Home/ Frameworks/ OSFI B-10/B-13
Framework · OSFI B-10 / B-13

OSFI expectations are rising. Your technology risk program needs to keep pace.

The Office of the Superintendent of Financial Institutions has significantly strengthened its technology and cyber risk guidelines. B-10 governs outsourcing arrangements; B-13 governs technology and cyber risk management for all federally regulated financial institutions. Sentrix is the only GRC platform with native B-10 and B-13 support, pre-built control sets, and crosswalks to DORA for dual-market institutions.

2023
B-13 Technology and Cyber Risk Management guideline effective date—now OSFI’s primary cyber framework
FRFIs
All federally regulated financial institutions subject to B-10 and B-13—banks, insurers, trust companies
Board
B-13 requires Board-level technology risk oversight—Sentrix generates board-ready risk reports in one click
Canadian
Native support—B-10 and B-13 are first-class frameworks in Sentrix, not custom mappings
B-10 and B-13 requirements

Outsourcing governance (B-10). Technology & cyber risk (B-13). One program.

B-10 requires FRFIs to maintain a comprehensive outsourcing risk management program covering due diligence, contract provisions, ongoing monitoring, and concentration risk for material outsourcing arrangements. B-13 establishes expectations for technology and cyber risk management including governance, risk identification, protection, detection, response, and recovery—aligned to the NIST CSF structure but with OSFI-specific expectations for FRFIs.

  • B-10: outsourcing policy, due diligence, contract provisions, monitoring, concentration risk
  • B-13 Domain 1: Governance and risk management framework, Board oversight
  • B-13 Domain 2: Technology operations and resilience
  • B-13 Domain 3: Cyber security controls aligned to NIST CSF functions
  • B-13 Domain 4: Third-party and cloud provider risk
  • B-13 Domain 5: Data risk management and data governance

OSFI B-13 · Domain coverage

LIVE MONITORING
D1: Governance & risk management✓ PASS
D2: Technology operations✓ PASS
D3: Cyber security▲ 2 gaps
D4: Third-party & cloud risk (B-10)✓ PASS
D5: Data risk management✓ PASS
⚠ D3: Penetration testing evidence due Q2 · Threat intel feed gap
Full OSFI capabilities

From Board risk reporting to outsourcing register—built for FRFIs.

B-13 governance framework

Board-level technology risk policy, risk appetite statements, and technology risk management framework documentation required by B-13 Domain 1. Pre-built templates adapted for Canadian federally regulated financial institutions.

Outsourcing register (B-10)

Comprehensive outsourcing risk management program: material vs. non-material classification, due diligence evidence, contract provision tracking (exit strategies, audit rights, subcontractor notification), and ongoing monitoring.

Concentration risk analysis

B-10 requires analysis of outsourcing concentration risk. Sentrix automatically identifies single-provider dependencies in your technology supply chain and generates the concentration risk report OSFI examiners request.

Board risk reporting

B-13 requires regular Board reporting on technology and cyber risk. Sentrix generates OSFI-aligned board dashboards with D1–D5 posture summaries, open risk items, and trend reporting in one click.

DORA crosswalk

Canadian FRFIs with EU operations face both OSFI and DORA requirements. Sentrix maps B-10 to DORA’s third-party provisions and B-13 to DORA’s ICT risk framework, eliminating duplicate compliance work.

OSFI examination readiness

OSFI supervisory examinations are increasingly focused on B-13 compliance. Sentrix maintains continuously updated examination packages with evidence organized by B-13 domain—ready before the OSFI team arrives.

See your OSFI B-10 and B-13 posture on your real infrastructure.

We map your technology and outsourcing risk program to OSFI requirements live in the demo.