OSFI Guideline B-13: The Complete Guide
In short
OSFI Guideline B-13 sets the technology and cyber risk expectations for Canada’s federally regulated financial institutions and took effect January 1, 2024. It is principles-based across three domains, governance, technology operations and resilience, and cyber security, and cascades to the vendors and MSPs that serve FRFIs. This guide explains who it touches, the three domains, and how to demonstrate readiness.
What is OSFI Guideline B-13?
Guideline B-13, Technology and Cyber Risk Management, sets the expectations of the Office of the Superintendent of Financial Institutions (OSFI) for how federally regulated financial institutions manage technology and cyber risk. It came into effect on January 1, 2024. B-13 is principles-based: it does not list specific tools, but it expects an FRFI to demonstrate sound governance, resilient operations, and effective cyber defence proportionate to its size and risk.
Who B-13 applies to, and why it reaches further
B-13 directly applies to federally regulated financial institutions (FRFIs): banks, federally regulated trust and loan companies, and insurers. But its reach is wider in practice. B-13’s third-party and outsourcing expectations (reinforced by Guideline B-10) mean that the vendors, fintechs, and managed service providers serving an FRFI must be able to evidence the same controls. If you supply technology to a bank or insurer, B-13 is effectively your problem too.
Facing a B-13 review or an FRFI due-diligence questionnaire?
Fusion Computing runs CISSP-led B-13 readiness reviews for financial institutions and the vendors that serve them. We map your current controls to the three domains and show you where the gaps are before OSFI or a procurement team finds them.
The three domains of B-13
B-13 organizes its expectations into three domains:
- Governance and Risk Management, accountability, a technology and cyber risk framework, and a current technology strategy.
- Technology Operations and Resilience, asset management, change and incident management, disaster recovery, and the ability to operate through disruption.
- Cyber Security, identify, defend, detect, respond, and recover capabilities aligned to recognized frameworks.
Get the OSFI B-13 Readiness Matrix
This guide explains B-13’s expectations. The matrix maps 14 controls to CIS Controls v8.1 and NIST CSF so an FRFI, or the MSP serving one, can show its work.
How B-13 relates to other frameworks
B-13 deliberately aligns with established frameworks. Most FRFIs and their vendors evidence B-13 using NIST Cybersecurity Framework functions and CIS Controls v8.1 safeguards, which is exactly how our readiness matrix is structured. B-13 also connects to OSFI’s Technology and Cyber Security Incident Reporting advisory, which requires FRFIs to report material incidents to OSFI promptly.
What “non-compliance” looks like
B-13 is a supervisory guideline, not a fining statute. OSFI does not levy fixed penalties for B-13 gaps; instead it escalates supervisory attention, increased scrutiny, findings that must be remediated, higher staging, and in serious cases constraints on the institution. For a vendor, the consequence is sharper: failing a B-13-driven due-diligence review can cost you the contract.
How to demonstrate B-13 readiness: a roadmap
- Establish governance. Document who owns technology and cyber risk and the framework you follow.
- Inventory and classify assets. You cannot protect or recover what you have not mapped.
- Prove resilience. Maintain tested disaster-recovery and incident-response capabilities with evidence.
- Run the readiness matrix. Map your controls to NIST CSF and CIS v8.1 and capture the evidence each row expects.
- Prepare your reporting path. Know how and when a material incident would be reported to OSFI.
B-13 and the rest of the financial-sector stack
FRFIs and their advisors rarely face B-13 alone. Investment dealers and advisors layer CIRO cybersecurity expectations; everyone handling personal information still answers to PIPEDA; and cyber insurers test much of the same ground. Our financial services IT practice and vCISO services are built around this stacked reality.
About this guide
This guide is maintained by Mike Pearlstein, CISSP, Founder and CEO of Fusion Computing Limited, a Canadian managed IT and cybersecurity provider and Microsoft Solutions Partner. It is reviewed as legislation and program requirements change. Definitions are written for business leaders, not lawyers, for a legal opinion on your specific obligations, consult qualified counsel.
Want a second opinion on where your organization actually stands? We will review your current controls against this framework in plain language, no jargon, no obligation.
Common Questions
When did OSFI Guideline B-13 come into effect?
OSFI Guideline B-13, Technology and Cyber Risk Management, came into effect on January 1, 2024. It applies to federally regulated financial institutions and increasingly shapes the requirements those institutions impose on their technology vendors and MSPs.
Who does OSFI B-13 apply to?
It directly applies to federally regulated financial institutions, banks, and federally regulated trust, loan, and insurance companies. Through B-13’s third-party and outsourcing expectations, the vendors, fintechs, and managed service providers that serve those institutions must be able to evidence the same controls.
What are the three domains of OSFI B-13?
Governance and Risk Management; Technology Operations and Resilience; and Cyber Security. Together they expect an FRFI to demonstrate accountable governance, the ability to operate through disruption, and identify/defend/detect/respond/recover cyber capabilities proportionate to its risk.
Are there fines for not complying with OSFI B-13?
B-13 is a supervisory guideline, not a fining statute, so there are no fixed monetary penalties. OSFI instead escalates supervisory action, increased scrutiny, remediation requirements, and higher staging. For a vendor, the practical penalty is failing due diligence and losing the contract.
How does B-13 relate to NIST and CIS Controls?
B-13 is principles-based and aligns with established frameworks. Most institutions and vendors evidence it using NIST Cybersecurity Framework functions and CIS Controls v8.1 safeguards, which is how our OSFI B-13 readiness matrix is structured.
We are an MSP, not a bank, does B-13 affect us?
Yes, indirectly but materially. If you provide technology services to a federally regulated financial institution, B-13’s third-party and outsourcing expectations mean your client must verify your controls. Being able to map your environment to B-13, NIST CSF, and CIS v8.1 is increasingly a condition of winning and keeping FRFI work.
Part of the Canadian IT Compliance Hub – PIPEDA, PHIPA, OSFI B-13, Bill C-8, CyberSecure Canada and cyber-insurance guidance for Canadian SMBs, in one place.
Updated

