OSFI B-13
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Assurance and Audit
Operate independent assurance + internal audit + external examination per OSFI B-13 Domain 6. Independent Assurance and Internal Audit must (a) maintain Internal Audit function independence per B-13 + OSFI Corporate Governance Guideline + (b) provide assurance on B-13 framework + control effectiveness + (c) develop risk-based audit plan covering technology and cyber risk + (d) execute audits with sufficient methodology + workpapers + supervisory review + QA + (e) report findings + ratings + management responses + remediation status to Audit Committee + (f) follow up to closure. External examination must (a) cooperate with OSFI Supervisory Activities + inspections + (b) respond to Information Requests + (c) implement remediation per Notices of Intent + Recommendations + Stage 1/2/3 supervisory ratings + (d) maintain transparency on emerging risks + control gaps. Coordinate with external a
- OSFI B-13 compliance evidence for OSFIB13-6
- compliance nominal
Cyber Hygiene and Awareness
Operate cyber hygiene + security awareness per OSFI B-13 Domain 5. Cyber hygiene must (a) maintain patch management with risk-based prioritisation + KEV-driven remediation + (b) configuration management with hardened baselines + drift detection + (c) vulnerability scanning + remediation tracking + (d) credential hygiene including password policies + MFA + privilege management + (e) backup integrity + ransomware resilience + immutable backup. Security awareness and training must (a) baseline training all personnel + (b) role-specific training (developers + administrators + executives + customer-facing + finance + HR + procurement) + (c) phishing simulation with realistic scenarios + measurement + targeted reinforcement + (d) executive briefing on emerging threats + organisational risk + (e) maintain training records + completion + competency assessment.
- OSFI B-13 compliance evidence for OSFIB13-5
- compliance nominal
Cyber Security (5 NIST CSF Functions)
Operate cyber security per OSFI B-13 Domain 3 aligned with NIST Cybersecurity Framework 2.0 functions (Govern + Identify + Protect + Detect + Respond + Recover). Identification must (a) maintain asset inventory + business context + risk assessment + governance + (b) implement vulnerability management with KEV + vendor advisory + threat intelligence consumption. Protection must (a) implement identity and access management + multi-factor authentication for privileged + remote + administrative + (b) network segmentation + zero trust progression + (c) endpoint protection + EDR + (d) data protection including encryption + DLP + classification + (e) application security including SAST + DAST + dependency scanning + (f) configuration hardening + change management + (g) secure development lifecycle + (h) security awareness + training. Detection must (a) implement SIEM + UEBA + EDR + with correla
- OSFI B-13 compliance evidence for OSFIB13-3
- compliance nominal
Governance and Three Lines
Establish governance + risk management + three lines of defense per OSFI Guideline B-13 Technology and Cyber Risk Management (issued July 2022, effective 1 January 2024). B-13 applies to Federally Regulated Financial Institutions (FRFIs) including banks + insurance companies + trust and loan companies + pension plan administrators + Crown corporations. Governance must (a) establish technology and cyber risk management framework approved by Board + senior management + (b) maintain risk appetite and tolerance per Domain 1 + (c) implement three lines of defense with documented responsibilities (Line 1: business + IT operations; Line 2: independent technology and cyber risk management; Line 3: internal audit) + (d) integrate with broader Enterprise Risk Management + (e) name accountable executive (typically CISO + CTO + COO + or equivalent) with documented reporting line + decision authority
- OSFI B-13 compliance evidence for OSFIB13-1
- compliance nominal
Incident Reporting
Operate Incident Reporting to OSFI per B-13 Technology and Cyber Incident reporting + broader OSFI incident reporting framework. Incident Reporting to OSFI must (a) report technology and cyber incidents per OSFI Technology and Cyber Incident reporting requirements within 24 hours of becoming aware where incident has high operational impact + (b) follow-up with full assessment within applicable timeframe + (c) maintain coordination with OSFI relationship manager + (d) coordinate with broader regulatory reporting (PIPEDA breach notification + provincial regulators + payment network + customers + employees + investors). Regulatory cooperation must (a) maintain OSFI relationship manager engagement + (b) respond to OSFI information requests + (c) cooperate with OSFI inspections + (d) implement remediation per OSFI direction + (e) maintain transparency on emerging risks. Communication and esca
- OSFI B-13 compliance evidence for OSFIB13-7
- compliance nominal
Metrics and Continuous Improvement
Operate metrics + monitoring + continuous improvement + maturity per OSFI B-13 Domain 6 + cross-cutting expectations. Metrics, Monitoring and Continuous Improvement must (a) maintain technology and cyber risk metrics covering control coverage + maturity + incident metrics + audit findings + training completion + phishing simulation results + third-party compliance + vulnerability remediation + (b) measure against documented thresholds + benchmarks + (c) report quarterly to executive + at least annually to board + (d) integrate with broader enterprise risk reporting. Maturity assessment must (a) assess against B-13 expectations + NIST CSF + ISO/IEC 27001/27002 + sectoral maturity model + (b) maintain maturity roadmap + improvement objectives + investment plan + (c) benchmark against peer FRFIs + industry indices. Continuous improvement must (a) feed lessons from incidents + audits + asses
- OSFI B-13 compliance evidence for OSFIB13-8
- compliance nominal
Technology Operations and Architecture
Operate technology operations + architecture + resilience per OSFI B-13 Domain 2. Technology architecture must (a) maintain enterprise architecture documentation including infrastructure + applications + data + integration + (b) align with documented architecture principles + (c) consider security + resilience + scalability by design. Asset management must (a) maintain inventory of technology assets + (b) maintain classification per criticality + (c) integrate with change management + capacity planning + (d) coordinate with vendor management. Technology change management must (a) implement change control covering all in-scope technology changes + (b) maintain change advisory board where applicable + (c) test changes before production deployment + (d) maintain rollback capability + (e) document emergency change procedures. Capacity and performance management must (a) monitor capacity + pe
- OSFI B-13 compliance evidence for OSFIB13-2
- compliance nominal
Third-Party Risk Management
Operate third-party risk management per OSFI B-13 Domain 4 + complementary OSFI Guideline B-10 Outsourcing of Business Activities and Functions. Third-Party Risk Management must (a) maintain third-party inventory categorised by criticality + service type + data access + (b) apply risk-based due diligence at acquisition + ongoing monitoring + (c) include cybersecurity + privacy + business continuity + sub-contractor flow-down + audit rights + insurance + breach notification + termination + transition assistance in contracts + (d) coordinate with OSFI on material outsourcing where required. Cloud computing arrangements per B-10 + B-13 must (a) assess cloud provider security + resilience + compliance + (b) maintain cloud-specific risk assessment + (c) implement cloud governance covering provisioning + change management + monitoring + (d) consider data residency + sovereignty + cross-border
- OSFI B-13 compliance evidence for OSFIB13-4
- compliance nominal
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the OSFI B-13 framework page.