Sentrix

Framework · OSFI B-10 / B-13

OSFI B-10 and B-13: outsourcing, technology and cyber risk

OSFI guidelines on outsourcing (B-10) and technology and cyber risk management (B-13) for Canada's federally regulated financial institutions, in one program.

The Office of the Superintendent of Financial Institutions (OSFI) supervises Canada's federally regulated financial institutions: banks, insurers, trust companies. Guideline B-10 governs outsourcing arrangements and third-party relationships; guideline B-13 sets expectations for technology and cyber risk management, aligned to the NIST CSF structure but with OSFI-specific expectations, including Board oversight.

Key facts

  • FRFIs: all federally regulated financial institutions are subject to B-10 and B-13.
  • 5 domains: B-13 structures its expectations in five domains, from governance to data risk management.
  • Board: B-13 requires Board-level technology risk oversight and regular Board reporting.
  • Concentration: B-10 requires concentration risk analysis for material outsourcing arrangements.

What B-10 and B-13 require

B-10 requires FRFIs to maintain a comprehensive outsourcing risk management program covering due diligence, contract provisions, ongoing monitoring, and concentration risk for material arrangements. B-13 establishes expectations for technology and cyber risk management: governance, risk identification, protection, detection, response, and recovery.

  1. B-10: outsourcing policy, due diligence, contract provisions, monitoring, concentration risk
  2. B-13 Domain 1: governance and risk management framework, Board oversight
  3. B-13 Domain 2: technology operations and resilience
  4. B-13 Domain 3: cyber security controls aligned to NIST CSF functions
  5. B-13 Domain 4: third-party and cloud provider risk
  6. B-13 Domain 5: data risk management and data governance

What Sentrix provides for OSFI

B-13 governance framework

Board-level technology risk policy, risk appetite statements, and technology risk management framework documentation required by Domain 1. Templates adapted for Canadian federally regulated financial institutions.

Outsourcing register (B-10)

Comprehensive outsourcing risk management program: material versus non-material classification, due diligence evidence, contract provision tracking (exit strategies, audit rights, subcontractor notification), and ongoing monitoring.

Concentration risk analysis

B-10 requires analysis of outsourcing concentration risk. Sentrix identifies single-provider dependencies in your technology supply chain and generates the concentration risk report OSFI examiners request.

Board risk reporting

B-13 requires regular Board reporting on technology and cyber risk. Sentrix generates OSFI-aligned dashboards with posture summaries by domain, open risk items, and trend reporting.

OSFI examination readiness

Sentrix maintains continuously updated examination packages with evidence organized by B-13 domain, ready before the OSFI team arrives.

Crosswalks

  • DORA: B-10 mapped to DORA's third-party provisions and B-13 to its ICT risk framework, for institutions operating in the EU.
  • NIST CSF 2.0: B-13 Domain 3 is aligned to the CSF functions.
  • PCI DSS: for institutions handling card data.
  • SOC 2 and ISO 27001: B-10 and B-13 control sets with crosswalks to both.

Further reading

Financial services solution and third-party risk.

See your B-10 and B-13 posture on your real infrastructure.

Contact us

Frequently asked questions

Who is subject to guidelines B-10 and B-13?
All federally regulated financial institutions (FRFIs) supervised by the Office of the Superintendent of Financial Institutions: banks, insurers and trust companies. B-10 governs outsourcing arrangements and third-party relationships; B-13 sets expectations for technology and cyber risk management, including Board oversight. OSFI supervisory examinations are increasingly focused on B-13 compliance.
What does guideline B-13 cover?
B-13 sets OSFI's expectations for technology and cyber risk management across five domains: governance and risk management framework with Board oversight; technology operations and resilience; cyber security controls aligned to the NIST CSF functions; third-party and cloud provider risk; data risk management and data governance. It requires regular Board reporting.
How do B-10 and B-13 relate to DORA?
Canadian institutions operating in the European Union face both OSFI and DORA requirements. Sentrix maps B-10 to DORA's ICT third-party provisions, including the Article 28 register, and B-13 to DORA's ICT risk management framework, to avoid duplicating compliance work across the two regimes.

Let's talk about your compliance program.

Last updated: 2026-09-17