Plan your credit union's 2027 AI budget, a free working session with BCU's COO Register →

Regulatory · Updated September 2026

OSFI Guideline E-23 for Credit Unions

E-23 takes effect on May 1, 2027. It is the most detailed statement a Canadian financial regulator has made about governing AI models. Whether it binds your credit union depends on one thing. In this article, we discuss whether E-23 applies to your credit union.

Does It Apply To You?

E-23 applies to federally regulated financial institutions. Most Canadian credit unions are provincially regulated, so for most of the sector the guideline is not directly binding.

The exception is the part worth knowing. OSFI regulates federal credit unions alongside banks, and a small number of credit unions have continued federally. For those institutions, E-23 applies on May 1, 2027 exactly as it applies to a bank. Coast Capital Savings Federal Credit Union is the largest of them.

If you are provincially regulated, the honest answer is that E-23 is not your obligation and nobody should tell you otherwise. It is still the clearest available description of what a Canadian regulator now considers adequate governance of AI models, provincial expectations have historically moved toward federal ones, and the question underneath the guideline is the question your own board will eventually ask: can you produce a list of the models you rely on and name who owns each one.

Confirm your own obligations with your regulator and your compliance function. This page is a plain-language summary from The GCC, not legal or compliance advice.

What E-23 Actually Says

The definition of a model got wider

OSFI defines a model as an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and machine learning methods, which processes input data to generate results. That is broader than the traditional idea of a quantitative risk model, and it is the single change most likely to catch an institution out. Things that were never called models are models now under the new E-23 definition.

It is explicitly proportional

The guideline is applied on a risk basis, proportional to an institution's size, strategy, risk profile, nature, scope and complexity of operations, and interconnectedness. Higher risk models get enhanced scrutiny and lower risk models are subject to fewer requirements. A smaller institution is not being asked to build the AI model risk function of a large bank.

It runs on a lifecycle

Design, independent review, deployment, ongoing monitoring, and formal decommission, supported by a model inventory, a risk rating, and approval processes. For AI models specifically, monitoring gets extra attention because of autonomous decision making, autonomous re-parametrization, and a higher potential for model drift, with explainability requirements that vary by purpose and by how autonomous the model is, and alternative controls expected where an approach is a black box.

The Clause Most Institutions Are Least Ready For

E-23 expects the model risk framework to cover models and data sourced externally, including from third-party vendors. Externally developed models are to be assessed for a risk rating on a standalone basis, and that assessment reaches into the platform's sub-components, including its data and libraries.

Buying rather than building does not move the risk off your balance sheet. This is difficult in practice because vendor AI does not arrive through procurement. It arrives in a release note. A core banking provider ships an AI feature into a product you already run, nobody signs anything, and the institution has acquired an AI model it never evaluated.

That is why an AI policy written around named products stops working almost immediately, and why the vendor-embedded clause belongs in the policy from the first draft rather than the second. See how the AI policy work runs.

What Proportional Readiness Looks Like at a $600M Credit Union

Not an AI model risk department. Not a validation function. At this size, proportional readiness is four things.

  1. 01 An Inventory That Exists. Every requirement downstream assumes you can list what you have. Most institutions cannot, and the exercise usually surfaces vendor features nobody had catalogued.
  2. 02 A Risk Rating Per Model. Rating is what makes proportionality operational. It is how you justify light-touch treatment of the low-consequence tools and concentrate effort on the ones that touch member outcomes.
  3. 03 A Named Owner For Each One. A role, not a department. If the answer is "IT" then there is no owner.
  4. 04 A Position On Vendor AI. Written down before the next release note, not after.

What a Model Inventory Row Looks Like

A spreadsheet is a legitimate starting point. What matters most is that every row can be answered honestly.

What it is The tool or feature, named the way staff name it
What it does The decision or output it produces
Where it came from Built in house, bought, or arrived inside a product you already licensed
Who owns it A named role, not a department
Data it touches Member data, internal only, or public
Consequence What happens to a member if the output is wrong
Risk rating Which drives how much scrutiny everything else gets

Common Questions

Does OSFI Guideline E-23 apply to credit unions?

It applies to federally regulated financial institutions, which includes federal credit unions. Most Canadian credit unions are provincially regulated and are therefore not directly bound by it. The exception matters: a small number of credit unions have continued federally and are supervised by OSFI, so for those institutions E-23 applies on May 1, 2027 the same way it applies to a bank. If you are provincially regulated, E-23 is not binding on you, but it is the most detailed public statement of what a Canadian regulator now expects from model and AI governance, and provincial expectations have historically converged on federal ones.

When does E-23 take effect?

May 1, 2027, following an eighteen-month transition period that OSFI provided so institutions could assess current practices and adjust before the guideline takes effect.

What counts as a model under E-23?

OSFI defines a model as an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and machine learning methods, which processes input data to generate results. That is deliberately broader than the traditional definition of a quantitative risk model. It captures scoring and decisioning tools, and it captures AI features that arrived inside software the institution already licenses.

Does E-23 cover AI that our vendor built rather than us?

Yes. OSFI expects the model risk management framework to cover models and data sourced externally, including from third-party vendors, and says externally developed models should be assessed for a model risk rating on a standalone basis, including their data and libraries. Buying rather than building does not transfer the risk. This is the provision most institutions are least prepared for, because vendor-supplied AI usually arrives through a product upgrade rather than through a procurement decision.

What does proportionality mean for a smaller credit union in Canada?

E-23 is applied on a risk basis, proportional to an institution's size, strategy, risk profile, nature, scope and complexity of operations, and interconnectedness. Higher risk models get enhanced scrutiny and lower risk models are subject to fewer requirements. In practice a smaller institution is not expected to build the model risk function of a large bank. It is expected to know what models it has, to have rated them, and to have someone accountable for each one.

Where should a credit union start looking at E-23?

With the inventory. Almost every other requirement in the guideline depends on knowing which models exist, what each one is used for, who owns it, and how consequential its output is. Most institutions that begin this work discover the inventory is longer than expected, because the broadened definition captures vendor features nobody had catalogued as a model.

Sources

Getting Ready For the Question

Building the inventory, rating what is on it, and writing the vendor position into a policy your board will approve is the first stage of how we work with credit unions.

Ready to Build AI Confidence?

Start with a free 30-minute call, or download the AI Policy Template to get a head start.