home / frameworks / osfi-e-21

// Canadian sector regulators

OSFI Guideline E-21, Operational Risk Management and Resilience

OSFI's guideline on operational risk and operational resilience for federally regulated financial institutions. Published August 22, 2024, it was fully in effect by September 1, 2026, with the most important operations identified, mapped, and given tolerances for disruption.

Canada (federal)

Overview

Guideline E-21 updates OSFI's 2016 operational risk guideline and adds new expectations for operational resilience, business continuity, crisis management, change management, and data risk. OSFI published the final version on August 22, 2024. It defines operational risk as the risk of loss from people, inadequate or failed processes and systems, or external events. Operational resilience is the ability to deliver operations, especially critical operations, through disruption. The 2 ideas are linked. Resilience is built on sound operational risk management.

Compliance was phased. Sections 1 and 2, on governance and operational risk management, applied right away because they repeat long-standing expectations. Section 4, on specific risk areas, was due by September 1, 2025. Full adherence was due by September 1, 2026, by which point institutions should have identified their most important operations, mapped them, and set tolerances for disruption. OSFI accepts that resilience programs will keep maturing, and its 2026 to 2027 risk outlook says supervisors will test how ready institutions are.

The guideline has 8 principles. Principles 1 to 5 cover governance, an enterprise-wide framework, risk appetite, identification and assessment using tools such as risk and control assessments, key risk indicators, event data, and scenario analysis, and monitoring and reporting. Principles 6 to 8 cover resilience through mapping of internal and external dependencies, tolerances for disruption, and regular testing against severe but plausible scenarios. Testing closes the loop. Section 4 links to business continuity, disaster recovery, crisis management, change management, data risk, and the separate B-13 and B-10 guidelines.

Who it applies to in Canada

All federally regulated financial institutions (FRFIs), including banks, insurers, and foreign bank and insurance branches.

E-21 is OSFI's main expectation on operational resilience for Canadian banks and federally regulated insurers. Suppliers that support their important services are drawn into mapping, tolerance setting, and scenario testing.

Controls at a glance

E-21 has 8 principles across governance, operational risk management, and operational resilience, plus a section on specific risk areas.

Governance (section 1, principle 1)

  • Senior management oversight of operational risk and resilience
  • Business and central functions own their risks
  • Independent oversight of the risk framework
  • Independent assurance, such as internal audit

Operational risk framework and appetite (principles 2 and 3)

  • Enterprise-wide operational risk management framework
  • Defined operational risk appetite and limits
  • Framework documented and applied across the institution

Risk identification and assessment (principle 4)

  • Risk and control self-assessments
  • Risk indicators and thresholds
  • Collection of operational risk event data
  • Scenario analysis

Monitoring and reporting (principle 5)

  • Continuous monitoring to find control weaknesses
  • Reporting and escalation of appetite or limit breaches
  • Regular reports to senior management

Operational resilience (section 3, principles 6 to 8)

  • Identify the operations the institution most depends on
  • Map people, technology, processes, information, facilities, and third parties
  • Set tolerances for disruption of those operations
  • Test against severe but plausible scenarios
  • Fix weaknesses found in testing

Business continuity, recovery, and crisis (section 4)

  • Business impact analysis
  • Business continuity plans and testing
  • Disaster recovery risk management
  • Crisis management

Other risk areas (section 4)

  • Change management
  • Technology and cyber risk, linked to Guideline B-13
  • Third-party risk, linked to Guideline B-10
  • Data risk management

Certification and assessment

OSFI reviews each institution's operational risk framework, mapping, tolerances, and test results through ongoing supervision and targeted readiness work. There's no certification. Institutions show adherence through framework documentation, dependency maps, tolerance statements, scenario test results, and regular reporting to the board and senior management.

Dates to know

2024-08-22
Final Guideline E-21 published, sections 1 and 2 effective immediately
2025-09-01
Full adherence to section 4 expected
2026-09-01
Full adherence to the whole guideline expected

Resources

Official texts and free tools for OSFI E-21. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Operational Risk Management and Resilience Guideline (E-21), Office of the Superintendent of Financial Institutions (OSFI)
  2. Operational Risk Management and Resilience, letter to industry, Office of the Superintendent of Financial Institutions (OSFI)
  3. Backgrounder, Guideline E-21, Operational Risk and Resilience, Office of the Superintendent of Financial Institutions (OSFI)
  4. OSFI's Annual Risk Outlook, fiscal year 2026 to 2027, Office of the Superintendent of Financial Institutions (OSFI)