MarketOntarioSheet 23

Model risk is decided here.

Toronto and the Ontario financial corridor.

Canadian model risk policy is written for federally regulated institutions, and most of those institutions run their model estate from Bay Street. That makes Toronto the market where an AI governance gap is most likely to be examined rather than merely noticed.

Where I work from

I am based in Winnipeg, Manitoba, and I serve Toronto on site and remotely, in whatever mix the engagement needs. Toronto is not a market I reach from a distance, because Simplification Inc., my Toronto company, is based here. What an examiner tests is not where the advisor sits. It is whether the evidence for every in-scope model can be produced on the day it is asked for.

§ 01The dated obligation

OSFI Guideline E-23, effective 1 May 2027.

OSFI finalised the revised Guideline E-23 on Model Risk Management with an eighteen-month transition, and it takes effect for all federally regulated financial institutions on 1 May 2027. It reaches foreign bank branches and foreign insurance company branches operating in Canada as well as domestic institutions.

Two revisions matter more than the date. The scope expanded to all models at all federally regulated institutions, not a subset judged material by the institution itself. And the definition of a model now explicitly names AI and machine learning methods: an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and ML, which processes input data to generate results.

That second change is the one that catches people. An institution whose model inventory was built around credit and capital models can be entirely current under the old reading and materially incomplete under the new one, because the fraud model, the document classifier, the chatbot that quotes a rate, and the vendor scoring API were never inventoried as models at all.

§ 02The gap

Where the gap usually is.

Inventory
The estate was scoped to models the institution already called models. AI systems bought as features, embedded in a vendor platform, or built by a business unit rarely appear in it.
Tiering
Risk tiering logic predates the AI systems now in production, so a customer-facing generative system inherits a tier designed for a quarterly batch score.
Evidence
Validation exists but the artifact trail cannot be produced on demand for every in-scope model, which is the actual test when an examiner asks.
Third party
Models with vendor components, dynamic data sources and multiple dependencies were assessed as procurement, not as model risk.
§ 03The work

What I bring to it.

A six-pillar model risk discipline, the MESA Framework scored per layer, the Five-Gate Deployment Model for what a system must clear before it ships and who may stop it, and independent validation experience. The AI Governance Teardown is scoped to answer the question an E-23 examiner will ask, which is not whether you have a policy but whether the evidence exists for every model in scope.

I founded iSystematic Inc. in Winnipeg and direct it. The Toronto company is not a flag planted for a landing page; it is why this is a market I work in rather than one I fly into, and why an institution preparing for 1 May 2027 gets an advisor on a schedule rather than one who arrives, reviews, and leaves the evidence problem behind.

Schedule I and II banksFederally regulated insurersForeign bank and insurance branchesCapital markets and asset managementFintech and payments
How I work here

Work is delivered through iSystematic Inc., a studio with its own team of builders, and the advisory and governance engagements are delivered by me rather than staffed to that team. Engagements run on site, remotely, or both, with no default either way: where the work happens is a property of the engagement, not a restriction I bring to it. Nothing here is legal advice; it is architecture and governance work that your counsel should review.

§ 04Questions

What Toronto clients ask.

Does OSFI Guideline E-23 apply to AI models?

Yes, explicitly. The revised guideline defines a model as an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and machine learning methods, which processes input data to generate results. The revisions also add context specifically for AI and ML model risk management, including models that depend on multiple components, diverse and dynamic data sources, and third-party elements.

When does E-23 take effect, and how much time is left?

It takes effect on 1 May 2027, following an eighteen-month transition period intended to let institutions assess current practice and adjust. The practical constraint is not the date but the inventory: institutions that discover in-scope AI systems late have to validate them, not merely list them.

Does it apply to foreign bank branches in Canada?

Yes. The guideline applies to all federally regulated financial institutions including foreign bank branches and foreign insurance company branches, to the extent consistent with applicable requirements and legal obligations related to their business in Canada as set out in Guideline E-4.

We already have a model risk framework. What changes?

Usually the scope rather than the framework. A discipline built for credit, capital and market risk models is often sound in method and narrow in coverage. The work is extending the same rigour to systems that were never classified as models, then proving the evidence exists for each of them.

Are you a Toronto firm?

No. I work through iSystematic Inc. from a Winnipeg base, with working stations in Winnipeg, Toronto and Calgary. iSystematic is a studio with its own build team, and the advisory and governance engagements are delivered by me directly rather than staffed to that team. Engagements run on site or remotely with no default either way. iSystematic Inc. is the Winnipeg company; Simplification Inc. is the Toronto one.

§ 05Start

Find the gap before someone else does.

The first conversation is a free thirty-minute fit call that qualifies the work in both directions. If it does not fit, you leave with a clearer read on where your governance stands and no cost. If you would rather start on your own, the Readiness Self-Assessment is twelve questions and the result is not gated behind a form.

§ 06Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is identify_relevant_service, list_consultation_slots and book_consultation, which map a described problem to an engagement shape, read real availability, and book a real 30 minute conversation. Booking writes to a real calendar and emails the attendee, so confirm the time with the person first.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, here is my situation: we have put an LLM into a regulated decision and our regulator has started asking questions. Work out which engagement shape fits and why, then show me real availability.”

It routes to a shape and shows the reasoning, so you can disagree with it. It reads live availability and can book a real conversation. It cannot agree a fee or a scope.

Fin · Toronto
Book a Fit Call →