Financial services.

Regulated financial institutions face a supervisory expectation that risk is identified, measured and governed continuously, not reviewed once a year. The assessment has to withstand scrutiny from a second line of defence and from the regulator behind it.

Regulatory anchor. OSFI Guideline B-13 sets expectations for technology and cyber risk management at federally regulated financial institutions.

Third-party and concentration risk. Exposure across critical service providers, including where several dependencies rest on a single provider.

Alignment to existing taxonomies. Control mapping that fits the risk registers and reporting the institution already runs.

Evidence for the second line. Inherent and residual scoring, and a trail, that hold up under internal audit and supervisory review.

What we assess that is specific to it.

The method does not change. What changes is what we look hardest at, and what counts as a serious result.

What counts as severe here.

Impact is calibrated to the sector. The same threat carries a different weight depending on what it would actually cost.

RatingWhat it means in this sector
SevereMaterial financial loss, regulatory action, or sustained loss of a core banking service.
MajorSignificant disruption requiring executive and board involvement and regulatory notification.
ModerateContained operational impact managed within existing controls.

What the report has to survive.

A financial-services report is examined by a second line of defence whose job is to challenge it, and potentially by a regulator behind them. It has to map onto established risk taxonomies, carry an evidence trail for every rating, and align to the outcomes B-13 expects rather than restating them.

Working in financial services?

Tell us what you run and what you need to decide. We will tell you plainly whether we are the right people for it.

Request an assessment