
By Jonathan Bruce, VP Global Partnerships, Alation, and Prithwiraj Thakur, Partner, Data and AI, PwC Canada
TL;DR
Alation and PwC Canada have built a joint accelerator for the data risk management requirements of OSFI Guideline E-21, the section where most Canadian financial institutions have the largest gap.
In one early engagement, a 300-page annual report was processed into a candidate list of roughly 100 Critical Data Elements, ranked against risk criteria and ready for steward review, compressing work the institution had scoped from months to days.
Against the manual path, Alation measures a 70% reduction in CDE governance costs and an average saving of seven days per CDE onboarded.¹
Early deployments at Canadian financial institutions have produced auditor-ready evidence packages ahead of the September 2026 deadline.
Scope limit, up front: this is not end-to-end E-21 coverage. It addresses the data risk management requirements in §4.7. That's deliberate, as it's the guideline's largest and most operationally demanding dimension.
That last point is the whole argument. Hitting the September 2026 deadline is a project. Staying compliant is an operating model. Most institutions are resourcing the first and hoping the second sorts itself out.
CDE governance is where data programs go to die
If you've ever run a Critical Data Element program, you know the drill.
Every element needs a business definition, an owner, a sensitivity classification, a policy linkage, quality rules, and traceable lineage. Then the source changes. Or the owner leaves. Or a pipeline gets refactored, and the lineage you documented in March describes a system that no longer exists. Scope that across an estate with thousands of tables and tens of thousands of columns, and that effort recurs, again and again.
E-21 makes that recursion an obligation; §4.7 asks for six things at once:
A data risk management program with governance, roles, and responsibilities
Architecture and infrastructure to collect, aggregate, trace lineage, and report critical data across the enterprise
Classification and protection processes
Methodologies for integrity, adaptability, confidentiality, and availability across the lifecycle
Escalation for data incidents
Training for everyone accountable
That’s six programme components in a single clause. Most institutions operationalize this the way the wider industry does: as a Critical Data Element project, narrowing scope to the elements that carry real regulatory and operational consequence. It's the right instinct. But done by hand, it's relentless.
And now the clock compresses it. E-21 set a phased timeline: full adherence to section 4 by September 1, 2025, full adherence to the guideline by September 1, 2026, and scenario testing for all critical operations by September 1, 2027.³
OSFI has said it will spend its 2026–27 fiscal year running supervisory activities to assess whether institutions are ready for the expectations taking effect this September.⁴ Readiness is being assessed now.
This deadline makes an already-brutal problem urgent, and plenty of institutions can staff their way to September 2026. However, almost none can staff that line indefinitely… and the obligation runs indefinitely.
What we actually built: About the E-21 Compliance Accelerator
The accelerator pairs PwC's packaged regulatory IP with agents running on both sides of the catalog. Here’s what loads on day one versus what you'd otherwise spend two hundred days building.
Loads on day one, from PwC Canada: PwC delivers E-21-aligned policies authored to OSFI's specific expectations; a library of Critical Data Element definitions spanning payments, insurance, lending, retail banking, and field-tested curation prompt templates; and expertise borne of decades spent advising on regulatory change in Canadian financial services. What's new is that it's packaged and runnable, loaded on day one instead of rebuilt engagement by engagement.
Runs continuously, from Alation: CDE Manager identifies, classifies, and tracks Critical Data Elements across the enterprise, connecting each element's policies, glossary terms, and lineage into a single audit-ready view of its health and ownership.¹ Curation automation generates business definitions, PII classifications, and sensitivity labels at scale. The Data Quality Agent applies compliance rules across thousands of columns and surfaces assets the moment they fall out of standard.
Reaches where catalogs historically couldn't: Critical data doesn't only move through SQL. It moves through Python transformations, XML feeds, JSON APIs, and spreadsheets — which is exactly where CDE exposure hides and where auditors find gaps. PwC's lineage agent parses those non-SQL transformations to produce column-level lineage with transformation logic documented at every hop, then writes that logic back into the Alation catalog automatically.
The word that matters is continuously. E-21 expects data risk management to operate as a live program: decisions and assessments adequately documented, significant issues reported and escalated to senior management and the board, and independent assurance from internal audit that controls, policies, and systems are designed and operating effectively.⁵ Those obligations recur for as long as the guideline is in force. As assets change, pipelines evolve, and ownership shifts, the system keeps pace… and evidence that once took months to assemble exports in minutes.
None of this is a bolt-on. On July 14, 2026, Alation launched the Alation Intelligence Operating System (AIOS), a unified system of data, context, and agents.⁶ AIOS is why PwC's agents can plug in at all: it's open, so third-party agents wire in through open standards alongside Alation's own; governed, so trust and audit trails travel with the data; and self-improving, so every steward review sharpens the next classification, lineage trace, and evidence package.⁶
Why this matters
The measurable change is cost and time: 70%, seven days, months to minutes.¹
The durable change is quieter. On the engagements running now, governance teams are shifting from doing the cataloging to governing the process. This is the difference between a standing army of analysts documenting elements one at a time and a small team supervising a system that documents them continuously: reviewing exceptions, adjudicating edge cases, and setting the criteria the agents apply.
That shift is what makes compliance sustainable. A team that does the work can hit a deadline. A team that governs the work can hold the line through the next reorganization, the next platform migration, and the next guideline.
Where this goes next
We're not finished, and the honest roadmap is short.
E-21 is the first packaged offering of this kind, and it covers one dimension of one guideline. OSFI's Guideline E-23 on model risk management takes effect May 1, 2027, covering all models that carry risk at all federally regulated institutions, with added guidance for AI and machine learning models specifically.⁷ It's the natural next chapter, and it's in development, not shipped. New frameworks, industries, and geographies are in development too. PwC is among the first global system integrators building packaged offerings on the AIOS, and a broader partner network is coming, because every regulated vertical has its own version of this problem and its own experts who know it cold.
The architecture is built to extend: the same CDE library expands, the same policies adapt, the same automation runs against new sources. This is worth weighing when you pick a path for September, because the architecture you choose for this deadline is the one you carry into scenario testing and E-23.
There's a broader case here too: that data which is known, owned, trusted, and traceable is the same foundation your AI, customer experience, and transformation agendas need, so the E-21 work needn't be money spent twice.
Frequently asked questions about OSFI E-21 and data risk management
Will an external auditor accept AI-generated data lineage as E-21 evidence?
Yes, when the transformation logic is documented and a human steward signs off. What the auditor reviews is not a black-box output: PwC Canada's lineage agent records the transformation logic at each hop and writes it into the Alation catalog, where it sits alongside the policy linkage, classification, and ownership record with the audit trail attached. Independent assurance from internal audit remains an OSFI E-21 expectation and remains a human judgment.⁵ Automation changes how evidence gets assembled, not who is accountable for it.
How is an E-21 compliance accelerator different from just buying a data catalog?
A catalog is a component, not the answer. The Alation–PwC Canada accelerator combines four things a catalog alone doesn't provide: regulatory IP authored to OSFI's specific E-21 expectations that loads on day one, agents running on both sides of the catalog, column-level lineage coverage extending into non-SQL transformations (Python, XML, JSON, spreadsheets) where audit gaps actually appear, and evidence packages formatted for the people who review them. Any one of those alone is a feature.
Can we automate Critical Data Element governance if our metadata is incomplete or inconsistent?
Yes — messy metadata is the normal starting condition, and generating definitions and classifications at scale is exactly what curation automation is for. Be realistic about sequencing, though: yield tracks input quality. A first pass on a poorly documented estate produces more candidates needing steward correction than a well-documented one. It is still faster than starting by hand. It is not instant.
What does OSFI E-21 §4.7 actually require for data risk management?
Six programme components in a single clause: a data risk management program with governance, roles, and responsibilities; architecture and IT infrastructure to collect, aggregate, trace lineage, and report critical data across the enterprise; classification and protection processes; methodologies for integrity, adaptability, confidentiality, and availability across the data lifecycle; escalation for data incidents; and training for everyone accountable.² Most institutions operationalize this as a Critical Data Element program, narrowing scope to the elements carrying real regulatory and operational consequence.
When are the OSFI E-21 deadlines?
OSFI set a phased timeline for federally regulated financial institutions: full adherence to section 4 by September 1, 2025; full adherence to the guideline by September 1, 2026; and scenario testing completed for all critical operations by September 1, 2027.³ OSFI has said it will spend its 2026–27 fiscal year on supervisory activities assessing institutional readiness for the expectations taking effect this September.⁴ Readiness is being assessed now.
Does the Alation-PwC accelerator cover all of OSFI E-21?
No. It addresses the data risk management requirements in §4.7, not end-to-end E-21 coverage. That scope limit is deliberate: §4.7 is the guideline's largest and most operationally demanding dimension, and the section where most Canadian financial institutions have their biggest gap.
How long does it take to identify Critical Data Elements for E-21 compliance?
In one early engagement, a 300-page annual report was processed into a candidate list of roughly 100 Critical Data Elements, ranked against risk criteria and ready for steward review — compressing work the institution had scoped from months to days. Against the manual path, Alation measures a 70% reduction in CDE governance costs and an average saving of seven days per CDE onboarded.¹
Should we plan for OSFI E-23 at the same time as E-21?
Worth weighing now, because the architecture you choose for the September 2026 E-21 deadline is the one you carry into scenario testing and E-23. Guideline E-23 on model risk management takes effect May 1, 2027 for all federally regulated institutions, covering all models that carry risk, with added guidance for AI and machine learning models specifically.⁷ An E-23 offering is in development, not shipped.
Let's talk
Whether your institution is still closing its E-21 data management gap or has closed it and now owns the recurring obligation behind it, we should talk. Connect with us today.
Curious to learn more? Read the press release.
Jonathan Bruce is VP Global Partnerships at Alation. Prithwiraj Thakur is Partner, Data and AI at PwC Canada.
Sources & notes
Every external claim on this page is independently verifiable. The public sources are listed here.
70% reduction in CDE governance costs; 7 days average time savings per CDE onboarded; single registry connecting policies, glossary terms and lineage into an audit-ready view of each CDE's health and ownership. Figures are Alation's own measurement. — Alation, CDE Manager, accessed 7 August 2026 ↗ https://www.alation.com/product/alation-cde-manager/
Data risk management program expectations, including data governance with clear roles and responsibilities; data architecture and IT infrastructure supporting collection, aggregation, lineage tracing and reporting of critical data across the enterprise; classification and protection processes; lifecycle integrity methodologies; incident escalation; and training. — OSFI, Guideline E-21, §4.7, 22 August 2024 ↗ https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/operational-risk-management-resilience-guideline
E-21 phased implementation: full adherence to section 4 expected by 1 September 2025; full adherence to the guideline expected by 1 September 2026; scenario testing completed for all critical operations by 1 September 2027. — OSFI, Operational Risk Management and Resilience — Letter, 22 August 2024 ↗ https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/operational-risk-management-resilience-letter
OSFI plans supervisory activities in fiscal 2026-27 to determine institutions' readiness to meet the operational resilience expectations effective 1 September 2026. The ARO covers 1 April 2026 to 1 April 2027. — OSFI, Annual Risk Outlook – Fiscal Year 2026-2027, 14 April 2026 ↗ https://www.osfi-bsif.gc.ca/en/about-osfi/reports-publications/osfis-annual-risk-outlook-fiscal-year-2026-2027
Documentation of decisions and assessments; reporting and escalation of significant issues to senior management and the board; independent assurance from internal audit that controls, policies, procedures and systems are designed and operating effectively. — OSFI, Guideline E-21, §1.3, §1.4 and §2.4.2, 22 August 2024 ↗ https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/operational-risk-management-resilience-guideline
AIOS launch, 14 July 2026; open, governed and self-improving architecture; Agentic Compliance described as improving regulatory compliance through governed data and AI workflows with proof ready on demand. — Alation, press release ↗ https://www.globenewswire.com/news-release/2026/07/14/3326909/0/en/alation-launches-aios-all-new-intelligence-operating-system-for-enterprise-ai.html
Guideline E-23 – Model Risk Management takes effect for all FRFIs on 1 May 2027; scope covers all models carrying risk to the institution, with added clarity for AI/ML model risk management. — OSFI, Guideline E-23 – Model Risk Management (2027) - Letter, 11 September 2025 ↗ https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027-letter
Analyst Attributions & Disclaimers
Gartner, "Lack of AI-Ready Data Puts AI Projects at Risk," Q&A with Roxane Edjlali, 26 February 2025.
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
- Active Data Governance
- AI
- Cloud Transformation
- Data Governance
Jonathan is a proven executive, technical and product leader with over 18 years of experience in the fields of software, program and product management. Track record of delivering innovative, creative and enterprise grade software backed by solid tactical and strategic planning processes. Success in growing and sustaining large customer base to maintain and meet aggressive revenue targets, while driving continued adoption at an industry context.

Prithwiraj Thakur
Partner, Data and AI, PwC Canada
A Partner and Data Management Practice Leader at PwC Canada, Prithwiraj brings over 22 years of global experience leading enterprise data transformations. With a background spanning Deloitte, Capgemini, and Cognizant, they specialize in AI-ready architecture, governance, master data management, and data monetization across healthcare, finance, and retail. Prithwiraj connects technical execution with boardroom strategy, helping organizations convert complex data into a scalable competitive advantage.
Keep reading
More from the data desk




