Featured Product

    OSFI Finalizes Third-Party Risk Guideline and Publishes Risk Outlook

    April 24, 2023

    The Office of the Superintendent of Financial Institutions (OSFI) published its final guideline on third-party risk management. OSFI also published its annual risk outlook for 2023-24, along with a new framework to strengthen the federally regulated financial institutions’ ability to withstand sophisticated cyber-attacks.

    The Guideline B-10 on third-party risk management sets out outcomes-focused, principles-based expectations for federally regulated financial institutions on the sound management of third-party risk. The Guideline outlines a principles-based approach with an increased emphasis on a risk-based approach to manage third-party arrangements. The Guideline also adopts a pragmatic approach to managing subcontractor and concentration risks according to the level of risk and criticality of the given third-party arrangement. OSFI expects the federally regulated financial institutions to understand the risk and criticality of all its third-party arrangements and apply this Guideline in a manner that is proportionate to both the risk and criticality of each third-party arrangement and the size, nature, scope, complexity of operations and risk profile of the federally regulated financial institution. The Guideline applies to all federally regulated financial institutions, excluding foreign bank branches and foreign insurance company branches. The Guideline will come into effect on May 01, 2024, roughly one year after its publication, to provide federally regulated financial institutions sufficient time to self-assess and build third-party risk management programs that comply with the new requirements of the Guideline, with the expectation that third-party arrangements commencing on or after the effective date adhere to the guideline and those entered into prior are being reviewed and updated at the earliest opportunity so that they adhere to the guideline by its effective date or as soon as possible thereafter.

    The Annual Risk Outlook report outlines the significant risks faced by the financial system in Canada, along with the regulatory and supervisory response of OSFI to those risks. The risks include housing market downturn risk, liquidity and funding risk, commercial real estate (CRE) risk, transmission risk from the non-bank financial intermediaries (NBFI) sector, corporate and commercial credit risk, digital innovation risk, climate risk, cyber risk and third-party risk. In addition, OSFI published near-term plan, along with the timelines, of guidance priorities for federally regulated financial institutions and private pensions in 2023-24. Key highlights of the report are as follows:

    • Climate Risk—OSFI will supervise climate-related risks in accordance with new principles-based regulatory expectations published in Guideline B-15: Climate Risk Management. OSFI also plan to develop a standardized climate scenario analysis exercise for all federally regulated financial institutions in 2024. Later in 2023, OSFI will launch a domestic Climate Risk Forum to raise awareness and build capacity amongst stakeholders on the evolution of the climate risk management framework.
    • Cyber Risk—OSFI plan to publish an Intelligence-Led Cyber Resilience Testing (I-CRT) framework to serve as an implementation guide for federally regulated financial institutions to conduct periodic I-CRT assessments by spring 2023. In response to rising technology and cyber threats and risks, OSFI issued the Technology and Cyber Risk Management Guideline B-13 in July 2022, with an effective date of January 01, 2024.
    • Digital Innovation Risk—OSFI plan to explore systemic and institutional vulnerabilities associated with digital innovations including blockchain applications (for example, crypto-assets, stablecoins, digital currencies, decentralized finance), artificial intelligence and machine learning (AI/ML), open finance, quantum computing, and other technologies.

    In addition to Annual Risk Outlook, OSFI released a framework to strengthen financial institutions’ resilience to cyber-attacks. The Intelligence-Led Cyber Resilience Testing (I-CRT) framework outlines a methodology and serves as an implementation guide for federally regulated financial institutions conducting I-CRT assessments. Under the I-CRT framework, OSFI provides guidance and oversight throughout the assessment, while FRFIs manage overall testing. The I-CRT framework is a supervisory tool that supplements Guideline B-13 on Technology and Cyber Risk Management, with I-CRT assessments that allow federally regulated financial institutions to proactively identify and address issues with their cyber resilience. The I-CRT framework currently applies to the systemically important banks and the internationally active insurance groups (IAIGs) in Canada. OSFI expects these institutions to conduct an I-CRT assessment at least once during each three-year supervisory cycle, beginning in 2023.

     

    Related Links


    Keywords: Americas, Canada, Banking, Cloud Service Providers, Liquidity Risk, Business Continuity, Annual Risk Outlook, ESG, Third-Party Risk, Guideline B-10, Concentration Risk, Climate Change Risk, Credit Risk, Cyber Risk, Operational Risk, Basel, Regtech, Cryptoassets, Subeadline, Operational Resilience, OSFI

    Featured Experts
    Related Articles
    News

    ISSB Sustainability Standards Expected to Become Global Baseline

    The finalization of the two sustainability disclosure standards—IFRS S1 and IFRS S2—is expected to be a significant step forward in the harmonization of sustainability disclosures worldwide.

    September 18, 2023 WebPage Regulatory News
    News

    IOSCO, BIS, and FSB to Intensify Focus on Decentralized Finance

    Decentralized finance (DeFi) is expected to increase in prominence, finding traction in use cases such as lending, trading, and investing, without the intermediation of traditional financial institutions.

    September 18, 2023 WebPage Regulatory News
    News

    BCBS Assesses NSFR and Large Exposures Rules in US

    The Basel Committee on Banking Supervision (BCBS) published reports that assessed the overall implementation of the net stable funding ratio (NSFR) and the large exposures rules in the U.S.

    September 14, 2023 WebPage Regulatory News
    News

    Global Agencies Focus on ESG Data, Climate Litigation and Nature Risks

    At the global level, supervisory efforts are increasingly focused on addressing climate risks via better quality data and innovative use of technologies such as generative artificial intelligence (AI) and blockchain.

    September 14, 2023 WebPage Regulatory News
    News

    ISSB Standards Shine Spotlight on Comparability of ESG Disclosures

    The finalization of the IFRS sustainability disclosure standards in late June 2023 has brought to the forefront the themes of the harmonization of sustainability disclosures

    August 22, 2023 WebPage Regulatory News
    News

    EBA Issues Several Regulatory and Reporting Updates for Banks

    The European Banking Authority (EBA) recently issued several regulatory publications impacting the banking sector.

    August 10, 2023 WebPage Regulatory News
    News

    BCBS Proposes to Revise Core Principles for Banking Supervision

    The Basel Committee on Banking Supervision (BCBS) launched a consultation on revisions to the core principles for effective banking supervision, with the comment period ending on October 06, 2023.

    August 04, 2023 WebPage Regulatory News
    News

    US Proposes Final Basel Rules, Transition Period to Start in July 2025

    The U.S. banking agencies (FDIC, FED, and OCC) recently proposed rules implementing the final Basel III reforms, also known as the Basel III Endgame.

    August 04, 2023 WebPage Regulatory News
    News

    FSB Report Outlines Next Steps for Climate Risk Roadmap

    The Financial Stability Board (FSB) recently published the second annual progress report on the July 2021 roadmap to address climate-related financial risks.

    August 04, 2023 WebPage Regulatory News
    News

    EBA Plans on Ad-hoc ESG Data Collection and Climate Scenario Exercise

    The recognition of climate change as a systemic risk to the global economy has further intensified regulatory and supervisory focus on monitoring of the environmental, social, and governance (ESG) risks.

    July 31, 2023 WebPage Regulatory News
    RESULTS 1 - 10 OF 8931