★ TPRM Insights

OSFI B-10: Third-Party Risk Guide for Canadian Banks

7 min read · Vendor Risk · September 2026

When Canada’s banking regulator rewrote its rules for outsourcing in 2024, it didn’t just update a checklist — it redefined what accountability for vendors actually means. OSFI B-10 third-party risk management is now the baseline every federally regulated financial institution in Canada must meet, replacing a guideline that predated cloud computing, API banking, and fourth-party AI risk. For CISOs, CPOs, and Heads of Risk running vendor programs built on the old rulebook, understanding what changed — and what OSFI expects next — is no longer optional.

★ Key Takeaways

OSFI B-10 took effect May 1, 2024, replacing a 2009 guideline built for a pre-cloud era

All federally regulated Canadian FIs — banks, insurers, trust companies — must comply, scaled by size and criticality

B-10 requires a continuous, risk-classified inventory of third-party arrangements, not annual reviews

Fourth-party subcontractor risk and defined vendor exit strategies are now explicit expectations

What Is OSFI B-10 and Why Does It Matter for Canadian Financial Institutions?

OSFI B-10 is the Office of the Superintendent of Financial Institutions’ guideline governing how federally regulated financial institutions (FRFIs) — banks, insurers, and trust companies — manage risk arising from third-party arrangements, from cloud providers to payment processors to outsourced operations. Finalized in 2023 and effective May 1, 2024, it replaced a 2009-era guideline written before cloud infrastructure, embedded finance, and AI-driven vendor tooling reshaped how Canadian FIs operate. The update reflects a broader global shift — echoed in the EU’s DORA, the UK’s operational resilience regime, and the US OCC’s third-party guidance — toward treating vendor risk as a continuous, board-level discipline rather than a procurement checkbox.

For Canadian FIs, B-10 matters because it raises the bar on documentation, monitoring, and accountability simultaneously. Institutions that treated their prior third-party programs as static onboarding exercises now need continuous oversight mechanisms, and OSFI has signaled through supervisory reviews that gaps in third-party inventories or concentration-risk visibility will draw scrutiny.

Who Must Comply With OSFI B-10?

Every federally regulated financial institution in Canada — domestic banks, foreign bank branches, insurance companies, and trust and loan companies — falls within OSFI B-10’s scope, regardless of size. The guideline applies proportionally: a large systemically important bank is expected to run a more sophisticated third-party risk function than a smaller regional trust company, but neither is exempt from the core expectations around due diligence, contractual controls, and ongoing monitoring.

Critically, B-10’s scope extends beyond direct vendor relationships to include intragroup arrangements and, where material, fourth-party subcontractors. An FI that outsources core banking infrastructure to a cloud provider is expected to understand — and where necessary assess — the risk introduced by that provider’s own critical subcontractors, not just the primary contract.

  • Domestic banks and foreign bank branches operating in Canada
  • Federally regulated insurance companies and reinsurers
  • Trust and loan companies under OSFI supervision

How Does OSFI B-10 Change Third-Party Risk Requirements?

OSFI B-10 shifts third-party risk management from point-in-time due diligence to a continuous, lifecycle-based discipline spanning pre-contract assessment, contract negotiation, ongoing monitoring, and exit planning. FRFIs are now expected to maintain a comprehensive, current inventory of all third-party arrangements, classified by criticality, so senior management and the board can see concentration risk and single points of failure across the vendor portfolio at any time.

The guideline also sharpens expectations around contractual controls — requiring provisions for audit rights, data location and sovereignty, incident notification timelines, and defined exit and transition strategies for critical arrangements. Business continuity and resilience testing for critical third parties is no longer optional documentation; OSFI expects FIs to demonstrate they could operate through a vendor failure, not just describe the plan on paper.

  • Comprehensive, risk-classified inventory of all third-party arrangements
  • Continuous monitoring in place of annual or point-in-time reviews
  • Defined exit and transition plans for every critical vendor
  • Board and senior management accountability for third-party risk appetite

What Does an OSFI B-10-Ready TPRM Program Look Like?

An OSFI B-10-ready TPRM program treats the third-party inventory, risk tiering, and monitoring cadence as living systems rather than annual spreadsheet exercises. That means real-time visibility into which vendors are critical, which have upstream fourth-party dependencies, and which contracts lack the exit provisions B-10 now expects — updated continuously rather than reconstructed each audit cycle.

In practice, this requires FIs to move past manual questionnaire-and-spreadsheet workflows toward platforms that maintain a live inventory, flag concentration risk automatically, and surface control gaps against B-10’s specific expectations before a supervisory review does. Institutions that centralize third-party data across procurement, legal, and information security teams — rather than leaving it fragmented across departments — are better positioned to produce the board-level reporting B-10 implicitly demands.

How Does OSFI B-10 Compare to DORA and Other Global Third-Party Risk Rules?

OSFI B-10 shares its core philosophy with the EU’s DORA and the US OCC’s third-party guidance — all three treat vendor risk as a continuous, board-owned discipline rather than a procurement function — but B-10 is notably less prescriptive on technical specifics like resilience-testing frequency, leaving more room for FI judgment on proportionality. Where DORA mandates specific ICT risk-testing cadences and a formal register format, B-10 asks FIs to build a ‘sound’ inventory and monitoring process without dictating the exact mechanics.

For multinational FIs operating across Canada, the EU, and the US, this creates both an opportunity and a risk: a TPRM program designed to satisfy DORA’s stricter requirements will generally satisfy B-10’s expectations, but the reverse isn’t guaranteed. Institutions building a single global third-party risk framework should design to the strictest applicable standard and map local guidance — B-10 included — against that baseline rather than maintaining parallel, jurisdiction-specific programs.

Conclusion

OSFI B-10 formalizes what many risk leaders already suspected: static, point-in-time vendor due diligence is no longer defensible in a regulatory environment that expects continuous accountability. For Canadian FIs, the shift from spreadsheet-based vendor tracking to a living, risk-classified inventory isn’t just a compliance exercise — it’s the difference between spotting a critical vendor’s fourth-party exposure before it becomes a headline and explaining afterward why it wasn’t visible.

Crest helps risk, compliance, and procurement teams turn OSFI B-10’s expectations into an operating reality — with a continuously updated third-party inventory, automated concentration-risk visibility, and monitoring built for board-level reporting rather than annual audit scrambles. If your TPRM program still runs on spreadsheets and yearly reviews, it’s worth seeing what continuous, B-10-aligned oversight looks like in practice.

★ Frequently Asked Questions

What is OSFI B-10?

OSFI B-10 is the Office of the Superintendent of Financial Institutions’ guideline for third-party risk management, requiring Canadian federally regulated financial institutions to assess, monitor, and manage risk from vendors, cloud providers, and outsourced service providers across the full relationship lifecycle. It replaced a 2009 guideline and took effect May 1, 2024.

Who does OSFI B-10 apply to?

OSFI B-10 applies to all federally regulated financial institutions in Canada, including domestic banks, foreign bank branches, insurance companies, and trust and loan companies. Requirements scale proportionally to an institution’s size and the criticality of its third-party arrangements, but no federally regulated FI is exempt.

What is the deadline for OSFI B-10 compliance?

OSFI B-10 took effect on May 1, 2024, and federally regulated institutions were expected to have their third-party risk management frameworks aligned with the guideline by that date. Institutions still operating on pre-2024 vendor risk processes should treat alignment as an active gap, not a future deadline.

How is OSFI B-10 different from the old third-party risk guideline?

The prior guideline, issued in 2009, predated cloud computing and modern outsourcing models and focused mainly on initial due diligence. OSFI B-10 requires continuous monitoring, a comprehensive risk-classified inventory of all third-party arrangements, defined exit strategies for critical vendors, and explicit board and senior management accountability.

Does OSFI B-10 cover fourth-party or subcontractor risk?

Yes. OSFI B-10 expects federally regulated institutions to understand and, where material, assess the risk introduced by their critical vendors’ own subcontractors, not just the direct third-party relationship. This is especially relevant for cloud and technology arrangements with layered subcontracting.

How can financial institutions demonstrate OSFI B-10 compliance?

Institutions demonstrate OSFI B-10 compliance by maintaining a current, risk-classified third-party inventory, evidencing continuous monitoring rather than annual reviews, showing contractual controls like audit rights and exit provisions are in place for critical vendors, and providing the board with regular reporting on third-party risk concentration.

★ See Crest in Action

Ready to Modernise Your TPRM?

Intelligence over information. Control over chaos. Insight over effort.

Published by the Crest Editorial Team · crest.digital