Sentrix

Breakdown · Finance

OSFI B-13: what the board and the regulator expect

OSFI Guideline B-13 sets the technology and cyber risk expectations for federally regulated financial institutions. Three domains, evidence, board questions.

By Sentrix · Published 2026-09-20

Since Guideline B-13 of the Office of the Superintendent of Financial Institutions (OSFI) came into force, the question the board of directors and the supervisor put to a federally regulated financial institution is no longer "is your cyber security sufficient?" but "can you demonstrate, domain by domain, that the expectations are covered?". This article summarizes what the text says and what you must be able to show.

What the guideline says

OSFI released the final version of B-13 in a letter dated July 13, 2022, with an effective date of January 1, 2024 to give institutions time to self-assess. The guideline applies to all federally regulated financial institutions: banks, foreign bank branches, life and property and casualty insurers, foreign insurance branches, trust and loan companies.

The text is organized in three domains, each with an expected outcome.

Governance and risk management. The intended outcome is that technology and cyber risks are governed through clear accountabilities and structures, and comprehensive strategies and frameworks. Senior management is accountable for directing technology and cyber security operations and must assign responsibility to qualified senior officers, for example a chief information officer or a chief information security officer. The institution must have a technology and cyber strategy aligned with the business strategy, with measurable objectives, and a risk management framework that defines risk appetite, identifies, assesses, monitors and reports.

Technology operations and resilience. The intended outcome is a technology environment that is stable, scalable and resilient, kept current and supported by robust recovery processes. The expectations cover an updated inventory of all technology assets supporting business processes, patch management processes ensuring the controlled and timely application of patches, the detection, logging and resolution of incidents with periodic exercises based on plausible scenarios, and an enterprise disaster recovery program tested on severe but plausible scenarios, including integration points with critical third parties.

Cyber security. The intended outcome is to maintain the confidentiality, integrity and availability of technology assets. The guideline follows five verbs: identify (threat assessments, intelligence-led testing, regular vulnerability assessments), defend (secure-by-design practices, multiple layers of controls, risk-based identity and access controls with multi-factor authentication, protection of data at rest, in transit and in use), detect (continuous security logging, detection of malicious activity, rapid triage of high-risk alerts), respond and recover (an incident response team available continuously, an incident taxonomy, investigations and root cause analysis for material incidents).

Added to this is OSFI's Technology and Cyber Security Incident Reporting Advisory, effective August 13, 2021 according to the text: any incident meeting one of the listed criteria (impact on the confidentiality, integrity or availability of customer information, disruption of critical systems, activation of the incident management team, reporting to the board or another authority, among others) must be reported within twenty-four hours, or sooner if possible, then followed by regular updates. The advisory states that failure to report may result in increased supervisory oversight, watch-listing or staging.

Why it matters

B-13 does not ask for exotic new controls. It asks for evidence. The difference shows during a supervisory review or a risk committee meeting: an updated asset inventory with owners, a patching dashboard by criticality, a recovery exercise report with the gaps and their follow-up, an incident register with the decision to report or not and its reason.

For the board, the guideline has an indirect but concrete effect: senior management must be able to answer, and directors must understand technology risk well enough to ask the right questions. An annual "awareness" presentation is not evidence; a quarterly report with measurable indicators is.

What we think at Sentrix

Most institutions we see already have most of the controls. What is missing is the mapping between those controls and the expectations of the text, and the discipline of evidence. In order:

  1. Map B-13 onto your existing framework. If you are certified to ISO 27001:2022, the asset inventory (5.9), management of technical vulnerabilities (8.8), logging and monitoring (8.15 and 8.16), incident management (5.24 to 5.28) and ICT readiness for business continuity (5.30) cover a large part of the expectations. The rest gets listed.
  2. Name an owner per expectation, not per domain. An expectation is one person who produces the evidence.
  3. Set the indicators the board will see every quarter: assets without an owner, critical patches past due, incidents reported to OSFI and reporting delay, last recovery exercise and open gaps.
  4. Test severe but plausible scenarios, as the text requires: loss of a cloud provider, ransomware on the backups, compromise of a privileged account. Document the gaps and the closure dates.
  5. Align the reporting process with the two regimes that often apply at the same time: OSFI's advisory and, for personal information, PIPEDA and Law 25.
  6. Extend the expectations to critical third parties through contracts and annual reviews, since B-13 explicitly refers to integration points with those third parties.

Our page on OSFI details the mappings; our cybersecurity posture assessment starts from the text of B-13 when the client is subject to it.

The next step

Take the list of B-13 expectations and, for each one, write the name of the document that proves it. The empty lines are your work plan. If you want us to run the exercise with you, contact us.

Sources

Frequently asked questions

Who does Guideline B-13 apply to?
All federally regulated financial institutions: banks, foreign bank branches, life insurance companies, property and casualty insurers, foreign insurance branches, trust and loan companies. OSFI's letter of July 2022 sets the effective date at January 1, 2024. The vendors of these institutions are not covered directly, but they receive the same expectations through contracts.
What do the three domains of B-13 cover?
Governance and risk management: clear accountabilities, a technology strategy aligned with the business, a risk framework with a defined appetite. Technology operations and resilience: asset inventory, patching, incident management, a disaster recovery program tested on severe but plausible scenarios. Cyber security: identify, defend, detect, respond and recover, with continuous logging and an incident response team.
What is the deadline for reporting an incident to OSFI?
OSFI's incident reporting advisory requires reporting to the Technology Risk Division and the Lead Supervisor within twenty-four hours, or sooner if possible, followed by regular updates until resolution. The advisory lists the criteria that make an incident reportable, including an impact on customer information and the activation of the incident management team.

Let's talk about your compliance program.

Last updated: 2026-09-20