The Office of the Superintendent of Financial Institutions (OSFI) published final revisions to its advisory on public disclosure requirements for global systemically important banks (G-SIBs). OSFI also published an updated cyber-security self-assessment template to help federally regulated financial institutions gauge and improve their current state of readiness in the face of emerging and expanding cyber threats. The self-assessment template covers criteria for reviewing third-party providers, including the providers of cloud services. It examines the capability of a financial institution to respond to a cyber incident in areas ranging from organization and resources, to how it manages threats, risks, and incidents, and allows an institution to rate each element on a scale from non-existent to continuous improvement. In a related development, OSFI updated the requirements governing how federally regulated financial institutions should disclose and report technology and cyber-security incidents to OSFI.
The updated advisory on technology and cyber-security incident reporting, which becomes effective from August 13, 2021, supports a coordinated and integrated response to technology and cyber-security incidents when they occur at federally regulated financial institutions. As updated, the federally regulated financial institutions must report a technology or cyber-security incident to the Technology Risk Division of OSFI as well as their Lead Supervisor at OSFI within 24 hours. Other changes to the advisory include a new "failure to report" section. In case a federally regulated financial institution does not report a cyber incident, it could be subject to increased supervisory oversight by OSFI, could be placed on a watchlist, or could be assigned one of the stages in the OSFI supervisory intervention approach, among other measures.
The revised advisory on G-SIB disclosures addresses changes to the disclosure requirements included in the updated assessment methodology of the Basel Committee on Banking Supervision, which was published in July 2018 and will take effect for the 2022 G-SIB assessment exercise; the key changes relate to the new Trading Volume indicator and the inclusion of insurance activities for certain existing G-SIB indicators. The revised advisory also provides guidance on the availability of publicly disclosed G-SIB indicators and the nature of qualitative information to accompany the disclosure requirements. This advisory applies to federally regulated banks with a Basel III leverage ratio exposure measure (including exposures arising from insurance subsidiaries) exceeding EUR 200 billion at financial year-end, or a bank that was included in the assessment sample by OSFI based on supervisory judgment.
- Letter on Revised G-SIB Advisory
- Advisory on G-SIB Disclosures
- Cyber Security Self-Assessment
- Self-Assessment Template (XLSX)
- News Release on Cyber Incident Reporting
- Cyber Incident Reporting Advisory
Keywords: Americas, Canada, Banking, G-SIBs, Basel, Incident Reporting, Reporting, Cyber Risk, Regulatory Capital, Self-Assessment Template, OSFI
Previous ArticleFCA to Enlist External Experts to Help Shape Work on ESG Issues
The three European Supervisory Authorities (ESAs) issued a letter to inform about delay in the Sustainable Finance Disclosure Regulation (SFDR) mandate, along with a Call for Evidence on greenwashing practices.
The International Sustainability Standards Board (ISSB) of the IFRS Foundations made several announcements at COP27 and with respect to its work on the sustainability standards.
The International Organization for Securities Commissions (IOSCO), at COP27, outlined the regulatory priorities for sustainability disclosures, mitigation of greenwashing, and promotion of integrity in carbon markets.
The European Banking Authority (EBA) issued a statement in the context of COP27, clarified the operationalization of intermediate EU parent undertakings (IPUs) of third-country groups
The Office of the Superintendent of Financial Institutions (OSFI) published an annual report on its activities, a report on forward-looking work.
The Australian Prudential Regulation Authority (APRA) finalized amendments to the capital framework, announced a review of the prudential framework for groups.
The Bank for International Settlements (BIS) Innovation Hubs and several central banks are working together on various central bank digital currency (CBDC) pilots.
The European Central Bank (ECB) published the results of its thematic review, which shows that banks are still far from adequately managing climate and environmental risks.
Among its recent publications, the European Banking Authority (EBA) published the final standards and guidelines on interest rate risk arising from non-trading book activities (IRRBB)
The European Commission (EC) recently adopted regulations with respect to the calculation of own funds requirements for market risk, the prudential treatment of global systemically important institutions (G-SIIs)