OSFI B-13 Compliance for Toronto Financial Services Firms: A Practical Guide for 2026
OSFI Guideline B-13 requires federally regulated financial institutions to demonstrate technology and cyber risk management. Here is what Toronto firms need.
OSFI B-13 Compliance Toronto Financial Services: What Your Firm Must Have in Place
OSFI Guideline B-13 - Technology and Cyber Risk Management - came into full effect for federally regulated financial institutions (FRFIs) on July 1, 2023. Three years into its implementation, OSFI examiners are moving from initial gap assessment to active scrutiny of whether institutions have operationalized their B-13 programs.
For Toronto financial services firms - including trust companies, federally chartered banks, insurance companies, and investment dealers that fall under OSFI's mandate - the question has shifted from whether B-13 applies to whether your implementation can withstand examination.
This guide explains what B-13 requires, where Toronto firms commonly fall short, and how to build an IT governance program that satisfies OSFI's expectations.
Guideline B-13 establishes OSFI's expectations for technology and cyber risk management across five domains:
B-13 requires a clear governance structure for technology and cyber risk. This means a designated Senior Accountable Officer (SAO) with explicit board-level accountability for technology risk, technology risk appetite statements approved by the board, and regular reporting to the board on technology and cyber risk exposure.
For smaller Toronto FRFIs, this governance structure is often the hardest B-13 requirement to operationalize. Many have appointed an SAO in title without establishing the reporting cadence, risk appetite framework, and board-level oversight structure B-13 envisions. OSFI examiners ask for board minutes showing technology risk discussions, not just an organizational chart.
B-13 requires FRFIs to maintain a complete, current inventory of technology assets - hardware, software, cloud services, and data assets. The inventory must include ownership, classification, and lifecycle information. OSFI's technology risk management expectations require that asset inventories be used to actively manage technology risk, not simply documented and filed.
This domain is where AI governance intersects directly with B-13. AI tools - including large language models used by staff, AI-powered SaaS platforms, and vendor systems that run AI against your data - are technology assets that must appear in your B-13 asset inventory. Shadow AI tools that have not been catalogued create an inventory gap that OSFI examiners specifically look for.