Canada

CA · CAN · Americas · Last verified 10 Sep 2026

5 regulators · 6 instruments · 1 upcoming deadline

Canada — hero image

Guideline 2023

OSFI Guideline B-10 — Third-Party Risk Management

Issued by Office of the Superintendent of Financial Institutions

Effective: 1 May 2024

Plain-English summary

OSFI Guideline B-10 refers to the regulatory regime that has been established by the Office of the Superintendent of Financial Institutions (OSFI) in Canada. It obligates federally regulated financial institutions (FRFIs) to effectively manage and mitigate any risks associated with their vendors. Contrary to the conventional regulations, which only concern themselves with outsourcing, this guideline takes a broad, lifecycle, and principles-based approach to all third-party relationships, regardless of the type of service that is being outsourced. The guideline focuses on six expected outcomes that seek to ensure operational and financial resilience. These include implementation of an effective governance strategy, strong cybersecurity, performance monitoring, and exit planning. The responsibility of protecting customers’ information and the integrity of the systems against risks emanating from third parties lies squarely on the shoulders of senior management.

Who it applies to

Banking · Insurance

Topics

Operational Risk & Outsourcing

Official source

Latest news

No related news yet. We publish updates as regulators act.

Browse all newsSubscribe for updates