OSFI B-13
Incident Reporting

OSFI B-13 7: Incident Reporting to OSFI and Regulatory Coordination

Operate Incident Reporting to OSFI per B-13 Technology and Cyber Incident reporting + broader OSFI incident reporting framework. Incident Reporting to OSFI must (a) report technology and cyber incidents per OSFI Technology and Cyber Incident reporting requirements within 24 hours of becoming aware where incident has high operational impact + (b) follow-up with full assessment within applicable timeframe + (c) maintain coordination with OSFI relationship manager + (d) coordinate with broader regulatory reporting (PIPEDA breach notification + provincial regulators + payment network + customers + employees + investors). Regulatory cooperation must (a) maintain OSFI relationship manager engagement + (b) respond to OSFI information requests + (c) cooperate with OSFI inspections + (d) implement remediation per OSFI direction + (e) maintain transparency on emerging risks. Communication and escalation procedures must (a) maintain regulator + customer + media + law enforcement communication channels + (b) escalate incidents per scheme procedures + (c) maintain on-call coverage + executive escalation + (d) integrate with broader crisis management.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.