Two Guidelines, One Date.
One Inventory Can Serve Both.

Québec’s Autorité des marchés financiers (AMF) guideline on the use of artificial intelligence takes effect on May 1, 2027, the same day as OSFI Guideline E-23. An institution that answers to both regulators is preparing for both at once. Most of the AMF’s governance, rating, and lifecycle expectations line up with an E-23 principle. Its client-treatment expectations do not, and E-23 work alone will not cover them.

In force May 1, 2027 Insurers, cooperatives, trust and deposit institutions authorized in Québec Any use of an AI system

If you operate in Québec, E-23 is half of your deadline

The AMF guideline applies to authorized insurers, financial services cooperatives, authorized trust companies, and other authorized deposit institutions. It supplements the AMF’s Model Risk Management Guideline and covers any use of an AI system, whether or not client records are involved. A federally chartered insurer still has to be authorized by the AMF to do business in Québec, so it can answer to OSFI and to the AMF at once.

The inventory is shared ground

Both guidelines expect a centralized inventory of the systems that carry non-negligible risk, each with a risk rating. The AMF says its inventory can be the model inventory.

The AMF rates the system, not only the model

An AI system gets its own rating, informed by the rating of each model inside it. Where the two conflict, the limits set for the system take precedence over those set for the model.

Client treatment has no E-23 counterpart

Section 8 covers discriminatory factors, bias, telling clients they are dealing with AI, and explaining AI decisions. E-23 is a model risk guideline and has no matching principle.

What the AMF Expects, and Where PulseAI Helps

Sections 4 to 8 of the guideline, 17 rows. For each one: what the AMF expects, the nearest OSFI E-23 principle, how PulseAI supports the work, and what remains your institution’s.

Read the labels before the prose. PulseAI supports 1 of these rows outright, holds part of the record for 13, and does nothing for 3. PulseAI has no AMF framework pack: this page maps the records PulseAI already keeps for E-23 onto the AMF’s sections.

Section 4 Institution-wide governance

4.1

Board of directors

E-23 principle 1.1

What the AMF expects

The board sees that senior management promotes responsible AI use, stays informed of trends, risks, and material changes from AI systems, and has the collective competency to understand those risks.

How PulseAI supports it

Partly supported

The compliance export gives a point-in-time picture of the AI inventory, its risk ratings, and the open governance gaps, in a form that can go into a board package.

What remains yours

Board competency, the reporting cadence, and what the board decides to do with the picture.

4.2

Senior management and AI system owners

E-23 principle 1.1

What the AMF expects

One member of senior management is accountable for all AI systems. Each system has an owner through its whole lifecycle, and the people who set, apply, and use AI policies know the systems, their risks, and their limits.

How PulseAI supports it

Partly supported

Every model record names its owner, reviewer, and approver, and carries the limitations users should know.

What remains yours

Designating the accountable member of senior management, and the knowledge and training of staff. PulseAI has no dedicated field for that institution-wide designation.

Section 5 Institution-wide risk management

5

A holistic view of AI risk

E-23 principle 1.2

What the AMF expects

Identify, assess, control, mitigate, and track each AI system while keeping an overall view of inherent and residual exposure, an up-to-date list of significant AI risks, and a periodic comprehensive assessment for key stakeholders.

How PulseAI supports it

Partly supported

The AI Impact Assessment is an assessment workflow with an approval step, and the registry and compliance export roll your models up into one view of ratings and gaps.

What remains yours

The model risk management framework itself, your list of significant AI risks, and the quantification of exposure.

5.1

AI system use

E-23 principle 1.3

What the AMF expects

Use AI systems suited to your needs that give significant support and reliable outputs, and modify or decommission the ones that are no longer fit for purpose.

How PulseAI supports it

Partly supported

Each model is linked to the use cases it serves and carries a lifecycle stage. An active model linked to no use case is raised as a governance gap.

What remains yours

The fitness-for-purpose judgment and the decision to modify or retire a system.

Section 6 Risk-based classification

6.1

AI system inventory

E-23 principle 2.1

What the AMF expects

Keep a regular record of all models and AI systems, and list those of non-negligible risk in a centralized inventory that gives a comprehensive picture, including the models behind each system.

How PulseAI supports it

PulseAI supports

One registry holds a governance record per model, vendor and internal alike, linked to the tools and use cases it serves. Google Workspace discovery surfaces AI applications employees have connected, so the record starts from what is in use.

What remains yours

Deciding which systems carry non-negligible risk, and how an AI system made of several models is grouped in your inventory.

6.2

Risk rating

E-23 principle 2.2

What the AMF expects

Assign a risk rating to each AI system and update it regularly. A provisional, conservative rating is acceptable until the information is available. Factors include the model risk rating of each underlying model.

How PulseAI supports it

Partly supported

Every rating records who assessed it, when, and the rationale. A rating with no assessment on file is labeled as not assessed, and a rating whose tier has changed since the assessment stops reading as assessed.

What remains yours

The rating criteria and the assessment. PulseAI records one rating per model record and does not derive a separate system-level rating from it, and it has no dedicated provisional flag.

6.3

Aligning expectations with risks

E-23 principle 2.3

What the AMF expects

The rating adjusts validation activity and frequency, documentation, the level of approval and exceptions, monitoring, and the schedule for reviewing the rating itself.

How PulseAI supports it

Partly supported

Next-review dates and completeness checks show where the evidence behind a model does not yet match its rating.

What remains yours

Calibrating intensity to rating. PulseAI shows the mismatch; it does not enforce a schedule by tier.

Section 7 The AI system lifecycle

7.1

Rationale

E-23 principle 1.3

What the AMF expects

Document the organizational need and the rationale when an AI system is selected, and reassess both at revalidation, weighing explainability, the need for controls, and the potential for biased or infringing outcomes.

How PulseAI supports it

Partly supported

The use cases a model serves and its usage context are on the record, and an approved impact assessment is kept as evidence.

What remains yours

The rationale itself, and the decision at revalidation that AI is still the best solution.

7.1

Data used for learning

E-23 principle 3.2

What the AMF expects

Quality checks on all data an AI system learns from, in training and in use: primary and secondary, private and public, real and synthetic, structured and unstructured.

How PulseAI supports it

Partly supported

Each model record lists its data sources and documented limitations.

What remains yours

The data quality checks. They run in your data estate, and PulseAI does not inspect training data.

7.1

Procurement or development

E-23 principle 3.3

What the AMF expects

Include the risk rating and your explainability requirements in the selection criteria, and consider systems designed to meet explainability and cybersecurity targets.

How PulseAI supports it

Partly supported

Records state the developer and whether the model is internal or vendor. A vendor API model cannot be activated until a data processing agreement is confirmed on its record.

What remains yours

Selection criteria, explainability requirements, and the procurement decision.

7.1

Validation

E-23 principle 3.4

What the AMF expects

Assess output explainability, cybersecurity, the timeliness of methods and tools, and third-party components, with validation triggers that control risks such as discrimination, bias, dynamic adjustment, and hallucination.

How PulseAI supports it

Partly supported

Every record names its reviewer and carries last-review and next-review dates, plus the dependencies a review should cover.

What remains yours

Conducting the validation and defining its triggers. PulseAI does not test models.

7.1

Approval

E-23 principle 3.5

What the AMF expects

Apply mitigating measures and restrictions, such as human review of outputs, when a higher-risk system is used before the information needed to assess it is complete.

How PulseAI supports it

Partly supported

The approver is named on the record, limitations and exceptions have their own entry, and an approved impact assessment is sealed into write-once storage.

What remains yours

The approval decision and the restrictions you attach to it.

7.1

Deployment

E-23 principle 3.5

What the AMF expects

Assess the relevant risks before deployment, including cybersecurity and infrastructure vulnerabilities, and the ability to explain outputs to stakeholders.

How PulseAI supports it

Partly supported

The production deployment date is tracked on the record.

What remains yours

Pre-deployment risk assessment, testing, and change control.

7.1

Monitoring

E-23 principle 3.6

What the AMF expects

Monitor performance and use against your objectives, including compliance and reputational risk, with standards by risk level and guideposts for autonomous or dynamically adjusted systems.

How PulseAI supports it

Partly supported

Monitoring status lives on every model record, and health findings raise governance gaps such as an active vendor model without a confirmed data processing agreement.

What remains yours

Monitoring execution, metrics, and thresholds. PulseAI does not monitor model performance or drift.

Section 8 Fair treatment of clients

8.1

Code of ethics

No E-23 counterpart

What the AMF expects

Your code of ethics upholds high standards of ethics and integrity that are relevant to how you use AI systems.

How PulseAI supports it

Not in PulseAI

PulseAI does not author or assess a code of ethics.

What remains yours

The code, and keeping it relevant to your AI use.

8.2

Discrimination and bias

No E-23 counterpart

What the AMF expects

For each AI system, list the factors and surrogate variables that may not be used, monitor for their use, correct promptly, report to decision-making bodies, and document the groups for which bias is corrected and monitored.

How PulseAI supports it

Not in PulseAI

PulseAI does not test for bias or discriminatory factors. A model record can hold the limitation as text; it has no structured list of prohibited factors.

What remains yours

The lists, the monitoring, the corrective actions, and the reporting.

8.3

Communication to the client

No E-23 counterpart

What the AMF expects

Tell clients when they are communicating with an AI system and that they can ask for a person, label content generated with AI, and explain AI decisions in plain language.

How PulseAI supports it

Not in PulseAI

PulseAI is not in your client channels and does not deliver these notices or explanations.

What remains yours

Disclosure, access to a person, content labeling, and decision explanations.

The AI-Specific Inventory Information, Item by Item

Annex 2 gives eight examples of information specific to AI systems that an inventory could hold. They are examples, not a mandatory field list. PulseAI’s model record was built from OSFI E-23 Appendix 1, so most of them have no dedicated field today.

The AI system’s risk rating

PulseAI supports

A dedicated field, with who assessed it, when, and why.

Origin and description of secondary information used to train the models or for continual learning

Partly supported

The data sources list holds the names. It does not separate training data from continual-learning data.

Use of dynamic adjustment, and limits on its frequency, models, and factors

Not in PulseAI

No dedicated field. Can be written into the limitations entry.

Involvement of an individual in interpreting outcomes (human-in-the-loop)

Not in PulseAI

No dedicated field. Can be written into the usage context or limitations entry.

Upstream or downstream isolation for confidentiality and cybersecurity

Not in PulseAI

No dedicated field.

Built-in redundancy if the AI system is impaired

Not in PulseAI

No dedicated field.

Technological controls capable of generating automated alerts

Not in PulseAI

No dedicated field.

Validation process triggers

Not in PulseAI

No dedicated field. The next-review date records when, not what triggers it.

For the seventeen fields E-23 does make mandatory, see Appendix 1, field by field.

What this page is not. It is a reading of the AMF’s English text beside the records PulseAI keeps, not legal advice and not a statement that using PulseAI satisfies the guideline. Whether the guideline applies to your institution, and how, is a question for your counsel and the AMF. PulseAI is available in English only.

Guideline text: AMF Guideline for the Use of Artificial Intelligence (March 2026) ↗ · Section numbers follow the AMF’s English edition

Prepare for Both With One Inventory

PulseAI is inviting a small number of Canadian financial-services organizations to become design partners. If you answer to both OSFI and the AMF, we would like to hear where this mapping falls short for you.

No commitment required · partnerships@pulseai.now