Free Consultation
Observatory

OSFI E-23 vs SR 26-2

The same obligation themes, side by side, from the catalogue that powers the rest of this site — 5 catalogued requirements across 3 themes. Expand any requirement to read it. Free, no login.

Comparing 2 of 38 regulations we track. This URL is the comparison — send it to anyone.

In force

OSFI Guideline E-23 — Model Risk Management (2027)

Authority
Canada — OSFI · Canada (federally regulated financial institutions)
Catalogued requirements
3, all mandatory
Themes it legislates on
3 of the 3 below
Maximum exposure
OSFI supervisory expectations (no statutory fines)
Next dated obligation
2027-05-01 — OSFI Guideline E-23 — Model Risk Management (incl. AI/ML) effective (in 250 days)
Official source last read
2026-08-23 — unchanged since our last read
Guidance

SR 26-2 — Interagency Model Risk Management Guidance (successor to SR 11-7)

Authority
US Fed / OCC / FDIC · USA (banking)
Catalogued requirements
2, none mandatory
Themes it legislates on
2 of the 3 below
Maximum exposure
Supervisory findings (MRAs) for regulated banks
Next dated obligation
Nothing dated ahead in our calendar
Official source last read
2026-08-23 — unchanged since our last read

Where they overlap

Every theme below appears in exactly one group, so these account for all 3 of them. Sharing a theme means both regimes legislate in that area — it does not mean complying with one discharges the other.

Both legislate here · 2 themes

OSFI E-23 · SR 26-2

Risk management systemAccuracy, robustness & security

1 of the 2 legislates here · 1 theme

OSFI E-23not: SR 26-2

Monitoring after deployment

Requirement by requirement

A dash means we have not catalogued a requirement for that regulation under that theme — a summary of our catalogue, not a finding that the law is silent. Always check the official text, linked from each regulation's page.

ThemeOSFI E-23SR 26-2
What you must assess first
Risk management system Must you run a documented, continuous risk process?
E-23 · Governance Model risk governance & lifecycle must

Operate an enterprise-wide model risk-management framework over the full model lifecycle, with a model inventory and risk-based materiality rating that explicitly captures AI/ML models.

Read it in context →
Inventory Model inventory & tiering should

Maintain a complete model inventory tiered by materiality, with documented development evidence for each model.

Read it in context →
What you must build and prove
Accuracy, robustness & security Must you hit and evidence performance targets?
E-23 · Validation Independent validation must

Independently validate models before first use and periodically thereafter — conceptual soundness, data quality, performance, and bias/fairness.

Read it in context →
Validation Independent validation & monitoring should

Independent validation covering conceptual soundness, ongoing monitoring (incl. benchmarking) and outcomes analysis/backtesting; change management triggers revalidation; vendor models validated too.

Read it in context →
What you must do while it runs
Monitoring after deployment Must you keep watching it once it is live?
E-23 · Monitoring Ongoing monitoring & human oversight must

Continuously monitor model performance and drift, document model decisions, and ensure appropriate human oversight of outputs.

Read it in context →

Which one bites first

Every dated obligation attached to these regulations, merged into one timeline.