Guideline 2023
OSFI Guideline B-10 — Third-Party Risk Management
Issued by Office of the Superintendent of Financial Institutions
Effective: 1 May 2024
Plain-English summary
OSFI Guideline B-10 refers to the regulatory regime that has been established by the Office of the Superintendent of Financial Institutions (OSFI) in Canada. It obligates federally regulated financial institutions (FRFIs) to effectively manage and mitigate any risks associated with their vendors. Contrary to the conventional regulations, which only concern themselves with outsourcing, this guideline takes a broad, lifecycle, and principles-based approach to all third-party relationships, regardless of the type of service that is being outsourced. The guideline focuses on six expected outcomes that seek to ensure operational and financial resilience. These include implementation of an effective governance strategy, strong cybersecurity, performance monitoring, and exit planning. The responsibility of protecting customers’ information and the integrity of the systems against risks emanating from third parties lies squarely on the shoulders of senior management.
Who it applies to
Banking · Insurance
Topics
Operational Risk & Outsourcing
Latest news
No related news yet. We publish updates as regulators act.