OSFI B-13 and B-10: what a federal financial institution shows
These guidelines apply to institutions OSFI supervises. A Quebec caisse or an insurer under the AMF follows the provincial regime.
The Office of the Superintendent of Financial Institutions supervises banks, foreign bank branches, insurers, and trust and loan companies under federal jurisdiction. Guideline B-13, Technology and Cyber Risk Management, has been in effect since 1 January 2024. Read it with Guideline E-21 on operational risk and Guideline B-10 on third-party risk.
B-13: three files you can open
1. Governance
Senior management and the board see technology and cyber risk. Risk appetite, responsibilities and follow-up are written down.
2. Operations and resilience
Important systems are known. Change, continuity and the ability to recover after an incident are tested.
3. Cyber security
Measures follow the risk: access, monitoring, incident response. OSFI's Technology and Cyber Security Incident Reporting Advisory sets out when and how to report. Keep that procedure next to the incident register.
B-13 is an expectation of sound management, proportionate to risk. It is not a certificate to display.
B-10: third parties
Guideline B-10, Third-Party Risk Management, has been in effect since 1 May 2024. An arrangement entered into on or after that date is expected to comply. An older arrangement is reviewed at the next renewal or revision, as soon as possible after the effective date.
Where technology or cyber risk, or criticality, calls for it, the third party meets the institution's standards or recognized industry standards, notably for access and data protection. B-13 remains the reference for the institution's own technology risk.
Privacy beside it
B-13 and B-10 do not decide which privacy statute applies. An activity in Quebec may fall under the provincial act, and a flow across provinces under PIPEDA. The article on Law 25 and PIPEDA is the place to sort that out. A hosting assessment outside Quebec is still documented when that provincial act applies.
If your licence is provincial, start from the AMF's expectations. The licence, not the industry label, names your prudential regulator.
Technology risk and third parties in one register
CapRISK and CapTRISK keep the critical systems, incidents and vendor files that B-13 and B-10 ask you to open.
