OSFI expectations are rising. Your technology risk program needs to keep pace.
The Office of the Superintendent of Financial Institutions has significantly strengthened its technology and cyber risk guidelines. B-10 governs outsourcing arrangements; B-13 governs technology and cyber risk management for all federally regulated financial institutions. Sentrix is the only GRC platform with native B-10 and B-13 support, pre-built control sets, and crosswalks to DORA for dual-market institutions.
Outsourcing governance (B-10). Technology & cyber risk (B-13). One program.
B-10 requires FRFIs to maintain a comprehensive outsourcing risk management program covering due diligence, contract provisions, ongoing monitoring, and concentration risk for material outsourcing arrangements. B-13 establishes expectations for technology and cyber risk management including governance, risk identification, protection, detection, response, and recovery—aligned to the NIST CSF structure but with OSFI-specific expectations for FRFIs.
- B-10: outsourcing policy, due diligence, contract provisions, monitoring, concentration risk
- B-13 Domain 1: Governance and risk management framework, Board oversight
- B-13 Domain 2: Technology operations and resilience
- B-13 Domain 3: Cyber security controls aligned to NIST CSF functions
- B-13 Domain 4: Third-party and cloud provider risk
- B-13 Domain 5: Data risk management and data governance
OSFI B-13 · Domain coverage
LIVE MONITORINGFrom Board risk reporting to outsourcing register—built for FRFIs.
B-13 governance framework
Board-level technology risk policy, risk appetite statements, and technology risk management framework documentation required by B-13 Domain 1. Pre-built templates adapted for Canadian federally regulated financial institutions.
Outsourcing register (B-10)
Comprehensive outsourcing risk management program: material vs. non-material classification, due diligence evidence, contract provision tracking (exit strategies, audit rights, subcontractor notification), and ongoing monitoring.
Concentration risk analysis
B-10 requires analysis of outsourcing concentration risk. Sentrix automatically identifies single-provider dependencies in your technology supply chain and generates the concentration risk report OSFI examiners request.
Board risk reporting
B-13 requires regular Board reporting on technology and cyber risk. Sentrix generates OSFI-aligned board dashboards with D1–D5 posture summaries, open risk items, and trend reporting in one click.
DORA crosswalk
Canadian FRFIs with EU operations face both OSFI and DORA requirements. Sentrix maps B-10 to DORA’s third-party provisions and B-13 to DORA’s ICT risk framework, eliminating duplicate compliance work.
OSFI examination readiness
OSFI supervisory examinations are increasingly focused on B-13 compliance. Sentrix maintains continuously updated examination packages with evidence organized by B-13 domain—ready before the OSFI team arrives.
See your OSFI B-10 and B-13 posture on your real infrastructure.
We map your technology and outsourcing risk program to OSFI requirements live in the demo.