2024-01-31
The Office of the Superintendent of Financial Institutions (OSFI) issued this guideline to establish risk-based expectations for federally regulated financial institutions regarding integrity and security policies. Institutions must implement, maintain, and regularly assess adequate procedures to protect physical premises, technology assets, personnel, and data against threats such as foreign interference, undue influence, and malicious activity. The framework mandates robust background checks for key personnel, rigorous third-party due diligence, and prompt detection and reporting of security incidents to ensure operational resilience and regulatory compliance.