Who this applies to
Federally regulated financial institutions such as banks and insurers, and the service providers they depend on.
What to know
- It covers three areas: governance and risk management, technology operations and resilience, and cyber security.
- It is outcome based. Institutions decide how to meet each expectation in proportion to their size and risk.
- Third-party and cloud arrangements fall inside its scope, so suppliers get asked to prove their controls.
- It works alongside separate OSFI expectations for reporting technology and cyber incidents.
What to do
- If you supply a regulated institution, expect due diligence questions that mirror the guideline and prepare evidence in advance.
- Read the incident reporting expectations alongside the guideline, not separately.
This guide is a plain-language summary for general information. It is not legal advice and it does not replace the official source. Requirements change, so check the linked source before you act.