Chapter 1 downloadSheet 69

The E-23 scope self-check.

Which of your AI systems sit inside the guideline, and which exemptions need a record.

Chapter 1 of OSFI E-23 for AI Systems sets out every field of this template in its text. The file is a convenience; the method is in the book. Every field is below, before anything is asked of you.

§ 01The template

Every field, before the form.

The ten-second testName one AI system in production that is not in your model inventory.

Where a field cites E-23, the guideline states it. Where it says the discipline’s, the handbook’s method chose it, inside what E-23 permits. Open any part to see its fields.

Part A. The three colors

Mark each check in Part B, and each field in Part C, in one of the three colors.

Color Meaning Examples Chapter 1 gives
1. Answers The framework already answers The five checks in Part B, where the framework meets them
2. Does not answer The framework does not answer A definition still written for quantitative estimates; a vendor policy that categorizes purchases by department; an inventory with no version or approver column
3. Never inventoried Systems that were never in an inventory, because the framework's definition did not reach them, or because someone decided they were tools Listed in Part D, which goes on top
Part B. Where the framework already answers
# The check, as Chapter 1 states it Basis Color (1 or 2)
B1 The institution is named in the scope sentence: "This guideline applies to all federally regulated financial institutions, including foreign bank branches and foreign insurance company branches" E-23
B2 The model definition is at least as broad as OSFI's: an application of theoretical, empirical, judgmental assumptions or statistical techniques, "including AI/ML methods", which processes input data to generate results, with a data input component, a processing component and a result component E-23
B3 External models are covered by reference to B-10: models or data sourced from external sources, including foreign offices and third-party vendors; externally developed models rated on a standalone basis; the processes that identify models across the enterprise include vendor and third-party models E-23
B4 Senior management holds the framework, and model risk reaches the board E-23
B5 The inventory carries the seventeen fields (Part C) E-23
Part C. The seventeen inventory fields

The guideline specifies the fields. The last column applies a test that is the discipline's and not the guideline's: can the field's value change without anyone editing it? Where it cannot, a person wrote it. A practitioner shown this test named the two fields most often written by hand: the monitoring status and the next review date (Chapter 1). The produced form of a monitoring status is the time and content of the monitor's last run.

# Field Required for Basis In the inventory (yes / no) Can its value change without anyone editing it? (yes: produced / no: typed)
C1 Model ID Every identified model E-23
C2 Name and description of key features and use Every identified model E-23
C3 Risk rating Every identified model E-23
C4 Owner Every identified model E-23
C5 Developer Every identified model E-23
C6 Origin Every identified model E-23
C7 Version Every model of non-negligible risk E-23
C8 Date of deployment into production Every model of non-negligible risk E-23
C9 Reviewer Every model of non-negligible risk E-23
C10 Approver Every model of non-negligible risk E-23
C11 Dependencies Every model of non-negligible risk E-23
C12 Data sources Every model of non-negligible risk E-23
C13 Approved uses Every model of non-negligible risk E-23
C14 Limitations, including exceptions Every model of non-negligible risk E-23
C15 Date of the most recent review Every model of non-negligible risk E-23
C16 Monitoring status Every model of non-negligible risk E-23
C17 Next review date Every model of non-negligible risk E-23
Part D. The third list: systems never inventoried (put this list on top)

The carve-out travels with every sentence about all models: only models whose inherent risk is determined to be non-negligible enter the inventory and full lifecycle governance, and an institution may define a rating category that implies negligible inherent risk and exempts such models, with a process to approve and track the exemptions (E-23). An institution that has not rated a system has decided none of the things the rating drives, and an unrated system is not a low-risk system (Chapter 1).

# System Why it was never in the inventory: the definition did not reach it, or someone decided it was a tool Rating set (tier and date), or "not rated" Where rated negligible: the record of the exemption's approval and tracking (E-23)
D1
D2
D3

Add rows as needed.

Part E. One rating, set

For each system on the third list, set the rating. The first three steps apply E-23's own factors; the fourth is the discipline's way of recording them (Chapter 1). The scale is the institution's; the book supplies none.

Step 1 and Step 2. E-23's factors. Write each factor with the fact that moved it.

# Factor Basis The fact that moved it
E1 System
E2 Materiality of the model's impact from its use E-23
E3 Business use or purpose E-23
E4 Complexity or level of autonomy E-23
E5 Reliability of data inputs E-23
E6 Customer impact E-23
E7 Regulatory risk: name the instruments the institution identifies, rather than leave the line blank. E-23 expects development data to adhere to "statutory, regulatory, and internal requirements for data ethics and customer privacy"; Chapter 1 records this line for a model that influences a decision about a person and processes personal data E-23

Step 3. Rated on its own. An externally developed model is rated on a standalone basis; the vendor's assurance informs the rating and does not set it. For a branch, a rating given by the parent "may not reflect the risk" to the branch (OSFI's letter); the book reads the parent's rating as an input to the branch's own standalone rating, not a substitute for it.

# Field Basis Entry
E8 Where the model is external or from a parent or head office: the vendor's assurance or the parent's rating, recorded as an input to this rating E-23; the input reading is the book's (Chapter 1)

Step 4. The record. The discipline's way of recording the rating (Chapter 1).

# Field Basis Entry
E9 Tier, on the institution's own scale E-23 (a categorical tier); the scale is the institution's
E10 Date set The discipline's (Chapter 1)
E11 Name of the person who set it The discipline's (Chapter 1)
E12 Date the rating is next re-assessed, at the interval the rating itself drives E-23
E13 Trigger events on which the rating is reviewed sooner E-23

The rating drives the frequency, intensity and scope of review, the documentation required, the level of authority needed to approve the model and any exemptions, the frequency, intensity and scope of monitoring, and the interval at which the rating itself is re-assessed (E-23). A rating recorded this way arrives with its reasons, and a later reader can dispute a factor rather than a word.

The claim, the test, the artifact (Chapter 1)

The claim. From 1 May 2027, what a system does and the risk it carries decide its scope, and a rating, even a low one, is a record.

The test. Mark your MRM framework in three colors: answers, does not answer, never inventoried.

The artifact. The framework, marked, with the third list on top.

nabeelkhan.com/e-23/scope-check. Questions: nabeelkhan.com/contact.

Get the Word file

Your email and role, and the download starts on this page. Nothing to confirm in your inbox.

Both starred fields are required.

Optional: your first name

Sent to Nabeel Khan: your email, role and region, and which template you took. Nothing is emailed to you unless you tick the box. Privacy notice.

Your download has started

Word file again

Next in the book: The gate record template, G1 to G5 (Chapter 5). Or take the E-23 check to see which template matters most for you.

§ 02Where this sits

Where this sits.

Chapter
Chapter 1Which of your AI systems sit inside the guideline, and which exemptions need a record.
Check
Theme 1, Scope and inventory; Theme 2, Rating and approvalThe E-23 readiness check points here for these themes. Take the check.
Understand
The scope of E-23, and the framework registryRead the method in Chapter 1 of OSFI E-23 for AI Systems; read the framework on its own page, with the DOI of its deposited specification.
§ 03Statements

The Office of the Superintendent of Financial Institutions (OSFI) does not endorse, approve or recommend this book, its author or any framework in it. Conformance with any framework named here is self-declared, by the institution, on its own record. Coldbrook, Thornbury and Pellbrook are fictional institutions, invented for the book.

Name one AI system in production that is not in your model inventory.

§ 04Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is get_framework, which returns the Defensible AI Framework Registry entry for any framework these templates are built on (the Five-Gate Deployment Model, the AVRF, PEVG, PARA), with its version and the concept DOI of its deposited specification. It does not yet hold the E-23 handbook or the guideline itself; for those, this page and the book are the source.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, get the Five-Gate Deployment Model and the AVRF from the framework registry, with their versions and DOIs, and tell me which gate a vendor model decision belongs to.”

A framework quoted from memory drifts. One returned from its registry, with the DOI of the deposited specification, does not.

Fin · E-23 Chapter 1 download
Get the template →