InventoryOSFI E-23

OSFI E-23 Readiness Playbook

Stand up the 17-field Appendix A model inventory, map controls to the six principles, and produce the artifact set your supervisor will read before the meeting.

Phases

How the playbook runs.

Each phase is operated jointly by our compliance agents and our specialists. Agents carry the mechanical steps; specialists own the judgement calls and the sign-off at the boundary between phases.

  1. 01
    Discoveryenumerate every AI and model in the estate
  2. 02
    Tieringmaterial-risk classification and control scaling
  3. 03
    Controlsvalidation, HITL, monitoring per principle
  4. 04
    Artifactsigned, dated Appendix A register
Artifacts produced

What you hold at the end.

Signed, dated, tamper-evident, portable. The artifact set reads in PDF, Excel and JSON — and without a platform login. Your practitioners keep working even if we walk away.

Artifact 01Appendix A register (Excel + JSON)signed · dated · portable
Artifact 02Principle-mapped control librarysigned · dated · portable
Artifact 03Validation playbookssigned · dated · portable
Artifact 04Ongoing monitoring cadencesigned · dated · portable
Frameworks covered

The regimes this playbook answers.

One playbook, mapped clause-by-clause to every framework in scope. Open any framework below for the primary-source detail and the controls we land against it.

How our agents assist

The agents that touch this playbook.

Each agent is bounded, instrumented and auditable. Actions are logged. Thresholds are reviewed. A specialist holds the pen at every decision point that carries supervisory weight.

  • Inventory AgentEnumerates AI, models and agents across platforms, SaaS, notebooks and shadow deployments — seeding the Appendix A register.
  • Risk Tiering AgentApplies the material-risk classification rubric consistently and flags use cases for specialist review before tiers are signed.
  • Control Mapping AgentMaps each inventoried system to the principle-level controls your framework expects, carrying the mapping into the evidence engine.
  • Evidence Engine AgentRenders the signed, dated register and the mapped control file into a supervisor-ready artifact package.

Start this playbook on your portfolio.

Tell us which estate it runs against and which supervisory conversation it needs to answer. We will walk from first discovery to a signed artifact — with the agents doing the assembly and our specialists owning the sign-off.