By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 25, 2026
Quick Answer
OSFI Guideline B-13 sets mandatory expectations for technology and cyber risk management at federally regulated financial institutions in Canada. It is organized around three domains: governance and risk management, technology operations and resilience, and cyber security. Third-party technology risk, which was in the original draft, was moved to OSFI’s companion Guideline B-10 and is read alongside B-13. Institutions that treat B-13 as a checkbox exercise, rather than building the controls and evidence OSFI examiners actually look for, find themselves exposed at the next supervisory review.
Key Takeaways
- OSFI B-13 applies to all federally regulated financial institutions: banks, foreign bank branches, trust and loan companies, insurers, and the small number of federal credit unions. It took effect January 1, 2024.
- B-13 is organized around three domains: governance and risk management, technology operations and resilience, and cyber security.
- Third-party and technology-service-provider risk is addressed in the companion Guideline B-10, effective May 1, 2024, read alongside B-13.
- OSFI examiners assess maturity, not just policy. Controls must be operating, evidence must be documented, and gaps must be managed.
- A cybersecurity programme built by professionals familiar with OSFI expectations produces the evidence and maturity that supervisory reviews require.
What Is OSFI B-13 and Why Does It Matter?
The Office of the Superintendent of Financial Institutions issued Guideline B-13 to set clear expectations for how federally regulated financial institutions manage technology and cyber risk. B-13 took effect on January 1, 2024, and reflected OSFI’s recognition that technology risk had become a systemic concern, not a secondary operational matter.
B-13 matters because it is not advisory. OSFI uses it as the framework for supervisory reviews of technology and cyber risk at the institutions it regulates. An institution that cannot demonstrate aligned governance, documented risk management processes, tested incident response capabilities, and oversight of its technology environment faces supervisory findings. OSFI does not levy fixed penalties for B-13 gaps; instead it escalates supervisory scrutiny, requires findings to be remediated within defined timeframes, and in serious cases imposes increased supervisory or capital requirements.
The guideline also matters because its expectations have teeth beyond the immediate regulatory relationship. Enterprise counterparties, insurers, and rating agencies increasingly look to B-13 alignment as a signal of institutional cyber maturity.
What Are the Three Domains of B-13?
Governance and Risk Management
B-13 expects financial institutions to establish clear accountability for technology and cyber risk at the board and senior management level. The board is expected to understand and oversee technology risk, not simply receive reports about it. Senior management is expected to own the technology risk framework, set risk appetite, and demonstrate that cyber risk is integrated into business decision-making. This creates a practical requirement for board-level cyber reporting in terms that non-technical directors can evaluate. A senior cybersecurity advisor who can translate technical risk into business and financial terms is often the resource that makes this expectation achievable for institutions below large-bank scale.
Technology Operations and Resilience
B-13 addresses the availability, reliability, and recoverability of technology systems. OSFI expects institutions to maintain accurate inventories of technology assets, manage technology risk across the full lifecycle of systems, and demonstrate that critical systems can recover within defined timeframes.
Business continuity and disaster recovery testing is explicitly within scope. An institution that has a recovery plan but has not tested it against realistic failure scenarios does not satisfy OSFI’s resilience expectations. Testing must be documented, results must be reviewed, and gaps must be remediated.
Cyber Security
The cyber security domain is the section most closely aligned with traditional cybersecurity controls. OSFI expects institutions to identify and classify cyber risks, implement controls proportionate to those risks, monitor the effectiveness of those controls, and maintain the ability to detect and respond to cyber incidents. Control expectations include access management with privileged access oversight, network segmentation, vulnerability management with defined remediation timelines, security testing of systems and applications, and continuous monitoring capabilities.
These are not aspirational expectations for large banks only. B-13 applies them proportionately to institution size and complexity, but the expectation of a structured programme with documented evidence applies broadly, and independent security testing of systems and applications is a consistent part of what OSFI expects institutions to demonstrate.
How Do B-13 and B-10 Work Together on Third-Party Risk?
Third-party technology and cyber risk appeared in the original draft of B-13 but was removed from the final guideline in response to consultation feedback. OSFI addresses it instead in Guideline B-10, Third-Party Risk Management, which came into effect on May 1, 2024. B-13 and B-10 are designed to be read together: B-13 governs the institution’s own technology and cyber risk, and B-10 governs the risk introduced by the vendors, technology service providers, and fintech partners the institution relies on.
This division matters because the systemic exposure created when many institutions depend on common technology service providers is exactly what OSFI is concerned about. Under B-10, institutions are expected to conduct due diligence before engaging service providers, manage risk on an ongoing basis, and ensure that contracts include appropriate security and incident notification provisions.
For institutions with fintech partnerships and API integrations, this has direct operational implications. An API connection to a payment platform or data aggregator is a third-party technology risk that B-10 expects to be identified, assessed, and managed, while the institution’s own handling of that connection falls under B-13. Many institutions find that their third-party inventory is less complete than these guidelines would expect, and that their oversight processes are less consistent than a supervisory review would find satisfactory.
How Does OSFI Assess B-13 Alignment in Practice?
OSFI supervisory reviews assess technology and cyber risk maturity against a defined framework. Examiners look for evidence that controls are operating, not just that policies exist. A well-written information security policy that has not been implemented in practice, a penetration test that was conducted years ago, or a vendor risk programme that covers only a subset of third parties will generate findings regardless of the quality of the policy documentation.
Examiners also assess whether institutions understand their own risk. An institution that cannot identify its most critical systems, articulate its threat profile, or describe how it would respond to a ransomware incident has a governance problem, not just a control gap. B-13 alignment requires that the people responsible for technology risk actually understand it.
What Does a B-13 Aligned Programme Look Like for Smaller Institutions?
B-13 acknowledges proportionality. A large Schedule I bank and a smaller federally regulated institution face different expectations in absolute terms, even though the framework applies to both. The key is that the programme must be proportionate to the institution’s size, complexity, and risk profile, and must be able to demonstrate that proportionality to an examiner. Provincially regulated credit unions are not directly bound by B-13, but many align with it as a matter of best practice and to satisfy counterparties.
For smaller federally regulated institutions and the institutions that align with B-13 voluntarily, the practical starting point is a gap assessment against B-13 expectations followed by a prioritized remediation roadmap. A fractional vCISO provides the governance leadership and OSFI reporting capability without the cost of a full-time hire. Armour Cybersecurity works with financial institutions across the size spectrum on B-13 alignment, delivering banking cybersecurity services that combine an evidence-first methodology, governance structure appropriate to institution size, and the controls that produce the documentation OSFI examiners look for.
How Does B-13 Interact With PCI DSS, SOC 2, and Other Frameworks?
Financial institutions subject to B-13 often carry additional compliance obligations: PCI DSS for cardholder data, SOC 2 for enterprise counterparty requirements, FINTRAC for anti-money-laundering reporting, and PIPEDA and Quebec Law 25 for customer privacy. These frameworks share significant control overlap with B-13.
An institution that builds its cybersecurity programme around B-13 requirements, with proper control design and evidence collection, finds that much of the work transfers to PCI DSS, SOC 2, and privacy programme requirements. A well-structured programme built from a common control set avoids rebuilding evidence from scratch for each framework and instead maps that single control set to each applicable standard.
Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the financial institutions that pass a supervisory review without a scramble are the ones that built B-13 as a real operating programme rather than a binder of policies, controls that actually run, evidence collected as work happens, and a named owner who can explain the institution’s risk in the room, so the examiner finds a programme that is lived rather than one assembled the week before.
Frequently Asked Questions
Does B-13 apply to foreign bank branches operating in Canada?
OSFI regulates foreign bank branches operating in Canada and expects alignment with B-13 proportionate to the branch’s operations, as set out in Guideline E-4 on foreign entities operating on a branch basis. The scope of the programme may differ from a full Schedule I bank, but the expectation of documented technology risk management and cyber controls applies. Foreign bank branches should seek guidance specific to their OSFI regulatory classification.
What happens if OSFI finds material gaps in our B-13 programme?
OSFI does not levy fixed penalties for B-13 gaps. Instead it escalates supervisory scrutiny, issues findings that must be remediated within defined timeframes, and in serious cases imposes increased supervisory or capital requirements. Material gaps in cyber risk management, particularly around incident response readiness or third-party oversight, are treated seriously given the systemic risk implications. Addressing gaps proactively, before a review cycle, is significantly better than remediating under supervisory deadline pressure.
How long does it take to build a B-13 aligned programme?
For an institution with basic controls already in place, a gap assessment and initial remediation roadmap can be completed in four to eight weeks. Building the full evidence base that a supervisory review would assess typically takes six to twelve months depending on the gaps identified and the institution’s capacity to implement changes alongside day-to-day operations. Starting before a review cycle, rather than in response to one, provides the time needed to build a credible programme.
Can Armour Cybersecurity support our OSFI examination preparation?
Yes. Armour’s vCISO and compliance audit services are designed to produce the governance structure, control documentation, and evidence packages that OSFI examiners assess. We have supported financial institutions through supervisory reviews and can assist with examination preparation, response to findings, and ongoing programme maintenance between review cycles.
The Bottom Line
OSFI B-13 is not a document to file and forget; it is the framework examiners use to judge whether a financial institution genuinely manages its technology and cyber risk. Its three domains, governance, technology operations and resilience, and cyber security, plus the third-party expectations in the companion B-10 guideline, all point at the same thing: controls that operate, evidence that is documented, and leaders who understand their own risk. The institutions that come through supervisory review cleanly are the ones that treated B-13 as an operating programme and built the evidence as they went. Armour Cybersecurity helps banks, credit unions, and financial institutions build banking cybersecurity services aligned to OSFI B-13 and B-10, with the vCISO governance, compliance evidence, and operational controls that supervisory reviews assess, so the next examination confirms a programme you already trust rather than exposing one built under deadline.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



