Canada - Model Risk Management (E-23)

Guideline E-23 — Model Risk Management (Office of the Superintendent of Financial Institutions) (final)

Canada

RAI-CA-NA-EMRMOXX-2025
Awaiting Entry(Awaiting Entry)
GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

Guideline E-23 (final) sets OSFI’s principles-based expectations for enterprise-wide model risk management for federally regulated financial institutions. Published on September 11, 2025, it expands the scope of covered models (explicitly including AI/ML and non-quantitative models), requires a risk-based, proportionate approach, and becomes effective May 1, 2027.

Summary

Guideline E-23 — Model Risk Management (final) is a principles-based guidance document issued by the Office of the Superintendent of Financial Institutions (OSFI) on September 11, 2025, to update and broaden expectations for model risk management across federally regulated financial institutions (FRFIs) in Canada. The guidance replaces and modernizes prior E-23 material (including the 2017 version) by explicitly broadening the definition of “model” to include analytical applications that process input data to generate results — covering statistical models, rule-based systems, and AI/ML-based systems. The final guideline emphasizes a risk-based, proportionate approach: institutions must identify models that carry non-negligible model risk, catalogue them in an enterprise-level model inventory, assign owners and risk ratings, and ensure governance commensurate with inherent risk. Key elements include model identification and inventory; lifecycle governance (development, testing, approval, deployment, monitoring, and decommissioning); independent model review and validation; data management and documentation; change management and model performance monitoring; third-party and vendor model oversight; board- and senior-management-level reporting; and controls for models that use advanced techniques such as machine learning, including considerations for explainability, fairness, and robustness. The guideline does not ban any specific modeling methodology; instead, it seeks to harmonize supervisory expectations and reduce systemic and firm-level vulnerabilities that stem from model failures or misuse. OSFI adopts a proportionate implementation: expectations scale with the size, complexity and risk profile of the institution and with model criticality. The final guideline follows public consultation (draft published November 20, 2023; consultation closed March 22, 2024), and OSFI published an explanatory letter summarizing stakeholder feedback and clarifications. The Guideline becomes formally effective on May 1, 2027, after an 18-month transition to allow institutions to adapt policies, inventories, and practices. OSFI retains standard supervisory tools and enforcement powers to address non-compliance, including supervisory directions, remedial plans, restrictions on operations, and where applicable, administrative monetary penalties under legislative authorities or future administrative penalty regimes. The guidance positions Canada’s prudential approach to model risk management in alignment with international supervisory practice and OECD definitions of AI systems cited in the text.

Full article

Read full text ↗

Overview

Guideline E-23 — Model Risk Management (final) (published by the Office of the Superintendent of Financial Institutions on September 11, 2025) establishes OSFI’s expectations for effective enterprise-wide model risk management (MRM) across federally regulated financial institutions. The document updates the prior E-23 content to reflect the increasing use of artificial intelligence and machine learning (AI/ML) and to broaden the definition of "model" to any system that "processes input data to generate results," thereby covering both quantitative and non-quantitative applications. OSFI frames the guidance as principles-based and risk-proportionate, focusing on governance, lifecycle controls, independent review, data quality, monitoring, and third-party oversight. For the official text, see Guideline E-23 – Model Risk Management (2027) and the accompanying backgrounder at OSFI backgrounder. The guideline sets an effective date of May 1, 2027, to provide an 18‑month transition period for institutions to implement proportional changes to their MRM frameworks.

Definitions

Key terms in E-23 include: "Model" — an application of theoretical, empirical, judgmental assumptions or statistical techniques (including AI/ML) that processes input data to generate results; "Model risk" — risk of adverse outcomes (financial, operational, reputational, legal) from model design, development, deployment or use; "Model inventory" — enterprise-level register of models with non-negligible risk; "Model lifecycle" — the stages of model development, validation, approval, deployment, monitoring and decommissioning; "Model stakeholders" — business, control functions, and others with a legitimate interest in the model’s design, use and oversight. E-23 adopts a risk-based and proportional lens — not all analytical artifacts must be governed with the same intensity; the institution triages models to determine which carry non-negligible inherent model risk and therefore merit full lifecycle governance.

Governance and Institutional Framework

OSFI requires clear governance structures for model risk at the board, senior management, and operational levels. Boards are expected to oversee model risk through risk committees or equivalent and to ensure that senior management puts in place appropriate policies, roles, and responsibilities. Senior management must maintain an enterprise MRM framework, a model inventory, escalation and approval processes for model changes, and resource allocation consistent with model risk. The guideline emphasizes functional separation between developers, owners and independent reviewers (model validation), and requires documented accountability assignments (model owners, model developers, model reviewers). Where relevant, institutions must integrate MRM into broader risk management, compliance and internal control frameworks and reflect the institution’s strategy and risk appetite. For OSFI’s official guidance on scope and governance, see Guideline E-23 (2027) and the explanatory letter to industry.

Key Focus Areas

OSFI’s final Guideline sets expectations across several interdependent focus areas: (1) Model identification and inventory — institutions must identify and maintain an enterprise inventory of models that carry non-negligible inherent risk and capture key metadata (model ID, purpose, owner, developer, origin, version, deployment date, risk rating, approved uses, limitations, review dates, monitoring status and dependencies); (2) Risk-based model classification/rating — institutions must adopt a transparent approach to assigning model risk ratings that reflect complexity, autonomy, data sensitivity, customer impact and systemic interconnectedness; (3) Model lifecycle governance — documented practices for design, development, code controls, testing, independent review/validation, approval (prior to deployment or material changes), production deployment, monitoring, and decommissioning; (4) Independent review and validation — models with non-negligible risk require review by personnel or units independent of development, using testing approaches appropriate to model type and complexity; (5) Data governance — OSFI expects data lineage, quality controls, representativeness checks, and documentation of data sources and preprocessing; (6) Monitoring and performance management — continuous or periodic monitoring plans, performance metrics, and triggers for revalidation or remediation; (7) Third-party and vendor models — due diligence, contractual protections, model access, and oversight for externally sourced or vendor models; (8) AI/ML-specific considerations — attention to model drift, retraining protocols, explainability, fairness, robustness and potential for automation-induced harms; and (9) Reporting and escalation — clear management reporting lines to senior management and the board for material model risks and incidents. These focus areas reflect OSFI’s intent to capture both traditional financial models (capital, provisioning, pricing) and newer risk domains (operational, cyber, climate, HR analytics) where models may influence material outcomes.

Implementation Framework

Implementation is explicitly risk-based and proportionate. Institutions must document their MRM framework and demonstrate how governance, resources and controls scale to model risk. Practical requirements include establishing or updating policies and standards; creating or enhancing a comprehensive model inventory; defining model lifecycle processes (development, testing, review, approval, deployment, monitoring, change management, retirement); assigning accountable owners and independent reviewers; implementing data management practices and repeatable testing frameworks; embedding vendor oversight processes; and integrating MRM metrics into operational and risk reporting. OSFI allows flexibility in process design but expects that approvals are obtained prior to deploying material model changes and following periodic reviews. The guideline recognizes non-production uses and single-run analytic outputs and cautions institutions that such uses may nonetheless carry model risk and therefore could be subject to governance commensurate with their assessed risk.

Monitoring and Evaluation

OSFI requires institutions to implement monitoring frameworks for model performance, stability and use. Monitoring should include quantitative performance metrics (e.g., accuracy, calibration, error distributions), data quality checks, and operational controls (logging, access control). Institutions must define thresholds and trigger events (for example, sustained performance degradation, material change in data, regulatory or business-context changes) that prompt investigation, revalidation, or temporary suspension. Model monitoring results and remediation activities should be documented and reported periodically to senior management and, for material models, to the board. OSFI expects institutions to retain records of tests, validations, issues and remediation activities to support supervisory review.

Penalties, Liability, and Appeals

While Guideline E-23 itself is not primary legislation, non-compliance with OSFI guidance can form the basis for supervisory engagement and enforcement under statutory authorities (Bank Act, Insurance Companies Act, Trust and Loan Companies Act, the OSFI Act and related provisions or administrative monetary penalty regimes as applicable). OSFI retains the authority to require remediation plans, impose operational restrictions, issue directions or conditions, and in cases where statutory penalty regimes apply, administrative monetary penalties. Affected institutions have standard avenues for engagement with OSFI and may contest supervisory findings or directions through established administrative and judicial channels. Institutions should therefore maintain traceable governance and records to support compliance and, where necessary, to demonstrate corrective action to supervisors.

Relationship to Other Instruments

Guideline E-23 complements OSFI’s broader supervisory framework, including other guidance on technology, cyber security, vendor risk, internal controls and the Integrity and Security Guideline. It references established definitions such as the OECD AI definition for AI/ML systems and should be read in concert with sectoral requirements (e.g., capital, liquidity, prudential reporting) and with any institution-specific supervisory expectations. The guideline clarifies interactions with foreign branch requirements (consistent with Guideline E-4 on foreign entities operating on a branch basis) and aligns with OSFI’s enterprise-wide risk appetite and supervisory priorities.

International Alignment

OSFI designed E-23 to reflect international supervisory trends on model and AI governance, including cross-reference to OECD definitions and best-practice principles. The guidance is consistent with a growing body of supervisory work from major jurisdictions that emphasize model inventories, independent validation, lifecycle governance, and AI-specific controls (explainability, bias assessment, robustness). OSFI’s approach aims to enable innovation while protecting prudential safety and to facilitate cross-border supervisory dialogue where models are developed or operated across jurisdictions.

Implementation Timeline

MilestoneDateNotes
Draft guideline published (public consultation)2023-11-20Draft updated and open for consultation to March 22, 2024
Final guideline published2025-09-11Final E-23 published with explanatory letter and backgrounder
Transition period2025-09-11 to 2027-04-3018-month period for institutions to implement requirements
Effective date2027-05-01All federally regulated financial institutions expected to comply on a proportionate basis

Sources and References

SourceType
Guideline E-23 – Model Risk Management (2027)Primary Source
Backgrounder: Guideline E-23 – Model Risk ManagementPrimary Source
Guideline E-23 – Model Risk Management (2027) - LetterPrimary Source

Requirements for a company

What an organisation has to do under Canada - Model Risk Management (E-23), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Awaiting Entry). These requirements apply once the instrument takes effect and may change before then.

Must do

15
  • Oversee model risk through risk committees or equivalent.Boards of federally regulated financial institutions.
  • Maintain an enterprise-wide model risk management framework.Senior management of federally regulated financial institutions.
  • Document accountability assignments for model owners, developers, and reviewers.Federally regulated financial institutions.
  • Identify and maintain an enterprise inventory of models with non-negligible risk.Federally regulated financial institutions.
  • Adopt a transparent approach to assigning model risk ratings.Federally regulated financial institutions.
  • Document practices for the entire model lifecycle, from design to decommissioning.Federally regulated financial institutions.
  • +9 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Canada - Model Risk Management (E-23), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Boards of federally regulated financial institutions.Oversee model risk through risk committees or equivalent.
Boards are expected to oversee model risk through risk committees or equivalent.
May 1, 2027Governance and Institutional FrameworkCritical
2Senior management of federally regulated financial institutions.Maintain an enterprise-wide model risk management framework.
Senior management must maintain an enterprise MRM framework.
May 1, 2027Governance and Institutional FrameworkCritical
3Federally regulated financial institutions.Document accountability assignments for model owners, developers, and reviewers.
requires documented accountability assignments (model owners, model developers, model reviewers).
May 1, 2027Governance and Institutional FrameworkCritical
4Federally regulated financial institutions.Identify and maintain an enterprise inventory of models with non-negligible risk.
institutions must identify and maintain an enterprise inventory of models that carry non-negligible inherent risk.
May 1, 2027Key Focus AreasCritical
5Federally regulated financial institutions.Adopt a transparent approach to assigning model risk ratings.
institutions must adopt a transparent approach to assigning model risk ratings.
May 1, 2027Key Focus AreasCritical
6Federally regulated financial institutions.Document practices for the entire model lifecycle, from design to decommissioning.
documented practices for design, development, code controls, testing, independent review/validation, approval... monitoring, and decommissioning.
May 1, 2027Key Focus AreasCritical
7Federally regulated financial institutions.Ensure independent review and validation for models with non-negligible risk.
models with non-negligible risk require review by personnel or units independent of development.
May 1, 2027Key Focus AreasCritical
8Federally regulated financial institutions.Establish continuous or periodic monitoring plans for model performance and stability.
OSFI requires institutions to implement monitoring frameworks for model performance, stability and use.
May 1, 2027Key Focus Areas / Monitoring and EvaluationCritical
9Federally regulated financial institutions.Define thresholds and trigger events for model revalidation or temporary suspension.
Institutions must define thresholds and trigger events... that prompt investigation, revalidation, or temporary suspension.
May 1, 2027Monitoring and EvaluationCritical
10Federally regulated financial institutions.Conduct due diligence and oversight for third-party and vendor models.
due diligence, contractual protections, model access, and oversight for externally sourced or vendor models.
May 1, 2027Key Focus AreasCritical
11Federally regulated financial institutions.Obtain approvals prior to deploying material model changes.
approvals are obtained prior to deploying material model changes.
Before deploying material changesImplementation FrameworkCritical
12Federally regulated financial institutions.Retain records of model tests, validations, issues, and remediation activities.
OSFI expects institutions to retain records of tests, validations, issues and remediation activities.
OngoingMonitoring and EvaluationCritical
13Federally regulated financial institutions.Implement data lineage, quality controls, and representativeness checks for model data.
OSFI expects data lineage, quality controls, representativeness checks, and documentation of data sources and preprocessing.
May 1, 2027Key Focus AreasImportant
14Federally regulated financial institutions using AI/ML models.Address AI/ML-specific considerations like model drift, explainability, fairness, and robustness.
attention to model drift, retraining protocols, explainability, fairness, robustness and potential for automation-induced harms.
May 1, 2027Key Focus AreasImportant
15Federally regulated financial institutions.Establish clear management reporting lines for material model risks and incidents.
clear management reporting lines to senior management and the board for material model risks and incidents.
May 1, 2027Key Focus AreasImportant

© Regulations.AI — created on 13-Jun-2026