OSFI Guideline E-23: Model Risk Management
The final E-23 guideline applies to Canadian federally regulated financial institutions, including banks, foreign bank branches, insurers, and trust and loan companies. It expands model risk management beyond deposit-taking institutions and explicitly addresses AI and machine-learning models. Expectations are proportional to the institution's size, strategy, risk profile, operational complexity, and interconnectedness. The guideline organizes requirements around enterprise-wide governance, risk-based classification, model lifecycle controls, review, deployment, monitoring, and decommissioning.
OSFI E-23 is Canada's enterprise-wide model risk management guideline for federally regulated financial institutions. The final 2025 guideline takes effect on 1 May 2027 and applies a risk-based approach across model identification, inventory, risk ratings, lifecycle governance, independent review, monitoring, third-party models, and decommissioning.
- Jurisdiction
- Canada
- MRM relevance
- Direct model risk management guidance
- Effective date
- 1 May 2027
- Issuing body
- Office of the Superintendent of Financial Institutions
- Official reference
- www.osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e
What it covers
- Enterprise-wide MRM governance, reporting, resourcing, and senior-management accountability.
- Periodic model identification and an accurate, controlled enterprise model inventory.
- Inherent model-risk ratings that drive review, documentation, approval, monitoring, and mitigation intensity.
- Model review that is sufficiently independent from development and use.
- Lifecycle controls for design, deployment, monitoring, change, limitations, and decommissioning.
- Coverage of external, vendor, AI, and machine-learning models using a proportional risk-based approach.
Adoption status
OSFI published the final revised guideline on 11 September 2025. It takes effect for all federally regulated financial institutions on 1 May 2027. Until then, affected institutions should distinguish implementation planning from current compliance status and confirm which earlier OSFI expectations still apply to them.
Reference only. This page explains what OSFI E-23 covers; it is not a claim that Model Risk Directory or any listed vendor satisfies it. Verify alignment directly against the issuing body's own current text before relying on it.
Sources. source 1 · source 2 · source 3. Data as of 2026-07-29. See methodology.