Anti-money laundering compliance in Canada has always meant juggling two different regulators with two different jobs. That gets more complicated the moment AI enters transaction monitoring, because a new player has entered the conversation: the Office of the Superintendent of Financial Institutions, and its model risk guideline, E-23. For banks, credit unions, and fintechs building or buying AI-driven AML monitoring tools, understanding where OSFI's expectations actually apply, and where they don't, is no longer optional homework. It's the difference between a smooth rollout and a compliance headache down the line.
This isn't a legal briefing. It's a practical look at what OSFI's guidance means for the AML systems you're running or considering, written for the people who have to actually implement them.
OSFI and FINTRAC Aren't the Same Regulator
The first source of confusion is figuring out which regulator owns which piece of the puzzle. FINTRAC is Canada's dedicated AML regulator. It enforces the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, and it's the body that receives suspicious transaction reports, sets reporting obligations, and issues penalties for anti-money laundering compliance failures directly.
OSFI plays a different role. It's the prudential regulator for federally regulated financial institutions (banks, trust companies, insurers, and pension plans), and its job is institutional safety and soundness, not AML enforcement in the FINTRAC sense. Where OSFI becomes directly relevant to AML is through its technology and model risk guidelines: Guideline B-13, covering technology and cyber risk management, and the newer OSFI Guideline E-23, covering model risk management, which explicitly includes AI and machine learning systems.
In practice, the two regulators' concerns overlap when your AML program uses AI. FINTRAC still cares about whether your suspicious activity detection actually works. OSFI cares about whether the AI model behind that detection is governed, explainable, and monitored properly. You need to satisfy both. They're not interchangeable.
What E-23 Actually Asks for When AI Is Involved
Guideline E-23 takes effect on May 1, 2027, and it applies a broad, technology-neutral definition of "Model," one that captures AI and machine learning systems used to process data and generate results. If your AML transaction-monitoring system uses machine learning to flag suspicious activity, score risk, or automate case triage, it falls inside that definition.
For AML monitoring specifically, this translates into a few concrete expectations:
- Model inventory and ownership: your institution needs a clear record of which AI models are involved in AML detection, who owns them, and how they were validated.
- Explainability: if a model flags a transaction as suspicious, someone needs to be able to explain why, not just point to a score.
- Ongoing monitoring for drift: AML patterns change as bad actors adapt, and a model trained on last year's typologies can quietly lose accuracy over time. E-23 expects institutions to actively watch for that kind of drift, not assume the model still works simply because it once did.
- Board-level accountability: model risk management, including AI-driven AML tools, needs to be visible at a governance level, not siloed inside a compliance team's tooling decisions.
- Third-party oversight: if your AML monitoring runs on a vendor's AI, you're still responsible for demonstrating that the vendor's model meets these same standards.
None of this is AML-specific guidance in the way FINTRAC's rules are. It's model governance that happens to apply to AML the moment AI gets involved.
Why This Matters for Toronto's Financial Sector
Toronto is home to Canada's largest concentration of federally regulated banks, along with a fast-growing base of fintechs and federally regulated credit unions operating in the Toronto financial institutions market. That means E-23 and B-13 apply here at real scale. A large share of the institutions directly in scope for these guidelines are based in or around the GTA.
It's worth being precise about what that does and doesn't mean, though. OSFI's own annual risk outlook has flagged the Greater Toronto Area for elevated stress, but that commentary centers on the residential mortgage and condo market, not AML. There's no indication that Toronto institutions face heightened AML scrutiny compared to the rest of the country. What is true is that because so many in-scope institutions operate here, the practical work of aligning AI-driven AML systems with E-23 is going to land on a large number of Toronto-based compliance and technology teams over the next couple of years.
What AI-Driven AML Monitoring Looks Like in Practice
Traditional, rules-based AML monitoring works off fixed thresholds: flag any transaction over a certain amount, or any pattern matching a known typology. It catches known patterns reliably but tends to generate a high volume of false positives, and it struggles with laundering techniques that don't match a predefined rule.
AI transaction monitoring adds pattern recognition that adapts over time. It can identify unusual behavior relative to a customer's own history, link related accounts or transactions that wouldn't trigger a simple rule, and prioritize alerts by actual risk rather than a flat threshold. Done well, this can help cut down the number of low-value alerts compliance teams have to manually clear, giving investigators more time for genuinely suspicious cases. How much improvement any institution sees depends heavily on data quality and implementation, so it's not something to promise a fixed percentage on.
The catch is that none of this works in isolation from the governance requirements above. A model that reduces false positives but can't explain its reasoning, or that drifts silently as laundering methods evolve, creates exactly the kind of risk E-23 is designed to catch. Financial crime detection AI has to be built with audit trails and explainability from the start, not bolted on afterward. That's a solvable problem with the right AI development services, but it does mean AML modernization and model governance need to be planned together, not one after the other.
Questions Worth Asking Before You Pick a Technology Partner
If you're evaluating a partner for AML monitoring for banks, or building the capability in-house, a few due-diligence questions go a long way toward avoiding E-23 headaches later:
- Can the model produce a documented, per-alert explanation of why a transaction was flagged?
- Is there a defined process for monitoring model drift and retraining on updated data?
- Does the vendor maintain documentation suitable for your institution's model inventory?
- How does the system integrate with your existing case-management and reporting workflows, rather than creating a parallel process?
- Who is accountable, internally, for the model's ongoing performance once it's live?
These aren't abstract questions. They're the difference between an AML upgrade that holds up under model risk review and one that creates new findings later. For institutions across the broader fintech AI solutions Canada landscape, this kind of groundwork is becoming a standard part of any AI-AML rollout, not an optional extra.
Where That Leaves Toronto Institutions
AML software Canada buyers are dealing with a genuinely new layer of expectations now that AI sits inside the compliance stack. The case for AI-driven monitoring (fewer wasted alerts, faster investigation, better pattern detection) is a real one, but OSFI now expects the AI behind that monitoring to be governed with the same rigor as any other financial model. For institutions in Toronto's dense federally regulated sector, that means treating AML modernization and E-23 readiness as one project, not two separate ones running on different timelines.
If your team is scoping an AI-driven AML monitoring upgrade and wants to build it with governance requirements in mind from day one, our team at Theta Technolabs can walk through what that looks like for your systems. Reach out at sales@thetatechnolabs.com to get started.
Frequently Asked Questions
What is OSFI Guideline E-23?
E-23 is OSFI's model risk management guideline. It covers how federally regulated financial institutions must govern models, including AI and machine learning systems, used across their operations. It takes effect May 1, 2027.
Does OSFI regulate AML directly, or is that FINTRAC's job?
FINTRAC is Canada's primary AML regulator and handles reporting obligations and enforcement. OSFI's role is prudential oversight, which becomes relevant to AML when AI or technology risk is involved, through guidelines like E-23 and B-13.
When do Toronto banks need to comply with E-23?
The guideline applies to all federally regulated financial institutions and comes into force on May 1, 2027, giving institutions time to bring existing AI models into compliance ahead of that date.
Can AI-based AML monitoring fully replace manual review?
No. AI can reduce false positives and help prioritize alerts, but E-23's expectations around explainability and human accountability mean manual review stays part of the process. It's not designed to replace it.



















