Responsible AI for Canadian Insurers: OSFI, Law 25, and Human-in-the-Loop
TL;DR
- The fact most vendor content gets wrong: OSFI Guideline E-23 does not apply to insurers today. The version in force right now is E-23 (2017), and its scope is deposit-taking institutions only. The final E-23 published 11 September 2025 brings life, fraternal and property and casualty companies into scope — but not until 1 May 2027. Any page describing E-23 as a current obligation on insurers is describing the wrong document.
- There is no standalone OSFI AI guideline, in force or in draft. OSFI's AI expectations sit inside E-23's model risk framework. The EDGE and AGILE material published alongside it comes from reports, not guidance, and is non-binding.
- Quebec's Law 25 does not ban automated decisions. Section 12.1 is triggered only by a decision "based exclusively on an automated processing," and what it grants is a right to submit observations to a person able to review the decision — not a right to have the decision re-made by a human.
- Human review is not mandated by Canadian law — it is a strong control. It keeps a decision outside the s.12.1 trigger, it produces the explainability record E-23 will ask for from 2027, and it is what the non-binding OSFI-adjacent frameworks recommend.
- Canadian data residency is not a legal requirement for insurers. The Insurance Companies Act record-keeping rule covers a defined list of corporate records, not claims files or underwriting documents, and PIPEDA has permitted cross-border processing since the OPC settled the question in 2009.
- The useful output of all this is a vendor governance checklist — and the hardest question on it ("where does inference run?") is one most AI vendors, including this one, should expect to be asked more often than they currently are.
Canadian insurance AI content has a sourcing problem. A great deal of it asserts that OSFI already obliges federally regulated insurers to run a model risk management framework under Guideline E-23, that Quebec's Law 25 gives consumers a right to a human decision, and that Canadian customer data has to be held in Canada. None of those three statements is accurate as of August 2026.
This piece is an attempt to state the Canadian position precisely, with dates and section numbers, and then to turn it into something operationally useful: a vendor evaluation checklist a compliance or underwriting-operations team can run without needing a law firm on retainer for the first pass.
One scoping note before anything else. OSFI supervises federally regulated financial institutions. A substantial share of Canadian property and casualty capacity is written by provincially incorporated insurers, reciprocals and mutuals that fall outside OSFI's remit entirely and answer instead to FSRA in Ontario, the AMF in Quebec, or their provincial equivalent. Brokerages sit outside all of it, with conduct oversight through bodies such as RIBO and association work through IBAO and IBAC. Before applying any of the below, confirm which supervisor actually has you.
What OSFI E-23 will require, and when
Guideline E-23 is OSFI's model risk management guideline. Two versions of it exist, and conflating them is the single most common error in Canadian insurance AI writing.
E-23 (2017) is the version in force today. Its scope is deposit-taking institutions only. It does not apply to insurers.
E-23 (2027) was published in final form on 11 September 2025 and takes effect on 1 May 2027. Its scope adds life insurance and fraternal companies, and property and casualty companies, alongside banks, foreign bank branches, and trust and loan companies. Federally regulated pension plans were in the draft and were removed from the final.
The practical consequence: federally regulated insurers are not currently subject to E-23. They come into scope on 1 May 2027. The correct framing is "will require, from 1 May 2027" — not the present tense. Insurers have until May 2027, which is roughly two budget cycles, not two quarters.
The final guideline is built around three Outcomes and twelve Principles (1.1–1.3, 2.1–2.3 and 3.1–3.6). It is principles-based and proportional, which means the depth of the framework OSFI expects scales with the risk a model carries rather than arriving as a fixed checklist.
Two things make E-23 (2027) unusually relevant to document AI and underwriting automation.
The first is the breadth of the definition of a model. E-23 (2027) defines it as:
"Model", per OSFI Guideline E-23 (2027)
"An application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI/ML methods, which processes input data to generate results."
On that wording, a document extraction system that reads a loss run or a CSIO application and emits structured fields is a model. So is a submission triage score. So is a rules engine with judgmental assumptions baked into it. Institutions that scope their May 2027 readiness work to pricing and reserving models alone are likely to find the inventory exercise larger than expected.
The second is that explainability is expressly calibrated rather than absolute. Principle 3.3 refers to "explainability requirements, which may vary based on the model's purpose, level of autonomy, regulatory requirements, or the potential impact on customers and stakeholders." Principle 3.1 asks that frameworks "be sufficiently flexible to accommodate evolving technologies, different model types (especially crucial given the 'black box' and autonomous nature of many AI/ML models)."
Read those together and the shape of the expectation is clear: the more autonomous the system and the more it touches a customer outcome, the more explanation an institution is expected to be able to produce. That is a sliding scale, and where a given deployment sits on it is a decision the institution has to make and defend.
Third-party models are in scope, and validation stays with you
E-23 (2027) covers models or data sourced externally, including from foreign offices or third-party vendors, and routes that through OSFI's third-party risk guideline. The cover letter is direct about the division of labour:
"Institutions should comply with third-party risk management principles established under guideline B-10… Institutions should also ensure that third-party models receive validation and monitoring commensurate to the model risk."
— OSFI, cover letter to Guideline E-23 (2027)
This is worth dwelling on, because it disposes of a category of vendor marketing. A vendor cannot make an institution E-23 ready, and there is no certification to hold. The obligation sits with the institution, and OSFI is explicit that validation and monitoring of a third-party model are the institution's responsibility. What a vendor can honestly offer is inputs to that work: documentation, explainability artefacts, monitoring outputs, model change notice, and contract terms that feed the institution's own model risk framework and its B-10 file. Anything phrased more strongly than that is a claim the guideline does not support.
The guidelines that already apply
While E-23 waits for 2027, two OSFI guidelines are already in force and already govern how a federally regulated insurer buys and runs AI software.
| Guideline | Status | What it governs |
|---|---|---|
| B-13 Technology and Cyber Risk | Published 31 July 2022, effective 1 January 2024. In force. Amended 22 February 2024 (foreign-branch clarification only). | Technology and cyber risk management at FRFIs, including life and P&C insurers. |
| B-10 Third-Party Risk Management | Published and effective 30 April 2023. In force. | The guideline that actually governs the vendor relationship today — due diligence, contractual terms, monitoring, concentration and exit. |
| E-23 Model Risk Management | 2017 version in force, deposit-taking institutions only. Final 2027 version effective 1 May 2027. | Model risk, including AI/ML methods — for insurers, from May 2027. |
If you are running an AI vendor evaluation in 2026 and looking for the hook to hang it on, B-10 is the one that is live.
What OSFI has published on AI that is not guidance
Two OSFI-associated publications get cited as though they were requirements. They are not, and treating them as such tends to undermine the credibility of the rest of a governance argument.
- The OSFI–FCAC risk report, AI Uses and Risks at Federally Regulated Financial Institutions (24 September 2024). It introduced the EDGE principles — Explainability, Data, Governance, Ethics — and reported AI use at FRFIs rising from roughly 30% in 2019 to about 50% in 2023, with an expectation of 70% by 2026. Useful framing and useful numbers. Not a rule.
- FIFAI II, AI Risks and Opportunities: Adopting an AGILE Framework (23 March 2026). AGILE stands for Awareness, Guardrails, Innovation, Learning, Ecosystem Resiliency. The document carries an explicit disclaimer that it does not necessarily reflect the views of the sponsoring authorities. It is worth reading — its recommendation to "include, where possible and appropriate, human oversight of material decisions made by AI-assisted tools, agents and services" is a fair summary of where supervisory thinking sits — but it is non-binding and should be cited that way.
There is no standalone OSFI AI guideline, in force or in draft. The AI expectations live inside E-23.
Quebec Law 25 and automated decision-making
Quebec's private-sector privacy statute — the Act respecting the protection of personal information in the private sector, CQLR c. P-39.1 — contains the most specific automated decision provision in Canadian law. Section 12.1 came into force on 22 September 2023. Here it is in full, because paraphrases of it are usually wrong:
"Any person carrying on an enterprise who uses personal information to render a decision based exclusively on an automated processing of such information must inform the person concerned accordingly not later than at the time it informs the person of the decision. He must also inform the person concerned, at the latter's request, (1) of the personal information used to render the decision; (2) of the reasons and the principal factors and parameters that led to the decision; and (3) of the right of the person concerned to have the personal information used to render the decision corrected. The person concerned must be given the opportunity to submit observations to a member of the personnel of the enterprise who is in a position to review the decision."
— CQLR c. P-39.1, s.12.1, in force 22 September 2023
Two points of precision matter more than anything else in that paragraph.
The trigger is "exclusively." Section 12.1 attaches to a decision based exclusively on automated processing. A decision that a qualified person meaningfully reviewed before it was rendered falls outside the trigger. That is not a loophole; it is the design of the provision, and it is the strongest and most honest argument available for human review in a Canadian underwriting or claims workflow. It is a far better argument than the overstatement that usually replaces it.
What it grants is observations, not a re-decision. Where s.12.1 does apply, the individual can be informed, can ask for the information used, the reasons and the principal factors and parameters, can have the personal information corrected, and can submit observations to a member of personnel who is in a position to review the decision. Quebec has not enacted a GDPR Article 22-style prohibition on automated decisions, and s.12.1 does not create a right to have the decision re-made by a human. Content that upgrades it into one is easy to disprove, and it takes the rest of the argument down with it.
Section 17 and transfers outside Québec
The provision with more day-to-day procurement consequence is s.17, also in force since 22 September 2023. Before communicating personal information outside Québec, an enterprise must conduct a privacy impact assessment that considers the sensitivity of the information, the purposes for which it is to be used, the protection measures — including contractual ones — that would apply to it, and the legal framework applicable in the destination jurisdiction. The communication may proceed if the assessment establishes that the information would receive adequate protection, and it must be covered by a written agreement.
That is an assessment obligation on the insurer, not a prohibition, and not something a vendor can discharge on your behalf. What a vendor can do is supply the inputs: the subprocessor list, the destination jurisdictions, the technical and contractual protection measures, and terms that survive in writing.
Law 25 is now fully in force. The final tranche, the data portability right in the third paragraph of s.27, landed on 22 September 2024. There is nothing further pending.
Where human-in-the-loop actually helps
It would be convenient to write that OSFI mandates a human in the loop. It does not, and E-23 does not say so. What E-23 (2027) will require is explainability calibrated to the model's purpose, level of autonomy, regulatory requirements and potential impact on customers and stakeholders. Human review is a well-supported control, not a mandate.
Stated that way, the argument for it is still strong, and it rests on three legs.
- It keeps a decision outside the Law 25 s.12.1 trigger. If a qualified person reviews the extracted data and the resulting decision before it is rendered, the decision is not based exclusively on automated processing, and the s.12.1 notification and observations machinery is not engaged. This is the cleanest, most defensible reason to design review into a Quebec-facing workflow, and it does not depend on any regulator publishing anything new.
- It produces the explainability record E-23 will ask for. Principle 3.3's sliding scale runs on autonomy and customer impact. A workflow in which a person sees the source document, the extracted value and the confidence signal, and either accepts or corrects it, generates a per-decision record almost as a by-product: what the model proposed, what the human did, when, and on what evidence. That record is an input to the institution's own validation and monitoring — which, per the cover letter, is where the obligation sits.
- It is the control the OSFI-adjacent frameworks recommend. The FIFAI II AGILE report asks institutions to include, where possible and appropriate, human oversight of material decisions made by AI-assisted tools, agents and services. EDGE puts Explainability first among its four principles. Neither is binding. Both are a reasonable read on where supervisory expectations are heading, and a governance posture built to satisfy them is unlikely to be embarrassed by whatever arrives next.
The counter-argument deserves an airing too, because a piece that only lists benefits is not a governance piece. Human review has a cost, it introduces its own error modes, and reviewer fatigue on a high-volume queue is a real failure mode rather than a theoretical one. The design question is not "human or not" but which decisions carry enough customer impact or model uncertainty to be worth a person's attention, and how you evidence that the attention was genuine rather than a click-through. An institution that cannot answer the second half of that is likely to have an awkward conversation in 2027.
What Canadian law actually says about where data lives
Data residency is the question that dominates Canadian AI procurement, and it is the one most often stated incorrectly — usually as a flat requirement that Canadian insurance data be held in Canada.
There is no general legal requirement that Canadian insurers hold customer or policy data in Canada.
The provision usually pointed at is the Insurance Companies Act. Section 262(1) does require that the records described in s.261 be kept at the head office or another place in Canada. But s.261 is a defined list of corporate records: incorporating documents, by-laws, minutes, returns to the Superintendent, corporate accounting records, and per-customer amounts owing. Claims files, submissions, loss runs and underwriting documents are not on that list. Applying a corporate records provision to an underwriting document pipeline is a category error, and it is one that has driven real procurement decisions.
OSFI itself contemplates records held outside Canada. B-10 s.2.3.2.2 expressly addresses that scenario, conditioned on OSFI having "immediate, direct, complete and ongoing access" to the records.
Federally, PIPEDA has been settled on this since the Office of the Privacy Commissioner published its Guidelines for processing personal data across borders on 27 January 2009, reaffirmed unchanged on 23 September 2019. The relevant lines:
"PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing."
"A transfer for processing is a 'use' of the information; it is not a disclosure."
— OPC, Guidelines for processing personal data across borders (2009, reaffirmed 2019)
What PIPEDA does impose is accountability and transparency. Under Schedule 1, Principle 4.1.3, an organization remains accountable for personal information transferred to a third party for processing and "shall use contractual or other means to provide a comparable level of protection" while it is there. Organizations are also expected to be transparent that information may be sent to another jurisdiction for processing, and that while the information is in that jurisdiction it may be accessed by the courts, law enforcement and national security authorities there.
Provincially, Alberta's PIPA and British Columbia's PIPA are recognised as substantially similar to PIPEDA by Governor in Council orders SOR/2004-219 and SOR/2004-220, both registered on 12 October 2004. The carve-out matters: the exemption applies only to organizations other than federal works, undertakings and businesses, and only to collection, use and disclosure occurring within that province. Quebec's regime, per s.17 above, sets its own assessment requirement rather than a prohibition.
So the accurate Canadian position is that cross-border processing is lawful, conditioned on assessment, comparable contractual protection, transparency, and — in Québec — a documented privacy impact assessment before the information goes. Residency can still be a sound commercial or risk-appetite preference. Plenty of Canadian buyers hold that preference for reasons that have nothing to do with statute, and it is a legitimate position to take in an RFP. It is just not a legal requirement, and describing it as one distorts the evaluation.
For completeness on our own position: Canadian data residency is available on request, and data does not leave the region your deployment is configured for. That is the whole of the accurate answer, and it is the level of specificity worth expecting from any vendor you ask.
A governance checklist for Canadian insurers evaluating AI vendors
This is the part worth keeping. It is written to be vendor-neutral, and it deliberately includes questions that are uncomfortable for AI vendors to answer, this one included. A checklist that only one supplier can pass is a sales document, not a governance tool.
- Confirm which supervisor actually applies to you. Federally regulated insurer, provincially licensed insurer, reciprocal, MGA or brokerage — OSFI's guidelines reach the first category. If FSRA, the AMF or another provincial supervisor has you, E-23 and B-10 are useful reference frameworks rather than obligations, and your privacy analysis may run through Alberta or British Columbia PIPA instead of PIPEDA.
- Ask where inference runs, not just where data is stored. Storage location is the question everyone asks, and it is the easier half. Where the model executes, whether any inference call leaves the configured region, whether an upstream model provider is involved and where that provider processes the request — these are separate questions with separate answers, and many vendors, this one included, get asked the storage question far more often than the inference question. Ask both, and ask for the answer in writing.
- Get the subprocessor list, and the change-notice term. Who else touches the data, in which jurisdiction, for what purpose, and how much notice do you get before that list changes? This is standard B-10 diligence, and it is also the raw material for a Law 25 s.17 assessment.
- Ask whether your documents train anyone's models. Get the answer for the vendor's own models and for any upstream provider. Confirm whether the default is off, whether it is contractual rather than a settings toggle, and what happens to derived artefacts such as embeddings and evaluation sets.
- Ask for the per-decision explainability artefact. For any extracted or inferred value, can the system show the source document, the specific location within it, a confidence signal, and the model version that produced it? Explainability that exists only as a dashboard-level accuracy number will struggle to carry an examiner conversation under E-23's Principle 3.3 sliding scale.
- Ask for the human review record, and check that it exports. Reviewer identity, timestamp, the value before and after, and whether the record leaves the vendor's platform in a form your own systems can retain. An audit trail you can only view inside the vendor's interface is a dependency, not evidence.
- Ask for the model change process. Version identifiers, notification lead time before a model changes underneath you, whether you can test a new version before it reaches production, and whether you can decline. Under E-23 a third-party model still needs validation and monitoring commensurate to its risk, and validating something that changes without notice is difficult to do honestly.
- Ask what monitoring output you receive, in what format, and how often. Then ask the harder follow-up: can your model risk function actually consume it? Drift and accuracy reporting that arrives as a PDF once a quarter is not an input to a framework.
- Assemble the Law 25 s.17 inputs before you need them. Sensitivity of the information, purposes of use, protection measures including contractual ones, and the legal framework of the destination jurisdiction. If personal information will be communicated outside Québec, that assessment is yours to perform and to document, and the written agreement is a precondition rather than a formality.
- Check the document reality, not the demo. Canadian submissions arrive as CSIO applications, CSIO eDocs, ACORD forms, broker-specific templates and carrier loss runs in a dozen layouts. Ask to see the vendor's output on your documents, including the ugly ones, and ask what happens on pages the system cannot read confidently. How a system behaves when it is uncertain says more about its governance posture than its headline accuracy figure.
- Ask what happens at exit. Data return and deletion format and timeline, whether extraction configuration and any assets trained on your data are portable, and how long audit records remain retrievable after termination. B-10 treats exit planning as part of the relationship, not an afterthought.
- Put incident notification thresholds and timelines in the contract. B-13 has been in force since 1 January 2024. Technology and cyber obligations do not pause because the tooling is AI, and a vendor's notification clause is one of the few parts of this picture that is fully negotiable at signing.
- Write down which of these the vendor could not answer. The list of unanswered questions is often more informative than the list of answered ones, and it is the part that should go into the file. Sector bodies such as the IBC publish useful context on where Canadian industry practice sits, but the record of what a specific supplier would and would not commit to is yours alone to build.
Nothing on that list requires E-23 to be in force. All of it is easier to do now, at evaluation, than in 2027 with a framework deadline behind it.
Frequently asked questions
Does OSFI E-23 apply to insurers?
Yes — from 1 May 2027, not today. The final version of Guideline E-23 was published on 11 September 2025 with an effective date of 1 May 2027, and its scope includes life insurance and fraternal companies and property and casualty companies alongside banks, foreign bank branches, and trust and loan companies. The version in force in the meantime is E-23 (2017), whose scope is deposit-taking institutions only. Federally regulated insurers are therefore not currently subject to E-23 and come into scope on 1 May 2027. Federally regulated pension plans appeared in the draft and were removed from the final.
Does Quebec Law 25 ban automated decisions?
No. Section 12.1 of the Act respecting the protection of personal information in the private sector (CQLR c. P-39.1), in force since 22 September 2023, does not prohibit automated decision-making. It applies only where a decision is based exclusively on automated processing, and where it applies it requires notification, and on request disclosure of the personal information used, the reasons and the principal factors and parameters, and the right to have that information corrected. The individual must also be given the opportunity to submit observations to a member of personnel who is in a position to review the decision. That is a right to be heard, not a right to have the decision re-made by a human, and Quebec has no GDPR Article 22-style prohibition.
Is Canadian data residency legally required for insurers?
No. There is no general legal requirement that Canadian insurers hold customer or policy data in Canada. Section 262(1) of the Insurance Companies Act requires the records described in s.261 to be kept at the head office or another place in Canada, but s.261 lists corporate records — incorporating documents, by-laws, minutes, returns to the Superintendent, corporate accounting records and per-customer amounts owing — rather than claims files, submissions or underwriting documents. OSFI's B-10 s.2.3.2.2 expressly contemplates records held outside Canada where OSFI has immediate, direct, complete and ongoing access. Federally, the OPC's cross-border guidelines confirm that PIPEDA does not prohibit transfers to another jurisdiction for processing, subject to accountability, comparable contractual protection and transparency. Québec adds a privacy impact assessment requirement under s.17 before information is communicated outside the province. Residency remains a legitimate commercial preference; it is not a statutory rule.
Does OSFI have an AI guideline?
No standalone one, in force or in draft. OSFI's expectations for AI sit inside Guideline E-23 on model risk management, whose definition of a model expressly includes AI and machine learning methods. The AI-specific documents OSFI has published are reports rather than guidance: the OSFI–FCAC risk report of 24 September 2024, which introduced the EDGE principles — Explainability, Data, Governance, Ethics — and the FIFAI II report of 23 March 2026, which set out the AGILE framework and carries an explicit disclaimer that it does not necessarily reflect the views of the sponsoring authorities. Neither should be cited as a requirement.
Getting the facts right is the governance work
The Canadian regulatory picture for insurance AI is more permissive and more specific than most content about it suggests. E-23 arrives for insurers on 1 May 2027 and not before. Law 25 constrains decisions made exclusively by machine and grants a hearing rather than a re-decision. Cross-border processing is lawful under PIPEDA, subject to accountability, transparency and comparable protection, and subject to a documented assessment in Québec.
What follows from that is not less governance work but better-aimed governance work. The institution owns validation. The vendor owns the artefacts that feed it. Human review earns its place because it keeps decisions outside a specific statutory trigger and produces a specific evidentiary record — not because a regulator ordered it.
If you are running a vendor evaluation this year, run the checklist above, and put the questions your suppliers could not answer in the file alongside the ones they could. For more Canadian market context, see our overviews of the Canadian insurtech landscape and CSIO documents, eDocs and data standards, or read how we think about human review in AI workflows.