OSFI is Canada's federal prudential regulator for banks and insurers, and Guideline B-13 sets its expectations for technology and cyber risk management, alongside Guideline B-10 on third-party risk. Like APRA's standards it governs how a regulated institution manages technology risk, and imposes no obligation to expose data or publish an interface.
OSFI Guideline B-13
OSFI’s position in Canadian insurance is prudential and federal, while market conduct sits with the provinces — the most fragmented supervisory split of any market in this research.
- B-13 (Technology and Cyber Risk) - Expectations covering governance, technology operations, cyber security and third-party technology arrangements.
- B-10 (Third-Party Risk) - Reaches the vendor and platform relationships an insurer depends on.
- Federal-provincial split - OSFI supervises solvency; FSRA in Ontario, the AMF in Quebec and eleven other provincial and territorial regulators handle market conduct.
- No access mandate - Nothing in the framework requires an insurer to publish a contract, and Canada’s open-banking framework excludes insurance entirely.
The finding worth recording against this entry is not about the guideline but about the regulator. The State of Canadian Insurance APIs scored OSFI at 48.1 — second in the entire country — on a live CKAN open-data platform whose tools were verified against the running service. Every federally-regulated insurer OSFI supervises scores below it, and the largest life insurer in Canada scores 8.3. When the supervisor is more machine-readable than the supervised, that is a fact about the sector’s priorities.
Referenced in API Evangelist papers
This regulation shows up in my published research. These reports read the machine-readable evidence provider by provider — and put this regulation in the context of a real sector.
The State of Canadian Insurance APIs
OSFI supervises federally-regulated insurers prudentially and publishes a better API than any of them — ranking second in the country on a live CKAN data platform.