OSFI B-13 Compliance Services
Canadian federally regulated financial institutions work to meet demanding technology and cyber risk expectations. OSFI Guideline B-13 sets out what meeting them looks like in practice.
What OSFI B-13 means for your organization
If your organization is a federally regulated financial institution in Canada, OSFI Guideline B-13 applies. Effective 1 January 2024, it sets out expectations for how banks, insurance companies, and other OSFI-supervised entities manage technology and cyber risk.
B-13 takes a principles-based approach, which gives institutions flexibility in how they meet expectations while holding them accountable for the outcomes. Translating those principles into practical, auditable controls is where the work sits, and where we come in alongside your team.
Understanding if OSFI B-13 applies to you
OSFI Guideline B-13 applies to all federally regulated financial institutions in Canada, including foreign bank branches and foreign insurance company branches:
-
Domestic and foreign banks operating in Canada
-
Federal credit unions
-
Life insurance and fraternal benefit companies
-
Property and casualty insurance companies
-
Trust and loan companies
-
Cooperative credit associations
What OSFI B-13 requires
B-13 is organized into three domains:
-
Governance and risk management: Accountability, leadership, organizational structure, and the framework supporting oversight of technology and cyber risk.
-
Technology operations and resilience: The design, implementation, management, and recovery of technology assets and services.
-
Cyber security: Management and oversight of cyber risk across the institution.
Two related OSFI obligations sit alongside B-13. Qualifying technology and cyber security incidents must be reported to OSFI under the Technology and Cyber Security Incident Reporting Advisory, and third-party risk is governed by Guideline B-10, effective May 2024.
Gartner Recognized
We are thrilled to share that Integrity360 has been recognized as a Gartner Representative Vendor in 5 of their Market Guides, including: Managed Security Services, Managed Detection and Response, Gartner's Market Guide for Co-Managed Security Monitoring Services and Managed SIEM Services.
Gartner has included a range of providers within its market guide for managed services to ensure clear coverage from a geographical, vertical and capabilities perspective. Those included in the Gartner market guide display clarity in the vision for an end-user outcome-focused offering distinct from a pure technology-driven offering.
Speak to an expert
Dublin: +353 01 293 4027
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673
OSFI B-13 FAQs
What does an OSFI B-13 gap assessment involve?
A gap assessment maps your current technology and cyber risk management practices against B-13's expectations, identifying where controls are missing, insufficient, or not yet documented. You come away with a clear picture of where you stand and a prioritized remediation plan your team can act on.
How long does OSFI B-13 compliance typically take?
It depends on the size and complexity of your institution and where your current framework sits relative to B-13's expectations. Most organizations benefit from starting with a gap assessment to understand the scope of work before committing to a timeline. Integrity360 helps you build a realistic plan from there.
Does Integrity360 work with both large and smaller federally regulated institutions?
Yes. Our approach is tailored to your institution's size, complexity, and risk profile. Whether you are a large domestic bank or a smaller federally regulated entity, we build a compliance program that fits your reality, not a generic framework dropped into your environment.
What makes Integrity360's OSFI B-13 service different?
We combine technical cybersecurity expertise with deep knowledge of the Canadian regulatory environment. Our advisors understand what OSFI expects, how examiners assess compliance, and what practical, defensible controls look like for institutions of different sizes and structures.
Can Integrity360 support ongoing compliance, not just the initial assessment?
Absolutely. B-13 compliance is not a one-time exercise. We offer ongoing managed services, continuous monitoring, and regular reassessments to ensure your institution stays aligned as your technology environment and OSFI's expectations evolve.