home / frameworks / osfi-b-10

// Canadian sector regulators

OSFI Guideline B-10, Third-Party Risk Management

OSFI's guideline on managing risk from vendors, cloud providers, and other third parties, in effect since May 1, 2024. It sets 6 outcomes and 11 principles, and its security, audit, and incident terms flow down to suppliers of Canadian banks and insurers.

Canada (federal)

Overview

Guideline B-10 replaced OSFI's older outsourcing guidance with a wider view of third-party risk. OSFI published the final version on April 24, 2023 and it took effect on May 1, 2024. Arrangements that start on or after that date must follow it. Older arrangements were to be reviewed and updated at the earliest renewal or revision point, by the effective date or as soon as possible after. Foreign bank and insurance branches had until March 31, 2025. It covers far more than outsourcing. The FRFI stays accountable for every arrangement, from cloud services to consultants.

The guideline sets 6 outcomes and 11 principles across 4 sections. Governance covers accountability and a third-party risk management framework. Management of third-party risk covers risk assessment, due diligence, subcontracting, written agreements, data protection, access to information, business continuity, monitoring, and incidents. A section on special arrangements deals with standard contracts, arrangements without a written contract, and services from the external auditor. The last section adds expectations for technology and cyber risk, including cloud. Annexes add checklists. They list due diligence factors and contract provisions for higher-risk arrangements.

For suppliers, B-10 shows up as questionnaires, evidence requests, and contract clauses. The requests can be detailed. FRFIs expect providers with higher technology and cyber risk to meet the FRFI's own standards or recognized industry standards, often shown with independent reports or pooled audits. Contracts typically cover roles for technology and cyber controls, data security and confidentiality, subcontracting limits and notice, audit and access rights, incident notification fast enough for the FRFI to meet OSFI's 24-hour reporting expectation, business continuity testing, and exit. OSFI's 2026 to 2027 risk outlook plans targeted work on third-party risk management and a fourth third-party data call.

Who it applies to in Canada

All federally regulated financial institutions (FRFIs) and every type of third-party arrangement they use, scaled to the risk and criticality of each arrangement. Suppliers to banks and insurers feel it through due diligence, contract terms, and monitoring.

Canadian software, cloud, payments, and managed service firms that sell to banks, insurers, or trust and loan companies are asked to meet B-10 terms on security, audit rights, incident notice, subcontracting, and exit. The same expectations reach foreign providers serving Canadian FRFIs.

Controls at a glance

B-10 has 11 principles grouped under its 4 sections, with Annex 2 listing contract provisions.

Governance (principles 1 and 2)

  • FRFI remains accountable for all third-party arrangements
  • Third-party risk management framework with clear accountabilities
  • Inventory of third parties by risk level
  • Proportionate approach based on arrangement risk

Risk identification and assessment (principles 3 to 5)

  • Assess risk before entering and periodically after
  • Due diligence proportionate to the arrangement's risk
  • Assess concentration risk across providers
  • Identify and manage subcontractor risk

Risk management and mitigation (principles 6 to 9)

  • Written agreements setting rights and responsibilities
  • Protect confidentiality, integrity, and availability of records and data
  • Timely access to information and audit rights
  • Business continuity and disaster recovery through disruption
  • Exit plans that avoid service disruption

Monitoring and reporting (principles 10 and 11)

  • Ongoing monitoring of performance and risk
  • Documented incident processes at both parties
  • Timely incident notice from the third party
  • Root cause analysis and remediation tracking

Special arrangements

  • Assess and accept risk on standard non-negotiable contracts
  • Cover arrangements that have no written contract
  • Keep external auditor services independent

Technology and cyber risk in third-party arrangements

  • Detailed split of technology and cyber control duties
  • Providers meet FRFI or recognized industry security standards
  • Cloud requirements on data protection and key management
  • Cloud portability and concentration risk planning
  • Third-party incidents support OSFI incident reporting

Contract provisions for higher-risk arrangements (Annex 2)

  • Scope of services and performance measures
  • Data security and confidentiality terms
  • Subcontracting limits and notification
  • Incident notification duties
  • Business continuity and disaster recovery requirements
  • Audit, access, default, termination, and dispute terms
  • Insurance requirements

Certification and assessment

OSFI reviews each institution's third-party framework, inventory, and oversight through supervision and data calls. FRFIs in turn assess suppliers through due diligence, contract terms, monitoring, independent reports such as SOC 2, and pooled or direct audits. There is no B-10 certification.

Dates to know

2023-04-24
OSFI publishes final Guideline B-10
2024-02-22
Consequential amendments clarify application to foreign branches
2024-05-01
Guideline B-10 takes effect for new arrangements
2025-03-31
Foreign bank and insurance branches expected to comply

Resources

Official texts and free tools for OSFI B-10. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Third-Party Risk Management Guideline (B-10), Office of the Superintendent of Financial Institutions (OSFI)
  2. OSFI response to draft Guideline B-10 consultation feedback, Office of the Superintendent of Financial Institutions (OSFI)
  3. OSFI announces new guideline to manage third-party risk, Office of the Superintendent of Financial Institutions (OSFI)
  4. Consequential amendments to Guidelines B-10 and B-13 related to foreign branches, Office of the Superintendent of Financial Institutions (OSFI)