Canada
OSFI's B-13 and B-10 remain the backbone of Canadian financial GRC work
Technology and cyber risk management, plus third party risk, are where most Canadian bank and insurer control testing actually happens.

What do OSFI Guidelines B-13 and B-10 cover?
B-13 sets OSFI's expectations for technology and cyber risk management at federally regulated financial institutions, covering governance, technology operations, cyber security and incident management. B-10 covers third party risk management, including due diligence, contracts and ongoing monitoring of service providers. Together they define most of the control testing Canadian banks and insurers actually run.
Key facts
Guideline B-13, Technology and Cyber Risk Management, was published 31 July 2022.
B-13 applies to banks, foreign bank branches, insurers, and trust and loan companies.
Guideline B-10 covers third party risk management and is frequently examined alongside B-13.
Why these two
B-13 sets OSFI's expectations for technology and cyber risk across governance, technology operations, cyber security and third party provisioning. OSFI also publishes a self-assessment tool against it.
B-10 covers third party risk management, and OSFI has issued consequential amendments linking B-10 and B-13 for foreign branches.
What the work looks like
Control mapping against B-13 domains, evidence collection for change and incident management, and third party inventories with criticality ratings and exit planning.
For candidates targeting Canadian financial institutions, this is the vocabulary hiring managers use in interviews.
What it means for you
If you want Canadian financial services GRC work, read B-13 end to end and run the OSFI self-assessment tool against a system you know. It turns a reading exercise into a story you can tell.
Regulation only pays you if you can show the work.
The GRC Experience Program builds practical project experience, interview-ready stories and the positioning to prove it.
Turn This Into Something You Can Prove.
Short fit call. Clear next step. If neither program is right for you, we'll tell you.
Related posts

Canada's Bill C-8 is law: what the Critical Cyber Systems Protection Act changes
Royal assent on 15 June 2026 created a federal cyber duty for telecom, banking, energy, transport and nuclear operators. The Act is on the books but not yet in force.
Read article
AI agents are now running the attack, and the timelines have collapsed
Unit 42 documented an enterprise network compromised in under ten hours by agents rather than operators. Mandiant traced a worm through roughly 100 repositories after a hijacked coding assistant session. This is the threat model every control owner now inherits.
Read article
The GRC market is on track to triple, and the scarce skill is judgment, not tooling
Grand View Research puts enterprise GRC at 72.4 billion dollars in 2025 and 203.7 billion by 2033. ISC2 finds 59 percent of practitioners reporting critical or significant skills gaps. The demand is for people who can explain risk, not only collect evidence.
Read article