OSFI has set out the schedule for release of draft guidance on the management of technology risks by federally regulated financial institutions and private pension plans. This follows an OSFI discussion paper on a range of technology risk areas such as cyber security, advanced analytics, and third-party technology ecosystem. The feedback period on the paper ended on December 15, 2020, with respondents expressing broad support for emerging principles-based and technology-neutral perspectives on technology risk management.
In the feedback, the respondents indicated that OSFI should first leverage its existing guidance and align any additional guidance with existing international and information technology standards. In light of the feedback received on the discussion paper, OSFI plans to release draft guidance and industry letters as per the following schedule:
- OSFI plans to publish an industry letter on operational resilience and a new draft guideline on technology and cyber risk in the third and fourth quarters of 2021, respectively.
- In the first quarter of 2022, OSFI plans to publish a draft of the revised guideline on third-party risk and an industry letter on advanced analytics and model risk.
- In 2022-23, OSFI plans to publish the revised Guideline E-21 on operational risk management and the revised guidance on model risk.
Keywords: Americas, Canada, Banking, Insurance, Technology Risk, Operational Risk, Operational Resilience, Third-Party Risk, Cyber Risk, Regtech, OSFI
Next ArticleEBA Publishes Phase 1 of Reporting Framework 3.1
APRA issued a letter on the loss-absorbing capacity (LAC) requirements for domestic systemically important banks (D-SIBs) and published a discussion paper, along with the proposed the prudential standards on financial contingency planning (CPS 190) and resolution planning (CPS 900).
The European Commission (EC) launched a call for evidence, until March 18, 2022, as part of a comprehensive review of the macro-prudential rules for the banking sector under the Capital Requirements Regulation (CRR) and Directive (CRD IV).
The Financial Stability Board (FSB) published a report that sets out good practices for crisis management groups.
The Australian Prudential Regulation Authority (APRA) found that Heritage Bank Limited had incorrectly reported capital because of weaknesses in operational risk and compliance frameworks, although the bank did not breach minimum prudential capital ratios at any point and remains well-capitalized.
The Office of the Superintendent of Financial Institutions (OSFI) released the annual report for 2020-2021.
Through a letter addressed to the banking sector entities, the Office of the Superintendent of Financial Institutions (OSFI) announced deferral of the domestic implementation of the final Basel III reforms from the first to the second quarter of 2023.
EIOPA recently published a letter in which EC is informing the European Parliament and Council that it could not adopt the set of draft regulatory technical standards for disclosures under the Sustainable Finance Disclosure Regulation (SFDR) within the stipulated three-month period, given their length and technical detail.
The Financial Conduct Authority (FCA) published the third in a series of policy statements that set out rules to introduce the UK Investment Firm Prudential Regime (IFPR), which will take effect on January 01, 2022.
The Australian Prudential Regulation Authority (APRA) published, along with a summary of its response to the consultation feedback, an information paper that summarizes the finalized capital framework that is in line with the internationally agreed Basel III requirements for banks.
The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) issued a consultative report focusing on access to central counterparty (CCP) clearing and client-position portability.