OSFI E-23 for AI Systems.
From Governance Requirements to Accountable Gates, Enforceable Controls and Reconstructable Evidence - A Practitioner's Handbook for Canadian Financial Institutions. By Dr. Nabeel A. Khan.
An implementation and operating handbook for bringing AI systems into a model risk governance lifecycle under Guideline E-23. It is not a compliance guide. The guideline sets expectations; the discipline in these pages is one way of meeting them.
Three questions, three answers.
What you hold at the end.
Work through the book with one of your own systems in hand, and by the last chapter the writing adds up to five artifacts, each produced in a named chapter. Five of the seven templates produce them; the other two, the scope self-check and the agent question set, are working tools used on the way.
Written for the seam.
The work sits at the seam between the person who signs and the person whose build is signed on. Three audiences are primary: model risk management, the heads of model risk and the validators; AI governance and responsible AI; and enterprise AI architecture and engineering. Internal audit and operational risk, and compliance and regulatory risk, read it for the record it leaves behind. Readers at a US bank or a US insurer, and readers with Islamic finance exposure, find their variant in Chapter 12.
Read it with one of your own systems in hand. Each chapter ends with something written about that system, and the templates for the work are collected at nabeelkhan.com/e-23.
Two formats, one text.
| Title | OSFI E-23 for AI Systems |
|---|---|
| Subtitle | From Governance Requirements to Accountable Gates, Enforceable Controls and Reconstructable Evidence - A Practitioner's Handbook for Canadian Financial Institutions |
| Author | Dr. Nabeel A. Khan |
| Publisher | iSystematic Inc., Canada |
| Release | 5 November 2026 |
| Ebook | ISBN 978-1-0678960-4-1 |
| Paperback | ISBN 978-1-0678960-5-8 |
Store links appear on this page when the listings are live.
The Office of the Superintendent of Financial Institutions (OSFI) does not endorse, approve or recommend this book, its author or any framework in it. Conformance with any framework named here is self-declared, by the institution, on its own record. Coldbrook, Thornbury and Pellbrook are fictional institutions, invented for the book.
Every field of every template, free to read today.
Ask your AI assistant instead.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is get_framework, which returns the Defensible AI Framework Registry entry for any framework these templates are built on (the Five-Gate Deployment Model, the AVRF, PEVG, PARA), with its version and the concept DOI of its deposited specification. It does not yet hold the E-23 handbook or the guideline itself; for those, this page and the book are the source.
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
“Using Concylium, get the Five-Gate Deployment Model and the AVRF from the framework registry, with their versions and DOIs, and tell me which gate a vendor model decision belongs to.”
A framework quoted from memory drifts. One returned from its registry, with the DOI of the deposited specification, does not.