Skip to main content
Image coming soon

CMP3355 Mastering OSFI B-13 for Compliance and Audit Readiness

$201.00
Adding to cart… The item has been added

What is the OSFI B-13 for Compliance and Audit course about?

A complete implementation-grade guide to OSFI B-13 for business and technology practitioners Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

What situation is the OSFI B-13 for Compliance and Audit for?

Compliance professionals spend weeks chasing down control evidence, reconciling policy gaps, and validating implementation across teams, only to face rework during review cycles. The cost isn’t just time; it’s credibility when auditors question readiness.

Who is the OSFI B-13 for Compliance and Audit course for?

Mid-to-senior compliance, risk, and technology professionals responsible for implementing and demonstrating OSFI B-13 controls in financial institutions or service providers.

What do you take away from the OSFI B-13 for Compliance and Audit course?

Produce audit-ready B-13 documentation in under 5 days Eliminate cross-team evidence chasing with pre-built templates Demonstrate control implementation with source-backed validation Become the internal reference for B-13 interpretation and execution Reduce annual compliance cycle time by 60%+.

What's included with your purchase?

12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.

What does the OSFI B-13 for Compliance and Audit cover on delivery and format?

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: Approximately 8, 10 hours of focused learning, designed for completion in short sessions over two weeks.

How does this compare to the alternatives?

Unlike generic compliance overviews, this course delivers implementation-grade detail on OSFI B-13, with templates and playbooks used by practitioners in major financial institutions.

What does the OSFI B-13 for Compliance and Audit cover on frequently asked?

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

Closely related courses: Compliance-Ready AI Audit Readiness for Audit Teams, Compliance-Ready AI Audit Readiness for Compliance, Compliance-Ready AI Audit Readiness for Regulated, Compliance-Ready AI Audit Readiness for Acquisitive.

More answers: what you get with every course, refund policy, all help answers.

A tailored course, built for your situation

Mastering OSFI B-13 for Compliance and Audit Readiness

A complete implementation-grade guide to OSFI B-13 for business and technology practitioners

$199 one-time
30-day money-back guarantee Verified against latest insights, updated access provided within 24h

Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Exhausting last-minute scrambles to compile B-13 evidence before audits

The situation this course is for

Compliance professionals spend weeks chasing down control evidence, reconciling policy gaps, and validating implementation across teams, only to face rework during review cycles. The cost isn’t just time; it’s credibility when auditors question readiness.

Who this is for

Mid-to-senior compliance, risk, and technology professionals responsible for implementing and demonstrating OSFI B-13 controls in financial institutions or service providers

Who this is not for

Entry-level analysts, executive leadership without implementation responsibility, or consultants who don’t own delivery

What you walk away with

  • Produce audit-ready B-13 documentation in under 5 days
  • Eliminate cross-team evidence chasing with pre-built templates
  • Demonstrate control implementation with source-backed validation
  • Become the internal reference for B-13 interpretation and execution
  • Reduce annual compliance cycle time by 60%+

The 12 modules (with all 144 chapters)

Module 1. Understanding OSFI B-13 Scope and Regulatory Intent
Break down the official mandate, clarify applicability, and align implementation to institutional risk posture.
12 chapters in this module
  1. What OSFI B-13 regulates and why it matters for financial institutions
  2. Mapping B-13 requirements to organizational boundaries
  3. Differentiating between federally regulated and provincially supervised entities
  4. Key definitions: technology and cyber resilience explained
  5. How OSFI interprets 'resilience' in operational contexts
  6. Regulatory expectations vs. implementation flexibility
  7. Identifying which business units fall under B-13 scope
  8. Aligning B-13 with existing governance frameworks like COBIT
  9. Common misconceptions about B-13 applicability
  10. Using OSFI guidance documents to inform scoping decisions
  11. Documenting scope justification for internal and external reviewers
  12. Preparing a living scope register for ongoing updates
Module 2. Building the B-13 Governance Framework
Establish clear ownership, accountability, and escalation paths for compliance.
12 chapters in this module
  1. Defining roles: Board, Senior Management, and Operational Leads
  2. Creating a B-13 steering committee with clear mandates
  3. Assigning responsibility for technology resilience oversight
  4. Developing escalation protocols for control failures
  5. Integrating B-13 governance into existing risk committees
  6. Documenting decision rights for incident response
  7. Setting up quarterly review cadences for control effectiveness
  8. Ensuring independence in internal audit validation
  9. Maintaining governance records for regulator requests
  10. Linking governance actions to control implementation status
  11. Using RACI matrices to clarify cross-functional ownership
  12. Updating governance structure as the organization evolves
Module 3. Risk Assessment and Inherent Risk Profiling
Conduct a defensible, repeatable risk assessment aligned with B-13 expectations.
12 chapters in this module
  1. Identifying critical systems subject to B-13 requirements
  2. Assessing inherent risk based on system importance and complexity
  3. Using OSFI’s risk tiers to prioritize implementation effort
  4. Documenting risk rationale with supporting evidence
  5. Engaging business owners in risk rating validation
  6. Updating risk profiles after system changes or incidents
  7. Aligning risk assessments with enterprise-wide risk registers
  8. Avoiding common pitfalls in risk scoring subjectivity
  9. Creating risk heat maps for leadership consumption
  10. Linking risk ratings to control design intensity
  11. Maintaining version-controlled risk assessment records
  12. Demonstrating consistency in risk methodology over time
Module 4. Designing Technology Resilience Controls
Translate B-13 requirements into specific, actionable technical and operational controls.
12 chapters in this module
  1. Mapping B-13 principles to control objectives and activities
  2. Designing controls for system availability and performance
  3. Implementing redundancy for critical infrastructure components
  4. Establishing capacity planning processes for peak loads
  5. Defining recovery time and recovery point objectives
  6. Creating failover procedures for data and applications
  7. Testing control design against real-world disruption scenarios
  8. Documenting control specifications for audit validation
  9. Integrating controls into change management workflows
  10. Ensuring third-party systems meet resilience standards
  11. Using control libraries to maintain consistency
  12. Versioning control designs for future reference
Module 5. Implementing Cyber Resilience Measures
Strengthen cyber defenses in line with B-13’s security expectations.
12 chapters in this module
  1. Aligning cyber resilience with NIST CSF and ISO 27001
  2. Conducting penetration testing on critical systems
  3. Implementing multi-factor authentication for privileged access
  4. Securing data in transit and at rest across environments
  5. Establishing endpoint detection and response capabilities
  6. Managing vulnerabilities with a defined remediation SLA
  7. Protecting against ransomware and supply chain attacks
  8. Ensuring encryption key management follows best practices
  9. Auditing user access logs for suspicious activity
  10. Integrating threat intelligence into security operations
  11. Developing incident response playbooks for cyber events
  12. Validating cyber controls through independent assessment
Module 6. Third-Party Risk Management Under B-13
Ensure vendors and partners meet OSFI’s resilience expectations.
12 chapters in this module
  1. Identifying third parties that support critical systems
  2. Assessing vendor risk based on service criticality
  3. Requiring B-13 compliance commitments in contracts
  4. Conducting on-site assessments of high-risk vendors
  5. Reviewing vendor business continuity and DR plans
  6. Monitoring vendor performance and incident reporting
  7. Managing concentration risk across service providers
  8. Establishing right-to-audit clauses in agreements
  9. Validating vendor testing results and certifications
  10. Documenting third-party oversight activities
  11. Responding to vendor incidents that impact operations
  12. Maintaining a centralized vendor risk register
Module 7. Business Continuity and Disaster Recovery Planning
Develop and validate plans that meet B-13’s resilience standards.
12 chapters in this module
  1. Defining maximum tolerable outage for critical functions
  2. Developing business continuity plans for key processes
  3. Creating disaster recovery plans for IT infrastructure
  4. Establishing emergency communication protocols
  5. Identifying alternate work sites and remote capabilities
  6. Testing plans annually with executive participation
  7. Documenting test results and lessons learned
  8. Updating plans after organizational or system changes
  9. Integrating BCP/DR with incident management workflows
  10. Ensuring plan accessibility during outages
  11. Aligning BCP/DR with regulatory reporting obligations
  12. Maintaining plan versions and approval records
Module 8. Incident Management and Reporting Procedures
Build a structured response process for technology disruptions.
12 chapters in this module
  1. Defining incident severity levels and escalation paths
  2. Establishing an incident response team with clear roles
  3. Documenting incident intake and triage procedures
  4. Creating communication templates for internal stakeholders
  5. Reporting significant incidents to OSFI within 72 hours
  6. Conducting post-incident reviews and root cause analysis
  7. Tracking incident trends for proactive mitigation
  8. Integrating incident data into risk assessments
  9. Ensuring logs are preserved for forensic analysis
  10. Validating response times against SLAs
  11. Training staff on incident reporting responsibilities
  12. Maintaining an incident register for audit purposes
Module 9. Testing and Validation of Resilience Controls
Prove control effectiveness through structured testing.
12 chapters in this module
  1. Scheduling annual resilience testing for critical systems
  2. Designing test scenarios based on real threat models
  3. Conducting tabletop exercises with leadership
  4. Performing technical failover tests without disruption
  5. Engaging independent third parties for test validation
  6. Documenting test plans, results, and action items
  7. Tracking remediation of test findings to closure
  8. Reporting test outcomes to senior management
  9. Using test results to refine control design
  10. Maintaining evidence of completed tests for auditors
  11. Aligning test frequency with system criticality
  12. Integrating testing into the change management lifecycle
Module 10. Documentation and Evidence Management
Create and maintain the artefacts needed for audit readiness.
12 chapters in this module
  1. Identifying required documentation under B-13
  2. Creating a central repository for compliance evidence
  3. Version-controlling policies, procedures, and records
  4. Organizing evidence by control and audit objective
  5. Using metadata to streamline evidence retrieval
  6. Automating evidence collection from monitoring tools
  7. Ensuring documentation reflects actual practice
  8. Preparing evidence packages for internal and external audits
  9. Redacting sensitive information before sharing
  10. Maintaining retention periods for compliance records
  11. Conducting pre-audit self-assessments
  12. Responding to auditor requests with precision
Module 11. Internal Audit and Assurance Alignment
Collaborate effectively with internal audit to demonstrate readiness.
12 chapters in this module
  1. Engaging internal audit early in the implementation process
  2. Sharing control design documentation for feedback
  3. Responding to audit findings with corrective action plans
  4. Tracking remediation progress for follow-up reviews
  5. Demonstrating independence in audit validation
  6. Aligning audit scope with B-13 requirements
  7. Using audit reports to strengthen control posture
  8. Facilitating audit access to systems and records
  9. Preparing for integrated audits with other frameworks
  10. Maintaining audit communication logs
  11. Building trust through transparency and timeliness
  12. Incorporating audit insights into continuous improvement
Module 12. Preparing for OSFI Examinations
Navigate regulatory reviews with confidence and precision.
12 chapters in this module
  1. Understanding OSFI’s examination process and timelines
  2. Receiving and acknowledging examination notifications
  3. Assembling the examination response team
  4. Providing requested evidence promptly and completely
  5. Answering examiner questions with clarity and consistency
  6. Maintaining examination meeting records
  7. Addressing preliminary findings before final report
  8. Developing action plans for formal recommendations
  9. Tracking implementation of OSFI directives
  10. Using examination outcomes to improve controls
  11. Building a culture of continuous compliance readiness
  12. Positioning your team as the go-to resource for B-13

How this maps to your situation

  • Scoping and governance setup
  • Risk and control design
  • Implementation and validation
  • Audit and regulatory readiness

Before vs. after

Before
Spending weeks assembling evidence, reconciling control gaps, and responding to auditor questions under pressure
After
Delivering audit-ready B-13 packages in days, with structured artefacts and validated controls

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 8, 10 hours of focused learning, designed for completion in short sessions over two weeks.

If nothing changes
Without structured implementation, teams face repeated audit findings, reputational exposure, and operational disruption during regulatory reviews.

How this compares to the alternatives

Unlike generic compliance overviews, this course delivers implementation-grade detail on OSFI B-13, with templates and playbooks used by practitioners in major financial institutions.

Frequently asked

Is this course suitable for non-technical compliance professionals?
Yes. The course balances technical depth with practical implementation guidance for business and technology roles alike.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Do I get access to updates if B-13 changes?
Yes. All course materials are updated to reflect regulatory changes, with notifications sent to enrolled learners.
$199 one-time. Approximately 8, 10 hours of focused learning, designed for completion in short sessions over two weeks..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee·144 chapters·Hand-built playbook included· Account access within 24 hours