E-23 Readiness ReviewSheet 66

E-23 Readiness Review.

Three weeks. A dated gap plan to 1 May 2027.

The paid diagnosis on the E-23 route. Your model risk framework read against E-23, two or three of your own systems tested against the handbook’s five artifacts, and every gap placed on the four altitudes of the MESA Framework, owned and dated.

Delivered personally by Nabeel Khan, through iSystematic Inc., not staffed to a bench. Remote, with one day on site. Fixed fee, disclosed on the Fit Call. It is the readiness assessment the handbook names at the back of the book, under Practitioner resources.

§ 01The three weeks

One week each.

Week 1
The framework and the inventoryThe model risk framework read against E-23. The inventory sampled for AI and vendor systems. Scope and exemptions tested, because only models of non-negligible inherent risk enter full lifecycle governance and the exemption is where an estate quietly disappears.
Week 2
Two or three systems, testedChosen with you, at least one AI system and one vendor model, each tested against the five artifacts: gate records, a BOE Declaration, a vendor scored with a gate decision, a trigger register, a gap plan.
Week 3
The planEvery gap placed on MESA’s four altitudes (the Regulatory Floor, the Strategic Compass, the Operational Machinery and the Technical Substrate), so that a gap in the running system is never mistaken for a gap in the policy. Each given an owner and a date and sequenced by dependency. A one-page board summary. A readout to the sponsor with the engineering lead present.
§ 02At a small institution

At a small institution.

At a small institution the same few names fill the owner column. E-23 applies on a risk basis, but it offers no lighter validation for a smaller institution, so the handbook sizes the work through the risk rating and through the approved, tracked exemption for systems of negligible risk. Two separations hold at any size, and the other roles may combine.

The Review follows the same rule: the sample is the systems you have, and the scope, and with it the fixed fee, is set on the Fit Call before anything is signed.

§ 03What you hold

Four things you keep.

1
A dated gap plan to 1 May 2027Every gap with one owner and one date, in dependency order.
2
Artifact status for the sampled systemsWhich of the five artifacts exist, which exist in name only, and which are missing.
3
A board summaryOne page, readable by a director who saw nothing else.
4
Your own answers beside the evidenceIf you took the free E-23 check, your answers sit next to the evidenced findings, so the distance between what was believed and what was shown is on the page.
§ 04What it does not do

What the Review does not do.

It does not attest conformance, approve any model, or substitute for your validation function. E-23 permits the Model Approver to be a unit, an individual or a committee; where the Review asks for one named signature, that is the handbook’s discipline, not the guideline’s requirement. Conformance with any framework named here is self-declared, by the institution, on its own record.

If the findings show gaps above model risk, in the operating model, the board or the strategy, the Review says so and names the AI Governance Teardown. It does not sell it to you in the same breath: one diagnosis first.

§ 05Afterward

What can follow.

The gap plan’s owners are the natural participants in the E-23 Practitioner Course. Implementation, with your teams executing the plan, and an advisory retainer are offered only after the Review, and only where the plan shows the need.

§ 06Statements

The Office of the Superintendent of Financial Institutions (OSFI) does not endorse, approve or recommend this book, its author or any framework in it. Conformance with any framework named here is self-declared, by the institution, on its own record. Coldbrook, Thornbury and Pellbrook are fictional institutions, invented for the book.

Thirty minutes to find out whether a Review is the right next step.

§ 07Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is get_framework, which returns the Defensible AI Framework Registry entry for any framework these templates are built on (the Five-Gate Deployment Model, the AVRF, PEVG, PARA), with its version and the concept DOI of its deposited specification. It does not yet hold the E-23 handbook or the guideline itself; for those, this page and the book are the source.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, get the Five-Gate Deployment Model and the AVRF from the framework registry, with their versions and DOIs, and tell me which gate a vendor model decision belongs to.”

A framework quoted from memory drifts. One returned from its registry, with the DOI of the deposited specification, does not.

Fin · E-23 Readiness Review
Book the Fit Call →