OSFI-ready AI governance for teams that are not fifty people
Model risk and operational resilience built together rather than twice — one inventory, one control set, and evidence that assembles from normal operation instead of a fire drill before the examination.
Book a briefingThree deadlines, one team.
E-21 adherence passed on September 1, 2026, with scenario testing due September 1, 2027. E-23 comes into force May 1, 2027 and applies to every model, AI included. If you have EU entities, clients or ICT providers in scope, DORA has been live since January 17, 2025.
At a large bank, three programmes get three teams. At everyone else, the same handful of people own all of it while continuing to run the business. That constraint, not the guidance itself, is what makes these deadlines hard — and it is what our approach is built around.
Build once, satisfy several.
One inventory, three uses
The model inventory E-23 requires is also the critical-operations dependency map E-21 asks for, and the deployment map that tells you where automation is safe. One build, three answers.
Tiering that stands up
Risk tiering with a documented rationale, so validation effort concentrates where the exposure is and the supervisor can see why.
Controls sized to the institution
A second line the size of yours needs proportionate controls, not a copy of a G-SIB framework nobody can operate.
Evidence by design
Every control is specified with the record it produces, so the examination pack assembles from normal operation.
Where your obligation sits.
What an engagement covers.
- Gap assessment against E-23 and E-21 with findings ranked by supervisory exposure
- Model and critical-operations inventory built to a single definition set
- Risk tiering methodology, validation standards and independent review expectations
- Scenario testing design and the first run, documented to withstand review
- Board and committee reporting that shows position, movement and residual risk
- A remediation plan with owners and dates that survives contact with the operating calendar
Common questions.
- We are not a big bank. Is the expectation the same?
- The principles apply, the implementation is proportionate. OSFI expects the framework to fit the size, nature and complexity of the institution — the work is defending that proportionality with a rationale, which is exactly what we document.
- Does E-23 cover AI models specifically?
- E-23 is deliberately model-agnostic and captures AI and machine learning within its scope, which is why organisations treating AI governance and model risk as two programmes end up paying twice.
- Can you work alongside our existing second line?
- That is the normal arrangement. We build the framework and the evidence discipline; your team owns and runs it, which is the only version that survives after we leave.
Book a 30-minute briefing
A short conversation is usually enough to tell you whether this is the right first move — and what it would cost.
Book a briefing