MarketOntarioSheet 23

Model risk is decided here.

Toronto and the Ontario financial corridor.

Canadian model risk policy is written for federally regulated institutions, and most of those institutions run their model estate from Bay Street. That makes Toronto the market where an AI governance gap is most likely to be examined rather than merely noticed.

§ 01The dated obligation

OSFI Guideline E-23, effective 1 May 2027.

OSFI finalised the revised Guideline E-23 on Model Risk Management with an eighteen-month transition, and it takes effect for all federally regulated financial institutions on 1 May 2027. It reaches foreign bank branches and foreign insurance company branches operating in Canada as well as domestic institutions.

Two revisions matter more than the date. The scope expanded to all models at all federally regulated institutions, not a subset judged material by the institution itself. And the definition of a model now explicitly names AI and machine learning methods: an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and ML, which processes input data to generate results.

That second change is the one that catches people. An institution whose model inventory was built around credit and capital models can be entirely current under the old reading and materially incomplete under the new one, because the fraud model, the document classifier, the chatbot that quotes a rate, and the vendor scoring API were never inventoried as models at all.

§ 02The gap

Where the gap usually is.

Inventory
The estate was scoped to models the institution already called models. AI systems bought as features, embedded in a vendor platform, or built by a business unit rarely appear in it.
Tiering
Risk tiering logic predates the AI systems now in production, so a customer-facing generative system inherits a tier designed for a quarterly batch score.
Evidence
Validation exists but the artifact trail cannot be produced on demand for every in-scope model, which is the actual test when an examiner asks.
Third party
Models with vendor components, dynamic data sources and multiple dependencies were assessed as procurement, not as model risk.
§ 03The work

What I bring to it.

A six-pillar model risk discipline, the MESA Framework scored per layer, the Five-Gate Deployment Model for what a system must clear before it ships and who may stop it, and independent validation experience. The AI Governance Teardown is scoped to answer the question an E-23 examiner will ask, which is not whether you have a policy but whether the evidence exists for every model in scope.

Toronto is also where iSystematic is based and where I hold the Director, Solutions Architecture role, so this is a market I work in rather than one I fly into.

Schedule I and II banksFederally regulated insurersForeign bank and insurance branchesCapital markets and asset managementFintech and payments
How I work here

Work is delivered through iSystematic Inc., and you work with me directly rather than with a bench of juniors. Engagements are delivered remotely by default, and on-site time is used where it earns its cost. Nothing here is legal advice; it is architecture and governance work that your counsel should review.

§ 04Questions

What Toronto clients ask.

Does OSFI Guideline E-23 apply to AI models?

Yes, explicitly. The revised guideline defines a model as an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and machine learning methods, which processes input data to generate results. The revisions also add context specifically for AI and ML model risk management, including models that depend on multiple components, diverse and dynamic data sources, and third-party elements.

When does E-23 take effect, and how much time is left?

It takes effect on 1 May 2027, following an eighteen-month transition period intended to let institutions assess current practice and adjust. The practical constraint is not the date but the inventory: institutions that discover in-scope AI systems late have to validate them, not merely list them.

Does it apply to foreign bank branches in Canada?

Yes. The guideline applies to all federally regulated financial institutions including foreign bank branches and foreign insurance company branches, to the extent consistent with applicable requirements and legal obligations related to their business in Canada as set out in Guideline E-4.

We already have a model risk framework. What changes?

Usually the scope rather than the framework. A discipline built for credit, capital and market risk models is often sound in method and narrow in coverage. The work is extending the same rigour to systems that were never classified as models, then proving the evidence exists for each of them.

Are you a Toronto firm?

No. I work through iSystematic Inc. from a Winnipeg base, with working stations in Winnipeg, Toronto and Calgary. There is no bench of juniors; you work with me directly, and engagements are delivered remotely by default with on-site time where it earns its cost.

§ 05Start

Find the gap before someone else does.

The first conversation is a free thirty-minute fit call that qualifies the work in both directions. If it does not fit, you leave with a clearer read on where your governance stands and no cost. If you would rather start on your own, the Readiness Self-Assessment is twelve questions and the result is not gated behind a form.

Fin · Toronto
Book a Fit Call →