Here is the honest situation. OSFI Guideline B-13 sets out how federally regulated financial institutions in Canada should manage technology and cyber risk, across three domains: governance and risk management, technology operations and resilience, and cyber security. It expects board accountability, a managed technology estate, resilient and recoverable critical services, a cyber security program across the security lifecycle, and controlled third parties. A federally regulated institution that runs these but cannot show its governance, its resilience testing or its cyber program is exactly where institutions fall short under supervision.
This Kit removes the guesswork. It is the B-13 expectations written as adopt-ready controls you personalize in a weekend, with the evidence a supervisor examines.
What you get, the moment you buy
Grounded in OSFI Guideline B-13, with technology and cyber governance and risk management, the technology asset lifecycle, change and operations, technology resilience and recovery, the cyber security program, third-party and data controls and oversight called out. Editable Word and Excel files.
What one control looks like
This is establishing technology and cyber governance, where B-13 begins. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. An expectation you cannot evidence is a supervisory finding. This tells you what a supervisor examines and where institutions fall short, for every expectation.
- Governance, resilience and cyber built in. The governance and risk management, the technology resilience and recovery and the cyber security program are written into the controls, the substance B-13 expects.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. B-13 aligns with your operational resilience, third-party and NIST-based security work, so this feeds your wider risk program.
Who buys this
Canadian federally regulated financial institutions and their technology, security, risk and compliance leads. Whether it is a first B-13 alignment or a supervisory-readiness pass, you save weeks and walk in with governance, operations, resilience and cyber structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this supervisory or legal advice? No. It is an implementation toolkit grounded in the guideline. For a specific matter consult your advisors; this gets your controls and evidence in order fast.
Does it cover technology resilience? Yes. Resilience, recovery objectives, backups and disaster recovery are built as controls.
Does it cover cyber security? Yes. A cyber program across identify, protect, detect, respond and recover is built as controls.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com