Operationalizing Canada’s Federal Guideline OSFI E-23 — Model Risk Management to Deliver Fair Consumer Outcomes
ver the past several years, the CAS, through its research task forces, has extensively researched how various state and international regulators are approaching algorithmic fairness and model bias. As the global actuarial profession transitions from defining these frameworks to operationalizing them, Canada emerges as a live-environment test case. On May 1, 2027, the Canadian insurance industry enters a new era of governance. This date marks the deadline for full compliance with the Office of the Superintendent of Financial Institutions (OSFI) Guideline E-23 on Model Risk Management (MRM).1 While treating E-23 primarily as a rigorous federal compliance checklist is a defensible baseline for many institutions, integrating it with the broader market conduct goals creates the foundational infrastructure needed to navigate an environment increasingly scrutinized for algorithmic fairness, specifically the “fair consumer outcomes” mandated by regulators like the Financial Services Regulatory Authority of Ontario (FSRA).
We are entering a period where models, including those for insurance ratemaking and underwriting, should be mathematically sound, legally defensible, and socially fair. A model that is predictive but results in unexplained disparities is no longer just a market conduct issue; under the expanded scope of E-23, it may represent a model risk event or a compliance challenge.
The great convergence: A national imperative
Guideline E-23 alters this landscape by forcing these two worlds to interact. By expanding the definition of Model Risk to explicitly include adverse financial impact such as operational or reputational consequences,1 E-23 provides the governance chassis where these deliberate trade-offs are evaluated, documented, and justified by management.
A market-moving trend
- Ontario: FSRA’s guidance explicitly moves toward principles-based regulation, focusing on outcomes rather than technical rules.
- Québec: The Autorité des marchés financiers (AMF) has released a guideline setting expectations for institutions to manage AI systems based on their impact on consumers.3
While the specific legal mechanisms differ among jurisdictions, E-23 provides the unified governance chassis to adapt to these evolving provincial expectations. Implementing a prudent E-23 MRM framework provides the evidentiary baseline required to demonstrate market conduct compliance to provincial regulators.
The legal landmine: The expiration of the “Zurich defense”
Challenge 1: The rational connection (from correlation to causality)
For instance, in usage-based insurance, heavily penalizing late-night driving might correlate with the shift workers in lower-income brackets. Actuaries should consider using appropriate proxy variable tests to prove the risk lies in the fatigue and visibility of night driving, not the socioeconomic status of the driver.
Challenge 2: No practical alternative in the age of AI
A structured due diligence framework: The Human Rights Impact Assessment (HRIA)
- Validating the Rational Connection: The HRIA advises insurers to evaluate statistical correlations, utilizing explainability tools to prove that variables are capturing genuine, causal risk drivers rather than acting as proxies for protected classes.
- Proving No Practical Alternative: If an adverse impact is identified, the HRIA recommends an alternatives analysis. By systematically testing less discriminatory models and generating privileged documentation that records the resulting degradation in predictive accuracy and financial viability, the HRIA establishes the evidentiary baseline required to debate “undue hardship” or lack of a commercially viable alternative before a regulator.
Integrating the HRIA into the E-23 validation process does not grant statutory immunity. However, it ensures that if an insurer retains a model with disparate impact, they do so with a documented defense that the model represents a sound insurance practice with no viable commercial or technical alternative.
Operationalizing E-23: Integrating model compliance risks into the model life cycle
- Risk Rating and Management Intensity: Insurers should establish a risk rating that moves beyond financial materiality to include key dimensions of compliance risk. For rating and underwriting applications, the significance of human impact, the likelihood of discriminatory harm, and the required level of explainability are critical factors in the inherent risk rating. These ratings drive the downstream model life cycle, determining model usage limits, monitoring intensity, and the escalation of residual risk management decisions.
- Model Rationale and Documentation: Model owners should provide a clear rationale for deployment that explicitly addresses market conduct and fair consumer outcomes. This includes documenting considerations for the required level of transparency and explainability, as well as a proactive assessment of the potential for biased outcomes, negative social and ethical implications, or privacy risks.
- Model Data and Development: The guideline expands data governance requirements from primarily accuracy concerns to broader facets: data should be relevant, representative, compliant, traceable, and timely. Insurers should enhance model explainability by analyzing the potential for unwanted data bias to translate into unfair model outputs and associated reputational risks. Clear, consistent, and repeatable practices for model development should be established to ensure that explainability standards are met, with rigor varying based on regulatory requirements and the potential impact on customers.
- Model Review and Deployment: E-23 requires independent model review to confirm that the model outputs are appropriately explainable and comply with performance expectations before the model impacts a consumer. Crucially, deployment might necessitate conditional approval subject to outcome monitoring to detect whether “fairness drift” occurs post-launch, ensuring that the model remains fair not just in the test environment, but in the real world.
By operationalizing these E-23 principles, insurers can ensure that the necessary evidence for the “Zurich Defense,” i.e., the proof of diligence and the testing of alternatives, is sufficient and documented as part of the standard, enterprise-wide control cycle.
The E-23 Perimeter: A risk-based expansion beyond ratemaking and underwriting
The regulatory dividend: Enterprise-wide confidence
The risk-based expansion can be illustrated through three tiers of operational reality:
- High compliance risk models do not always calculate a premium; they can act as gatekeepers to the quoting process itself. Consider an algorithmic point-of-sale fraud model that evaluates a digital footprint. If an applicant is scored as “high risk,” the system intentionally injects quoting friction, such as blocking the direct-to-consumer online rate and forcing a manual broker call. If this model relies on proxy variables that systematically flag specific minority cohorts, it could constitute a discriminatory barrier to entry for a mandatory financial product. Because these models dictate fundamental, equitable access to coverage, those resulting in systematic, disparate barriers require a full “reasonable and bona fide” assessment. Insurers should use human impact assessment tools like the HRIA to prove the fraud variables capture genuine, causal risk rather than acting as protected-class proxies and explicitly demonstrate a lack of less discriminatory screening alternatives.
- Medium compliance risk models prioritize convenience, creating an indirect fairness impact that requires lighter control. For example, a claims triage model that decides who gets instant approval versus standard handling creates a conduct risk if one group is systematically slowed down, but it does not accuse the customer of fraud. While these models may not demand an exhaustive assessment, they need sufficient pre-deployment proxy testing on historical data combined with automated post-deployment circuit breakers to ensure service level disparities remain within acceptable bounds.
- Low compliance risk models have remote or nonexistent human impact. Applying fairness testing here would be a misuse of resources. For example, actuarial reserving models operate on aggregate data pools to ensure solvency. While crucial for financial stability, they do not make individual decisions about consumers. For these models, impact assessment tools like the HRIA are non-applicable. The focus remains on the traditional pillars of performance and stability. By explicitly categorizing these as low compliance risk that are subject only to light inventory requirements, the insurer demonstrates the “proportionality” required by OSFI, preserving resources for the highest impact models.
The path forward: Operationalizing E-23 to deliver fair consumer outcomes
To navigate this successfully, the industry should focus on:
- Integrated life cycle management: The end-to-end model life cycle should explicitly integrate model compliance parameters for fair consumer outcomes.
- Risk-based governance: Governance rigor should be proportional to the model compliance risk parameters such as bias, fairness, explainability, and human impact.
- Evidentiary escalation versus risk acceptance: Market conduct violations cannot be formally accepted like financial and insurance risks. Models exhibiting unmitigated disparate impact should be escalated to senior management and legal counsel strictly to validate the “Zurich defense” prior to deployment.
The convergence of E-23 and FSRA requirements on fair consumer outcomes represents the current trajectory. Actuaries should review their model inventories not just for financial materiality, but also for compliance materiality. As the industry transitions into a regulatory environment that demands higher transparency, proactively operationalizing risk-based fairness provides the essential infrastructure to navigate these evolving standards effectively.
References
- Office of the Superintendent of Financial Institutions (OSFI). Guideline E-23: Model Risk Management (2027)
- Financial Services Regulatory Authority of Ontario (FSRA). Guidance: Automobile Insurance Rating and Underwriting Supervision (No. AU0142INT)
- Autorité des marchés financiers (AMF). Guideline for the Use of Artificial Intelligence. June 2025.
- Zurich Insurance Co. v. Ontario (Human Rights Commission), [1992] 2 S.C.R. 321.
- Law Commission of Ontario & Ontario Human Rights Commission. Human Rights Impact Assessment (HRIA) for AI. November 2024.