Canada · United States · European Union · United Kingdom

Every framework your portfolio touches.

Canadian, US, EU, UK and international obligations converge on the same control surface — governance, data, validation, evidence, provenance. We maintain one authoritative control mapping, indexed clause by clause against every regime below, so the artefact that answers OSFI E-23 also answers the EU AI Act, NIST AI RMF and ISO/IEC 42001 with the rewiring each supervisor expects.

Select a framework to see what we know in it, which services cover it, and the playbooks that ship against it.

The Canadian regulator record is indexed in our retrieval catalog (OSFI, FINTRAC, OSC, FSRA, and Ontario sources). Non-Canadian frameworks are covered through senior advisory work, not the catalog.

28 frameworks5 jurisdictionsPrimary-source anchoredContinuously maintained

Canada

10 frameworks
OSFI E-23Canada

Model Risk Management Guideline

Effective May 1, 2027

The 17-field Appendix A model inventory. Applies to FRFIs across all model types — traditional, generative, agentic.

Open framework →
OSFI B-10Canada

Third-Party Risk Management

Effective May 1, 2024

The third-party AI cascade — nth-party traceability through vendor stacks embedded in enterprise software.

Open framework →
OSFI E-21Canada

Operational Risk & Resilience

Revised 2024

Critical operations, tolerances for disruption, and the resilience posture required when AI sits in the critical path.

Open framework →
OSFI FIFAICanada

Financial Industry Forum on AI

Discussion report series

OSFI-convened industry workshops on AI governance expectations for federally regulated financial institutions.

Open framework →
PIPEDACanada

Personal Information Protection and Electronic Documents Act

In force

Federal private-sector privacy law. Meaningful consent, accountability, access rights.

Open framework →
Quebec Law 25Canada

Act to modernize legislative provisions as regards the protection of personal information

In force since September 22, 2023

ADM transparency, PIAs, cross-border transfer rules. Penalties up to $25M CAD or 4% of global revenue.

Open framework →
PHIPACanada

Personal Health Information Protection Act (Ontario)

In force

Ontario health information privacy — relevant only for BFSI institutions with direct health-data exposure (e.g., group insurance, health-savings accounts).

Open framework →
PCMLTFACanada

Proceeds of Crime (Money Laundering) and Terrorist Financing Act

In force with ongoing regulatory amendments

AI-driven AML, KYC, and transaction monitoring under FINTRAC supervision.

Open framework →
CIROCanada

Canadian Investment Regulatory Organization

Active SRO since January 1, 2023 (IIROC + MFDA merger)

Algorithmic supervision, gatekeeping, and AI-assisted order handling obligations for investment dealers.

Open framework →
OSC Staff Notice 11-348Canada

Applicability of Canadian Securities Laws and the Use of AI by Market Participants

Published Q4 2024

Staff guidance on how Canadian securities laws apply when registrants, issuers and dealers use AI.

Open framework →

Bring your framework stack. We bring the compliance intelligence layer.

Tell us which regimes your portfolio answers to and we will map your existing posture against every applicable clause — gaps, evidence, and the fastest route to an artifact your regulator will read.