“system and service accounts are securely authenticated, managed and monitored”; “continuous security logging for technology assets”; a “current and comprehensive” asset inventory (AI tools, model endpoints and pipelines are assets); controlled change with segregation of duties. AI is not mentioned.
LLM API vendors, cloud AI platforms and consulting firms are third-party arrangements: audit rights, subcontractor (embedded model) management and notification, concentration risk “including geography, supplier, and subcontractor”, contingency and exit plans, third parties held to the bank’s access-management and data-security standards. OSFI’s 2026-27 outlook announces a fourth third-party data call.
Final 22 Aug 2024; s.4 full adherence 1 Sep 2025; critical-operations identification, mapping and tolerances by 1 Sep 2026; scenario testing complete by 1 Sep 2027
Change management (s.4.4) must “govern the risks introduced by change”, with “implementing new technological systems” named as a significant change; critical operations are mapped end to end across “people, technology, processes, information, facilities, third parties” (CI/CD and test pipelines that support critical operations are in that map); “severe but plausible” scenario testing should include AI-capability failure and manual fallback.
Final 11 Sep 2025; effective 1 May 2027; replaces the 2017 guideline
A model is any “application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI/ML methods, which processes input data to generate results”; inventory must be “accurate, evergreen, and subject to robust controls”; proportionality applies “on a risk-basis”; explainability expectations vary with “level of autonomy”, with “alternative controls” for black-box or autonomous models; externally sourced models are rated on a standalone basis under B-10. Does not specifically address generative or agentic AI. Pilot models and agents should be registered now with a documented risk rating.
Final 31 Jan 2024; new or expanded expectations by 31 Jan 2025, except background checks by 31 Jul 2025; action plan due 31 Jul 2024 (implementation letter)
Screening of contractors on a pilot; data controls “at rest, in transit, and in use”; limits on access to information; defers to B-13 for electronic security.
Initial report “within 24 hours, or sooner if possible”; triggers include impact on critical systems or customer data and a material third-party breach. An AI-caused defective deployment or data exposure that meets the triggers is reportable.
OSFI bulletins and reports (sound practices, non-binding)
Discretionary sound practices that map almost exactly to a conservative pilot’s control boundary: “assign unique non-human identities, enforce least privilege, apply scoped permissions, and use just-in-time access with short-lived credentials”; “log and review agent activity and tool usage along with periodic access recertification”; “ensure human oversight with accountability for material or high-impact decisions, with clear and auditable documentation”; “apply enterprise secure development and change management controls to AI components”; “enforce an obligation on third parties to notify if and how they are using AI to deliver services”. Refers to E-23 for model risk.
23 Mar 2026 (OSFI and Global Risk Institute with Finance Canada, Bank of Canada, FCAC, FINTRAC)
“Human oversight of material decisions made by AI-assisted tools, agents and services”; set “clear governance guidelines for agentic AI, defining where human approval is required and where autonomous agents can operate safely”; map “fourth, fifth, and ‘nth party’ dependencies” in the AI supply chain.
Names “coding assistance” among generative-AI uses; controls include “human-in-the-loop, performance monitoring, back-up systems, alerts”; “financial institutions are responsible for the results of third-party AI systems”; customized LLMs carry “heightened risks for unintended release of consumer data or trade secrets”.
PIPEDA in force; principles published 7 Dec 2023 (page modified May 2025, no substantive revision documented)
Personal information in test environments and prompts; “accountability for decisions rests with the organization, and not with any kind of automated system”; traceability as “a complete account of how the system works”; independent auditing of validity and reliability.
First reading 15 Jun 2026; no further stage; House resumes 21 Sep 2026
Would replace PIPEDA Part 1; permits de-identification without consent and use of de-identified information for “internal research, analysis and development purposes”; explanation duties for automated decision systems; administrative penalties up to the higher of $10 million or 3% of global revenue, offences up to $25 million or 5%. No standalone AI statute is proposed.
Quebec Law 25
Fully in force since 22 Sep 2024
Privacy impact assessment for any project to “acquire, develop, or overhaul an information system” involving personal information and for transfers outside Quebec; relevant where AI tooling processes Quebec personal information or uses cross-border vendors.
Sectoral approach; commits to modernizing privacy and online-safety law; no new binding obligations for banks; OSFI remains the primary AI supervisor for federally regulated institutions.
Published 10 Jun 2026; consultation closed 22 Jul 2026; final expected in the coming months
Twelve practices including “prompt versioning and version control to enable rollback”, activity logging and monitoring, a “centralised, organisation-wide AI inventory”, human oversight scaled to “materiality, risk, autonomy, complexity”; names coding assistants explicitly.
“Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance”; a request for information on AI model risk is planned. Contrast: Canada’s E-23 keeps AI/ML in scope.
Omnibus in force 27 Jul 2026; Annex III high-risk obligations apply 2 Dec 2027, Annex I 2 Aug 2028; DORA applying since 17 Jan 2025
Relevant to banks with EU operations; DORA’s ICT third-party oversight and incident reporting parallel B-10 and the OSFI advisory.
How to use this page in a proposal
Present the control design as alignment with published supervisory expectations rather than as self-imposed caution. A one-page mapping from pilot controls to these instruments (see Pilot control mapping) reassures the sponsor, pre-empts second-line objections and differentiates the proposal from vendor pitches that treat governance as an afterthought.