OSFI GUIDELINE B-13 · FEDERALLY REGULATED FINANCIAL INSTITUTIONS

OSFI B-13: Technology &
Cyber Risk Management

OSFI's Guideline B-13 is the primary technology and cyber risk management standard for federally regulated banks, trust companies, life insurers, and property & casualty insurers in Canada. Non-compliance is identified during OSFI examinations and can result in supervisory intervention. ThreeShield delivers B-13 gap assessments and governance frameworks backed by Lavawall® continuous monitoring.

What Is OSFI Guideline B-13?

OSFI's Guideline B-13: Technology and Cyber Risk Management sets out the Office of the Superintendent of Financial Institutions' expectations for how federally regulated financial institutions (FRFIs) manage technology risk and cyber risk. Effective January 1, 2022, B-13 replaced earlier OSFI guidance and significantly raised the bar for technology governance, cyber resilience, and third-party risk management.

B-13 applies to all FRFIs - banks, federally regulated trust and loan companies, life insurance companies, property and casualty insurance companies, and fraternal benefit societies. Non-compliance is assessed during OSFI's regular supervisory examination cycle and can result in supervisory letters, increased examination intensity, and in serious cases, formal intervention.

Schedule I & II Banks Federal Trust Companies Life Insurance Companies P&C Insurance Companies Mortgage Insurance Companies Federally Regulated Pension Plans

B-13's Three Domains

OSFI B-13 is organized around three interconnected domains, each with specific outcomes OSFI expects FRFIs to achieve.

Domain 1: Governance & Accountability

Board and senior management oversight of technology and cyber risk. Defined roles (CISO or equivalent), risk appetite statement for technology risk, and integration of technology risk into the enterprise risk management framework. OSFI expects demonstrable board engagement - not delegation to IT.

Domain 1 (cont.): Technology Risk Management

Formal technology risk assessment processes, risk tolerance thresholds, risk acceptance procedures, and integration of technology risk metrics into management reporting. Technology risk must be managed with the same rigour as credit or market risk.

Domain 2: Technology Operations & Resilience

Reliable, secure technology infrastructure. Asset lifecycle management, change management, patch and vulnerability management, capacity planning, and backup and recovery - all monitored continuously. Lavawall® addresses patch compliance and vulnerability management components directly.

Domain 2 (cont.): Cyber Security

Risk-based cybersecurity program covering identity and access management, network security, data protection, security monitoring, and incident management. OSFI expects evidence of continuous monitoring - not point-in-time assessments.

Domain 3: Third-Party & Supply Chain Risk

Due diligence on technology vendors and cloud service providers. Contractual security requirements, ongoing monitoring, and exit strategies for critical technology dependencies. Aligns with Bill C-8 CCSPA supply chain requirements for designated operators.

Domain 3 (cont.): Cyber Incident Response

Documented and tested incident response and recovery plans. OSFI expects institutions to demonstrate they can detect, contain, and recover from significant cyber incidents with defined Recovery Time Objectives (RTOs). 72-hour incident reporting to OSFI for significant events.

B-13 & Bill C-8: Dual Obligations for FRFIs

Federally regulated financial institutions that are designated operators under Bill C-8 face obligations under both B-13 and the CCSPA simultaneously. The good news: the programs are complementary. A B-13-compliant institution has most of what a C-8 cybersecurity program requires. ThreeShield maps both frameworks and builds programs that satisfy both without duplication.

How Lavawall® Supports B-13 Compliance

B-13 RequirementLavawall® AutomatedThreeShield Expert Layer
Continuous security monitoring✓ 24/7 across endpoints, cloud, M365 -
Patch and vulnerability management✓ 7,533+ apps, automated reporting -
Identity and access management monitoring✓ Entra ID / M365 / AWSIAM policy review
Third-party risk monitoring⚑ Vendor exposure monitoringFormal vendor assessment methodology
Cyber risk assessment⚑ Risk scoring dataCISSP/CISA formal B-13 risk assessment
Incident response and 72-hr OSFI reporting⚑ Detection and alertingIR plan with OSFI notification workflow
Technology risk governance documentation - ThreeShield develops governance framework
Board reporting on technology risk⚑ Automated dashboardsBoard-ready reporting templates

Three Ways to Achieve B-13 Compliance

Self-Serve

DIY via Lavawall®

For FRFIs with internal security teams needing continuous monitoring and evidence collection for B-13 examinations

  • Lavawall® continuous technology risk monitoring
  • Automated patch compliance and vulnerability reporting
  • M365/Entra/Azure/AWS security monitoring
  • Evidence collection for OSFI examination responses
Start with Lavawall®
Recommended

Supported

CISSP/CISA expert guidance alongside your internal team

  • B-13 gap assessment against all three domains
  • Technology risk governance framework development
  • Third-party risk assessment methodology
  • Incident response plan with OSFI reporting workflow
  • OSFI examination preparation support
Get Supported Engagement
Fully Managed

Done-for-You

Complete B-13 compliance program delivered by ThreeShield

  • Full B-13 program documentation across all three domains
  • Board and senior management reporting framework
  • Vendor risk assessment program
  • Annual examination cycle support
  • Ongoing Lavawall® monitoring retainer
Book Done-for-You

Frequently Asked Questions

Banks designated under Bill C-8 face both B-13 and CCSPA obligations simultaneously. OSFI is the sector regulator under Bill C-8 for the banking sector. A bank's B-13 cybersecurity program provides a strong foundation for C-8 compliance - the risk assessment, incident response, and third-party risk management requirements are substantially aligned. ThreeShield maps both and builds a single program that satisfies both, eliminating duplicate effort.

B-13 applies to federally regulated financial institutions - those incorporated or registered under federal legislation. Provincial credit unions (regulated by BCFSA, FSRA, DICO, etc.) are not directly subject to B-13, though they face analogous expectations from their provincial regulators. For BC credit unions, see our BCFSA page. For Ontario credit unions, FSRA has its own cyber expectations.

OSFI's examination cycle varies by institution size and risk profile - typically every 1-3 years for most FRFIs, with larger systemic institutions examined more frequently. Technology and cyber risk is now a standard examination area, not an occasional focus. Organizations should maintain B-13 compliance continuously, not only in the months before an expected examination.

Ready for Your Next OSFI Examination?

ThreeShield delivers OSFI B-13 gap assessments that identify exactly where you stand against all three domains - with Lavawall® providing the continuous monitoring evidence OSFI expects to see.

Book a B-13 Gap Assessment

Also covers Bill C-8 CCSPA · PIPEDA/C-27 · CIRO Cybersecurity Guidance