Overview
OSFI Guideline B-13 is Canada's prudential technology and cyber risk management guideline for federally regulated financial institutions. It is not a third-party risk rule, although third-party technology risk is part of it.
B-13 pushes FRFIs to treat technology and cyber risk as enterprise risk. The institution should know which systems and data support business operations, how cyber risk is controlled, how technology changes are governed, how incidents are detected and handled, and how third-party technology providers fit into the risk profile.
Teams need a joined view of systems, applications, data, identities, privileged access, cloud services, managed service providers, business owners, critical operations, control evidence, and incidents. If a provider hosts a critical platform, the record should connect provider risk to technology operations, cyber controls, recovery, and business impact.
This implementation guide explains what the regulation requires, how those requirements translate into operational controls and evidence, and how Halbarad helps organizations operationalize compliance through assessments, continuous monitoring, governance workflows, and supply chain risk intelligence.