Model risk is decided here.
Canadian model risk policy is written for federally regulated institutions, and most of those institutions run their model estate from Bay Street. That makes Toronto the market where an AI governance gap is most likely to be examined rather than merely noticed.
I am based in Winnipeg, Manitoba, and I serve Toronto on site and remotely, in whatever mix the engagement needs. Toronto is not a market I reach from a distance, because Simplification Inc., my Toronto company, is based here. What an examiner tests is not where the advisor sits. It is whether the evidence for every in-scope model can be produced on the day it is asked for.
OSFI Guideline E-23, effective 1 May 2027.
OSFI finalised the revised Guideline E-23 on Model Risk Management with an eighteen-month transition, and it takes effect for all federally regulated financial institutions on 1 May 2027. It reaches foreign bank branches and foreign insurance company branches operating in Canada as well as domestic institutions.
Two revisions matter more than the date. The scope expanded to all models at all federally regulated institutions, not a subset judged material by the institution itself. And the definition of a model now explicitly names AI and machine learning methods: an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and ML, which processes input data to generate results.
That second change is the one that catches people. An institution whose model inventory was built around credit and capital models can be entirely current under the old reading and materially incomplete under the new one, because the fraud model, the document classifier, the chatbot that quotes a rate, and the vendor scoring API were never inventoried as models at all.
Where the gap usually is.
What I bring to it.
A six-pillar model risk discipline, the MESA Framework scored per layer, the Five-Gate Deployment Model for what a system must clear before it ships and who may stop it, and independent validation experience. The AI Governance Teardown is scoped to answer the question an E-23 examiner will ask, which is not whether you have a policy but whether the evidence exists for every model in scope.
I founded iSystematic Inc. in Winnipeg and direct it. The Toronto company is not a flag planted for a landing page; it is why this is a market I work in rather than one I fly into, and why an institution preparing for 1 May 2027 gets an advisor on a schedule rather than one who arrives, reviews, and leaves the evidence problem behind.
Work is delivered through iSystematic Inc., a studio with its own team of builders, and the advisory and governance engagements are delivered by me rather than staffed to that team. Engagements run on site, remotely, or both, with no default either way: where the work happens is a property of the engagement, not a restriction I bring to it. Nothing here is legal advice; it is architecture and governance work that your counsel should review.
What Toronto clients ask.
Does OSFI Guideline E-23 apply to AI models?
Yes, explicitly. The revised guideline defines a model as an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and machine learning methods, which processes input data to generate results. The revisions also add context specifically for AI and ML model risk management, including models that depend on multiple components, diverse and dynamic data sources, and third-party elements.
When does E-23 take effect, and how much time is left?
It takes effect on 1 May 2027, following an eighteen-month transition period intended to let institutions assess current practice and adjust. The practical constraint is not the date but the inventory: institutions that discover in-scope AI systems late have to validate them, not merely list them.
Does it apply to foreign bank branches in Canada?
Yes. The guideline applies to all federally regulated financial institutions including foreign bank branches and foreign insurance company branches, to the extent consistent with applicable requirements and legal obligations related to their business in Canada as set out in Guideline E-4.
We already have a model risk framework. What changes?
Usually the scope rather than the framework. A discipline built for credit, capital and market risk models is often sound in method and narrow in coverage. The work is extending the same rigour to systems that were never classified as models, then proving the evidence exists for each of them.
Are you a Toronto firm?
No. I work through iSystematic Inc. from a Winnipeg base, with working stations in Winnipeg, Toronto and Calgary. iSystematic is a studio with its own build team, and the advisory and governance engagements are delivered by me directly rather than staffed to that team. Engagements run on site or remotely with no default either way. iSystematic Inc. is the Winnipeg company; Simplification Inc. is the Toronto one.
Find the gap before someone else does.
The first conversation is a free thirty-minute fit call that qualifies the work in both directions. If it does not fit, you leave with a clearer read on where your governance stands and no cost. If you would rather start on your own, the Readiness Self-Assessment is twelve questions and the result is not gated behind a form.
Ask your AI assistant instead.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is identify_relevant_service, list_consultation_slots and book_consultation, which map a described problem to an engagement shape, read real availability, and book a real 30 minute conversation. Booking writes to a real calendar and emails the attendee, so confirm the time with the person first.
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
“Using Concylium, here is my situation: we have put an LLM into a regulated decision and our regulator has started asking questions. Work out which engagement shape fits and why, then show me real availability.”
It routes to a shape and shows the reasoning, so you can disagree with it. It reads live availability and can book a real conversation. It cannot agree a fee or a scope.