OSFI E-23 Guideline and Its Impact on Financial Institutions
Introduction
The regulatory landscape related to artificial intelligence continues to evolve. For regulated entities like Canadian banks and insurance companies and their foreign affiliates, for federally regulated credit unions, and for Canadian affiliates of foreign banks and insurance operating in Canada (“FIs”), OSFI Guideline E-23 – Model Risk Management (2027), which will come into force on May 1, 2027 (“Guideline E-23”), adds a new layer of regulatory and contracting complexity.
Contracts between service providers and FIs are already complicated because of the requirements of FIs to comply with Canadian privacy laws such as PIPEDA and privacy laws in other jurisdictions in which they operate, regulatory guidelines such as OSFI’s updated B-10 Third-Party Risk Management Guideline, OSFI’s Technology and Cyber Security Incident Reporting Advisory, and other guidance.…