OSFI Guideline B-13 is The Office of the Superintendent of Financial Institutions' guideline on Technology and Cyber Risk Management. It sets supervisory expectations for how federally regulated financial institutions in Canada govern, operate, and secure their technology, and it has been in effect since January 1, 2024.
What OSFI B-13 requires
B-13 is principles-based and outcome-focused: OSFI expects each institution to manage technology and cyber risk in a way that is proportionate to its size, risk profile, and complexity, rather than checking a fixed list. The guideline is organized around three domains, and you should be able to demonstrate sound practice in all three.
Governance and Risk Management
Formal accountability, leadership, organizational structure, and the framework used to support oversight of technology and cyber risk. Senior management and the board must be able to see and own the risk.
Technology Operations and Resilience
Management and oversight of the design, implementation, management, and recovery of technology assets and services, so critical operations keep running and can recover from disruption.
Cyber Security
Management and oversight of cyber risk across defence, detection, response, and recovery, proportionate to the institution's size, risk profile, and complexity.
OSFI also publishes a technology and cyber risk management self-assessment tool that institutions use to gauge readiness. You can read the guideline and the tool directly on the OSFI guidance library (osfi-bsif.gc.ca).
Who must comply in Canada
B-13 applies to all federally regulated financial institutions: banks, federally regulated trust and loan companies, and insurers, plus foreign bank branches and foreign insurance company branches operating in Canada. Provincially regulated institutions such as credit unions are not directly in scope, though many adopt B-13 as a best-practice baseline because their enterprise clients and partners increasingly expect it. B-13 is also closely related to OSFI's Third-Party Risk Management Guideline (B-10), so most FRFIs run the two together.
How SecuritComply helps you get B-13 ready
- The three B-13 domains mapped to concrete, owned, trackable controls
- Evidence repository, keep policies, logs, and artifacts organized and audit-ready
- Risk register with likelihood x impact scoring and documented treatment plans
- Third-party and cloud risk management, aligned with OSFI B-10
- Incident and resilience documentation for the recovery expectations in Domain 2
- Cross-mapping to PCI-DSS, SOC 2, and ISO 27001 so you do the work once
- Canadian data residency, your records never leave Canadian servers
OSFI B-13 readiness checklist
A practical starting point for B-13 readiness:
- Assign board and senior-management accountability for technology and cyber risk.
- Document your technology and cyber risk management framework and risk appetite.
- Build a current inventory of technology assets, services, and their criticality.
- Set resilience and recovery objectives for critical operations, and test them.
- Stand up cyber defence, detection, response, and recovery capabilities.
- Assess and monitor third-party and cloud providers (align with OSFI B-10).
- Run the OSFI self-assessment and close the gaps it surfaces.
- Keep evidence organized so you can respond to supervisory review quickly.
Most FRFIs carry B-13 alongside other obligations. See how it fits with SOC 2, ISO 27001, and the full picture on our financial services use case.
OSFI B-13 compliance FAQ
What is OSFI Guideline B-13?▾
OSFI Guideline B-13, Technology and Cyber Risk Management, sets the Office of the Superintendent of Financial Institutions' expectations for how federally regulated financial institutions manage technology and cyber risk. It is organized around three domains: Governance and Risk Management, Technology Operations and Resilience, and Cyber Security. It came into effect on January 1, 2024.
Who must comply with OSFI B-13?▾
B-13 applies to all federally regulated financial institutions (FRFIs) in Canada, including banks, federally regulated trust and loan companies, and insurers, as well as foreign bank branches and foreign insurance company branches operating in Canada, to the extent consistent with their legal obligations. Provincially regulated institutions such as credit unions are not directly in scope, though many adopt B-13 as best practice.
When did OSFI B-13 take effect?▾
OSFI released the final guideline in 2022 and gave institutions time to self-assess and prepare. B-13 became effective on January 1, 2024. FRFIs are expected to be able to demonstrate sound technology and cyber risk management across the three domains from that date onward.
What are the three domains of OSFI B-13?▾
Domain 1, Governance and Risk Management, covers accountability, leadership, organizational structure and the framework used to oversee technology and cyber risk. Domain 2, Technology Operations and Resilience, covers the design, implementation, management and recovery of technology assets and services. Domain 3, Cyber Security, covers the management and oversight of cyber risk, including defence, detection, response and recovery.
How does SecuritComply help with OSFI B-13?▾
SecuritComply lets you map the three B-13 domains to concrete, owned controls, store the evidence supervisors expect in one place, run a risk register with treatment plans, and manage third-party and cloud risk, all with your data kept in Canada. It also aligns naturally with the frameworks FRFIs run alongside B-13, such as PCI-DSS, SOC 2, and ISO 27001.
General information, not legal or regulatory advice. Supervisory expectations are set by OSFI and depend on your institution. Confirm your obligations with OSFI guidance and your own advisors.