Canadian model risk policy is written for federally regulated institutions, and most of those institutions run their model estate from Bay Street. That makes Toronto the market where an AI governance gap is most likely to be examined rather than merely noticed.
OSFI finalised the revised Guideline E-23 on Model Risk Management with an eighteen-month transition, and it takes effect for all federally regulated financial institutions on 1 May 2027. It reaches foreign bank branches and foreign insurance company branches operating in Canada as well as domestic institutions.
Two revisions matter more than the date. The scope expanded to all models at all federally regulated institutions, not a subset judged material by the institution itself. And the definition of a model now explicitly names AI and machine learning methods: an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and ML, which processes input data to generate results.
That second change is the one that catches people. An institution whose model inventory was built around credit and capital models can be entirely current under the old reading and materially incomplete under the new one, because the fraud model, the document classifier, the chatbot that quotes a rate, and the vendor scoring API were never inventoried as models at all.
A six-pillar model risk discipline, the MESA Framework scored per layer, the Five-Gate Deployment Model for what a system must clear before it ships and who may stop it, and independent validation experience. The AI Governance Teardown is scoped to answer the question an E-23 examiner will ask, which is not whether you have a policy but whether the evidence exists for every model in scope.
Toronto is also where iSystematic is based and where I hold the Director, Solutions Architecture role, so this is a market I work in rather than one I fly into.
Work is delivered through iSystematic Inc., and you work with me directly rather than with a bench of juniors. Engagements are delivered remotely by default, and on-site time is used where it earns its cost. Nothing here is legal advice; it is architecture and governance work that your counsel should review.
Yes, explicitly. The revised guideline defines a model as an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and machine learning methods, which processes input data to generate results. The revisions also add context specifically for AI and ML model risk management, including models that depend on multiple components, diverse and dynamic data sources, and third-party elements.
It takes effect on 1 May 2027, following an eighteen-month transition period intended to let institutions assess current practice and adjust. The practical constraint is not the date but the inventory: institutions that discover in-scope AI systems late have to validate them, not merely list them.
Yes. The guideline applies to all federally regulated financial institutions including foreign bank branches and foreign insurance company branches, to the extent consistent with applicable requirements and legal obligations related to their business in Canada as set out in Guideline E-4.
Usually the scope rather than the framework. A discipline built for credit, capital and market risk models is often sound in method and narrow in coverage. The work is extending the same rigour to systems that were never classified as models, then proving the evidence exists for each of them.
No. I work through iSystematic Inc. from a Winnipeg base, with working stations in Winnipeg, Toronto and Calgary. There is no bench of juniors; you work with me directly, and engagements are delivered remotely by default with on-site time where it earns its cost.
The first conversation is a free thirty-minute fit call that qualifies the work in both directions. If it does not fit, you leave with a clearer read on where your governance stands and no cost. If you would rather start on your own, the Readiness Self-Assessment is twelve questions and the result is not gated behind a form.