ReadinessSheet 64
Two routes to ready.
Which one is yours turns on one question.
Readiness, on this site, means one thing: whether your organisation can show the record a board, an auditor or a supervisor would ask for, for the AI systems it actually runs. Not whether it has a policy. Whether the record exists.
There are two routes to finding out. Each starts with a free check you run in your browser, with no form in front of it, and each ends, only if you need it, in one fixed-scope paid diagnosis. Nothing is sold before a diagnosis.
§ 01Which route
Where you are supervised decides it.
Canada
E-23 ReadinessFor federally regulated financial institutions in Canada: banks, insurers, trust and loan companies and foreign branches. Measured against what OSFI Guideline E-23 expects, as the handbook OSFI E-23 for AI Systems reads it. That handbook is an independent practitioner’s book by the author of this site, released 5 November 2026; OSFI does not endorse it.
US
Model risk under SR 26-2For a US bank under SR 26-2, which replaced SR 11-7, or a US insurer under the NAIC bulletin. The same discipline, read against your supervisor: the handbook’s Chapter 12 sets out both US variants, and the model risk page is the practice’s overview of model risk governance, SR 26-2 among the regimes it reads. SR 26-2’s own footnote 3 places generative and agentic AI outside its scope, so for those systems the AI Governance route below is the one that applies.
GCC
AI Governance ReadinessFor banks, Islamic financial institutions and government entities in Saudi Arabia, the UAE, Qatar, Kuwait, Bahrain and Oman, including model risk under your own central bank and Sharia validation inside it, which the Sharia AI Compliance Framework sets out from one record set for both authorities. Measured on the MESA Framework, whose first layer, the Regulatory Floor, is your supervisor’s rules. Written from AI Governance and Compliance Frameworks for the Middle East.
Anywhere
AI Governance ReadinessFor any other jurisdiction, and for a Canadian institution whose question is wider than model risk: the operating model, the board, the strategy.
Unsure? Run either free check. Both take a few minutes, both score in your browser, and each says plainly when the other route would serve you better.
§ 02E-23 Readiness
Can you show it by 1 May 2027.
OSFI Guideline E-23 takes effect on 1 May 2027 and names artificial intelligence and machine learning inside its definition of a model. The question this route answers is narrow on purpose: for the AI systems in scope, can you show what E-23 expects?
Free
The E-23 readiness checkTwelve questions across six themes, scored in your browser. A profile per theme and the weakest theme named, with the chapter and the template that address it.
Free
The seven templatesOne for each chapter of the handbook that uses one, every field shown on its page before anything is asked: the scope self-check, the gate record, the declaration for a control, the questions for an agent, the vendor assessment, the trigger register and the gap plan.
Free
A working sessionNinety minutes, one per institution: one real system walked through the five approval points the handbook calls gates, from data and design to operation. It runs only when the person who validates the system and the person who builds or runs it both attend, because the gap sits between them.
Paid
The E-23 Readiness ReviewThree weeks, fixed fee, disclosed on the Fit Call. A dated gap plan to 1 May 2027, every gap with an owner.
§ 03AI Governance Readiness
Is it defensible, end to end.
For any regulated organisation or government entity, in any jurisdiction, and for model risk under any supervisor other than OSFI. The question: is your AI governance defensible, from the regulatory floor down to the running system? In the GCC, the Regulatory Floor is read against the authorities the GCC page sets out, with Sharia governance inside it wherever Islamic finance applies. MESA scores four altitudes separately (the Regulatory Floor, the Strategic Compass, the Operational Machinery and the Technical Substrate; the free check calls them layers), because one combined grade is what lets a strong policy posture hide a substrate that cannot hold it up.
Free
The AVRF questionnaireFor organisations buying AI from vendors. A deposited instrument any organisation may issue to any vendor without asking permission.
Free
The Fit CallThirty minutes. Bring your profile and it becomes the agenda.
§ 04How it works
Four rules hold it together.
1
Every step is useful without the one after it.The free checks and templates stand on their own. You never have to go further to get value from the step you are on.
2
Nothing is sold before a diagnosis.Training, delivery and the retainer follow one of the paid diagnoses, never a catalogue.
3
One diagnosis first.An organisation buys one. The second is offered only when the first one’s findings show the need, and when both are bought the second reuses the first’s evidence.
4
Both sides of the seam are in the room.The person who signs and the person who builds. Every readout has both, because the gap almost never sits on one side alone.
§ 05What this is not
What none of this claims.
No check on this page, and no diagnosis behind it, makes an organisation anything. Each produces a record that can be read. Conformance with any framework is self-declared, by the organisation, on its own record. No regulator endorses these instruments, and none of them is a standard of any regulator or standards body.
Start with the check. It costs a few minutes.
§ 06Ask an assistantLive, no key
Ask your AI assistant instead.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is start_assessment and score_assessment, which run the same 50-question MESA self-assessment this page describes, and return a scored result with the weakest layer named. The output states in its own text that it is a self-assessment and not an audit.
01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
02 · Ask
“Run the MESA self-assessment from Concylium against my organisation. Ask me the questions one layer at a time, then score it and tell me the weakest control.”
Fifty published questions, each with its five-level rubric. The score is preliminary and says so in its own output.