OSFI B-13 OSFIB13-4: Third-Party Risk Management and Cloud
Operate third-party risk management per OSFI B-13 Domain 4 + complementary OSFI Guideline B-10 Outsourcing of Business Activities and Functions. Third-Party Risk Management must (a) maintain third-party inventory categorised by criticality + service type + data access + (b) apply risk-based due diligence at acquisition + ongoing monitoring + (c) include cybersecurity + privacy + business continuity + sub-contractor flow-down + audit rights + insurance + breach notification + termination + transition assistance in contracts + (d) coordinate with OSFI on material outsourcing where required. Cloud computing arrangements per B-10 + B-13 must (a) assess cloud provider security + resilience + compliance + (b) maintain cloud-specific risk assessment + (c) implement cloud governance covering provisioning + change management + monitoring + (d) consider data residency + sovereignty + cross-border transfer requirements (Canadian privacy law + Quebec + provincial). Concentration risk management must (a) monitor concentration across providers + critical-service identification + alternative arrangements + (b) coordinate with OSFI on concentration concerns. Exit strategy and transition planning must (a) maintain exit planning per third party covering data + portability + service continuity + (b) test exit assumptions periodically.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 111 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained