Overview
Guideline E-21 updates OSFI's 2016 operational risk guideline and adds new expectations for operational resilience, business continuity, crisis management, change management, and data risk. OSFI published the final version on August 22, 2024. It defines operational risk as the risk of loss from people, inadequate or failed processes and systems, or external events. Operational resilience is the ability to deliver operations, especially critical operations, through disruption. The 2 ideas are linked. Resilience is built on sound operational risk management.
Compliance was phased. Sections 1 and 2, on governance and operational risk management, applied right away because they repeat long-standing expectations. Section 4, on specific risk areas, was due by September 1, 2025. Full adherence was due by September 1, 2026, by which point institutions should have identified their most important operations, mapped them, and set tolerances for disruption. OSFI accepts that resilience programs will keep maturing, and its 2026 to 2027 risk outlook says supervisors will test how ready institutions are.
The guideline has 8 principles. Principles 1 to 5 cover governance, an enterprise-wide framework, risk appetite, identification and assessment using tools such as risk and control assessments, key risk indicators, event data, and scenario analysis, and monitoring and reporting. Principles 6 to 8 cover resilience through mapping of internal and external dependencies, tolerances for disruption, and regular testing against severe but plausible scenarios. Testing closes the loop. Section 4 links to business continuity, disaster recovery, crisis management, change management, data risk, and the separate B-13 and B-10 guidelines.
Who it applies to in Canada
All federally regulated financial institutions (FRFIs), including banks, insurers, and foreign bank and insurance branches.
E-21 is OSFI's main expectation on operational resilience for Canadian banks and federally regulated insurers. Suppliers that support their important services are drawn into mapping, tolerance setting, and scenario testing.
Controls at a glance
E-21 has 8 principles across governance, operational risk management, and operational resilience, plus a section on specific risk areas.
Governance (section 1, principle 1)
- Senior management oversight of operational risk and resilience
- Business and central functions own their risks
- Independent oversight of the risk framework
- Independent assurance, such as internal audit
Operational risk framework and appetite (principles 2 and 3)
- Enterprise-wide operational risk management framework
- Defined operational risk appetite and limits
- Framework documented and applied across the institution
Risk identification and assessment (principle 4)
- Risk and control self-assessments
- Risk indicators and thresholds
- Collection of operational risk event data
- Scenario analysis
Monitoring and reporting (principle 5)
- Continuous monitoring to find control weaknesses
- Reporting and escalation of appetite or limit breaches
- Regular reports to senior management
Operational resilience (section 3, principles 6 to 8)
- Identify the operations the institution most depends on
- Map people, technology, processes, information, facilities, and third parties
- Set tolerances for disruption of those operations
- Test against severe but plausible scenarios
- Fix weaknesses found in testing
Business continuity, recovery, and crisis (section 4)
- Business impact analysis
- Business continuity plans and testing
- Disaster recovery risk management
- Crisis management
Other risk areas (section 4)
- Change management
- Technology and cyber risk, linked to Guideline B-13
- Third-party risk, linked to Guideline B-10
- Data risk management
Certification and assessment
OSFI reviews each institution's operational risk framework, mapping, tolerances, and test results through ongoing supervision and targeted readiness work. There's no certification. Institutions show adherence through framework documentation, dependency maps, tolerance statements, scenario test results, and regular reporting to the board and senior management.
Dates to know
- 2024-08-22
- Final Guideline E-21 published, sections 1 and 2 effective immediately
- 2025-09-01
- Full adherence to section 4 expected
- 2026-09-01
- Full adherence to the whole guideline expected
Resources
Official texts and free tools for OSFI E-21. Links open the publisher’s site.
- Operational Risk Management and Resilience Guideline (E-21), Office of the Superintendent of Financial Institutions (OSFI)
- Operational Risk Management and Resilience, letter to industry, Office of the Superintendent of Financial Institutions (OSFI)
- Backgrounder, Guideline E-21, Operational Risk and Resilience, Office of the Superintendent of Financial Institutions (OSFI)guidance
- OSFI's Annual Risk Outlook, fiscal year 2026 to 2027, Office of the Superintendent of Financial Institutions (OSFI)guidance
Need help? Browse the directory or read the guides.
References
- Operational Risk Management and Resilience Guideline (E-21), Office of the Superintendent of Financial Institutions (OSFI)
- Operational Risk Management and Resilience, letter to industry, Office of the Superintendent of Financial Institutions (OSFI)
- Backgrounder, Guideline E-21, Operational Risk and Resilience, Office of the Superintendent of Financial Institutions (OSFI)
- OSFI's Annual Risk Outlook, fiscal year 2026 to 2027, Office of the Superintendent of Financial Institutions (OSFI)
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.