OSFI Guideline B-13: The Complete Guide
In short
OSFI Guideline B-13 sets the technology and cyber risk expectations for Canada’s federally regulated financial institutions and took effect January 1, 2024. It is principles-based across three domains, governance, technology operations and resilience, and cyber security, and cascades to the vendors and MSPs that serve FRFIs. This guide explains who it touches, the three domains, and how to demonstrate readiness.
CISSP-led · Toronto-basedHolding a B-13 due-diligence questionnaire from an FRFI client, or only now finding out that B-13 reaches you? Send us what it asks. We aim to reply within one business day with what B-13 requires of you specifically. Send us your questionnaire or call (416) 566-2845.
What is OSFI Guideline B-13?
Guideline B-13, Technology and Cyber Risk Management, sets the expectations of the Office of the Superintendent of Financial Institutions (OSFI) for how federally regulated financial institutions manage technology and cyber risk. According to OSFI (2024), it came into effect on January 1, 2024. B-13 is principles-based: it does not list specific tools, but it expects an FRFI to demonstrate sound governance, resilient operations, and effective cyber defence proportionate to its size and risk.
Who B-13 applies to, and why it reaches further
B-13 directly applies to federally regulated financial institutions (FRFIs): banks, federally regulated trust and loan companies, and insurers. But its reach is wider in practice. B-13’s third-party and outsourcing expectations (reinforced by Guideline B-10) mean that the vendors, fintechs, and managed service providers serving an FRFI must be able to evidence the same controls. If you supply technology to a bank or insurer, B-13 is effectively your problem too.
Facing a B-13 review or an FRFI due-diligence questionnaire?
Fusion Computing runs CISSP-led B-13 readiness reviews for financial institutions and the vendors that serve them. We map your current controls to the three domains and show you where the gaps are before OSFI or a procurement team finds them.
The three domains of B-13
B-13 organizes its expectations into three domains:
- Governance and Risk Management, accountability, a technology and cyber risk framework, and a current technology strategy.
- Technology Operations and Resilience, asset management, change and incident management, disaster recovery, and the ability to operate through disruption.
- Cyber Security, identify, defend, detect, respond, and recover capabilities aligned to recognized frameworks.
What an FRFI’s B-13 vendor questionnaire actually asks you to evidence
An FRFI’s B-13 due-diligence questionnaire asks a vendor to evidence three things: named ownership of technology risk, tested resilience, and cyber controls mapped to a recognized framework. Those are the same three domains B-13 uses, and B-13 states seventeen numbered principles across them. Your FRFI client builds its own due-diligence questions on the expectations in Guideline B-10, Third-Party Risk Management, which took effect May 1, 2024. Each question is closed by an artifact rather than an assurance, and the artifacts below are the ones reviewers usually ask for.
| Domain | B-13 principles | Evidence that usually answers it |
|---|---|---|
| Governance and risk management | 1 to 3 | A named owner, a dated technology and cyber risk policy, and a current risk register |
| Technology operations and resilience | 4 to 13 | An asset inventory, an incident-response plan, and a restore-test schedule with its most recent result |
| Cyber security | 14 to 17 | A control map to CIS Controls v8.1 or the NIST Cybersecurity Framework, with evidence named per row |
Governance: who owns the risk, and can you show it in writing
Domain one covers Principles 1 to 3. Expect to be asked who owns technology and cyber risk, which framework you run to, and when your risk assessment was last reviewed. What a reviewer typically accepts: a named owner, a dated technology and cyber risk policy, and a current risk register. "Our senior engineer handles it" rarely clears this. A review date shows when the policy was last checked; pair it with evidence of who owns the risk and how decisions actually get made.
Operations and resilience: what you hold, and how fast you come back
Domain two is the largest, Principles 4 to 13. A reviewer will want an asset inventory covering anything that touches the institution’s data. Expect questions on change and incident management, on your recovery time and recovery point objectives, and on your restore testing. The evidence that usually satisfies it: the inventory itself, an incident-response plan with escalation paths and contact trees, and your restore-test schedule with the most recent result. A single untested backup reads as a gap here.
Cyber security: controls mapped to a framework the reviewer knows
Domain three covers Principles 14 to 17. The cyber questions cover identity and access, logging and monitoring, patch cadence, penetration testing, and encryption in transit and at rest. They also cover how fast you would tell the institution about an incident touching its data. That is usually answered with a control map to CIS Controls v8.1 or the NIST Cybersecurity Framework (NIST CSF), evidence named per row, and your notification commitment in writing. This one has a clock on it: under OSFI’s Technology and Cyber Security Incident Reporting advisory the FRFI must report a technology or cyber security incident to OSFI within 24 hours, and it cannot meet that deadline if you are slow to tell it.
Across all three domains, a questionnaire is scoped to the service you actually provide, so "not applicable, we do not hold that data" is a fair answer when it is true and documented. The evidence pack is also reusable: the same artifacts carry into the next FRFI review, a CIS v8.1 self-assessment, and a cyber-insurance renewal. If any of this is live for you right now, send us the questionnaire and we will come back on where you already have the evidence. This is general guidance and not a legal opinion; for your specific obligations, consult qualified counsel.
Get the OSFI B-13 Readiness Matrix
This guide explains B-13’s expectations. The matrix maps 14 controls to CIS Controls v8.1 and NIST CSF so an FRFI, or the MSP serving one, can show its work.
How B-13 relates to other frameworks
B-13 deliberately aligns with established frameworks, which is how our readiness matrix is structured: NIST Cybersecurity Framework functions and CIS Controls v8.1 safeguards. Both moved after B-13 landed. NIST (2024) released Cybersecurity Framework 2.0 on February 26, and CIS (2024) shipped Controls v8.1 on June 25, so a control map assembled before then is already a version behind. B-13 also connects to OSFI’s Technology and Cyber Security Incident Reporting advisory, which puts the reporting clock described above on the institution.
What “non-compliance” looks like
B-13 is a supervisory guideline, not a fining statute. What escalation looks like in practice is a finding in a supervisory letter, a remediation plan OSFI expects in response, and closer supervisory attention while it stays open. Remediation costs management time, and the finding stays open until the institution closes it. For a vendor the consequence is sharper and lands sooner: failing a B-13-driven due-diligence review can cost you the contract, because your gap is what your client has to explain.
How to demonstrate B-13 readiness: a roadmap
- Establish governance. Document who owns technology and cyber risk and the framework you follow.
- Inventory and classify assets. You cannot protect or recover what you have not mapped.
- Prove resilience. Maintain tested disaster-recovery and incident-response capabilities with evidence.
- Run the readiness matrix. Map your controls to NIST CSF and CIS v8.1 and capture the evidence each row expects.
- Prepare your reporting path. Know how and when a material incident would be reported to OSFI.
Score your controls against what OSFI expects a federally regulated institution and its third parties to demonstrate. About 3 minutes.
Run the readiness check →or book a free 30-min call →Free · no email until you see your score, or talk to a senior engineer.
B-13 and the rest of the financial-sector stack
FRFIs and their advisors rarely face B-13 alone. Investment dealers and advisors layer CIRO cybersecurity expectations; everyone handling personal information still answers to PIPEDA; and cyber insurers test much of the same ground. Our financial services IT practice and vCISO services are built around this stacked reality.
About this guide
This guide is maintained by Mike Pearlstein, CISSP, Founder and CEO of Fusion Computing Limited, a Canadian managed IT and cybersecurity provider. Last updated September 2026. It is reviewed again as legislation and program requirements change. Definitions are written for business leaders, not lawyers, for a legal opinion on your specific obligations, consult qualified counsel.
Ready to check your OSFI B-13 readiness?
Tell us your institution type and where your technology risk program stands today. We aim to reply within one business day with what B-13 requires of you specifically.
Start the conversation
Share the business problem, team size and timing. Managed services usually suit 10 to 150 employees; smaller project and AI enquiries are welcome.
- ✔We aim to reply in 1 business day
- ✔CISSP-led Canadian team
- ✔No obligation
By submitting this form, you consent to Fusion Computing contacting you. We do not sell your information. We use service providers to operate the form and our communications. See our Privacy Policy.
Or call us directly: (416) 566-2845
Common Questions
When did OSFI Guideline B-13 come into effect?
OSFI Guideline B-13, Technology and Cyber Risk Management, came into effect on January 1, 2024. It applies to federally regulated financial institutions and increasingly shapes the requirements those institutions impose on their technology vendors and MSPs.
Who does OSFI B-13 apply to?
It directly applies to federally regulated financial institutions, banks, and federally regulated trust, loan, and insurance companies. Through B-13’s third-party and outsourcing expectations, the vendors, fintechs, and managed service providers that serve those institutions must be able to evidence the same controls.
What are the three domains of OSFI B-13?
Governance and Risk Management; Technology Operations and Resilience; and Cyber Security. Together they expect an FRFI to demonstrate accountable governance, the ability to operate through disruption, and identify/defend/detect/respond/recover cyber capabilities proportionate to its risk.
Are there fines for not complying with OSFI B-13?
B-13 is a supervisory guideline, not a fining statute, so there are no fixed monetary penalties. OSFI instead escalates supervisory action, increased scrutiny, remediation requirements, and higher staging. For a vendor, the practical penalty is failing due diligence and losing the contract.
How does B-13 relate to NIST and CIS Controls?
B-13 is principles-based and aligns with established frameworks. Most institutions and vendors evidence it using NIST Cybersecurity Framework functions and CIS Controls v8.1 safeguards, which is how our OSFI B-13 readiness matrix is structured.
We are an MSP, not a bank, does B-13 affect us?
Yes, indirectly but materially. If you provide technology services to a federally regulated financial institution, B-13’s third-party and outsourcing expectations mean your client must verify your controls. Being able to map your environment to B-13, NIST CSF, and CIS v8.1 is increasingly a condition of winning and keeping FRFI work.
Part of the Canadian IT Compliance Hub – PIPEDA, PHIPA, OSFI B-13, Bill C-8, CyberSecure Canada and cyber-insurance guidance for Canadian SMBs, in one place.
What to do next
What to do when a B-13 questionnaire lands on your desk
Most suppliers need an answer today, long before they need a compliance programme. Send us the questionnaire you have, or tell us where your controls stand. We aim to reply within one business day with what B-13 requires of you specifically.
Or call (416) 566-2845 and ask for the B-13 review. CISSP-led and Toronto-based.

