OSFI E-23 · MODEL RISK · 1 MAY 2027

The model inventory you hold probably isn’t the whole estate.

E-23 binds the institution, not the supplier - an enterprise framework, a rated inventory and independent review, in force 1 May 2027.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
A supervisor asks for the file, not the intention
Model inventory Risk rating Independent review Five lifecycle stages AI and ML in scope

Our promise

“A guideline is a shape. The audit trail is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $25,000, and nothing is charged until you approve it.

Each additional system
$6,000
Re-audit, same scope
$16,000
Renewal, every twelve months
$21,000 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

Guideline E-23, in three chapters

The Guideline

OSFI published Guideline E-23 on 11 September 2025 and it takes effect on 1 May 2027. It sets the expectation for how a federally regulated institution identifies, measures and controls model risk — across the five lifecycle components it names, rather than at build and validation only.

The Gap

Most institutions arrive with development and validation covered and the other three components thin: deployment assumed, monitoring annual and living in a slide, decommission absent. Underneath, discovery routinely finds a third more models than the register held.

The Office

Every model on your inventory is one iDharma has no stake in. We find the estate from the systems inwards, rate it on the factors the guideline actually names, review the highest-rated models against their intended use, and sequence the findings against the effective date.

What counts as a model?

What it does, not what you call it.

A rules engine, a spreadsheet, a bought score, an LLM — if the output is relied on, assume a model.

Tier 1 · Highest materiality № 01
  • Full independent validation up front
  • Revalidation at least annually
  • Board-visible reporting
  • Tight change control, re-approval
E-23 · iDharma · Rated for review
Tier 2 · Moderate materiality № 02
  • Independent review, scoped to risk
  • Revalidation on a defined cycle
  • Monitored to escalation thresholds
  • Documented approval to deploy
E-23 · iDharma · Rated for review
Tier 3 · Lower materiality № 03
  • Proportionate review, not validation
  • Inventory entry with a named owner
  • Light performance monitoring
  • Re-rated when the use changes
E-23 · iDharma · Rated for review
Whose duty is it

The duty is yours. The model may not be.

You

The institution using the model

E-23 places the expectation on the institution that uses the model. The enterprise framework, the inventory, the risk rating, the independent review and the reporting to senior management and the board are all yours - and none is satisfied by a supplier who has done it for their other clients.

Your supplier

The people who built the model

A vendor can hand you documentation on data, method and limitations, and a good one will. What it cannot hand you is the rating, the review conclusion or the monitoring, because those are judgements about the model as YOU use it - on your portfolio, in your process, against your risk appetite.

The catch

What a bought model still owes you

A third-party model sits on your inventory, carries your rating and is reviewed and monitored like one of your own. If the supplier will not give you enough to do that, the gap is not theirs to carry - it is a finding against your framework, and the answer to it is usually contractual rather than technical.

What most teams assume

“The vendor validated it, so it’s covered.”

What the guideline expects

A bought model is your model risk, rated as yours.

It is the most common finding we write up.

  • Who it is for
  • Banks & foreign branches
  • Life & P&C insurers
  • Trust & loan companies
  • Model risk & validation
  • Data science & AI teams
Why this matters in 2027
A string-tied kraft envelope lying on a dark grey desk, stamped CONFIDENTIAL in red above a ruled line reading for authorized personnel only.
01 There is no fine to quote. OSFI supervises rather than penalises, and what it applies instead is harder to discharge than a payment would be.
02

Findings are raised through ongoing supervision, and the remediation runs on OSFI’s timetable rather than on your own.

03

Weakness in model risk feeds the view taken of your governance overall - and that is what brings attention across the rest of the book.

04

Persistent weakness reaches the staged intervention framework, with the activity restrictions or capital consequence that carries.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a supervisory call.

0 of 3

OSFI-regulated entity -

Insurers are in now. Banks, foreign bank branches and trust and loan companies were always here; life, fraternal and property and casualty companies came in with this version of the guideline.

Models in the estate -

Non-financial risk counts. The definition reaches climate, cyber, technology and digital-innovation models, not only the ones that produce a capital number.

Inventory and rating -

A rating that changes nothing is a label. E-23 expects the rating to drive how much review and monitoring each model actually gets.

The lifecycle

Five components, and most programmes cover two.

E-23 governs a model from the idea to the retirement - controls and documentation are expected at every stage.

  1. Design

    Before build

    Purpose, data, assumptions and method chosen and written down while the limitations are still obvious.

  2. Review

    Before use

    Conceptual soundness and performance assessed independently, at a depth set by the risk rating it carries.

  3. Deployment

    At release

    Controlled release into the live path, with the tested model and the deployed model reconciled first.

  4. Monitoring

    In life

    Performance watched against expectations, with thresholds that fire and a defined route to a decision.

  5. Decommission

    At retirement

    Retirement as a controlled act: dependants told, retention resolved, the entry closed and not deleted.

The trap

Development and validation are two of five. The three that follow them are where a supervisor finds the gap - and decommission is the one almost nobody has at all: a model switched off still has downstream consumers, retained outputs and a live inventory entry.

Expectation & coverage

What the guideline expects, what we ship

12 expectations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.

Enterprise MRM framework Governance
A framework document aligned to your risk appetite statement, with the scope boundary written down - including what you have decided is not a model, and why.
Model definition and scoping test Scope
A definition your teams can actually apply, with worked examples on the borderline: rules engines, spreadsheets, vendor scores, an LLM step inside a workflow.
Model inventory Inventory
An enterprise register with owner, rating, purpose, status, dependencies and vendor provenance - and a route by which a new model actually gets onto it.
Risk rating methodology Rating
A rating scheme built from the quantitative and the qualitative factors alike, applied across the inventory, with every borderline call documented.
Roles and accountabilities Accountability
Owner, developer, reviewer, approver and user defined and mapped to named people, plus the reporting line to senior management and the board.
Lifecycle standards Lifecycle
A standard for each of the five stages, with the evidence each stage has to leave behind before the model moves to the next one.
Independent review function Validation
A review methodology scaled by rating, a findings register with owners and dates, and the independence argument written down rather than asserted.
Monitoring and thresholds Monitoring
Metrics per model with thresholds, owners and an escalation route - and for AI and ML, drift and data-quality checks that run without being asked.
Decommission procedure Lifecycle
The retirement runbook: dependency check, retention decision, notification list, and an inventory status that closes rather than disappears.
Vendor and third-party models Scope
The documentation you need from a supplier before a bought model can be rated, reviewed and monitored like one of your own - and what to do when it does not arrive.
Board and management reporting Governance
A reporting pack that puts model risk in front of the board in a form it can act on, at a cadence that survives a quiet quarter.
Gap plan to 1 May 2027 Readiness
A findings list against every expectation on this page, sequenced, owned and dated against the effective date rather than against a wish.
The engagement

Model risk, independently reviewed

From a pricing spreadsheet to a model nobody can fully explain.

  1. Intake

    Which models are in scope, and what your inventory already knows.

  2. Rate and review

    Inherent risk scored on E-23 factors, then review scaled to the rating.

  3. Report and plan

    Findings, owners and dates - sequenced against the effective date.

Request your E-23 review
An auditor in a navy trouser suit and cream blouse, with shoulder-length blonde hair, standing against a warm pale wall and pointing into the open space alongside.
The rating is not negotiable - that is what you are buying.
Struck in your favour

Why institutions choose iDharma for E-23

Genuinely independent

We build, licence and operate no models, and take no fee tied to what the review concludes.

Written to the guideline

Every finding maps to the expectation it discharges, so a supervisor checks it against E-23.

One engagement, end to end

Discovery, rating, review and gap plan sit in one scope, so nothing falls between suppliers.

Built for AI and ML

Drift, explainability and data quality all sit in the base scope, not a line added to the quote.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

The E-23 readiness report

One document a supervisor can read: the scope boundary and the models you excluded with the reason for each, the rating applied across the inventory, the independent-review conclusions on the highest-rated models, and the findings list that becomes the gap plan - every claim written against the expectation it discharges.

Register · Workbook

The model inventory

Found from the systems inwards rather than the questionnaire outwards - the spreadsheets, the vendor scores and the model nobody calls one.

Methodology · Memo

The rating scheme

A scheme applied across the estate, so the intensity of your controls can be defended against the factors the guideline actually names.

Assessment · Report

The independent review

Conceptual soundness and performance assessed by people with no stake in the answer, which is the whole content of the word independent.

Design · Spec

The monitoring design

Metrics, thresholds and escalation defined before go-live, with drift and data-quality checks on the models that actually need them.

Standards · Runbook

Lifecycle standards

All five stages written as standards with an evidence requirement each - including the retirement runbook almost no programme has.

Plan · Dated

The gap plan

Findings against every expectation, sequenced against the 1 May 2027 effective date, with an owner and a date on each rather than a heat map.

Format & fee

Real numbers, upfront.

Scope
Set by the guideline, not us
Estate
Your models, as you use them
Re-review
Annually, from the review date - $21,000 against your known baseline

The guideline fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this audit
E-23 · Named engagement $25,000 flat
  • Model discovery and the inventory
  • Inherent-risk rating across the estate
  • Independent review of the top tier
  • Gap plan dated to 1 May 2027
Show your hand

Four things you have to be able to produce

E-23 is not graded on intent. Each of these is either in your hand on the day a supervisor asks, or it is not.

The register,
whole

Every model of non-negligible risk on one inventory, reconciled to what is actually running in production, each with an owner who knows that they own it.

The rating,
applied

A rating on every entry, built from the factors E-23 names, visibly driving the review and monitoring each one gets. A rating that changes nothing is a label.

The review,
in date

The highest-rated models validated and in date, findings tracked through to closure, and the independence of whoever did the validating argued in writing.

The alert,
wired up

Thresholds set per model, a breach routed to a named owner, and at least one occasion on which that actually happened. Monitoring nobody answers is not monitoring.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

What E-23 is, what counts as a model, tiering. Answered straight.

Request this audit
Our vendor validated the model. Are we covered?

No. A bought model sits on your inventory, carries your rating, and is reviewed and monitored like one of your own - the supervisor asks you, not your supplier.

What is Guideline E-23, in one paragraph?

OSFI's expectations for model risk management at federally regulated financial institutions, published 11 September 2025 and effective 1 May 2027, applied across five lifecycle components.

What counts as a model?

An application of theoretical, empirical, judgmental or statistical technique - AI and machine learning included - that processes input data to generate results. What it does, not what you call it.

Does E-23 really reach AI and machine learning?

By name. The guideline stays technology-neutral, which cuts both ways: an opaque method is neither excluded from scope nor excused from the expectations that apply to it.

Does E-23 require three tiers?

No. It requires a risk rating built from the named factors, and expects it to drive the rigour proportionally. How many bands you use, and where the boundaries sit, is yours to defend.

Get started

Request your E-23 review

Tell us about your models and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this comes out of your governance material in an afternoon, and we tell you which extracts before you commit to anything.

  1. Whatever passes for a model inventory today
  2. Your model risk policy or framework, if one is written
  3. The last validation or review report, for any one model
  4. Which models a vendor built, and what came with them
  5. Your target date for evidencing the framework

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request your E-23 review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • OSFI Guideline E-23, Model Risk
  • OSFI Guideline E-4, foreign branches
Published
11 September 2025
Effective
1 May 2027

What it means

  • General information about what the guideline expects — not legal or supervisory advice, and no professional relationship.
  • E-23 is principles-based, so more of it is arguable than a rules-based text would be. Where a call is genuinely open, our reports say so rather than pick the convenient answer.

Scope & limitation

  • Do not rest a supervisory position on it; go to the guideline for the wording.
  • It covers E-23 alone - B-10, E-21 and privacy law can reach the same model.
  • Use it as a starting point for a scoping conversation, not as your final word.

Something on this page out of date?

Tell us