OSFI B-13
Third-Party Risk Management

OSFI B-13 OSFIB13-4: Third-Party Risk Management and Cloud

Operate third-party risk management per OSFI B-13 Domain 4 + complementary OSFI Guideline B-10 Outsourcing of Business Activities and Functions. Third-Party Risk Management must (a) maintain third-party inventory categorised by criticality + service type + data access + (b) apply risk-based due diligence at acquisition + ongoing monitoring + (c) include cybersecurity + privacy + business continuity + sub-contractor flow-down + audit rights + insurance + breach notification + termination + transition assistance in contracts + (d) coordinate with OSFI on material outsourcing where required. Cloud computing arrangements per B-10 + B-13 must (a) assess cloud provider security + resilience + compliance + (b) maintain cloud-specific risk assessment + (c) implement cloud governance covering provisioning + change management + monitoring + (d) consider data residency + sovereignty + cross-border transfer requirements (Canadian privacy law + Quebec + provincial). Concentration risk management must (a) monitor concentration across providers + critical-service identification + alternative arrangements + (b) coordinate with OSFI on concentration concerns. Exit strategy and transition planning must (a) maintain exit planning per third party covering data + portability + service continuity + (b) test exit assumptions periodically.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.