home / guides / osfi-guideline-b-13

Sector and contracting · Office of the Superintendent of Financial Institutions

OSFI Guideline B-13 technology and cyber risk

Expectations for how federally regulated financial institutions govern and manage technology and cyber risk.

Who this applies to

Federally regulated financial institutions such as banks and insurers, and the service providers they depend on.

What to know

  • It covers three areas: governance and risk management, technology operations and resilience, and cyber security.
  • It is outcome based. Institutions decide how to meet each expectation in proportion to their size and risk.
  • Third-party and cloud arrangements fall inside its scope, so suppliers get asked to prove their controls.
  • It works alongside separate OSFI expectations for reporting technology and cyber incidents.

What to do

  • If you supply a regulated institution, expect due diligence questions that mirror the guideline and prepare evidence in advance.
  • Read the incident reporting expectations alongside the guideline, not separately.