Free tool Tier a model against OSFI E-23 in about five minutes — seven risk dimensions, the controls your tier requires, and a report you can print. Open it →
osfi-gate

About

Blake Medulan

Technology and AI Sherpa at 3 Halves Labs. Twenty-five years leading global enterprise technology teams, working as a digital transformation and AI architect. Based in Markham, Ontario.

osfi@melx.buzz LinkedIn

Why this exists

Canadian federally regulated institutions have no shortage of control frameworks. What they tend to lack is evidence — the kind somebody outside the team can check without taking the team's word for it.

The usual arrangement is a control attested quarterly by the people who operate it, recorded in a GRC platform that is itself trusted, and reviewed by someone with no practical way to reproduce the finding. Every step is reasonable. The result is a chain of assertions with no point at which anyone can independently confirm anything.

osfi-gate takes the opposite position: the evidence should survive not being trusted. A gate run records what it saw, what policy it applied and what it decided, signs it, chains it, and makes the whole decision replayable offline. If the tool that produced it disappeared tomorrow, the evidence would still check out.

That constraint is what shaped the design, and it is also what rules things out. It is why approvals happen in Git rather than in a web form, why the tool refuses to report "unknown" as "passing", and why there is no hosted service that would require sending you evidence you were told you did not have to trust us about.

What is on this site

Getting in touch

For a walkthrough, a pilot on your own estate, or an awkward question about any of the stated limits — email is the fastest way to reach me.

osfi@melx.buzz