Law / Canada

OSFI Guideline E-23, Enterprise-Wide Model Risk Management for Deposit-Taking Institutions (2017)

OSFI Guideline E-23 (2017), Enterprise-Wide Model Risk Management for Deposit-Taking Institutions

Guidance, not a law: the Office of the Superintendent of Financial Institutions's reading of Bank Act: investment and lending policies, standards and procedures. It binds nobody by itself; the law it reads does.

Guidance on an AI sector rules rule, addressed to private bodies.

Criminal exposure
No
Instrument type
guidance published by a regulator
Obligation class
Governance
Audit expectation
periodic
Who audits it
Internal independent, Independent third party
Where the report goes
Kept

As of .

What the regulator expects

  • It reaches you if you operate as a bank, bank holding company, federally regulated trust and loan company or cooperative retail association (foreign bank branches are outside its scope); it applies in proportion to the nature, size, complexity and risk profile of your institution, with fuller expectations for an institution approved to use an internal model for regulatory capital purposes, and every line below states what OSFI expects.
  • OSFI expects a sound governance framework for model risk, with policies and procedures that cover each stage of a model's life cycle (development, validation, approval, review, modification and decommission) and that name the stakeholders and their roles, responsibilities and authorities.
  • Senior management should develop and operationalize enterprise-wide model risk management policies, and each model in use should have an owner who is clearly assigned and who keeps thorough documentation at each stage of the model's life cycle.
  • Implement a model risk materiality classification scheme that ranks the risk of each model, review it periodically, and set triggers for re-assessing a model's materiality.
  • An internal models approved institution should have independent model vetting processes, as a second line of defense, to check whether models are sound and fit for their intended purpose, and a reviewer who does not direct or engage in model development.
  • Models should be subject to a periodic review with a frequency consistent with their model risk materiality assessments.
  • Applying a vendor product does not remove the need for the same vetting, approval, ongoing validation, decommissioning and documentation as for in-house models; seek adequate technical documentation from the vendor, set policies on selecting, monitoring and retaining vendor models, and develop contingency plans for material models.
  • Internal audit, using individuals independent of model development, validation or use, should assess the effectiveness and adequacy of the model risk policy and compliance with it, including whether validation is independent and occurring on schedule and whether documentation and the model inventory records are consistent and complete.
  • Maintain an up-to-date inventory of all models in use and recently decommissioned, controlled by a list of authorized individuals, and make it available to OSFI on request.
  • A standardized institution should, at a minimum, provide OSFI with an inventory of all models in use and identify and assess its most material models.

Who enforces it

Enforcement body

Office of the Superintendent of Financial Institutions, which supervises financial institutions to make sure they are following its guidance.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

OSFI expected internal models approved institutions to comply with Guideline E-23 by . Standardized institutions had until to become compliant with the guideline. The guideline applies to banks, bank holding companies, federally regulated trust and loan companies and cooperative retail associations. OSFI excluded foreign bank branches from the scope of the guideline.

The guideline is to be interpreted in the context of a proportionality principle whereby applicability is commensurate with the nature, size, complexity and risk profile of the institution. OSFI distinguishes institutions with approval to use an internal model for regulatory capital purposes from other, standardized institutions.

OSFI's minimum expectation of a standardized institution includes providing OSFI with an inventory of all models in use and identifying and assessing its most material models. The guideline describes a model as a methodology, system or approach that applies theoretical and judgmental assumptions and statistical techniques to process input data in order to generate quantitative estimates.

It says internal models approved institutions should have independent model vetting processes as a second line of defense. It says models should be subject to a periodic review with a frequency consistent with their model risk materiality assessments. It says adopting a vendor product does not eliminate the need to apply a similar process for vetting, approval, ongoing validation, decommissioning and documentation as for in-house developed models.

It says internal audit, as the third line of defense, should assess the overall effectiveness and adequacy of the model risk policy and determine compliance by the various stakeholders with that policy. OSFI expects institutions to maintain an up-to-date inventory of all models in use and recently decommissioned. The model inventory should be made available upon request by OSFI.

OSFI's Guideline B-12 on interest rate risk management refers institutions to the 2017 Guideline E-23 for details of the model governance process. A revised Guideline E-23, Model Risk Management, was released on . The effective date of the revised guideline for all federally regulated financial institutions is . OSFI describes its guidelines as outlining expectations for financial institutions. OSFI says it uses its guidance as a basis for its supervision.

Back to the example  ·  Lint your app