AMF · Guideline for the Use of Artificial Intelligence
Québec’s Autorité des marchés financiers (AMF) guideline on the use of artificial intelligence takes effect on May 1, 2027, the same day as OSFI Guideline E-23. An institution that answers to both regulators is preparing for both at once. Most of the AMF’s governance, rating, and lifecycle expectations line up with an E-23 principle. Its client-treatment expectations do not, and E-23 work alone will not cover them.
Who this is for
The AMF guideline applies to authorized insurers, financial services cooperatives, authorized trust companies, and other authorized deposit institutions. It supplements the AMF’s Model Risk Management Guideline and covers any use of an AI system, whether or not client records are involved. A federally chartered insurer still has to be authorized by the AMF to do business in Québec, so it can answer to OSFI and to the AMF at once.
01
Both guidelines expect a centralized inventory of the systems that carry non-negligible risk, each with a risk rating. The AMF says its inventory can be the model inventory.
02
An AI system gets its own rating, informed by the rating of each model inside it. Where the two conflict, the limits set for the system take precedence over those set for the model.
03
Section 8 covers discriminatory factors, bias, telling clients they are dealing with AI, and explaining AI decisions. E-23 is a model risk guideline and has no matching principle.
The crosswalk
Sections 4 to 8 of the guideline, 17 rows. For each one: what the AMF expects, the nearest OSFI E-23 principle, how PulseAI supports the work, and what remains your institution’s.
Read the labels before the prose. PulseAI supports 1 of these rows outright, holds part of the record for 13, and does nothing for 3. PulseAI has no AMF framework pack: this page maps the records PulseAI already keeps for E-23 onto the AMF’s sections.
Section
What the AMF expects
How PulseAI supports it
What remains yours
What the AMF expects
The board sees that senior management promotes responsible AI use, stays informed of trends, risks, and material changes from AI systems, and has the collective competency to understand those risks.
How PulseAI supports it
Partly supported
The compliance export gives a point-in-time picture of the AI inventory, its risk ratings, and the open governance gaps, in a form that can go into a board package.
What remains yours
Board competency, the reporting cadence, and what the board decides to do with the picture.
What the AMF expects
One member of senior management is accountable for all AI systems. Each system has an owner through its whole lifecycle, and the people who set, apply, and use AI policies know the systems, their risks, and their limits.
How PulseAI supports it
Partly supported
Every model record names its owner, reviewer, and approver, and carries the limitations users should know.
What remains yours
Designating the accountable member of senior management, and the knowledge and training of staff. PulseAI has no dedicated field for that institution-wide designation.
Section
What the AMF expects
How PulseAI supports it
What remains yours
What the AMF expects
Identify, assess, control, mitigate, and track each AI system while keeping an overall view of inherent and residual exposure, an up-to-date list of significant AI risks, and a periodic comprehensive assessment for key stakeholders.
How PulseAI supports it
Partly supported
The AI Impact Assessment is an assessment workflow with an approval step, and the registry and compliance export roll your models up into one view of ratings and gaps.
What remains yours
The model risk management framework itself, your list of significant AI risks, and the quantification of exposure.
What the AMF expects
Use AI systems suited to your needs that give significant support and reliable outputs, and modify or decommission the ones that are no longer fit for purpose.
How PulseAI supports it
Partly supported
Each model is linked to the use cases it serves and carries a lifecycle stage. An active model linked to no use case is raised as a governance gap.
What remains yours
The fitness-for-purpose judgment and the decision to modify or retire a system.
Section
What the AMF expects
How PulseAI supports it
What remains yours
What the AMF expects
Keep a regular record of all models and AI systems, and list those of non-negligible risk in a centralized inventory that gives a comprehensive picture, including the models behind each system.
How PulseAI supports it
PulseAI supports
One registry holds a governance record per model, vendor and internal alike, linked to the tools and use cases it serves. Google Workspace discovery surfaces AI applications employees have connected, so the record starts from what is in use.
What remains yours
Deciding which systems carry non-negligible risk, and how an AI system made of several models is grouped in your inventory.
What the AMF expects
Assign a risk rating to each AI system and update it regularly. A provisional, conservative rating is acceptable until the information is available. Factors include the model risk rating of each underlying model.
How PulseAI supports it
Partly supported
Every rating records who assessed it, when, and the rationale. A rating with no assessment on file is labeled as not assessed, and a rating whose tier has changed since the assessment stops reading as assessed.
What remains yours
The rating criteria and the assessment. PulseAI records one rating per model record and does not derive a separate system-level rating from it, and it has no dedicated provisional flag.
What the AMF expects
The rating adjusts validation activity and frequency, documentation, the level of approval and exceptions, monitoring, and the schedule for reviewing the rating itself.
How PulseAI supports it
Partly supported
Next-review dates and completeness checks show where the evidence behind a model does not yet match its rating.
What remains yours
Calibrating intensity to rating. PulseAI shows the mismatch; it does not enforce a schedule by tier.
Section
What the AMF expects
How PulseAI supports it
What remains yours
What the AMF expects
Document the organizational need and the rationale when an AI system is selected, and reassess both at revalidation, weighing explainability, the need for controls, and the potential for biased or infringing outcomes.
How PulseAI supports it
Partly supported
The use cases a model serves and its usage context are on the record, and an approved impact assessment is kept as evidence.
What remains yours
The rationale itself, and the decision at revalidation that AI is still the best solution.
What the AMF expects
Quality checks on all data an AI system learns from, in training and in use: primary and secondary, private and public, real and synthetic, structured and unstructured.
How PulseAI supports it
Partly supported
Each model record lists its data sources and documented limitations.
What remains yours
The data quality checks. They run in your data estate, and PulseAI does not inspect training data.
What the AMF expects
Include the risk rating and your explainability requirements in the selection criteria, and consider systems designed to meet explainability and cybersecurity targets.
How PulseAI supports it
Partly supported
Records state the developer and whether the model is internal or vendor. A vendor API model cannot be activated until a data processing agreement is confirmed on its record.
What remains yours
Selection criteria, explainability requirements, and the procurement decision.
What the AMF expects
Assess output explainability, cybersecurity, the timeliness of methods and tools, and third-party components, with validation triggers that control risks such as discrimination, bias, dynamic adjustment, and hallucination.
How PulseAI supports it
Partly supported
Every record names its reviewer and carries last-review and next-review dates, plus the dependencies a review should cover.
What remains yours
Conducting the validation and defining its triggers. PulseAI does not test models.
What the AMF expects
Apply mitigating measures and restrictions, such as human review of outputs, when a higher-risk system is used before the information needed to assess it is complete.
How PulseAI supports it
Partly supported
The approver is named on the record, limitations and exceptions have their own entry, and an approved impact assessment is sealed into write-once storage.
What remains yours
The approval decision and the restrictions you attach to it.
What the AMF expects
Assess the relevant risks before deployment, including cybersecurity and infrastructure vulnerabilities, and the ability to explain outputs to stakeholders.
How PulseAI supports it
Partly supported
The production deployment date is tracked on the record.
What remains yours
Pre-deployment risk assessment, testing, and change control.
What the AMF expects
Monitor performance and use against your objectives, including compliance and reputational risk, with standards by risk level and guideposts for autonomous or dynamically adjusted systems.
How PulseAI supports it
Partly supported
Monitoring status lives on every model record, and health findings raise governance gaps such as an active vendor model without a confirmed data processing agreement.
What remains yours
Monitoring execution, metrics, and thresholds. PulseAI does not monitor model performance or drift.
Section
What the AMF expects
How PulseAI supports it
What remains yours
8.1
Code of ethics
No E-23 counterpart
What the AMF expects
Your code of ethics upholds high standards of ethics and integrity that are relevant to how you use AI systems.
How PulseAI supports it
Not in PulseAI
PulseAI does not author or assess a code of ethics.
What remains yours
The code, and keeping it relevant to your AI use.
8.2
Discrimination and bias
No E-23 counterpart
What the AMF expects
For each AI system, list the factors and surrogate variables that may not be used, monitor for their use, correct promptly, report to decision-making bodies, and document the groups for which bias is corrected and monitored.
How PulseAI supports it
Not in PulseAI
PulseAI does not test for bias or discriminatory factors. A model record can hold the limitation as text; it has no structured list of prohibited factors.
What remains yours
The lists, the monitoring, the corrective actions, and the reporting.
8.3
Communication to the client
No E-23 counterpart
What the AMF expects
Tell clients when they are communicating with an AI system and that they can ask for a person, label content generated with AI, and explain AI decisions in plain language.
How PulseAI supports it
Not in PulseAI
PulseAI is not in your client channels and does not deliver these notices or explanations.
What remains yours
Disclosure, access to a person, content labeling, and decision explanations.
Annex 2
Annex 2 gives eight examples of information specific to AI systems that an inventory could hold. They are examples, not a mandatory field list. PulseAI’s model record was built from OSFI E-23 Appendix 1, so most of them have no dedicated field today.
The AI system’s risk rating
PulseAI supports
A dedicated field, with who assessed it, when, and why.
Origin and description of secondary information used to train the models or for continual learning
Partly supported
The data sources list holds the names. It does not separate training data from continual-learning data.
Use of dynamic adjustment, and limits on its frequency, models, and factors
Not in PulseAI
No dedicated field. Can be written into the limitations entry.
Involvement of an individual in interpreting outcomes (human-in-the-loop)
Not in PulseAI
No dedicated field. Can be written into the usage context or limitations entry.
Upstream or downstream isolation for confidentiality and cybersecurity
Not in PulseAI
No dedicated field.
Built-in redundancy if the AI system is impaired
Not in PulseAI
No dedicated field.
Technological controls capable of generating automated alerts
Not in PulseAI
No dedicated field.
Validation process triggers
Not in PulseAI
No dedicated field. The next-review date records when, not what triggers it.
For the seventeen fields E-23 does make mandatory, see Appendix 1, field by field.
What this page is not. It is a reading of the AMF’s English text beside the records PulseAI keeps, not legal advice and not a statement that using PulseAI satisfies the guideline. Whether the guideline applies to your institution, and how, is a question for your counsel and the AMF. PulseAI is available in English only.
Guideline text: AMF Guideline for the Use of Artificial Intelligence (March 2026) ↗ · Section numbers follow the AMF’s English edition
Get started
PulseAI is inviting a small number of Canadian financial-services organizations to become design partners. If you answer to both OSFI and the AMF, we would like to hear where this mapping falls short for you.
No commitment required · partnerships@pulseai.now