Canada

CA · CAN · Americas · Last verified 10 Sep 2026

5 regulators · 6 instruments · 1 upcoming deadline

Canada — hero image

Guideline 2022

OSFI Guideline B-13 — Technology and Cyber Risk Management

Issued by Office of the Superintendent of Financial Institutions

Effective: 1 Jan 2024

Plain-English summary

Guideline B-13 of OSFI is an all-encompassing regulatory framework published by Canada's Office of the Superintendent of Financial Institutions (OSFI) requiring federally regulated financial institutions (FRFIs) to develop effective operational strategies to protect themselves from the rising threat of technology and cybersecurity risks. Divided into three key pillars – Governance and Risk Management, Technology Operations and Resilience, and Cyber Security – the guideline takes the regulatory perspective from being based on technical checkmarks and makes it an outcomes-based approach to risk management. The guideline places full responsibility on the shoulders of senior management and boards to establish risk appetites for cyber threats, safeguard digital assets, ensure data confidentiality, and enforce identity management. Moreover, by integrating itself with the third-party requirements in Guideline B-10, it ensures that the threat management, incident response, and disaster recovery testing by an institution extends beyond its vendor and cloud ecosystem.

Who it applies to

Banking · Insurance

Topics

Cybersecurity & IT Risk

Official source

Latest news

No related news yet. We publish updates as regulators act.

Browse all newsSubscribe for updates