OSFI B-13
Third-Party Risk Management

OSFI B-13 OSFIB13-4: Third-Party Risk Management and Cloud

Operate third-party risk management per OSFI B-13 Domain 4 + complementary OSFI Guideline B-10 Outsourcing of Business Activities and Functions. Third-Party Risk Management must (a) maintain third-party inventory categorised by criticality + service type + data access + (b) apply risk-based due diligence at acquisition + ongoing monitoring + (c) include cybersecurity + privacy + business continuity + sub-contractor flow-down + audit rights + insurance + breach notification + termination + transition assistance in contracts + (d) coordinate with OSFI on material outsourcing where required. Cloud computing arrangements per B-10 + B-13 must (a) assess cloud provider security + resilience + compliance + (b) maintain cloud-specific risk assessment + (c) implement cloud governance covering provisioning + change management + monitoring + (d) consider data residency + sovereignty + cross-border transfer requirements (Canadian privacy law + Quebec + provincial). Concentration risk management must (a) monitor concentration across providers + critical-service identification + alternative arrangements + (b) coordinate with OSFI on concentration concerns. Exit strategy and transition planning must (a) maintain exit planning per third party covering data + portability + service continuity + (b) test exit assumptions periodically.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 111 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation

APRA CPS 234 · 4 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.4 Resilience Testing
  • IM8-TPM.4 Supply Chain Risk Management
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • BS65000-RM-03 Leadership and Culture
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • CAT-D1-2 Risk management
  • CAT-D5-4 Resilience planning and testing
  • CAT-ML-2 Evolving
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)

NIST SP 800-53 Rev 5 · 3 controls

  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.3 Information security risk treatment

ISO/IEC 27031:2011 · 2 controls

  • 27031-8.1 Exercising and Testing
  • 27031-B High availability embedded systems
  • PSPF24-1 Security Culture, Governance, Risk Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • AMLCTF-82 Part A Compliance

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • AS9100D-8.1 Operational Planning and Control
  • ASD37-20 Multi-factor authentication (Essential)
  • ACQS-8-4 Risk Management

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • CJIS-19 Supply Chain Risk Management
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components
  • ISO-20400-4.5 Key considerations for sustainable procurement

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach
  • ISO28001-SA-04 Security Risk Treatment Planning
  • ISO20000-03 Capacity and availability management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27019:2024 · 1 control

  • ISO27019-21 Supply chain risk management for critical components

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

NIST SP 1800-32 · 1 control

  • ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework
  • AIGF-1.1 Risk Management and Internal Controls
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)

South Korea ISMS-P · 1 control

  • ISMSP-MS-02 Risk Management
  • CRM-3 Risk Management Framework
  • CERT-1 RRA Certification to EPA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 111 it maps to, and the evidence behind each claim, over MCP and REST.