---
title: "OSFI Guideline B-10 — Third-Party Risk Management — KYE Protocol™ coverage"
description: "OSFI Guideline B-10 — Third-Party Risk Management coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it."
url: https://kyeprotocol.com/compliance/osfi-b-10/
lang: en
source: "KYE Protocol"
---

> OSFI Guideline B-10 — Third-Party Risk Management coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.

OSFI Guideline B-10 — Third-Party Risk Management

# OSFI Guideline B-10 — Third-Party Risk Management — 100% of in-scope requirements covered.

3 requirements · 3 in scope (3 enforced). The 100% is weighted over the in-scope base.

**Source:** Office of the Superintendent of Financial Institutions, Guideline B-10 Third-Party Risk Management (effective 1 May 2024). Risk-based, principles-based management of third-party arrangements: a central record of third-party arrangements, risk assessment proportionate to criticality, and ongoing monitoring of third-party performance and concentration risk.

## By category

| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
| --- | --- | --- | --- | --- | --- | --- |
| Third-party arrangement register | 1 | 1 | 0 | 0 | 0 | **100%** |
| Risk assessment by criticality | 1 | 1 | 0 | 0 | 0 | **100%** |
| Ongoing monitoring + concentration risk | 1 | 1 | 0 | 0 | 0 | **100%** |

## Every requirement → the KYE™ artefact that enforces it

| ID | Title | Status | KYE™ enforcement |
| --- | --- | --- | --- |
| `osfi-b-10.register` | Third-party arrangement register: maintain a central record of third-party arrangements with sufficient detail to manage their risks | enforced | **audit\_events**: `kye.risk.authority_register.v1`, `kye.compliance.attestation.v1` **engines**: `internal`, `internal` **constitution\_refs**: `constitution/51-NO-SPOF.md` |
| `osfi-b-10.risk-assessment` | Risk assessment by criticality: assess and manage third-party risk proportionate to the criticality and risk of each arrangement | enforced | **audit\_events**: `kye.risk_assessment.v1`, `kye.purpose.admissibility.v1` **engines**: `internal` **constitution\_refs**: `constitution/13-RESILIENCE-LOOP.md`, `constitution/12-PURPOSE-PERMISSION.md` |
| `osfi-b-10.monitoring` | Ongoing monitoring + concentration risk: monitor third-party performance and assess concentration risk arising from reliance on a small number of providers | enforced 1 unverified citation | **audit\_events**: `kye.resilience.signal.v1` unverified citation, `kye.compliance.attestation.v1` **engines**: `internal`, `internal` **constitution\_refs**: `constitution/51-NO-SPOF.md` |

Canonical KYE™ surfaces referenced on this page: [KYE Protocol™](https://kyeprotocol.com/).
