Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver. Regulatory figures verified against FSRA primary sources on August 5, 2026.
Note: the brokerage and the principal broker below are a composite from FC engagements with 3 Ontario mortgage brokerages in Q4 2025 and Q1 2026, with identifying details changed. The FSRA notification path and the MBRCC principles those engagements landed against are real.
The principal broker called me from her car on a Tuesday evening in February. Her brokerage manager had spent the afternoon with a lender’s fraud desk over a submission package carrying a forged income document.
By 4pm the manager had confirmed the agent’s lender-portal credentials were used the previous Saturday from an IP address matching neither the agent’s home nor any office the Mississauga brokerage operates. Somebody else had been inside her account.
The principal broker is broker-of-record for a 12-agent shop. She had been on the road since lunch, and her brokerage had been sitting on a materiality determination for 6 hours without anyone treating it as one.
I am an MSP, not a regulator, so read the timing rules below with FSRA-experienced counsel. What follows is the pattern I watched across those 3 Ontario engagements, checked line by line against what FSRA actually publishes.
Key Takeaways.
- FSRA imposed CA$875,000 in administrative monetary penalties on Ontario mortgage professionals in 2024-25. That is roughly 73% of the CA$1.2 million levied across all its sectors, and close to double the CA$460,000 of the prior year.
- The violation themes FSRA publishes are suitability, unlicensed activity, unauthorized remuneration, undisclosed conflicts, and false information to the regulator. Not one is a cyber charge, which is the point.
- The correction most brokerage posts get wrong: the MBRCC Principles for Cybersecurity Preparedness contain four principles, not nine, and FSRA adopted them as MB0048INF effective August 18, 2022.
- GR0016INT asks for notification as soon as is reasonable, normally within 72 hours or sooner, once a material IT risk incident is determined. For mortgage brokerages the channel is a named FSRA inbox.
- The 90-day sprint below maps to what FSRA examined in 2024-25 and what E&O carriers now ask at renewal.
Book a Consultation
CISSP-led practice, Microsoft Solutions Partner, serving Ontario brokerages since 2012.
The CA$875K figure explained: what FSRA actually levied on mortgage brokerages
The CA$875,000 headline is an aggregate across 43 sanctions, not one penalty against one brokerage. FSRA initiated 100 enforcement actions in 2024-25, up from 65, and imposed 80 unique sanctions. Mortgage professionals drew 43 of them.
Counted as money, the run looks like a fine. Counted as facts it is a supervision-and-records story with a technology gap underneath. That distinction decides whether an Ontario principal broker spends the next year buying software or fixing process.
I read the public Ontario decisions the week she called me from her car. None of the failures were exotic: income documentation nobody verified, lender credentials shared across 2 or 3 agents, compliance reviews that never ran.
What the run tells me about our own book is simpler than the penalties suggest. The Ontario brokerages getting sanctioned read the MBRCC guidance in 2022, filed it, and never ran it.
The pattern across the cases: what 2024-25 enforcement actually flagged
The published violation themes for the sanctioned Ontario files are narrow and they repeat. FSRA names 5.
- Failing to ensure mortgage suitability. The single largest theme, and the one the 2024-25 exam data puts at 100% of private-mortgage files reviewed.
- Operating outside an authorizing brokerage, or without a licence. An access-control problem wearing a licensing label.
- Receiving remuneration from unauthorized sources. Detected in records, not in software.
- Failing to disclose conflicts of interest. Missing or inadequate disclosure of brokerage relationships ran at 65% of files examined in 2024-25.
- Providing false or misleading information to the regulator. This is the one that converts a single incident into a multi-year file.
Notice what is absent. None of the 5 themes is a cybersecurity charge, and I would rather be precise than sell fear: FSRA issued no standalone cyber penalties in the 2024-25 run. What a control gap does is manufacture the upstream record failures FSRA does penalize.
The Tuesday-call brokerage was carrying the third theme and building the first without knowing it. The compromised agent had filed 3 packages that week which the principal broker signed off on, 2 of them carrying documents she never reviewed. Six weeks of submissions had to be re-papered with her real review notes before FSRA could be told the Mississauga brokerage held a complete record.
The 3 mistakes brokers-of-record made that turned manageable incidents into AMPs
The first mistake is what that Tuesday evening exposed. The broker-of-record did not know a materiality determination had already been made inside her own brokerage, so the 72-hour expectation in GR0016INT was running while she was on the highway.
The fix is to delegate the determination and the filing by role. In the plan we wrote that night the Mississauga manager became FSRA notification owner cleared to file after hours, and the principal broker reviews and signs once the file is open.
The second mistake turns a single event into a multi-year file. An Ontario principal broker certifies annually that brokerage records support the year’s agent activity. Where they do not the certification is itself a contravention, and false information to the regulator is one of FSRA’s 5 published themes.
The fix is a quarterly evidence sweep: the manager samples agent submissions, matches each against the principal broker’s real review notes, and re-papers the gaps before the quarter ends. A 30-minute call with our team walks you through the sweep template.
The third mistake is the one I see most often, because it feels like normal practice until FSRA inspects. Supervision runs reactively: the submission lands, the principal broker scans and signs, and nothing records what was looked at. FSRA measured that at 100% of Ontario entities examined in 2024-25.
FSRA’s expected practice: the criteria a 12-agent brokerage is measured against
GR0016INT is principles-based rather than prescriptive. FSRA expects an Ontario brokerage to assess IT risks, deploy controls proportionate to its size, monitor for incidents, document response and recovery, and notify FSRA of material ones. For a 12-agent shop that is a 6-page runbook, and across our Ontario brokerage and professional-services clients the same 6 pages come up every time.
- Page 1, assets. The lender-channel portals, the Microsoft 365 tenant, the CRM, the document repository. Every line has a named owner and fits on one page.
- Page 2, access. Multi-factor authentication on every account, no lender credentials shared between agents, a password manager with role-based vaults, and a quarterly access review.
- Page 3, detection. Lender fraud-desk alerts, Microsoft 365 audit-log retention on, and a weekly review of unusual sign-ins, impossible-travel alerts, and privilege-escalation events.
- Page 4, notification. The IT Risk Incident Notification Form goes to [email protected] or the FSRA Incident Notification Portal, with the manager cleared to file it.
- Page 5, recovery. Which lender contact resets compromised credentials, how to pull agent session history, which submissions to flag for lender re-review.
- Page 6, after-action. What happened, which control caught or missed it, what changed before the next quarterly review. This page becomes the next tabletop drill.
Page 4 is the one almost nobody has. MB0048INF names the destination in writing, and I have yet to open an Ontario brokerage runbook that recorded that inbox before we wrote it in. Send us your current runbook and we will tell you which of the 6 pages is missing.
The page-by-page build is written up separately in our FSRA IT risk incident notification SOP walkthrough, and the 4 principles are decomposed into 9 working controls in the MBRCC cybersecurity principles breakdown. That 4-into-9 decomposition is where the “9 MBRCC principles” error usually starts.
For the full sector spine mapping each FSRA and MBRCC expectation to a Microsoft 365 Business Premium control, work through the FSRA-aligned brokerage cybersecurity playbook.
How to run the 90-day brokerage cyber-hygiene sprint back to defensible
A 12-agent Ontario brokerage can move from a typical control-gap baseline to defensible inside 90 days. We measured the 4 phases across 3 engagements in Q1 2026 and the sequence held each time.
- Days 1 to 15, inventory and policy. Asset list, access inventory, vendor list, and a written IT incident response plan the manager and principal broker both sign.
- Days 16 to 45, identity hardening. Multi-factor authentication everywhere, lender-credential cleanup, conditional access, and a password manager with role-based vault separation.
- Days 46 to 75, monitoring and SOP. Audit-log retention, weekly sign-in review, an FSRA notification rehearsal, the FINTRAC suspicious-transaction path, and E&O carrier contact mapping.
- Days 76 to 90, tabletop and renewal-readiness. A 2-hour drill of the account-takeover scenario, an after-action review, and a checklist mapping every certification line to its evidence.
Licensing for that set lands around CA$32 per user per month on Microsoft 365 Business Premium, which most Ontario brokerages I meet already pay for and do not use.
What your E&O carrier requires before it will renew at last year’s rate
Errors and omissions carriers underwriting Ontario brokerages now ask cyber-control questions that were not on the form 2 cycles ago. Across our clients the recurring 5 are multi-factor coverage, a documented incident response plan, lender-credential management, FINTRAC programme existence, and FSRA notification history.
A no on any of the 5 converts a routine renewal into a re-underwriting file. The Ontario questions have shifted from policy-level to operational: not “do you have a privacy policy” but “can you show me last quarter’s sign-in log review”.
I have read the resulting carrier requests across 3 Q1 2026 engagements. The carrier asks for the plan as written, the latest tabletop after-action report, and the last quarterly access review log. It checks that controls run, not that policies exist.
[NAMED CLIENT] PRINCIPAL BROKER PULL-QUOTE
“The hardest thing I had to admit on the Tuesday call was that I did not know my brokerage manager could file with FSRA without me. The clause saying she can was the single most useful sentence we added. By May our E&O renewal came back flat, and I sleep again on Sunday nights.”
The board conversation a principal broker has to have
That expansion is why a 12-agent Ontario shop should care about a plan aimed at larger firms. FSRA is walking its supervision threshold downward, and principal-broker accountability is the stated reason.
The conversation I coach every Ontario principal broker through before the year-end ownership meeting has 3 lines. The FSRA expected practice, what the brokerage runs against it today, and what remediation costs set beside the exposure of leaving the gap open.
Cost of action versus cost of inaction: the math a principal broker has to show
Remediation sits inside an existing operating budget. Microsoft 365 licensing is usually already bought, and turning on the controls inside it is the work. A 6-page runbook and 2 drills a year cost a fraction of one 2024-25 sanction.
Leaving the gap open lands harder. For most Ontario brokerages the permanent public record beats the money, because a re-underwritten E&O policy and a searchable FSRA entry both outlive the incident by years.
The Mississauga principal broker had that board conversation in March and I sat in the second half at her request. By the May ownership meeting the sprint was done, the E&O renewal was flat, and her manager was the named FSRA notification contact.
Further reading and primary sources
- FSRA, Information Technology (IT) risk management, GR0016INT. Seven practices and the 72-hour notification expectation.
- MBRCC Principles for Cybersecurity Preparedness (PDF). Four principles plus the Appendix A checklist.
- FSRA mortgage brokering regulatory framework. The canonical supervisory index.
- Office of the Privacy Commissioner of Canada, PIPEDA. The federal duty on borrower files.
- Canadian Centre for Cyber Security guidance library. The ITSAP and ITSG baselines.
Frequently Asked Questions
What is the CA$875K FSRA mortgage brokerage penalty figure?
It is an aggregate, not a single penalty. In 2024-25 FSRA imposed CA$875,000 in administrative monetary penalties on Ontario mortgage professionals, roughly 73% of the CA$1.2 million levied across all FSRA-regulated sectors.
That came from 43 of the 80 unique sanctions FSRA issued. The prior-year mortgage figure was CA$460,000, so the sector total rose about 90% in one cycle.
When does the FSRA IT risk notification expectation actually start?
GR0016INT asks a regulated entity to notify as soon as is reasonable, normally within 72 hours or sooner, after determining an IT risk incident is material. The trigger is that materiality determination.
The duty attaches to the brokerage, not to 1 officer, so waiting for the broker-of-record pauses nothing. Name an alternate filing authority in the Ontario brokerage plan.
How many MBRCC cybersecurity principles exist, four or nine?
Four. The MBRCC Principles for Cybersecurity Preparedness set out responsibility and resourcing, identification and prevention of risks, incident monitoring, detection and response, and third-party management. There is no principle 5 through 9.
The nine-principle claim usually comes from a decomposition of the 4 principles into 9 working controls, or from the MBRCC Code of Conduct. FSRA adopted the cybersecurity principles as MB0048INF effective August 18, 2022, and the source PDF is dated July 2022.
How does a mortgage brokerage actually notify FSRA of a cyber incident?
Guidance MB0048INF says Ontario mortgage brokerages and administrators should notify FSRA by emailing the IT Risk Incident Notification Form to [email protected], or uploading it to the Incident Notification Portal.
The trigger is a cybersecurity incident that could materially affect client information. Recording that address in the runbook saves about 30 minutes of searching on the worst afternoon of the year.
Does FSRA penalize principal brokers personally or just brokerages?
Both. FSRA licenses about 16,000 mortgage professionals and 1,162 brokerages in Ontario, and its register carries decisions naming brokerages, principal brokers individually, and agents.
For Ontario ownership that means a principal broker’s personal exposure now competes with entity-level exposure when the brokerage sets its supervision and security budget.
Does an E&O carrier ask about FSRA enforcement history at renewal?
Yes. Carriers underwriting Ontario brokerages now ask about FSRA notifications filed in the policy year, incident response plan documentation, multi-factor coverage, and lender-credential management.
A no on any of those converts a routine renewal into a re-underwriting file. Across our clients, brokerages with a documented plan and a clean record renewed flat or near-flat through Q1 2026.
What does the 2025-26 FSRA supervision plan focus on?
Two areas: private mortgage brokering with brokerage and principal-broker supervision, and protection of mortgage investors. IT risk is not a named focus in that plan, because GR0016INT and MB0048INF carry it separately.
The notable change is scope. FSRA expanded the focus from brokerages authorizing 200 or more agents to those authorizing 100 or more.
What is the cheapest defensible cybersecurity stack for a 12-agent brokerage?
Microsoft 365 Business Premium with the security features turned on lands around CA$32 per user per month. Licensing is the small number; runbook discipline produces the defensible posture.
The runbook covers asset inventory, multi-factor authentication, conditional access, audit-log retention, weekly sign-in review, and 2 tabletop drills a year. Annual cost for a 12-agent shop stays well below one 2024-25 sanction.
Bottom Line
The CA$875,000 FSRA levied on Ontario mortgage professionals in 2024-25 bought a lesson about supervision records, notification delegation, and a runbook a manager can run alone. Fix page 4 first: name the filing authority and write down [email protected]. Then work through the FSRA-aligned brokerage cybersecurity playbook and run the 90-day sprint.
Contact Us
Mike Pearlstein, CISSP. Fusion Computing has supported Ontario brokerages through FSRA-graded technology change since 2012.

