Regulatory News · Jun 24, 2026

On September 11, 2025, OSFI published the final Guideline E-23 Model Risk Management (2027). It takes effect May 1, 2027 across every federally regulated financial institution in Canada — and its definition of "model" explicitly includes AI and ML, pulling fraud detection and AML transaction monitoring into scope by default.

What Guideline E-23 requires

OSFI structured the final guideline around three outcomes with nine numbered principles. The three outcomes: model risk is well understood and managed across the enterprise; model risk is managed using a risk-based approach; and model governance covers the entire model lifecycle. Every model in scope needs an inventory entry, a risk rating, documented governance policies, independent validation appropriate to risk, and continuous monitoring including drift detection for AI/ML.

Fraud and AML systems are material by default

The guideline defines a model as "an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI/ML methods, which processes input data to generate results." Fraud scoring, transaction monitoring rules, sanctions matching, adverse media classification, and behavioural biometrics all sit inside this definition. Practitioner guidance consistently treats fraud and AML models as material by default because their outputs drive customer decisions with regulatory consequences.

The vendor cascade

The most immediate operational consequence is that E-23 pulls third-party models into the bank's governance perimeter. Federally regulated institutions cannot outsource their model risk obligation to procurement. Every material vendor model must have documented model risk management evidence the bank's second-line-of-defence team can review and integrate into its own model inventory. Bank procurement teams are already sending E-23 questionnaires to fintech vendors — model cards, independent validation, monitoring dashboards, human-in-the-loop specifications, data lineage, incident response playbooks, and change control workflows are all being requested.

Book a Demo

FINTRAC penalties just multiplied by 40x

On March 26, 2026, amendments to the Proceeds of Crime (Money Laundering) and Terrorist Financing Act received Royal Assent. FINTRAC's Administrative Monetary Penalty maximum for minor violations increased from $1,000 to $40,000, and serious violations now cap at $4,000,000. FINTRAC also revised its guidance to remove references to working with reporting entities before imposing penalties. Combined with OSFI's aligned enforcement posture from its September 2025 Letter to Industry, the compliance stakes for AML and fraud program failures at Canadian banks are materially higher than they were 12 months ago.

What Canadian institutions should do now

Build a complete inventory of AI/ML models in scope — including those embedded in vendor platforms. Assign risk ratings using a documented tiering methodology. Require every material vendor to produce an E-23 evidence package before contract renewal or new procurement. Validate that in-house AML and fraud models have independent validation on file, current monitoring dashboards, and defensible change-control history. The clock to May 2027 sounds long, but the practical procurement window closes earlier — most tier-1 banks want vendor evidence in inventory by Q1 2027 to give their own examiners time.

How UMCA helps

Aurora is built with model governance as a first-class output, not a documentation afterthought. Every algorithm ships with a model card, independent validation evidence, monitoring metrics, drift detection, human-in-the-loop gating for high-risk actions, full data lineage, and audit-ready decision trails. Our E-23 alignment mapping documents show Canadian financial institutions exactly how Aurora's architecture and processes map to the three outcomes and nine principles — ready for direct ingest into a bank's own model risk management inventory.

Book a Demo