PlatformAI Action FirewallPolicy EngineReal-Time DashboardGitOps Policies
SolutionsAI Agent SecurityMCP SecurityLLM SecurityCompliance & Audit
ResourcesDocumentationResearchIntelligencePricing
Pricing Pricing
CompanyAboutCareersContact

OSFI E-23 Compliance

End-to-end model risk management aligned with the Office of the Superintendent of Financial Institutions' most critical AI governance guideline.

What OSFI E-23 Requires

OSFI Guideline E-23 establishes the regulatory expectations for model risk management at federally regulated financial institutions in Canada. It mandates that banks, credit unions, and lenders maintain complete visibility into their AI and model inventory, conduct ongoing risk assessments, and implement governance frameworks at the board level.

The guideline covers the full model lifecycle — from development and validation to deployment, monitoring, and retirement. Institutions must demonstrate not just compliance, but defensible governance practices that hold up under regulatory examination.

How Saillent Helps

Our five-tier governance framework maps directly to OSFI E-23's core requirements:

Tier 1 — Model Inventory: Complete AI and model inventory including Shadow AI detection.
Tier 2 — Risk Assessment: Classify and rate each model by risk level, aligned with OSFI E-23.
Tier 3 — Audit Trail: Real-time monitoring and automated logging for high-risk models.
Tier 4 — Governance Framework: Board-approved policies, procedures, and committee charters.
Tier 5 — Training: Role-based training and annual certification programs.

Who This Applies To

OSFI E-23 applies to all federally regulated financial institutions — Schedule I and II banks, trust companies, loan companies, and cooperative credit associations. Provincial regulators increasingly reference OSFI guidelines.

Start your OSFI E-23 readiness assessment →
Get Started Today

Ready to Secure Your AI?

See how SAILLENT protects AI agents in real-time. Block prompt injection, prevent data leakage, and enforce zero-trust tool access.

Please use your work email (Gmail, Yahoo, etc. not accepted)
AI-Optimized

Ask AI about SAILLENT

We've optimized our data for AI assistants. Copy this prompt to get instant insights about enterprise AI security.

"Why does SAILLENT believe the next security perimeter is the action, not the model?"
Optimized for:
ChatGPTClaudeGeminiCopilotPerplexityMeta AICohereMistralGrokHugging Face
TRUST & COMPLIANCE

Security & AI-governance you can audit

SAILLENT is engineered to satisfy the world's strictest frameworks across the US, Canada, and Europe — and produces the cryptographic evidence your auditors need. Explore compliance tooling →

SOC 2 Type II
ALIGNED
Trust Services Criteria · Global
ISO 27001:2022
ALIGNED
Information Security Management
GDPR
COMPLIANT
EU Data Protection · Europe
HIPAA
COMPLIANT
Healthcare Privacy · US
NIST AI RMF
ALIGNED
AI Risk Management · US
ISO/IEC 42001
ALIGNED
AI Management Systems
OSFI E-23
COMPLIANT
Financial Oversight · Canada
SR 11-7
COMPLIANT
Model Risk Management · US Fed

COMPLIANT = current attestation · ALIGNED = certification in progress · Evidence packages available under NDA

Request Audit Documentation →