home / frameworks / osfi-b-13

// Canadian sector regulators

OSFI Guideline B-13, Technology and Cyber Risk Management

OSFI's guideline on technology and cyber risk for federally regulated banks, insurers, and trust and loan companies, in effect since January 1, 2024. It sets 17 principles in 3 domains covering governance, technology operations and resilience, and cyber security.

Canada (federal)

Overview

Guideline B-13 sets out what OSFI expects from federally regulated financial institutions (FRFIs) when they manage technology and cyber risks such as data breaches and technology outages. OSFI released the final guideline in July 2022 and made it effective on January 1, 2024, so institutions had time to self-assess. It's principles-based. Each institution applies it in proportion to its size, the nature and complexity of its operations, and its risk profile. In February 2024 OSFI amended the text to clarify how it applies to foreign bank and foreign insurance branches, without changing its practical effect.

The guideline has 3 domains, each with a stated outcome. Governance and risk management asks for clear accountability, a technology and cyber strategy, and a risk management framework. Technology operations and resilience covers architecture, asset inventories, project management, the system development life cycle, change and patch management, incident management, service measurement, and disaster recovery. Cyber security is organized as identify, defend, detect, and respond, recover and learn. In all, the domains hold 17 principles.

B-13 links to OSFI's Technology and Cyber Security Incident Reporting Advisory, in place since August 2021. Under the advisory an institution reports a qualifying incident to OSFI's Technology Risk Division and its lead supervisor within 24 hours, or sooner if possible, then sends regular updates. B-13 also works alongside Guideline B-10 on third-party risk and Guideline E-21 on operational resilience. Suppliers don't report to OSFI. They meet B-13 through contract terms, security reviews, and audit requests from their financial clients, and OSFI's 2026 technology risk bulletins on artificial intelligence apply the same 3 guidelines to new threats.

Who it applies to in Canada

All federally regulated financial institutions (FRFIs), including banks, foreign bank branches, life and property and casualty insurers, foreign insurance branches, and trust and loan companies.

OSFI is the federal prudential regulator for banks and federally regulated insurers, so B-13 is a direct supervisory expectation for them. Technology vendors, cloud providers, and managed security firms meet it indirectly through their FRFI clients' contracts, questionnaires, and audits.

Controls at a glance

B-13 groups 17 principles into 3 domains. The second domain is shown here in 2 parts.

Domain 1, Governance and risk management (principles 1 to 3)

  • Senior management assigns accountability for technology and cyber risk
  • Documented technology and cyber strategy tied to business strategy
  • Enterprise framework to identify, assess, and manage these risks
  • Defined risk appetite with regular reporting
  • Proportionate application based on size and risk profile

Domain 2, Technology operations (principles 4 to 9)

  • Technology architecture framework
  • Current inventory of technology assets
  • Governed technology projects
  • System development life cycle with security built in
  • Change and release management
  • Timely patch management

Domain 2, Technology resilience (principles 10 to 13)

  • Detect, manage, and report technology incidents
  • Measure and monitor technology service performance
  • Enterprise disaster recovery program
  • Scenario testing of disaster recovery capabilities

Domain 3, Cyber security (principles 14 to 17)

  • Identify and assess cyber weaknesses and threats
  • Multi-layer preventive controls
  • Continuous security monitoring and detection
  • Respond to, recover from, and learn from cyber incidents
  • Protect confidentiality, integrity, and availability of technology assets

Incident reporting (linked advisory)

  • Report qualifying incidents to OSFI within 24 hours
  • Notify the Technology Risk Division and lead supervisor in writing
  • Send regular updates until the incident is closed
  • Criteria include high-severity incidents and cyber insurance claims

Certification and assessment

OSFI assesses adherence through ongoing supervision, targeted technology and cyber reviews, and intelligence-led cyber resilience testing. There is no certification. Institutions can use OSFI's voluntary technology and cyber risk management self-assessment tool, updated in November 2025, to rate the maturity of each control on a 0 to 5 scale and find gaps.

Dates to know

2021-08-13
Updated Technology and Cyber Security Incident Reporting Advisory takes effect
2022-07-13
OSFI releases final Guideline B-13
2024-01-01
Guideline B-13 becomes effective
2024-02-22
Consequential amendments clarify application to foreign branches
2025-11-03
OSFI publishes updated technology and cyber risk self-assessment tool

Resources

Official texts and free tools for OSFI B-13. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Technology and Cyber Risk Management (Guideline B-13), Office of the Superintendent of Financial Institutions (OSFI)
  2. OSFI releases final Guideline B-13, Technology and Cyber Risk Management (letter), Office of the Superintendent of Financial Institutions (OSFI)
  3. Technology and Cyber Security Incident Reporting Advisory, Office of the Superintendent of Financial Institutions (OSFI)
  4. Consequential amendments to Guidelines B-10 and B-13 related to foreign branches, Office of the Superintendent of Financial Institutions (OSFI)