The Office of the Superintendent of Financial Institutions (OSFI) is consulting on the draft guideline B‑13 on technology and cyber risk management. The proposed guideline sets out expectations for sound technology and cyber risk management across five domains. Each domain is guided by a desired outcome and related technology-neutral principles that collectively contribute to operational resilience. The Annex to the consultation letter also sets out the feedback OSFI received as a result of the Fall 2020 discussion paper on technology and related risks. The comment period for this consultation ends on February 09, 2021.
The expectations outlined in the guideline aim to support federally regulated financial institutions in developing greater resilience to technology and cyber risks in the areas of—
- Governance and Risk Management: Covers expectations for the formal accountability, leadership, organizational structure, and framework used to support risk management and oversight of technology and cyber security
- Technology Operations: Sets expectations for management and oversight of risks related to the design, implementation and management of technology assets and services.
- Cyber Security: Covers expectations for management and oversight of cyber risk
- Third-Party Provider Technology and Cyber Risk: Expands on he existing OSFI guidance for outsourcing and third-party risk, to set expectations for institutions that engage with third-party providers to obtain technology and cyber services and/or other services that give rise to cyber and/or technology risk
- Technology Resilience: Sets expectations for capabilities to deliver technology services through operational disruption
Comment Period: February 09, 2021
Keywords: Americas, Canada, Banking, Cyber Risk, Guideline B-13, Operational Resilience, Governance, Operational Risk, Regtech, OSFI
Previous ArticleHM Treasury Issues Proposals on Future Regulatory Framework Review
The European Banking Authority (EBA) published four draft principles to support supervisory efforts in assessing the representativeness of COVID-19-impacted data for banks using the internal ratings based (IRB) credit risk models.
The European Council and the European Parliament (EP) reached a provisional political agreement on the Corporate Sustainability Reporting Directive (CSRD).
The Prudential Regulation Authority (PRA) launched a consultation (CP6/22) that sets out proposal for a new Supervisory Statement on expectations for management of model risk by banks.
The European Commission (EC) published the Delegated Regulation 2022/954, which amends regulatory technical standards on specification of the calculation of specific and general credit risk adjustments.
The Bank for International Settlements (BIS) Innovation Hub updated its work program, announcing a set of projects across various centers.
The European Insurance and Occupational Pensions Authority (EIOPA) published two consultation papers—one on the supervisory statement on exclusions related to systemic events and the other on the supervisory statement on the management of non-affirmative cyber exposures.
Certain members of the U.S. Senate Committee on Banking, Housing, and Urban Affairs issued a letter to the Securities and Exchange Commission (SEC)
The European Insurance and Occupational Pensions Authority (EIOPA) published a consultation paper on the advice on the review of the securitization prudential framework in Solvency II.
The Prudential Regulation Authority (PRA) issued a statement on PRA buffer adjustment while the Bank of England (BoE) published a notice on the statistical reporting requirements for banks.
The Basel Committee on Banking Supervision (BCBS) issued principles for the effective management and supervision of climate-related financial risks.