AI governance, risk and compliance advisory
Your organization is adopting AI faster than anyone has written rules for it. We build the governance layer that lets you keep moving — AI inventories, model risk management frameworks, vendor due diligence, and the oversight your board and your counterparties will ask to see.
Three buyers
Who we work with
Federally regulated financial institutions
Smaller banks, trust and loan companies, foreign bank branches, and insurers who now fall inside OSFI’s expanded model risk expectations but don’t have an enterprise model risk function to meet them.
Firms that supply or partner with regulated institutions
Fintechs, model and analytics vendors, servicers, and technology providers. Your clients’ obligations are becoming your obligations, delivered through their vendor questionnaires and contract terms.
Provincially regulated and other financial services firms
Credit unions, portfolio managers, mortgage investment corporations, MGAs, and payment businesses. You may sit outside OSFI’s perimeter, but your board, your auditors, your insurers, and your institutional counterparties are asking the same questions.
The deadline
OSFI Guideline E-23 takes effect on 1 May 2027.
The revised guideline applies to all federally regulated financial institutions and to all models that carry risk — not just the quantitative models a bank would traditionally validate. That includes machine learning models, generative AI assistants, rule-based decision engines, and, in many cases, spreadsheets that drive material decisions.
Two things about it matter more than the headline:
It reaches models you didn’t build.
The guideline applies regardless of whether a model is developed internally or sourced from a third party. A regulated institution remains accountable for models it licenses — which means it has to be able to evidence how those models are governed, validated and monitored.
That obligation flows downhill.
Many AI and analytics vendors do not yet have governance, validation or reporting capabilities that would satisfy an institution’s model risk framework. If you sell into regulated financial services, expect the questions to arrive well before the deadline does — because your clients need their evidence in place before 1 May 2027, not on it.
If you are inside the perimeter, the work of identifying your models alone typically takes longer than firms expect. If you supply into it, the commercial risk is losing a renewal to a competitor who can answer the questionnaire.
What we deliver
Where we help
AI governance readiness assessment
An honest picture of where you stand against OSFI E-23, the NIST AI Risk Management Framework, and ISO/IEC 42001. You get a gap register, a risk-ranked remediation roadmap, and a realistic view of effort — not a maturity score with no plan attached.
Model and AI inventory
The step almost everyone underestimates. We work through your business to identify what actually meets the definition of a model, tier it by risk and materiality, and build the inventory that everything else depends on. Without this, a framework has nothing to govern.
Model risk management framework design
Policy, model tiering and materiality criteria, lifecycle controls from development through decommissioning, validation and independent review standards, ongoing performance monitoring, and defined roles across the three lines of defence. Proportional to your size — a framework built for a bank of forty thousand people will not survive contact with a firm of forty.
AI usage policy and acceptable use standards
The practical questions your team is already navigating without guidance: which tools are approved, what data may go into them, when a human must review output, who signs off on a new use case, and what happens when someone gets it wrong. See our six-decision breakdown of exactly this.
AI and model vendor due diligence
Assessment of third-party AI and model providers against your risk appetite — what to ask, how to evaluate what you get back, which contractual controls to insist on, and how to document residual risk you’ve decided to accept. Delivered as a one-off assessment or as a repeatable programme your team runs itself.
Board and management reporting
Turning AI and model risk into something a director can act on: risk appetite statements, key risk indicators, issue and remediation tracking, and committee reporting packs. This is the discipline we spent nearly a decade practising at the scale of a major Canadian bank.
AI governance committee and operating model design
Terms of reference, decision rights, escalation paths, and the meeting cadence that makes governance real rather than documented.
Engagement shapes
Typical engagements
Readiness assessment
Where you stand, what’s missing, what to do first. The usual starting point, and often enough on its own for a firm that just needs to answer its board.
Framework build
Full model risk management framework, policy set, inventory and tiering, and the reporting scaffolding — built with your team so they can run it after we leave.
Vendor due diligence
Either we assess specific vendors for you, or we build the process and train your team to run it.
Fractional AI governance support
Ongoing advisory for firms that need the capability but not the headcount. Committee attendance, reporting review, new use case assessment, and a standing line to call when something unexpected lands.
Fluency, not jargon
Standards and frameworks
Canadian financial services
- OSFI Guideline E-23 (Model Risk Management, 2027)
- OSFI B-10 (Third-Party Risk Management)
- OSFI B-13 (Technology and Cyber Risk Management)
AI-specific
- NIST AI Risk Management Framework
- ISO/IEC 42001
- Canada’s Voluntary Code of Conduct on Advanced Generative AI
- EU AI Act, where you have European exposure
Governance and controls foundation
- COBIT 5
- COSO ERM
- Three lines of defence
Privacy
- PIPEDA
- Quebec Law 25, including automated decision-making
A note on the Canadian legal position, since it’s widely misunderstood: there is currently no comprehensive federal AI statute. The Artificial Intelligence and Data Act died on the order paper in January 2025 and has not been reintroduced. That does not mean AI is unregulated in Canadian financial services — it means the obligations arrive through sector guidance, privacy law and contract rather than through a single act. For a regulated financial services firm, OSFI’s expectations are the binding constraint, not a future AI law.
Why Hosmak
Governance experience first, AI second — which is the right way round.
Most AI governance advice today comes from people who understand AI but have never designed a control framework, sat in an independent challenge role, or written a paper for a board risk committee.
We came to AI governance from twenty-five years of doing exactly that work in financial services: eleven years at PwC and EY leading technology governance assessments, IT risk assessments and controls reviews for financial institutions, and nearly a decade inside one of Canada’s five largest banks building enterprise technology risk governance — the process, risk and control framework, the risk appetite statement and KRI suite, the issue management reporting, and the executive and board-level risk packages that went with them.
AI model risk management is not a new discipline. It is model risk management, applied to a harder class of model, under a control framework that has to hold up when someone independent comes to look at it. We have built those frameworks at institutional scale. We now build them at a scale you can actually operate.
Credentials
- FCA (Nigeria) — see designation note
- CISA
- CRISC
- AAIR
- CFSA
- COBIT 5 Accredited
Questions
Common questions
We’re not federally regulated. Does E-23 apply to us?
Not directly. But if you supply models or AI services to a federally regulated institution, their obligations reach you through their third-party risk process and their contracts. And if you’re provincially regulated, your own supervisor, your auditors and your board are asking materially similar questions. The framework is much the same; the driver is different.
We only use tools like Copilot and ChatGPT. Is this overkill?
Probably not, though the answer depends on what you’re using them for. The question that matters isn’t which tool you’ve licensed — it’s whether any output is influencing a decision that affects a customer, a financial statement, or a regulatory filing, and whether anyone has written down who’s accountable when it goes wrong.
Isn’t this our IT or security team’s job?
They own part of it. Security controls, access and data protection sit with them. But model risk is a business risk, not a technology risk: it’s about whether a model is fit for its purpose, whether its limitations are understood, and who owns the decision it informs. That’s governance work, and it usually needs someone independent of the team that built or bought the model.
How long does this take?
A readiness assessment is typically 2–4 weeks. A full framework build is typically 6–12 weeks depending on how many models you have and how much of the inventory already exists. The inventory is almost always the long pole.
Do you implement, or only advise?
We build the artefacts with your team and hand over working documents you own and can maintain. We don’t leave you a locked PDF and an invoice.
What if we’re starting from nothing?
That’s the most common starting point, and it’s a better position than a framework nobody follows. We’d usually begin with the inventory and a short readiness assessment so you know the size of the problem before committing to a budget.
This page describes general regulatory expectations and industry practice, not legal advice. Firms should confirm their specific obligations against the source instruments and with their own advisors.
Start with a conversation
Bring the questionnaire, the board question, or the audit finding. Thirty minutes, no cost, and you’ll leave with a clear view of what it would take to answer it properly — whether or not you work with us.
Book a 30-minute consultationOr email hello@hosmaksolutions.ca