Featured Product

    OSFI to Amend Guideline on Technology and Cyber Risk Management

    June 09, 2022

    The Office of the Superintendent of Financial Institutions (OSFI) published, in the form of a letter, its response to the feedback received on the draft Guideline B-13 on technology and cyber risk management. The response explains the changes made to the guideline as a result of the comments received and informs that the final guideline will be published in the coming weeks.

    The Guideline B-13 on technology and cyber risk management will be applicable to all federally regulated financial institutions. The final guideline should be read from a risk-based perspective that allows federally regulated financial institutions to compete effectively and take full advantage of digital innovation, while maintaining sound technology risk management. OSFI received feedback from interested stakeholders during the three-month consultation on draft Guideline B-13 and implemented the following changes to the final Guideline B-13:

    • OSFI removed several expectations and examples that were overly prescriptive in some areas and included fewer prescriptive expectations and examples, with added emphasis on approaching Guideline B-13 from a risk-based perspective.
    • OSFI streamlined the final Guideline B-13 to focus on three core domains, instead of the earlier five domains: Governance and Risk Management, Technology Operations and Resilience, and Cyber Security. OSFI achieved this by moving third-party expectations to the revised draft Guideline B-10 (Third Party Risk Management) and by consolidating and streamlining Technology Operations and Resilience domain.
    • OSFI clarified the definitions in final Guideline B-13 by advancing a single definition of “technology risk” that includes cyber risk. OSFI also noted that the Guideline B-13 definitions were informed by recognized standard-setting bodies.
    • Respondents had identified expectations that were overlapping and confusing in some areas and OSFI clarified these in the final Guideline B-13, in addition to removing or consolidating expectations, where appropriate.


    Related Link: Letter


    Keywords: Americas, Canada, Banking, Insurance, Securities, Guideline B-13, Cyber Risk, Technology Risk, Regtech, Operational Resilience, OSFI

    Related Articles

    ESAs Issue Multiple Regulatory Updates for Financial Sector Entities

    The three European Supervisory Authorities (ESAs) issued a letter to inform about delay in the Sustainable Finance Disclosure Regulation (SFDR) mandate, along with a Call for Evidence on greenwashing practices.

    November 15, 2022 WebPage Regulatory News

    ISSB Makes Announcements at COP27; IASB to Propose IFRS 9 Amendments

    The International Sustainability Standards Board (ISSB) of the IFRS Foundations made several announcements at COP27 and with respect to its work on the sustainability standards.

    November 10, 2022 WebPage Regulatory News

    IOSCO Prioritizes Green Disclosures, Greenwashing, and Carbon Markets

    The International Organization for Securities Commissions (IOSCO), at COP27, outlined the regulatory priorities for sustainability disclosures, mitigation of greenwashing, and promotion of integrity in carbon markets.

    November 09, 2022 WebPage Regulatory News

    EBA Finalizes Methodology for Stress Tests, Issues Other Updates

    The European Banking Authority (EBA) issued a statement in the context of COP27, clarified the operationalization of intermediate EU parent undertakings (IPUs) of third-country groups

    November 09, 2022 WebPage Regulatory News

    OSFI Sets Out Work Priorities and Reporting Updates for Banks

    The Office of the Superintendent of Financial Institutions (OSFI) published an annual report on its activities, a report on forward-looking work.

    November 07, 2022 WebPage Regulatory News

    APRA Finalizes Changes to Capital Framework, Issues Other Updates

    The Australian Prudential Regulation Authority (APRA) finalized amendments to the capital framework, announced a review of the prudential framework for groups.

    November 03, 2022 WebPage Regulatory News

    BIS Hub and Central Banks Conduct CBDC and DeFI Pilots

    The Bank for International Settlements (BIS) Innovation Hubs and several central banks are working together on various central bank digital currency (CBDC) pilots.

    November 03, 2022 WebPage Regulatory News

    ECB Sets Deadline for Banks to Meet Its Climate Risk Expectations

    The European Central Bank (ECB) published the results of its thematic review, which shows that banks are still far from adequately managing climate and environmental risks.

    November 02, 2022 WebPage Regulatory News

    ESAs, ECB, & EC Issue Multiple Regulatory Updates for Financial Sector

    Among its recent publications, the European Banking Authority (EBA) published the final standards and guidelines on interest rate risk arising from non-trading book activities (IRRBB)

    October 31, 2022 WebPage Regulatory News

    EC Adopts Final Rules Under CRR, BRRD, and Crowdfunding Regulation

    The European Commission (EC) recently adopted regulations with respect to the calculation of own funds requirements for market risk, the prudential treatment of global systemically important institutions (G-SIIs)

    October 26, 2022 WebPage Regulatory News
    RESULTS 1 - 10 OF 8582