Canada
5 regulators · 6 instruments · 1 upcoming deadline
| Instrument | Type | Year | Regulator | Summary | Source |
|---|---|---|---|---|---|
| OSFI Guideline B-10 — Third-Party Risk Management | Guideline | 2023 | OSFI | OSFI Guideline B-10 refers to the regulatory regime that has been established by the Offi… | official |
OSFI Guideline B-10 refers to the regulatory regime that has been established by the Office of the Superintendent of Financial Institutions (OSFI) in Canada. It obligates federally regulated financial institutions (FRFIs) to effectively manage and mitigate any risks associated with their vendors. Contrary to the conventional regulations, which only concern themselves with outsourcing, this guideline takes a broad, lifecycle, and principles-based approach to all third-party relationships, regardless of the type of service that is being outsourced. The guideline focuses on six expected outcomes that seek to ensure operational and financial resilience. These include implementation of an effective governance strategy, strong cybersecurity, performance monitoring, and exit planning. The responsibility of protecting customers’ information and the integrity of the systems against risks emanating from third parties lies squarely on the shoulders of senior management. | |||||
| OSFI Guideline B-13 — Technology and Cyber Risk Management | Guideline | 2022 | OSFI | Guideline B-13 of OSFI is an all-encompassing regulatory framework published by Canada's … | official |
Guideline B-13 of OSFI is an all-encompassing regulatory framework published by Canada's Office of the Superintendent of Financial Institutions (OSFI) requiring federally regulated financial institutions (FRFIs) to develop effective operational strategies to protect themselves from the rising threat of technology and cybersecurity risks. Divided into three key pillars – Governance and Risk Management, Technology Operations and Resilience, and Cyber Security – the guideline takes the regulatory perspective from being based on technical checkmarks and makes it an outcomes-based approach to risk management. The guideline places full responsibility on the shoulders of senior management and boards to establish risk appetites for cyber threats, safeguard digital assets, ensure data confidentiality, and enforce identity management. Moreover, by integrating itself with the third-party requirements in Guideline B-10, it ensures that the threat management, incident response, and disaster recovery testing by an institution extends beyond its vendor and cloud ecosystem. | |||||
| Personal Information Protection and Electronic Documents Act (PIPEDA) | Act | 2000 | OPC | The Personal Information Protection and Electronic Documents Act (PIPEDA) is the major fe… | official |
The Personal Information Protection and Electronic Documents Act (PIPEDA) is the major federal legislation governing the privacy of the private sector in Canada and is regulated by Innovation, Science and Economic Development Canada (ISED), while being enforced by the Office of the Privacy Commissioner of Canada (OPC). It provides guidelines for the way companies gather, use, and share private information. Based on 10 Fair Information Principles, it obliges companies to ensure the provision of proper consent from consumers, to specify the reasons for the information collection, to develop strong organizational measures, and also to allow people to get access to the information about themselves and to change it. Data security under PIPEDA cannot be delegated. | |||||
| Proceeds of Crime (Money Laundering) and Terrorist Financing Act | Act | 2000 | FINTRAC | Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) is the most si… | official |
Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) is the most significant legislation at the federal level in Canada regarding the problem of money laundering and terrorist financing; the agency that regulates it is the Department of Finance, and it is administered by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC). The legislation took effect in the year 2000, and its efforts aim to prevent and detect criminal activities through strict compliance and identification, along with transaction monitoring requirements that have to be complied with by so-called "reporting entities," including banks, insurance companies, securities dealers, and virtual currency businesses. The PCMLTFA mandates businesses to create a comprehensive five-step compliance program, which includes designation of a compliance officer, creation of policies, performing risk assessment, training of employees, and biannual audits, along with reporting of suspicious activities and transactions of more than 10,000 Canadian dollars. Thus, this legislation ensures that the ultimate responsibility for total control falls upon the business organization for the transparency of the financial system. | |||||
| Bank Act | Act | 1991 | — | Banking Act is the Canadian federal law that regulates the activities of the banking indu… | official |
Banking Act is the Canadian federal law that regulates the activities of the banking industry in Canada, the regulation of whose financial safety, capital adequacy, and consumer protection is carried out mostly through OSFI and FCAC respectively. Originally enacted in 1871 and revised in 1991, the Act determines the way how banks should be operating and prohibits them from carrying out any prohibited commercial operations ensuring deposit insurance at the same time. In order to keep up with the modern financial environment, the Banking Act has its own special sunset clause in the form of periodic review and renewal of the Act until June 30, 2033. | |||||
| Securities Act (Ontario) | Act | 1990 | OSC | The Securities Act (Ontario) is the main provincial legislation that governs capital mark… | official |
The Securities Act (Ontario) is the main provincial legislation that governs capital markets, securities, and financial institutions in the province of Ontario, and is enforced and regulated by the autonomous Ontario Securities Commission (OSC). Passed in 1945 and consolidated into law in 1990, the Act enforces market integrity and safeguards the interests of investors via three principal regulatory pillars: mandatory registration of all market players, full and clear disclosure of pertinent financial information to the public, and strong regulatory powers to deal with insider trading or market manipulation. Since Canada operates under a system of securities regulation on a provincial basis, and not through an autonomous federal body, these are the laws applicable to anyone raising capital and providing investment advice in Toronto's financial market. | |||||
| No instruments match these filters. | |||||