Skip to content
TB
TeamBenchResources

OSFI Compliance Documentation for Canadian Financial Institutions

OSFI expects federally regulated financial institutions to maintain extensive documentation. Here's how to review your compliance documentation systematically.

TeamBench· Content Quality PlatformFebruary 9, 202611 min read

The Office of the Superintendent of Financial Institutions (OSFI) regulates all federally regulated financial institutions (FRFIs) in Canada — banks, insurance companies, trust and loan companies, and private pension plans. OSFI's supervisory framework is documentation-intensive: institutions must maintain comprehensive policies, procedures, risk assessments, and governance records that demonstrate compliance with OSFI guidelines, the Bank Act, and prudential standards.

OSFI has significantly increased its supervisory intensity in recent years. The 2025-26 Annual Risk Outlook highlights technology and cyber risk, climate risk, residential mortgage risk, and third-party risk as key focus areas. Each of these requires documented risk management frameworks, policies, and evidence of implementation.

For compliance teams at FRFIs, the documentation burden is substantial. A single institution may maintain hundreds of policies, procedures, and risk documents — all of which must be current, consistent, and aligned with OSFI expectations. This guide covers what OSFI requires, where institutions commonly fail, and how to build a systematic review process.

What OSFI Requires

Key OSFI Guidelines

GuidelineWhat It CoversKey Documentation
B-10Third-party risk managementThird-party risk management framework, due diligence records, contracts, monitoring reports
B-13Technology and cyber risk managementTechnology risk management framework, cyber security strategy, incident response plan
E-13Legislative compliance managementCompliance management framework, compliance risk assessment, reporting
E-21Operational risk managementOperational risk framework, risk and control self-assessments, incident records
B-15Climate risk managementClimate risk governance, scenario analysis, disclosure
E-23Model risk managementModel inventory, validation reports, model risk framework
B-20Residential mortgage underwritingUnderwriting policies, stress testing, documentation standards

Corporate Governance (Guideline E-17)

OSFI's Corporate Governance Guideline establishes expectations for boards of directors and senior management:

  • Board must have documented terms of reference and committee mandates
  • Risk appetite framework must be documented and board-approved
  • Senior management must provide regular reporting to the board on key risks
  • Board minutes must evidence meaningful oversight and challenge
  • Succession planning must be documented
  • Board and committee effectiveness reviews must be conducted and documented

Technology and Cyber Risk (Guideline B-13)

Guideline B-13 requires comprehensive technology risk documentation:

AreaDocumentation Required
GovernanceTechnology risk management framework, roles and responsibilities, board reporting
Technology operationsIT asset inventory, change management procedures, capacity planning
Cyber securityCyber security strategy, threat intelligence programme, vulnerability management
Incident managementCyber incident response plan, recovery procedures, notification protocols
Technology resilienceBusiness continuity plan, disaster recovery plan, testing records
Third-party technologyCloud risk assessment, vendor security assessments, contractual controls

Third-Party Risk Management (Guideline B-10)

Guideline B-10 is one of OSFI's most documentation-intensive guidelines:

  • Third-party risk management framework
  • Risk assessment for each material third-party arrangement
  • Due diligence records for all third parties
  • Contracts meeting OSFI requirements (audit rights, subcontracting controls, exit provisions)
  • Ongoing monitoring and performance assessment
  • Concentration risk assessment
  • Exit strategy for critical third parties

Common Documentation Failures

1. Framework-Practice Gaps

The most prevalent failure across FRFIs. The institution has a documented framework — but the documented framework doesn't match actual practice.

Examples:

  • Operational risk framework requires quarterly risk and control self-assessments, but only two were completed last year
  • Third-party risk management framework requires annual due diligence reviews, but 30% of material third parties haven't been reviewed in 18+ months
  • Cyber incident response plan specifies a 4-hour initial assessment, but incident records show average initial assessment time of 12+ hours
  • Model risk framework requires annual model validation, but the model inventory shows 15% of models are overdue for validation

OSFI examiners specifically look for these gaps. They read the framework, then ask for evidence of implementation.

2. Board Documentation Deficiencies

OSFI expects board minutes and committee records to evidence active oversight:

  • Board risk reporting that's too summarised to demonstrate meaningful oversight
  • Committee minutes without evidence of challenge or questioning
  • Risk appetite statements that are approved but never referenced in decision-making
  • Missing evidence that the board discussed key risks identified in OSFI's Risk Outlook
  • No documentation of board education or training on emerging risks

3. Third-Party Documentation Gaps

B-10 compliance is a common supervisory finding:

  • Material third-party arrangements without formal risk assessments
  • Contracts that don't include required OSFI provisions (audit rights, subcontracting approval, exit provisions)
  • No concentration risk analysis across third-party portfolio
  • Due diligence records that are point-in-time (at onboarding) without ongoing monitoring evidence
  • Cloud arrangements without specific cloud risk assessments

4. Incident Management Records

Operational and cyber incidents that aren't properly documented:

  • Incidents reported verbally but not recorded in the incident management system
  • Root cause analysis not completed or not documented
  • Corrective actions identified but not tracked to completion
  • No evidence that incidents informed risk assessment updates
  • Near-miss events not captured

5. Model Risk Documentation

E-23 expectations for model risk management are frequently undermet:

  • Model inventory incomplete (models exist that aren't in the inventory)
  • Validation reports overdue
  • Model limitations not documented
  • No evidence that model risk is reported to the board
  • Models in production without formal approval documentation

Building a Compliance Documentation Review Process

Step 1: Map Documentation to Guidelines

OSFI GuidelineRequired DocumentsOwnerLast ReviewedStatus
B-10 Third-Party RiskThird-party risk frameworkCROMarch 2025✅ Current
B-10 Third-Party RiskMaterial third-party risk assessmentsProcurement/RiskVaries⚠️ 8 of 25 overdue
B-13 Technology RiskTechnology risk frameworkCTO/CISOJanuary 2026✅ Current
B-13 Technology RiskCyber incident response planCISONovember 2025✅ Current
E-17 Corporate GovernanceBoard terms of referenceCorporate SecretarySeptember 2025✅ Current
E-21 Operational RiskOp risk frameworkCROAugust 2025✅ Current
E-21 Operational RiskRisk and control self-assessmentsBusiness unitsVaries⚠️ Q3 assessments incomplete
E-23 Model RiskModel inventoryModel RiskDecember 2025⚠️ 3 models missing

Step 2: Prioritise by OSFI Focus Areas

Align your review priorities with OSFI's current supervisory focus:

  1. Technology and cyber risk (B-13) — OSFI's top supervisory priority
  2. Third-party risk (B-10) — increasing scrutiny, especially for cloud and fintech arrangements
  3. Climate risk (B-15) — expanding disclosure expectations
  4. Operational resilience (E-21) — post-pandemic emphasis on resilience documentation
  5. Model risk (E-23) — AI/ML models creating new documentation requirements

Step 3: Implement Review Cycles

Document TypeReview FrequencyTriggered Review
Risk management frameworksAnnuallyOSFI guideline update, significant risk event
Board and committee reportingQuarterly (review quality)OSFI supervisory letter
Third-party risk assessmentsAnnually per arrangementNew arrangement, significant change, incident
Incident recordsMonthly (completeness check)Post-incident review
Model documentationAnnually per modelModel change, validation finding
Policies and proceduresAnnuallyRegulatory change, incident, audit finding

Step 4: Conduct Cross-Document Consistency Checks

  • Risk appetite statement vs. risk reporting — does reporting reference the risk appetite thresholds?
  • Framework commitments vs. implementation evidence — for every "must" in a framework, is there evidence it happened?
  • Board-approved policies vs. operational procedures — are procedures consistent with what the board approved?
  • Incident records vs. root cause analysis vs. corrective actions — is the chain complete?

Using AI to Review OSFI Documentation

What AI Can Check

  • Completeness — verify frameworks cover all required elements per the OSFI guideline
  • Consistency — cross-reference frameworks, policies, and procedures for contradictions
  • Currency — flag references to outdated OSFI guidelines, superseded regulations, or expired dates
  • Implementation evidence — identify framework commitments that should have corresponding evidence
  • Terminology — check correct use of OSFI regulatory terminology
  • Structure — verify documents follow expected formats and address mandatory elements

What AI Cannot Replace

  • OSFI regulatory interpretation for institution-specific situations
  • Assessment of whether risk management frameworks are appropriate for the institution's risk profile
  • Evaluation of board oversight quality from meeting minutes
  • Verification that documented controls operate effectively
  • Supervisory relationship management

Practical Example

In TeamBench, you could configure a reviewer:

Reviewer name: OSFI Compliance Documentation Reviewer

System prompt:

You are an OSFI compliance documentation reviewer for Canadian federally regulated financial institutions. Review risk management frameworks, policies, procedures, and governance documents against OSFI guidelines (B-10, B-13, E-13, E-17, E-21, E-23, B-15, B-20). Check for: completeness (all guideline requirements addressed), consistency (no contradictions between frameworks and procedures), currency (current OSFI guideline references, valid dates), implementation commitments (framework statements that should have corresponding evidence), and specificity (institution-specific content, not generic templates). Flag specific gaps with the OSFI guideline reference. Use Canadian English.

Evaluation criteria:

  • Completeness (weight: 3) — All OSFI guideline requirements addressed
  • Consistency (weight: 3) — No contradictions across documents
  • Specificity (weight: 2) — Tailored to the institution, not generic templates
  • Currency (weight: 2) — Current OSFI references and valid dates
  • Structure (weight: 1) — Well-organised, professionally presented

Quality gate: Minimum score: 85.

Upload relevant OSFI guidelines and your institution's risk management framework into a Knowledge Base.

Frequently Asked Questions

How often does OSFI examine financial institutions?

OSFI uses a risk-based supervisory approach. Large, systemically important banks (D-SIBs) are examined continuously. Smaller institutions are examined on a cycle based on their risk profile — typically every 1-3 years for full examinations, with interim monitoring throughout. OSFI can also conduct targeted examinations on specific risk areas at any time.

What happens if OSFI finds documentation gaps?

OSFI issues supervisory letters outlining findings and expectations. Depending on severity, outcomes range from recommendations (address within a reasonable timeframe) to directions (formal requirements with specific deadlines) to conditions on the institution's licence. Persistent or serious gaps can result in increased supervisory intensity, capital surcharges, or restrictions on activities.

Does OSFI require specific document formats?

OSFI doesn't prescribe specific formats for most documents. However, the content must address all elements specified in the relevant guideline. The institution chooses the format — but the substance must be complete, current, and specific to the institution.

How do we handle OSFI's expectations for AI/ML model risk?

Guideline E-23 applies to all models, including AI/ML models. Additional expectations include: model explainability documentation, bias testing records, ongoing monitoring of model performance, and escalation procedures when model outputs deviate from expectations. Document the full model lifecycle from development through deployment to retirement.

What's the relationship between OSFI and provincial regulators?

OSFI regulates federally incorporated financial institutions. Provincial regulators (e.g., AMF in Quebec, FSRA in Ontario) regulate provincially incorporated institutions. Credit unions are typically provincially regulated. Requirements may differ — ensure your documentation addresses the correct regulatory framework.

How should we document cloud arrangements under B-10?

Cloud arrangements with material third parties require: specific cloud risk assessment (covering data residency, multi-tenancy, concentration risk), contractual provisions meeting B-10 requirements, ongoing monitoring of cloud service provider performance and security, and exit planning specific to cloud migration. Document these separately from general third-party risk assessments.

Key Takeaways

  • OSFI's supervisory framework is documentation-intensive — institutions must maintain comprehensive policies, procedures, risk assessments, and governance records.
  • Framework-practice gaps are the most common failure. Examiners read your frameworks, then ask for evidence of implementation. Every "must" in a framework needs corresponding evidence.
  • OSFI's 2025-26 focus areas include technology and cyber risk (B-13), third-party risk (B-10), climate risk (B-15), and model risk (E-23). Prioritise documentation review in these areas.
  • Board documentation must show active oversight — minutes with evidence of challenge, risk appetite referenced in decisions, and regular education on emerging risks.
  • Third-party documentation under B-10 requires risk assessments, due diligence records, compliant contracts, ongoing monitoring, and concentration risk analysis.
  • Map every document to its OSFI guideline using a compliance matrix, and track review dates, owners, and status.
  • AI-assisted review can check completeness, consistency, currency, and specificity across your documentation portfolio, but cannot replace OSFI regulatory judgement.
  • Implement review cycles aligned with OSFI's examination schedule and supervisory priorities.

This article provides general information about OSFI compliance documentation requirements and is not regulatory advice. Always consult OSFI directly for current guidelines and seek qualified compliance advice for your institution's specific situation.

osficompliancefinancial-institutionsdocumentationbankingcanada

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required