A detailed guide to OSFI Guideline B-13
As financial institutions become increasingly dependent on digital technologies, cloud computing, third-party service providers, and interconnected systems, technology risk has become one of the most significant challenges facing the financial sector. Cyberattacks, system outages, operational disruptions, ransomware incidents, and third-party failures can have severe financial, operational, and reputational consequences for organizations while also impacting customers and the broader financial system.
To address these growing risks, regulators around the world are strengthening their expectations for technology governance and cyber resilience. Organizations are now expected to move beyond traditional cyber security controls and adopt comprehensive frameworks that integrate governance, risk management, operational resilience, incident response, and continuous monitoring.
In Canada, one of the most important regulatory frameworks supporting these objectives is OSFI Guideline B-13.
Developed by the Office of the Superintendent of Financial Institutions (OSFI), OSFI Guideline B-13 establishes clear expectations for technology risk management and cyber security within federally regulated financial institutions (FRFIs). Rather than focusing solely on technical security controls, the guideline encourages organizations to build resilient governance structures, strengthen operational resilience, manage third-party risks, and continuously improve their ability to detect, respond to, and recover from technology and cyber incidents.
Although the guideline applies specifically to Canadian federally regulated financial institutions, its principles represent global best practices for technology governance. Many organizations outside Canada’s financial sector also use its recommendations to strengthen their cyber security programmes and improve operational resilience.
This detailed guide explains everything organizations need to know about OSFI Guideline B-13, including its objectives, scope, governance expectations, implementation requirements, core principles, compliance strategies, benefits, challenges, and best practices for building an effective technology and cyber risk management programme.
- What is OSFI Guideline B-13?
- What is OSFI?
- Why was OSFI Guideline B-13 introduced?
- Objectives of OSFI Guideline B-13
- Who must comply with OSFI Guideline B-13?
- Why OSFI Guideline B-13 matters beyond Canada
- The core pillars of OSFI Guideline B-13
- Outcome 1: Technology and cyber governance
- Outcome 2: Technology operations and resilience
- Outcome 3: Cyber security
- Benefits of implementing OSFI guideline B-13
- Common challenges when implementing OSFI guideline B-13
- Best practices for implementing OSFI Guideline B-13
- OSFI Guideline B-13 compared to other frameworks
- Conclusion
- FAQs
What is OSFI Guideline B-13?
OSFI Guideline B-13, officially titled Technology and Cyber Risk Management, is a regulatory guideline published by the Office of the Superintendent of Financial Institutions (OSFI). It establishes the regulator’s expectations for how federally regulated financial institutions should identify, assess, manage, monitor, and recover from technology and cyber risks.
The guideline recognizes that technology has become fundamental to every aspect of financial services. Digital banking, online payments, cloud infrastructure, artificial intelligence, mobile applications, open banking initiatives, and third-party technology providers have significantly increased both operational efficiency and cyber risk.
As organizations become more digitally connected, cyber threats have also become more sophisticated. Financial institutions face risks ranging from ransomware attacks and insider threats to software vulnerabilities, third-party service failures, and supply chain attacks.
OSFI Guideline B-13 provides a structured approach for managing these risks through effective governance, resilient technology operations, comprehensive cyber security practices, and continuous oversight.
Rather than prescribing specific technologies or cyber security tools, the guideline establishes outcome-based expectations. This allows organizations to implement controls that are appropriate for their size, complexity, business model, and overall risk profile while still meeting regulatory expectations.
What is OSFI?
The Office of the Superintendent of Financial Institutions (OSFI) is Canada’s independent federal regulator responsible for supervising and regulating federally regulated financial institutions and private pension plans.
OSFI’s primary objective is to contribute to public confidence in Canada’s financial system by ensuring that financial institutions operate safely, remain financially resilient, and effectively manage risks that could affect customers, investors, or the broader economy.
Its regulatory oversight includes:
- Banks.
- Bank holding companies.
- Trust and loan companies.
- Insurance companies.
- Federally regulated pension plans.
- Foreign financial institutions operating in Canada.
In recent years, OSFI has expanded its focus beyond traditional financial risks to include operational resilience, cyber security, digital transformation, and technology governance as organizations increasingly rely on complex digital ecosystems.
OSFI Guideline B-13 reflects this broader regulatory focus by providing comprehensive expectations for managing technology and cyber risks across the entire organization.
Why was OSFI Guideline B-13 introduced?
The financial sector has undergone rapid digital transformation over the past decade.
Financial institutions now depend heavily on cloud platforms, APIs, mobile applications, artificial intelligence, third-party technology providers, digital payment systems, and interconnected infrastructure to deliver services.
While these technologies improve customer experience and operational efficiency, they also introduce new categories of risk that traditional cyber security programmes may not fully address.
Several factors contributed to the development of OSFI Guideline B-13.
Increasing cyber threats
Cybercriminals continue to target financial institutions because they manage valuable financial assets, sensitive customer information, and critical national infrastructure.
Attack techniques have evolved significantly and now include ransomware campaigns, phishing attacks, credential theft, supply chain compromises, advanced persistent threats, and attacks targeting cloud environments.
Organizations require stronger governance and resilience capabilities to respond effectively to these evolving threats.
Growing technology dependencies
Modern financial institutions depend on highly interconnected technology environments.
Core banking systems, cloud platforms, third-party vendors, payment processors, identity providers, and managed service providers all play essential roles in daily operations.
A disruption affecting any of these components can impact business continuity and customer services.
The guideline emphasizes the importance of understanding and managing these technology dependencies.
Third-party risk
Outsourcing has become common across the financial sector.
Organizations increasingly rely on cloud providers, software vendors, cyber security providers, fintech companies, and external technology partners.
While outsourcing offers flexibility and innovation, it also creates additional risks that must be governed effectively.
OSFI Guideline B-13 encourages organizations to strengthen oversight of third-party technology risks throughout the vendor lifecycle.
Operational resilience
Regulators now recognize that preventing every cyber incident is impossible.
Instead, organizations must also demonstrate their ability to detect, respond to, recover from, and learn from operational disruptions.
Operational resilience has therefore become a central theme within OSFI Guideline B-13.
Rather than measuring success solely by preventing incidents, organizations are expected to minimize disruption and restore critical services quickly when incidents occur.
Objectives of OSFI Guideline B-13
The primary objective of OSFI Guideline B-13 is to improve the resilience of Canada’s financial sector by strengthening technology governance and cyber security practices.
More specifically, the guideline aims to help organizations:
Strengthen technology governance
Technology risks should receive the same level of executive attention as financial, operational, and strategic risks.
The guideline encourages boards and senior management to establish governance structures that provide effective oversight of technology investments, cyber security, operational resilience, and digital transformation initiatives.
Improve cyber risk management
Organizations should identify, assess, prioritize, and manage cyber risks using structured and repeatable processes.
Cyber security should become an integrated component of enterprise risk management rather than an isolated IT function.
Enhance operational resilience
Financial institutions should continue delivering critical business services even during significant technology failures or cyber incidents.
Organizations should understand their critical operations, prepare for disruptions, and develop recovery capabilities that minimize customer impact.
Promote continuous improvement
Technology risks evolve continuously.
Organizations should regularly review governance processes, cyber security controls, incident response capabilities, and operational resilience strategies to ensure they remain effective as business environments and threat landscapes change.
Encourage enterprise-wide accountability
Technology and cyber risk management should not be limited to technology teams.
The guideline encourages collaboration across executive leadership, risk management, compliance, cyber security, business operations, internal audit, and technology functions to ensure accountability throughout the organization.
Who must comply with OSFI Guideline B-13?
OSFI Guideline B-13 applies primarily to Federally Regulated Financial Institutions (FRFIs) operating under OSFI’s supervision.
These include:
- Canadian banks.
- Foreign bank branches.
- Trust companies.
- Loan companies.
- Life insurance companies.
- Property and casualty insurance companies.
- Fraternal benefit societies.
- Federally regulated cooperative credit associations.
Although the guideline directly applies to Canadian financial institutions, its recommendations are increasingly influencing technology governance practices across other highly regulated industries.
Organizations operating in sectors such as healthcare, telecommunications, critical infrastructure, energy, and government frequently adopt similar governance principles to strengthen operational resilience and cyber risk management.
Technology vendors and third-party service providers supporting Canadian financial institutions also benefit from understanding OSFI Guideline B-13, as customers increasingly expect suppliers to demonstrate alignment with its requirements.
Why OSFI Guideline B-13 matters beyond Canada
While OSFI Guideline B-13 is a Canadian regulatory guideline, its influence extends well beyond national borders.
Many of its expectations closely align with internationally recognized cyber security and operational resilience frameworks, including the NIST Cybersecurity Framework (CSF), ISO/IEC 27001, ISO 22301, DORA (Digital Operational Resilience Act), and broader enterprise risk management practices.
The guideline reflects a global regulatory shift toward integrated technology governance, where cyber security, operational resilience, third-party risk management, and executive accountability are treated as interconnected business priorities rather than isolated technical functions.
Organizations that align with the principles of OSFI Guideline B-13 are often better prepared to address evolving regulatory expectations, improve stakeholder confidence, and build resilient technology environments capable of supporting long-term business growth.
In the next section, we will explore the core pillars of OSFI Guideline B-13, examining the governance expectations, technology lifecycle management, cyber security requirements, operational resilience practices, and third-party risk management principles that organizations should implement to achieve effective compliance.
The core pillars of OSFI Guideline B-13
OSFI Guideline B-13 is organized around three core outcomes that together create a comprehensive framework for managing technology and cyber risk. Rather than treating cyber security as a standalone technical function, the guideline encourages organizations to integrate governance, operational resilience, technology management, and cyber security into enterprise-wide risk management.
Each outcome builds upon the others, creating a continuous approach to identifying, managing, monitoring, and responding to technology-related risks.
Organizations that successfully implement these outcomes are better positioned to maintain business continuity, protect customer information, comply with regulatory expectations, and strengthen overall operational resilience.
Outcome 1: Technology and cyber governance
The first outcome focuses on governance.
OSFI expects technology and cyber risks to receive the same level of oversight as financial, operational, and strategic risks. Technology decisions should not be isolated within IT departments. Instead, executive leadership and boards should actively participate in setting governance expectations, defining accountability, approving risk appetite, and monitoring organizational performance.
Strong governance creates the foundation upon which every other technology and cyber risk management activity depends.
Board and senior management responsibilities
The board of directors and senior management are ultimately responsible for ensuring that technology and cyber risks are governed effectively.
Their responsibilities include:
- Approving technology and cyber risk strategies.
- Establishing organizational risk appetite.
- Providing sufficient resources for cyber security and resilience.
- Reviewing technology-related risks regularly.
- Monitoring compliance with regulatory expectations.
- Promoting a strong risk culture across the organization.
Technology governance should become an ongoing executive discussion rather than an annual compliance exercise.
Clearly defined roles and responsibilities
Organizations should establish governance structures that clearly define ownership for technology and cyber risks.
Responsibilities should be assigned across executive leadership, information security, technology operations, risk management, compliance, internal audit, and business units.
This prevents accountability gaps during both normal operations and cyber incidents.
Employees should also understand their individual responsibilities for protecting organizational technology assets.
Technology risk management framework
OSFI expects organizations to develop a formal technology risk management framework that aligns with enterprise risk management practices.
The framework should define:
- Risk identification processes.
- Risk assessment methodologies.
- Risk reporting mechanisms.
- Risk acceptance criteria.
- Escalation procedures.
- Governance responsibilities.
- Continuous monitoring activities.
A structured framework allows organizations to make consistent, risk-based decisions throughout the technology lifecycle.
Outcome 2: Technology operations and resilience
Technology systems are essential for delivering financial services.
Customers expect uninterrupted access to banking platforms, insurance services, digital payments, investment platforms, and mobile applications.
For this reason, OSFI Guideline B-13 places significant emphasis on operational resilience.
Organizations should not only prevent technology failures but also ensure they can recover quickly when disruptions occur.
Technology asset management
Organizations should maintain comprehensive visibility into their technology environment.
This includes documenting:
- Hardware assets.
- Software applications.
- Cloud services.
- Data repositories.
- Networks.
- Infrastructure components.
- Critical business applications.
Maintaining accurate technology inventories enables organizations to understand dependencies, prioritize critical systems, and respond more effectively during incidents.
Technology lifecycle management
Technology environments evolve continuously.
Applications receive updates, infrastructure changes, cloud environments expand, and software eventually reaches end-of-life.
OSFI expects organizations to manage technology throughout its entire lifecycle.
Effective lifecycle management includes:
- Secure system design.
- Change management.
- Configuration management.
- Patch management.
- Vulnerability management.
- System retirement planning.
Technology should be maintained proactively rather than reactively.
Change and release management
Uncontrolled technology changes are a common source of operational failures.
Organizations should implement formal change management processes that evaluate the risks associated with infrastructure changes, software releases, security updates, and system migrations.
Changes should be:
- Tested before deployment.
- Approved through defined governance processes.
- Documented appropriately.
- Monitored after implementation.
This reduces the likelihood of unexpected service disruptions.
Business continuity and disaster recovery
OSFI Guideline B-13 emphasizes resilience rather than simply disaster recovery.
Organizations should identify critical business services and ensure they can continue operating during technology failures or cyber incidents.
Business continuity planning should include:
- Recovery objectives.
- Critical service prioritization.
- Backup strategies.
- Alternate operating procedures.
- Recovery testing.
- Crisis communication plans.
Regular testing ensures recovery plans remain effective under real-world conditions.
Outcome 3: Cyber security
The third outcome focuses on protecting technology assets from internal and external cyber threats.
Rather than prescribing specific security technologies, OSFI outlines the capabilities organizations should establish to manage evolving cyber risks effectively.
Cyber security should be embedded throughout the organization rather than limited to security teams.
Threat and vulnerability management
Organizations should continuously identify vulnerabilities across their technology environments.
This includes:
- Vulnerability scanning.
- Security assessments.
- Threat intelligence.
- Penetration testing.
- Patch management.
- Risk prioritization.
Threat intelligence should inform security decisions by helping organizations understand emerging attack techniques and evolving adversary behaviors.
Identity and access management
Unauthorized access remains one of the most common causes of cyber incidents.
Organizations should implement strong identity and access management practices that ensure users receive only the permissions necessary to perform their responsibilities.
Effective identity governance includes:
- Multi-factor authentication.
- Role-based access controls.
- Privileged access management.
- User lifecycle management.
- Periodic access reviews.
These controls help reduce insider threats while limiting the impact of compromised credentials.
Security monitoring
Cyber threats evolve continuously.
Organizations should establish monitoring capabilities that provide visibility into technology environments and enable rapid detection of suspicious activities.
Monitoring may include:
- Security event monitoring.
- Log analysis.
- Endpoint monitoring.
- Network monitoring.
- Cloud security monitoring.
- User activity monitoring.
Continuous visibility allows organizations to identify attacks before they escalate into significant incidents.
Incident response
No organization can eliminate cyber risk entirely.
OSFI therefore expects organizations to prepare for incidents before they occur.
Incident response capabilities should include:
- Clearly defined response procedures.
- Incident classification criteria.
- Roles and responsibilities.
- Communication protocols.
- Regulatory notification processes.
- Recovery procedures.
- Post-incident reviews.
Learning from incidents helps organizations continuously strengthen their cyber resilience.
Third-party technology risk management
Modern financial institutions rarely operate entirely on their own technology infrastructure.
Cloud providers, software vendors, payment processors, managed service providers, fintech companies, and outsourced technology partners all contribute to daily operations.
This interconnected ecosystem creates additional risks that require active governance.
OSFI Guideline B-13 expects organizations to manage third-party technology risks throughout the entire vendor relationship.
Effective third-party risk management should include:
- Vendor due diligence before engagement.
- Security assessments.
- Contractual security requirements.
- Ongoing performance monitoring.
- Continuous risk assessments.
- Exit and transition planning.
Organizations remain accountable for outsourced services, even when operational activities are performed by external providers.
Operational resilience as a continuous capability
One of the defining characteristics of OSFI Guideline B-13 is its emphasis on resilience rather than prevention alone.
Traditional cyber security programmes often focus on preventing attacks.
While prevention remains important, modern organizations must also assume that some incidents will occur despite strong security controls.
Operational resilience enables organizations to continue delivering critical services even when technology disruptions happen.
This requires continuous preparation, regular testing, governance oversight, and ongoing improvement.
Organizations that integrate resilience into everyday operations are generally better equipped to withstand cyber incidents, technology failures, third-party disruptions, and rapidly changing threat landscapes.
In the next section, we will explore the benefits of implementing OSFI Guideline B-13, common implementation challenges, best practices for achieving compliance, how it compares with frameworks such as NIST CSF, ISO/IEC 27001, and DORA, and how organizations can strengthen technology and cyber risk management using modern GRC platforms like CyberArrow.
Benefits of implementing OSFI guideline B-13
Organizations that align with OSFI Guideline B-13 gain far more than regulatory compliance. The guideline encourages financial institutions to establish mature technology governance, strengthen cyber resilience, improve operational stability, and build greater confidence among customers, regulators, and stakeholders.
As technology continues to shape the financial sector, organizations that proactively implement the guideline are better prepared to respond to emerging threats while supporting long-term business growth.
Strengthens technology governance
One of the most significant benefits of OSFI Guideline B-13 is stronger governance over technology-related decisions.
By integrating technology risk into enterprise governance, organizations ensure that boards, senior management, risk teams, and technology leaders share responsibility for managing cyber and operational risks.
This enterprise-wide approach enables better strategic decision-making while improving accountability across the organization.
Improves operational resilience
Technology failures can disrupt essential financial services within minutes.
OSFI Guideline B-13 encourages organizations to understand their critical business services, strengthen recovery capabilities, and regularly test resilience plans.
This helps reduce downtime, minimize customer impact, and improve the organization’s ability to recover from technology disruptions quickly and effectively.
Enhances cyber security posture
The guideline promotes a proactive approach to cyber security by encouraging organizations to continuously monitor threats, manage vulnerabilities, strengthen identity management, and improve incident response capabilities.
Rather than relying solely on preventive controls, organizations build security programmes that can rapidly detect, contain, and recover from cyber incidents.
Reduces third-party risk
Third-party providers play an increasingly important role in financial services.
Cloud providers, managed service providers, payment processors, software vendors, and fintech partners all contribute to critical business operations.
OSFI Guideline B-13 encourages organizations to establish stronger vendor governance throughout the supplier lifecycle, reducing operational risks associated with outsourcing.
Supports regulatory readiness
Although OSFI Guideline B-13 applies specifically to federally regulated financial institutions in Canada, many of its governance principles align closely with international cyber security and operational resilience frameworks.
Organizations that implement the guideline often find it easier to demonstrate compliance with other regulatory expectations because governance, documentation, risk management, and resilience processes are already well established.
Common challenges when implementing OSFI guideline B-13
Implementing OSFI Guideline B-13 requires more than deploying new cyber security technologies.
Organizations must establish governance structures, improve collaboration across departments, modernize operational processes, and continuously monitor evolving risks.
Several challenges commonly arise during implementation.
Legacy technology environments
Many financial institutions continue to operate legacy infrastructure that was not designed to support modern cyber security requirements.
Older systems may lack visibility, automation capabilities, or integration with modern monitoring tools, making technology governance more complex.
Organizations often need phased modernization strategies to reduce risk while maintaining business continuity.
Fragmented technology governance
Technology governance responsibilities are frequently distributed across multiple departments.
Risk management, cyber security, IT operations, compliance, internal audit, and business units may all maintain separate processes and reporting structures.
Without centralized governance, organizations struggle to maintain consistent oversight across technology risks.
Limited visibility into technology assets
Effective governance depends on understanding the organization’s technology environment.
Many institutions lack accurate inventories of hardware, software, cloud resources, APIs, third-party services, and business dependencies.
Without comprehensive visibility, identifying critical assets and assessing technology risks becomes significantly more difficult.
Managing third-party dependencies
Financial institutions increasingly depend on external technology providers.
Monitoring vendor security, resilience capabilities, contractual obligations, and ongoing risk exposure requires continuous oversight rather than one-time due diligence.
Organizations must ensure outsourced services meet the same governance expectations applied internally.
Keeping pace with emerging threats
Cyber threats evolve continuously.
Attack techniques, ransomware campaigns, software vulnerabilities, and supply chain attacks change rapidly, requiring organizations to update governance processes, security controls, and incident response capabilities on an ongoing basis.
Static cyber security programmes quickly become ineffective in today’s threat landscape.
Best practices for implementing OSFI Guideline B-13
Organizations can significantly improve implementation success by adopting a structured, risk-based approach.
Rather than viewing compliance as a one-time project, organizations should establish governance programmes that continuously evolve alongside technology and business operations.
Integrate technology risk into enterprise risk management
Technology risk should be managed alongside financial, operational, legal, and strategic risks.
Integrating technology governance into enterprise risk management enables consistent oversight and better executive decision-making.
Maintain a comprehensive technology inventory
Organizations should maintain accurate records of technology assets, infrastructure, applications, cloud services, third-party providers, and critical business systems.
A centralized inventory supports risk assessments, incident response, vulnerability management, and business continuity planning.
Perform regular risk assessments
Technology and cyber risks should be evaluated regularly rather than only during audits.
Risk assessments should consider changes in business operations, emerging threats, technology updates, third-party relationships, and evolving regulatory expectations.
Continuous assessment enables organizations to prioritize remediation efforts effectively.
Strengthen third-party risk management
Vendor governance should extend throughout the entire relationship.
Organizations should perform security due diligence before onboarding vendors, monitor supplier performance continuously, review contractual obligations regularly, and establish exit strategies for critical service providers.
Strong vendor governance significantly reduces operational risk.
Continuously test operational resilience
Business continuity and disaster recovery plans should be tested under realistic conditions.
Regular simulation exercises, cyber incident scenarios, recovery testing, and tabletop exercises help identify weaknesses before real incidents occur.
Testing also improves coordination between business, technology, and executive leadership teams.
OSFI Guideline B-13 compared to other frameworks
Organizations often implement multiple governance frameworks simultaneously.
Understanding how OSFI Guideline B-13 relates to other cyber security standards helps organizations build integrated compliance programmes rather than duplicating efforts.
OSFI Guideline B-13 vs ISO/IEC 27001
ISO/IEC 27001 establishes an Information Security Management System (ISMS) that helps organizations manage information security risks across the enterprise.
OSFI Guideline B-13 has a broader regulatory focus on technology governance, operational resilience, cyber security, and executive accountability within financial institutions.
Many organizations use ISO/IEC 27001 to strengthen information security while using OSFI Guideline B-13 to guide technology governance and regulatory compliance.
OSFI Guideline B-13 vs NIST Cybersecurity Framework
The NIST Cybersecurity Framework (CSF) provides flexible guidance for managing cyber security risks using five core functions: Govern, Identify, Protect, Detect, Respond, and Recover.
OSFI Guideline B-13 incorporates many similar concepts but places greater emphasis on regulatory expectations, technology lifecycle management, operational resilience, and board-level governance for federally regulated financial institutions.
The two frameworks complement each other well and are often implemented together.
OSFI Guideline B-13 vs DORA
The Digital Operational Resilience Act (DORA) applies to financial entities operating within the European Union.
Like OSFI Guideline B-13, DORA emphasizes operational resilience, ICT risk management, third-party oversight, incident reporting, and resilience testing.
While DORA is legislation with mandatory legal requirements across the EU, OSFI Guideline B-13 establishes supervisory expectations specifically for Canadian federally regulated financial institutions.
Despite differences in jurisdiction, both frameworks share the objective of strengthening operational resilience across the financial sector.
Conclusion
Technology has become the backbone of modern financial services, making effective technology governance and cyber resilience essential for long-term success. As financial institutions continue to expand their digital capabilities, they must also strengthen their ability to manage cyber threats, technology failures, operational disruptions, and third-party risks.
OSFI Guideline B-13 provides a comprehensive framework that helps organizations move beyond traditional cyber security by integrating technology governance, operational resilience, cyber risk management, and executive accountability into a unified approach. Rather than treating technology risk as solely an IT responsibility, the guideline encourages enterprise-wide ownership that supports secure, resilient, and reliable financial services.
Successfully implementing OSFI Guideline B-13 requires more than policies and documentation. Organizations need centralized visibility into technology assets, continuous risk monitoring, streamlined compliance processes, structured vendor oversight, and effective governance that can adapt as technology and regulatory expectations evolve.
CyberArrow GRC helps organizations simplify technology governance and cyber risk management by centralizing policies, controls, risk registers, compliance activities, evidence management, third-party risk management, and audit readiness within a single platform. Trusted by some of the world’s biggest brands across the United States, Europe, Africa, Asia, and the Middle East, CyberArrow enables organizations to strengthen governance, improve operational resilience, and align with leading frameworks and regulatory requirements, including OSFI Guideline B-13, ISO/IEC 27001, NIST CSF, and DORA. Whether your organization is building a mature technology risk programme or preparing for regulatory assessments, CyberArrow provides the visibility, automation, and governance capabilities needed to stay resilient in an increasingly complex digital landscape.
FAQs
What is OSFI Guideline B-13?
OSFI Guideline B-13 is a regulatory guideline issued by the Office of the Superintendent of Financial Institutions (OSFI) that establishes expectations for technology risk management and cyber security within federally regulated financial institutions in Canada.
Who must comply with OSFI Guideline B-13?
The guideline applies to federally regulated financial institutions (FRFIs), including banks, trust companies, loan companies, insurance companies, and foreign bank branches supervised by OSFI.
Is OSFI Guideline B-13 mandatory?
Yes. While it is published as a supervisory guideline rather than legislation, OSFI expects federally regulated financial institutions to align with its requirements and may assess compliance during supervisory reviews.