E-23 Readiness CheckSheet 68

Can you show it, today.

Twelve questions. Six themes. About six minutes.

Each question is worded from the handbook OSFI E-23 for AI Systems and asks about your own institution. Four answers each, and only the last one, Yes, and we could show the record, counts in full: E-23 is read through what an institution can show, not what it believes.

Free, and no form in front of it. The result appears on this page the moment you finish, and your answers never leave your browser unless you ask for your gap plan rows.

§ 01The check

Twelve questions, six themes.

Answer for the institution as it stands today, not as the policy describes it. Where the honest answer is that it exists but you could not produce it this week, the answer is Partly.

Theme
1

Scope and inventory

Chapter 1

Q01Is every system that meets E-23's definition of a model either on your model inventory with a risk rating, or exempted as negligible under a process that approves and tracks the exemption?

E-23 defines a model as an application of theoretical, empirical, judgmental assumptions or statistical techniques, "including AI/ML methods", which processes input data to generate results.

Where this question comes from

From Chapter 1. "The model inventory contains all models whose inherent risk is determined to be non-negligible to the institution; only models that carry risk to the institution need be captured on it and subjected to full lifecycle governance; and an institution may define a risk rating category that implies negligible inherent risk and exempts such models, with a process to approve and track the exemptions." And: "An institution that has not rated a system has decided none of those things, and an unrated system is not a low-risk system."

Q02Does your model inventory carry the seventeen fields E-23 sets out, the version and the approver among them?

Six fields for every identified model (model ID, name and description of key features and use, risk rating, owner, developer and origin), and eleven more for every model of non-negligible risk (version, date of deployment into production, reviewer, approver, dependencies, data sources, approved uses, limitations including exceptions, date of the most recent review, monitoring status and next review date).

Where this question comes from

From Chapter 1. "Its minimum fields are specified." Chapter 1 counts, among the marks of a framework that does not yet answer, "an inventory with no version or approver column."

Theme
2

Rating and approval

Chapters 1 and 5

Q03Is each system's rating recorded with each factor and the fact that moved it, the tier, the date, the name of the person who set it, the date it is next re-assessed and the trigger events on which it is reviewed sooner?
Where this question comes from

From Chapter 1. "Each factor is written with the fact that moved it, then the tier, the date and the name of the person who set it, and two things written beside the rating: the date it is next re-assessed, an interval the rating itself drives, and the trigger events on which it is reviewed sooner; for Cairn, a new Kelso version, which in August 2025 arrived without Pellbrook hearing of it."

Q04Does the approval record for each system name one person, cite the validation report by an identifier that would retrieve it, state what the system is approved to do and until when or under what trigger, and carry the version of the policy that was in force?
Where this question comes from

From Chapter 5. "Ask for the approval record for the system you have been carrying and read it for four things: whether it names one person or a body; whether it cites the validation report by an identifier that would retrieve it; whether it states what the system is approved to do and until when, or under what trigger; and whether it carries the version of the policy that was in force."

Theme
3

Validation

Chapters 3 and 5

Q05Does each validation report state, in the same document, what was not established: the properties the evidence did not cover, the changes it did not anticipate, and the parts of the system that were not in the room?
Where this question comes from

From Chapter 3, which asks for a statement of what a validation proved, written in four parts. "Fourth, and in the same document, what was not established: the properties the evidence did not cover, the changes it did not anticipate, the parts of the system that were not in the room."

Q06For each system, is the review independent from development, and is the person accountable at G2 never the person accountable at G3?

G2 is the validation gate, where a named validator decides on the independent review, and G3 is the approval gate, where a named accountable executive accepts the system into production use.

Where this question comes from

From Chapter 5. "Two separations hold at any size: whoever developed the system does not review it, because E-23 asks that review be independent from model development; and the person accountable at G2 is never the person accountable at G3, the discipline's own rule."

Theme
4

Third-party models

Chapter 9

Q07Does each vendor model's contract require notice before the model is retrained or rescaled?
Where this question comes from

From Chapter 9. "Before any questionnaire goes out, answer three questions from one vendor contract, one API response from last week and the institution's own records." The first is: "Does the contract require notice before the model is retrained or rescaled?" And: "A no to either of the first two is a contract term still to be written."

Q08Could your institution compute each vendor model's performance by segment from records it already holds?
Where this question comes from

From Chapter 9. "Could the institution compute the model's performance by segment from records it already holds?" And: "A no to the third means that when the vendor declines, the institution has nothing of its own to validate on."

Theme
5

Monitoring

Chapter 10

Q09Does every row of your trigger register carry a threshold, an owner and a consequence, all three fixed before the system was deployed?

A trigger register lists every condition the system's approval assumed, each with a threshold, one owner and a consequence written as a review, a rollback or a loop-back.

Where this question comes from

From Chapter 10. "A trigger is a threshold, an owner and a consequence, all three fixed before the system is deployed. Remove any one and what remains is a metric."

Q10Does your signal register keep the signals closed without becoming incidents, each with the reason and the name of the person who closed it?

The signal register is the trigger register's downstream: every trigger that fires, and every outside finding, enters it as a signal, confirmed or not.

Where this question comes from

From Chapter 10. "Open the signal register and look past the confirmed incidents for the signals closed without becoming one: each breach, alert or outside finding that someone set aside, with the reason and the name of the person who closed it."

Theme
6

Evidence and agents

Chapters 2, 6, 7 and 8

Q11For a decision one of your systems made on a given day, can the record show what it saw, what it drew on and which version produced it?
Where this question comes from

From Chapter 2. "The third kind is about the evidence. Not the evidence that was reviewed at approval, but the evidence that exists now, for the decision the model made on a given day: what it saw, what it drew on, which version produced it, what the monitoring showed at the time, and whether any of that can be put on a table." From Chapter 8: "Reconstructable evidence for the assistant is a wish until the retrieved passage identifiers are written to the log at the moment of the call, with the corpus version."

Q12For each agent, can you show one recorded refusal of a verified claim, from production or from a seeded test?

A recorded refusal of a verified claim is a claim the verifier accepted as true that a separate policy-enforcement point at the output refused on classification, authorization or policy, with the refusal recorded as a policy decision.

Where this question comes from

From Chapter 7. "Ask for one recorded refusal of a verified claim, in production or in a seeded test; if none exists, neither does the second boundary."

0 of 12 answered.

§ 02Your profile

Your profile, theme by theme.

Readiness profile against E-23's expectations as this book reads them. Conformance is self-declared.

Your gap plan rows, ready to fill

One row of the handbook’s gap plan for every answer short of the record, with the question, theme, chapter and template filled in and the owner and date left for you. Shaped like this:

Both starred fields are required.

Optional: your first name and institution type

Sent to Nabeel Khan: your email, role and region, and the questions you answered short of the record, so a reply can be about your plan rather than in general. Nothing is emailed to you unless you tick the box. Privacy notice.

QThemeCh.TemplateOwnerDate
Q04Rating and approval5Gate record  

Your profile appears here when all twelve questions are answered. Nothing is sent anywhere to produce it.

§ 03What this is not

What this check cannot do.

It reads your answers, not your records. A Yes you could not show is a Partly, and only you know which it is. It states no conformance level, ranks no institution and passes or fails nothing. It is a profile against E-23’s expectations as the handbook reads them; meeting E-23 is a supervisory judgment, and conformance with any framework named here is self-declared.

Where a question rests on a rule that is the handbook’s discipline rather than E-23’s, the result says so beside your answer.

§ 04Statements

The Office of the Superintendent of Financial Institutions (OSFI) does not endorse, approve or recommend this book, its author or any framework in it. Conformance with any framework named here is self-declared, by the institution, on its own record. Coldbrook, Thornbury and Pellbrook are fictional institutions, invented for the book.

Every answer short of the record is a line in the gap plan.

§ 05Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is get_framework, which returns the Defensible AI Framework Registry entry for any framework these templates are built on (the Five-Gate Deployment Model, the AVRF, PEVG, PARA), with its version and the concept DOI of its deposited specification. It does not yet hold the E-23 handbook or the guideline itself; for those, this page and the book are the source.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, get the Five-Gate Deployment Model and the AVRF from the framework registry, with their versions and DOIs, and tell me which gate a vendor model decision belongs to.”

A framework quoted from memory drifts. One returned from its registry, with the DOI of the deposited specification, does not.

Fin · E-23 Readiness Check
Start the check →