Executive boardroom overlooking the Toronto skyline

Insights · Regulatory Updates

What evolving OSFI guidance means for third-party risk programs

Third-party oversight has moved from a procurement control to a board-level resilience discipline. The practical question is no longer whether a framework exists, but whether it can be evidenced.

01

From outsourcing control to enterprise risk discipline

Earlier outsourcing expectations were largely transactional: identify material arrangements, contract carefully, and review them periodically. The current posture is broader. Institutions are expected to govern the full lifecycle of every third-party arrangement — sourcing, due diligence, contracting, ongoing monitoring, incident response, renewal and exit — and to scale that governance to risk and criticality rather than spend.

The practical consequence is organizational. Third-party risk can no longer sit entirely inside procurement or a single vendor-management team. It requires named accountability in the first line, independent challenge in the second, and assurance in the third, with the board approving the framework and receiving reporting that is specific enough to support challenge.

02

Criticality is a judgement the board should be able to defend

Most programs stall at the first step: deciding which arrangements matter. A criticality assessment that leans on contract value or historical labels will misclassify small, deeply embedded providers — a data feed, a document-signing platform, a reconciliation utility — that would halt a critical operation within hours.

  • Define criticality by impact on critical operations, clients, regulatory obligations and financial condition
  • Assess substitutability and realistic switching time, not just contractual notice periods
  • Record the rationale for each classification so it can be re-tested and challenged
  • Re-assess when the service, data scope, geography or subcontracting chain changes

03

Concentration, subcontracting and the parts you do not contract with

Two institutions can each have well-governed contracts and still share the same single point of failure four layers down the chain. Understanding material subcontracting for critical services is now an expectation, not a nicety — including where data resides, which jurisdictions apply, and who actually performs the work.

Concentration should be measured in more than one dimension: by provider, by underlying technology or cloud region, by geography, and by the internal business services that depend on the same provider. A provider that is immaterial to three business lines individually may be critical to the institution collectively.

04

Contracts that support supervision, not just commerce

  • Audit, inspection and regulator access rights, exercisable in practice and not only on paper
  • Defined service levels tied to the institution's own disruption tolerances
  • Incident and breach notification timelines that let the institution meet its own reporting obligations
  • Notification and consent requirements for material subcontracting or location changes
  • Data location, ownership, portability and secure return or destruction on exit
  • Termination assistance obligations that survive the end of the contract

05

Exit planning is the test most programs fail

An exit plan is not a clause. It is a documented, resourced and periodically tested route to move or in-source a service within a defined period, including data extraction, alternative providers, transitional capacity and the cost of running both arrangements in parallel. Institutions that discover their exit plan only during a provider failure discover it too late.

Testing does not always mean a live migration. Tabletop exercises, partial data-extraction tests and validated recovery runbooks materially improve credibility, provided the results and the follow-up actions are documented.

06

Where programs most often fall short

  • An inventory that is complete for contracts but incomplete for services actually consumed
  • Due diligence evidence collected once at onboarding and never refreshed
  • Monitoring based on provider self-attestation with no independent validation
  • Reporting that counts vendors instead of describing risk, concentration and readiness
  • Remediation actions tracked in a spreadsheet with no owner, date or closure evidence

What good looks like

  • A single authoritative inventory of third parties, mapped to the critical operations they support
  • Risk-tiered due diligence with defined evidence requirements and refresh cycles
  • Contract terms aligned to the institution's resilience, privacy and reporting obligations
  • Continuous monitoring with defined triggers for escalation and re-assessment
  • Tested exit plans for every critical arrangement, with documented results
  • Board reporting that pairs a concentration view with remediation and readiness status

This article summarizes publicly available Canadian regulatory expectations, including OSFI Guideline B-10. Obligations vary by charter, regulator and risk profile — confirm specific requirements with counsel and your principal regulator.

Frequently asked questions

Which institutions does OSFI Guideline B-10 apply to?

+

B-10 applies to federally regulated financial institutions, including banks, bank holding companies, federally regulated trust and loan companies, and insurers. Provincially regulated entities are often held to comparable expectations by the AMF in Quebec or FSRA in Ontario, and many adopt B-10 as a practical benchmark.

How is a 'critical' third party defined?

+

Criticality is based on the consequence of failure rather than contract value. A third party is generally critical if a disruption, breach or exit would materially affect the institution's critical operations, financial condition, regulatory compliance or reputation. The definition should be documented, applied consistently and approved through the risk framework.

Does B-10 cover fourth parties and subcontractors?

+

Yes. Institutions are expected to understand material subcontracting arrangements supporting critical services, including where data is processed and stored, and to secure contractual rights to be informed of and assess changes in the supply chain.

What third-party reporting should the board receive?

+

Boards typically receive periodic reporting on the critical third-party inventory, concentration and substitutability, material risk events and incidents, contractual compliance gaps, exit-plan readiness and remediation status against the framework the board approved.

How does third-party risk interact with operational resilience?

+

Third-party risk is a delivery channel for operational risk. OSFI E-21 asks institutions to define critical operations and tolerances for disruption; B-10 asks them to govern the external providers those operations depend on. The two programs should share a common view of critical operations, dependencies and testing.

Ready when you are

Bring clarity, control and confidence to your risk and compliance program.

Explore Our Services