If you sell software, models, analytics or AI services to a Canadian bank, trust company or insurer, sometime in the next year you are likely to receive a questionnaire that asks how your models are governed. Not how your data is secured — you’ve answered that one before. How your models are governed: who validates them, how they’re monitored, what happens when they drift, and who is accountable when one of them is wrong.
If your honest answer is “our data scientists are careful,” this article is for you, because that answer is about to start costing renewals.
I spent close to a decade inside the technology risk function of one of Canada’s five largest banks, including years building the reporting that went to executive and board risk committees. I’ve been on the side of the table that writes these questionnaires, reads the answers, and decides which vendors get flagged as residual risk. What follows is what that experience says about the next eighteen months.
What changed
In September 2025, OSFI — the regulator of Canada’s federally regulated financial institutions — published the final version of Guideline E-23 on model risk management. It takes effect on 1 May 2027.
Two features of the guideline matter enormously to firms that are not themselves regulated by OSFI.
First, the definition of “model” is broad. It is not limited to the capital and credit models a bank’s model validation team has always looked after. It reaches AI and machine learning systems, decision engines, and data-driven tools generally — anything whose output materially influences decisions. If your product scores, ranks, predicts, classifies, flags, prices or drafts, there is a good chance your client will conclude it contains a model.
Second — and this is the part that changes your commercial position — the guideline applies to models regardless of where they came from. An institution cannot answer “who validates this model?” with “our vendor seems reputable.” It remains accountable for models it buys, licenses or consumes as a service, and it has to evidence how those third-party models are governed, assessed and monitored within its own framework.
An institution cannot delegate its accountability to you. What it can do — what it must do — is push the evidentiary burden onto you. That is the flow-down, and it arrives through two instruments you already know: the due diligence questionnaire and the contract.
Why this lands before May 2027
A compliance deadline of 1 May 2027 does not mean the questions arrive on 30 April 2027.
Inside an institution, the sequence runs roughly like this. The model risk team must first build or refresh the model inventory — including third-party models, which means going business unit by business unit asking “what did we buy, and does it contain a model?” Then each third-party model has to be tiered by materiality, assessed against the framework, and either brought into compliance or documented as accepted residual risk with mitigations. Then the results have to survive internal audit and be reportable upward. Every one of those steps has to finish before the effective date, and each one takes a quarter or more at institutional scale.
Which means vendor outreach starts now-ish, peaks through 2026, and turns sharp in early 2027 when whatever hasn’t been resolved becomes an escalation. If you haven’t seen the questionnaire yet, you are not exempt. You are in a later wave.
There is a second-order effect worth understanding: renewals are the pressure point, not new sales. An institution mid-contract with a vendor that can’t evidence model governance has a problem it must document and explain. The path of least resistance at renewal is to switch to a competitor who can answer the questions cleanly. You will not be told this is why you lost the renewal.
What the questionnaire is actually asking
Having read a great many vendor responses, I can tell you the questions behind the questions. When an institution’s risk function asks about your model governance, it is trying to establish six things:
1. Do you know what your models are? An inventory. Which of your product’s components are models, what they do, what data they consume, and which decisions they influence. Vendors fail here more often than anywhere else — not because they lack the information, but because no one has ever assembled it in the shape a risk function recognizes.
2. Does someone independent check them? Validation, in the institution’s vocabulary. Not “the team that built it tested it” — someone with distance from the build reviewed the design, challenged the assumptions, and documented what they found. In a forty-person firm this does not require a validation department. It requires demonstrable independence and a record.
3. Do you watch them in production? Performance monitoring, drift detection, thresholds that trigger action, and evidence that the actions actually happen. A dashboard nobody reviews is worse than no dashboard, because it proves you knew what to look at.
4. Do you control changes? How a model moves from development to production, who approves retraining or material changes, and how a client would find out about a change that affects them. If your answer to the last part is “the release notes,” expect a follow-up.
5. Is anyone accountable? A named owner. Not a committee, not “the ML team” — a person whose job description includes this model behaving.
6. What are the limits? Documented limitations, known failure modes, and the conditions under which the model should not be relied on. Counterintuitively, a vendor who can articulate limitations scores better than one who claims none. To a risk reviewer, “no known limitations” reads as “no one has looked.”
Notice what is not on this list: your model’s accuracy benchmarks, your architecture, your parameter count. The institution is not evaluating whether your model is good. It is evaluating whether your model is governed — whether, if something goes wrong, there is a system that would have noticed, a person who would have acted, and a paper trail that proves both.
What “good enough” looks like at vendor scale
The mistake vendors make in both directions: some do nothing and hope the questionnaire is a formality; others panic and try to replicate a bank’s model risk department. Both are wrong. What a proportionate answer looks like for a firm of twenty to two hundred people:
A model inventory — likely a single well-structured document. Every model-like component, its purpose, its data, its downstream decisions, its owner, its risk tier. This is a week or two of honest work, and it is the foundation for every other answer.
A short model risk policy — a few pages establishing tiering, the lifecycle controls per tier, who approves what, and how often things are reviewed. Written to be followed, not to impress.
Independent review, sized honestly — for a small firm this can be a structured peer review by someone outside the build team, an external reviewer for the highest-tier models, or both. What matters is the independence and the documentation, not the headcount.
Monitoring with teeth — defined metrics, defined thresholds, a named responder, and a log showing that when a threshold tripped, something happened.
A client-facing governance summary — a two-to-four page document that answers the six questions above, ready to attach to any questionnaire. This single artifact shortens due diligence cycles more than anything else on this list, because it lets the institution’s reviewer copy your answers into their assessment instead of chasing you for them. Make the reviewer’s job easy and you become the vendor they advocate keeping.
None of this is beyond a small firm. All of it is beyond a small firm the week the questionnaire lands with a fourteen-day turnaround.
The uncomfortable truth about timing
Everything above can be built calmly in six to ten weeks, or frantically in two — and the frantic version reads as frantic to the person assessing it. Risk reviewers develop a feel for documentation that was written the week before it was requested. Backdated governance is worse than absent governance, because it converts a capability gap into a credibility problem.
There is also an asymmetry worth sitting with. For your client, an unresolved vendor gap is a line item in a residual risk report. For you, it is a renewal. The institution has a process for living with your weakness. You do not have a process for living with their exit.
The vendors who treat the next twelve months as a window rather than a threat will find that model governance flips from a cost into a differentiator — the thing their sales team leads with while competitors are still asking their engineers what “validation” means to a bank.
Where to start
If you sell into Canadian regulated financial services and any part of your product predicts, scores, classifies, or generates, do three things this quarter: build the inventory, write the two-page governance summary, and pressure-test both against the six questions above as if you were the reviewer. If you want a second pair of eyes from someone who has sat on the reviewing side, that is precisely the work we do.