This publication has noted repeatedly that Canada has no comprehensive federal AI statute, since the Artificial Intelligence and Data Act died on the order paper in January 2025. That statement remains true and continues to mislead people, because it invites the conclusion that AI use in Canadian financial services is ungoverned. It is not. It is governed by a document with a definition section, a hard effective date, and enforcement behind it, and most businesses that will be affected by it have never read a word of it.
Key Takeaway
OSFI published the final version of Guideline E-23, Model Risk Management, on September 11, 2025, taking effect May 1, 2027 after an 18-month transition. Legal commentary explicitly frames it as one of Canadian regulators' efforts to fill the country's legislative gap on AI guardrails. Three features make it consequential well beyond the institutions it directly binds. First, scope expanded dramatically: the 2017 version applied only to deposit-taking institutions, while the 2025 version applies to all federally regulated financial institutions including foreign bank branches and life and P&C insurers. Second, "model" is defined broadly enough to capture all methodologies that process input data to generate results, with AI and machine learning expressly included. Third, it applies to all models regardless of source, internal or third party, which means a software vendor selling into a Canadian bank or insurer inherits compliance obligations through the procurement relationship regardless of whether OSFI regulates that vendor at all.
Filling A Legislative Gap Nobody Else Filled
The framing here comes from Canadian legal commentary rather than from this publication's own characterization. BLG describes the updated Guideline E-23 as one of the latest efforts by Canadian regulators to respond to AI risks and opportunities and fill Canada's current legislative gap with respect to AI guardrails[1]. That is a precise description of what is happening: in the absence of a statute of general application, sectoral regulators are establishing binding expectations within their own supervisory perimeters, and the financial sector regulator moved first and furthest.
This matters for how a business should read the Canadian AI landscape. The relevant question is not "is there an AI law," to which the answer is currently no, but "does a regulator with authority over me, or over my customers, have published AI expectations," to which the answer is increasingly yes. For anyone whose business touches Canadian banking, insurance, or lending, E-23 is the operative document.
The Dates That Matter
The sequence is worth stating precisely because the transition period is already substantially consumed. OSFI published a draft revised Guideline E-23 on November 20, 2023, with public consultation open until March 22, 2024[2]. The final guideline was published September 11, 2025, as part of OSFI's quarterly release of regulatory changes[3], and takes effect May 1, 2027 following an 18-month transition period intended to give institutions time to assess current practices and make adjustments[4].
OSFI's own letter notes it revised the implementation date to May 1, 2027 partly because many institutions signalled they had already begun work[5]. Commentary is blunter about where that leaves the laggards: the 18-month transition began September 11, 2025, and institutions that have not started gap assessments are behind[6].
The Scope Expansion Is The Real Story
Torys identifies the most significant change to the guideline as its expanded scope, covering both the entities and models governed as well as the model risks it aims to regulate[7]. The specifics are substantial. The 2017 guideline, titled Enterprise-Wide Model Risk Management for Deposit-Taking Institutions, applied only to that category[2]. The 2025 version applies to all federally regulated financial institutions, expanding applicability to foreign bank branches and to life, property and casualty insurance companies alongside banks and trust and loan companies[8].
One scope reduction went the other way and is worth noting for accuracy: the 2023 draft extended to federally regulated private pension plans, but the final guideline excludes them[7]. OSFI explained this was reconsidered given differences in its mandate to supervise pension plans and the availability of alternative industry guidance addressing pension risk management[2]. A business should not assume the draft and final documents are interchangeable on scope questions.
What Counts As A "Model"
The definitional breadth is where many organizations will discover they have more in scope than they expected. The guideline defines "model" broadly to capture all methodologies that process input data to generate results, and artificial intelligence and machine learning methods are expressly included in the definition[7]. Commentary confirms the guideline now explicitly covers all models regardless of technology or purpose[6], and that scope follows the risk a model carries rather than the team that happens to own it[9].
Two practical consequences follow. A spreadsheet-based methodology that processes inputs to generate results for a decision of non-negligible risk is potentially in scope on the plain definition, regardless of whether anyone in the institution would colloquially call it a "model." And an organization's model inventory obligation is correspondingly larger than a list of things the quantitative team built: Torys notes the guideline's expectations may require substantial governance effort including developing an inventory of all models with non-negligible risk[7].
Explainability: What Stakeholders Asked For And Got
The explainability provisions have a documented history worth knowing, because it shows the requirement strengthened rather than softened through consultation. OSFI's own summary of stakeholder feedback records that stakeholders requested more guidance on explainability, and OSFI's response was that it incorporated additional explainability guidance in the final guideline throughout the components of the model lifecycle[5].
"Throughout the lifecycle" is the operative phrase and distinguishes this from a checkbox at approval. The published guideline text on deployment, for instance, lists among the required elements a review of explainability requirements and communication of explanatory outputs to the appropriate stakeholders[10]. The same text ties data properties directly to this objective, noting that one important purpose of the specified data properties is to enhance the explainability of the model and associated outputs[10]. Explainability is treated as something designed into data governance and model construction, not as documentation produced afterward to satisfy a reviewer.
Commentary summarizing the AI-specific provisions puts the design obligation directly: for AI/ML models, institutions must consider transparency and explainability as part of model design, and bias, ethical risk, and privacy risks must be assessed during development[6].
The Black-Box Provision
The most interesting single provision, and the one that resolves a question this publication has raised elsewhere about the tension between model accuracy and interpretability, concerns models that cannot be explained. Where a model is a "black box" or operates autonomously, institutions must document alternative controls[6].
This is a meaningfully different regulatory posture than a prohibition, and it is worth appreciating why it is more sophisticated than one. OSFI did not resolve the accuracy-versus-interpretability trade-off by banning the more accurate but less interpretable model, which would have imposed a real performance cost. It instead required that if you cannot explain the model, you must be able to demonstrate what you do instead: what compensating controls, monitoring, output testing, or human oversight substitute for the explanation you cannot provide. The guideline is described as principles-based and technology-agnostic, requiring that risk be managed rather than that particular methods be avoided[9].
The Self-Learning Model Problem
A second consultation exchange addressed a genuinely hard technical governance question. Stakeholders requested more guidance on self-learning models, specifically how the model modification approval requirement could be satisfied for models that are always changing[5]. This is a real problem: a governance framework requiring approval for model modifications collides awkwardly with a model that modifies itself continuously by design.
OSFI's response was to incorporate additional guidance around model modifications under model identification, model review, and model monitoring, and to direct that institutions should establish internal criteria to determine when a self-learning model has materially changed[5]. The solution is delegation with accountability: the institution defines, in advance and in writing, what constitutes material change for a given model, and that threshold becomes the trigger for the approval process. This is a sensible answer to an awkward problem, and it places the burden of defining materiality on the institution rather than pretending a universal threshold exists.
Third-Party Reach: Why This Concerns Vendors
This is the section most relevant to readers who are not themselves financial institutions. The guideline applies to all models regardless of source, with internal and third-party models both in scope[9], and includes formal third-party model governance aligned with OSFI Guideline B-10[6]. Torys notes explicitly that the updates carry significant implications for both regulated entities and their service providers[7].
The mechanism by which this reaches an unregulated business is procurement rather than direct supervision. A federally regulated institution cannot satisfy an explainability, documentation, validation, or monitoring obligation for a model it licenses from a vendor unless the vendor supplies what the institution needs. The obligation therefore propagates down the supply chain as contractual and diligence requirements: a Canadian software company selling analytics, scoring, underwriting support, fraud detection, or any other model-based capability into a bank or insurer should expect to be asked for validation evidence, explainability documentation, model change notification, and performance monitoring data, whether or not OSFI has any authority over that company.
For a vendor, the strategic reading is straightforward. Being able to answer an E-23-shaped diligence questionnaire before competitors can is a commercial advantage in the Canadian financial services market between now and May 2027. Being unable to answer it after that date is a disqualification.
What This Means For Lending Decisions Specifically
Credit and underwriting decisions are among the most consequential applications of models within scope, and E-23's structure has specific implications for them worth drawing out. A model that influences whether a business or individual receives credit, on what terms, and at what price is not plausibly a negligible-risk model, so the full framework applies: inventory, documentation, independent validation, explainability consideration at design, and ongoing monitoring.
The explainability requirement matters here in a way it does not for, say, an internal capital forecasting model, because the outputs affect an identifiable third party who may reasonably ask why. E-23's deployment provisions require communication of explanatory outputs to the appropriate stakeholders[10], and the development-stage requirement to assess bias and ethical risk[6] is most obviously engaged where model outputs allocate access to credit across a population.
It should be stated plainly what E-23 is and is not. It is a prudential model risk management guideline, not a consumer credit or human rights instrument. It does not itself create a borrower's right to an explanation of an adverse credit decision, and Canadian requirements bearing on automated decision-making transparency for individuals arise from other instruments and vary by jurisdiction. What E-23 does is require the institution to have built the capability to explain, which is a precondition for meeting any such obligation from any source, and which most institutions did not uniformly have before.
The Risks OSFI Says It Is Responding To
E-23 did not emerge from an abstract regulatory exercise. It sits alongside a broader supervisory workstream, and the risks that workstream identified explain the guideline's emphases. OSFI, the Department of Finance Canada and the Global Risk Institute held the first of four workshops in May 2025 as part of the second Financial Industry Forum on Artificial Intelligence[3], and the resulting July 2025 report identified specific risk categories[8].
Two are worth naming because they connect directly to material covered elsewhere in this publication. On cybersecurity, the report identified AI-enhanced tools such as adaptive malware enabling threat actors to move quickly and inflict significant damage[8]. On data risk, it identified that internal AI models process sensitive data, creating exposure to data poisoning, model extraction, and adversarial manipulation[8]. These are attacks on the model itself rather than on the network around it, which is a category of risk most businesses' security posture does not currently address at all, and it explains why E-23 treats data governance as one of its four named framework components rather than as an IT concern sitting outside model risk.
A Worked Case: The Vendor Questionnaire Nobody Could Answer
A Canadian software company supplying a cash-flow-based risk scoring tool to a mid-sized federally regulated lender received a procurement questionnaire during a routine contract renewal. It asked for the model's development documentation, the validation methodology and results, the explainability approach for individual scores, the process by which the vendor would notify the lender of material model changes, and the ongoing performance monitoring the vendor conducted.
The company had a genuinely effective product and could answer none of the five questions in the form asked. Its model had been developed iteratively by a small team with documentation existing largely as code comments and internal chat history. Validation had been continuous and informal, in the sense that the team watched performance and adjusted, which is not the same thing as independent validation with a documented methodology. Explainability existed in the sense that the team could reason about why a score came out as it did, but not in a form transmissible to a customer's model risk function. There was no defined threshold for what constituted a material change requiring customer notification, because changes were shipped continuously.
The renewal proceeded, but with a remediation schedule attached and a twelve-month deadline against which the vendor is now building documentation, validation, and change-notification processes it would not otherwise have prioritized. The instructive point is that nothing about the product was deficient. What was deficient was the evidentiary apparatus around it, and that apparatus is now a condition of selling into this market segment at all.
The Multi-Disciplinary Team Requirement
One governance requirement deserves specific attention because it is unusual and reveals something about OSFI's conception of model risk. The final guideline sets out expectations for enterprise-wide model risk management frameworks and specifies that to effectively assess model risks, organizations should establish a multi-disciplinary team representing a wide range of expertise and functions from across the organization, including legal and ethics professionals[3].
The explicit inclusion of ethics professionals in a prudential regulator's guideline on model risk is a notable signal. It reflects a judgment that model risk is not exclusively a technical or quantitative question, and that assessing whether a model should be used, as distinct from whether it performs accurately, requires expertise that a quantitative validation team does not by itself possess. Institutions treating E-23 compliance as a project for the model risk function alone are likely to find that reading insufficient against the guideline's own text.
Proportionality, And Its Limits
The guideline requires risk-based policies and procedures for model use that are proportional to an institution's size, risk profile, complexity of operations, and interconnectedness in the financial system, situated within the organization's broader governance framework[3]. OSFI has stated it will provide support through the transition to help institutions apply the principles proportionately to their size, complexity, and risk profile[4], and proportionality is named as one of four components alongside data governance, resourcing and expertise, and documentation[9].
Proportionality is genuine relief but it is not an exemption, and the distinction matters for smaller institutions and for vendors serving them. A smaller institution may implement a lighter framework; it may not implement no framework. And the model inventory obligation attaches to all models with non-negligible risk[7], a threshold set by the model's risk rather than by the institution's size, meaning a small institution using a consequential model does not escape the requirement by being small.
The Limits Of This Analysis
Several caveats matter. This article summarizes a lengthy technical guideline and a body of legal commentary about it; it is not a substitute for reading the guideline itself, and any institution with a live compliance obligation should work from OSFI's published text and qualified counsel rather than from a summary. Several characterizations here, particularly the AI/ML-specific provisions on black-box controls and bias assessment, are drawn from published commentary summarizing the guideline rather than from direct quotation of the guideline text, and readers should verify specific requirements against the primary document. The discussion of lending decisions distinguishes what E-23 requires from what other Canadian instruments may require regarding automated decision-making transparency for individuals; that adjacent area varies by jurisdiction, was not researched in depth for this article, and should not be inferred from anything stated here. Finally, the guideline takes effect May 1, 2027 and OSFI has indicated it will provide implementation support during transition, so supervisory expectations may be further clarified before that date.
Frequently Asked Questions
What is OSFI Guideline E-23 and when does it take effect?
Who does it apply to?
Does it apply to third-party vendor models?
Does E-23 ban "black box" AI models?
How does it handle self-learning models that change constantly?
Does E-23 give borrowers a right to an explanation of a credit decision?
References
- BLG. (2025, November 19). OSFI Responds To The Growing Use Of AI: Key Updates To Guideline E-23. blg.com/en/insights/2025/11/osfi-responds-to-the-growing-use-of-ai
- Office of the Superintendent of Financial Institutions. (2025, September 11). Guideline E-23 – Model Risk Management (2027) – Letter. osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027-letter
- Blakes. (2025, September 26). OSFI Releases Final Guideline E-23 For Model Risk Management And AI Use By Federally Regulated Financial Institutions. blakes.com/insights/osfi-releases-final-guideline-e-23
- Office of the Superintendent of Financial Institutions. (2025, September 11). Backgrounder: Guideline E-23 – Model Risk Management. osfi-bsif.gc.ca/en/news/backgrounder-guideline-e-23-model-risk-management
- Office of the Superintendent of Financial Institutions. (2025). Guideline E-23 – Model Risk Management (2027) – Letter, summary of stakeholder comments and OSFI responses on explainability and self-learning models. osfi-bsif.gc.ca/en/print/pdf/node/2842
- AI Compliance Vendors. (2026, April 26). OSFI E-23 (2025): Guide For Canadian Banks & Insurers. aicompliancevendors.com/blog/osfi-e23-final-guideline-canadian-banks-2026
- Torys LLP. (2025, October 22). OSFI Updates And Expands Scope Of Guideline E-23 For AI Governance. torys.com/en/our-latest-thinking/publications/2025/10/osfi-updates-and-expands-scope-of-guideline-e-23
- Protiviti. OSFI's E-23 Model Risk Management Guideline, noting expanded applicability and the July 2025 Financial Industry Forum on Artificial Intelligence report published by OSFI, the Department of Finance and the Global Risk Institute. protiviti.com/gl-en/insights-paper/strengthening-decision-making-with-osfi-e-23-model
- iTmethods. (2026). OSFI E-23 Model Risk Management: What Changes For AI. itmethods.com/reign/osfi-e23
- Office of the Superintendent of Financial Institutions. Guideline E-23 – Model Risk Management (2027), published guideline text on model deployment and explainability. osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027
This article summarizes published regulatory guidance and legal commentary and is provided for general informational purposes. It is not legal or compliance advice and is not a substitute for the guideline text itself. Institutions and vendors with compliance obligations should work from OSFI's published guideline and qualified counsel.