OSFI published the final version of Guideline E-23, Model Risk Management, on September 11, 2025. It takes effect on May 1, 2027, and it applies to all federally regulated financial institutions, including foreign bank branches and foreign insurance company branches.
Most readings of it open with the definition of a model and stop there. The inventory is the more useful place to start, because it is the artifact a supervisor can ask to see, and because nearly every other expectation in the guideline points back at a field inside it.
Source: OSFI, Guideline E-23 – Model Risk Management (2027)
Two records, not one
The guideline separates identification from inventory, and the distinction is easy to miss because both produce a list. Principle 2.1 asks institutions to identify and track all models in use or recently decommissioned. The inventory is the narrower record: it stores the models deemed to carry non-negligible inherent model risk.
Appendix 1 follows the same split. For each identified model, six fields at minimum: model ID, model name and a description of key features and use, model risk rating, model owner, model developer, and model origin. For the models that carry non-negligible risk and are therefore stored in the inventory, eleven more: version, production deployment date, reviewer, approver, dependencies, data sources and description, approved uses, limitations, most recent review date, monitoring status, and next review date.
The consequence is practical. The six-field record covers a wider population than the inventory does. A spreadsheet that shapes a pricing decision may never earn a place in the inventory, and it still has to be identified, rated and tracked. An institution that treats the inventory as the whole obligation ends up with a well-governed inventory and an unmeasured population sitting outside it.
Source: Guideline E-23, §C.1 Model identification and Appendix 1
The rating is the load-bearing field
Of the six minimum fields, the model risk rating is the one that decides what happens next. Under Principle 2.3, the inherent model risk rating drives the frequency, intensity and scope of model review, the documentation requirements, the level of authority required to approve the model, the frequency and scope of monitoring, and the interval at which the rating itself is re-assessed.
A rating is therefore not a label applied once the governance is designed. It is the input that prices the governance. Rating a model low is a decision that it needs less review, thinner documentation and a lower approval authority, whether or not anyone framed it that way at the time.
The guideline asks for clear, measurable criteria across both quantitative factors, such as the importance, size and growth of the portfolio a model covers, and qualitative ones, such as business use, model complexity or level of autonomy, reliability of data inputs, customer impacts, and regulatory risk. It also permits a rating category implying negligible risk, which exempts a model from full lifecycle governance, on the condition that a robust process approves and tracks those exemptions.
Source: Guideline E-23, §C.2 Model risk rating and §C.3 Risk management intensity
Five properties that are harder than they look
Section C.1 sets five expectations of the inventory itself. It should be comprehensive across models whose inherent risk is non-negligible. It should be maintained at the enterprise level and serve as a basis for management and regulatory reporting. It should be accurate, evergreen, and subject to robust controls. It should be updated in a timely manner, including on modifications and on changes in use, risk rating or performance status. And it should include decommissioned models for a period the institution considers reasonable.
Two of those carry quiet workload. Evergreen means the inventory is a live system of record rather than the output of a periodic survey, so updating it has to sit inside the way models actually change rather than in a quarterly reconciliation. Retaining decommissioned models means the record outlives the model, which is precisely the case where nobody is left with an incentive to keep it accurate.
The dependency and data-source fields carry a similar cost. Recording what a model depends on and where its data comes from, honestly and in a form someone else can audit, requires lineage that many institutions hold informally in the heads of the people who built the thing.
Source: Guideline E-23, §C.1 Model identification
Third-party models are in scope
The guideline states that identification processes cover vendor and third-party models, that the framework covers models or data sourced externally including from foreign offices and third-party vendors, and that externally developed models should be assessed for model risk ratings on a standalone basis.
A vendor's own documentation does not discharge that assessment. The obligation to understand a model's limitations and its approved uses stays with the institution deploying it.
Source: Guideline E-23, §B.2 Model risk management framework and §C.2
What this asks of a smaller institution
E-23 applies on a risk basis, proportional to an institution's size, strategy, risk profile, the nature, scope and complexity of its operations, and its interconnectedness. Proportionality changes the depth of the work. It does not remove the two records, or the rating that connects them.
So the first honest exercise is a survey rather than a framework. Which processes here apply theoretical, empirical, judgmental assumptions or statistical techniques to input data to generate results, and which of those carry non-negligible risk? The answer usually reaches past the models the risk function currently owns. Producing that list, with an owner and a defensible rating against every line, is most of what a first year of readiness actually consists of.