E-23 Readiness Review.
The paid diagnosis on the E-23 route. Your model risk framework read against E-23, two or three of your own systems tested against the handbook’s five artifacts, and every gap placed on the four altitudes of the MESA Framework, owned and dated.
Delivered personally by Nabeel Khan, through iSystematic Inc., not staffed to a bench. Remote, with one day on site. Fixed fee, disclosed on the Fit Call. It is the readiness assessment the handbook names at the back of the book, under Practitioner resources.
One week each.
At a small institution.
At a small institution the same few names fill the owner column. E-23 applies on a risk basis, but it offers no lighter validation for a smaller institution, so the handbook sizes the work through the risk rating and through the approved, tracked exemption for systems of negligible risk. Two separations hold at any size, and the other roles may combine.
The Review follows the same rule: the sample is the systems you have, and the scope, and with it the fixed fee, is set on the Fit Call before anything is signed.
Four things you keep.
What the Review does not do.
It does not attest conformance, approve any model, or substitute for your validation function. E-23 permits the Model Approver to be a unit, an individual or a committee; where the Review asks for one named signature, that is the handbook’s discipline, not the guideline’s requirement. Conformance with any framework named here is self-declared, by the institution, on its own record.
If the findings show gaps above model risk, in the operating model, the board or the strategy, the Review says so and names the AI Governance Teardown. It does not sell it to you in the same breath: one diagnosis first.
What can follow.
The gap plan’s owners are the natural participants in the E-23 Practitioner Course. Implementation, with your teams executing the plan, and an advisory retainer are offered only after the Review, and only where the plan shows the need.
The Office of the Superintendent of Financial Institutions (OSFI) does not endorse, approve or recommend this book, its author or any framework in it. Conformance with any framework named here is self-declared, by the institution, on its own record. Coldbrook, Thornbury and Pellbrook are fictional institutions, invented for the book.
Thirty minutes to find out whether a Review is the right next step.
Ask your AI assistant instead.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is get_framework, which returns the Defensible AI Framework Registry entry for any framework these templates are built on (the Five-Gate Deployment Model, the AVRF, PEVG, PARA), with its version and the concept DOI of its deposited specification. It does not yet hold the E-23 handbook or the guideline itself; for those, this page and the book are the source.
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
“Using Concylium, get the Five-Gate Deployment Model and the AVRF from the framework registry, with their versions and DOIs, and tell me which gate a vendor model decision belongs to.”
A framework quoted from memory drifts. One returned from its registry, with the DOI of the deposited specification, does not.