Model risk management that is ready before May 2027
An enterprise model inventory, defensible risk tiering, proportionate validation standards and lifecycle controls — built so the evidence exists before a supervisor asks for it.
Book a briefingEvery model, not just the credit models.
OSFI's revised Guideline E-23 on model risk management takes effect May 1, 2027 and applies enterprise-wide. Its scope is deliberately broad: any quantitative method that processes input into output to support a decision, which captures machine learning, generative AI and vendor models alongside the traditional book.
The expectations are familiar in shape — an accurate inventory, risk-based tiering, proportionate validation, defined lifecycle controls, and accountable oversight — and demanding in evidence. Institutions get caught not on policy but on whether the records exist when asked.
Time and scope.
Date the revised E-23 expectations come into force
Scope: all models, including AI, ML and vendor-supplied
Validation intensity must be defensibly proportionate to model tier
How the build runs.
- 01
Discovery
Gap assessment against E-23 clause by clause, plus a first sweep for models the register never captured.
- 02
Inventory
A single enterprise inventory with owner, purpose, tier, data lineage and dependency for every model.
- 03
Framework
Tiering methodology, validation standards by tier, lifecycle controls, and the roles that own each.
- 04
Operate
Backlog validations cleared in tier order, reporting live, and the framework handed to your team.
What you get.
- Enterprise model inventory with definitions that hold up under challenge
- Risk tiering methodology and the documented rationale behind each tier assignment
- Validation standards by tier, including expectations for AI and vendor models
- Lifecycle controls covering development, approval, deployment, monitoring, change and retirement
- Model risk appetite, escalation thresholds and board-level reporting
- A dated remediation plan for the validation backlog, sequenced by exposure
Common questions.
- Do vendor and third-party models count?
- Yes. Buying the model does not transfer the risk. You are expected to understand it well enough to tier it, validate it proportionately, and monitor it in production — which usually means renegotiating what your vendor is contractually required to disclose.
- Does a generative AI assistant count as a model?
- If its output supports a decision, treat it as in scope and tier it accordingly. The safer posture is to inventory it and justify a low tier, rather than to omit it and defend the omission later.
- How long does an E-23 programme take?
- Inventory and framework typically take twelve to sixteen weeks. Clearing the validation backlog depends on the size of the estate and runs alongside, which is why starting well ahead of May 2027 matters.
- Can the inventory be reused?
- It should be. The same inventory answers your AI governance obligations and doubles as the map of where automation can safely be deployed first — one build, two returns.
Book a 30-minute briefing
A short conversation is usually enough to tell you whether this is the right first move — and what it would cost.
Book a briefing