OSFI B-13 explained for fintechs and suppliers

OSFI Guideline B-13 sets expectations for how federally regulated financial institutions manage technology and cyber risk, and it has been in effect since January 1, 2024. It does not bind fintechs or technology suppliers directly. It reaches them through Guideline B-10, which expects institutions to write security, incident and information terms into their contracts with third parties.

What is OSFI Guideline B-13?

Guideline B-13 applies to all federally regulated financial institutions (FRFIs): banks, trust and loan companies, and federally regulated insurers, including foreign bank and foreign insurance company branches. It is principles-based and organized in three domains, each with a stated outcome:

  • Governance and risk management: clear accountability, strategy and a risk management framework.
  • Technology operations and resilience: a stable, current environment, with incident management and recovery that work.
  • Cyber security: confidentiality, integrity and availability, including multi-factor authentication on external-facing channels and privileged accounts, and intelligence-led testing such as penetration testing and red teaming.

Does OSFI B-13 apply to suppliers?

OSFI’s Guideline B-10 names cloud service providers, managed service providers and technology companies that deliver financial services as third parties. As of September 2026, its expectations scale with the risk and criticality of the arrangement, and they land on your desk as contract terms:

B-10 expects the institution to secureWhat the supplier should have ready
Clear roles for technology and cyber controlsA shared-responsibility description that says who configures what
Notice of incidents at the supplier or its subcontractorsAn incident process fast enough for the institution’s own reporting to OSFI
Notice of subcontracting and the ability to assess the change; for higher-risk work, possibly a right to refuse a subcontractorA current list of subprocessors and where they operate
Rights for the institution and OSFI to evaluate your risk practices, directly or through an appointed reviewerIndependent reports and evidence you can share on request
Continuity, termination and exitTested recovery plans and a documented way to return data

Can a supplier be B-13 compliant?

The common myth is that a supplier can be “B-13 compliant”. It cannot, because the guideline is addressed to the institution. What you can be is easy to approve. Does a SOC 2 report or an ISO 27001 certificate satisfy B-13? They help but do not settle it. B-10 lets an institution hold a higher-risk supplier to recognized industry standards, and counts independent reports among its sources of assurance; an ISO 27001 certificate or a SOC 2 report is that kind of evidence. Neither replaces the contract terms, incident notice and information rights the institution still has to secure.

The second error is treating the security questionnaire as the whole exercise. The contract terms above outlive it, and an incident clause you cannot meet is a breach of contract waiting to happen. How institutions run this from their side is in security for credit unions and insurers; the buyer-side program is vendor risk management.

Where should a supplier start?

Map the questions you are already being asked to the three B-13 domains and the B-10 contract provisions, then fix the gaps an institution would treat as material: incident notice, subcontractor disclosure, access control and exit. The readiness work that sits behind those answers is regulated-sector readiness. This is not legal advice; contract positions are for your counsel.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

Testing and adversary simulation are carried out only with signed authorization, to a scope agreed in writing.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Does OSFI B-13 apply to a fintech or technology supplier?

Not directly. B-13 applies to federally regulated financial institutions. A supplier meets it second-hand, through the contract, the due diligence questionnaire and the rights the institution is expected to hold over its third parties under Guideline B-10.

Does SOC 2 or ISO 27001 satisfy B-13?

They help but do not settle it. B-10 lets an institution hold a higher-risk supplier to recognized industry standards, and counts independent reports among its sources of assurance; an ISO 27001 certificate or a SOC 2 report is that kind of evidence. Neither replaces the contract terms, incident notice and information rights the institution still has to secure.

Can we negotiate the contract terms?

Yes, within limits. OSFI acknowledges that not all contracts with third parties will be negotiable, and asks institutions to manage the risk by other means where they cannot contract for it. Expect more scrutiny, not a waiver.

What should a supplier do first?

Map the questions you are already being asked to the three B-13 domains and the B-10 contract provisions, then fix the gaps an institution would treat as material: incident notice, subcontractor disclosure, access control and exit.

Selling to a regulated institution

Send us the questionnaire or contract schedule you have been given, and the reply says which answers an institution would treat as gaps. More of our writing is indexed at writing.

Discuss a scope