OSFI Guideline B-13 — Technology & Cyber Risk Management

OSFI Guideline B-13 — Technology & Cyber Risk Management — 100% of in-scope requirements covered.

4 requirements · 4 in scope (4 enforced). The 100% is weighted over the in-scope base.

Source: Office of the Superintendent of Financial Institutions, Guideline B-13 Technology and Cyber Risk Management (effective 1 January 2024). Three domains: governance and risk management (Domain 1), technology operations and resilience (Domain 2), cyber security (Domain 3) — including the technology-asset register, secure-by-design, monitoring and detection, and incident management.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Governance + risk management (Domain 1)11000100%
Technology operations + resilience (Domain 2)22000100%
Cyber security — monitoring + incident (Domain 3)11000100%

Every requirement → the KYE™ artefact that enforces it

IDTitleStatusKYE™ enforcement
osfi-b-13.d1Domain 1 — Governance and risk management: maintain a technology and cyber risk-management framework with clear accountability, a risk appetite, and senior-management oversightenforcedaudit_events: kye.risk_assessment.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/12-PURPOSE-PERMISSION.md
osfi-b-13.d2-asset-registerDomain 2 — Technology asset management: maintain a current inventory of technology assets and their interdependencies, classified by criticalityenforcedaudit_events: kye.risk.authority_register.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/51-NO-SPOF.md
osfi-b-13.d2-resilienceDomain 2 — Technology resilience: design and operate technology to recover within tolerance and maintain critical operations during a disruptionenforced 1 unverified citationaudit_events: kye.resilience.signal.v1 unverified citation, kye.replay.proof.v1
engines: internal, internal
constitution_refs: constitution/25-EDGE-GOVERNANCE.md, constitution/51-NO-SPOF.md
osfi-b-13.d3Domain 3 — Cyber security: continuously monitor and detect cyber threats and manage cyber incidents, including timely reportingenforcedaudit_events: kye.signal.incident.opened.v1, kye.evidence.tool_call.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/35-STREAMING-LOGS.md

Canonical KYE™ surfaces referenced on this page: KYE Protocol™.