Back to home

OSFI B-10

OSFI's guideline for managing third-party risk at federally regulated financial institutions.

Overview

Guideline B-10 from the Office of the Superintendent of Financial Institutions (OSFI) sets expectations for how federally regulated financial institutions (banks, insurers, trust companies) manage risk from their third-party arrangements, including fintechs and SaaS vendors serving them.

Why it matters

If you sell into Canadian banks, insurers, or credit unions, their procurement and vendor risk teams will assess you against B-10 expectations, even though the guideline is formally directed at the institution, not you. Being prepared to answer B-10-aligned due diligence materially shortens the sales cycle.

How Sense Six Cyber helps

  • Prepare vendor risk documentation aligned to B-10 expectations
  • Map your controls to the risk categories OSFI-regulated institutions assess
  • Support due diligence questionnaires from financial institution customers
  • Build incident notification and business continuity documentation
  • Advise on contract and SLA terms financial institutions typically require

Ideal for

Fintechs and SaaS vendors selling to Canadian banks, insurers, or other OSFI-regulated institutions.