OSFI Guideline E-23, Model Risk Management (2027)
OSFI Guideline E-23 (2027), Model Risk Management
Guidance, not a law: the Office of the Superintendent of Financial Institutions's reading of Bank Act: investment and lending policies, standards and procedures. It binds nobody by itself; the law it reads does.
Guidance on an AI sector rules rule, addressed to private bodies.
- Criminal exposure
- No
- Instrument type
- guidance published by a regulator
- Obligation class
- Governance
- Audit expectation
- periodic
- Who audits it
- Internal independent, Independent third party
- Where the report goes
- Kept
As of .
What the regulator expects
- It reaches you if you operate as a federally regulated financial institution, including a foreign bank branch or foreign insurance company branch to the extent the guideline is consistent with your obligations in Canada; OSFI lists banks, foreign bank branches, life insurance and fraternal companies, property and casualty companies, and trust and loan companies, and excludes pension plans. It applies on a risk basis, proportional to your size, strategy, risk profile, the nature, scope and complexity of your operations and your interconnectedness, and every line below states what OSFI expects.
- OSFI expects you to have a model risk management framework that fits your broader risk and governance framework, reflects your risk appetite for model risk, defines how model risk is identified, assessed, managed, monitored and reported, covers models or data sourced from third-party vendors (pursuant to Guideline B-10), and is reviewed periodically, especially as new technologies emerge.
- You should identify and track all models in use or recently decommissioned, including vendor and third-party models, and keep every model with non-negligible inherent model risk in a model inventory that is comprehensive, maintained at the enterprise level, accurate and updated in a timely manner.
- You should assign each model a model risk rating based on inherent model risk, supported by clear, measurable criteria that combine quantitative and qualitative factors, and review and update the rating regularly, including when a trigger event occurs; externally developed models should be rated on a standalone basis.
- You should scale the frequency, intensity and scope of model review, documentation, approval authority and monitoring to the model's inherent risk rating, and keep your model risk management capabilities appropriate to the complexity of your models, with correspondingly mature governance and oversight for extensive use of advanced AI/ML techniques.
- Data used to develop a model should be suitable for its intended use: accurate and fit for use, relevant and representative, compliant with statutory, regulatory and internal requirements for data ethics and customer privacy, traceable and timely.
- For models using advanced techniques such as AI/ML, model owners should consider the level of transparency and explainability required, the need for alternative controls, and the potential for biased outcomes, negative social and ethical implications or privacy risks.
- You should have a model review process that is independent from model development and that assesses conceptual soundness and performance, using internal reviewers or objective third parties, with the extent and frequency of review commensurate with the model risk rating and prompted by new models, modifications, performance breaches, significant data changes and scheduled risk-based periodic reviews.
- You should deploy models in an environment with quality and change control processes, test that the model operates as expected in production, document deployment procedures, and assess related risks such as cybersecurity risk and infrastructure vulnerabilities before deployment (see OSFI Guidelines B-13 and E-21).
- You should have defined standards for model monitoring that cover frequency, scope and evaluation criteria by risk rating and model type, thresholds for breaches, contingency plans for model unavailability, deterioration or failure, and processes for AI/ML challenges such as autonomous decision making, autonomous re-parametrization and model drift.
- You should follow a disciplined process to decommission a model: alert stakeholders, retain the retired model and its documentation for a set period, determine additional actions for third-party models, and monitor downstream effects.
- At a minimum, maintain for each identified model its ID, name and description of key features and use, model risk rating, owner, developer and origin, and for each model in the inventory also its version, deployment date, reviewer, approver, dependencies, data sources, approved uses, limitations, most recent review date, monitoring status and next review date.
Who enforces it
Enforcement body
Office of the Superintendent of Financial Institutions, which supervises financial institutions to make sure they are following its guidance.
What this law does
The Office of the Superintendent of Financial Institutions (OSFI) released the final Guideline E-23 on model risk management on . The guideline's effective date for all federally regulated financial institutions is . OSFI describes the guideline as principles-based and as setting out its expectations for effective enterprise-wide model risk management using a risk-based approach.
The guideline applies to all federally regulated financial institutions, including foreign bank branches and foreign insurance company branches, to the extent it is consistent with applicable requirements and legal obligations related to their business in Canada. OSFI's guidance library lists the sectors the guideline reaches as banks, foreign bank branches, life insurance and fraternal companies, property and casualty companies, and trust and loan companies.
Pension plans are excluded from the scope of the guideline due to their distinct supervisory framework. The guideline applies on a risk basis, proportional to the institution's size, strategy, risk profile, nature, scope and complexity of operations, and interconnectedness.
The guideline defines a model as an application of theoretical, empirical or judgmental assumptions or statistical techniques, including artificial intelligence and machine learning (AI/ML) methods, that processes input data to generate results. For the purposes of the guideline, OSFI points to the OECD definition of an AI system, which it says can be based on one or multiple models.
The guideline says a model inventory should be a comprehensive inventory of models whose inherent risk is determined to be non-negligible to the institution. Under Principle 2.2, each model should be assigned a model risk rating. Under Principle 3.4, institutions should have a process to independently assess the conceptual soundness and performance of models, and may use the work of internal reviewers or objective third parties.
Under Principle 3.6, institutions should have defined standards for model monitoring and model decommission. The guideline says an institution's model risk management framework should cover models or data sourced from third-party vendors, pursuant to Guideline B-10 on third-party risk management.
OSFI's letter says institutions should comply with the third-party risk management principles of Guideline B-10 and should ensure that third-party models receive validation and monitoring commensurate to the model risk. Before deployment, the guideline says institutions should assess related risks such as cybersecurity risk and infrastructure vulnerabilities, and refers to Guidelines B-13 and E-21.
The revised draft of the guideline included several changes relative to the 2017 Guideline E-23 on enterprise-wide model risk management for deposit-taking institutions. OSFI describes its guidelines as outlining expectations for financial institutions. OSFI says it uses its guidance as a basis for its supervision.