Law / Canada

OSFI Guideline B-10, Third-Party Risk Management

OSFI Guideline B-10, Third-Party Risk Management

Guidance, not a law: the Office of the Superintendent of Financial Institutions's reading of Prudential supervision of banks: the Office's objects and the Superintendent's directions to a bank. It binds nobody by itself; the law it reads does.

Guidance on a sector security regimes rule, addressed to private bodies.

Criminal exposure
No
Instrument type
guidance published by a regulator
Obligation class
Governance, Security, Reporting

As of .

What the regulator expects

  • It reaches you if you operate as a federally regulated financial institution (FRFI): a bank, foreign bank branch, foreign insurance company branch, life insurance or fraternal company, property and casualty company, or trust and loan company, with branches covered to the extent the guideline is consistent with your obligations in Canada. It applies in proportion to the risk and criticality of each third-party arrangement and to your size, nature, scope, complexity of operations and risk profile, and every line below states what OSFI expects.
  • Manage the risks of all your third-party arrangements, which include outsourced activities, brokers, utilities, financial market infrastructures, affiliates and other relationships involving goods, services or the storage, use or exchange of data, such as cloud service providers, managed service providers and technology companies that deliver financial services; you retain accountability for business activities, functions and services outsourced to a third party.
  • Establish a third-party risk management framework that sets out accountabilities, responsibilities, policies and processes for identifying, managing, mitigating, monitoring and reporting on risks from the use of third parties.
  • Undertake due diligence before entering a contract or other arrangement with a third party, and on an ongoing basis, in proportion to the risk and criticality of the arrangement.
  • Identify, monitor and manage the risk arising from subcontracting arrangements that your third parties undertake.
  • Enter into written arrangements that set out the rights and responsibilities of each party, and make sure the arrangements give you timely access to accurate and comprehensive information to oversee the third party's performance and risks, including a right to conduct or commission an independent audit of the third party.
  • Establish and maintain measures with the third party to protect the confidentiality, integrity and availability of records and data throughout the arrangement.
  • Where risk or criticality requires it, make sure third parties with elevated technology and cyber risk comply with your standards, or recognized industry standards, notably for access management and for data security and protection (see Guideline B-13), and develop cloud-specific requirements so that cloud adoption occurs in a planned and strategic manner.
  • Include in the agreement with the third party the ability to deliver operations through disruption, including maintenance, testing and activation of business continuity and disaster recovery plans, and keep contingency plans for critical third-party arrangements.
  • Monitor third-party arrangements to verify that the third party can keep meeting its obligations and managing risks, and keep documented processes with the third party to identify, investigate, escalate, track and remediate incidents.
  • Provide OSFI, upon request, information related to your business and strategic arrangements with third parties, risk management and control environments, and promptly notify OSFI of substantive issues affecting your ability to deliver critical operations due to a third-party arrangement.

Who enforces it

Enforcement body

Office of the Superintendent of Financial Institutions, which supervises financial institutions to make sure they are following its guidance.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

OSFI published the final Third-Party Risk Management Guideline, Guideline B-10, on . OSFI gave as the guideline's effective date, with the expectation that third-party arrangements commencing on or after that date adhere to it. Foreign bank branches and foreign insurance company branches have until to adhere to the guideline in the manner set out for branches.

The guideline is applicable to all federally regulated financial institutions, including foreign bank branches and foreign insurance company branches, to the extent it is consistent with applicable requirements and legal obligations related to their business in Canada.

The guideline defines a third-party arrangement as any type of business or strategic arrangement between the institution and an entity or individuals, by contract or otherwise, other than arrangements with customers and employment contracts. Third-party arrangements include relationships involving the provision of goods and services or the storage, use or exchange of data, such as cloud service providers, managed service providers and technology companies that deliver financial services.

OSFI expects the institution to manage the risks related to all third-party arrangements and emphasizes that the institution retains accountability for business activities, functions and services outsourced to a third party. OSFI expects institutions to apply the guideline in a manner proportionate to the risk and criticality of each third-party arrangement and to the size, nature, scope, complexity of operations and risk profile of the institution.

One of the guideline's six expected outcomes is that technology and cyber operations carried out by third parties are transparent, reliable and secure. The guideline says an institution should develop cloud-specific requirements to ensure that cloud adoption occurs in a planned and strategic manner. The guideline lists Guideline B-13 on Technology and Cyber Risk Management among the OSFI guidance to be read in conjunction with it.

The guideline says institutions are required to provide OSFI, upon request, information related to their business and strategic arrangements with third parties, risk management and control environments, to support supervisory monitoring and review work. OSFI expects to be promptly notified of substantive issues affecting the institution's ability to deliver critical operations due to a third-party arrangement. OSFI describes its guidelines as outlining expectations for financial institutions. OSFI says it uses its guidance as a basis for its supervision.

Back to the example  ·  Lint your app