home / frameworks / amf-guideline

// Canadian sector regulators

AMF Guideline on Information and Communications Technology Risk Management

The AMF's expectations for how Quebec insurers, financial services cooperatives, and trust and deposit institutions manage technology and cyber risk. Since April 23, 2025 a separate regulation also requires incident policies, 24-hour incident reports to the AMF, and an incident register.

Quebec

Overview

The AMF published its Guideline on Information and Communications Technology Risk Management in February 2020 and expected institutions to adopt and apply it by February 27, 2021. It defines ICT risk broadly. It includes availability, continuity, security (including cybersecurity), change, data integrity, and outsourcing risk. The stated aim is basic security hygiene, such as timely patching, network monitoring, access management, strong authentication for sensitive systems, and malware monitoring, to prevent a major incident and limit its effect. Each institution applies it in light of its nature, size, complexity, and risk profile.

The guideline has 3 parts. The first asks for a forward-looking taxonomy of ICT risks. The second covers ICT governance, with roles for the board, senior management, and other functions, integrity and competency, and ICT documentation. The third covers ICT risk management in 3 stages, named preparation, treatment, and follow-up. An appendix sets out practices for ICT security, ICT operations, outsourcing and cloud computing, and change projects. On cloud, institutions should secure audit rights, encrypt data, manage subcontracting chains, plan exits, and watch concentration risk.

Incident reporting has a legal basis too. The Regulation respecting the management and reporting of information security incidents by certain financial institutions and by credit assessment agents was published in October 2024 and has applied since April 23, 2025. Institutions need an incident management policy and a designated person in charge. They must report incidents with potential adverse impacts to the AMF within 24 hours, update the AMF every 3 days, file a closing report within 30 days, and keep an incident register for at least 5 years. The AMF also issued a Third-Party Risk Management Guideline dated March 2026 to replace its outsourcing guideline. Its draft proposed an April 1, 2027 effective date, which we couldn't confirm on the final text.

Who it applies to in Canada

Financial institutions under AMF prudential oversight, including authorized insurers, financial services cooperatives, trust companies, and savings companies and other deposit institutions. The incident regulation also covers designated credit assessment agents.

The AMF is Quebec's integrated financial regulator, so Quebec-chartered insurers, caisses, and trust companies answer to it rather than to OSFI. Technology suppliers to these institutions meet the guideline through outsourcing and cloud terms, audit rights, and security assurance requests.

Controls at a glance

The guideline is organized in 3 sections plus an appendix of practices, and the 2025 regulation adds binding incident duties.

Types of ICT risks (section 1)

  • Forward-looking taxonomy of all ICT risk types
  • Consider technology governance, positioning, and implementation risk
  • Aggregate ICT risks with other enterprise risks
  • Use clear, consistent ICT risk terminology

ICT governance (section 2)

  • Board oversight of ICT strategy and risk
  • Senior management accountability and reporting to the board
  • Information security function independent of ICT operations
  • Integrity and competency of ICT staff
  • Current ICT documentation
  • Internal audit review of ICT controls

ICT risk management, preparation (section 3.1)

  • Inventory information assets and their vulnerabilities
  • Classify data by availability, integrity, and confidentiality needs
  • Business impact analysis for important processes
  • Plausible disaster and cyber scenarios in continuity plans
  • Tested backups with set recovery times

ICT risk management, treatment and follow-up (sections 3.2 and 3.3)

  • Select controls for each identified risk
  • Manage legacy systems and shadow IT
  • Incident management with escalation and recovery
  • Analysis after major incidents
  • Track remediation and lessons learned

ICT security and operations (appendix)

  • Identity and access management with least privilege
  • Security training and awareness
  • Security event logging and monitoring
  • Periodic independent testing of security controls
  • Configuration and change management

Outsourcing, cloud, and change projects (appendix)

  • Contractual audit and access rights with cloud suppliers
  • Encryption of data in transit, in memory, and at rest
  • Manage subcontracting and concentration risk
  • Exit strategies without service disruption
  • Security by design in ICT projects

Incident management and reporting regulation (2025)

  • Incident management policy with detection and response procedures
  • Designated person responsible for incidents
  • Report incidents with potential adverse impacts within 24 hours
  • Updates to the AMF every 3 days
  • Closing report within 30 days
  • Incident register kept at least 5 years

Certification and assessment

The AMF reviews how institutions apply its guidelines through ongoing supervision and inspections. There's no certification. Incident reports go to the AMF under the 2025 regulation, and an institution that fails to manage, report, or record incidents as required can face administrative penalties.

Dates to know

2020-02
AMF publishes the Guideline on ICT Risk Management
2021-02-27
Institutions expected to have adopted the guideline
2024-10-23
Information security incident regulation published
2025-04-23
Incident management and reporting regulation comes into force
2026-03
AMF Third-Party Risk Management Guideline issued to replace the outsourcing guideline

Resources

Official texts and free tools for AMF ICT guideline. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Guideline on Information and Communications Technology Risk Management (PDF, February 2020), Autorité des marchés financiers (AMF)
  2. New security incident reporting obligations for certain financial institutions in Quebec, Torys LLP
  3. Higher standards are coming for financial institutions in Quebec, Borden Ladner Gervais LLP