The BOE Declaration template and the Coldbrook example.
Chapter 6 of OSFI E-23 for AI Systems sets out every field of this template in its text. The file is a convenience; the method is in the book. Every field is below, before anything is asked of you.
Every field, before the form.
Where a field cites E-23, the guideline states it. Where it says the discipline’s, the handbook’s method chose it, inside what E-23 permits. Open any part to see its fields.
Part A. The declaration for one control
"Every control operated under any framework in this registry MUST carry a BOE Declaration: a statement of the Boundary it fixes, the Optimizer it frees, and the Evidence proving the boundary held." (Chapter 6, quoting the specification)
| # | Field | What it states (Chapter 6) | Entry |
|---|---|---|---|
| A1 | Control | The control the declaration is written for | |
| A2 | Boundary | The clause the control refuses to cross: the one thing that may not happen while the control is in force, in one clause. A control that cannot state its boundary in one clause has not yet decided what it forbids | |
| A3 | Optimizer | What the control leaves free: which choices of model, method, threshold, prompt and infrastructure the control does not touch | |
| A4 | Evidence | The artifact that would show the boundary held, named so that a reader could ask for it and either receive it or learn that it does not exist. Not the assurance that it held, and not the policy that says it should | |
| A5 | Does the artifact exist? (yes / no) | Whether the artifact exists is a matter of fact. A declaration written for a control that produces no artifact is a correct declaration of a control that cannot be evidenced |
The limit. "A BOE Declaration is not a control, an assurance, or a claim that the boundary in fact held." It states which boundary a control fixes and which artifact would show that it held.
For the engineer (Chapter 13). Mark each declaration deterministic or statistical, because the two carry different evidence.
| # | Field | What it states (Chapter 13) | Entry |
|---|---|---|---|
| A6 | Kind: deterministic boundary or statistical guardrail | A deterministic boundary refuses by construction; a statistical guardrail refuses by judgment and holds to a stated miss rate, never absolutely | |
| A7 | Evidence, if deterministic | The configuration by version, a test that tries to cross it and fails, and the log of every refusal | |
| A8 | Evidence, if statistical | The guardrail's version, and a judge model's own pinned version; a versioned test set containing the forbidden language; the miss rate on that set, with the interval its size supports; and the rate at which production responses are sampled and read by a person |
Part B. One record, rewritten in the declaration's shape
Take the approval record of one system, or, if no approval record exists as such, the minute or the email that stands where one should be. Fill each field from what exists. Where nothing exists, leave the field empty, and do not fill it with what the institution intends to do, because an intention is not an artifact and the shape is built to reject one (Chapter 6).
| # | Field | Basis | The record |
|---|---|---|---|
| B1 | System and version | Five-Gate record field (Chapter 5) | |
| B2 | Gate | Five-Gate record field | |
| B3 | Decision | Five-Gate record field | |
| B4 | Boundary fixed | The declaration (Chapter 6) | |
| B5 | Optimizer freed | The declaration (Chapter 6) | |
| B6 | Evidence relied on, by identifier | The declaration; E-23 asks that the review be documented and reported with an overall recommendation on approval to the model approver | |
| B7 | Approved use | Five-Gate; E-23: the inventory carries approved uses | |
| B8 | Accountable person | The discipline's: one named person, a narrower choice inside E-23, which allows the Model Approver to be a unit, an individual or a committee | |
| B9 | Conditions, each with a date and an owner | Five-Gate (Chapter 5) | |
| B10 | Expiry or revalidation trigger | Five-Gate (Chapter 5) | |
| B11 | Policy version in force | Five-Gate (Chapter 5) | |
| B12 | Date | Five-Gate (Chapter 5) |
For a gate other than G3, Chapter 6 reads the five gates' boundaries, optimizers and evidence as the gate record template sets them out (nabeelkhan.com/e-23/gate-record, Part 2).
Part C. The three questions
Put the three questions to the record and count how many places it sends you (Chapter 6, the test). A record in the declaration's shape answers all three from one page.
| # | Question | Where the answer sits in the record | Answered from this page (yes / no) | Places it sends you |
|---|---|---|---|---|
| C1 | Who approved? | The name in the record (B8) | ||
| C2 | On what evidence? | The artifact, cited by identifier (B6) | ||
| C3 | What record exists now? | The record itself, with its policy version and its date (B11, B12) |
Part D. Empty fields, carried to the gap plan
The empty fields are the first entries in the gap plan of Chapter 11, each naming a specific artifact, the gate that requires it, and the person who will have to produce it (Chapter 6).
| # | Empty field | The artifact it names | The gate that requires it | The person who will have to produce it |
|---|---|---|---|---|
| D1 | ||||
| D2 |
The claim, the test, the artifact (Chapter 6)
The claim. Records written in one shape join; records in different shapes lie side by side and answer nothing, however many are kept.
The test. Put the three questions to one approval record and count how many places it sends you.
The artifact. That record, rewritten as a BOE Declaration, its empty fields left empty.
Worked example: Coldbrook, Ask Coldbrook, the G3 record
Coldbrook is fictional. The institutions, systems, people and incidents in the book are fictional composites constructed to teach; they are not drawn from any real institution, incident or client engagement. Every value below is a fact the book states about Coldbrook; where the book does not give a value, the field says so.
Coldbrook, before
The approval of Ask Coldbrook is a record dated 12 June 2025, and it says that the Digital Channels Steering Committee, eleven members, approved the assistant, with no single signatory. The evidence before the committee was the May 2025 validation. Monitoring would cover latency, containment rate and customer satisfaction; logging would keep transcripts ninety days and retrieved document identifiers seven, with the prompt template version and no model version; the model was the provider's current default, unpinned.
Put to that record, the three questions were answered as follows (Chapter 6):
| Question | What the June 2025 record could answer |
|---|---|
| Who approved the assistant? | A committee of eleven |
| On what evidence? | A test that proved the system answered 240 prompts acceptably on one day in May, against an index and a model version that were not written down |
| What record exists now? | For the conversation of 14 October, a transcript and a prompt template version, with no retrieved document identifiers and no model version |
Nothing in the June record was false. It was written in the shape of a minute.
Coldbrook, after
The same approval as a G3 record in the declaration's shape, every field filled from what existed in June 2025 and left empty where nothing did (Chapter 6).
| Field | The record |
|---|---|
| System and version | Ask Coldbrook; prompt template version as logged; model: the provider's current default, unpinned. The version field cannot be completed, and that is the first finding |
| Gate | G3 Approval |
| Decision | Approved, by the Digital Channels Steering Committee |
| Boundary fixed | A system nobody is answerable for may not enter production |
| Optimizer freed | Which customer-facing systems the bank chooses to run; inside the approval, the team's freedom over tone, prompt, retrieval ranking and containment |
| Evidence relied on | The May 2025 validation, by identifier: a model card review and a 240-prompt test set for tone, refusal and product accuracy, examined against one model version and one index on one day |
| Approved use | Product, servicing and account questions, on the envelope the validation examined, and no wider |
| Accountable person | Empty. Eleven members, no single signatory. The record cannot be completed, and that is the second finding |
| Conditions | Retrieval index unclassified for what may be spoken to a customer; model version not logged; commitment language not monitored. Each would need a date and an owner. None had either |
| Expiry or revalidation trigger | Empty. A provider model version change and an addition to the retrieval index are the two triggers the record would need to name. Neither was named |
| Policy version in force | Nothing in the case record shows one |
| Date | 12 June 2025 |
Every empty field names something that turned out, on 14 October 2025, to be the thing that mattered: the version that changed on 3 October, the index that grew on 9 September, the commitment language nothing watched, and the person nobody had named (Chapter 6).
The three questions, asked of the rewritten record
| Question | The rewritten record's answer (Chapter 6) |
|---|---|
| Who approved? | The record says that no one did, in the sense the question means, and it says so in June rather than in November |
| On what evidence? | A named validation with a stated scope, so that a reader can see at once that September's index and October's model lay outside it |
| What record exists now? | This one, with its conditions dated and owned, its triggers named, and its policy version recorded |
Empty fields, carried to the gap plan
| Empty or incomplete field | What it named (Chapter 6) | The gate that requires it | The person who will have to produce it |
|---|---|---|---|
| System and version | The model version, which changed on 3 October 2025 | G3 Approval (this record) | Marcus Leblanc, in conversational platforms, owns Coldbrook's evidence line, because the fix is a change to what the build emits and retains (Chapter 11) |
| Accountable person | The person nobody had named | G3 Approval | [not stated in the book] |
| Conditions | The retrieval index, unclassified, which grew on 9 September 2025; the model version, not logged; the commitment language nothing watched | G3 Approval | [not stated in the book] |
| Expiry or revalidation trigger | A provider model version change; an addition to the retrieval index | G3 Approval | [not stated in the book] |
| Policy version in force | [not stated in the book] | G3 Approval | [not stated in the book] |
The rewritten record does not make Coldbrook's decision a better one. It makes it a decision, with a person, a scope, a set of conditions and a trigger, instead of a meeting (Chapter 6).
nabeelkhan.com/e-23/boe-declaration. Questions: nabeelkhan.com/contact.
Your download has started
Next in the book: The PEVG and PARA review question set (Chapter 7). Or take the E-23 check to see which template matters most for you.
Where this sits.
The Office of the Superintendent of Financial Institutions (OSFI) does not endorse, approve or recommend this book, its author or any framework in it. Conformance with any framework named here is self-declared, by the institution, on its own record. Coldbrook, Thornbury and Pellbrook are fictional institutions, invented for the book.
Pick one control. Is it a boundary the system enforces, or an optimization it pursues?
Ask your AI assistant instead.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is get_framework, which returns the Defensible AI Framework Registry entry for any framework these templates are built on (the Five-Gate Deployment Model, the AVRF, PEVG, PARA), with its version and the concept DOI of its deposited specification. It does not yet hold the E-23 handbook or the guideline itself; for those, this page and the book are the source.
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
“Using Concylium, get the Five-Gate Deployment Model and the AVRF from the framework registry, with their versions and DOIs, and tell me which gate a vendor model decision belongs to.”
A framework quoted from memory drifts. One returned from its registry, with the DOI of the deposited specification, does not.