OSFI’s draft Guideline E-23, expected to be finalized by September 11, 2025, introduces several critical elements:
Expanded Definition of “Model”: The guideline broadens the definition to explicitly include artificial intelligence (AI) and machine learning (ML) methods. A “model” is now defined as: “The application of theoretical, empirical, judgmental assumptions and/or statistical techniques, including AI/ML methods, which process input data to generate results.” Enterprise-Wide Model Risk Management (MRM): OSFI emphasizes that model risk must be managed on a risk-based and enterprise-wide basis. This approach requires organizations to adopt robust MRM frameworks that cover the entire model lifecycle, from development to decommissioning. Seven Guiding Principles: The guideline outlines seven principles that organizations should implement: Governance and Accountability: Establish clear governance structures and assign accountability for model risk management. Model Inventory: Maintain a comprehensive inventory of all models in use, including AI/ML models. Model Validation and Testing: Implement rigorous validation and testing processes to ensure model reliability and performance. Model Monitoring: Continuously monitor model performance and risk exposure. Model Documentation: Maintain thorough documentation for all models, detailing their development, validation, and usage. Model Risk Assessment: Assess and categorize model risks based on their potential impact and likelihood. Data Governance: Ensure robust data governance practices to support model integrity and compliance. Alignment with Federal AI Legislation: OSFI is working closely with other agencies, including the Financial Consumer Agency of Canada (FCAC) and Innovation, Science and Economic Development Canada, to align financial-sector oversight with broader federal AI legislation, such as the Artificial Intelligence and Data Act (AIDA).

Leave a Reply