OSFI B-13
What is OSFI B-13?
Canadian OSFI Technology and Cyber Risk Management guideline. It comprises 8 controls organised across 8 domains, and applies in Canada.
How OSFI B-13 maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains OSFI B-13 groups its controls into
Frameworks that share controls with OSFI B-13
Each of these has at least one control mapped to a control in OSFI B-13. The number is how many OSFI B-13 controls are shared, counted from the mapping graph.
Protective Security Policy Framework (PSPF) Release 2024
5 shared controlsUK Open Banking Standard
5 shared controlsEASA Part-IS - Information Security in Aviation
5 shared controlsISO 27019
5 shared controlsIEC 62443
5 shared controlsFFIEC IT Examination Handbook
5 shared controlsAPI 1164
5 shared controlsNIST SP 1800-32
5 shared controlsWhere OSFI B-13 overlaps with the standards you already hold
What OSFI B-13 means in your sector
What OSFI B-13 means for your job
Questions people ask about OSFI B-13
What is OSFI B-13?
How many controls does OSFI B-13 have?
Where does OSFI B-13 apply?
What frameworks does OSFI B-13 map to?
How do I get started with OSFI B-13 compliance?
Query OSFI B-13 programmatically
OSFI B-13, its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
OSFI B-13 API reference and MCP config →How ready are you for OSFI B-13?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.