ISMS Copilot
OSFI B-13

OSFI Guideline B-13 Copilot

Technology and cyber risk management for Canadian FRFIs.

What the OSFI B-13 Copilot Can Do

Walk Guideline B-13 by OSFI's own domain and expectation titles

Draft FRFI technology-risk and cyber-risk documentation against those titles

Keep B-13 separate from OSFI E-21 (operational resilience) and B-10 (third party)

Cross-map to ISO 27001 and NIST CSF when a FRFI already runs those programmes

Prepare self-assessment worksheets that point at B-13, not at a consultant's rewrite

Plain-English explanations of who a FRFI is, without pretending to classify your charter

About OSFI Guideline B-13 Copilot

OSFI B-13 Copilot helps federally regulated financial institutions and their vendors draft documentation against OSFI Guideline B-13, Technology and Cyber Risk Management (final July 2022, effective 1 January 2024). It is a documentation assistant for the guideline's titled expectations. It is not an OSFI supervisory assessment and it is not a substitute for the guideline itself.

Cross-framework mappings

Working across OSFI B-13 and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.

Browse free mappings

Frequently Asked Questions

Who is Guideline B-13 for?

OSFI wrote it for federally regulated financial institutions: banks, insurers, trust and loan companies, and other FRFIs listed on the official guideline page. Vendors to FRFIs get asked for B-13-shaped evidence even when they are not FRFIs themselves.

Is this the same as MAS TRM or APRA CPS 234?

No. Those are Singapore and Australian prudential instruments. B-13 is the OSFI guideline. The Copilot keeps them in separate packs. See /frameworks/sg-mas-trm for the Singapore counterpart.

Does the Copilot replace an OSFI review?

No. OSFI supervises FRFIs. The Copilot drafts the documentation a FRFI team brings to that conversation.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.