FreeThe +45-page Authentication Analytics Whitepaper — measuring real login journeysDownload
Back to Overview

OSFI B-13 Guideline for Federally Regulated Financial Institutions (FRFIs) in Canada

Learn how to comply with Canada’s OSFI Guideline B-13 by using MFA, enhancing governance & boosting technology resilience to protect financial institutions.

alexander petrovski
Alex

Created: January 14, 2025

Updated: August 25, 2026

OSFI B-13 Guideline for Federally Regulated Financial Institutions (FRFIs) in Canada
Key Facts
  • OSFI Guideline B-13, effective January 1, 2024, mandates risk-based identity controls and MFA for all federally regulated financial institutions in Canada.
  • B-13 is the first formal regulatory directive in Canada requiring safer MFA, moving institutions beyond vulnerable SMS-OTP methods.
  • 25% of Canadians reported fraud within a three-year window; 2,769 scam calls impersonating financial institutions were recorded in just nine months of 2022.
  • SMS-OTP, still prevalent among Canadian banks, is vulnerable to SIM swapping, phishing and interception, making it inadequate under B-13's risk-based requirements.
  • Replacing SMS-OTP with phishing-resistant passkeys removes the per-message cost of every code and every resend, while achieving B-13 compliance.

1. Introduction#

Financial fraud is increasing in Canada, and the banking sector is under increasing pressure to strengthen its defenses. In an effort to mitigate these threats, Canada’s Office of the Superintendent of Financial Institutions (OSFI) has introduced OSFI Guideline B-13 - a regulatory framework that sets new expectations for federally regulated financial institutions (FRFIs). Effective from January 1, 2024, Guideline B-13 provides a roadmap for improving technology and cyber risk management, including stricter requirements for multi-factor authentication (MFA).

In this post, we’ll answer the following questions regarding Guideline B-13:

WhitepaperBanking Icon

Banking Passkeys Report. Practical guidance, rollout patterns and KPIs for passkey programs.

Get the Report
  • Why is Guideline B-13 so important?
  • What are the areas Guideline B-13 is focusing on?
  • What are the practical steps Canadian banks and fintech organizations can take to meet B-13 standards?

2. The Growing Threat of Financial Fraud in Canada#

Fraudsters are becoming increasingly sophisticated, and recent statistics underscore the need for tighter security protocols:

  • 25% of Canadians reported experiencing fraud within a three-year window, according to a September 2022 survey.
  • Phone-based schemes are particularly rampant. Between January and September 2022, there were 2,769 reported scam phone calls claiming to originate from financial institutions , as recorded by the Canadian Anti-Fraud Centre (CAFC).

Compounding this problem is the fact that many Canadian banks still rely on inferior authentication methods, such as SMS-OTP (one-time passcodes sent via text). These codes are vulnerable to interception, social engineering, and phishing attacks, making them a weak link in Canada’s digital security chain.

Igor Gjorgjioski Testimonial

Igor Gjorgjioski

Head of Digital Channels & Platform Enablement, VicRoads

We hit 80% mobile passkey activation across 5M+ users without replacing our IDP.

See how VicRoads scaled passkeys to 5M+ users, alongside their existing IDP.

Read the case study

3. Why Multi-Factor Authentication Matters#

Although some Canadian financial institutions have already embraced MFA, the common approach of sending an SMS OTP remains prevalent. However, SMS-OTP-based authentication:

  • Requires users to manually enter a code from one channel (SMS) into another (a browser or banking app).
  • Leaves room for human error and opens the door for phishing attempts, where criminals trick victims into sharing their verification codes.
  • Has limited resilience against more advanced scam tactics, including SIM swapping and unauthorized access to text messages (SMS OTP were simply not designed for authentication when SMS became a thing).
  • Leads to high costs for the company since every send SMS must be payed for

To counter these vulnerabilities, Guideline B-13 stipulates the adoption of more secure authentication methods. This requirement marks the first formal regulatory directive in Canada that mandates safer, more reliable MFA.

Why are Passkeys important?

Passkeys for Enterprises

Passwords & phishing put enterprises at risk. Passkeys offer the only MFA solution balancing security and UX. Our whitepaper covers implementation and business impact.

Passkeys for Enterprises

Download free whitepaper

4. What Is OSFI Guideline B-13?#

Released in July 2022 by OSFI, Guideline B-13 sets forth principles for how FRFIs should handle technology and cyber risk. Beyond safeguarding against data breaches and outages, it emphasizes the need for risk-based identity and access controls - including multi-factor authentication and privileged access management. Not only should indentity measures should be employed, but also PEP screening to evaluate the risk of fraud associate with the individual.

According to the Office of the Superintendent of Financial Institutions OSFI:

“The widespread use of technology and the growing rate of cyber incidents has created an urgent need for enhanced regulatory guidance to FRFIs on technology and cyber risk management. OSFI’s final Guideline B-13 provides that guidance, while allowing FRFIs to compete effectively and take full advantage of digital innovation.”

5. Key Areas of Guideline B-13#

Guideline B-13 is built around three main pillars, each of which encompasses various strategies to enhance technology and cyber risk management:

Substack Icon

Subscribe to our Passkeys Substack for the latest news.

Subscribe

5.1 Governance and Risk Management#

  • Focus: Leaders and decision-makers must establish clear structures, strategies, and frameworks for overseeing technological and cyber risks.

  • Why It Matters: Effective governance not only supports accountability but also provides the necessary oversight to ensure technology initiatives and risk controls are properly implemented.

5.2 Cyber-Security#

  • Focus: Establishes the defensive measures needed to safeguard an institution’s technology assets.

  • Why It Matters: By implementing stronger preventative and detective controls, organizations are better equipped to protect sensitive data and respond effectively to potential cyber threats.

6. Recommendation for Canadian Banks and FinTechs#

6.1 Assess Current MFA Measures#

Begin by auditing your existing authentication methods and map out their vulnerabilities. Compare these findings against B-13’s risk-based requirements to prioritize improvements. Aim for scalable solutions that can adapt to new threats and regulatory shifts.

6.2 Explore Phishing-Resistant Passwordless Authentication#

Transition away from SMS-based authentication to more secure alternatives, such as phishing-resistant MFA with passkeys. This and other methods significantly reduce the risk of intercepted codes and SIM swap attacks.

6.3 Strengthen Cybersecurity Governance#

Clearly define roles and responsibilities to foster accountability. Integrate cyber risk management into strategic planning, and regularly review policies on vendor risk, data privacy, and incident response. Cultivate a security-first culture through ongoing staff education, phishing simulations, and shared best practices.

6.4 Invest in Resilient Technology#

Upgrade outdated infrastructure to minimize downtime, improve system stability, and support advanced security tools. For example, migrating mission-critical applications to secure cloud platforms can lower the risk of data. Regular disaster-recovery drills simulating ransomware attacks help pinpoint weaknesses and train your response teams.

7. How Corbado can help#

Recommendation 6.1 asks you to audit the authentication you already run before you replace it, and that is the step most B-13 programmes skip. Corbado Observe is the authentication observability layer, and it reads your current SMS-OTP and password flows with no passkey rollout in front of it. A Canadian bank or fintech running that audit can:

  • Show what the current MFA costs users. Login Methods holds three rows, passkey, password and social, and reports for each what fraction of logins it carries, how often it finishes, how often it fails and how long customers spend in it over one period. SMS-OTP is measured a level below that, as its own subflow, which is where "SMS-OTP is vulnerable" turns into a completion rate and an error rate you can put in front of a regulator.
  • Locate the abandonment. Friction shows where in the login people give up, which is the evidence a risk-based control under B-13 has to be argued from.
  • Report it to the board. Executive Reporting is a board-level view of the same data, with page subscriptions that email a saved board on a weekly or monthly schedule to one project member. That fits the governance expectations in section 5.1.
  • Keep the telemetry defensible. What lands in Observe is opaque tus- and flw- keys plus whatever your integration chooses to send alongside them. Write that choice into the integration spec and the data-handling part of a B-13 review has a source document behind it instead of a vendor assurance.
See Login Friction in Corbado Observe →

Whether you are a large bank or an emerging fintech, the move off SMS OTP itself is what Corbado Connect handles: passkey login and append components in front of the identity provider you already run, plus a gradual rollout ruleset so the first cohort is a decision you make on client conditions. A dry run over the last seven days of your own recorded traffic sizes that cohort before anybody is moved onto it.

StateOfPasskeys Icon

See how many people actually use passkeys.

View Adoption Data

8. Conclusion#

Guideline B-13 represents a decisive step forward in fortifying Canada’s financial sector against escalating cyber threats. By addressing governance, operational resilience, and advanced cybersecurity measures, OSFI is sending a clear message that outdated authentication methods and lax oversight are no longer acceptable.

In this article, we answered the initial questions as follows:

  • Why is Guideline B-13 so important?

    Guideline B-13 is critically important because it establishes a clear framework for Canadian financial institutions to manage technology and cyber risks, ensuring operational resilience, regulatory compliance, and protection against increasing cyber threats.

  • What are the areas Guideline B-13 is focusing on?

    Guideline B-13 primarily focuses on enhancing governance structures, strengthening risk management practices, improving the security of technology operations, ensuring robust cybersecurity measures, and developing effective incident response and recovery processes.

  • What are the practical steps Canadian banks and fintech organizations can take to meet B-13 standards?

    To meet B-13 standards, Canadian banks and fintech organizations can adopt comprehensive cybersecurity frameworks, conduct regular risk evaluations, improve board-level oversight on cyber risks, enhance third-party risk management, and establish well-defined protocols for responding to and recovering from cyber incidents.

Corbado

About Corbado

Corbado is the Passkey Intelligence Platform for large-scale CIAM teams running consumer authentication. We help you see what IDP logs and generic analytics tools can't: where passkeys, passwords, OTP, social login and fallback journeys succeed, stall or fail, which devices and browsers create friction, and when an OS update silently breaks login. Two products: Corbado Observe layers process mining and observability across authentication journeys. Corbado Connect adds managed passkeys with analytics built in alongside your IDP. VicRoads runs passkeys for 5M+ users with Corbado (+80% passkey activation). Talk to a Passkey Expert

Frequently Asked Questions#

What is the OSFI B-13 compliance deadline and which institutions must comply?#

OSFI Guideline B-13 took effect on January 1, 2024, applying to all federally regulated financial institutions (FRFIs) in Canada. Released in July 2022, the guideline gave institutions roughly 18 months to prepare, covering banks, fintechs and other OSFI-supervised entities.

Why does OSFI B-13 consider SMS-OTP insufficient for MFA compliance?#

SMS-OTP requires users to manually transfer codes between channels, exposing them to SIM swapping, phishing and interception attacks. SMS was not designed as an authentication mechanism, and B-13's risk-based identity requirements push Canadian financial institutions toward phishing-resistant MFA alternatives like passkeys.

What governance structures does OSFI B-13 require FRFIs to implement?#

B-13 requires leaders and decision-makers to establish clear structures, strategies and frameworks for overseeing technology and cyber risks. This includes integrating cyber risk into strategic planning, defining accountability roles, managing vendor risk and regularly reviewing data privacy and incident response policies.

Start by auditing existing authentication methods and mapping vulnerabilities against B-13's risk-based requirements. Then transition to phishing-resistant MFA such as passkeys, upgrade legacy infrastructure and conduct regular disaster-recovery drills simulating ransomware attacks to validate resilience.

What cybersecurity controls beyond MFA does OSFI B-13 require Canadian financial institutions to have?#

B-13 requires FRFIs to implement preventative and detective cybersecurity controls, conduct phishing simulations and maintain well-defined incident response protocols. Migrating mission-critical applications to secure cloud platforms and performing regular disaster-recovery drills are also recommended to reduce downtime and improve system stability.

Next Step: Ready to implement passkeys at your bank? Our +90-page Banking Passkeys Report is available.

Get the Report

Share this article


LinkedInTwitterFacebook