Digging into OSFI’s E-23 Model Risk Management Framework

In 2017, the Office of the Superintendent of Financial Institutions (OSFI) issued Guideline E-23, outlining guidance for the model risk management (MRM) requirements for federally regulated deposit-taking institutions. In November 2023, OSFI released a revised Draft Draft Guideline E-23 E-23 that will take effect July 1, 2025. The revised guideline focuses on the following key changes:

  • Expanding the scope to include not only deposit-taking institutions, but also federally regulated insurance companies and federally regulated private pension plans
  • Applying the guideline to all models used at these regulated institutions
  • Enhancing the risk focus, emphasizing a risk-based approach to model risk management
  • Modernizing guidance with explicit expected outcomes and principles

OSFI expects the regulated institutions to adequately manage models at each lifecycle stage and to have a robust MRM framework. This article shares tips for regulated institutions to prepare for the E-23 requirements and leading practices in MRM within the industry.

How should regulated entities prepare for OSFI’s Guideline E-23?

  1. Conduct a gap assessment and review current MRM capabilities, including:
    a. MRM frameworks, policies, standards, and guidelines
    b. Governance, such as governance bodies, model risk appetite, and metrics
    c. End-to-end model lifecycle activity processes
    d. Model validation planning and capabilities
    e. Ongoing monitoring and reporting
    f. Target operating model
  2. Review (or create) MRM policies and standards, and create an updated version in line with industry best practices and Guideline E-23.
  3. Review the accuracy and completeness of the model inventory to ensure it captures all enterprise models. Create and update the model risk reporting template to satisfy all OSFI requirements.
  4. Establish processes, procedures, and templates for model validation.

What are industry-leading practices for model risk management?

Model risk management policies

  • Organizations have policies and standards outlining the minimum requirements for each stage of the model lifecycle, from the rationale for modelling to modifications and decommission. These MRM policies should carry the same weight within the institution as other risk policies, such as operational risk.
  • Policies and standards are regularly reviewed and updated to ensure alignment with OSFI requirements and industry best practices.
  • Roles and responsibilities are clearly defined in MRM policies, and key definitions (such as model and model risk) are explicitly outlined.

Model inventory

  • Organizations maintain a centralized information hub to track all models in use and those recently decommissioned.
  • The model inventory contains, at a minimum, all fields listed in Appendix A of OSFI’s Draft Guideline E-23. Key information includes, but is not limited to, model name, identification, version, intended use, risk rating, dependency, performance monitoring, limitations, validation dates, and exception status.
  • The model inventory is updated promptly and is the basis for quarterly risk reporting and key decisions.

Model validation

  • Institutions typically formulate a model validation policy or procedures providing guidance and minimum requirements for validators. These standards are risk-based and aligned with the model’s use, complexity, and materiality, and the institution’s size and complexity.
  • Model validators possess high technical expertise to account for model complexity and are familiar with the business units using the model and its intended use. They have the authority to challenge developers and users and do not solely rely on information from developers.
  • Model validators assess the completeness of model submissions before validation and reject incomplete submissions.
  • Standardized validation plan, report, and model documentation templates ensure consistency, completeness, and accuracy of model submissions and validation.
  • There is consistent application of model risk rating methodology with clearly defined criteria.
  • Model validators typically cover the following components:
    – Assessing the accuracy and reasonableness of documentation, input data, assumptions, methodology, and reporting processes
    – Conducting independent testing, including replication, benchmarking, sensitivity testing, and back-testing, as appropriate
    – Assessing ongoing model performance monitoring results submitted by the model owner

The journey toward effective model risk management requires continuous efforts. Institutions can start early by reviewing and updating model risk management policies, establishing an enterprise-wide model inventory, and implementing and standardizing validation procedures.