Insights
OSFI B-10 in Practice: What Canadian Fintechs Must Get Right on Cloud and Third-Party Risk in 2026
The Stakes Have Changed for Third-Party Risk
When the Office of the Superintendent of Financial Institutions (OSFI) released its revised Guideline B-10 — Third-Party Risk Management in April 2024, many Canadian fintechs and their regulated partners treated it as a documentation exercise. Two years later, that posture is catching up with them. OSFI supervisory reviews in 2026 are probing cloud arrangements, sub-contractor chains, and exit strategies with a level of specificity that a policy document alone cannot satisfy. For fintech companies that serve federally regulated financial institutions (FRFIs) — or that are themselves regulated — getting B-10 right is no longer optional.
Three Areas Where B-10 Compliance Is Falling Short
1. Cloud Concentration Risk Is Underestimated
B-10 requires FRFIs to identify critical arrangements — third-party relationships where disruption would materially affect core business functions — and to actively manage concentration risk within those arrangements. In practice, concentration risk is most acute where institutions rely on a single hyperscaler (AWS, Microsoft Azure, or Google Cloud) for mission-critical infrastructure without credible fallback options.
OSFI’s supervisory expectation is not that institutions avoid hyperscalers — they are mature, audited platforms — but that they can demonstrate a plausible exit or recovery path. Many firms lack this. Their exit plans exist on paper but have never been tested, and their contractual rights to retrieve data in a usable format within a defined timeframe are either missing or buried in vendor addenda that predate the institution’s B-10 review.
2. Fourth-Party Visibility Is a Genuine Gap
B-10 extended due diligence obligations beyond direct vendors to include sub-arrangements — the third parties that your third parties rely on. For a fintech offering a cloud-based AML or payments platform to an FRFI client, this creates real upstream pressure: your FRFI client must understand your sub-contractor stack, and regulators may ask them to demonstrate that visibility.
The practical challenge is that sub-contractor maps change frequently. A SaaS vendor may rotate data centres, switch cloud regions, or onboard a new identity-verification provider without notifying their customers. Institutions need vendor contracts that mandate change notification and periodic sub-contractor disclosures — not just a one-time assessment at onboarding.
3. Data Residency Expectations Are Evolving
B-10 itself does not mandate that data be stored in Canada, but the combination of B-10’s confidentiality requirements, the Office of the Privacy Commissioner’s cross-border transfer guidance, and emerging CPPA obligations is pushing many institutions toward a de facto Canadian data residency requirement for the most sensitive data categories — particularly personally identifiable information and transaction records subject to FINTRAC retention rules.
Fintechs that rely on US- or EU-based cloud infrastructure for Canadian financial data should audit their data flows now. The question OSFI supervisors are asking is not just where data lives, but whether the institution can demonstrate it knows where data lives — and can prove the storage location to an examiner on short notice. Our Canadian sovereign cloud infrastructure team works with firms navigating exactly this intersection of regulatory obligation and operational architecture.
Practical Steps to Strengthen Your B-10 Posture
- Build and maintain a Technology and Critical Third-Party (CTP) Register. This living document should capture every material arrangement, its criticality classification, data types involved, sub-contractor dependencies, and the contractual protections in place. OSFI examiners will ask to see it.
- Perform a materiality re-assessment annually. What was non-critical eighteen months ago may be critical today if the vendor now processes higher volumes or supports a broader function. Materiality is not a one-time label.
- Negotiate enhanced contractual rights with cloud vendors. At minimum: audit rights (or independent assessment equivalents), data portability guarantees with defined export timelines, sub-contractor change notification obligations, and termination rights that do not require cause.
- Test your exit plan. An exit plan that has never been exercised is a gap risk, not a control. Conduct a tabletop exercise annually and document what broke — this demonstrates good faith to supervisors even when the plan is imperfect.
- Map and monitor your sub-contractor chain. Use vendor questionnaires, contractual disclosure obligations, and SOC 2 Type II reports to maintain visibility into fourth parties. Treat a vendor’s failure to provide sub-contractor transparency as a risk flag, not a minor administrative issue.
- Align your B-10 and B-13 programs. OSFI’s companion Guideline B-13 (Technology and Cyber Risk Management) sets resilience and incident-response expectations for the same cloud arrangements governed by B-10. Treating them in silos creates both audit gaps and operational blind spots — review them together.
What’s Coming in 2027
OSFI has signalled that artificial intelligence model risk — including the use of large language models in credit decisioning, fraud detection, and customer service — will become a distinct supervisory focus in 2027. The institutions that will adapt most readily are those that have already built disciplined third-party risk frameworks under B-10: inventoried vendors, maintained sub-contractor maps, and negotiated substantive contractual protections. The operational infrastructure you build today for cloud vendors will be the template you apply tomorrow to AI model providers.
Summary
OSFI B-10 is no longer a new guideline — it is an active supervisory lens. The firms that will fare best in upcoming reviews are those that have moved from policy compliance to operational embedding: tested exit plans, current sub-contractor maps, negotiated contractual protections, and integrated B-10/B-13 programs. The technology architecture decisions you make today directly shape your regulatory risk posture tomorrow.
Need guidance? Reach out to our team — no pressure, no jargon.