Framework · OSFI B-10 / B-13
OSFI B-10 and B-13: outsourcing, technology and cyber risk
OSFI guidelines on outsourcing (B-10) and technology and cyber risk management (B-13) for Canada's federally regulated financial institutions, in one program.
The Office of the Superintendent of Financial Institutions (OSFI) supervises Canada's federally regulated financial institutions: banks, insurers, trust companies. Guideline B-10 governs outsourcing arrangements and third-party relationships; guideline B-13 sets expectations for technology and cyber risk management, aligned to the NIST CSF structure but with OSFI-specific expectations, including Board oversight.
Key facts
- FRFIs: all federally regulated financial institutions are subject to B-10 and B-13.
- 5 domains: B-13 structures its expectations in five domains, from governance to data risk management.
- Board: B-13 requires Board-level technology risk oversight and regular Board reporting.
- Concentration: B-10 requires concentration risk analysis for material outsourcing arrangements.
What B-10 and B-13 require
B-10 requires FRFIs to maintain a comprehensive outsourcing risk management program covering due diligence, contract provisions, ongoing monitoring, and concentration risk for material arrangements. B-13 establishes expectations for technology and cyber risk management: governance, risk identification, protection, detection, response, and recovery.
- B-10: outsourcing policy, due diligence, contract provisions, monitoring, concentration risk
- B-13 Domain 1: governance and risk management framework, Board oversight
- B-13 Domain 2: technology operations and resilience
- B-13 Domain 3: cyber security controls aligned to NIST CSF functions
- B-13 Domain 4: third-party and cloud provider risk
- B-13 Domain 5: data risk management and data governance
What Sentrix provides for OSFI
B-13 governance framework
Board-level technology risk policy, risk appetite statements, and technology risk management framework documentation required by Domain 1. Templates adapted for Canadian federally regulated financial institutions.
Outsourcing register (B-10)
Comprehensive outsourcing risk management program: material versus non-material classification, due diligence evidence, contract provision tracking (exit strategies, audit rights, subcontractor notification), and ongoing monitoring.
Concentration risk analysis
B-10 requires analysis of outsourcing concentration risk. Sentrix identifies single-provider dependencies in your technology supply chain and generates the concentration risk report OSFI examiners request.
Board risk reporting
B-13 requires regular Board reporting on technology and cyber risk. Sentrix generates OSFI-aligned dashboards with posture summaries by domain, open risk items, and trend reporting.
OSFI examination readiness
Sentrix maintains continuously updated examination packages with evidence organized by B-13 domain, ready before the OSFI team arrives.
Crosswalks
- DORA: B-10 mapped to DORA's third-party provisions and B-13 to its ICT risk framework, for institutions operating in the EU.
- NIST CSF 2.0: B-13 Domain 3 is aligned to the CSF functions.
- PCI DSS: for institutions handling card data.
- SOC 2 and ISO 27001: B-10 and B-13 control sets with crosswalks to both.
Further reading
Financial services solution and third-party risk.
See your B-10 and B-13 posture on your real infrastructure.
Frequently asked questions
- Who is subject to guidelines B-10 and B-13?
- All federally regulated financial institutions (FRFIs) supervised by the Office of the Superintendent of Financial Institutions: banks, insurers and trust companies. B-10 governs outsourcing arrangements and third-party relationships; B-13 sets expectations for technology and cyber risk management, including Board oversight. OSFI supervisory examinations are increasingly focused on B-13 compliance.
- What does guideline B-13 cover?
- B-13 sets OSFI's expectations for technology and cyber risk management across five domains: governance and risk management framework with Board oversight; technology operations and resilience; cyber security controls aligned to the NIST CSF functions; third-party and cloud provider risk; data risk management and data governance. It requires regular Board reporting.
- How do B-10 and B-13 relate to DORA?
- Canadian institutions operating in the European Union face both OSFI and DORA requirements. Sentrix maps B-10 to DORA's ICT third-party provisions, including the Article 28 register, and B-13 to DORA's ICT risk management framework, to avoid duplicating compliance work across the two regimes.
Related pages
Framework · DORA
DORA is in force. Your ICT risk framework needs to be too.
The EU Digital Operational Resilience Act for financial entities, applicable since 17 January 2025: ICT risk, incident reporting, testing and ICT third parties.
Framework · NIST CSF 2.0
NIST CSF 2.0: the risk framework your board understands
The NIST Cybersecurity Framework, version 2.0 of 2024: six outcome-based functions, including the new Govern function, that layer on top of your standards.
Framework · PCI DSS v4.0.1
PCI DSS v4.0.1: 12 requirements, one evidence program
Payment Card Industry Data Security Standard: twelve requirements, quarterly vulnerability scans and annual validation by a QSA report or self-assessment.
Framework · SOC 2
SOC 2 is a continuous program, not a one-time audit
AICPA attestation framework across five Trust Services Criteria categories, reported as Type I or Type II. Continuous evidence, drift alerts, auditor access.
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Let's talk about your compliance program.
Last updated: 2026-09-17
