Skip to main content
    Regulatory alignment · OSFI E-23

    OSFI E-23 takes effect on 1 May 2027.

    It covers traditional models, actuarial models, and AI and machine learning models under one framework. There is no separate AI regime to stand up, and no exemption for a model because it happens to be statistical rather than learned.

    What it requiresThe third-party clauseAll frameworks

    No compliance claim. iTmethods makes no compliance, certification or accreditation claim under OSFI E-23 or any other framework named on this page. We are not certified against, accredited for, or approved under any of them. Alignment is not compliance. The determination belongs to your own risk function, and nothing here transfers it to us.

    What it requires

    One framework, every model type.

    The 2025 update added context and clarity specifically for AI and machine learning model risk management, inside the framework that was already there.

    Every model, one regime

    Traditional, actuarial, and AI and machine learning models are governed by the same framework. Nothing falls out of scope for being statistical rather than learned.

    Which of your models are on that list today?

    Principles-based, technology-agnostic

    E-23 does not prohibit any modeling approach. Institutions may innovate provided risk management holds. It sets expectations about how risk is governed, not which techniques are permitted.

    Can you show how a given approach is governed?

    Harder than a ban, not easier

    A prohibition would be simple to evidence. An expectation that risk management holds across every model you run is continuous, and it is the harder one to meet.

    What would you produce if asked this quarter?

    The third-party clause

    Source does not change scope.

    E-23 applies to all models regardless of source or purpose. Internal or third party, both in scope.

    A model you bought is still a model you are answerable for. That makes the record of what a vendor model was allowed to do, and what it did, part of your obligation rather than the vendor’s courtesy.

    Where Reign fits

    The operating record across the model lifecycle.

    Which limits applied at the moment of each action, what was authorized, what the outcome was, and who decided each exception.

    The compliance and assurance assessment rests with the institution’s risk officers, compliance professionals, auditors and advisers. Reign gives those experts the operating evidence their judgment draws on. It does not form the judgment.

    Reign is aligned to OSFI E-23. It is not certified against it, no product can be, and no product makes an institution compliant with it. OSFI does not endorse, approve or recommend Reign or iTmethods.

    Next step

    Bring us the models you are answerable for.

    We will look at what evidence exists across their lifecycle today, and what would be missing on 1 May 2027.