Security & Compliance
Lynx Compliance - OSFI B-13 + B-10
The two OSFI guidelines a federally regulated financial institution is supervised against - B-13 technology and cyber risk, and B-10 third-party risk - as assessable expectations.
lynx_compliance_osfi
· v19.0.1.0.0
· Add-on
Beta
What this solves
Lynx Compliance - OSFI B-13 + B-10
The two guidelines a federally regulated financial institution is supervised against for technology, cyber and third-party risk. They ship together because they are supervised together, and because B-10 leans directly on B-13: a critical third-party arrangement is assessed for the same technology and cyber risks the institution is assessed for itself.
Both guidelines are outcome-based. OSFI states the outcome it expects and leaves the institution to demonstrate how it achieves it, proportionate to size, nature and complexity. That has a practical consequence for how this pack should be used. The assessment status matters less than the evidence attached to it, and a supervisory review tests the evidence rather than counting the controls. The guidance in this pack is written accordingly: the evidence section names the artefact a supervisor will actually ask to see, and the residual-risk examples are the states institutions are usually in when they believe they are green.
The B-10 revision widened scope from outsourcing to any third-party arrangement, which brought in the software, data and cloud relationships that had been assessed as procurement. Obligations then scale with criticality, so the criticality assessment is the control that decides how much of the rest applies — and the register that feeds it is the control most often incomplete.
Key Features
78 expectations across two frameworks - 45 for B-13 across its three domains, 33 for B-10 across governance, lifecycle and the specific risk domains.
ISO 27001 Annex A references throughout - an institution with a 27001 programme carries those assessments across rather than rebuilding them under a different heading.
Written for a supervisory review, not a checklist - evidence guidance names board minutes, tolerance breaches, measured recovery times and exercised audit rights, because those are what get tested.
Complementary user entity controls called out - the assurance-report obligations that are yours rather than the provider's, and that most institutions never map to an owner.
Criticality treated as the gating control - because under B-10 it determines the depth of everything downstream.
Numbering that tracks the guideline structure - domain, section and expectation, so a reader can find the source text.
Integrates With
lynx_compliance_certification - the ISO 27001 Annex A controls both frameworks reference.
lynx_compliance_vendor_posture - the third-party register, due diligence and monitoring records for B-10.
lynx_compliance_subprocessor_map - subcontracting visibility and data location.
lynx_compliance_incident - incident classification, escalation and the OSFI reportability assessment.
Try Lynx Compliance - OSFI B-13 + B-10 on your team.
Free trial, no credit card. Talk to sales when you're ready.