Overview
The AMF published its Guideline on Information and Communications Technology Risk Management in February 2020 and expected institutions to adopt and apply it by February 27, 2021. It defines ICT risk broadly. It includes availability, continuity, security (including cybersecurity), change, data integrity, and outsourcing risk. The stated aim is basic security hygiene, such as timely patching, network monitoring, access management, strong authentication for sensitive systems, and malware monitoring, to prevent a major incident and limit its effect. Each institution applies it in light of its nature, size, complexity, and risk profile.
The guideline has 3 parts. The first asks for a forward-looking taxonomy of ICT risks. The second covers ICT governance, with roles for the board, senior management, and other functions, integrity and competency, and ICT documentation. The third covers ICT risk management in 3 stages, named preparation, treatment, and follow-up. An appendix sets out practices for ICT security, ICT operations, outsourcing and cloud computing, and change projects. On cloud, institutions should secure audit rights, encrypt data, manage subcontracting chains, plan exits, and watch concentration risk.
Incident reporting has a legal basis too. The Regulation respecting the management and reporting of information security incidents by certain financial institutions and by credit assessment agents was published in October 2024 and has applied since April 23, 2025. Institutions need an incident management policy and a designated person in charge. They must report incidents with potential adverse impacts to the AMF within 24 hours, update the AMF every 3 days, file a closing report within 30 days, and keep an incident register for at least 5 years. The AMF also issued a Third-Party Risk Management Guideline dated March 2026 to replace its outsourcing guideline. Its draft proposed an April 1, 2027 effective date, which we couldn't confirm on the final text.
Who it applies to in Canada
Financial institutions under AMF prudential oversight, including authorized insurers, financial services cooperatives, trust companies, and savings companies and other deposit institutions. The incident regulation also covers designated credit assessment agents.
The AMF is Quebec's integrated financial regulator, so Quebec-chartered insurers, caisses, and trust companies answer to it rather than to OSFI. Technology suppliers to these institutions meet the guideline through outsourcing and cloud terms, audit rights, and security assurance requests.
Controls at a glance
The guideline is organized in 3 sections plus an appendix of practices, and the 2025 regulation adds binding incident duties.
Types of ICT risks (section 1)
- Forward-looking taxonomy of all ICT risk types
- Consider technology governance, positioning, and implementation risk
- Aggregate ICT risks with other enterprise risks
- Use clear, consistent ICT risk terminology
ICT governance (section 2)
- Board oversight of ICT strategy and risk
- Senior management accountability and reporting to the board
- Information security function independent of ICT operations
- Integrity and competency of ICT staff
- Current ICT documentation
- Internal audit review of ICT controls
ICT risk management, preparation (section 3.1)
- Inventory information assets and their vulnerabilities
- Classify data by availability, integrity, and confidentiality needs
- Business impact analysis for important processes
- Plausible disaster and cyber scenarios in continuity plans
- Tested backups with set recovery times
ICT risk management, treatment and follow-up (sections 3.2 and 3.3)
- Select controls for each identified risk
- Manage legacy systems and shadow IT
- Incident management with escalation and recovery
- Analysis after major incidents
- Track remediation and lessons learned
ICT security and operations (appendix)
- Identity and access management with least privilege
- Security training and awareness
- Security event logging and monitoring
- Periodic independent testing of security controls
- Configuration and change management
Outsourcing, cloud, and change projects (appendix)
- Contractual audit and access rights with cloud suppliers
- Encryption of data in transit, in memory, and at rest
- Manage subcontracting and concentration risk
- Exit strategies without service disruption
- Security by design in ICT projects
Incident management and reporting regulation (2025)
- Incident management policy with detection and response procedures
- Designated person responsible for incidents
- Report incidents with potential adverse impacts within 24 hours
- Updates to the AMF every 3 days
- Closing report within 30 days
- Incident register kept at least 5 years
Certification and assessment
The AMF reviews how institutions apply its guidelines through ongoing supervision and inspections. There's no certification. Incident reports go to the AMF under the 2025 regulation, and an institution that fails to manage, report, or record incidents as required can face administrative penalties.
Dates to know
- 2020-02
- AMF publishes the Guideline on ICT Risk Management
- 2021-02-27
- Institutions expected to have adopted the guideline
- 2024-10-23
- Information security incident regulation published
- 2025-04-23
- Incident management and reporting regulation comes into force
- 2026-03
- AMF Third-Party Risk Management Guideline issued to replace the outsourcing guideline
Resources
Official texts and free tools for AMF ICT guideline. Links open the publisher’s site.
- Guideline on Information and Communications Technology Risk Management, Autorité des marchés financiers (AMF)
- Guideline on Information and Communications Technology Risk Management (PDF, February 2020), Autorité des marchés financiers (AMF)
- Third-Party Risk Management Guideline (March 2026), Autorité des marchés financiers (AMF)
- Application and implementation guide, information security incident regulation (July 2025), Autorité des marchés financiers (AMF)guidance
- New security incident reporting obligations for certain financial institutions in Quebec, Torys LLPguidance
Need help? Browse the directory or read the guides.
References
- Guideline on Information and Communications Technology Risk Management (PDF, February 2020), Autorité des marchés financiers (AMF)
- New security incident reporting obligations for certain financial institutions in Quebec, Torys LLP
- Higher standards are coming for financial institutions in Quebec, Borden Ladner Gervais LLP
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.