OSFI B-13
Metrics and Continuous Improvement

OSFI B-13 8: Metrics, Monitoring, Continuous Improvement, Maturity

Operate metrics + monitoring + continuous improvement + maturity per OSFI B-13 Domain 6 + cross-cutting expectations. Metrics, Monitoring and Continuous Improvement must (a) maintain technology and cyber risk metrics covering control coverage + maturity + incident metrics + audit findings + training completion + phishing simulation results + third-party compliance + vulnerability remediation + (b) measure against documented thresholds + benchmarks + (c) report quarterly to executive + at least annually to board + (d) integrate with broader enterprise risk reporting. Maturity assessment must (a) assess against B-13 expectations + NIST CSF + ISO/IEC 27001/27002 + sectoral maturity model + (b) maintain maturity roadmap + improvement objectives + investment plan + (c) benchmark against peer FRFIs + industry indices. Continuous improvement must (a) feed lessons from incidents + audits + assessments + supervisory feedback into framework updates + (b) maintain change tracking + version control of framework + policies + procedures + (c) integrate with broader enterprise transformation initiatives.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.