Your AI Made A Decision. Can You Prove Why?
- Jul 27
- 4 min read
Updated: 4 days ago
Published by Slater Hill Solutions Powered by QRX Technology Group
August 2026
OSFI just gave Canadian banks and insurers a deadline to show their work on AI. If you're not in financial services, don't tune out — this is the preview of where you're headed too.
Here's the short version. Last September, OSFI (that's the Office of the Superintendent of Financial Institutions, the federal regulator for banks, insurers, and trust companies) rewrote Guideline E-23, its model risk management rulebook, to explicitly cover AI and machine learning. It takes effect May 1, 2027.
Quebec's Autorité des marchés financiers finalized a parallel rule on the same timeline. So if you're a bank or insurance CIO, that date is already sitting on your calendar. If you're not, consider this your heads up.
What the rule actually asks for isn't complicated to describe. Know every model you're running, including anything you bought from a vendor. Rate each one by how much damage a bad call could do. And be ready to show a regulator — not just what the model did, but why it did it. Miss that audit and OSFI can make you hold more capital or file a plan to fix it, on their timeline, not yours.
Actually pulling that off is a different story.
The New Reality
Why I keep coming back to this
Dr. Joseph Geraci — founder of NetraMark, a Canadian company that's been analyzing clinical trial data for the better part of a decade — spoke at CIOCAN's Peer Forum earlier this year as part of our team, at Slater Hill Digital. One line he said stuck with me: most companies can tell you what their AI agent did. Almost none of them can tell you why it decided that, in a way a regulator, a customer, or your board would actually buy.
Joe works closely with us and with our customers, so I'm not coming at this secondhand.
Digital Journal's Jennifer Friesen covered the Peer Forum talk in more detail, including more of what Joe had to say about accountability and how his pharma background shapes his thinking on autonomous agents — worth a read if you want the fuller writeup: “Your AI made a decision, and Canadian regulators want to know how,” Digital Journal.
That gap matters more than it did even a year ago. Microsoft says the number of active agents running inside Microsoft 365 alone is up fifteenfold. Deloitte's 2026 State of AI in the Enterprise report found only one company in five has anything resembling a mature process for governing them. A chatbot hallucinating in a draft email is embarrassing. That same failure inside a system that's approving refunds or flagging fraud on its own isn't embarrassing anymore — it's a model-risk incident somebody has to catch, document, and explain. Regulator involved or not.
Geraci's world — pharma — has lived with this bar for years. Drug developers have always had to defend how they got from data to conclusion. His argument is that enterprise AI is walking into the same expectation cold, with none of the discipline pharma built up to survive it.
What E-23 is actually asking for, stripped down
A complete inventory — every model in use, including vendor AI, not just what your own team built in-house.
A risk rating for each one — based on what it does, how autonomously it operates, and how much damage a bad output could cause.
Proof of the reasoning — how each higher-risk model reaches its decisions, who's accountable for it, and how it's monitored once it's live.
The Foundation Under The Audit
The part nobody wants to hear
Snowflake's chief data and analytics officer, Anahita Tafvizi, put it well when she said the honest version of this problem starts before any AI vendor is even in the room. Most companies haven't documented their own data well enough to onboard a new hire on it, let alone a model. Her question was simple — if it's not documented well enough to train a person, how exactly are you training an AI agent on it?
Security assessments are finding 350 to 430 AI services running inside a single organization, and most were never formally signed off on. That's not really an AI problem. That's a paper trail problem that AI is now making impossible to ignore.
This is the part that doesn't get fixed with a better policy memo. It gets fixed the boring way — organized records, structured data, someone actually owning what lives where, and documentation that falls out of doing the work properly instead of getting assembled the week before an audit.
That's the whole idea behind our Managed Intelligence Solutions work at QRX, and it's exactly the foundation E-23 assumes every institution already has sitting under it.

Looking Ahead
Where this leaves you
Banks and insurers have until May 1, 2027 because a regulator decided the risk was urgent enough to put a date on it. Everyone else still gets to make that call for themselves — for now. But the standard Geraci was describing doesn't go away once the deadline passes for the companies that were forced into it first.
The organizations that already have their data house in order are going to find this easy. Everybody else is going to be doing it under a clock, in front of an auditor or a board asking the exact question OSFI just put in writing.
Turns out showing your work in grade 8 math class was training for something after all.
Audits Don't Wait. Neither Should You.
Slater Hill Solutions Powered by QRX Technology Group gets Canadian teams audit-ready before regulators ever have to ask. Let's start building yours — today.
Talk soon.
Tom
VP Managed Intelligence Solutions



