lifecycle processes (development, testing, review, approval, deployment, monitoring, change management, retirement); assigning accountable owners and independent reviewers; implementing data management practices and repeatable testing frameworks; embedding vendor oversight processes; and integrating MRM metrics into operational and risk reporting. OSFI allows flexibility in process design but expects that approvals are obtained prior to deploying material model changes and following periodic reviews. The guideline recognizes non-production uses and single-run analytic outputs and cautions institutions that such uses may nonetheless carry model risk and therefore could be subject to governance commensurate with their assessed risk.
Monitoring and Evaluation
OSFI requires institutions to implement monitoring frameworks for model performance, stability and use. Monitoring should include quantitative performance metrics (e.g., accuracy, calibration, error distributions), data quality checks, and operational controls (logging, access control). Institutions must define thresholds and trigger events (for example, sustained performance degradation, material change in data, regulatory or business-context changes) that prompt investigation, revalidation, or temporary suspension. Model monitoring results and remediation activities should be documented and reported periodically to senior management and, for material models, to the board. OSFI expects institutions to retain records of tests, validations, issues and remediation activities to support supervisory review.
Penalties, Liability, and Appeals
While Guideline E-23 itself is not primary legislation, non-compliance with OSFI guidance can form the basis for supervisory engagement and enforcement under statutory authorities (Bank Act, Insurance Companies Act, Trust and Loan Companies Act, the OSFI Act and related provisions or administrative monetary penalty regimes as applicable). OSFI retains the authority to require remediation plans, impose operational restrictions, issue directions or conditions, and in cases where statutory penalty regimes apply, administrative monetary penalties. Affected institutions have standard avenues for engagement with OSFI and may contest supervisory findings or directions through established administrative and judicial channels. Institutions should therefore maintain traceable governance and records to support compliance and, where necessary, to demonstrate corrective action to supervisors.
Relationship to Other Instruments
Guideline E-23 complements OSFI’s broader supervisory framework, including other guidance on technology, cyber security, vendor risk, internal controls and the Integrity and Security Guideline. It references established definitions such as the OECD AI definition for AI/ML systems and should be read in concert with sectoral requirements (e.g., capital, liquidity, prudential reporting) and with any institution-specific supervisory expectations. The guideline clarifies interactions with foreign branch requirements (consistent with Guideline E-4 on foreign entities operating on a branch basis) and aligns with OSFI’s enterprise-wide risk appetite and supervisory priorities.
International Alignment
OSFI designed E-23 to reflect international supervisory trends on model and AI governance, including cross-reference to OECD definitions and best-practice principles. The guidance is consistent with a growing body of supervisory work from major jurisdictions that emphasize model inventories, independent validation, lifecycle governance, and AI-specific controls (explainability, bias assessment, robustness). OSFI’s approach aims to enable innovation while protecting prudential safety and to facilitate cross-border supervisory dialogue where models are developed or operated across jurisdictions.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Draft guideline published (public consultation) | 2023-11-20 | Draft updated and open for consultation to March 22, 2024 |
| Final guideline published | 2025-09-11 | Final E-23 published with explanatory letter and backgrounder |
| Transition period | 2025-09-11 to 2027-04-30 | 18-month period for institutions to implement requirements |
| Effective date | 2027-05-01 | All federally regulated financial institutions expected to comply on a proportionate basis |
Compliance Checklist
| Requirement | Compliant (Y/N) | Evidence / Notes |
|---|---|---|
| Maintain enterprise model inventory for non-negligible risk models | List model metadata, versions, owners, risk ratings | |
| Assign model owners and independent reviewers | Organizational charts, role descriptions | |
| Adopt risk-based model rating methodology | Policy documentation | |
| Document model lifecycle processes (dev/test/approve/deploy/monitor) | Standard operating procedures and workflow logs | |
| Implement monitoring, performance thresholds and triggers | Dashboards, monitoring reports, alerts | |
| Apply vendor oversight for third-party models | Vendor contracts, due diligence records | |
| Retain model documentation and validation evidence | Versioned repositories, validation reports |
Sources and References
| Source | Type |
|---|---|
| Guideline E-23 – Model Risk Management (2027) | Primary Source |
| Backgrounder: Guideline E-23 – Model Risk Management | Primary Source |
| Guideline E-23 – Model Risk Management (2027) - Letter | Primary Source |
Canada's financial regulator, the Office of the Superintendent of Financial Institutions (OSFI), has published new expectations for how federally regulated financial institutions must manage the risks associated with their use of models. This guideline, known as E-23, applies to all banks, insurance companies, and other financial entities overseen by OSFI.
The most significant change is a much broader definition of what constitutes a "model." It now explicitly includes artificial intelligence and machine learning (AI/ML) systems, and any application that processes data to generate results, encompassing both quantitative and non-quantitative tools. This means many more systems than before will fall under the new rules. Institutions must adopt a risk-based approach, meaning the intensity of oversight should match the potential risk a model poses.
To comply, institutions must establish clear governance structures, from the board down to operational teams, with distinct roles for model developers, owners, and independent reviewers. They also need to maintain a comprehensive inventory of all models that carry non-negligible risk, detailing their purpose, risk rating, and usage. Furthermore, the guideline requires managing the entire model lifecycle, from design and development through independent validation, approval before deployment, continuous monitoring, and eventual decommissioning. Robust oversight is also crucial for any models sourced from third-party vendors, including due diligence and contractual protections.
This guideline takes effect on May 1, 2027, giving institutions an 18-month transition period to adapt their systems and processes. While E-23 is a guideline, not a law, OSFI can enforce non-compliance through various means, including requiring remediation plans, imposing operational restrictions, or issuing administrative monetary penalties. A practical pitfall to watch out for is that even non-production or single-run analytical tools could be considered "models" if they carry significant risk, requiring appropriate governance.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 15 marked completePlain-English obligations under Canada - Model Risk Management (E-23). Not legal advice — verify against the official text before relying on it.
- #1CriticalGovernance and Institutional Framework⏰ May 1, 2027
Applies to: Boards of federally regulated financial institutions.
“Boards are expected to oversee model risk through risk committees or equivalent.”
- #2CriticalGovernance and Institutional Framework⏰ May 1, 2027
Applies to: Senior management of federally regulated financial institutions.
“Senior management must maintain an enterprise MRM framework.”
- #3CriticalGovernance and Institutional Framework⏰ May 1, 2027
Applies to: Federally regulated financial institutions.
“requires documented accountability assignments (model owners, model developers, model reviewers).”
- #4CriticalKey Focus Areas⏰ May 1, 2027
Applies to: Federally regulated financial institutions.
“institutions must identify and maintain an enterprise inventory of models that carry non-negligible inherent risk.”
- #5CriticalKey Focus Areas⏰ May 1, 2027
Applies to: Federally regulated financial institutions.
“institutions must adopt a transparent approach to assigning model risk ratings.”
- #6CriticalKey Focus Areas⏰ May 1, 2027
Applies to: Federally regulated financial institutions.
“documented practices for design, development, code controls, testing, independent review/validation, approval... monitoring, and decommissioning.”
- #7CriticalKey Focus Areas⏰ May 1, 2027
Applies to: Federally regulated financial institutions.
“models with non-negligible risk require review by personnel or units independent of development.”
- #8CriticalKey Focus Areas / Monitoring and Evaluation⏰ May 1, 2027
Applies to: Federally regulated financial institutions.
“OSFI requires institutions to implement monitoring frameworks for model performance, stability and use.”
- #9CriticalMonitoring and Evaluation⏰ May 1, 2027
Applies to: Federally regulated financial institutions.
“Institutions must define thresholds and trigger events... that prompt investigation, revalidation, or temporary suspension.”
- #10CriticalKey Focus Areas⏰ May 1, 2027
Applies to: Federally regulated financial institutions.
“due diligence, contractual protections, model access, and oversight for externally sourced or vendor models.”
- #11CriticalImplementation Framework⏰ Before deploying material changes
Applies to: Federally regulated financial institutions.
“approvals are obtained prior to deploying material model changes.”
- #12CriticalMonitoring and Evaluation⏰ Ongoing
Applies to: Federally regulated financial institutions.
“OSFI expects institutions to retain records of tests, validations, issues and remediation activities.”
- #13ImportantKey Focus Areas⏰ May 1, 2027
Applies to: Federally regulated financial institutions.
“OSFI expects data lineage, quality controls, representativeness checks, and documentation of data sources and preprocessing.”
- #14ImportantKey Focus Areas⏰ May 1, 2027
Applies to: Federally regulated financial institutions using AI/ML models.
“attention to model drift, retraining protocols, explainability, fairness, robustness and potential for automation-induced harms.”
- #15ImportantKey Focus Areas⏰ May 1, 2027
Applies to: Federally regulated financial institutions.
“clear management reporting lines to senior management and the board for material model risks and incidents.”
Related Regulations
Implementation Guide for Managers of Artificial Intelligence Systems (Innovation, Science and Economic Development Canada)
Canada86% similar
Artificial Intelligence Model Risk Management – Observations from a Thematic Review (MAS information paper)
Singapore86% similar
FINMA Guidance 08/2024: Governance and risk management when using artificial intelligence
Switzerland86% similar
Directive on Automated Decision-Making (Treasury Board of Canada Secretariat)
Canada86% similar
Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems
Canada85% similar
© Regulations.AI — created on 13-Jun-2026