Global fintech and funding innovation ecosystem

OSFI and GRI Workshops Reveal What Regulated AI Needs

Mar 24, 2026 | NCFA Feature | AI Finance And Data Governance

AI Image Risks in AI Finance

OSFI And GRI AI Workshops Show What Regulated AI Needs

On Mar 23 2026, OSFI and the Global Risk Institute published the FIFAI II final report based on four workshops held between May and November 2025. More than 170 participants took part across banks, insurers, asset managers, fintechs, vendors, regulators, academics, and consumer voices.

The report confirms that AI adoption is here, citing 72% AI use at work in financial services and 75% organizational support for AI. While AI is already in use.  The real issue is what still limits its use in regulated decisions and customer outcomes.

The series covered four areas that affect operational, prudential, consumer, and system-wide risk at the same time. Full report and framework: FIFAI II final report and AGILE framework PDF

  1. Security and Cybersecurity workshop PDF
  2. Financial Crime workshop PDF
  3. Financial Stability workshop PDF
  4. Financial Well-being and Consumer Protection workshop PDF

AI Won't Spread At The Same Speed

One of the clearest takeaways is that AI will not spread across finance at the same speed. The first gains will come in internal functions such as fraud detection, surveillance, reporting, cyber defence, and operations. Those areas already have strong data, measurable outputs, and clearer accountability.

Customer-facing decisions are different. Underwriting, advice, product recommendations, and self-serve tools carry more pressure around explainability, fairness, consent, and complaints handling.

AI powered Canadian finance will likely grow faster in control functions than in customer-facing decisions.

Third Party AI Is No Longer Just A Vendor Issue

The report treats third party AI as more than a procurement issue. It highlights growing dependence on external providers for models, infrastructure, and data, along with limited visibility into how those systems work and who sits behind them.

It's important because a failure, outage, or change in access at one provider can affect more than one function at the same time. Fraud controls, underwriting tools, customer service, and risk monitoring can all be exposed together. The financial stability workshop adds to that concern by linking third party dependency to concentration and system level risk.

See: Inside the Feedback Loops Driving AI Failure

Banks, insurers, and fintechs will need stronger oversight of models and providers, better audit access, tested fallback plans, and clearer visibility into the wider supply chain behind key AI services.

Fraud Is Becoming Harder To Contain

AI is improving both offence and defence. The final report points to synthetic identity, deepfakes, voice spoofing, AI assisted cyberattacks, fraud as a service, and disinformation. It notes a sharp rise in deepfake attacks and growing concern about voice verification as AI voice cloning improves.

This reality changes the operating environment. Static controls lose value faster when attack tools get cheaper, stronger, and easier to use. Manual review and occasional rule updates will not be enough. Firms will need faster detection, stronger identity controls, better information sharing, and systems that can adjust while attacks are happening.

Weak Identity And Poor Data Still Limit What AI Can Do

Data problems come up across the whole series, but the larger issue is bigger than data quality alone. Weak identity and fragmented data still limit how far AI can go in regulated finance. The report points to inconsistent data, incomplete records, fragmented platforms, offshore storage concerns, and weak data lineage as barriers to both efficiency and safety.

See:  AI Agents Gain Identity and Wallet Access WCGW

The report doesn't mince words on identity. Canada still doesn't have a widely adopted secure digital identity layer. That leaves onboarding, authentication, consumer channels, remote work, and agent based systems more exposed than they should be. If identity and data remains weak, AI will keep working best in narrower internal use cases and face more limits in customer facing execution.

Board Oversight Has To Show Up In Real Controls

The final report introduces the AGILE framework as part of its overall findings, which stands for Awareness, Guardrails, Innovation, Learning, and Ecosystem Resiliency. The framework calls for stronger governance and oversight, stronger data and risk controls, continued investment in technology and talent, and deeper public private collaboration.

AI oversight cannot remain just at the strategy level. If AI is used in lending, fraud, underwriting, complaints, or customer recommendations, governance has to show up in controls, evidence, escalation, and accountability. In regulated finance, that's what turns AI use from experimentation into something firms can defend and scale.

What Financial Institutions and Fintechs Do Now

The workshop series points to a practical sequence:

First, identify where AI already impacts decisions and controls.

Second, separate the use cases that can scale now from the ones that still need stronger explainability and customer safeguards.

See:  AI Governance Gaps Exposed By Legal Leaders

Third, tighten vendor oversight before dependency grows further.

Fourth, invest more in identity, data lineage (origin and how it's used and updated), and real time fraud controls.

Fifth, show boards stronger evidence instead of high level claims and broad assurance language.

The report also carries a warning worth taking seriously. Firms that move too slowly can fall behind on productivity, resilience, and customer expectations while still facing external AI enabled threats.  One participant line stands out: “The biggest risk is not doing enough.”

Why This Matters For Canada

Canada’s national AI strategy work has focused heavily on trust, safety, and responsible adoption. That is necessary, but this workshop series adds something more useful for operators. It shows where AI use slows once it enters regulated finance: concentrated provider risk, weak identity, fragmented data, explainability pressure, fraud risk, and unclear accountability.

There's a call to action policy lesson here too. Canada doesn't just need AI ambition and adoption. It needs stronger execution layers around Digital ID, data governance, third party oversight, and information sharing if it wants regulated financial AI to scale beyond contained pilots.

The OSFI and GRI workshop series is useful because it takes a holistic approach to identifying and adapting to AI risks in finance. AI is already inside financial systems. The advantage now goes to firms that can prove control, trust, and accountability in live decisions.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Leave a Reply

Your email address will not be published. Required fields are marked *