OSFI Guideline E-23

Model risk management that is ready before May 2027

An enterprise model inventory, defensible risk tiering, proportionate validation standards and lifecycle controls — built so the evidence exists before a supervisor asks for it.

Book a briefing
The obligation

Every model, not just the credit models.

OSFI's revised Guideline E-23 on model risk management takes effect May 1, 2027 and applies enterprise-wide. Its scope is deliberately broad: any quantitative method that processes input into output to support a decision, which captures machine learning, generative AI and vendor models alongside the traditional book.

The expectations are familiar in shape — an accurate inventory, risk-based tiering, proportionate validation, defined lifecycle controls, and accountable oversight — and demanding in evidence. Institutions get caught not on policy but on whether the records exist when asked.

The clock

Time and scope.

May 1, 2027

Date the revised E-23 expectations come into force

Enterprise-wide

Scope: all models, including AI, ML and vendor-supplied

Risk-based

Validation intensity must be defensibly proportionate to model tier

Programme

How the build runs.

  1. 01

    Discovery

    Gap assessment against E-23 clause by clause, plus a first sweep for models the register never captured.

  2. 02

    Inventory

    A single enterprise inventory with owner, purpose, tier, data lineage and dependency for every model.

  3. 03

    Framework

    Tiering methodology, validation standards by tier, lifecycle controls, and the roles that own each.

  4. 04

    Operate

    Backlog validations cleared in tier order, reporting live, and the framework handed to your team.

Deliverables

What you get.

  • Enterprise model inventory with definitions that hold up under challenge
  • Risk tiering methodology and the documented rationale behind each tier assignment
  • Validation standards by tier, including expectations for AI and vendor models
  • Lifecycle controls covering development, approval, deployment, monitoring, change and retirement
  • Model risk appetite, escalation thresholds and board-level reporting
  • A dated remediation plan for the validation backlog, sequenced by exposure
FAQ

Common questions.

Do vendor and third-party models count?
Yes. Buying the model does not transfer the risk. You are expected to understand it well enough to tier it, validate it proportionately, and monitor it in production — which usually means renegotiating what your vendor is contractually required to disclose.
Does a generative AI assistant count as a model?
If its output supports a decision, treat it as in scope and tier it accordingly. The safer posture is to inventory it and justify a low tier, rather than to omit it and defend the omission later.
How long does an E-23 programme take?
Inventory and framework typically take twelve to sixteen weeks. Clearing the validation backlog depends on the size of the estate and runs alongside, which is why starting well ahead of May 2027 matters.
Can the inventory be reused?
It should be. The same inventory answers your AI governance obligations and doubles as the map of where automation can safely be deployed first — one build, two returns.

Book a 30-minute briefing

A short conversation is usually enough to tell you whether this is the right first move — and what it would cost.

Book a briefing