OSFI E-23

OSFI E-23 Model Risk Management for AI Agents, Effective May 1, 2027

Guideline E-23 brings AI and machine learning models into model risk management at federally regulated financial institutions, and it expects an enterprise model inventory kept current. Lumenova AI covers the agents in that inventory and the MCP servers, skills, and prompts they use.

OSFI E-23
OSFI E-23 Model Risk Management for AI Agents, Effective May 1, 2027

What Is OSFI Guideline E-23?

OSFI Guideline E-23 sets expectations for enterprise-wide model risk management at federally regulated financial institutions (FRFIs) in Canada. The final guideline, published September 11, 2025, takes effect May 1, 2027. It defines models broadly, AI and machine learning included, and expects a risk-based framework, a complete model inventory, and governance at every stage of a model’s lifecycle.

Lumenova AI is an agentic AI governance platform that extends that inventory and lifecycle to AI agents, which act on their own and call tools a model inventory doesn’t track. It sits beside the model inventory in your model risk system.

OSFI expects each institution to scale its framework to its size, complexity, and use of models. In the US, SR 26-2 and OCC Bulletin 2026-13 went the other way in April 2026 and placed generative and agentic AI models outside their scope.

Key Dates

  1. 11 Sep 2025OSFI publishes the final guideline, with AI and machine-learning models in scope.
  2. 1 May 2027Guideline E-23 takes effect for federally regulated financial institutions.

CORE CHECKS

What the E-23 Framework Asks For

In effect from May 1, 2027, for every federally regulated financial institution in Canada.

Enterprise Model Inventory

A complete, current inventory of the models in use, with an owner and a risk rating for each, AI and machine learning models included.

Risk Ratings and Materiality

A risk rating for each model based on its materiality and complexity, which sets how much review and oversight it gets.

Lifecycle Governance

Controls at each stage: design and development, review, deployment, monitoring, and decommissioning.

Clear Accountability

Named owners, developers, reviewers, and approvers, with review kept independent of development.

Monitoring and Reporting

Ongoing monitoring of how models perform, with thresholds that trigger review and reporting to senior management.

Fundamental Rights Impact Assessment

Deployers of credit scoring and life and health insurance pricing systems must assess the system’s impact on people before first use.


How Lumenova AI Supports Model Risk Management Under E-23

Registration-Based Access

Scope what each agent can reach at the gateway by its approved use case, and surface unregistered agents for review.

Tiered Use Case Approval

Record each use case’s owner, approver, and risk tier alongside the resources it’s allowed to use.

Lifecycle Tracking

Move agents, MCP servers, skills, and prompts from active to retired, and see what depends on each before you decommission it.

Independent Score Validation

Test agents before launch and in production, and check automated scores against reviewers independent of the build team.

Materiality-Based Limits

Enforce each agent’s limits before the action runs, with tighter rules for agents rated higher in materiality.

Exportable Decision Records

Keep each decision’s policy, outcome, and input, with full policy version history, ready to export for validation and audit.


How to Get Ready

  • Keep an inventory with an owner and a risk rating for each model and each agent;
  • Record each approval on the use case it covers;
  • Set the review evidence you expect at each level of materiality;
  • Enforce limits in the path of the call for agents that act;
  • Decide which monitoring results trigger a review;
  • Before you retire an agent, check what depends on it.

Frequently Asked Questions

May 1, 2027. OSFI published the final guideline on September 11, 2025, which gives institutions about 20 months to build or update their model risk frameworks.

E-23 doesn’t name agents, but its model definition includes AI and machine learning, and agents run on those models. Treating each agent as an inventory entry, with the tools and data it can reach, keeps the inventory complete. Lumenova AI registers agents that way.

Federally regulated financial institutions in Canada, including banks and federally regulated insurers. OSFI expects each institution to scale its model risk framework to its size, complexity, and use of models. 

SR 26-2 and OCC Bulletin 2026-13 replaced SR 11-7 in April 2026 and placed generative and agentic AI models outside their scope. E-23 goes the other way and brings AI and machine learning models into model risk management. Banks in both countries govern agents under E-23 in Canada and under broader risk management practices in the US.

No. Lumenova AI sits beside your model inventory and model risk system. It adds the agents, and the MCP servers, skills, and prompts they use, with lifecycle states, approvals, evaluations, and decision records your model risk team can use as evidence.

Control, Test, and Prove What Your AI Agents Do

This is one piece of Lumenova AI. See how it connects to the rest on your own use case.

Book a discovery call