OSFI's deadline for full adherence to Guideline E-21 passed on September 1, 2026.¹ That milestone did not close the file. OSFI has said it will spend its 2026-27 fiscal year on supervisory activities assessing whether institutions are ready for the expectations that took effect on that date.² Scenario testing for all critical operations is due September 1, 2027.¹ Guideline E-23 on model risk management takes effect May 1, 2027.³
OSFI E-21 compliance: Key takeaways
The full-adherence deadline for OSFI E-21 has passed, the supervisory assessment window is open, and OSFI's Annual Risk Outlook covers April 2026 to April 2027.²
Section 4.7, the data risk management clause, asks for six programme components at once, and it is the dimension where most institutions built toward a date rather than toward an operating model.⁴
Point-in-time evidence decays on its own. Lineage documented in March describes a system that no longer exists after a pipeline refactor, and the ownership record breaks at the next reorganization.
The useful question now is not whether the institution complied in September. It is whether the institution can answer a supervisor's question about a reported number today, without standing up a project to do it.
This article covers Section 4.7 specifically rather than end-to-end E-21 coverage. Section 4.7 is the guideline's largest and most operationally demanding dimension, and it is the one where data and governance teams carry the load.
OSFI E-21 requirements and where the data risk clause sits
Guideline E-21, Operational Risk Management and Resilience, sets OSFI's expectations for how federally regulated financial institutions prepare for, withstand, and recover from operational disruption. OSFI published the final guideline on August 22, 2024. It enhanced existing operational risk expectations and established new ones covering operational resilience, business continuity, crisis management, change management, and data risk management.⁵
Most coverage of E-21 concentrates on critical operations mapping, impact tolerances, and scenario testing. That emphasis is fair, because those areas make up the bulk of the guideline. The clause that lands on data and governance teams is Section 4.7, and it has received far less attention than the work it actually generates.
Date | Expectation |
August 22, 2024 | The guideline was published, and sections 1 and 2 took effect immediately.⁵ |
September 1, 2025 | Full adherence to section 4 was expected.¹ |
September 1, 2026 | Full adherence to the guideline was expected.¹ |
April 2026 to April 2027 | OSFI conducts supervisory activities assessing institutional readiness.² |
September 1, 2027 | Scenario testing must be completed for all critical operations.¹ |
May 1, 2027 | Guideline E-23 on model risk management takes effect.³ |
OSFI E-21 Section 4.7 requirements for data risk management
Section 4.7 sets out six programme components in a single clause. Read as a requirements list, it is easy to nod along to. Read as questions a supervisor might ask, it becomes harder.⁴
Section 4.7 requires a data risk management programme with governance, roles, and responsibilities. A supervisor can reasonably ask who owns a given critical data element. The answer needs to name a person and a date, not a team.
It requires architecture and IT infrastructure to collect, aggregate, trace lineage, and report critical data across the enterprise. The practical test is whether the institution can trace a reported number back to its authoritative source right now, including the hops that run through spreadsheets and applications with no connector.
It requires classification and protection processes. Each element needs a current sensitivity classification, and that classification needs to survive the last schema change.
It requires methodologies for integrity, adaptability, confidentiality, and availability across the data lifecycle. For any given element, the institution should be able to state which rule governs its quality and when that rule last failed.
It requires escalation for data incidents. When an element last fell out of tolerance, someone should be able to say who was informed and what happened next.
It requires training for everyone accountable. The person who owns an element should be able to explain why it is critical.
That is six programme components inside one clause. Most institutions operationalize it the way the wider industry does, by running a Critical Data Element programme that narrows scope to the elements carrying real regulatory and operational consequence. That instinct is the right one. Done by hand, the work is relentless.
Why OSFI E-21 compliance does not end at the deadline
Plenty of institutions staffed their way to September 1. Almost none can staff that line indefinitely, and the obligation runs indefinitely.
The difficulty is that Section 4.7 evidence decays without anyone touching it. Every element needs a definition, an owner, a classification, a policy linkage, quality rules, and traceable lineage. Then the source changes, or the owner leaves, or a pipeline gets refactored. Scope that across thousands of tables and tens of thousands of columns and the work recurs whether or not anyone is resourcing it.
This is not a theoretical risk, and it is not unique to Canada. BCBS 239 has been in force for more than a decade and functions as a natural experiment in what happens to data governance programmes built for attestation. When the Basel Committee assessed the 31 global systemically important banks, only two were fully compliant with all of the principles, and supervisors specifically noted that several still lacked a common taxonomy and complete data lineage.⁶ In a 2026 newsletter, the Committee observed that legacy systems, distributed data estates, and the dynamic nature of lineage all complicate end-to-end traceability, and that identifying and maintaining it is resource-intensive.⁷
Supervisory direction elsewhere points the same way. The European Central Bank's guide on risk data aggregation and reporting sets a minimum expectation of complete, up-to-date lineage at the data-attribute level, tracing from data capture through extraction, transformation, and loading. It also expects manual workarounds to be documented, controlled, and migrated over time into an audit-trailed environment.⁸ Manual effort is therefore not disqualifying. Undocumented manual effort is.
E-21 itself expects the programme to operate as a live one. Decisions and assessments must be adequately documented, significant issues must be reported and escalated to senior management and the board, and internal audit must provide independent assurance that controls, policies, and systems are designed and operating effectively.⁹ Those obligations recur for as long as the guideline is in force.
Hitting a deadline is a project. Staying compliant is an operating model. The institutions that will hold the line through the next reorganization and the next platform migration are the ones that stopped doing the cataloguing and started governing the process. That means a small team supervising a system which documents continuously, reviewing exceptions and setting the criteria the automation applies, rather than a standing army documenting elements one at a time.
OSFI E-21 audit evidence: What supervisors expect to see
Set the platform question aside and there are five artifacts a supervisor or internal auditor can reasonably ask to see.
A Critical Data Element register must reflect the estate as it stands today. Each element should carry its definition, owner, sensitivity classification, policy linkage, quality rules, and lineage in one place, with a defined path from candidate to certified. The test is not whether the register exists. It is whether the register is current.
Lineage must reach all the way to source. Critical data does not only move through SQL. It moves through Python transformations, XML feeds, JSON APIs, and spreadsheets, which is exactly where exposure hides and where auditors find gaps. Automated scanning stops at the connected perimeter, so the trace has to continue past it.
Known gaps need an accountable record. This is the point most programmes get backwards. A documented gap states what is missing, who owns resolving it, when it was raised, and what the resolution path is, and that is a defensible position in a review. An undocumented break in the chain is not.
Certified lineage needs point-in-time snapshots. Build the lineage, certify it, snapshot it, then compare current state against that record when the next attestation falls due. That is one effort maintained continuously rather than rebuilt from zero every year.
The decision and escalation trail must be documented. That includes the independent internal audit assurance E-21 expects, which remains a human judgment.⁹
Alation builds toward these artifacts directly. Critical Data Manager maintains the register, connecting each element's policies, glossary terms, and lineage into a single audit-ready view of its health and ownership. Against the manual path, Alation measures a 70% reduction in CDE governance costs and an average saving of seven days per element onboarded.¹⁰ Critical Lineage, generally available since August 13, 2026, blends automated, manual, and placeholder lineage into one version-controlled graph so that spreadsheets and unconnected applications sit inside the trace rather than beside it.¹⁰ Institutions that want the regulatory intellectual property packaged alongside the tooling can use the E-21 Compliance Accelerator built with PwC Canada, which loads E-21-aligned policies and a CDE definition library on day one.
OSFI E-21 scenario testing and Guideline E-23: What comes next
The architecture an institution chose for September is the architecture it carries into 2027.
Scenario testing for all critical operations is due September 1, 2027.¹ Guideline E-23 on model risk management takes effect May 1, 2027, covering all models that carry risk at federally regulated institutions, with added guidance for artificial intelligence and machine learning models specifically.³ Both obligations lean on the same foundation, which is knowing what the critical data is, who owns it, and where it came from.
There is a broader case here too. Data that is known, owned, trusted, and traceable is the same foundation an enterprise AI programme needs. As agents begin consuming lineage and classification evidence to make decisions, that evidence becomes a governed input to AI rather than an audit artifact alone. The Section 4.7 work does not have to be money spent twice.
Frequently asked questions about OSFI E-21
Has the OSFI E-21 deadline passed? Yes. OSFI expected full adherence to Guideline E-21 by September 1, 2026. Full adherence to section 4 was expected a year earlier, by September 1, 2025, and scenario testing for all critical operations is due by September 1, 2027.¹ OSFI has said it will use its 2026-27 fiscal year for supervisory activities assessing institutional readiness for the expectations that took effect in September 2026.²
What does OSFI E-21 Section 4.7 require for data risk management? Section 4.7 sets out six programme components in one clause. It requires a data risk management programme with governance, roles, and responsibilities; architecture and IT infrastructure to collect, aggregate, trace lineage, and report critical data across the enterprise; classification and protection processes; methodologies for integrity, adaptability, confidentiality, and availability across the lifecycle; escalation for data incidents; and training for everyone accountable.⁴
What is a Critical Data Element under OSFI E-21? E-21 does not prescribe a list of Critical Data Elements. It requires that critical data be collected, aggregated, traced, and reported across the enterprise.⁴ Most institutions operationalize that requirement by identifying the subset of data elements carrying real regulatory and operational consequence, typically those feeding regulatory reporting, risk decisions, and customer outcomes, and then governing those elements to a defined standard.
How is OSFI E-21 different from BCBS 239? BCBS 239 is a Basel Committee standard focused on risk data aggregation and risk reporting, applied primarily to globally systemically important banks and adopted progressively more widely. E-21 is an OSFI guideline for Canadian federally regulated institutions, and its scope is broader, covering operational resilience, business continuity, crisis management, change management, and data risk management.⁵ The Section 4.7 data expectations overlap substantially with BCBS 239's lineage and quality requirements, so institutions subject to both should build a single evidence base rather than two.
Will an external auditor accept AI-generated lineage as OSFI E-21 evidence? An auditor can accept it when the transformation logic is documented and a steward signs off. What the auditor reviews is not a black-box output. The logic at each hop sits in the catalog alongside the policy linkage, classification, and ownership record, with the audit trail attached. Independent assurance from internal audit remains an E-21 expectation and remains a human judgment.⁹ Automation changes how the evidence gets assembled, not who is accountable for it.
Should institutions plan for Guideline E-23 alongside E-21? Planning for both together is worth considering now. E-23 takes effect May 1, 2027 and covers all models carrying risk to the institution, with added clarity for artificial intelligence and machine learning model risk.³ The critical data foundation that E-21 Section 4.7 requires is the same foundation E-23 model documentation draws on.
Does OSFI E-21 apply to credit unions? Credit unions are provincially regulated and fall outside OSFI's mandate, so no single national deadline applies to them. Provincial regulators including Ontario's FSRA, BCFSA in British Columbia, and Quebec's AMF have been developing comparable operational resilience expectations on broadly similar timelines. Institutions should check their provincial regulator's current guidance.
Get help with OSFI E-21 data risk management
Whether your institution is still closing its Section 4.7 gap or has closed it and now owns the recurring obligation behind it, we should talk. Start a conversation.
Sources and notes
Every external claim on this page is independently verifiable. The public sources are listed here.
E-21 phased implementation: full adherence to section 4 expected by 1 September 2025; full adherence to the guideline expected by 1 September 2026; scenario testing completed for all critical operations by 1 September 2027. Source: OSFI, Operational Risk Management and Resilience Letter, 22 August 2024. ↗ https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/operational-risk-management-resilience-letter
OSFI plans supervisory activities in fiscal 2026-27 to determine institutions' readiness to meet the operational resilience expectations effective 1 September 2026. The Annual Risk Outlook covers 1 April 2026 to 1 April 2027. Source: OSFI, Annual Risk Outlook, Fiscal Year 2026-2027, 14 April 2026. ↗ https://www.osfi-bsif.gc.ca/en/about-osfi/reports-publications/osfis-annual-risk-outlook-fiscal-year-2026-2027
Guideline E-23, Model Risk Management, takes effect for all federally regulated financial institutions on 1 May 2027. Its scope covers all models carrying risk to the institution, with added clarity for artificial intelligence and machine learning model risk management. Source: OSFI, Guideline E-23, Model Risk Management (2027) Letter, 11 September 2025. ↗ https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027-letter
Data risk management programme expectations, including data governance with clear roles and responsibilities; data architecture and IT infrastructure supporting collection, aggregation, lineage tracing and reporting of critical data across the enterprise; classification and protection processes; lifecycle integrity methodologies; incident escalation; and training. Source: OSFI, Guideline E-21, Section 4.7, 22 August 2024. ↗ https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/operational-risk-management-resilience-guideline
Guideline E-21 was published 22 August 2024. It enhances operational risk management expectations and sets new expectations for operational resilience, business continuity risk management, crisis management, change management, and data risk management. Sections 1 and 2 were effective immediately. Source: OSFI, Backgrounder: Guideline E-21, Operational Risk and Resilience, 22 August 2024. ↗ https://www.osfi-bsif.gc.ca/en/news/backgrounder-guideline-e-21-operational-risk-resilience
Of 31 global systemically important banks assessed, only two were fully compliant with all BCBS 239 principles. Supervisors noted several banks still lacked a common taxonomy and complete data lineage. Source: Basel Committee on Banking Supervision, Progress in adopting the Principles for effective risk data aggregation and risk reporting, November 2023, pages 1, 5 and 14. ↗ https://www.bis.org/bcbs/publ/d559.pdf
Legacy systems, distributed data estates and the dynamic nature of data lineage complicate end-to-end traceability. Identifying and maintaining lineage is resource-intensive. Source: Basel Committee on Banking Supervision, Implementation of the Principles for effective risk data aggregation and risk reporting, Newsletter, 6 January 2026. The Committee states that this newsletter is informational and does not constitute new supervisory guidance. ↗ https://www.bis.org/publ/bcbs_nl36.htm
Minimum supervisory expectation of complete and up-to-date data lineage at data-attribute level, from data capture through extraction, transformation and loading. Manual workarounds are expected to be documented, controlled, and migrated over time. Source: European Central Bank, Guide on effective risk data aggregation and risk reporting, May 2024, Sections 3.4(3) and 3.5(5). ↗ https://www.bankingsupervision.europa.eu/ecb/pub/pdf/ssm.supervisory_guides240503_riskreporting.en.pdf
Documentation of decisions and assessments; reporting and escalation of significant issues to senior management and the board; independent assurance from internal audit that controls, policies, procedures and systems are designed and operating effectively. Source: OSFI, Guideline E-21, Sections 1.3, 1.4 and 2.4.2, 22 August 2024. ↗ https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/operational-risk-management-resilience-guideline
A 70% reduction in CDE governance costs and 7 days average time savings per CDE onboarded. A single registry connects policies, glossary terms and lineage into an audit-ready view of each CDE's health and ownership. Critical Lineage became generally available on 13 August 2026 for Alation Cloud Service customers as part of Critical Data Manager. These figures are Alation's own measurement. Source: Alation. ↗ https://www.alation.com/product/alation-cde-manager/
- AI
- Customer Stories
- Data Governance
- Data Quality
- Digital Transformation
Keep reading
More from the data desk



