INDUSTRIES

OSFI B-13 compliance for Canadian financial services

OSFI B-13 has been in force since 2024-01-01, and the first question isn't which controls to buy. It's whether the guideline binds you at all. For a lot of the firms that ask us it doesn't, and they're still answering for it through somebody else's programme.

WHAT APPLIES

Which rules apply to you?

  • OSFI B-13

    Applies now

    Technology and cyber risk across three domains: governance, technology operations and resilience, and cyber security. It binds federally regulated institutions, and only those.In force 2024-01-01

  • OSFI B-10

    Applies now

    Third-party risk, and the route by which B-13 reaches suppliers who aren't regulated themselves. It reaches subcontractors too, which is why the questionnaire asks about your suppliers.In force 2024-05-01

  • OSFI E-23

    Not yet in force

    Model risk management, covering AI and machine learning models whether you built them or bought them. The only item here with runway left.In force 2027-05-01

  • Provincial credit union regimes

    Applies conditionally

    Credit unions are provincially regulated, with three federal exceptions. Ontario, British Columbia and Quebec run operational resilience expectations of their own.

  • CCSPA (Bill C-8)

    Not yet in force

    Banking is one of six Schedule 1 sectors. Schedule 2 is empty, so no organisation carries the duty today.Royal assent 2026-06-15

TECHNOLOGY

Whose kit does this run on?

The platforms we design, build and support. Named because a buyer with an estate already standardised on one of them needs to know before the first call, not after it.

Cisco, Palo Alto, F5, Azure, AWS, VMware

QUESTIONS

What buyers in this sector ask.

Almost certainly not directly. Credit unions are provincially regulated, with three federal exceptions: UNI Financial, Coast Capital Savings FCU, and Innovation Federal Credit Union. Your provincial regulator likely has an equivalent operational resilience requirement, and that one does apply to you.

You're being reached through your bank customer's B-10 third-party obligation, in force since 2024-05-01. The questions look like B-13 because the bank's own programme is built on it. You answer as a supplier, not as a regulated entity, and the difference changes what you have to build.

There isn't a fixed one. OSFI escalates supervisory scrutiny, requires remediation, and in serious cases constrains the institution. That's harder to budget for than a fine, which is rather the point of running it that way, and it is why banking cybersecurity Canada work gets funded late.

No. E-23 is model risk management and it comes into force on 2027-05-01. The 2025 update pulled AI and machine learning models firmly into scope, across all models regardless of whether you built them or bought them. It's a separate programme and the one still worth getting ahead of.

If you need an attestation or an audit opinion, you need an assessor, and it can't be the firm that built the controls. We'll build, evidence and hand over. Someone independent signs. Ask any supplier which of the two they are before the engagement is scoped.

PARLONS-EN

Un spécialiste chevronné répond en moins d'une heure, 24/7.