veille Built for, Financial Services
Vertical

Built for the financial institutions the AMF regulates.

Caisses, mid-market insurers, OCRI/CIRO dealers, and fintechs answer first to the AMF and to Loi 25, not to OSFI. The AMF's guideline on the use of AI takes effect May 1, 2027; Loi 25's automated-decision rules are already in force. Veille encodes both, adds OSFI E-23 if you are also federally regulated, and the EU AI Act if you serve Europe. Most tools are built federal-first and miss the provincial layer entirely. We built it the other way around, and because we price by institution size with unlimited AI systems, a fintech running dozens of models pays the same band as an institution running three.

Primary frameworkAMF guideline + Loi 25 (Québec)
Key deadlineAMF guideline, May 1, 2027
PricingBy institution size, unlimited AI systems

Regulatory framework

Provincial first. Federal when it applies.

Québec, Finance AMF, Guideline on the use of artificial intelligence
The Autorité des marchés financiers is the sole prudential and market-conduct regulator for Québec caisses, insurers, and registered dealers. Its guideline on the use of AI takes effect May 1, 2027 and covers AI governance, risk management, transparency to clients, and oversight of third-party and vendor AI. This is the framework your next AMF exam will turn on, and federal-only tools ignore it entirely. Veille's AMF module is anchored verbatim to the official AMF texts and is in validation with counsel. Read the full AMF guide →
Québec, Privacy Loi 25, Privacy and automated decisions (QC)
Loi 25 binds every organization operating in Québec, financial or not, and it is already in force. It creates obligations for AI systems making automated decisions affecting customers, including credit decisions, fraud flags, and pricing. Art. 12.1 requires transparency notices before an exclusively automated decision, plus the right to human review. Art. 3.3 and 17 require a privacy impact assessment (EFVP) before deployment and before any transfer outside Québec. In full force since September 2023, enforced by the CAI, a distinct regulator from the AMF.
Federal, if applicable OSFI E-23, only if you are a FRFI
If you are also federally regulated, OSFI's Guideline E-23 on enterprise-wide model risk management applies, with a compliance date of May 1, 2027, the same day as the AMF guideline. It requires a model inventory, independent validation, ongoing monitoring, and full lifecycle documentation for AI and ML models. Provincially regulated? This one does not bind you, and Veille will not clutter your posture with it. Federally regulated too? Veille covers both from one registry.
Europe, if applicable EU AI Act, Annex III §5
Credit scoring and insurance risk assessment are explicitly listed as high-risk AI systems under Annex III §5. For institutions serving European customers or operating EU subsidiaries, this creates mandatory conformity documentation, human oversight, and registration obligations, with high-risk (Annex III) provisions applying 2 December 2027, deferred from 2 August 2026 by the Digital Omnibus on AI.

Use cases

AI systems Veille monitors for financial institutions.

System Primary frameworks Key obligations
Credit scoring engine Loi 25AMFEU AI ActOSFI E-23 EFVP, Art. 12.1 transparency, AMF governance, Annex III §5 conformity
Fraud detection model Loi 25AMF Automated-decision transparency, Human escalation pathway, AMF risk governance
AML transaction monitoring Loi 25AMF Model governance, False positive rate monitoring, Registry of record
Pricing / robo-advisor Loi 25AMF Art. 12.1 transparency for individual decisions, AMF fair-treatment expectations
KYC / onboarding AI Loi 25AMF Biometric data obligations, EFVP, Identity-based decision transparency

Pain points

What we hear from financial compliance teams.

01
The tools you were pitched are built federal-first
Most AI-governance products assume OSFI and skip the AMF. If you are a caisse, a Québec insurer, or an OCRI dealer, that means the one regulator that examines you is the one your tool ignores. Veille encodes the AMF layer, not as an add-on, but as the starting point.
02
Loi 25 EFVPs done retroactively, or not at all
The requirement to complete a privacy impact assessment before deployment has created a backlog. Most institutions have systems in production with no documented assessment. The CAI has signalled that retroactive EFVPs are acceptable only in limited circumstances.
03
Shadow AI appears faster than governance catches it
Fintechs and digital-first institutions ship models and vendor integrations at a pace compliance teams cannot track by hand, and most AI is bought, not built, so the obligation lands on you without warning. Veille's discovery layer surfaces the systems no one declared. Priced by size with unlimited systems, you are never penalized for finding more of them.
04
The annual audit model doesn't work for AI
A model validated in January can drift by April. The AMF guideline and Loi 25 both expect ongoing oversight, not a point-in-time snapshot. Veille's continuous scan replaces the annual audit and keeps the evidence current.

Act now

Your AMF deadline is May 1, 2027.

Institutions that start now will have a discovered, documented, continuously monitored AI inventory, in French and English, before the AMF guideline takes effect and Loi 25 enforcement tightens. A 30-minute call is enough to map which of your systems are in scope.

Book a 30-minute call