## INTRODUCTION AND METHODOLOGY

## Source details

**Canonical URL:** [INTRODUCTION AND METHODOLOGY](https://www.imf.org/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf.json)

---

### Overview and Scope
- Assessment covered OSFI’s regulation and supervision of banks and foreign bank branches and federally regulated deposit-taking institutions, including trust and loan companies and credit cooperatives, generally referred to as banks.
- Canada’s six Domestic Systemically Important Banks (D-SIBs) account for 96 percent of banking sector assets.
- Total assets of the banking sector reached more than 226 percent of GDP as of 2023.
- Report prepared by Ana Paula Castro Carvalho and José García-Barroso Recio.

### Institutional mandates, powers, and independence (CPs 1–2)
- Findings:
  - OSFI has necessary legal powers to conduct supervision; guidelines are enforceable in practice.
  - The OSFI Act’s statutory purpose is “to contribute to public confidence in the Canadian financial system” (OSFI Act, Section 3.1).
  - The Bank Act provides the Minister of Finance a prominent statutory role in prudential matters and multiple Ministerial/Governor-in-Council regulatory powers.
  - OSFI is not fully independent to define and execute its budget: budget needs Minister of Finance sign-off and has faced cost‑containment measures (wage freezes, hiring freezes).
  - OSFI’s objects include supervision for integrity and security (foreign interference) via Subsection 4(2), points (a.1) and (b.1).
- Risks identified:
  - Lack of explicit primacy of safety and soundness in law; “public confidence” mandate can host broader objectives.
  - Expanded integrity/security mandate could distract from core prudential work and create role ambiguity with national security bodies.
  - Budgetary constraints have produced resource shortfalls in core supervision, while mandates expanded.

### Key high-level recommendations
- Enhance OSFI’s institutional legal framework to guarantee autonomy in law and clarify safety and soundness as OSFI’s primary objective.
- Strengthen OSFI’s budgetary autonomy to address resource constraints and ensure capacity for increased supervisory activity.
- Make supervision more intrusive: increase frequency and depth of on-site reviews, strengthen review of banks’ model outputs, implement supervisory cycles tied to ORR and bank tier.
- Improve sanctioning framework: raise deterrent effect of monetary penalties; consider publication policy for certain sanctions; broaden use of statutory powers where remediation is not achieved.
- Strengthen AML/CFT supervisory resources and sanctioning regime to increase coverage and deterrence for high-risk entities.

*Source: INTRODUCTION AND METHODOLOGY, IMF Financial Sector Assessment — Canada.*

---

### SUPERVISORY FRAMEWORK, RATING AND INTERVENTION (CPs 8–11)

### ORR supervisory framework (effective April 1, 2024)
- Features:
  - Overall Risk Rating (ORR) scale: 1 (minimal risk) to 8 (non-viability imminent).
  - Staging: ORR 1–4 = Stage 0; ORR 5 = Stage 1; ORR 6 = Stage 2; ORR 7 = Stage 3; ORR 8 = Stage 4.
  - Four risk categories assessed: Business Risk; Financial Resilience; Operational Resilience; Risk Governance.
  - ORR is forward-looking and can be driven by any of the four risk categories.
- Outcomes:
  - ORR enhanced clarity on remediation and early intervention; more banks being staged and clearer remediation paths.

### Supervisory approach and practices
- Ongoing monitoring foundation; supervisory process culminates in annual supervisory ratings.
- Tiering (since end–2023):
  - Tier 1: 6 banks (D-SIBs)
  - Tier 2: 8 banks
  - Tier 3: 17 banks
  - Tier 4: 33 banks
  - Tier 5: 38 banks
- Specialist resources and composition:
  - One LS per institution; LS for each of six D-SIBs has a team of around 6 people.
  - Division for SMSBs composed of 62 people; credit risk specialists: 33 people; market & liquidity — 5 for trading, 5 for liquidity; technology risk — 32 people; climate — 26 people; integrity/security — 16 people.
- Quality assurance:
  - SQAD provides methodology QA; Group Rating Committees and Entity Rating Panels provide review.

### Intrusiveness, on‑site reviews, and resource constraints
- Findings:
  - Supervisory practices rely heavily on off-site monitoring, questionnaires, and cross-sector reviews; many thematic reviews are questionnaire-based.
  - On-site reviews are less frequent in core banking areas (credit, interest rate risk, model validation).
  - Resource constraints impacted supervision of core areas; recommendation to increase deeper on-site reviews and implement supervisory cycles with minimum number of deeper reviews per cycle tied to ORR and tier.

### Corrective and sanctioning powers
- Practice and legal tools:
  - Moral suasion is preferred; statutory powers (Directions of Compliance, Prudential Agreements, Orders to increase capital/liquidity, taking control) considered ultima ratio.
  - Administrative Monetary Penalties (AMPs) statutory maxima:
    - Natural person: Minor $10,000; Serious $50,000; Very serious $100,000.
    - Entity: Minor $25,000; Serious $100,000; Very serious $500,000.
  - AMPs infrequently used; individuals have never been sanctioned by OSFI.
  - Sanctions considered Prescribed Supervisory Information and are confidential; publication policy absent.
- Recommendations:
  - Raise deterrent effect of AMPs; consider publication policy for certain sanctions; broaden use of statutory powers when remediation not achieved.

*Source: IMF FSAP assessment excerpts.*

---

### LICENSING, OWNERSHIP, SUBSTANTIAL INVESTMENTS (CPs 4–7)

### Licensing and new entrants
- Two-step process:
  - Letters patent by Minister of Finance (upon Superintendent’s recommendation).
  - Order to commence and carry on business by the Superintendent.
- OSFI conducts lengthy reviews of business plan, governance, risk management, capital, liquidity, IRRBB, AML/CFT and technology.
- OSFI’s Internal Risk Tolerance Framework for New Entrants emphasizes low tolerance for loss to depositors and zero tolerance for national security and AML/CFT matters.

### Transfer of significant ownership & major acquisitions
- Statutory definitions:
  - Significant interest: >10 percent of class of shares.
  - Major shareholder: >20 percent voting shares or >30 percent non-voting shares (section 2.2).
  - Banks with equity of CAD 12 billion or more must be “widely held” (no major shareholder; no person shall control such a bank).
- Approval requirements:
  - Ministerial approval required for acquisitions of significant interests/control in many cases (sections 373, 377.1, 396).
  - OSFI reviews and recommends; Minister may impose terms and conditions.
- Findings:
  - Examples of after‑the‑fact approvals for SMSBs occurred; voting rights suspension used; assessors recommend outreach and potential reporting requirements for non‑widely held banks.

*Source: IMF assessment excerpts.*

---

### AML/CFT SUPERVISION AND SANCTIONS (CP 29)

### Institutional arrangements and scope
- FINTRAC is Canada’s financial intelligence unit and sole AML/CFT supervisor since 2021.
- PCMLTFA provides legal basis; FINTRAC reports to the Minister of Finance.
- FI unit supervising banks: 17 full-time equivalents (FI unit supervisory scope: 35 domestic banks, 15 foreign banks and 29 foreign bank branches).

### Supervisory coverage and frequency
- Findings:
  - FINTRAC able to perform on average one thorough compliance review every 6 years at each large bank.
  - Supervisory cycle for D-SIBs is long; resource constraints impede higher-frequency, deep compliance reviews.
- Sanctions:
  - AMPs under PCMLTFA Regulations: entity maximum for a very serious violation: CAD 500,000; individual maximum CAD 100,000.
  - 2023–24: FINTRAC issued 12 Notices of Violation totaling CAD 26.1 million (largest AMPs in FINTRAC history).
  - Assessors: current penalties often too low to be an effective deterrent for banks; enforcement effectiveness limited to period inspected (usually 1 year).

### Observations and recommendations
- Increase FINTRAC supervisory resources and frequency of in-depth compliance reviews for high-risk entities (banks).
- Reform sanctioning framework:
  - Re-calibrate penalties relative to bank profitability/scale.
  - Expand catalogue of infractions to cover delays, non-compliance with recommendations, misconduct.
  - Allow sanctions beyond the one-year inspection period where long-standing issues detected.
  - Consider clauses allowing penalties to exceed statutory caps in egregious cases.
- Increase coordination with OSFI on integrity/security and supervisory findings.

*Source: IMF FSAP assessment excerpts.*

---

### CONSOLIDATED SUPERVISION, CROSS‑BORDER RELATIONS, RESOLUTION

### Consolidated supervision (CP12)
- Findings:
  - Consolidated supervision is well-established; OSFI collects and analyzes consolidated information for banking groups.
  - All Canadian D-SIBs use internal models to calculate credit risk capital requirements; credit risk represents more than 80 percent of RWAs for D-SIBs.
  - OSFI’s ability to review parent and affiliate activities for SMSBs is more limited and often reactive; assessors recommend stronger oversight of SMSB wider-group risks.

### Home‑host relationships, supervisory colleges and CMGs (CP3, CP13)
- Findings:
  - OSFI has more than 30 MoUs with foreign regulators and hosts Supervisory Colleges, CMGs, and Outreach Panels.
  - Regular (usually quarterly) meetings with regulators of key jurisdictions; active cooperation with US, UK and other host regulators.
  - OSFI and CDIC have Strategic Alliance Agreement and Guide to Intervention for coordination from early intervention to non‑viability stages.

### Crisis management, intervention, and CDIC powers
- OSFI statutory intervention tools include Directions of Compliance (section 645), Prudential Agreements (section 644.1), Orders to increase capital/liquidity (section 485), and taking control (section 648).
- CDIC tools include liquidation/payout; agency agreement; assisted transaction; forced sale; open bank assistance; bridge bank; Enhanced Financial Institution Restructuring Powers for D-SIBs enabling bail-in.
- Guide to Intervention links ORR stages to OSFI and CDIC actions; staging affects CDIC premiums and preparatory actions.

*Source: IMF FSAP assessment excerpts.*

---

### RISK‑SPECIFIC SUPERVISORY FINDINGS AND RECOMMENDATIONS

### Credit risk, provisioning and model risk (CPs 15–18)
- Findings:
  - Credit risk supervisory approach and methodologies are sound and well-developed.
  - Deep credit risk inspections are not frequent; model risk receives insufficient supervisory coverage.
  - Model Risk unit in CRD: 5 full-time employees (2 analysts, 2 senior specialists, 1 director vacancy).
  - CRD: 33 full-time employees; banking supervision staff for banks: 365 people as of March 31st, 2024.
  - More than 60 IRB models approved across six D-SIBs; Canada’s historical loss data described as benign, creating risks of underestimation.
- Recommendations:
  - Reinforce credit risk department with model specialists.
  - Issue guidance on minimum thresholds for material model changes; notification thresholds should not be at banks’ discretion.
  - Increase frequency/depth of model reviews and on-site verification of model outputs; tie findings to quantitative capital impacts where warranted.
  - Define forbearance and cure periods; consider longer lifetime loss horizons for RESL mortgages (reflecting real payment period, not short contractual maturities).

### Market risk and IRRBB (CPs 22–23)
- Findings:
  - Market risk framework (Chapter 9 CAR) applied to D-SIBs and banks with significant trading activity; these banks hold 96 percent of banking assets.
  - OSFI has not conducted supervisory reviews of banks’ IRRBB models; monitors via regulatory returns and peer comparisons.
- Recommendations:
  - Conduct minimum focused reviews of IRRBB models and internal systems for Tiers 1–2 banks to inform supervisory assessment and ICAAP capital considerations.

### Liquidity risk (CP 24)
- Findings:
  - OSFI at the forefront of liquidity supervision: LCR, NSFR (for D-SIBs and certain SMSBs), NCCF, OCFS tools; proportionality applied across SMSB categories I–III.
  - DSB adjustments occur twice a year (June and December).
  - LCR expectations: D-SIBs LCRs of the six D-SIBs in the range 126–129 percent (as of June 2024).
- Recommendations:
  - More frequent bank-specific deep‑dive reviews to verify liquidity practices given complexity and systemic importance.

### Operational risk and resilience (CP 25)
- Findings:
  - OSFI issued Guideline E-21 (August 2024) for Operational Risk and Resilience with phased expectations:
    - Sections 1–2 immediately in effect; full adherence to section 4 by September 1, 2025; mapping of critical operations by September 1, 2026; testing complete by September 1, 2027.
  - Supervisory reviews of technology, cyber and business continuity are more frequent than core banking reviews; investment in operational risk teams increased.
- Recommendations:
  - Continue building supervisory practices for operational resilience; expand incident-to-loss integration and third‑party concentration monitoring.

### Internal control, audit, reporting and disclosure (CPs 26–28)
- Findings:
  - Corporate Governance Guideline sets board responsibilities; OSFI regularly obtains board materials and meets audit committees.
  - Assurance Guideline (2022) sets assurance expectations for capital, liquidity and leverage returns; external audit assurance phased in with some elements deferred to 2025.
  - Pillar 3 disclosures and IFRS reporting are broadly aligned with international standards; OSFI publishing of consolidated data and move to OpenGov underway.
- Recommendations:
  - Increase bank‑specific deep on‑site reviews for internal control and audit effectiveness.
  - Avoid excessive reliance on management and auditors for supervisory assurance; apply supervisory verification selectively.

*Source: IMF assessment excerpts.*

---

### RELATED PARTY, CONCENTRATION, COUNTRY/TRANSFER, AND LARGE EXPOSURES (CPs 19–21, 20)

### Related party transactions (CP 20)
- Findings:
  - Part XI (Self‑dealing) and section 486 define related party; Canadian definition narrower than international standard (close family limited to spouse/common-law partner and children under 18).
  - Substantial set of exceptions permit many related-party transactions; banks do not report related party transactions to OSFI; OSFI does not monitor these transactions systematically.
  - Aggregate exposure limits: subsection 497(2) limits transactions with directors/officers and their interests to 50 percent of regulatory capital.
- Assessment: Principle 20 — Materially Non‑Compliant.
- Recommendations:
  - Implement a prudential related‑party framework aligned with international standards.
  - Consider lowering aggregate exposure limits (e.g., align with 25 percent large exposure standard) and require systematic reporting to OSFI.

### Concentration risk and large exposures (CP 19)
- Findings:
  - D-SIB large exposure limit: 25 percent of Tier 1 capital per counterparty or connected group (Guideline B-2, 2019).
  - 1994 large exposure rules for SMSBs remain in force; assessors suggest lowering the 100 percent of total capital limit for foreign bank subsidiaries (1994 guidance) to improve consistency.
- Assessment: Principle 19 — Compliant.
- Recommendation: Align limits for foreign bank subsidiaries with large exposure framework to reduce outlier 100 percent limit.

### Country and transfer risk (CP 21)
- Findings:
  - OSFI’s CRR assessment criteria and credit risk guidance do not explicitly deal with country and transfer risk.
  - OSFI is not systematically assessing banks’ country and transfer risk management.
- Assessment: Principle 21 — Materially Non‑Compliant.
- Recommendation: Incorporate country and transfer risk expectations into credit risk guidance and CRR assessment criteria.

*Source: IMF assessment excerpts.*

---

### CAPITAL FRAMEWORK, TLAC, BUFFERS, AND IMPLEMENTATION (CP 16)

### Capital targets and buffers (CAR Guideline Chapter 1)
- Target capital ratios (supervisory targets):
  - SMSBs: CET1 7% ; Tier 1 8.5% ; Total capital 10.5%
  - D-SIBs: supervisory target at least CET1 8% ; Tier 1 9.5% ; Total capital 11.5% plus the DSB
- DSB:
  - DSB adjusted twice per year (June and December).
  - DSB announced levels and rationales are publicly communicated.
  - As of October 2024, DSB set at 3.5 percent of RWA (noted elsewhere in assessment material).
- Basel III final reforms:
  - OSFI implemented final Basel III reforms effective February 1, 2023, except output floor which remains at 67.5 percent; no timeline to implement 72.5 percent output floor.
  - On February 12, 2025, OSFI announced deferral of further increases to the output floor; the output floor will remain at 67.5 percent pending further announcement.

### TLAC and leverage for D‑SIBs
- TLAC and leverage targets (as presented):
  - TLAC Leverage ratio: 6.75 percent (Superintendent’s order dated August 21, 2018).
  - Addition of DSB: 3.5 percent.
  - Addition of D-SIB leverage ratio buffer: 0.5 percent.
  - Total required TLAC ratio for D-SIBs: 25 percent.
  - Total required leverage ratio for D-SIBs: 7.25 percent.
- Supervisory discretion: Superintendent may set higher targets or Pillar 2 add-ons where warranted.

### Capital composition and trends (D‑SIBs)
- D-SIBs capital ratios (percent):
  - CET1: 2020: Q4 — 12.2; 2021: Q4 — 13.3; 2022: Q4 — 13.6; 2023: Q4 — 13.4; 2024: Q2 — 13.1
  - AT1: 2020: Q4 — 1.7; 2021: Q4 — 1.7; 2022: Q4 — 1.8; 2023: Q4 — 1.8; 2024: Q2 — 1.8
  - Tier 2: 2020: Q4 — 2.1; 2021: Q4 — 2.0; 2022: Q4 — 2.0; 2023: Q4 — 1.9; 2024: Q2 — 1.9
  - Total Capital: 2020: Q4 — 16.0; 2021: Q4 — 16.9; 2022: Q4 — 17.4; 2023: Q4 — 17.0; 2024: Q2 — 16.8
- AT1 composition (as of Q2 2024):
  - 23 percent retail preferred shares
  - 12 percent institutional preferred shares
  - 56 percent limited recourse capital notes
  - 9 percent other AT1

### Recommendations and observations
- Maintain close scrutiny of model‑based capital estimations given IRB prevalence (credit risk >80 percent RWA).
- Consider a simplified market risk capital requirement for non‑D-SIBs with significant foreign currency/commodity exposure.

*Source: CAR Guideline excerpts and IMF assessment text.*

---

### DATA, REPORTING, ASSURANCE AND SANCTIONS (CPs 10, 11)

### Regulatory reporting and data modernization
- Regulatory returns:
  - BCAR (capital), LCR, NSFR, I3 (IRRBB), Schedule 986 (market risk) and others submitted at prescribed frequencies.
- Data modernization:
  - Data Collection Modernization (DCM) initiative launched June 2023; procurement and replacement of RRS platform planned with goal to award contract by early 2025.
- Assurance guideline (2022):
  - External audit opinion, senior management attestation and internal audit opinions required for capital, liquidity and leverage returns; external audit assurance phased in, some elements deferred to 2025.

### Enforcement, timeliness and penalties
- Late and erroneous filing penalty framework: per‑day penalties tiered by bank size ($100, $250, $500 per day depending on bank size), administrative procedures for Notices of Violation and invoice issuance.
- Assessors’ view on sanctions:
  - AMPs low relative to bank scale; infrequent use undermines deterrence.
  - Recommendation to recalibrate AMPs, broaden scope, and consider publication where appropriate (requires reform of PSI confidentiality).

*Source: IMF assessment excerpts.*

---

### PRINCIPAL ASSESSMENTS — OVERVIEW OF RATINGS (HIGHLIGHTS)
- Principle 1 — Largely Compliant.
- Principle 2 — Materially Non‑Compliant (assessors’ conclusion on independence, accountability, resourcing and legal protection).
- Principle 4 — Compliant (permissible activities and licensing).
- Principle 6 — Compliant (transfer of significant ownership), with operational concerns on ex‑post approvals.
- Principle 8 — Compliant (supervisory approach / ORR).
- Principle 9 — Largely Compliant (supervisory techniques; reliance on off‑site monitoring; need for deeper reviews).
- Principle 10 — Compliant (reporting and data), with recommendations on assurance and sanctioning.
- Principle 12 — Compliant (consolidated supervision), with recommended improvements for SMSB wider‑group supervision.
- Principle 16 — Compliant (capital framework).
- Principle 17 — Largely Compliant (credit risk; model risk weaknesses).
- Principle 18 — Compliant (problem exposures and provisioning), with recommendations on forbearance, cure periods and RESL lifetime horizons.
- Principle 20 — Materially Non‑Compliant (related party framework).
- Principle 21 — Materially Non‑Compliant (country and transfer risk).
- Principle 23 — Largely Compliant (IRRBB), with recommendation for focused model reviews.
- Principle 24 — Compliant (liquidity).
- Principle 25 — Largely Compliant (operational risk and resilience).
- Principle 26 — Largely Compliant (internal control and audit).
- Principle 27 — Compliant (financial reporting and external audit).
- Principle 28 — Compliant (disclosure and transparency).
- Principle 29 — Materially Non‑Compliant (AML/CFT supervision by FINTRAC given review frequency, sanctioning weaknesses and resourcing constraints).

*Source: IMF FSAP assessment excerpts.*

---

*Italic: Excerpts from IMF Financial Sector Assessment — Canada (IMF FSAP Detailed Assessment; source PDF 1canea2025007-source-pdf).*

### INTRODUCTION AND METHODOLOGY _______________________________________________________ 15

### INTRODUCTION AND METHODOLOGY _______________________________________________________ 15

### Overview and Scope
- Assessment covered OSFI’s regulation and supervision of banks and foreign bank branches and federally regulated deposit-taking institutions, including trust and loan companies and credit cooperatives, generally referred to as banks.
- Canada’s six Domestic Systemically Important Banks (D-SIBs) account for 96 percent of banking sector assets.
- Total assets of the banking sector reached more than 226 percent of GDP as of 2023.
- The report was prepared by Ana Paula Castro Carvalho, Senior Financial Sector Expert at the IMF’s Monetary and Capital Markets Department, and José García-Barroso Recio (IMF External Expert).

### Institutional mandates, powers, and independence (CPs 1–2)
- OSFI has necessary legal powers to conduct supervision and its guidelines are enforceable in practice, but enhancements to the institutional legal framework are warranted to guarantee autonomy in law.
- Key legal and governance observations:
  - The Bank Act provides the Minister of Finance a prominent statutory role in prudential matters, including regulation-making authorities for the Governor in Council.
  - OSFI is not fully independent to define and execute its budget; OSFI’s budget needs Minister of Finance sign-off and is challenged by the Minister of Finance.
  - The promotion of the safety and soundness of banks is not explicitly enshrined as OSFI’s primary objective in the OSFI Act; the “public confidence” mandate is described as plastic and creates lack of clarity.
  - OSFI has a new mandate on integrity and security, including foreign interference; while many aspects are congruent with safety and soundness, the mandate could in some instances go beyond that objective, introducing uncertainty around limits of OSFI’s role and allocation of national responsibilities.
- Potential risks identified:
  - Lack of clear primacy of safety and soundness, jointly with avenues of influence allowed by the Bank Act, may enable the government to impose general political priorities and policy stances over OSFI’s prudential positions.
  - Cost-cutting initiatives and lack of budgetary autonomy have produced resource constraints in core supervision functions, while OSFI’s mandate has expanded (integrity and security).

### Supervisory framework and practices (CPs 8–10, 11)
- OSFI implemented a new supervisory framework in April 2024: the Overall Risk Rating (ORR).
  - The ORR significantly enhanced how supervisory issues are indicated to banks and led to more clarity towards remediation.
  - The ORR assesses comprehensive risk categories and requires a forward-looking view.
  - The Guide to Intervention provides a clear early intervention framework for OSFI and the Canada Deposit Insurance Corporation (CDIC) to coordinate actions.
- Supervisory approach:
  - OSFI’s supervisory process is predicated on ongoing monitoring and cross-sector reviews; the process culminates in annual supervisory ratings of banks.
  - OSFI defines its supervisory approach as risk-based and cross-sector reviews are increasingly common compared to institution-specific reviews.
  - OSFI incorporates macroeconomic conditions, stress testing, and business risk in risk management assessments.
  - Non-financial risks and operational resilience aspects have been incorporated, but supervisory practices on emerging operational resilience issues are ongoing.
- Areas needing strengthening:
  - Supervision could be more intrusive through more frequent and deeper on-site reviews, notably on banks’ risk measurement models and testing effectiveness of banks’ risk management and internal control policies. Quoting guidance: “Good supervision is intrusive. Supervision is premised on an intimate knowledge of the supervised entity. It cannot be outsourced and it cannot rely solely or mainly on offsite analysis. Supervisors in the financial sector should not be viewed as hands-off or distant observers (...).”
  - Resource constraints have impacted supervision of core banking areas, such as credit and interest rate risks, where review of banks’ model outputs could be strengthened.
  - Recommendation to conduct more frequent deeper and targeted reviews in core banking areas, including on-site reviews, and implement formally distinct supervisory cycles with different lengths for banks with different risk profiles, performing a minimum number of deeper reviews in a supervisory cycle for a specific bank, in accordance with its ORR and tier.
- Corrective and sanctioning powers:
  - OSFI acts timely and at an early stage to correct deficiencies and frequently imposes specific capital and liquidity targets to banks.
  - Enforcement relies mainly on moral suasion and non-binding recommendations; statutory powers are now very infrequently used.
  - Monetary penalties are legally capped at low amounts that do not serve as a deterrent and are infrequently used; individuals have never been sanctioned by OSFI.
  - Sanctions are never published because they are considered confidential supervisory information; the report notes that a policy on publication of certain sanctions may help increase dissuasion via reputational impact.

### Ownership, licensing, and structure (CPs 4–7)
- Licensing and approvals:
  - OSFI carries out a lengthy and thorough review of new entrants covering business and strategic plans, Board and senior management suitability, all major risks and risk management capabilities.
  - Licensing involves OSFI’s Approvals Division, supervisors, and specialized subject-matter experts; findings and recommendations are conveyed to new entrants for remediation and commitments are used to condition initial steps as federally regulated banks.
  - OSFI’s analysis is guided by its Internal Risk Tolerance Framework for New Entrants, which considers that OSFI should have a low risk tolerance for loss to depositors and other creditors.
- Substantial investments and ownership change:
  - OSFI can review, reject and impose prudential conditions on transfers of significant ownership, controlling interests and major acquisitions (“substantial investments”).
  - Largest banks with equity of $12 billion or more must be “widely held” by virtue of the Bank Act; no person may be a major shareholder of such a bank and no person shall control in fact such a bank.
  - The Approvals Division carries out comprehensive internal analyses before recommending approvals. Recent non-compliance with prior approval rules was addressed by suspension of voting rights and fines.

### AML/CFT supervision and sanctions
- FINTRAC has been, since 2021, the sole public body entrusted to carry out the functions of Canada’s financial intelligence unit and AML/CFT supervisor.
- The Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and related regulations and guidelines provide a sound financial crime prevention framework.
- Weaknesses identified:
  - Amount of supervisory attention and resources devoted to high-risk entities (such as banks) and deficiencies in the sanctioning framework severely impact AML/CFT results.
  - FINTRAC performs one thorough compliance review every six years on each D-SIB.
  - Current penalties are too low to serve as a deterrent and effectiveness of sanctions is generally limited to the period inspected, which usually corresponds to one year of operations.
  - Authorities’ intention to strengthen the sanctioning regime is noted as important.

### Main recommendations and improvement priorities (high-level)
- Enhance OSFI’s institutional legal framework to guarantee autonomy in law and clarify that safety and soundness of banks is OSFI’s primary objective.
- Strengthen OSFI’s budgetary autonomy to address resource constraints and ensure capacity for increased supervisory activity, including operational resilience mandates.
- Make supervision more intrusive: increase frequency and depth of on-site reviews, strengthen review of banks’ model outputs, and formally implement supervisory cycles tied to ORR and bank tier.
- Improve sanctioning framework: raise deterrent effect of monetary penalties, consider publication policy for certain sanctions, and broaden use of statutory powers where remediation is not achieved.
- Strengthen AML/CFT supervisory resources and sanctioning regime to increase coverage and deterrence for high-risk entities; reduce long intervals between thorough compliance reviews for D-SIBs.

*Source: INTRODUCTION AND METHODOLOGY, IMF Financial Sector Assessment — Canada.*

### 14.      OSFI collaborates closely and effectively with other government entities regarding the

### 14.      OSFI collaborates closely and effectively with other government entities regarding the

### Cooperation and coordination with federal and provincial authorities
- OSFI collaborates closely and effectively with other federal entities with functions regarding policymaking and supervision of the financial sector, including the Department of Finance (DOF), the Bank of Canada (BoC), CDIC, and the Financial Consumer Agency of Canada (FCAC).
- Canadian law and administrative practice provide fora where these public bodies can communicate supervisory priorities by discussing strategies and action plans for addressing problem supervised entities and other emerging issues.
- There is a lack of exchange of institution-specific information with provincial authorities mainly due to legal confidentiality barriers.
- Mechanisms for federal-provincial cooperation are not as well-established and institutionalized.

### Consolidated supervision
- Consolidated supervision is well-established in Canada.
- Canadian legislation and OSFI’s guidance impose prudential standards on a consolidated basis for the banking groups.
- OSFI collects and analyzes financial and other information on a consolidated basis for the banking group.
- OSFI’s supervisors use the whole banking group as a reference, including foreign operations and domestic subsidiaries.
- The scope of supervisory reviews often refers to portfolios or areas related to subsidiaries and cross-border inspections.

### Home-host relationship management
- OSFI’s home-host relationship management is at the forefront.
- Canadian authorities have a complete network of cooperation Memorandum of Understanding (MoU) and host several fora that support interaction, cooperation and exchange of information with foreign regulators.
- The six D-SIBs are internationally active and have material subsidiaries and business in the US, the UK, Latin America and Asia; Canada is mainly a home jurisdiction.
- OSFI routinely exchanges information with key foreign home and host regulators and conducts regular (usually quarterly) meetings with regulators of key jurisdictions, depending on the institution being assessed.

### Corporate governance (CP 14)
- Minimum requirements on banks’ board structures and responsibilities are established in the Bank Act.
- OSFI’s guidelines set expectations with respect to corporate governance of banks.
- OSFI implemented a comprehensive supervisory framework that obtains extensive information on board and senior management discussions via the quarterly monitoring process and establishes important touchpoints with senior management and the board.
- The new supervisory framework places great emphasis on the assessment of corporate governance.

### Prudential requirements, regulatory framework, accounting and disclosure (CPs 15–28)
- Risk management processes of banks in Canada are included in OSFI’s supervisory framework through ongoing monitoring and reviews that examine corporate governance issues.
- Macroeconomic conditions are incorporated into supervisory processes via stress testing and business risk in risk management assessments.
- OSFI has invested significantly in supervision of non-financial risks, with supervisory reviews covering contingency arrangements and operational resilience.
- All Canadian D-SIBs use internal models to calculate their credit risk capital requirements, which represent more than 80 percent of Risk-weighted Assets (RWAs).

### Capital framework and Basel III implementation
- OSFI expects all banks to maintain supervisory targets equal to or greater than the minimum capital ratios plus various buffers.
- OSFI implemented the final Basel III reforms effective February 1, 2023, in line with the Basel timeline, except for the output floor, which will remain at 67.5 percent, with no timeline to implement the Basel III 72.5 percent capital floor applicable to capital requirement calculated under internal models.
- OSFI imposes specific capital charges to D-SIBs and Small and Medium Sized Banks (SMSBs) mainly through establishing idiosyncratic higher capital targets linked to macroeconomic factors or specific deficiencies in internal controls, risk management or corporate governance.

### Credit risk supervision and model risk
- OSFI’s supervisory approach and methodologies for credit risk are sound and well-developed.
- Deep credit risk inspections are not frequent and model risk receives insufficient supervisory coverage.
- Credit risk supervisory reviews (CRRs) are devised as thorough examinations when conducted with appropriately wide scope and sufficient verificative activities.
- OSFI lacks enough specialists for appropriate Internal Ratings-Based (IRB) model supervision, does not perform enough onsite reviews, and lacks a prescriptive framework to oversee material model changes.
- Parameters are judged mainly with reference to peers, whose models may be underestimating risks (benign historical loss data, PD erosion, point-in-time behavior of risk drivers).

### Provisioning and forbearance
- OSFI appropriately monitors changes in provisions through periodic examinations of banks’ practices for early identification and management of problem assets and the maintenance of adequate provisions and reserves.
- The main concepts of the provisioning framework should be defined in guidelines in a uniform way to increase comparability and prevent circumvention of impairment rules.
- OSFI lacks a definition of forbearance, does not define cure periods, and the granting of concessions by a bank does not generally trigger a Stage 2 presumption.
- Lifetime losses for mortgage loans (RESL) may have to be estimated during a much longer horizon (equivalent to the real payment period of the loan, irrespective of the shorter contractual maturity) to reflect likely holding period in the bank’s balance sheet.

### Concentration risk and stress testing
- OSFI’s guidelines set supervisory expectations for banks to identify, measure, evaluate, monitor, report and control concentration risk.
- The Capital Adequacy Requirements (CAR) Guideline together with the Corporate Governance Guideline establish expectations on risk limits, controls, mitigation and data aggregation.
- The Stress Testing guideline sets expectations on banks’ stress testing programs as part of enterprise-wide risk management.
- The 2019 and the 1994 guidelines on Large Exposure Limits define such limits for D-SIBs and SMSBs, respectively.

### Related party exposures
- Implementation of a related party prudential framework aligned with the BCP minimum is missing in Canada.
- Current framework is based on the concept that related party transactions are prohibited in the Bank Act; however:
  - (i) the definition of related party in the Bank Act is much narrower than in the international standard; and
  - (ii) an array of related party transactions is exempted from the prohibition, including designation of Superintendent under certain conditions.
- The framework is complex and subject to exceptions that may not be prudent.
- Banks do not report related party transactions to OSFI and OSFI does not monitor these transactions.
- OSFI does not conduct reviews specifically to control risks of transactions with related parties, aside from supervisory action triggered by issues self-reported by banks via internal documents.

### Country and transfer risk
- OSFI’s credit risk management guidelines and supervisory methodologies do not deal with country and transfer risk.
- OSFI is not assessing adequacy and effectiveness of banks’ country and transfer risk management, policies and processes.
- OSFI’s assessment criteria for CRRs do not reference country and transfer risk.
- This gap creates potential inconsistencies in risk monitoring, provisioning, and capital allocation for exposures to high-risk jurisdictions, diverging from international best practices.

### Market risk and IRRBB
- OSFI regularly assesses banks in relation to market risk and interest rate risk in the banking book (IRRBB).
- Risk management expectations are set in the Corporate Governance guideline and measurement expectations in specific guidelines.
- Market risk capital requirements apply to D-SIBs and banks with significant trading activity.
- OSFI has not conducted reviews of banks’ IRRBB models and assesses adequacy via monitoring process, allowing peer comparisons.
- Supervisory evaluation of internal capital measurement systems for IRRBB should be informed by minimum focused reviews of banks’ models and systems.

### Liquidity risk
- OSFI is at the forefront regarding liquidity risk requirements and supervisory practices, with thresholds for supervisory action closely monitored and acted upon.
- Banks are expected to use specific liquidity adequacy tools to provide a more complete picture of liquidity risks.
- Deep work on liquidity risk results in important findings and close monitoring of liquidity risk measurement and management through a well-construed proportional framework.
- Changes in banks’ liquidity risk assessments are actively reflected in banks’ ORR.

### Operational risk and resilience
- OSFI has been investing in enhancing the operational risk and operational resilience framework by issuing new guidelines and promoting supervisory processes that drive bank enhancements.
- The risk management framework is coherent with the Corporate Governance guideline and complemented by principles-based guidelines: Operational Risk and Resilience, Technology and Cyber Risk Management and Third Party Risk Management.
- Supervisory reviews of non-financial risks at individual banks, especially technology and cyber risks and business continuity, are more frequent than for other core banking areas.
- Implementation of procedures and best practices related to business disruptions and disaster recovery; identification and mapping of critical operations and systems; and understanding risks from third-party service providers, is a work in progress.

### Internal control and audit
- OSFI’s regulatory framework adequately sets expectations for banks to have effective internal control frameworks.
- Supervision frequently verifies internal control and audit in the context of reviews dedicated to specific risks.
- Some deep reviews result in relevant findings that can trigger remediation in banks.
- More bank-specific and in-depth reviews are needed to test and verify effectiveness and adherence to reported internal control and audit policies and procedures.

### Abuse of financial services / AML/CFT supervision (CP 29)
- FINTRAC lacks an effective and deterrent sanctioning framework, and its supervisory cycle is excessively long, adversely impacting frequency of compliance reviews.
- The PCMLTFA and related regulations provide a sound financial crime prevention framework, however the sanctioning framework is a weak instrument to induce compliance or punish wrongdoing.
- Amounts of current penalties are too low to serve as a deterrent or even to surpass benefits of infractions in some cases; authorities are planning to strengthen the sanctioning regime.
- The Financial Institutions unit of FINTRAC supervises all Canadian banks (35 domestic banks, 15 foreign banks and 29 foreign bank branches) and consists of 17 employees conducting assistance, monitoring, inspection and enforcement activities.
- FINTRAC is able to perform on average one thorough compliance review every 6 years at each large bank.
- FINTRAC’s salary scales and professional profiles are restricted by general rules applicable to public sector employees.

### Introduction and methodology
- This assessment of implementation of the BCP in Canada was completed as part of the Financial Sector Assessment Program (FSAP) mission undertaken by the International Monetary Fund (IMF) during October–November 2024, at the request of the Canadian authorities.
- The assessment reflects the regulatory and supervisory framework in place as of the date of completion and is not intended to represent an analysis of the state of the banking sector or the crisis management framework.
- The assessment focused on banking supervision and regulation in Canada and did not cover specificities of other financial institutions.
- Assessors reviewed laws, regulations, manuals and materials mainly provided by OSFI and held extensive meetings with OSFI officials, Finance Canada, BoC, FINTRAC, banks, external audit firms, and the Canadian Bankers’ Association.
- The assessment was performed against the Revised BCP issued by the Basel Committee on Banking Supervision in April 2024.

*Source: IMF FSAP assessment text (excerpts as provided).*

### 34.      Canada has opted to be assessed and graded against both the essential and additional

### 1canea2025007-source-pdf - 34.      Canada has opted to be assessed and graded against both the essential and additional

### Assessment methodology and compliance ratings
- Canada was assessed against both the essential and additional criteria of the BCP Methodology, which uses essential criteria (EC) and additional criteria (AC) for each Core Principle (CP).
- Assessment is qualitative, using a five-part rating system:
  - compliant
  - largely compliant
  - materially noncompliant
  - noncompliant
  - non-applicable
- Definitions and judgment standards:
  - "compliant": all essential and additional criteria are met without any significant deficiencies, including instances where the principle has been achieved by other means.
  - "largely compliant": only minor shortcomings that do not raise concerns about the authority’s ability and clear intent to achieve full compliance within a prescribed period; can be used when not all EC and AC are met but overall effectiveness is sufficiently good and no material risks are left unaddressed.
  - "materially noncompliant": severe shortcomings despite formal rules and procedures; evidence that supervision has clearly been ineffective or raises doubts about the authority’s ability to achieve compliance.
  - "noncompliant": not substantially implemented, several essential criteria not complied with, or supervision is manifestly ineffective.
  - "non-applicable": criteria do not relate to the country’s circumstances.
- The methodology is explicitly qualitative and judgment-based; the number of criteria complied with does not necessarily determine the overall compliance grade for a principle. Emphasis should be placed on the comments accompanying each principle grade rather than on the grade itself.
- Evidence of effective application of relevant laws and regulations is essential to confirm that criteria are met.

### Institutional and market structure — overview and key statistics
- Canada’s financial system characteristics:
  - "Total assets of financial institutions reached 756 percent of GDP in 2024, increasing by 43.3 percent since 2019."
  - Non-bank financial institutions (NBFI) sector share: "65 percent of financial system assets" as of 2024 — mainly mutual funds, pension funds, and insurance firms.
  - Financial sector oversight is complex, involving both federal and provincial agencies.
- Federal/provincial regulatory split and major institutions:
  - Large share of banks and insurance firms: federally regulated by OSFI.
  - Securities markets: overseen by provincial authorities.
  - Quebec’s Autorité des Marchés Financiers (AMF) supervises Desjardins (a major credit cooperative group designated a Domestic Systemically Important Financial Institution (D-SIFI) by the Québec government).
  - Federal crisis management and safety net involvement: BoC, CDIC, and others; provinces/territories have their own arrangements.
  - Systemic risk oversight: not explicitly assigned to a single body; BoC plays a leading role in systemic risk surveillance.
  - Macroprudential tools: lie with the DOF and OSFI.

### Banking system concentration, asset composition, funding, and cross-border presence
- System concentration and D-SIFI metrics:
  - "Seven D-SIFIs account for more than 90 percent of DTI assets."
  - "Canada’s six D-SIBs account for about 96 percent of banking sector assets."
  - The six D-SIBs are: Royal Bank of Canada, Toronto-Dominion Bank, Bank of Nova Scotia, Bank of Montreal, Canadian Imperial Bank of Commerce, and National Bank of Canada. Royal Bank of Canada and Toronto-Dominion Bank are also considered global systemically important banks (G-SIBs).
- Asset composition:
  - "Loans comprise roughly 50 percent of bank assets."
  - Real estate concentration in loans:
    - "residential (42 percent of loans)"
    - "commercial (11 percent of loans)"
  - Securities (mostly sovereign): "23 percent of banks’ assets."
- Funding composition and risks:
  - Funding split: "retail and commercial deposits (54 percent)" and wholesale funding instruments including repos, derivatives, covered bonds, and senior debt.
  - Wholesale funding exposure creates vulnerability to turbulence in global markets.
- Cross-border expansion:
  - Canadian banks have significantly expanded their cross-border presence in the US since 2017.

### Credit performance, capital, liquidity, and profitability
- Credit performance and delinquencies:
  - "Nonperforming Loans (NPLs) have remained low at 0.6 percent," with a recent increase driven by credit cards and auto loans of borrowers without mortgages.
  - "Mortgage delinquency rates are just 0.19 percent," below historical averages.
- Capital and liquidity metrics:
  - "CET1 ratio of 13 percent as of June 2024."
  - "Liquidity Coverage Ratios (LCRs) of the six D-SIBs in the range 126–129 percent."
- Profitability outlook:
  - Profitability has been impacted by increasing provisions for loan losses and "is likely to be affected over the medium-term by monetary policy easing."

### Preconditions for effective banking supervision
A. Sound and Sustainable Macroeconomic Policies
- Federal framework establishes clear and distinct mandates for financial sector agencies; overall responsibility rests with the Minister of Finance.
- Financial agencies have distinct tools and powers to manage systemic risks and collaborate in fora such as the Senior Advisory Committee (SAC) and the Financial Institutions Supervisory Committee (FISC).
- Financial sector statutes include sunset provisions leading to regular review and renewal every five years; unless amended, authorizing legislation lapses, creating a discipline mechanism to keep legislation up to date.
- The DOF may initiate ad hoc policy or legislative reviews for statutes not subject to sunset provisions.

B. Framework for Financial Stability Policy Formulation
- "The Minister of Finance has responsibility for protecting financial stability in Canada."
- Institutional setup for systemic risk oversight and macroprudential policy has been effective in increasing resiliency and was effective in coordinated measures addressing housing sector risks and managing COVID-19 economic shocks on the financial sector.
- Federal responsibility includes renewal of the Bank Act, the Insurance Companies Act, and the Trust and Loan Companies Act every five years.
- Federal and provincial governments share jurisdiction over financial services; under the Constitution, Government of Canada has exclusive jurisdiction over banks and banking.
- Federally incorporated institutions are prudentially regulated by OSFI; provincially incorporated institutions are regulated by relevant provincial authorities.
- Credit unions: most are provincially incorporated and regulated; federal framework (established December 2012) allows credit unions to incorporate under the Bank Act as federal credit unions.
- Credit union centrals are provincially incorporated, regulated and supervised at the provincial level.
- Securities sector: wholly regulated at provincial and territorial level through provincial/territorial securities commissions.

C. A Well-Developed Public Infrastructure
- Key federal financial institutions statutes: Bank Act, Trust and Loan Companies Act, and Insurance Companies Act govern banks, federal credit unions, and federally chartered insurance and trust and loan companies.
- Statutory review status: "The most recent review is currently ongoing, with a statutory timeline ending on June 30, 2026."
- Corporate and insolvency law framework elements include: Canada Business Corporations Act; Ontario Business Corporations Act; the federal Bankruptcy and Insolvency Act (BIA); Companies’ Creditors Arrangement Act (CCAA); Winding Up and Restructuring Act (WURA); and provincial Sale of Goods Acts for contractual law.

### Federal agencies, mandates, and coordination mechanisms
- Principal federal agencies and roles:
  - The Minister of Finance: responsible for all matters relating to the financial affairs of Canada, including overall stability of the financial system; overarching authority over federal financial sector legislation.
  - Bank of Canada (BoC): five main responsibilities—monetary policy, currency, financial system, funds management and retail payments supervision; provides liquidity; oversees key payment, clearing and settlement systems; assesses risks to overall stability.
  - OSFI: independent agency established in 1987; supervises and regulates all banks and federally regulated life and property & casualty insurers, trust and loan companies, credit unions, fraternal benefit societies, and private pension plans subject to federal oversight; reviews and monitors safety and soundness of CMHC’s commercial activities.
  - Canada Deposit Insurance Corporation (CDIC): federal deposit insurer and resolution authority for federally regulated deposit-taking institutions; Crown corporation established in 1967 by the Canada Deposit Insurance Corporation Act.
  - Financial Consumer Agency of Canada (FCAC): responsible for protecting rights and interests of consumers of financial products and services; supervises market conduct of federally regulated financial entities; promotes financial literacy and awareness of rights and responsibilities.
- Coordination and information-sharing mechanisms:
  - FISC: established in 1987, mandated in the OSFI Act to facilitate consultation and exchange of information among OSFI, CDIC, BoC, FCAC, and DOF; chaired by the Superintendent of Financial Institutions; meets at least quarterly.
  - Senior Advisory Committee (SAC): same membership as FISC, chaired by the Deputy Minister of Finance; discussion forum for financial sector policy issues; convened approximately every quarter.
  - CDIC Board of Directors: composition and responsibilities set out in CDIC Act; includes Chairperson, six independent private sector directors, and six public sector directors (including Deputy Minister of Finance, Governor of the BoC, Superintendent of Financial Institutions, Commissioner of the FCAC, and CDIC's CEO).
  - Heads of Agencies (HoA) Committee: chaired by the Governor of the BoC; includes DOF, OSFI, and four provincial Securities Regulators (OSC, AMF, ASC, BCSC); supported by the Systemic Risk Surveillance Committee (SRSC) chaired by the BoC and including CDIC, CMHC, British Columbia Financial Services Authority, and Financial Services Regulatory Authority of Ontario.
  - Canadian Securities Administrators (CSA): established a Systemic Risk Committee in October 2009 to identify and analyze systemic risks in Canadian capital markets and coordinate with other domestic regulators/agencies.

*Source: 1canea2025007-source-pdf - 34.      Canada has opted to be assessed and graded against both the essential and additional*

### 53.      Privacy and data information is protected under legislation. The Privacy Act (1983)

### 1canea2025007-source-pdf - 53. Privacy and data information is protected under legislation. The Privacy Act (1983)

### Privacy, consumer protection, and AML/CFT framework
- Privacy Act (1983)
  - Imposes obligations on federal government departments and agencies to respect privacy rights by limiting the collection, use and disclosure of personal information.
  - Gives individuals the right to access and request correction of personal information about themselves held by federal government organizations.
- Financial Consumer Protection Framework (Bank Act, 2022)
  - Applies new and enhanced protections for consumers in their dealings with banks.
  - Key elements: corporate governance accountability requirements, appropriate product and sales culture safeguards, and whistleblower protections.
  - Requires banks to provide timely information to help consumers make informed decisions (for example, electronic alerts).
  - Holds banks to higher standards for sales practices (for example, appropriate products) and resolving consumer issues (for example, more effective and timely complaints handling).
- PCMLTFA (Proceeds of Crime (Money Laundering) and Terrorist Financing Act)
  - Main legislative basis for Canada’s AML/CFT regime.
  - Establishes FINTRAC as Canada’s financial intelligence unit; FINTRAC is an independent agency reporting to the Minister of Finance and is the competent authority for AML/CFT regulation in Canada.

### Legal infrastructure and professional regulation
- Courts and judiciary
  - Courts system and legal infrastructure highly developed; independence of the judiciary is respected.
  - Constitution recognizes separation between judiciary, parliament and government; judicial independence secured through security of tenure, financial security and administrative independence.
  - Institutions fostering judicial independence include the Canadian Judicial Council, the Commissioner for Federal Judicial Affairs and the National Judicial Institute.
- Accounting and auditing standards
  - Federally regulated banks in Canada are required to use the International Financial Reporting Standards (IFRS).
  - Bank Act subsection 308(4) requires financial statements to be prepared in accordance with generally accepted accounting principles; primary source is the CPA Canada Handbook.
  - Paragraph 4 of the Preface to the CPA Canada Handbook indicates publicly accountable enterprises apply the IFRS Accounting Standards.
  - Bank Act requires financial statements to be audited in accordance with generally accepted auditing standards (GAAS); primary source is the CPA Canada Handbook.
  - Canadian Auditing Standards (GAAS in Canada) are aligned with internationally accepted standards and are based on International Standards on Auditing (ISA).
  - Audits of federally regulated financial institutions are conducted in accordance with ISAs.
  - Reporting and Assurance Standards Oversight Council (RASOC) provides oversight over Canadian accounting, auditing and sustainability boards standard setters.
- Audit oversight and accounting profession
  - Canadian Public Accountability Board (CPAB) is Canada’s public company audit regulator; CPAB is a member of the International Forum of Independent Audit Regulators.
  - Audits of entities that are not public companies are overseen by CPA provincial and regional bodies.
  - Canada’s accounting profession is regulated by CPA provincial/territorial institutes; CPA Canada supports the profession internationally via the Global Accounting Alliance and the International Federation of Accountants.
- Legal profession
  - Self-regulated by provincial/territorial law societies (example: Law Society of Ontario).

### Securities regulation, credit reporting, statistics, and payments infrastructure
- Securities regulation
  - Undertaken under provincial and territorial regulation and supervision; each province/territory has its own Securities Regulator and laws, though most regulations are harmonized.
  - Objectives generally consistent: promoting investor protection and fostering fair and efficient capital markets.
  - Discussions continue on possible creation of a common securities regulator.
  - Canadian Securities Administrators (CSA) is a voluntary umbrella organization of Securities Regulators.
    - CSA members except Ontario have developed a “passport system” using a “principal regulator” for approvals across jurisdictions for prospectus approval, discretionary exemption decisions and registration.
- Credit bureaus
  - Provincially regulated; required to maintain accurate and up-to-date records and to permit consumers access to their credit file.
- Statistics Canada
  - Legislated to produce statistics on population, resources, economy, society and culture at provincial, territorial and federal level.
- Payment clearing and settlement infrastructure
  - Subject to regulation and oversight by the Minister of Finance, the Bank of Canada (BoC), and provincial securities commissions (collectively, the CSA).
  - Minister of Finance has oversight powers respecting the Canadian Payments Association and payments systems under the Canadian Payments Act.
  - Systems identified: Automated Clearing and Settlement System (national retail payment system) and Lynx (Canada’s high-value payment system).
  - Under the Payment Clearing and Settlement Act, the BoC can identify and, subject to Minister of Finance approval, designate systems as systemically important or prominent, bringing them under Bank oversight.
  - BoC is resolution authority for domestic designated clearing and settlement systems.
  - Under the Retail Payment Activities Act:
    - BoC responsible for registering and supervising payment service providers who carry on retail payments activities in Canada.
    - Registration came into force on November 1, 2024, and supervisory requirements will come into force in September 2025.

### Crisis management, recovery, and resolution framework
- Federal supervisory and intervention regime
  - Key agencies: OSFI (prudential regulator), BoC (liquidity provider), CDIC (resolution authority for federally regulated DTIs), FCAC (financial consumer information), and DOF (advice to Minister of Finance concerning resolution tools).
  - Agencies meet regularly through the FISC and the CDIC Board to share information and consult on supervision and use of resolution tools.
- OSFI powers
  - Supervisory Framework and Guides to Intervention designed to support mandate to contribute to public confidence.
  - Powers include: take control of an institution and/or its assets, remove directors and senior management, enter into prudential agreements, issue orders regarding asset maintenance and issue directions of compliance.
- Bank of Canada emergency lending
  - BoC can provide Emergency Lending Assistance (ELA) to eligible financial institutions and financial market infrastructures at its discretion.
  - Eligibility criteria for federally regulated institutions include Payments Canada membership and credible recovery and resolution framework.
  - ELA lending may be against broader collateral than typical operations and is subject to a maximum term-to-maturity of six months; loans can be renewed as often as the BoC deems appropriate.
  - BoC can also provide loans under the Standing Term Liquidity Facility to eligible financial institutions in need of temporary liquidity support if the Bank has no concerns about the institution’s financial soundness.
- Canada Deposit Insurance Corporation (CDIC)
  - Deposit insurer and resolution authority for CDIC-member financial institutions.
  - Statutory mandate: provide deposit insurance, resolve member institutions in the event they fail, and promote and contribute to financial stability while minimizing the Corporation’s exposure to loss.
  - Resolution tools: liquidation and payout; agency agreement; assisted transaction; forced sale (share or asset); open bank assistance (ranging from a onetime, finite loan to a blanket guarantee); bridge bank arrangements.
  - For D-SIBs, CDIC has Enhanced Financial Institution Restructuring Powers enabling it to take control, restructure, and/or effect a “bail-in” by converting certain debt instruments into common shares.
  - Canada’s largest banks required to develop recovery and resolution plans; CDIC has developed resolution plans for some smaller and medium sized banks.
- FCAC role in crises
  - Coordinates with federal financial safety net partners and provides authoritative, unbiased, and reliable information to stakeholders and consumers in a timely manner.
  - Works with federal partners in dealing with a troubled institution.

### Systemic protection, coordination, and market discipline
- Systemic Advisory Committee (SAC)
  - Monitors and advises on macroprudential oversight matters and system-wide crisis prevention measures.
  - Composition: OSFI, DOF, BoC, CDIC, and FCAC.
  - Chaired by the Deputy Minister of Finance, who advises the Minister of Finance; convenes approximately every quarter and more often when needed.
  - Provides advice to the Minister of Finance on financial stability and macroprudential issues and informs agencies of potential systemic risks.
- OSFI–CDIC coordination
  - OSFI and CDIC have a Strategic Alliance Agreement to coordinate activities, promote consultation and facilitate exchange of information.
- Market discipline arrangements
  - Corporate governance requirements for financial institutions set out in federal and provincial statutes (e.g., Bank Act): board structure, director qualifications, minimum number of independent directors.
  - Securities laws require disclosure of governance arrangements; institutional investors actively monitor governance at public corporations.
  - Toronto Stock Exchange sets governance and disclosure requirements as conditions of listing.
  - Banks expected to comply with BCBS Pillar 3 requirements.
  - D-SIBs expected to adopt Financial Stability Board’s Enhanced Disclosure Task Force (EDTF) recommendations and evolving risk disclosure best practices.
  - OSFI publishes institution-specific data on its website, including balance sheet and income statement data, capital and derivative components, and premiums written, among other financial information, for various federally regulated financial institutions.

### Detailed assessment — Supervisory framework overview (Principle 1; EC1)
- Principle 1: Responsibilities, Objectives, and Powers
  - Effective system of banking supervision requires clear responsibilities and objectives for each authority, and suitable legal framework to provide necessary powers to authorize banks, conduct ongoing supervision, address compliance and undertake timely corrective actions.
- Essential Criterion EC1
  - EC1 text: The responsibilities and objectives of each of the authorities involved in banking supervision are clearly defined in legislation and publicly disclosed. Where more than one authority is responsible for supervising the banking system, a credible and publicly available framework is in place to avoid regulatory and supervisory gaps.
- Findings related to EC1
  - Office of the Superintendent of Financial Institutions (OSFI)
    - Division of federal public administration entrusted with supervision of federally regulated financial institutions (all banks, federally regulated life and property and casualty insurers, trust and loan companies, cooperative credit associations, fraternal benefit societies and private pension plans subject to federal oversight; see OSFI Act, Section 4).
    - OSFI is an integrated prudential supervisor overseeing more than 400 financial institutions and 1200 pension plans.
  - Provincial supervisors license and supervise certain non-bank deposit-taking institutions, including credit unions, trust companies and loan companies incorporated under and subject to provincial laws.
  - For the Detailed Assessment Report, “bank” or “banks” may refer to any deposit-taking institution regulated by OSFI (banks, foreign banks and other federally regulated deposit-taking institutions such as trust companies, loan companies and cooperative credit associations / credit unions).
  - OSFI is a separate agency of the Government of Canada with independent status as an employer and is listed under Financial Administration Act (FAA), Schedule V and the OSFI Act.

*Italicized source attribution line.*

### Section 13) subject to the authority and the responsibility of the Minister of Finance.

### Section 13) subject to the authority and the responsibility of the Minister of Finance.

### Legal framework and OSFI’s statutory remit
- The Office of the Superintendent of Financial Institutions Act (“OSFI Act”) constitutes OSFI, defines its goals, and establishes its powers and duties (including enforcement and sanctioning powers).
- The Bank Act (“BA”) also confers powers and duties on OSFI (see OSFI Act, Section 6) and the Minister of Finance, and sets the main legal framework for banks to be developed through regulations (issued by the Governor in Council on advice from the Minister of Finance) and guidelines (issued by OSFI).
- OSFI Act, Section 3.1: purpose of the OSFI Act is “to ensure that ‘financial institutions are regulated by an office of the Government of Canada so as to contribute to public confidence in the Canadian financial system.’”
- OSFI Act, Subsection 4(2) sets out OSFI’s objects:
  - (a) to supervise financial institutions to determine whether they are in sound financial condition and are complying with their governing statute law and supervisory requirements under that law;
  - (a.1) to supervise financial institutions to determine whether they have adequate policies and procedures to protect themselves against threats to their integrity or security, including foreign interference;
  - (b) to promptly advise management and the board when an institution is not in sound financial condition or not complying with governing statute law or supervisory requirements and to take or require corrective measures without delay;
  - (b.1) to promptly advise management and the board when an institution does not have adequate policies and procedures to protect itself against threats to its integrity or security and to take or require corrective measures without delay;
  - (c) to promote the adoption by management and boards of policies and procedures designed to control and manage risk;
  - (d) to monitor and evaluate system-wide or sectoral events or issues that may have a negative impact on the financial condition of financial institutions.
- OSFI Act, Subsection 4(3), point (a): in pursuing its objects, “the Office shall strive in respect of financial institutions, to protect the rights and interests of depositors, policyholders and creditors of financial institutions, having due regard to the need to allow financial institutions to compete effectively and take reasonable risks.”

### OSFI’s mandate: breadth, ambiguity, and internal policy
- The statutory purpose “to contribute to public confidence in the Canadian financial system” is wide and can encompass multiple objectives, including safety and soundness but also other public policy goals depending on political will.
- OSFI’s new integrity and security / preventing foreign interference mandate (OSFI Act, Subsection 4(2), points (a.1) and (b.1)) and “the need to allow financial institutions to compete effectively” are on equal footing with safety-and-soundness-related functions in the statutory text.
- OSFI internally treats safety-and-soundness and competition as a “dual mandate,” and internal policy gives significant weight to competition considerations alongside depositor protection. This dual mandate may:
  - delay appropriate action and hamper early intervention and proactive supervision;
  - serve in court review as a legal criterion that could constrain ex ante discretion.
- The assessors judge the current risk that other public policy goals will subordinate safety-and-soundness as low, noting that OSFI does not enforce consumer-oriented provisions (these are entrusted to FCAC), but warn that future policy shifts could change that balance.

### Strategic documents, risk appetite, and mandate evolution
- The document A Blueprint for OSFI’s Transformation 2022 – 2025 (basis for the 2022-2025 Strategic Plan) framed a shift to “place greater emphasis on contributing to public confidence in the Canadian financial system,” describing a change in how the mandate is used and making public confidence “the key driver of all we do.”
- The Blueprint emphasized the need for a consistent and accepted risk appetite framework (RAF) across OSFI to:
  - identify priorities;
  - evaluate trade-offs between different priorities; and
  - understand strategic investments necessary for prioritized risks.
- The Blueprint stated: “We need a more rigorous and future focused RAF. Such a framework will enable a risk-led approach to priority setting and support greater consistency and rigor in selecting strategic priorities and related resource allocations.”
- Relevant strategic updates:
  - The 2022-2025 Strategic Plan is no longer in force; it was replaced with the 2024-2027 Strategic Plan.
  - OSFI issued the Integrity and Security Guideline in January 2024.
  - OSFI’s Strategic Plan for 2024–27 lists the integrity and security expanded mandate as priority number one and sets the goal for having tools, systems, authorities, and infrastructure to support its role related to integrity, security and national security.
  - A National Security Sector, outside of Supervision, with 40 staff and an “Intelligence Division,” has been established at OSFI.

### Integrity, security, and foreign interference: scope and concerns
- Integrity and security definitions in OSFI’s guidance:
  - “Security” includes “protection against malicious or unintentional internal and external threats to real property, infrastructure, and personnel, and to technology assets,” aligning with operational risk from external events.
  - “Integrity” includes “actions, behaviors, and decisions consistent with the letter and intent of regulatory expectations, laws, and codes of conduct,” relating to legal risk, operational risk, and corporate governance.
  - “Foreign interference” is defined to include clandestine, deceptive, or coercive activities within or relating to Canada detrimental to Canada’s interests and security, including attempts to covertly influence, intimidate, manipulate, interfere, corrupt, or discredit individuals, organizations, and governments to further foreign interests.
- The assessors note potential problems:
  - The foreign interference definition is broad; while abuse of a bank for such purposes may jeopardize prudential condition, prudential supervisors are not part of national security architecture.
  - Clarity of roles and responsibilities among authorities is vitally important to avoid role confusion and overlap (similar to AML/CFT spheres).
  - The specific emphasis on the integrity and security mandate creates a risk of distraction from core prudential safety-and-soundness work; greater clarity and specification is needed, and the integrity/security objective should clearly support safety and soundness.

### Coordination with other federal authorities
- OSFI is the sole federal agency responsible for prudential supervision of banks and federal trust and loan companies, and it collaborates with other federal bodies accountable to Parliament through the Minister of Finance, including:
  - The Minister of Finance / DOF: responsibility for financial affairs of Canada and overall stability of the financial system; overarching authority over federal financial sector legislation.
  - The Canada Deposit Insurance Corporation (CDIC): federal deposit insurer and resolution authority for federally regulated deposit-taking institutions; provides deposit insurance against loss of eligible deposits.
  - The Bank of Canada (BoC): main responsibilities include monetary policy, currency, financial system, and funds management; a fifth area, administering the Retail Payment Activities Act, was introduced in November 2024. The Bank provides liquidity; oversees key domestic payment, clearing and settlement systems; participates in development of financial system policies; and assesses risks to overall financial stability.
  - The Financial Consumer Agency of Canada (FCAC): federal regulatory body to protect and inform consumers; primary responsibility is ensuring market conduct compliance of federally regulated financial entities with federal legislation and regulations.
- Federal coordination mechanisms:
  - The Financial Institutions Supervisory Committee (FISC): constituted under the OSFI Act; members are expressly identified in legislation; chairs: Superintendent of Financial Institutions; meets at least quarterly. FISC facilitates consultation and exchange of information among OSFI, CDIC, BoC, FCAC, and DOF, and coordinates responses to problem financial institutions and emerging issues.
  - The Senior Advisory Committee (SAC): chaired by the Deputy Minister of Finance with participation from the same agencies as FISC; acts as a forum for financial sector policy issues to inform advice to the Minister of Finance.
  - The CDIC Board of Directors: composition and responsibilities set out in the CDIC Act; board includes a Chair, six independent private sector directors, and six public sector directors (including the Deputy Minister of Finance, the Governor of the BoC, the Superintendent of Financial Institutions, a deputy Superintendent or officer of OSFI, and the Commissioner of the FCAC); directors must act in the best interests of the Corporation and Canadians and exercise care, diligence and skill pursuant to the FAA.
  - The Heads of Agencies (HoA) Committee: chaired by the Governor of the BoC and includes DOF, OSFI, and four provincial Securities Regulators (OSC, AMF, ASC, BCSC); allows federal and provincial securities market regulators to exchange information and coordinate on mutual concerns.
- Assessors note federal–provincial cooperation mechanisms in banking supervision are less institutionalized, creating deficiencies in articulating a system-wide view and opportunities for regulatory arbitrage, although legislative frameworks do not allow supervisory gaps and distribution of responsibilities is clear.

### EC2 — Primary objective of banking supervision: findings and recommendations
- Findings:
  - The BA allows the Minister and Superintendent to take into account broader public policy matters when granting approvals, including national security and Canada’s international relations (BA, section 973.01(1) and subparagraphs).
  - The Blueprint and strategic documents show a shift toward prioritizing public confidence as the driver of OSFI’s actions, which may alter how OSFI balances objectives.
  - The assessors consider the present risk of conflict that subordinate safety-and-soundness to other objectives to be low, but highlight the potential for change.
  - The new integrity and security mandate potentially extends beyond traditional safety-and-soundness objectives and raises the need for clearer role delineation with national security bodies.
- Recommendation (implicit in findings):
  - The assessors conclude that legislation should enshrine clearly in the OSFI Act that the primary goal of OSFI’s banking supervision is the safety and soundness of banks and the financial system, ensuring broader responsibilities and public policy goals are subordinate and do not conflict with that primary objective.

### EC3 — Framework for setting and enforcing prudential standards: description and findings
- Legal framework:
  - The BA, Trust and Loan Companies Act (TLCA) and supporting regulations provide the framework for setting and enforcing minimum prudential standards (ownership, governance, capital, liquidity, self-dealing, investments, borrowing).
- OSFI guidance instruments (non-legally binding but supported by statutory and intervention powers):
  - Guidelines: set OSFI expectations on solvency and prudence (capital adequacy, liquidity, corporate governance, large exposure limits).
  - Legislative Advisories: clarify OSFI’s position on policy issues or how provisions of BA and TLCA are administered/interpreted; entities are expected to consider their relevance.
  - Rulings:
    - Legislative rulings: based on specific fact situations; a bank applies; anonymized versions can be made public.
    - Capital rulings: opinions on computability of capital instruments.
  - Regulatory notices: introduced in 2024 as interim guidance to adopt best practices in response to evolving risks; OSFI does not consult on them; provisional and may be rescinded or substituted by formal guidelines.
  - Quarterly release pilot: within the Annual Risk Outlook (ARO) OSFI publishes quarterly releases to give stakeholders visibility on supervisory expectations (recent examples indicate expectations regarding mortgage switching activity).
- Enforcement:
  - OSFI’s objects require supervision to determine compliance and to advise and require corrective measures where necessary.
  - For less-than-compliant entities OSFI initially uses tools such as Supervisory Letters and discussions with management and boards (recommendations, not legally binding).
  - The BA and TLCA provide the Superintendent with enforcement powers to use when solvency/prudential standards are not met or when integrity/security policies are inadequate.
  - Non-compliance with BA and TLCA is an offence that may attract criminal sanctions and civil monetary penalties under the Administrative Monetary Penalties (OSFI) Regulations.
  - Enforcement of restrictions and directions of compliance can be pursued through courts if necessary.
- Capital framework and discretion:
  - OSFI’s minimum capital requirements are set in the Capital Adequacy Requirements Guideline (“CAR Guidelines”) and the Leverage Ratio Guidelines.
  - Legislation requires banks to hold “adequate capital” (subsections 485(1) and 949(1) BA and subsection 473(1) TLCA).
  - BA subsections 485(3) and 949(3) for bank holding companies empower the Superintendent to, by order, direct a bank
    - (a) to increase its capital; or
    - (b) to provide additional liquidity in such forms and amounts as the Superintendent may require.
  - OSFI operationalizes these powers through a Pillar 2 framework set out in OSFI’s Internal Capital Adequacy Assessment Process (ICAAP) Guideline to address idiosyncratic risks not captured under Pillar 1.
  - OSFI evaluates capital adequacy and capital management on a continuous basis; from incorporation a bank becomes subject to regulatory minimums and to more onerous supervisory targets.

*Source: CANADA — INTERNATIONAL MONETARY FUND (excerpt).*

### Chapter 1 of the CAR Guideline:

### Chapter 1 of the CAR Guideline

### Capital targets, buffers, and supervisory intervention
- OSFI expects all institutions to maintain target capital ratios equal to or greater than the minimum capital ratios plus the conservation buffer.
- For SMSBs, target ratios are:
  - 7% for CET1
  - 8.5% for Tier 1
  - 10.5% for Total capital
- For D-SIBs, target ratios are equal to or greater than the minimum capital ratios plus the sum of the conservation buffer, the D-SIB surcharge and the DSB. For D-SIBs, this equates to target ratios of least:
  - 8% for CET1
  - 9.5% for Tier 1
  - 11.5% for Total capital plus the DSB
- These targets are triggers for supervisory intervention consistent with OSFI’s Guide to Intervention:
  - If an institution is offside the relevant target ratios, supervisory action will be taken proportional to the shortfall and circumstances that caused the shortfall and may include a range of actions, including, but not limited to, restrictions on distributions.
- The Superintendent may set higher target capital ratios for individual institutions or groups where circumstances warrant, including idiosyncratic and/or systemic risks not adequately captured by Pillar I requirements and buffers.
  - The need for Pillar II capital and corresponding higher target capital ratios would consider allowances, stress testing program, and ICAAP results.
- OSFI can apply supervisory Pillar 2 add-ons (i.e., buffers) to increase a bank’s risk-based and/or leverage supervisory targets for reasons including:
  - an increase in supervisory expectations,
  - an incurred or expected loss,
  - a macroeconomic vulnerability,
  - an erosion of controls or lapse in governance.
- Where a bank becomes subject to a supervisory adjustment to its capital targets, OSFI would convey the change via a formal letter and a meeting with senior management and, where appropriate, its Board of Directors.

### Domestic Stability Buffer (DSB) adjustments
- D-SIBs are subject to adjustments to their capital targets through changes to the Domestic Stability Buffer (DSB).
- The DSB is subject to adjustment twice per year, in June and December, based on OSFI’s views of macroeconomic vulnerabilities and risks.
- Changes to the DSB with supporting rationale are announced publicly through a published letter to the industry and briefings for the media and analysts.

### Legislative review mechanism and “sunset” provisions
- Canada has an automatic review mechanism on basic banking laws to ensure they remain effective and relevant.
- Section 21 of the BA and Section 20(1) of the TLCA contain a “sunset” clause resulting in a review of the statute every five years or so.
- Excerpt of the sunset provision:
  - "21 (1) Subject to subsections (2) and (4), banks shall not carry on business, and authorized foreign banks shall not carry on business in Canada, after June 30, 2026.
  - Extension
  - (2) The Governor in Council may, by order, extend by up to six months the time during which banks may continue to carry on business and authorized foreign banks may continue to carry on business in Canada. No more than one order may be made under this subsection.
  - Order not a regulation
  - (3) The order is not a regulation for the purposes of the Statutory Instruments Act. However, it shall be published in Part II of the Canada Gazette.
  - Exception—dissolution
  - (4) If Parliament dissolves on the day set out in subsection (1) or on any day within the six-month period before that day or on any day within an extension ordered under subsection (2), banks may continue to carry on business, and authorized foreign banks may continue to carry on business in Canada, until the end of the 180th day after the first day of the first session of the next Parliament."
- Since enactment in 1992, the BA and TLCA underwent “sunset” reviews in 1997, 1999, 2001, 2007, 2012, and 2018–19.
- The current “sunset” review consultations commenced:
  - First consultation: October 2023
  - Second consultation: December 2023
- Two primary focuses of the latest review: uphold the integrity of Canada’s financial sector and increase competition in the financial sector.
- OSFI is involved in this process and often consults directly with stakeholders, given OSFI’s dual role as (1) a prudential supervisor and (2) administrator of all provisions of these statutes except for consumer provisions.
- Legislative amendments may also be made more regularly through the federal government’s annual budget implementation legislation.

### Regulatory development, OSFI guidance, and stakeholder consultation
- Administrative regulations (“statutory instruments” or “regulations”) under the BA and TLCA may be proposed at any time through a “Governor-in-Council” process; this requires public consultations including publication of draft amendments for public review and comments.
- OSFI’s guidance is non-binding and not a statutory instrument; amendment does not require a “Governor-in-Council” process.
- Most prudential standards (capital, governance, liquidity, risk management) take the form of OSFI’s guidance.
- When updating or developing guidance, OSFI carries out formal public consultations:
  - Consultation papers and/or draft versions are posted for comments on OSFI’s website.
  - A summary of industry’s comments and OSFI’s responses are published on OSFI’s website concurrent with final guidance.
  - Recent examples of public consultations include guidelines on Capital Adequacy Requirements, Mortgage Underwriting and Corporate Governance.
- OSFI is piloting a new approach to release regulatory guidance (Quarterly Releases):
  - OSFI will release regulatory guidance on one day of each quarter, including a media briefing and a high-level stakeholder briefing.
  - The first of these events took place on August 22, 2024.
  - A virtual industry day will be held two weeks later for stakeholder questions and comments.
  - Goal: make OSFI’s work more predictable and transparent.
- OSFI’s Policy Development and Standards Division monitors status of guidelines, discusses potential changes, and oversees effectiveness reviews of older and recently issued guidelines.
- Legislation and regulations are published in the Canada Gazette and available on the Department of Justice webpage. OSFI’s portal contains applicable legislation and regulation; OSFI’s guidance is published on OSFI’s webpage with a search engine.

### Supervisory powers, access, and consolidated supervision
- Supervision is conducted on a consolidated basis, assessing all material entities (subsidiaries, branches, joint ventures) domestically and internationally.
- Legal authorities enabling access and examination include:
  - Subsection 628(1) of the BA and section 495 of the TLCA — require banks and trust and loan companies to provide the Superintendent with such information, at such times and in such form as the Superintendent may require (ad hoc requests and regular reporting).
  - Subsection 643(1) of the BA and subsection 505(1) of the TLCA — provide the Superintendent with powers of examination and inquiry into the business and affairs of the bank or trust or loan company.
    - Excerpt: "643 (1) The Superintendent, from time to time, but at least once in each calendar year, shall make or cause to be made any examination and inquiry into the business and affairs of each bank that the Superintendent considers to be necessary or expedient ... After the conclusion of each examination and inquiry, the Superintendent shall report on it to the Minister."
  - Subsection 643(2) of the BA and subsection 505(2) of the TLCA — provide the Superintendent (or a person acting under the Superintendent's direction) access to records, cash, assets and security held by a bank and may require directors, officers and the auditor to provide information and explanations.
    - Excerpt: "(2) The Superintendent or a person acting under the Superintendent’s direction (a) Has a right of access to any records, cash, assets and security held by or on behalf of a bank; and (b) May require the directors, officers and the auditor or auditors of a bank to provide information and explanations, to the extent that they are reasonably able to do so, in respect of the condition and affairs of the bank or any entity in which the bank has a substantial investment."
  - Section 644 of the BA and section 506 of the TLCA — provide the Superintendent (or a person acting under the Superintendent's direction) with all powers of a commissioner under Part II of the Inquiries Act for obtaining evidence under oath, including:
    - enter and remain within any public office or institution and access every part thereof;
    - examine all papers, documents, vouchers, records and books;
    - summon persons to give evidence orally or in writing and on oath;
    - administer the oath or affirmation;
    - issue subpoenas or summonses to appear, testify, and produce documents;
    - issue commissions authorizing officers to take evidence in lieu of attendance.
- For the purpose of “access,” supervisory access includes in person to the bank’s premises, and to senior executive staff and the board (both individual members and as a whole) in person or virtually as needed.
- Section 635 of the BA and subsection 502(1) of the TLCA allow the Superintendent to direct a person who controls a bank or affiliated entity to provide necessary information to satisfy the Superintendent on sound financial condition and compliance.
- Subsection 22(2) of the OSFI Act authorizes the Superintendent to enter into agreements with foreign regulators to share information; OSFI usually enters into Memoranda of Understanding (MoUs) for confidential information sharing.

### Third-party arrangements and record location requirements
- OSFI’s Third-Party Risk Management Guideline expects institutions to provide OSFI, upon request, information related to business and strategic arrangements with third parties, risk management, and control environments.
  - Institutions are expected to promptly notify OSFI of substantive issues affecting the ability to deliver critical operations due to a third-party arrangement.
  - Third-party agreements are expected to establish availability of records and timely access to data by the financial institution and OSFI, upon request.
- Amendments following the Canada-United States-Mexico Agreement (ratified in 2020 and included in Schedule IV of the BA) changed prior requirements to maintain certain records in Canada:
  - Institutions that are subsidiaries of certain foreign financial institutions can be exempted from the requirement to maintain copies of certain records at a location in Canada, but the Superintendent may order them to maintain such copies if the Superintendent is of the opinion they do not have immediate, direct, complete and ongoing access to those records.
  - The Superintendent must also order an exempted institution to maintain copies in Canada if advised by the Minister of Finance that it is not in the national interest for the institution not to do so.
  - Under the Administrative Monetary Penalties (OSFI) Regulations, the Superintendent may impose a monetary penalty for failure to comply without delay with such an order.
- These authorities underpin OSFI’s supervisory and risk assessment processes and are relied on heavily for day-to-day functions: gather information, prepare and perform on-site examinations, and meet with management teams and boards.

*Source: Chapter 1 of the CAR Guideline (source PDF).*

### conclusion that moral suasion is the preferred approach at OSFI, and the formal use of

### 1canea2025007-source-pdf - conclusion that moral suasion is the preferred approach at OSFI, and the formal use of

### Enforcement approach and general principle
- Moral suasion is the preferred approach at OSFI; formal use of statutory powers is regarded as an ultima ratio instrument and is used only if all other possibilities fail.
- The BA and TLCA provide the Superintendent with enforcement powers for failures in solvency, prudential standards, integrity, or security policies and procedures.

### Available enforcement tools (overview)
- Special examinations
- Prudential agreements
- Capital orders
- Directions of compliance
- Taking control of the bank or trust or loan company
- Non-compliance with BA and TLCA can attract criminal sanctions (see Part XVII of the BA) and civil monetary penalties under the Administrative Monetary Penalties (OSFI) Regulations.
- Enforcement of restrictions and directions of compliance can be pursued through the courts.

### Explicit statutory authorities (selected sections and powers)
- Section 54 of the BA and section 58 of the TLCA – power to impose conditions or limitations, or vary existing conditions, on an institution’s Order to Commence and Carry on Business.
- Section 325 of the BA and section 330 of the TLCA – authority to require the institution's external auditor to enlarge the scope of the review of the financial statements and/or to perform other procedures and prepare a report thereon.
- Section 480 of the BA and section 468 of the TLCA – authority to order divestiture of loans, investments or subsidiaries acquired in contravention of Part IX of the BA.
- Section 485 of the BA and section 473 of the TLCA – authority to issue an order to direct the institution to increase its capital or provide additional liquidity.
- Section 644.1 of the BA and section 506.1 of the TLCA – authority to enter into a Prudential Agreement to maintain or improve safety and soundness.
- Section 645 of the BA and section 507 of the TLCA – authority to issue a Direction of Compliance to cease or prevent an unsafe or unsound practice.
- Section 646 of the BA and section 509 of the TLCA – authority to apply for a court order requiring compliance with a prudential agreement or Direction of Compliance, or to cease contravention of the BA.
- Sections 647 and 647.1 of the BA and section 509.2 of the TLCA – authority to disqualify or remove a person from office, such as a director or senior officer, in certain circumstances.
- Sections 648 to 656 of the BA – Superintendent’s role in deciding when (for example, determination of non-viability) and how to effect the orderly resolution of a problem bank or trust or loan company, including assuming control of assets, assuming control of the institution, and seeking a winding-up order.
- For transaction or control-related approvals under the BA or TLCA (see CP6 and CP7): the Superintendent or Minister may deny requested approval in control; approve transactions subject to terms and conditions; or require an undertaking from an unregulated parent (for control-related approvals).
- Part XV of the BA grants similar powers with regard to bank holding companies.
- Section 973.03 of the BA and subsection 527.2(7) of the TLCA – authority for the Minister and Superintendent to revoke, suspend or amend any approval, including issuance of letters patent and the order to commence and carry on business.

### Triggering resolution and measures on non-viability
- The joint OSFI-CDIC Guide to Intervention identifies OSFI activities including communicating to management and the board the importance of considering resolution options such as restructuring or seeking a prospective purchaser.
- When the Superintendent determines “non-viability/insolvency imminent,” potential actions include:
  - Assuming temporary control of the assets (16 days) of the institution and the assets under its administration;
  - Taking control of the institution’s assets or taking control of the institution for a period exceeding 16 days if there is not advice on the contrary by the Minister of Finance;
  - Requesting that the Attorney General of Canada apply for a winding-up order under the Winding-up and Restructuring Act in respect of the institution, where the assets of the institution are under the control of the Superintendent or the bank is under the Superintendent’s control.
- Subsection 648(1.1) BA — “Circumstances for taking control” (text preserved verbatim):
  - (1.1) Control by the Superintendent under subsection (1) may be taken in respect of a bank where
    - (a) The bank has failed to pay its liabilities or, in the opinion of the Superintendent, will not be able to pay its liabilities as they become due and payable;
    - (b) [Repealed, 2001, c. 9, s. 182]
    - (c) The assets of the bank are not, in the opinion of the Superintendent, sufficient to give adequate protection to the bank’s depositors and creditors;
    - (d) Any asset appearing on the books or records of the bank or held under its administration is not, in the opinion of the Superintendent, satisfactorily accounted for;
    - (e) The regulatory capital of the bank has, in the opinion of the Superintendent, reached a level or is eroding in a manner that may detrimentally affect its depositors or creditors;
    - (f) The bank has failed to comply with an order of the Superintendent under paragraph 485(3)(a);
    - (g) The bank’s deposit insurance has been terminated by the Canada Deposit Insurance Corporation.
    - (g.1) In the opinion of the Superintendent, the bank’s depositors and creditors may be detrimentally affected because all of the common shares or membership shares of the bank must be disposed of under a direction made by the Minister or because there is a prohibition under this Act in respect of the exercise of the right to vote attached to all of the common shares or membership shares of the bank;
    - (h) In the opinion of the Superintendent, any other state of affairs exists in respect of the bank that may be materially prejudicial to the interests of the bank’s depositors or creditors or the owners of any assets under the bank’s administration, including where proceedings under a law relating to bankruptcy or insolvency have been commenced in Canada or elsewhere in respect of the holding body corporate of the bank;
    - (i) In the opinion of the Superintendent, the continued operation of the bank by the directors of the bank or by the officers of the bank responsible for its management would be materially prejudicial to its integrity or security; or
    - (j) In the opinion of the Superintendent, the continued operation of the bank by the directors of the bank or by the officers of the bank responsible for its management would pose a risk to national security.
- The Minister of Finance may direct the Superintendent to take intervention measures for reasons of national security according to Subsection 648(1.11) BA.
- In practice, resolution decisions are discussed at FISC (see EC1), a committee chaired by OSFI with members from CDIC, the BoC, FCAC, and the DOF.
- CDIC powers linked to Superintendent’s determination of non-viability include:
  - Sections 39.1 to 39.37 of the CDIC Act – restructuring the financial institution pursuant to the Financial Institution Restructuring Provisions;
  - Sections 39.371 to 39.3723 of the CDIC Act – establishing a bridge bank to preserve critical bank functions and help maintain financial stability;
  - Section 39.2 (2.3) of the CDIC Act – to carry out a conversion (“bail-in”) of a SIB to preserve critical bank functions and help maintain financial stability.

### Cross-border cooperation and information access
- Subsection 22(2) of the OSFI Act provides that the Superintendent can enter into MoUs with foreign regulators to assist with orderly resolution of a bank or trust or loan company.
- Other tools for internationally active banks include supervisory colleges and crisis-management groups.
- EC7: The supervisor has the power to review activities of parent companies and of companies affiliated with parent companies to determine their impact on the safety and soundness of the bank.
- The supervisor has access, whether directly or through the supervised bank, to all necessary information for conducting such a review irrespective of where it is available.

### Ownership rules and major shareholder thresholds (relevant to EC7)
- Canadian ownership rules require that certain domestic banks (including those with an equity of CAD 12 billion or more, see section 375 BA) be “widely held,” notably the seven largest domestic banks in Canada.
- Sections 2.2 and 2.3, BA define “Major shareholder” (text preserved verbatim):
  - 2.2 For the purposes of this Act, a person is a major shareholder of a body corporate if
    - (a) the aggregate of the shares of any class of voting shares of the body corporate that are beneficially owned by the person and that are beneficially owned by any entities controlled by the person is more than 20 per cent of the outstanding shares of that class of voting shares of the body corporate; or
    - (b) the aggregate of the shares of any class of non-voting shares of the body corporate that are beneficially owned by the person and that are beneficially owned by any entities controlled by the person is more than 30 per cent of the outstanding shares of that class of non-voting shares of the body corporate.

*Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf*

### 2.3 For the purposes of this Act, an entity is widely held if it is

### 2.3 For the purposes of this Act, an entity is widely held if it is 

### Definition of "widely held"
- (a) a body corporate that has no major shareholder;  
- (a.1) a federal credit union;  
- (b) an insurance company incorporated or formed under a mutual plan;  
- (c) an association to which the Cooperative Credit Associations Act applies; or  
- (d) a cooperative credit society incorporated or formed, and regulated, by or under an Act of the legislature of a province.

### OSFI’s consolidated approach to supervision and scope
- OSFI’s consolidated approach focuses primarily on assessment of the federally regulated financial institution (the bank or the trust or loan company) and its subsidiaries (see CP12).  
- For banks with major shareholders (generally Small and Medium-sized Banks, “SMSB,” i.e., those below CAD 12 billion in equity that are not subject to the “widely held” requirement of the bank act, see CP6), OSFI’s risk assessment also considers activities of parent companies and affiliates where they exist and their impact on the regulated institution.  
- OSFI’s supervision of parent and affiliate activities is not performed on a regular basis (see CP12); OSFI focuses on parent/affiliate activities when an approval process is triggered, including:  
  - During review of an application for incorporation, where pursuant to section 27 of the BA and section 26 of the TLCA OSFI reviews the financial resources of the applicant and the extent to which the proposed corporate structure of the applicant and their affiliates may affect supervision and regulation, having regard to:  
    - The nature and extent of the proposed financial services activities to be carried out by the institution and its affiliates; and  
    - The nature and degree of supervision and regulation applying to the proposed financial services activities to be carried out by the affiliates of the institution.  
  - For other significant transactions, such as amalgamations and acquisitions of significant interest, OSFI considers the ability to adequately supervise entities.

### Use of undertakings, information powers and international cooperation
- OSFI may secure undertakings from group entities, including parent companies, to address prudential or supervisory matters of concern; OSFI regularly obtains undertakings from a parent entity that is not a regulated entity.  
- Undertakings are intended to provide OSFI with access to parental data and information, as needed.  
- Apart from undertakings (that are not required in all cases, nor prescribed by law), OSFI may use production of information and documents powers:  
  - subsection 635(1) of the BA; and  
  - subsection 502(1) of the TLCA.  
  - These empower the Superintendent to order a person who controls an institution or any affiliated entity to provide information or documents where the Superintendent believes production is necessary to be satisfied that the provisions of the BA or TLCA are being duly observed, that the institution is in sound financial condition or that it has adequate policies and procedures to protect itself against threats to its integrity or security.  
- OSFI has more than 30 information sharing and cooperation arrangements MoUs in place with foreign regulators that may be used to obtain information on foreign parents and affiliates of Canadian banks (see CP3, CP12 and CP13).

### Assessment of Principle 1 — Summary finding
- Assessment of Principle 1: Largely Compliant.

### Key findings on mandate, objectives and legislative framework
- OSFI is the federal supervisor for federally regulated financial institutions (all banks, federally regulated life and property and casualty insurers, trust and loan companies, cooperative credit associations, fraternal benefit societies and private pension plans subject to federal oversight). Provincial supervisors license and supervise certain non-bank deposit-taking institutions (credit unions, trust companies and loan companies incorporated under provincial laws).  
- OSFI’s responsibilities and objectives are defined in Canadian banking legislation (mainly OSFI Act, the Bank Act and the Trust and Loan Companies Act). However:  
  - The primary objective of banking supervision is not entirely clear. Section 3.1 of OSFI Act defines OSFI’s purpose as “to contribute to public confidence in the Canadian financial system.” This wide concept can host other objectives depending on political will.  
  - The Strategic Plan 2022-2025 “refocus / change in how we use our mandate” exercise shows that a widely defined mandate may be subject to significant changes depending on policy vision and political will of OSFI’s leadership.  
  - In the regulatory process (see EC4), when new or amended rules are created by OSFI, the Department of Finance (DOF) considers pros and cons and balances:  
    - The Government’s priorities and policy objectives,  
    - Prudential safety and soundness considerations, and  
    - The ability of financial institutions to compete effectively and take reasonable risks (these other public goods are placed on an equal footing with prudential safety and soundness).  
  - OSFI’s new integrity and security / preventing foreign interference mandate (OSFI Act, Subsection 4(2), points (a.1) and (b.1)) and “the need to allow financial institutions to compete effectively” (OSFI Act, Subsection 4(3), point (a)) are on an equal footing with functions directly related to safety and soundness; the overarching “public confidence” goal does not clearly prioritize among these objectives in case of trade-offs.  
    - Assessors note that most integrity and security elements identified by OSFI are congruent with prudential safety and soundness but that emphasis on the new mandate creates a risk of distraction, especially on foreign interference aspects that may not always align with safeguarding prudential safety and soundness (see EC2).  
  - OSFI internally frames part of its mandate as a “dual mandate”: consider competition in the banking sector and protection of depositors. Internal documents show competition considerations are given a very important role in deciding use and timing of supervisory powers. This perception may delay appropriate action and hamper early intervention and proactive supervision, and may serve as a legal criterion in court review of OSFI decisions.  
  - Assessors view present risk of conflict and inadequate trade-offs between policy goals that subordinate safety and soundness to other objectives as low, noting OSFI does not enforce consumer-oriented provisions (this is FCAC’s remit). However, future public policy goals legally fitting within “public confidence” could overshadow safety and soundness.

- Conclusion: The legislation establishing OSFI does not guarantee that safety and soundness will always be the primary and overriding objective; broader responsibilities and public policy goals (including integrity and security / preventing foreign interference and “the need to allow financial institutions to compete effectively”) may not be subordinate to the primary objective and could conflict with it.

### Legislative and policy instruments, guidance and supervisory powers
- The legislative framework of federal and provincial authorities does not allow for regulatory and supervisory gaps; distribution of responsibilities is clear and comprehensive.  
- OSFI has no decision-making power over laws or binding regulations but can propose legislative and regulation amendment requests and acts as a “co-lead” with the DOF for implementation of such requests. OSFI is involved in changes to the BA and TLCA and in making or changing regulations under these statutes, given its dual role as (1) prudential supervisor and (2) administrator of statutory provisions except consumer provisions.  
- OSFI publishes non-binding guidance to develop legislative requirements or articulate expectations. Guidance is not legally binding and is issued at OSFI’s discretion; guidance is supported by OSFI’s statutory and intervention powers (see EC5, EC6 and CP11).  
- The BA empowers OSFI to increase prudential requirements (capital and liquidity; see subsections 485(3) and 949(3) for bank holding companies) for individual banks and banking groups based on risk profile and systemic importance. OSFI has a Pillar 2 framework set out in OSFI’s ICAAP Guideline to address idiosyncratic risks not captured under Pillar 1.  
- Canada has an automatic review mechanism for basic banking laws to ensure effectiveness and relevance: the BA contains a “sunset” clause resulting in review of the statute every five years or so. OSFI participates in international regulatory fora and is an active and innovative regulator. Rules and guidance are published in the Canada Gazette and on OSFI’s web portal.  
- Modification of legislation is preceded by public consultations led by the DOF (often with OSFI, but not always). Amendments or new statutory instruments are led by the DOF and include public consultation (often with OSFI participation, but not always).  
- Most prudential standards (capital, governance, liquidity and risk management) take the form of OSFI’s non-binding guidance. OSFI conducts formal public consultations when developing or updating guidance; consultation papers and/or drafts are posted for comments on OSFI’s website. Summaries of industry comments and OSFI’s responses are published concurrent with final guidance.  
- The pilot approach for quarterly release of regulatory guidance initiated in the third quarter of 2024 is intended to increase transparency and engagement and help OSFI’s guidance remain relevant and up to date.  
- OSFI’s Policy Development and Standards Division monitors guideline status, discusses potential changes, and oversees effectiveness reviews of older and recent guidelines. Such reviews assess whether desired impact is achieved.

### Supervisory powers and access to information
- The BA and TLCA confer on OSFI the legal powers to:  
  - Authorize commencement of activity of new banks (banks are authorized by letters patent of incorporation by the Minister of Finance upon recommendation of the Superintendent, see CP5).  
  - Conduct ongoing supervision of overall activities, including activities performed by relevant service providers and activities of parent companies and companies affiliated with parent companies, both domestic and cross-border.  
  - Address compliance with laws and undertake timely corrective actions to address safety and soundness concerns (see CP11), including intervention or triggering resolution.  
- OSFI’s access to information powers can be used to retrieve information from parent companies and affiliates of a bank. OSFI’s supervisory assessment considers activities of parent companies and affiliates and their impact on the regulated institution.

### Recommendations (as stated in the source)
- Establish clearly and in a highlighted way in the OSFI Act that the safety and soundness of banks and the banking system is the primary and overriding objective of OSFI and explicitly subordinate all its other activities and legal mandates to this goal.  
- Clarify or suppress the references to “the need to allow financial institutions to compete effectively and take reasonable risks” in OSFI Act, so that safety and soundness goal clearly prevails.  
- When the DOF leads regulatory (“statutory instruments”) or legislative projects regarding prudential matters, the participation of OSFI in the consultation as “co-lead” of the project should be compulsory, as a matter of procedure. No legislation or regulation on prudential matters should be issued without due consideration of OSFI’s opinions and recommendations, irrespective of which authority is legally responsible for drafting/approval.

### Principle 2 — Independence, Accountability, Resourcing and Legal Protection (intro)
- Principle 2 summary: The supervisor possesses operational independence, transparent processes, sound governance, budgetary processes that do not undermine autonomy, and adequate resources, and is accountable for discharge of duties and use of resources. The legal framework includes legal protection for the supervisor.  
- Reference: BCBS, Report on the impact and accountability of banking supervision, July 2015.

### EC1 — Operational independence, accountability and governance (findings)
- OSFI is established under the OSFI Act and is the division of federal public administration entrusted with supervision of federally regulated financial institutions (OSFI Act, Section 4).  
- OSFI is an office of the Government of Canada subject to the authority and responsibility of the Minister of Finance (OSFI Act, Subsection 4(1)):  
  - “Office Established 4(1) There is hereby established an office of the Government of Canada called the Office of the Superintendent of Financial Institutions over which the Minister [of Finance] shall preside and for which the Minister shall be responsible.”  
- Section 6 of the OSFI Act confers to the Superintendent the powers, duties and functions assigned under the BA and TLCA; the Superintendent “shall examine into and report to the Minister [of Finance] from time to time on all matters connected with the administration of the provisions of those Acts.”  
- OSFI’s placement within government provides accountability to Parliament through the Minister of Finance, but the relationship goes beyond accountability and can potentially impact OSFI’s technical autonomy to set prudential policy and take supervisory actions. Assessors identify indicators that the DOF–OSFI relationship can affect discretion because numerous BA and TLCA sections provide for a role, decision or intervention by the Minister of Finance in prudential matters. Examples of ministerial approvals foreseen in the BA include (non-exhaustive list in source):  
  - Subsection 3(4) BA, guidelines precising the concept of control of an entity.  
  - Section 22 BA, issuance of letters patent of incorporation for a new bank and establishment of terms and conditions (Section 28 BA) and amendment of letter patent (Section 215 BA and Section 216.01 BA for conversion into another type of entity, Section 671 BA for incorporation of a bank holding company).  
  - Section 26 BA, OSFI informs the Minister on any objections received to an application for letters patent of incorporation and about any findings resulting from investigation of these objections.  
  - Section 223, 229 and 33 BA, issuance of letters patent of continuance / amalgamation / merger of banks and bank holding companies and application for court enforcement of its conditions (Sections 229.1 and 810 BA).  
  - Section 54 BA, order requiring a bank not to have average total assets in any three month period exceeding the bank’s average total assets in the previous three month period if the Minister is of the opinion that it is in the best interests of the financial system in Canada (or, as per Section 386 BA, if the bank with equity exceeding CAD 2 billion does not comply with the 35 percent public holding requirement of Section 385 BA for its shares).

*Source: Excerpt from the provided IMF document.*

### 6. Section 55 BA, on the recommendation of the Superintendent, the Minister may

### 6. Section 55 BA, on the recommendation of the Superintendent, the Minister may authorize banks that are subsidiaries of foreign banks to hold certain assets prohibited in the Bank Act.

### Ministerial statutory powers over banks (enumerated authorities)
- Section 55 BA: on the recommendation of the Superintendent, the Minister may authorize banks that are subsidiaries of foreign banks to hold certain assets prohibited in the Bank Act.
- Subsection 156.09(8) BA: the Minister may order the disposal of an amount of shares to a shareholder casting directly or by proxy more than 20 percent of eligible votes in a bank with more than CAD 12 billion equity (thereby violating the restriction of Subsection 156.09(2)) and restrict their voting rights (as per Subsection 156.09(9) BA).
- Section 236(1) BA: approving asset and liabilities sales of a bank’s business.
- Section 245 (1) BA: the Superintendent may order that bank (or for bank holding companies, Section 822 BA) records and information processing be maintained and performed only in Canada to prevent this situation from hindering its supervision and the Minister may instruct the Superintendent to issue such order on the basis of the national interest.
- Section 345 BA: approval of voluntary dissolution and liquidation of a bank.
- Section 373 BA: approval of acquisition of a significant interest in a bank.
- Section 374.1 BA: establishment of a timeframe for major shareholder divestiture in a bank with an equity exceeding CAD 12 billion.
- Section 377.1 BA: approval of the acquisition of a controlling interest in a bank with an equity of less than CAD 12 billion.
- Section 395 BA: establishes that the applications for Ministerial approvals under Part VII Ownership of the BA must be filed with the Superintendent and contain the information, material and evidence that the Superintendent may require, which will send it to the Minister once its completion has been ascertained (Section 398 BA).
- Section 402 BA: orders to dispose of shares to controlling shareholders in breach of agreements or precepts of the BA regarding ownership of banks.
- Section 402.2 BA: orders to dispose of shares of shareholders that pose a threat to the integrity or security of the bank or the financial system in Canada or a threat to national security.
- Section 410 BA: authorization for banks to carry out certain activities different from and additional to the banking business.
- Section 468 BA: establishes the entities where banks are permitted to make substantial or controlling investments and foresees the prior approval of the Minister for these operations.
- Section 484.1 BA: the Minister may prevent the Superintendent from declaring a bank as a D-SIB (or from revoking a prior D-SIB designation) if the Minister is of the opinion that is not in the public interest to do so.
- Subsection 485(1.3) BA: the Minister may prevent the Superintendent from imposing a minimum Total Loss Absorbing Capacity (TLAC) amount on a D-SIB bank as a D-SIB, if the Minister is of the opinion that is that amount is not in the public interest (a different one would be imposed).
- Sections 522.21 BA and 522.211 BA: approval of a foreign bank / entity associated to a foreign bank to have a financial establishment in Canada.
- Section 522.22 BA: approval of a foreign bank / entity associated to a foreign bank to acquire control (directly or indirectly) of a Canadian financial entity.
- Section 522.25 BA: order the divestiture for acquisitions made in breach of the BA.
- Section 524 BA: authorize the opening of a branch or the exercise of business in Canada by a foreign bank, after consulting the Superintendent.
- Section 525 BA: OSFI informs the Minister on any objections received to an application for authorization of a foreign bank’s branch or activity in Canada and about any findings resulting from the investigation of these objections.
- Section 537 BA: authorization of the transfer of liabilities of the Canadian business of a foreign bank to another entity.
- Sections 606 and 636 BA: allows the Superintendent to share any confidential information of a bank, an authorized foreign bank or a person dealing with them with the Deputy Minister of Finance.
- Section 609 BA and Section 639 BA: the Superintendent shall disclose, at the times and in the manner that the Minister may determine, any information obtained by the Superintendent under this Act that the Minister considers ought to be disclosed for the purposes of the analysis of the business in Canada of an authorized foreign bank and that (a) is contained in returns filed pursuant to the Superintendent’s financial regulatory reporting requirements in respect of a bank or an authorized foreign bank; or (b) has been obtained as a result of an industry-wide or sectoral survey conducted by the Superintendent in relation to an issue or circumstances that could have an impact on the business in Canada of on a bank or an authorized foreign bank.
- Section 613 BA and Section 643 BA: after the conclusion of each examination and inquiry on a bank or an authorized foreign bank (on its business and affairs, about its policies and procedures, about the administration of banking regulation), the Superintendent shall report on it to the Minister.
- Section 619 BA and Section 649 BA: the Superintendent cannot prolong an intervention of a bank or an authorized foreign bank (taking control of its assets) for more than 16 days against the advice of the Minister.
- Subsections 619(2.1) BA and 648(1.11) BA: the Minister may, for reasons related to national security, direct the Superintendent to take control of the assets of a bank or of an authorized foreign bank.
- Subsections 620(2) BA and 650(2) BA: empower the Minister to declare the end of the intervention by the Superintendent.

### Notable operational and national-security powers
- The Minister may order maintenance and performance of records and information processing only in Canada (Section 245 (1)).
- The Minister may intervene in D-SIB designation and TLAC imposition (Section 484.1 and Subsection 485(1.3) BA).
- The Minister can direct Superintendent interventions for national security reasons (Subsections 619(2.1) BA and 648(1.11) BA).

### Orders to dispose of shares and divestiture
- Subsection 156.09(8) BA: disposal orders tied to exceeding 20 percent of eligible votes in banks with more than CAD 12 billion equity.
- Section 402 BA and Section 402.2 BA: disposal orders for breaches or threats to integrity, security, or national security.
- Section 374.1 BA: timeframe for major shareholder divestiture in banks with equity exceeding CAD 12 billion.
- Section 522.25 BA: order divestiture for acquisitions made in breach of the BA.

---

### Governor-in-Council regulatory powers in prudential matters (binding regulations list)
- Subsection 410(3) BA: regulations ordaining the additional activities to the banking business that banks may be authorised to carry out.
- Subsections 415.2 and 415.3 BA: regulations in relation to derivatives and eligible financial contracts and respecting a bank’s activities in relation to benchmarks (publicly available price, estimate, rate, index or value used for reference of interest rates or other financial variables).
- Section 419.1 BA: regulations on asset encumbrance and respecting the creation by a bank of security interests in its property to secure obligations of the bank and the acquisition by the bank of beneficial interests in property that is subject to security interests.
- Section 467 BA: regulations in relation to (a) respecting the determination of the amount or value of loans, investments and interests for the purposes of Part IX Investments [limits] of the BA; (b) respecting the loans and investments, and the maximum aggregate amount of all loans and investments, that may be made or acquired by a bank and its prescribed subsidiaries to or in a person and any persons connected with that person; (c) specifying the classes of persons who are connected with any person for the purposes of paragraph (b); and (d) concerning specialized financing for the purposes of subsection 466(4).
- Section 479 BA: regulations (a) defining the interests of a bank in real property; (b) determining the method of valuing those interests; or (c) exempting classes of banks from certain requirements of the BA.
- Subsection 485 (2) BA: regulations respecting the maintenance by banks of adequate capital and adequate and appropriate forms of liquidity and the maintenance by domestic systemically important banks of the minimum capacity to absorb losses.
- Section 485.01 BA: regulations respecting the conditions that domestic systemically important banks must meet in issuing, originating or amending prescribed shares or liabilities.
- Section 485.02 BA: regulations respecting the disclosure by domestic systemically important banks of information in relation to their capacity to absorb losses.
- Section 637 BA: regulations prohibiting, limiting or restricting the disclosure by banks of prescribed supervisory information.
- Subsection 949(2) BA: respecting the maintenance by bank holding companies of adequate capital and adequate and appropriate forms of liquidity.
- Subsection 978 (1) BA: broad Governor-in-Council power to regulate matters including:
  - (a) prescribing anything that is required or authorized by the BA to be prescribed;
  - (b) prescribing the way in which anything that is required or authorized by the BA to be prescribed is to be determined;
  - (c) respecting, for any purpose of any provision of the BA, the determination of the equity of a bank or a bank holding company;
  - (d) defining words and expressions to be defined for the purposes of the BA;
  - (e) requiring the payment of a fee in respect of the filing, examining or issuing of any document or in respect of any action that the Superintendent is required or authorized to take under the BA, and fixing the amount of the fee or the manner of determining its amount;
  - (f) respecting the regulatory capital and total assets of a bank or a bank holding company;
  - (g) respecting the retention, in Canada, of assets of a bank or a bank holding company;
  - (h) respecting the value of assets of a bank or a bank holding company to be held in Canada and the manner in which those assets are to be held;
  - (i) respecting the protection and maintenance of assets of a bank or a bank holding company, including regulations respecting the bonding of directors, officers and employees of a bank or a bank holding company;
  - (j) respecting the holding of shares, membership shares and ownership interests for the purposes of sections 70, 74 and 714 BA;
  - (k) respecting information, in addition to the information required by section 634 BA or 953 BA, to be maintained in the register referred to in that section; and
  - (l) generally, for carrying out the purposes and provisions of the Bank Act.

---

### Institutional roles, practices, and identified governance risks
- The Minister of Finance is the central political figure responsible for all matters relating to the financial affairs of Canada, including the overall stability of the financial system.
- The Minister of Finance has overarching authority over federal financial sector legislation and sets the policy focus of each multiyear revision of banking legislation prompted by the sunset clause.
- Authorities report a practice of dual focus:
  - Ministerial policy considerations by the Minister of Finance (which legally prevails), and
  - statutory and prudential considerations by OSFI who prepares the recommendation for the Ministerial decision.
- The combination of Ministerial powers and administrative practice, together with the lack of clarity of OSFI’s legal mandate and primary legislative goals, may cause the prudential goal of safety and soundness to be eclipsed or overridden by other public goods.
- This practice may change because it is an administrative custom and not contained in a written statute; the Minister of Finance could process ministerial approvals directly where OSFI’s involvement is not prescribed or give little weight to OSFI’s considerations.
- The institutional legal framework allows a potentially significant increase of the influence of the Minister of Finance on OSFI and its prudential policy and supervisory decisions; this risk is characterized as a macro risk that has increased significantly.
- Relevant contextual points:
  - (i) The DOF (Department of Finance) is presided by a central political figure of the Cabinet;
  - (ii) The DOF has a very wide mandate that includes general economic policy objectives and supporting general government policies which may clash with OSFI’s microprudential mandate.
- The Mandate Letter of the current Minister of Finance includes policy objectives such as:
  - “seek opportunities within your portfolio to support our whole-of-government effort to reduce emissions, create clean jobs and address the climate-related challenges communities are already facing”
  - “We must continue building a strong middle class and work toward a better future where everyone has a real and fair chance at success and no one is left behind”
  - “You will work to make life more affordable for middle class Canadians and their families, including building off our sustained investment in early learning and child care and taking significant action on housing affordability”
  - “Crack down on predatory lenders by lowering the criminal rate of interest”
  - “Continue to engage with stakeholders to lower the average overall cost of interchange fees for merchants, proceeding in a way that ensures small businesses benefit from this work and protects existing reward points of consumers”
- Potential consequences noted:
  - The Minister of Finance could encroach on OSFI’s regulatory guidance by promoting more Governor-in-Council regulations.
  - The Minister could impose political priorities and policy stances over OSFI prudential positions and influence the tone of the Superintendent’s term.

### Legal safeguards and sources of OSFI autonomy
- The Superintendent is appointed by the Governor-in-Council under the advice of the Minister of Finance for a fixed term of seven years and can only be removed for cause (see EC2 and Section 5 of the OSFI Act).
- The long mandate term and removal only for cause reinforce operational and technical independence of the Superintendent and mitigate the risk of political capture.
- OSFI is a separate agency of the Government of Canada listed under Schedule V of the FAA; section 11.2 of the FAA permits the Governor in Council to delegate to the appropriate minister or deputy head certain powers or functions of the Governor in Council or the Treasury Board in relation to human resources management.
- Sections 7, 11, 12 and 13 of the OSFI Act provide statutory duties and HR arrangements:
  - Section 7(1): “The Superintendent shall engage exclusively in the duties and functions of the Superintendent under section 6 and the duties and functions of the Superintendent as the deputy head of the Office.”
  - Section 11: employees necessary to enable the Superintendent to perform duties shall be appointed in accordance with the Public Service Employment Act.
  - Section 12: continuity of employment for employees of predecessor entities.
  - Section 13: Superintendent authorized to exercise powers and perform functions of the Treasury Board that relate to human resources management for persons appointed under section 11.
- Under Subsection 12(2) FAA, the Superintendent as deputy head may exercise powers including:
  - (a) determine learning, training and development requirements and fix terms;
  - (b) provide awards for outstanding performance and meritorious achievements;
  - (c) establish standards of discipline and set penalties including termination, suspension, demotion and financial penalties;
  - (d) provide for termination of employment or demotion for reasons other than breaches of discipline or misconduct.
- The appropriate Minister for OSFI is the Minister of Finance; the accounting officer is the Superintendent. The Superintendent is accountable before parliamentary committees for program organization, internal controls, signing of accounts for Public Accounts, and other duties per Section 16.4 FAA.
- Assessors’ view on organizational autonomy:
  - The functions and powers of the Superintendent as deputy head provide OSFI with enough organizational autonomy to hire and dismiss its own personnel, apply disciplinary sanctions, decide organizational changes, allocate functional responsibilities, and make staff changes and promotions.
  - However, assessors consider that terms and conditions of the delegation may be used to undermine OSFI’s organizational autonomy and that conferring those powers directly in legislation (for example, in the OSFI Act) would be preferable.
  - Restrictions imposed by the Public Service Commission reduce flexibility needed by a specialized agency like OSFI to acquire skills and professional profiles needed for safety and soundness goals.

### Reporting, disclosures, and accountability arrangements
- OSFI must produce an Annual Report detailing its operations for the year, which the Minister must table before Parliament under section 40 of the OSFI Act.
- Section 6 of the OSFI Act requires the Superintendent to report to the Minister from time to time on all matters connected with the administration of the BA and TLCA.
- Authorities view these obligations as accountability structures that do not compromise OSFI’s operational independence; assessors concur partially, indicating that it is not parliamentary accountability per se that undermines independence but other legal powers, reporting mechanisms, and potential de facto influence described above.

---

*Source: 1canea2025007-source-pdf - 6. Section 55 BA, on the recommendation of the Superintendent, the Minister may authorize banks that are subsidiaries of foreign banks to hold certain assets prohibited in the Bank Act.*

### section 23

### section 23

### Budgetary autonomy and funding arrangements
- OSFI’s funding: mandated under section 23 of the OSFI Act to be financed through assessments on federally regulated financial institutions.
- Budget planning process:
  - OSFI conducts its own budget planning as part of the annual Departmental Plan development process, which includes planned budget for the next 3 fiscal years.
  - The plan is submitted to the DOF, which challenges it and provides advice to the Minister of Finance.
  - The Minister of Finance needs to sign-off this Departmental Plan for it to be tabled in Parliament.
  - Parliament debates it along with the other Departmental Plans.
- Effect on autonomy:
  - The approval by the Minister of Finance of the budget undermines OSFI’s budgetary autonomy.
  - Through this avenue, the Government has imposed on OSFI fiscal restraints such as wage freezes, hiring freezes and other cost containment exercises.
  - Although OSFI’s costs are mostly recovered from the institutions it regulates and is not funded through general government revenues, OSFI is not fully independent to define and execute its budget.
- Operational impact:
  - The lack of budgetary autonomy is currently impacting OSFI’s supervisory activities of core banking risks with resource constraints that impact its capacity to perform frequent and deep supervisory reviews (see, for example, CP9, CP15 and CP17).
  - This occurs in a context of widening mandates and functions of OSFI (which have required additional resources and have been the focus of past budget increases).
- Assessment and principle:
  - Assessors acknowledge the public good inherent in budgetary contention initiatives (safeguard fiscal capacity and introduce efficiency in government spending) and how difficult it can be for banking supervisors to stay away from these politically mandated measures.
  - A banking supervisor must be able to decide its budget considering only the resources necessary to safeguard the safety and soundness of banks and the banking system (and its other public interest mandates, subordinated to safety and soundness, such as integrity and security in the case of OSFI).
  - The attainment of the safety and soundness public policy goal is not correlated with the ups and downs of the fiscal position of general governments; rather it has dynamics of their own (depending on the risks or complexities in the banks and in the system).
  - The budget of the banking supervisors should thus be stable in the long-term (because the build-up of supervisory capacity is a process of gradual accretion),predictable and follow these dynamics (not only provide for emergencies, unforeseen events or circumstances).

### Stakeholder engagement and transparency
- Governance of stakeholder engagement:
  - OSFI has a Stakeholders Affairs Framework managed institution-wide by a Stakeholders Affairs Department.
  - Goals include increasing public awareness, building trust with stakeholders, and increasing OSFI’s awareness of stakeholder priorities, issues and risks.
  - Interactions with stakeholders are governed by principles of relevancy, accountability (engagement processes and outcomes should be documented and evaluated and results shared openly within OSFI), sustainability (long-standing relationships) and inclusiveness.
  - The Framework foresees a mapping of stakeholders categorizing them according to their interest in OSFI and influence on OSFI.
- Public communications and events:
  - OSFI is transparent about its speaking engagement criteria, which prioritizes taking part in speaking engagements that are open to stakeholders and advance understanding of its work.
  - Senior Executives at OSFI participate in common fora held by private sector actors to communicate OSFI’s role, its positions and how it performs its duties; summaries of speaking points/speeches are posted on OSFI’s website.
  - Results of external consultation initiatives on OSFI guidelines are posted to OSFI’s website.
  - OSFI-hosted external events/common fora—which include private sector actors/stakeholders as attendees—are evaluated and results are shared internally; they are typically not published publicly but may be shared on occasion with external stakeholders or partners.

### Appointment and removal of the head (EC2)
- Institutional structure:
  - The Superintendent is the “Deputy Head” of OSFI.
  - The Superintendent is supported by an Executive Leadership Team and Senior Leadership Team.
  - OSFI does not have a separate “governing body,” such as a board of directors.
- Appointment process:
  - A competitive hiring process is followed, which includes a public call for applicants to the position.
  - Applicants are subjected to an interview process where a board of reviewers assess candidates against the published criteria.
  - The selection process is coordinated by the Privy Council Office (Senior Personnel Secretariat) on behalf of the Prime Minister’s Office.
  - The Superintendent is appointed by the Governor General pursuant Order-in-Council has been issued by the Governor-in-Council.
- Removal and transparency (EC2 standard):
  - EC2 requires that the head(s) of the supervisory authority be appointed for a minimum term and removed during their term only for reasons specified in law or if they are not physically or mentally capable of carrying out the role or have been found guilty of misconduct, with the reason(s) for removal publicly disclosed.
  - Description and findings re EC2 are provided in the text above.

*Source: section 23 of the provided IMF content unit*

### Section 5 of the OSFI Act provides that OSFI will be headed by a Superintendent who is

### 1canea2025007-source-pdf - Section 5 of the OSFI Act provides that OSFI will be headed by a Superintendent who is

### Appointment, term, removal, and interim substitution
- Superintendent is appointed by the Governor in Council for a fixed term of seven years.
- Appointment is made “during good behaviour”, meaning removal only for cause (i.e., misconduct), as opposed to “during pleasure.”
- Where the Superintendent is removed from office, the Order in Council providing for the removal must be laid before Parliament.
- A Superintendent has never been removed from office since OSFI was established in 1987.
- The Superintendent, on the expiration of any term of office, may be re-appointed for a further term of office.
- In the event of absence or incapacity of the Superintendent, or if the office is vacant, the Governor in Council may appoint a qualified person to hold office instead of the Superintendent for a term not exceeding six months, with all powers, duties, and functions of the Superintendent.
- This interim appointment may be renewed for subsequent six-month terms. There have never been interim appointments up to now.
- Appointment documentation requires compliance with:
  - Ethical and Political Activity Guidelines for Public Office Holders,
  - the Conflict of Interest Act,
  - the Values and Ethics Code for the Public Sector, and
  - Sections 7 and 19 of OSFI Act.
- Job poster minimums included: relevant university degree; more than 10 years of recent experience in banking, finance, risk management or regulation; experience with senior interactions, leading organizational change and resolving complex risk management issues; knowledge and skills including Canadian financial sector, prudential regulation, leadership and cooperation skills.

### Transparency, public accountability, and published objectives (EC3)
- OSFI is transparent about its role, responsibilities, and how it performs duties; OSFI’s website is a source of public information on mandate, role relative to other government bodies, and methods of performing duties.
- OSFI’s pilot quarterly regulatory releases commenced in the third quarter of 2024.
- OSFI conducts periodic surveys to gauge industry opinion on OSFI’s effectiveness; results are published on the website and through Library and Archives Canada, along with OSFI’s responses.
- Public communications include speeches and news releases.
- OSFI’s objectives and performance are made public annually in multiple publications tabled in Parliament:
  - Annual Report – summarizes key activities for the fiscal year, discusses objectives and performance, outlines future plans and priorities, and includes OSFI’s audited financial statements;
  - Departmental Plan – provides detail over a three-year period on OSFI’s main priorities by strategic outcomes, program activities and planned/expected results;
  - Departmental Results Report – outlines results achieved against planned performance expectations as set out in the Departmental Plan.
- Additional public publications:
  - Strategic Plan – sets OSFI’s high-level priorities for a three-year period;
  - ARO – provides an overview of the current risk environment and OSFI’s responses; annex sets out regulatory priorities and supervisory strategies with a one-year horizon.
- Access to Information and Privacy:
  - OSFI is fully subject to the Access to Information Act (ATIA) and the Privacy Act (PA); records must be produced for proper requests but may be redacted under exemptive provisions.
  - Under the BA, TLCA, and OSFI Act, information obtained by the Superintendent regarding a regulated institution or person dealing with such an institution is confidential.
  - In 2019, Part II of the ATIA was created and lists OSFI’s pro-active disclosure requirements, including:
    - Briefing Materials prepared for incoming Superintendents;
    - Title of Briefing Notes prepared for the Superintendent;
    - Briefing Package prepared for the Superintendent’s parliamentary committee appearances.
  - OSFI also publishes:
    - a list of requests completed under the Access to Information Act;
    - summaries of completed Privacy Impact Assessments;
    - and maintains the OSFI chapter of Sources of Federal Government and Employee Information (Info Source) with links to Application and Approval Guides, OSFI’s Guides to Intervention and OSFI’s Supervisory Framework.
- The Minister of Finance must table the Annual Report before Parliament under section 40 of the OSFI Act. Section 6 requires the Superintendent to report to the Minister from time to time on matters connected with administration of the BA and TLCA.

### Internal governance, delegation, decision-making, and emergency procedures (EC4)
- OSFI has a Framework for Exercising the Superintendent’s Statutory Powers (FESP) that:
  - outlines powers retained by the Superintendent and those assigned to specific positions;
  - ensures timely supervisory decisions at levels appropriate to issue significance;
  - allows the Superintendent, Deputy Superintendent or Assistant Superintendents to have a subordinate act in their capacity for functions or periods of time.
- The Superintendent can be substituted for decision-making by two senior officers (Deputy or Assistant Superintendents) if absent or incapable.
- OSFI maintains written procedures for key regulatory and supervisory functions (risk assessment and examination, approvals, rulemaking, etc.) that complement FESP and job descriptions.
- FESP contains provisions for emergency exercise of certain powers normally reserved to the Superintendent.
- OSFI has a Business Recovery Plan covering business interruption, including decision making in emergencies.
- Regular meetings between senior operational management (within and between sectors) and executive management meetings including heads of all sectors facilitate timely discussion and decisions.
- Approval Authorities internal decision-making framework allocates authority for key supervisory tasks to:
  - Deputy Superintendent;
  - Executive Director in charge of the Risk Assessment and Intervention Hub;
  - Senior Directors of the Risk Assessment and Intervention Hub; and
  - Lead Supervisors (LSs) in charge of a bank or portfolio.
- Approval authority allocation differs by bank tiering (less delegation for more systemic/important banks).
- OSFI has a documented Enterprise Risk Management (ERM) framework and policy aligned with ISO 31000 principles.
- Risk Appetite Statement (RAS) provides foundational structure for risk-informed decision-making and is embedded in the bank tiering system used in the new supervisory approach.
- Internal governance aligned with three lines model:
  - First line: governance committees on policy, supervision and administration.
  - Second line: ERM Committee (ERMC) providing advice to the Superintendent and first line committees; ERMC has two subcommittees: External Risk Committee (ERC) and Internal Risk Committee (IRC).
    - ERC accountable for identification of and actions to address cross-sector industry-wide risks facing banks and other regulated entities.
    - IRC accountable for identification of and actions to address internal risk facing OSFI as an organization.
  - Third line: Departmental Audit Committee advising the Superintendent on non-prudential (corporate) matters.
- OSFI maintains an internal audit function; financial statements are audited by a private audit firm; OSFI is subject to “value for money” audits by the Office of the Auditor General of Canada (OAG). The most recent OAG topic noted was in April 2023 (the topic was how you incorporate climate risk in financial supervision).
- If OSFI fails to meet objectives or deviates from objectives, outcomes are explained and publicly disclosed in Annual Report, Departmental Plan, Departmental Results Report, or OSFI‘s responses to internal audit or OAG reports.

### Emergency contracting and surge capacity
- OSFI established, via a competitive contracting process, three “as and when requested” contracts for financial industry related consulting and professional services (“the Standing Contracts”) to expedite procedures in case of an emergency.
- Each Standing Contract has a ceiling value of $20million and is structured to allow OSFI to access support for interventions with federally regulated financial institutions within 24–48 hours.
- Procedures for leveraging these contracts, including expedited onboarding (security briefings, provision of laptops), are documented and communicated to key stakeholders.
- Standing Contracts include conflict of interest considerations between third-party consulting firms and regulated institutions.
- OSFI obtained an exceptional emergency contract delegation to establish additional contracts for financial sector consulting and professional services, up to $4million each, on a sole source basis, when existing contracts cannot be leveraged due to conflict of interest or lack of capacity.
- OSFI recently awarded contracts to two additional consulting firms (“the Contingency Contracts”) using the exceptional emergency delegation to ensure vetted consulting resources are available.

### Credibility, stakeholder consultations, and conflicts of interest (EC5)
- Since 2008, OSFI has commissioned biennial consultations with key stakeholders (mainly banks and insurance companies) to assess effectiveness and support continuous improvement; consultations are carried out by independent third-party consultants.
- Consultation outcomes assess OSFI and employees against OSFI’s Statement of Values and Code of Conduct (professionalism, integrity, respect for people); assessors reviewed the last and previous survey waves and found stakeholder views generally satisfactory with mixed but satisfactory results across granular areas.
- Sections 19 to 21 of the OSFI Act establish rules for the Superintendent, Deputy Superintendent, and members of FISC on avoiding real and perceived conflicts of interest:
  - Prohibits owning shares of federally regulated financial institutions;
  - Prohibits acceptance or receipt of any grant or gratuity from federally regulated financial institutions, with consequences for contravention (monetary fines and /or imprisonment);
  - Imposes disclosure requirements with respect to borrowings from federally regulated financial institutions.
- Section 1.2 of OSFI’s Conflict of Interest Policy:
  - Policy applies to every person employed by OSFI (full-time, part-time, term, leave without pay, students, casual employees), unless otherwise stipulated or excluded; employees on leave continue to be subject to the Policy for the extent of their leave.
  - The Policy does not apply to individuals who provide services to OSFI by virtue of a contract or an MoU; contractual documentation binds them in a manner aligned with the spirit of the Policy.
- The Values and Ethics Code for the Public Sector applies to every public servant in the federal public sector; definitions and scope of “public sector” as per the Public Servants Disclosure Protection Act are noted.
- Assessors conclude that policies and codes reviewed are comprehensive and well-designed to prevent conflict of interest and breaches of confidentiality.

*Source: 1canea2025007-source-pdf - Section 5 of the OSFI Act provides that OSFI will be headed by a Superintendent who is*

### Section 22 of the OSFI Act, section 636 of the BA and section 503

### Section 22 of the OSFI Act, section 636 of the BA and section 503

### Confidentiality and legal framework
- Sections establish rules for the Superintendent, Deputy Superintendent, employees or anyone acting under the Superintendent’s direction, and members of FISC on the appropriate use of information obtained through work.
- Subject to a limited number of exceptions, information about federally regulated financial institutions, and OSFI’s interaction with them, is deemed confidential and may only be used for lawful supervisory purposes.
- The Superintendent must be satisfied that when information is shared, it will be treated as confidential and exclusively for lawful supervisory purposes.
- OSFI’s internal Conflict of Interest Policy and its Statement of Values and Code of Conduct reflect and expand these statutory requirements; employees review these policies annually and are required to sign documents confirming compliance with certain requirements, such as the prohibition on owning shares of federally regulated financial institutions.
- Section 980 of the BA and subsection 533(1) of the TLCA provide that every person who, without reasonable cause, contravenes any provision of the BA or TLCA (including section 636 in BA and section 503 of the TLCA) or its associated regulations may be punished by way of monetary fines and/or imprisonment.
- OSFI has discretion to impose sanctions, up to and including dismissal, if an employee is found to be in breach of the OSFI Act, the BA or TLCA, or workplace policies.
- Footnote example: the OSFI Act allows confidential information to be shared with members of FISC and other government bodies that regulate or supervise the institutions.

### Information security policies and safeguards
- OSFI guidance includes: Policy on Corporate Security; Directive on Information Security; Guide to Information Security; Directive on Sensitive Compartmented Information; Directive on Travel Security (outlining appropriate handling of information while travelling).
- These documents provide guidelines and outline rules regarding appropriate physical and electronic safeguards to protect OSFI information.
- Classification tools available to assist information classification: Information Security Requirements Chart; Injury Assessment Tool; Injury Assessment Decision Tree — these determine who can access information and how it must be safeguarded.
- Breaches are subject to investigation and can result in consequences such as loss of security clearance or termination.
- All external experts are subject to the same confidentiality rules that apply to regular OSFI staff.

### EC6 — Resources for effective supervision: description and findings
- EC6 elements listed:
  - (a) A budget that provides for staff in sufficient numbers and with skills commensurate with the risk profile and systemic importance of the banks supervised;
  - (b) Salary scales that allow it to attract and retain qualified staff;
  - (c) The ability to commission external experts with necessary professional skills and independence subject to confidentiality restrictions;
  - (d) A budget and program for the regular training of staff;
  - (e) A technology budget sufficient to equip staff with tools needed to supervise the banking industry and assess individual banks;
  - (f) A travel budget that allows appropriate on-site work, effective cross-border cooperation and participation in domestic and international meetings of significant relevance (for example supervisory colleges).
- Overall finding: OSFI lacks budgetary autonomy despite financing itself from banks’ assessments; OSFI’s budget is integrated in its annual Departmental Plan and needs the approval of the Minister of Finance before being tabled in Parliament. Government cost-cutting initiatives have impacted OSFI and are producing resource constraints in core supervision functions while additional functions are entrusted to OSFI (integrity and security).
- (a) Staffing authorities:
  - Section 11 of the OSFI Act requires appointments in accordance with the Public Service Employment Act (PSEA), administered by the Public Service Commission (PSC).
  - PSC delegated staffing authorities to the Superintendent via the Appointment Delegation and Accountability Instrument; assessors found the delegation adequate in principle but noted terms and conditions may undermine OSFI’s organizational autonomy.
  - OSFI’s appointment processes are merit-based, documented, transparent; processes may be internal or external; OSFI posts announcements on the PSC webpage.
- (b) Compensation:
  - Pursuant to sections 13 and 15 of the OSFI Act, OSFI determines its own compensation regime.
  - Historically targeted the 75th percentile of base salary of the competitive financial services market.
  - OSFI can set executive pay scales different from the larger federal government but must seek a mandate from the Treasury Board of Canada to adjust non-executive compensation.
  - Non-executive workforce is unionized and subject to collective bargaining.
  - OSFI does not report problems attracting and retaining non-executive staff with necessary skills.
- (c) External experts:
  - OSFI has legal authority and necessary budget to commission outside experts and regularly draws on such experts (for example, specialized credit consultants).
  - Contracting and HR policies ensure external experts have necessary skills and independence and are subject to confidentiality rules.
- (d) Training:
  - Over the last 3 years, OSFI spent on average $1925 yearly on training in addition to training offered at no additional cost internally or through the Canada School of Public Service.
  - The Learning and Development budget is used for enterprise training needs (new employee orientation, leadership training, 360 evaluations, language training, coaching).
- (e) Technology and IM/IT:
  - OSFI has a designated Chief Information Officer (CIO) and a separate budget for the Information Management/Information Technology (IM/IT) Division managed according to IM/IT best practice portfolio management guidelines.
  - Technologies and information are managed based on a defined IM/IT strategy, a long-term IT renewal program, and life-cycle management policies.
  - IT/IM tools such as OSFI’s Business Intelligence Tool (BI Tool) consolidate quantitative and qualitative inputs about individual financial institutions and improve supervisory capability.
  - Document storage and retrieval capabilities are being upgraded to increase efficiencies.
- (f) Travel and on-site work:
  - OSFI develops annual supervisory strategies and plans for each banking group, including foreign operations; on-site reviews include meetings with host country supervisors when foreign operations are reviewed.
  - Travel budget has been affected by cost-cutting initiatives, leading to more virtual and desk reviews; tests remain rigorous and scope sufficiently wide.
  - OSFI participates in and supports cross-border commitments (e.g., supervisory colleges) and participation in international rule-making bodies (FSB, BCBS, International Association of Insurance Supervisors, Joint Forum).

### EC7 — Workforce planning, skills, and training: description and findings
- OSFI regularly monitors the external risk environment (for example, the published ARO) and uses external risk assessments as input into supervisory planning.
- OSFI prepares Risk and Control Self-Assessments (RCSA) to assist Supervision and Regulatory Response sectors in identifying new and emerging risks and determining requirements/needs for supervisory/regulatory response.
- OSFI operates on a three-year planning cycle and reviews plans at least annually; training needs are reviewed through human resource planning and senior management discussions.
- Individual sectors and divisions have access to operational and training budgets to bridge identified gaps.
- Staffing statistics:
  - Between March 31st, 2019, and March 31st, 2024, OSFI’s employee population (currently circa 1300 staff) increased by approximately 550 persons or 75 percent.
  - From the grand total of employees, the banking supervision and regulation activities are performed by 365 people as of March 31st, 2024 (they were 252 in March 31st, 2019; a 45 percent increase).
  - Most of the increase was due to the new three lines of defense structure and to reinforce supervision of new risks (operational resilience, technology and climate risks) and non-financial risks, including security and integrity.
  - Sectors in charge of financial risk have not grown, have suffered from attrition (retirement of senior personnel), and need more personnel to carry out risk-based supervision.

### EC8 — Risk-based supervision and resource allocation: description and findings
- OSFI employs a risk-based approach embedded in its Supervisory Framework to assess safety and soundness and identify issues early for timely corrective actions.
- Intensity of planned supervisory work depends on size, complexity, impact of failure (entity’s tier rating), and risk profile.
- Quality assurance and quality control arrangements:
  - Quality Assurance:
    - Supervision Quality Assurance Division (SQAD) delivers ongoing and objective Quality Assurance on methodology design/adherence and quality/consistency of supervisory outputs.
    - SQAD focuses on consistent application of supervisory methodology; conducts Group Rating Committees for cohorts of similar entities to discuss and approve supervisory ratings.
    - SQAD conducts thematic Quality Assurance Reviews sampling entities for adherence to methodology and quality of outputs.
  - Quality Control:
    - Reviewers and approvers act as front line of quality control to ensure consistency and sound supervisory judgment.
    - Heads of subsectors lead regular monitoring meetings to discuss quality of supervisory outputs and consistent application of methodology.
- Supervisory planning and tiering:
  - OSFI annually prepares a supervisory strategy for each institution; strategy guides resource allocation decisions for the upcoming year.
  - Tier rating scale (1 to 5) classifies banks based on size, complexity, and impact of failure:
    - Tier 1: Large and/or complex institutions with highest system impact
    - Tier 2: Large and/or complex institutions with significant system impact
    - Tier 3: Mid-size institutions with moderate system impact
    - Tier 4: Smaller and/or less complex institutions with low system impact
    - Tier 5: Smallest, least complex institution with very low system impact
  - All D-SIBs are considered tier 1 institutions.
  - OSFI updates tier assignments at least annually; off-cycle tier assessment can occur if warranted.
- Supervisory Strategy and Planning Standard inputs:
  - Macro risks (External Risk Committee work, e.g., ARO)
  - FRFI or Federally Regulated Pension outcomes expected to address identified issues (supervisors develop up to three supervisory outcome statements)
  - Risk currency (work to keep risk assessments up to date)
  - Specific risks (work on topics such as risk management practices, capital and liquidity assessments, or new regulatory initiatives)
- OSFI has dedicated supervisory teams for conglomerate banks or banking groups and can leverage specialist support staff focused on certain types of risk (for example, credit risk).

*Source: Section 22 of the OSFI Act, section 636 of the BA and section 503 of the TLCA (source PDF).*

### Section 39 of the OSFI Act provides legal protection to OSFI and its staff against lawsuits for

### Section 39 of the OSFI Act provides legal protection to OSFI and its staff against lawsuits for

### Legal protection under Section 39
- Full verbatim statutory protection:
  - “No liability 
    39 No action lies against Her Majesty, the Minister, the Superintendent, any Deputy 
    Superintendent, any officer or employee of the Office or any person acting under the direction 
    of the Superintendent for anything done or omitted to be done in good faith in the 
    administration or discharge of any powers or duties that under any Act of Parliament are 
    intended or authorized to be executed or performed.
    Not compellable
    39.1 The Superintendent, any Deputy Superintendent, any officer or employee of the Office or 
    any person acting under the direction of the Superintendent, is not a compellable witness in 
    any civil proceedings in respect of any matter coming to their knowledge as a result of 
    exercising any of their powers or performing any of their duties or functions under this Act or 
    the Acts listed in the schedule.” 

### Interpretation of “supervisor and its staff”
- The term “supervisor and its staff” is interpreted to cover:
  - the head of the authority,
  - the governing body,
  - employees, and
  - any professional service providers who carry out tasks for the supervisory authority.
- The protection applies to actions taken and/or omissions made while discharging duties in good faith and continues after the term of appointment, engagement or employment has ended.
- Reference note present in source: “19”

### Government defense coverage
- The Government of Canada, through the Treasury Board, covers the costs of an employee's defense if the employee acted within the scope of his/her duties.
- The defense provided to the employee would be carried out by the lawyers of the Department of Justice.
- The Department of Justice may avail of specialized lawyers outside of the Department if needed.
- Assessment comment: “The forecited legal provisions foresee a sound framework of legal protection that covers all civil servants and their actions in the exercise of their functions (even after they have ceased to be civil servants) and provides for adequate coverage of the legal defense costs.”

### Assessment of Principle 2
- Conclusion: Materially Non-Compliant
- Comments highlighted by assessors:
  - OSFI operates under the authority of the Minister of Finance as part of the Government of Canada; this subordination functions as an accountability mechanism but is not confined to democratic accountability.
  - The relationship between OSFI and the Minister of Finance can potentially impact OSFI’s technical autonomy to set prudential policy and take supervisory actions or decisions on banks.

### Factors undermining OSFI independence (assessors’ findings)
- Multiple statutory and practical elements that may undermine independence:
  - Numerous sections of the BA and the TLCA provide for a role or a decision of the Minister of Finance in prudential matters, including licensing and revocation of banks, entry into the market and significant investments authorizations, intervention of banks, D-SIB designation and its consequences, information on supervisory matters, reporting to the Minister after all bank examinations and national security interventions.
  - Governor-in-Council regulation powers in prudential matters (including capital and liquidity requirements and general power to develop provisions of the Bank Act) are wide and could reduce or direct OSFI’s capacity to set prudential policy.
  - The legal role of the Minister of Finance as (i) responsible for all matters relating to the financial affairs of Canada, including the overall stability of the financial system; and (ii) as holding overarching authority over federal financial sector legislation may, in the broader context of other powers and mechanisms, place the Minister in a position where OSFI’s independence may be undermined.
  - Administrative practice of a dual focus: “Ministerial policy considerations” (which legally prevail) and “statutory and prudential considerations” by OSFI may cause the prudential goal of safety and soundness to be eclipsed or overridden by other public goals.
  - The practice is an administrative custom (not statutory) and could change; the Minister could process ministerial approvals independently or give little weight to OSFI’s considerations.
  - The institutional legal framework allows for a potentially significant increase in the influence of the DOF on OSFI and its prudential policy and supervisory decisions; this macro risk “has increased significantly” and aligns with previous IMF recommendations on separating legal processes for OSFI prudential decisions.
- Contextual considerations emphasized:
  - (i) The DOF is presided by a central political figure of the Cabinet (at the time of drafting the report, the Minister of Finance, who later resigned, was also the Deputy Prime Minister);
  - (ii) The DOF’s wide mandate includes general economic policy objectives and supporting general government policies which may clash with OSFI’s microprudential mandate (examples in the Mandate Letter include climate change fighting, reducing economic inequality and strengthening the middle class, fiscal sustainability, protection of financial consumers and small businesses, fostering housing affordability).

### Institutional and governance practice risks
- Potential government actions that could affect OSFI’s prudential autonomy:
  - The Minister of Finance could encroach on OSFI’s regulatory guidance by promoting the issuance of more Governor-in-Council regulations.
  - The government may impose political priorities and policy stances over OSFI’s prudential positions and influence the tone of the Superintendent’s term from the outside.

### Organizational autonomy and staffing
- Assessors’ view on delegated powers:
  - The Superintendent’s functions and powers as deputy head of OSFI by delegation of the Governor-in-Council (Section 11.2 FAA and Sections 11, 12 and 13 of OSFI Act) provide OSFI with enough organizational autonomy in principle.
  - Through delegation, the Superintendent (and OSFI’s officers by delegation) can hire and dismiss its own personnel, apply disciplinary sanctions, decide organizational changes, allocate functional responsibilities, and make staff changes and promotions.
- Caveats and recommendations by assessors:
  - The terms and conditions of the delegation may be used to undermine OSFI’s organizational autonomy.
  - The assessors consider that the best solution would be to directly confer those powers in legislation (for example, in the OSFI Act).
  - Restrictions imposed by the Public Service Commission (certain conditions that set out certain preferences of public service employees to private sector hires) have reduced flexibility needed by a specialized agency such as OSFI to acquire skills and professional profiles in a rapidly evolving and high complexity financial system.
- Reference pages in source: “CANADA 76” and “CANADA 77”

### Budget note (partial text from source)
- “OSFI’s budget is not dependent on government appropriations, rather, it is authorized by”

*Source: Excerpt from the provided PDF content.*

### section 23

### Section 23 — OSFI governance, cooperation, and permissible activities

### Budgetary autonomy and resource constraints
- OSFI’s budget is to be financed through assessments of federally regulated financial institutions and OSFI conducts budget planning as part of the annual Departmental Plan process, which includes planned budget for the next 3 fiscal years.
- The Departmental Plan is submitted to DOF, challenged and advised upon, and ultimately signed-off by the Minister of Finance; it is tabled by the President of the Treasury Board in Parliament.
- The requirement to prepare an annual Departmental Plan pursuant to Treasury Board policies undermines OSFI’s budgetary autonomy.
- Government-imposed fiscal restraints (wage freezes, hiring freezes, cost containment exercises) have been applied to OSFI despite cost recovery from regulated institutions.
- The lack of budgetary autonomy is impacting OSFI’s supervisory activities of core banking risks by constraining resources and limiting capacity to perform frequent and deep supervisory reviews (see CP9, CP15, CP17 and CP23).
- The assessment emphasizes that supervisory budgets should be stable in the long-term, predictable, and aligned with supervisory risk dynamics rather than with the fiscal position of general governments.

### Appointment, tenure, accountability, and legal protections
- OSFI’s Superintendents are appointed by the Governor-in-Council after a competitive hiring process coordinated by the Privy Council Office (Senior Personnel Secretariat) and include a public call for applicants.
- Superintendents serve for a fixed term of seven years and can only be removed with cause (for example, misconduct, breach of the code of ethics) by the Governor-in-Council or due to absence or incapacity.
- Where the Superintendent is removed, the Order in Council providing for the removal must be laid before Parliament.
- Canadian law provides a sound framework of legal protection covering civil servants and their actions and provides for coverage of legal defense costs.

### Transparency, internal governance, and quality assurance
- Formal accountability mechanisms:
  - Deposit by the Minister of Finance of OSFI’s Annual Report before each House of Parliament.
  - External audit of financial statements by a private firm.
  - Efficiency audits by the OAG.
- OSFI publishes Annual Report, Departmental Plans, Departmental Results Reports, ARO updates semi-annually, and three-year Strategic Plans on its webpage.
- Internal governance:
  - The FESP outlines regulatory and supervisory powers retained by the Superintendent and those assigned within the organization.
  - Approval Authorities internal decision-making framework and job descriptions support timely supervisory decisions and emergency provisions.
  - ERM framework follows a Three Lines Model, supervised by ERM committees and internal audit.
- Conflict of interest, use of information, and confidentiality rules are sound; staff credibility and integrity are well-established.
- Supervisory planning is underpinned by macro risk vision, prior supervisory outcomes, timing of reviews, strategic plan, and human resources plan.
- The Supervisory Strategy and Planning Standard requires documented work plans for supervisory priorities.
- Quality Assurance by SQAD emphasizes consistency of methodologies and outcomes; Group Rating Committees foster joint discussion; SQAD ex post Quality Assurance Reviews identify pain points and improvements.

### Cooperation and collaboration (Principle 3) — domestic coordination (EC1, EC2, EC6)
- OSFI is an integrated supervisor for federally regulated financial institutions (banks, insurers, trust and loan companies, cooperative credit associations, fraternal benefit societies and private pension plans), reducing need for sectoral formal cooperation but increasing need for internal coordination to avoid silos.
- Key federal coordination forums and arrangements:
  - FISC: constituted under Section 18, OSFI Act; Subsection 18(4) grants members access to “any information on matters relating directly to the supervision of financial institutions...”; chaired by the Superintendent; meets at least quarterly and more as needed (e.g., working groups, ad hoc meetings, increased cadence during COVID-19).
    - FISC responsible for coordination on strategies and action plans for problem institutions and emerging issues, and for regulatory policy discussions.
    - There is also a “sub-FISC” of deputies; both meet at least quarterly; ad hoc and thematic meetings occur; DSB buffer level discussed (see CP16).
  - SAC: non-statutory committee chaired by the Deputy Minister of Finance with participation from FISC agencies; discusses financial sector policy issues and informs advice to the Minister of Finance.
    - Supported by working groups on Stablecoins, Housing Finance, Deposit Insurance Review, Catastrophe Risk in Insurance, Legislative Review.
  - OSFI representation on the CDIC Board of Directors (public sector directors include the Superintendent of Financial Institutions or a deputy), with obligations under the FAA.
  - OSFI–CDIC Strategic Alliance Agreement to coordinate activities, consultation and exchange of information; Guide to Intervention outlines coordination during intervention to insolvency stages.
  - OSFI–BoC Information Sharing Agreement on payment systems relevant to safety and soundness.
- Practical cooperation:
  - Frequent file-specific meetings and monthly (or more frequent) “Case Review” meetings with DOF on regulatory approval applications (e.g., incorporations of new banks).
  - OSFI conducts Macro Stress Tests with the BoC (including provincial inputs such as AMF); results shared at FISC; FISC/Sub-FISC used to discuss calibration of macroprudential tools (DSB, MQR).
  - OSFI shares macroprudential views in FISC, SAC, HoA; HoA includes a systemic risk surveillance sub-committee with BoC experts.
- Recovery and resolution coordination (EC6):
  - OSFI leads assessment of Recovery Plans; CDIC is the resolution authority and leads resolution plans.
  - All systemically important banks (including two global systemically important banks) are required to submit recovery plans; other banks submit on a risk basis or specific criteria.
  - OSFI collaborated with CDIC and BoC to develop recovery planning guidance.
  - OSFI–CDIC Strategic Alliance Agreement and quarterly information sharing; examples of information shared include detailed ratings reports, intervention reports, supervisory letters and responses.
  - OSFI and CDIC host annual bank-specific Crisis Management Groups (CMGs) for G-SIBs and bi-annual for other D-SIBs; agendas include systemic events, lessons learned, emerging risks (e.g., technological risk), and resolution plan updates.
  - Assessors reviewed recent CMG agendas and content and found the level of information and topics very satisfactory.

### Cooperation and collaboration — foreign cooperation and confidentiality (EC3, EC4, EC5)
- OSFI has MoUs with more than 30 foreign supervisory authorities and more than 20 MoUs specifically concerning the Alternative Investment Fund Managers Directive (AIFMD).
- OSFI routinely exchanges information with foreign home and host regulators under MoUs and participates in collaborative on-site reviews in host jurisdictions.
- Before entering MoUs OSFI assesses potential partners via a questionnaire on legal regimes, practices, and confidentiality capability; if unsatisfied, OSFI will not enter an MoU.
- MoUs contain:
  - Provisions obliging confidentiality and exclusive use for lawful supervisory purposes.
  - Employee confidentiality obligations and clauses requiring the other regulator to advise OSFI if compelled to disclose information (e.g., by a court).
- OSFI maintains regular meetings and ad hoc discussions with key host regulators (e.g., Federal Reserve, Office of the Comptroller of the Currency).
- Assessors judged cooperation with main foreign supervisors of material subsidiaries (US and UK) as excellent; cooperation with other supervisors is adequate and risk-based.

### Federal–provincial coordination deficiencies and confidential information barriers
- The only formal federal-provincial forum noted is the HoA committee (chaired by the Governor of the BoC) for securities markets, meeting semi-annually and including DOF, OSFI, four largest provincial securities regulators (Alberta, British Columbia, Ontario, and Québec) and the Chair of the Canadian Securities Administrators.
- There is no federal-provincial forum for deposit-taking supervision issues.
- OSFI engages provincially via CUPSA (observer member) to communicate supervisory priorities to provincial credit union supervisors; CUPSA is an information exchange forum on best practices.
- The lack of federal-provincial coordination has:
  - Resulted in deficiencies in articulating a system-wide view and impaired exchange of institution-specific information (e.g., OSFI does not share confidential prudential data with the Québécois AMF, potentially limiting supervision of the Desjardins Group).
  - Been mitigated since 2019 through improved policy and regulatory coordination, policy communication, and informal cooperation.
- Legal confidentiality barriers (Subsection 22(1) OSFI Act) limit exchange of institution-specific information with provincial authorities because of risks that OSFI’s Prescribed Supervisory Information (PSI) could be forcefully disclosed during judicial proceedings in which provincial authorities are parties.
- Suggested remedial action includes consultation with relevant branches of the judiciary to consider court procedural improvements to eliminate confidentiality risks.
- Recommendation from assessors:
  - OSFI should consider promoting establishment of a joint provincial-federal taskforce to determine legal barriers to sharing institution-specific information and design a roadmap to enable safe exchange of such information.

### Recommendations to reinforce OSFI’s autonomy and capacity
- Foster OSFI’s technical autonomy so its discretion to set prudential policy and take supervisory actions is fully protected from potential government influence. Recommended legislative changes include:
  - Reduce accountability towards the Minister of Finance strictly to aggregate reports on the discharge of OSFI’s duties and to what is necessary to comply with constitutional requirements on the use of public money, attainment of common public policy objectives and rendering of accounts towards the legislature.
  - Circumscribe Interaction with the DOF to matters of common interest (banking legislation reform, macroprudential and financial policy, resolution involving public monies), while protecting OSFI’s full discretion to set prudential policy and take supervisory decisions on banks from political influence. Microprudential policy and decisions should be under exclusive purview of OSFI; DOF involvement should be limited to legislative reform or Governor-in-Council regulatory projects, with OSFI’s participation and procedural incentives to consider its input codified in legislation.
  - Reinforce in legislation (OSFI Act, Bank Act) the technical autonomy of the Superintendent by explicitly codifying that the Superintendent has full discretion to set prudential policy and take supervisory actions or decisions on banks and that no other branch, division or agency of the Government of Canada may instruct or influence it on these matters.
  - Review authorizations and decisions requiring Ministerial approval under the Bank Act and the TLCA to grant OSFI full discretion when purely prudential considerations prevail. Where DOF is involved, OSFI should be legally entitled to prepare a draft decision and opinion and have due regard to its considerations.
  - Fix in law the scope of matters OSFI can regulate, including the development and technical detailing of all prudential matters related to the safety and soundness of banks, to address potential encroachment by Governor-in-Council regulatory powers.
- Ensure Public Service Commission delegation terms do not undermine OSFI’s organizational autonomy; consider conferring Public Service Employment Act powers directly to OSFI in legislation (for example, OSFI Act).
- Protect OSFI’s budgetary autonomy by:
  - Enabling OSFI to define its budget and table it in Parliament without approval of the Minister of Finance; OSFI’s budget and correlative assessments on regulated entities would be subject directly to parliamentary control.
  - If full budgetary independence is unfeasible, adjust the framework to reduce Minister of Finance influence by:
    - Making the Minister’s role consultative rather than approval-based.
    - If ministerial approval remains, require it to be granted unless specific and predefined circumstances justify intervention, narrowly defined to include:
      - Legal compliance issues where proposed budget conflicts with non-discretionary statutory limits.
      - Material operational inefficiencies identified by an independent review.
      - Extraordinary national economic crises requiring temporary constraints.
    - Ensure OSFI’s budget remains subject to parliamentary oversight, potentially via a specialized parliamentary committee for scrutiny.
  - Attribute to OSFI the capacity to set its salary scales and compensation schemes for executive and non-executive personnel, subject to appropriate audit from the Canadian public audit or comptrollers.

### Permissible activities (Principle 4 — EC1 findings)
- The term “bank” is clearly defined in section 2 of the Bank Act to mean “a bank listed in Schedule I or II”, and includes federal credit unions; only entities licensed by the Minister of Finance under Schedule I or II are banks.
  - Schedule I: domestic banks.
  - Schedule II: subsidiaries of foreign banks.
  - Schedule III lists authorized foreign banks (foreign bank branches) and section 2 defines a foreign bank more broadly.
- Foreign banks are not allowed to accept deposits in Canada unless they set up a “full-service” branch, which may accept deposits in Canada of $150,000 or greater (section 545 BA); these deposits are not insured by CDIC. It is possible to opt-out from deposit insurance if all deposits taken are $150,000 or greater.
- Federal deposit-taking institutions are defined by Section 8 of CDIC Act:
  - “Federal institutions
    8 For the purposes of this Act, the following are federal institutions:
    (a) a bank;
    (b) a company to which the Trust and Loan Companies Act applies; and
    (c) a retail association within the meaning of regulations made under the Cooperative Credit Associations Act.”
- Permitted activities of federal trust and loan companies are defined in the TLCA; trust companies can act as trustees in Canada and are subject to a limit on commercial lending; trust and loan companies with permitted activities similar to banks can be provincially regulated.
- Credit unions can be licensed provincially as well as federally and are allowed to perform the same activities as banks; most credit unions are provincially regulated.

*Source: 1canea2025007-source-pdf — section 23*

### Part VIII (Business and Powers) of the Bank Act defines the permissible activities of banks.

### Part VIII (Business and Powers) of the Bank Act defines the permissible activities of banks.

### Permissible business of banking (subsection 409(2))
- For greater certainty, the business of banking includes:
  - (a) providing any financial service;
  - (b) acting as a financial agent;
  - (c) providing investment counselling services and portfolio management services; and
  - (d) issuing payment, credit or charge cards and, in cooperation with others including other financial institutions, operating a payment, credit or charge card plan.

### Additional activities a bank may engage in (section 410(1))
- A bank may:
  - (a) hold, manage and otherwise deal with real property;
  - (b) provide prescribed bank-related data processing services;
  - (c) outside Canada or, with the prior written approval of the Minister, in Canada, engage in any of the following activities, namely,
    - (i) collecting, manipulating and transmitting
      - (A) information that is primarily financial or economic in nature,
      - (B) information that relates to the business of a permitted entity, as defined in subsection 464(1), or
      - (C) any other information that the Minister may, by order, specify,
    - (ii) providing advisory or other services in the design, development or implementation of information management systems,
    - (iii) designing, developing or marketing computer software, and
    - (iv) designing, developing, manufacturing or selling, as an ancillary activity to any activity referred to in any of subparagraphs (i) to (iii) that the bank is engaging in, computer equipment integral to the provision of information services related to the business of financial institutions or to the provision of financial services;
  - (c.1) with the prior written approval of the Minister, develop, design, hold, manage, manufacture, sell or otherwise deal with data transmission systems, information sites, communication devices or information platforms or portals that are used
    - (i) to provide information that is primarily financial or economic in nature,
    - (ii) to provide information that relates to the business of a permitted entity, as defined in subsection 464(1), or
    - (iii) for a prescribed purpose or in prescribed circumstances;
  - (c.2) engage, under prescribed terms and conditions, if any are prescribed, in specialized business management or advisory services;
  - (d) promote merchandise and services to the holders of any payment, credit or charge card issued by the bank;
  - (e) engage in the sale of
    - (i) tickets, including lottery tickets, on a non-profit public service basis in connection with special, temporary and infrequent non-commercial celebrations or projects that are of local, municipal, provincial or national interest,
    - (ii) urban transit tickets, and
    - (iii) tickets in respect of a lottery sponsored by the federal government or a provincial or municipal government or an agency of any such government or governments;
  - (f) act as a custodian of property;
  - (g) act as receiver, liquidator or sequestrator; and
  - (h) provide identification, authentication or verification services.

### Deposit acceptance (section 437)
- A bank may, without the intervention of any other person,
  - (a) accept a deposit from any person whether or not the person is qualified by law to enter into contracts; and
  - (b) pay all or part of the principal of the deposit and all or part of the interest thereon to or to the order of that person.
- Exception (437(2)):
  - Paragraph (1)(b) does not apply if, before payment, the money deposited in the bank pursuant to paragraph (1)(a) is claimed by some other person
    - (a) in any action or proceeding to which the bank is a party and in respect of which service of a writ or other process originating that action or proceeding has been made on the bank, or
    - (b) in any other action or proceeding pursuant to which an injunction or order made by the court requiring the bank not to make payment of that money or make payment thereof to some person other than the depositor has been served on the bank,
  - and, in the case of any such claim so made, the money so deposited may be paid to the depositor with the consent.
- Execution of trust (437(3)):
  - A bank is not bound to see to the execution of any trust to which any deposit made under the authority of this Act is subject.
- Payment when bank has notice of trust (437(4)):
  - Subsection (3) applies regardless of whether the trust is express or arises by the operation of law, and it applies even when the bank has notice of the trust if it acts on the order of or under the authority of the holder or holders of the account into which the deposit is made.

### Foreign bank branches (sections 538–556, 540, 545)
- Foreign bank branches have the same powers and are subject to the same restrictions as Schedule I and II banks, except:
  - A foreign bank branch does not have the ability to take retail deposits (i.e., deposits of less than $150,000).
  - A “full-service” foreign bank branch is permitted to accept deposits in Canada of $150,000 or greater (section 545).
  - A “lending” foreign bank branch is generally prohibited from accepting deposits (section 540).

### Permissible investments (Part IX) and standards
- Part IX sets out permissible investment powers of banks.
- All investments by a bank in an entity are subject to the “reasonable and prudent person” standard (section 465) with a view to ensuring that banks do not expose themselves to undue financial or other risks via their investments.
- All acquisitions of substantial investments in, and/or control of, a single entity by a bank are subject to specific rules.

### Foreign bank investments (Part XII) and self-dealing (Part XI)
- Part XII sets out permitted investments in Canada for a foreign bank without a branch, with an establishment and without an establishment; permitted investments generally mirror those permitted to a Schedule I or II bank.
- Part XI sets out limited permissible transactions for banks with related parties.

### OSFI guidance and legislative advisories
- OSFI issues Legislative Advisories to clarify its position regarding certain policy issues or describe how OSFI administers and interprets provisions of the BA and TLCA, regulations, or guidelines.
- Example: OSFI Advisory: Business and Powers – Ownership Interests in Commodities provides clarity on circumstances in which taking an ownership interest in commodities would be a permissible activity and prudential standards to be followed.

### Use of the word “bank” and naming restrictions (EC3)
- The use of the word “bank” and derivations (e.g., “banking”) in a name, including domain names, is limited to licensed and supervised institutions where the general public might otherwise be misled.
- The Bank Act generally restricts use of “bank,” “banker” or “banking” in a name or to describe a business in Canada to banks and authorized foreign banks (section 983); this includes equivalents in any language (subsection 983(13)).
- A subsidiary of a bank may use the name of its parent bank in its name (subsection 983(5)).
- Exception: a person may use “bank,” “banker” or “banking” in relation to a business that is not engaged in financial activities if it is unlikely the general public would be misled (subsection 983(5.1)).
- Crown corporations and provincial crown corporations may be exempted under other Acts of Parliament (subsection 983(2) BA).
- OSFI’s supervision on misuse of the word “bank” is not proactive; OSFI normally reacts to complaints or findings.

### Deposit-taking framework and licensing environment (EC4, EC5, Principle 4, Principle 5, EC1)
- Deposit-taking is reserved for institutions that are licensed and subject to supervision as banks.
- The vast majority of deposit-taking from the public is undertaken by federally regulated financial institutions (“FRFI,” for example, banks, including federal credit unions, and trust and loan companies). Deposits may also be taken by provincially regulated institutions (for example, provincial credit unions).
- Institutions incorporated pursuant to the Bank Act and Trust and Loan Companies Act are subject to the same licensing requirements and ongoing supervision/regulation as banks, including the requirement to obtain OSFI’s approval to take deposits.
- Federal incorporating statutes (Canada Business Corporations Act, Canada Not-for-profit Corporations Act, Canada Cooperatives Act) prohibit federal corporations from carrying on the business of a bank or other entity to which the FRFI legislation applies.
- Provincial legislation also restricts deposit-taking; example: in Ontario, only banks, federal trust and loan companies, credit unions and caisses populaires are permitted to engage in deposit-taking.
- Exception: ATB Financial is a crown corporation of the Province of Alberta and is regulated by the Alberta Superintendent of Financial Institutions under the ATB Financial Act.
- Fintech platforms (example names in source) offer deposit-related services through partnerships with banks; CDIC insurance covering these deposits is provided under the CDIC membership of the partner banks, not the fintech companies themselves.
- Provincial securities legislation restricts deposit taking via the definition of “security,” which includes any evidence of indebtedness, but excludes evidence of a deposit issued by a bank, trust or loan corporation or credit union; for entities not exempted, offering a deposit would have to be qualified for sale by prospectus or by an exemption.

- Public availability of licensed banks (EC5):
  - The OSFI website makes available a current list of all banks, foreign bank branches and foreign bank representative offices operating in Canada.
  - The Bank Act’s Schedules I, II and III list all banks and foreign bank branches.
  - OSFI’s public register contains information available to the public for a fee on letters patent and authorizations, banks’ contact information, Board of Directors information, the external auditor's firm name, and other information specified in s.634(1) of the Bank Act; copies may be requested via OSFI’s Access to Information and Privacy team.
  - Provincial deposit-taking institutions’ information is available in provincial public registers (examples in source: Québec and Alberta registers).

- Assessment of Principle 4: Compliant.
  - Comments include definitions: “bank” defined in section 2 to mean “a bank listed in Schedule I or II,” and includes federal credit unions; Schedule I = domestic banks, Schedule II = subsidiaries of foreign banks.
  - Schedule III lists authorized foreign banks (foreign bank branches).
  - Foreign banks are not allowed to accept deposits in Canada unless they set up a “full-service” branch, which may accept deposits in Canada of $150,000 or greater (section 545 BA); these deposits are not insured by CDIC. It is possible to opt-out from deposit insurance if all deposits taken are $150,000 or greater.
  - Federal deposit taking institutions are defined by Section 8 of CDIC Act:
    - “Federal institutions
      8 For the purposes of this Act, the following are federal institutions:
      (a) a bank;
      (b) a company to which the Trust and Loan Companies Act applies; and
      (c) a retail association within the meaning of regulations made under the Cooperative Credit Associations Act.”
  - Permitted activities of federal trust and loan companies are defined in the Trust and Loan Companies Act; trust companies are the only deposit taking institutions able to act as a trustee in Canada and are subject to a limit on their commercial lending.
  - Credit unions can be licensed provincially as well as federally and are allowed to perform the same activities as banks.

### Licensing process and authority (EC1, Principle 5)
- Licensing authority and process:
  - Two-step application process to incorporate a bank in Canada:
    - Step 1: obtain letters patent of incorporation issued by the Minister of Finance (section 22) upon recommendation of the Superintendent. An application for letters patent must be filed with the Superintendent together with such information, material and evidence as the Superintendent may require (subsection 25(1)).
    - Step 2: obtain an order to commence and carry on business, issued by the Superintendent (section 49). A newly licensed bank may not commence operations (section 48(1)) until it completes the second step.
  - For companies continuing as banks from other federal statutes, letters patent of continuance and the order to commence and carry on business are generally issued at the same time.
- OSFI’s assessment practices for new entrants:
  - OSFI realizes a lengthy and thorough review of new entrants with several phases: submissions by the applicant, analysis of submissions and drafting of an internal supervisory plan, internal consultation and external consultation, closure of recommendations, external consultation and granting/conditioning/recommendation.
  - Review areas include business and strategic plans, Board and senior management suitability, credit risk, operational risk, liquidity and funding risks, capital position, IRRBB, AML/CFT and governance, involving staff from the Approvals Division, supervisors and specialized subject-matter experts.
  - Findings and recommendations are communicated to the new entrant for remediation before or after authorization; commitments are received from the new entrant as a way to condition the first steps as a federally regulated bank (examples of commitments include: not changing the business plan without OSFI’s consent, specific ad personam capital and leverage ratios, promises regarding improvements in credit and operational risk management, governance or liquidity risk).
  - Conditions on the order to commence and carry on business (or on the letters patent) are very infrequent; assessors were provided with a decade-old example of conditions imposed by the Minister on a significant interest approval to ensure OSFI’s ability to supervise the bank after acquisition.

- Withdrawal/revocation of a bank license:
  - Can be voluntarily initiated by the bank or initiated by the Superintendent.
  - Voluntary continuance under other federal legislation requires Ministerial approval (section 39.1); upon continuance the entity would no longer be a bank (section 39.3).
  - The Bank Act sets requirements for Ministerial approval in respect of voluntary liquidation & dissolution (sections 342–346).

*Source: 1canea2025007-source-pdf - Part VIII (Business and Powers) of the Bank Act defines the permissible activities of banks.*

### section 347).

### section 347)

### License revocation initiated by the Superintendent
- The Bank Act gives the Superintendent authority to take control of a “problem” bank (for example, if, in the Superintendent’s opinion, the circumstances of the bank are prejudicial to the interests of the bank’s depositors and creditors).
- When a bank is under the Superintendent’s control, the Superintendent may request the Attorney General of Canada to apply for a winding-up order of the bank (section 651).

### Granting a Branch License to a Foreign Bank
- Two-step application process for establishing a foreign bank branch in Canada:
  - Step 1: Obtain an order permitting the foreign bank to establish a branch in Canada, issued by the Minister (subsection 524(1)), upon the Superintendent’s recommendation.
  - The Minister may only make such an order if, after consultation with the Superintendent, the Minister is of the opinion that the applicant is a bank in its home jurisdiction and is regulated in a manner acceptable to the Superintendent and the applicant’s principal activity is financial services or services permitted by the Bank Act if they were provided by a bank in Canada (subsection 524(4)).
  - Step 2: After receiving an order, a new branch may not commence operations (subsection 534(2)) until it obtains an order approving the commencement and carrying on of business in Canada by the branch, issued by the Superintendent (subsection 534(1)).

### Withdrawing a Branch License of a Foreign Bank
- Withdrawal or revocation of a foreign branch license can be voluntary or imposed.
- A foreign bank branch wishing to discontinue operations in Canada must seek the approval of the Superintendent for the release of its assets maintained on deposit in Canada (subsection 599(1)). Upon receipt of approval for this release, the subsection 524(1) order is deemed to be revoked.
- In problem situations, the Superintendent may request the Attorney General of Canada to apply for a winding up order of a foreign bank branch where the assets of the branch are under the Superintendent’s control (section 621).
- The Minister or Superintendent can also revoke any approval (section 973.03).

### Consideration of OSFI’s Views
- Minister issues letters patent of incorporation and orders establishing foreign bank branches in practice based on OSFI’s recommendation, as OSFI reviews licensing applications and makes recommendations to the Minister.
- The Bank Act states the Minister must take into account the Superintendent’s opinion in respect of certain matters (paragraph 27(g)).
- A newly licensed bank may not commence operations until the Superintendent approves the issuance of an order to commence and carry on business; similar consultation requirements apply for foreign bank branches (subsection 524(4)).

### Provision of Information
- A bank/branch application shall be filed with the Superintendent (subsections 25(1) and 525(1)).
- The Superintendent (OSFI) possesses all application materials and is the point of contact with the applicant throughout the licensing process, using this information to make its recommendation to the Minister.

### Prudential Conditions or Limitations
- The Minister may impose terms and conditions in respect of the issuance of letters patent and orders to establish a branch as the Minister considers appropriate (subsections 28(3) and 527(3)), typically on recommendation of the Superintendent.
- An order approving the commencement and carrying on of business by a bank or foreign bank branch may contain conditions or limitations consistent with the Bank Act as the Superintendent deems expedient and necessary (section 53 and subsection 534(5)).
- Minister’s approval is required where a person would acquire a significant interest directly or indirectly and/or acquire control of a new bank (sections 373 and 377.1); the Minister may impose terms and conditions for ownership approval (section 397).
- The Minister or Superintendent may impose any terms, conditions, or undertakings they consider appropriate in relation to any approval (section 973.02).
- In practice, OSFI obtains commitments and undertakings in new entry applications:
  - OSFI requires a support principle letter signed by controlling shareholder(s) acknowledging expectations to act as an ongoing source of financial, managerial and operational support.
  - Controlling shareholders may be required to undertake to maintain a sufficient amount of common equity to maintain certain capital levels, risk-based ratios or leverage ratios; the Superintendent can apply to a court for an order directing compliance with terms of such an undertaking (paragraph 973.04(2)(b)).
  - All new banks are required to acknowledge and commit to initial business plans by CEO written commitment: if intending to deviate materially from the Business Plan, the bank will advise its OSFI LS by written notice early enough to allow OSFI sufficient time to assess supervisory and regulatory risk impact; this commitment letter has been expanded to permit enhanced monitoring by OSFI.
  - OSFI can designate persons or entities as related parties (see CP20) or require creation of a bank holding company under the Bank Act to ensure consolidated supervision where contagion risk exists.
  - Information undertakings by the ultimate controlling shareholder provide access to information on group entities that are financial in nature and notifications where a financial services entity is to be acquired by a group entity not controlled by the bank.
- A bank will only be able to accept deposits when authorized by the Superintendent, reflected in the order to commence and carry on business (section 53).
- For foreign bank branches, the Minister’s order permitting establishment in Canada may restrict the branch from taking deposits (subsection 524(2)).
- The issuance of letters patent by the Minister and the order to commence and carry on business by the Superintendent are discretionary powers.

### EC2 — Laws or regulations for licensing authority powers (Description and Findings)
- EC2: Laws or regulations give the licensing authority power to set criteria for licensing banks; authority to reject an application where criteria are not fulfilled or information is inadequate; power to revoke a license if based on false information.
- The Bank Act sets out criteria the Minister will take into account before issuing letters patent to incorporate a bank, including “all matters that the Minister considers relevant to the application” (section 27).

- Matters for Consideration (section 27) that the Minister shall take into account before issuing letters patent to incorporate a bank:
  - (a) The nature and sufficiency of the financial resources of the applicant or applicants as a source of continuing financial support for the bank;
  - (b) the soundness and feasibility of the plans of the applicant or applicants for the future conduct and development of the business of the bank;
  - (c) the business record and experience of the applicant or applicants;
  - (d) The character and integrity of the applicant or applicants or, if the applicant or any of the applicants is a body corporate, its reputation for being operated in a manner that is consistent with the standards of good character and integrity;
  - (e) Whether the bank will be operated responsibly by persons with the competence and experience suitable for involvement in the operation of a financial institution;
  - (f) The impact of any integration of the businesses and operations of the applicant or applicants with those of the bank on the conduct of those businesses and operations;
  - (g) The opinion of the Superintendent regarding the extent to which the proposed corporate structure of the applicant or applicants and their affiliates may affect the supervision and regulation of the bank, having regard to
    - (i) The nature and extent of the proposed financial services activities to be carried out by the bank and its affiliates, and
    - (ii) The nature and degree of supervision and regulation applying to the proposed financial services activities to be carried out by the affiliates of the bank;
  - (h) If the bank will be a federal credit union, that it will be organized and carry on business on a cooperative basis in accordance with section 12.1; and
  - (i) The best interests of the financial system in Canada including, if the bank will be a federal credit union, the best interests of the cooperative financial system in Canada.

- OSFI’s application analysis and requirements:
  - OSFI takes into account legislative criteria and other matters it deems relevant when developing a recommendation to the Minister.
  - The Bank Act allows the Minister to consider all matters relevant in the circumstances, including national security and Canada’s international relations and international legal obligations (subsection 973.01(1)).
  - OSFI’s Internal Risk Tolerance Framework for New Entrants: OSFI should have a low risk tolerance for loss to depositors and other creditors; an applicant’s initial base case business plan must demonstrate that capital is sufficient to cover any losses expected during either the first three years of operation of the new bank or until the bank begins generating a profit, whichever comes later.
  - The Internal Risk Tolerance Framework contains expectations classified by impact category, covering foreign regulatory and supervisory regime, business strategy, capital, access to external sources of capital, earnings, liquidity, stress testing, risk controls, three lines of defense, corporate governance, and zero tolerance for national security and AML/CFT matters.
  - For a proposed bank that would be a subsidiary of a non-WTO member foreign bank, the Minister may only issue letters patent if reciprocal treatment is accorded to banks to which the Bank Act applies in the foreign bank’s home jurisdiction (section 24).
  - The Superintendent may request such information, material and evidence as required in respect of an application (section 25); an applicant must publish notice of its intention to apply to incorporate a bank (section 25).
  - The Superintendent must not issue an order to commence and carry on business until satisfied that “all other relevant requirements of this Act have been complied with” (section 52).
  - The Superintendent may consider all matters relevant, including national security and Canada’s international relations and international legal obligations (subsection 973.01(2)).
  - The Bank Act prevents governments, or agencies thereof, from applying to incorporate a bank (section 23). Other ownership restrictions are set out in Part VII.
  - OSFI’s Guide for Incorporating Banks sets out prudential and legislative requirements and information submission procedures; OSFI can request additional information as circumstances require (section 25).
  - In practice, specific information is requested relevant to the proposed business model and new and emerging risks.

### Licensing Criteria — Foreign Bank Branches
- The Bank Act sets out criteria the Minister will take into account before making an order to establish a foreign bank branch, including “all matters that the Minister considers relevant to the application” (section 526).
- OSFI considers legislative criteria and other relevant matters in developing recommendations; subsection 973.01(1) is applicable.
- OSFI’s risk tolerance for foreign bank branch entry is higher than for new incorporations because a branch is not a separate legal entity and is permitted to accept only sophisticated depositors (a branch is only permitted to accept deposits greater than or equal to $150,000).
- The Minister may only make an order if, where the application is by a non-WTO member foreign bank, reciprocal treatment is accorded in the foreign bank’s home jurisdiction (subsection 524(3)).
- The Minister may only make an order if, after consultation with the Superintendent, the Minister is of the opinion that the applicant is a bank in its home jurisdiction and is regulated in a manner acceptable to the Superintendent and its principal activity is the provision of financial services or services that would be permitted by the Bank Act if provided by a bank in Canada (subsection 524(4)).
- The Bank Act prohibits a foreign bank from establishing a branch in Canada if the foreign bank or any of its affiliates/substantial investments engage in personal property leasing activities in Canada in which a bank or its investments would not be permitted to engage (section 524.1).
- The Superintendent may request such information, material and evidence as required for an order to establish a branch; an applicant must publish notice of its intention to apply for an order to establish a branch (section 525).
- The Superintendent may make an order to commence and carry on business only if satisfied that the branch has deposited specified assets in Canada, submitted a power of attorney for the branch’s principal officer and complied with all other relevant requirements of the Bank Act (subsection 534(3)).
- OSFI’s Guide to Foreign Bank Branching sets out legislative criteria and required information and procedures; OSFI can request additional information as circumstances require.

*Source: section 347).*

### section 525).

### section 525)

### Power to Reject Applications
- The Bank Act sets out that the Minister and Superintendent “may” issue letters patent and the order to commence and carry on business, respectively, so this power may be exercised with discretion where criteria are not met (sections 22 and 49).
- The Superintendent must not make an order approving the commencement and carrying on of business by a bank more than one year after the day on which the bank comes into existence (subsection 52(2)); if requirements are not met and the year timeframe expires, the letters patent will lapse and the bank will cease to exist (section 57).
- For branch applications, the Minister and Superintendent “may” issue an order to establish a branch and the order to commence and carry on business, respectively (subsection 524(1) and 534(1)).
- The Superintendent must not make an order approving the commencement and carrying on of business by a branch more than one year after the day on which the branch is established by Ministerial order (subsection 534(9)); if requirements are not met and the year timeframe expires, the order establishing the branch is revoked (subsection 534(10)).

### Revocation in the Case of False Information
- The Bank Act provides authority to the Minister and Superintendent to revoke any approval (section 973.03).
- It is an offence under the Bank Act to knowingly provide false information in relation to any matter under the Act or Regulations; punishments include fines and prison (sections 980, 980.1 and 985).

### EC3 — Structures Will Not Hinder Supervision or Corrective Measures; Shell Banks Prohibited
- EC3 requirement: licensing authority determines that proposed legal, managerial, operational and ownership structures of the bank and its wider group will not hinder effective:
  - (a) Supervision on both a solo and a consolidated basis; and
  - (b) Implementation of corrective measures in the future.
- Shell banks must not be licensed.

Description and Findings re EC3
- OSFI determines whether the structure of the bank and its group will not hinder effective supervision and, where appropriate, the effective implementation of corrective measures.
- Before issuing letters patent to incorporate a bank, the Minister must take into account matters including the Superintendent’s opinion regarding how the proposed corporate structure of the applicant and affiliates may affect supervision and regulation, having regard to the nature and extent of proposed financial services activities and the nature and degree of supervision and regulation applying to affiliates (paragraph 27(g)).
- OSFI assesses factors including: proposed activities of the bank, the predominant nature of the group’s financial activities, the independence of the bank, and regulatory oversight of the group (Instruction Guide for Incorporating Banks).
- OSFI considers parallel-banking risks (self-dealing, group-wide risk, and contagion) and applies mechanisms such as designation of related parties, business plan commitments, requirement for a bank holding company, and information undertakings to address supervision gaps and obtain consolidated-group risk visibility.

### Managerial and Operational Assessment (Banks)
- OSFI’s Corporate Governance Guideline sets expectations for board, senior management relationships and monitoring systems; new banks are expected to comply at inception.
- OSFI analyzes board and senior management composition and draft mandates, policies and procedures (Guide for Incorporating Banks) to determine supervisory capability.
- Guideline B-10 - Third-Party Risk Management: expectations for outsourcing and that supervisory powers should not be constrained regardless of whether activity is in-house or outsourced.
- OSFI determines, where appropriate, that structures will not hinder future corrective measures.

### Foreign Bank Branches — Home Regulator Reliance and Assessment
- The Minister may make an order permitting a foreign bank to establish a branch only if, after consultation with the Superintendent, the applicant is a bank in its home jurisdiction and is regulated in a manner acceptable to the Superintendent (subsection 524(4)).
- OSFI assesses home jurisdiction supervision framework to determine if OSFI can effectively supervise the branch; factors include MoUs with home regulator, BIS and BCBS memberships, and recent FSAP reports.
- Guide to Foreign Bank Branching: OSFI receives ownership and financial strength information, including organization chart for corporate group, and assesses transparency/complexity.

Managerial/Operational (Branches)
- OSFI’s Corporate Governance Guideline recognizes branches do not have boards; OSFI looks to Branch Management to oversee branch business in Canada (Guideline E-4).
- Branch Management may include the principal officer of a foreign bank Branch and senior officers located in or outside Canada.
- OSFI analyzes Branch Management roles as set out in draft mandates, policies and procedures to determine supervisory ability.
- Where Branch Management does not have direct responsibility for a significant function, this should be documented in written mandates/policies or service level agreements; such arrangements are treated as outsourcing under Guideline B-10.

### Shell Banks — Prohibitions and Domestic Requirements
Banks
- Head office of a bank is to be situated in Canada (paragraph 28(1)(b) and section 237) and shareholders’ meetings must be held in Canada (section 136).
- At least one half of the directors of a bank that is a subsidiary of a foreign bank and a majority of the directors of any other bank must be resident Canadians (subsection 159(2)).
- Directors must not transact business at meetings unless, for a foreign-bank subsidiary, at least one half of directors present are resident Canadians, or otherwise the majority present are resident Canadians (section 183).
- The CEO must be ordinarily resident in Canada (section 196).
- Bank records are to be kept in Canada (subsection 239(1)), except for a bank that is a subsidiary of a foreign bank domiciled in a country in which a trade agreement listed in Schedule IV is applicable or of a regulated foreign entity (subsection 239(3.1)).
- The Superintendent has the power to require a bank to process information in Canada (section 245).
- The bank’s central securities register must be maintained in Canada (section 251).

Foreign Bank Branches
- The principal office of the branch must be located in Canada (sections 527 and 535).
- The branch must maintain a foreign bank branch deposit in Canada with a Canadian financial institution approved by the Superintendent (subsection 534(4) and section 582).
- In specific circumstances OSFI has required branches to maintain additional assets in Canada.
- The branch’s Principal Officer must be ordinarily resident in Canada and branch records must be kept in Canada (section 536 and subsection 597(2)).

### EC4 — Identification and Suitability of Major Shareholders; Ownership Transparency
- EC4 requirement: licensing authority identifies and determines the suitability of the bank’s major shareholders (including beneficial owners) and others that may exert significant influence; assesses transparency of ownership structure, sources of initial capital and ability of shareholders to provide additional financial support.

Description and Findings re EC4
- OSFI determines the suitability of major shareholders, transparency of ownership structure, and initial/future capital sources during review.
- Any person who would have a significant interest in or control of a bank must receive Ministerial approval to acquire that interest/control; considerations mirror licensing considerations (see BCP 6) and include nature and sufficiency of financial resources, business record and experience, character and integrity (sections 27 BA and 396 BA).
- The Guide for Incorporating Banks sets out information requirements that assist in these determinations.

Suitability
- Applicants must provide details of criminal proceedings or administrative sanctions (Guide for Incorporating Banks).
- For foreign financial institution applicants, OSFI engages the foreign regulator regarding suitability.
- For corporate applicants, OSFI engages the Canadian Security Intelligence Service (CSIS) for a security assessment.
- Individuals with significant interest/control: OSFI obtains personal information, curriculum vitae, and a completed OSFI Security Information Form for RCMP and CSIS security assessments.
- OSFI discusses applicant’s commitment and expected rate of return; similar criteria apply when a new shareholder applies to acquire significant interest.
- OSFI shares and receives information from FINTRAC as part of the licensing process pursuant to subsection 53.31 (1) of the PCMLTFA; this may inform whether a major shareholder is fit and proper.
- Board, senior managers, and major shareholders are shared with FINTRAC on a case-by-case basis regarding individuals.

Transparency of the Ownership Structure
- Guide for Incorporating Banks requires identification of all entities in the corporate group, entities in which the applicant beneficially owns 10 percent or more of voting rights, details of voting agreements involving control, and names and personal details of all persons owning more than 10 percent of any class of shares or ownership interests.

Guide for Incorporating Banks — Section 1.1 Ownership and Financial Strength: prospective applicant generally expected to provide:
- a. the name of the jurisdiction and date of incorporation or establishment of the prospective applicant;
- b. the current organization chart (with percentages owned) of the prospective applicant`s corporate group, including entities in which the prospective applicant (and any of its parents that are not also prospective applicants) beneficially owns 10 percent or more of the voting rights (indicate by an asterisk whether any of the entities shown on the chart operate in Canada, and provide a summary of these operations);
- c. details regarding any voting agreement or other similar arrangements that involve persons exercising direct or indirect control over the prospective applicant;
- d. the names of all persons owning more than 10 percent of any class of shares or ownership interests in the prospective applicant (and in any of its parents that are not also prospective applicants), and the percentage of shares or ownership interests held (to the extent not already shown in the organization chart referred to in (b) above);
- e. details of any shares or ownership interests of the prospective applicant (and any of its parents that are not also prospective applicants) that are held by a government or a political subdivision, an agent or agency thereof, together with a summary of its involvement in the operation and affairs of the prospective applicant;
- f. a summary of the current and proposed financial services and other key activities carried on by the prospective applicant and its affiliates (other than the proposed FRFI), including a list of jurisdictions in which they operate and the nature and degree of regulatory oversight applicable to the financial services activities;
- g. a copy of the most recent annual report of the prospective applicant (and of any of its parents that are not also prospective applicants);
- h. the audited consolidated financial statements of the prospective applicant (and of any of its parents that are not also prospective applicants) for the last three years (balance sheet, income statement, statement of changes in shareholders’ equity); and
- i. details of whether the prospective applicant (and any of its affiliates that are not also prospective applicants) has been:
  - I. denied a request to establish a financial institution or a branch in any jurisdiction; and
  - II. the subject of any criminal proceedings or administrative sanctions.

Sources of Initial Capital / Ability to Provide Additional Support
- OSFI requires evidence that the applicant’s financial resources are sufficient to provide continuing financial support or that it would have access to financial resources to enable it to do so.
- An applicant must submit a capital plan and funding policies (Guide for Incorporating Banks); corporate applicants must submit three years of audited consolidated financial statements for themselves and their ultimate parent.
- For individuals who would control the new bank, OSFI may request net worth statements.
- OSFI requires a Support Principle acknowledgement letter, usually from the controlling shareholder, with respect to supporting operations and capital needs.
- Paid-in capital must be deposited prior to the issuance of an order to commence and carry on business (section 52).

Foreign Bank Branches (Capital and Suitability)
- Before making an order to establish a branch, the Minister must take into account the nature and sufficiency of the financial resources of the foreign bank as a source of continuing financial support for the carrying on of business in Canada, the business record and past performance of the foreign bank and the reputation of the foreign bank for being operated in a manner consistent with standards of good character and integrity (section 526).
- OSFI obtains details on foreign bank ownership structure, financial information for the past five years, the most recent credit-rating agency reports on the foreign bank and any controlling company, and, for the past five years, details of any material regulatory actions, criminal convictions or breaches of statutory or other administrative or regulatory enactments.
- OSFI obtains details of any refusal by regulatory authorities in any jurisdiction to permit the foreign bank from establishing or acquiring an entity, subsidiary or branch to carry on financial activities and engages in dialogue with the home country regulator/supervisor.

Note: The Bank Act prevents governments, or agencies thereof, from applying to incorporate a bank (section 23).

### EC5 — Minimum Initial Capital Amount
- EC5 requires a minimum initial capital amount for all banks.

Description and Findings re EC5
Banks
- The Bank Act stipulates the initial paid-in capital of a bank must be at least $5 million or any greater amount specified by the Minister (paragraph 52(1)(b)).
- In practice, OSFI requires that initial capital be the greater of:
  - $5 million;
  - the total amount of capital required to remain above the applicant’s target risk-based capital ratio (as determined by the bank’s ICAAP) for the longer of the first three years of the bank’s operations or until the bank is profitable under the base case scenario; or
  - the total amount of capital required for the bank to remain above its authorized leverage ratio (with an appropriate buffer) for the longer of the first three years of its operations or until it is profitable under the base case scenario.
- Initial capital should be sufficient to cover expected losses during the first years of operation.
- Deposit of paid-in capital is a condition for the Superintendent to make an order approving commencement of business; the above practice also applies in the context of a continuance.

Foreign Bank Branches
- A foreign bank applying to establish a branch must demonstrate that its risk-based capital ratio meets the minimum international standards established by BIS and set out in OSFI’s Capital Adequacy Requirements Guideline.
- A full-service branch is required to maintain, on deposit in Canada, assets equal to at least 5 percent of the branch’s Canadian liabilities or $5 million, whichever is greater.
- A lending branch is required to maintain assets on deposit equal to $100,000.

*Source: section 525).*

### section 582). Pursuant to the Bank Act, the

### section 582). Pursuant to the Bank Act, the

### EC6 — Fit and Proper Assessment of Board and Senior Management
- Licensing authority evaluates proposed board members and senior management on:
  - expertise and integrity,
  - availability and time commitment,
  - potential for conflicts of interest (fit and proper test).
- Fit and proper criteria include:
  - skills and experience in relevant financial operations commensurate with the intended activities of the bank;
  - no record of criminal activities or adverse regulatory judgments that make a person unfit to hold important positions in a bank.
- Licensing authority determines whether the bank’s board has collective sound knowledge of the material activities the bank intends to pursue, and the associated risks.
- Supervisor reassesses suitability of board members in case of significant events (for example, change of control or major acquisition) or upon receipt of information that impacts their fitness and propriety.
- Description and findings:
  - OSFI evaluates proposed Board members and senior management as to expertise and integrity during review.
  - Post-authorization, OSFI relies on the bank’s or foreign bank branch’s internal processes for ongoing suitability assessments, guided by OSFI’s Integrity and Security Guideline and Guideline E-17 - Background Checks on Directors and Senior Management of FREs.
  - OSFI reviews time commitment and capacity to exert good governance and sound management, despite this not being explicitly foreseen in some Canadian guidelines.
  - Example: in licensing a new federal bank OSFI highlighted concerns about shared positions with the parent bank, analyzed Board and Senior Management structure, and the proposed new bank committed to fill most senior management roles with full-time dedicated employees and measures to manage conflict of interest and lack of independence risks.
  - Recommendation: OSFI should, as a matter of internal policy, also evaluate the suitability of new or changed senior managers and members of the Board (not fully relying on the bank’s internal processes).
- Banks — statutory and procedural elements:
  - Bank Act considerations: Minister takes into account whether the bank will be operated responsibly by persons with the competence and experience suitable for involvement in the operation of a financial institution (paragraph 27(e)).
  - Bank Act provisions for directors: residency requirements, disqualified persons, limitations regarding affiliated directors and limitations on directors who are employees (sections 159, 160, 163,164).
  - Guide for Incorporating Banks: OSFI obtains personal details, curriculum vitae, and details of any material regulatory actions or criminal convictions for all directors and senior officers responsible for oversight.
  - Applicants must provide board composition, committee mandates, policies, practices, and planned self-assessment programs to inform OSFI’s determination of collective sound knowledge.
  - Corporate Governance Guideline: reasonable representation of relevant financial industry and risk management expertise on a bank’s board and board committees.
  - OSFI’s Supervisory Framework includes a risk governance assessment covering frameworks used to identify, assess, and manage risks.
  - OSFI assesses potential conflicts of interest on the board by examining individual directors’ employment and other directorships.
  - OSFI obtains a completed OSFI Security Information Form from all senior officers and directors for RCMP and CSIS security assessments; additional advice sought from other Canadian intelligence and law enforcement agencies.
  - If fit and proper criteria are not met, OSFI informs applicant that these persons need to be replaced to proceed.
  - At issuance of letters patent of incorporation, directors receive the Corporate Governance Guideline; all new banks are expected to comply at inception.
- Foreign Bank Branches:
  - Bank Act consideration: Minister takes into account whether proposed branch will be operated responsibly by persons with competence and experience suitable for involvement in the operation of a financial institution (paragraph 526(e)).
  - Guide to Foreign Bank Branching: OSFI obtains personal details, curriculum vitae, and details of material regulatory actions or criminal convictions for all senior executive officers and directors directly responsible for oversight, and for the Principal Officer and each officer who will work in the branch.
  - OSFI obtains completed OSFI Security Information Form from the Principal Officer and senior officers who will work in the branch for RCMP and CSIS security assessments; assessments performed through established protocols and with additional intelligence and law enforcement advice.
  - Where fit and proper criteria are not met, OSFI informs the applicant that these persons must be replaced.

### EC7 — Review of Strategic and Operating Plans; Governance and Controls
- Licensing authority reviews proposed strategic and operating plans, including:
  - that an appropriate system of corporate governance, risk management and internal controls will be in place,
  - controls related to detection and prevention of criminal activities,
  - oversight of proposed outsourced functions.
- Operational structure must reflect scope and degree of sophistication of proposed activities.
- Description and findings:
  - OSFI analyses strategic and operating plans of proposed bank.
  - Bank Act: Minister considers soundness and feasibility of applicant’s plans for future conduct and development of the bank (paragraph 27(b)).
  - Guide for Incorporating Banks: business plan must contain analysis of target markets, opportunities, competitors, and the bank’s overall strategy.
- Phase-1 Information Requirements (selected items preserved exactly as listed):
  1.0 Phase-1 Information Requirements
  1.1 Ownership and Financial Strength
  - Prospective applicant generally expected to provide:
    a. the name of the jurisdiction and date of incorporation or establishment of the prospective applicant;
    b. the current organization chart (with percentages owned) of the prospective applicant`s corporate group, including entities in which the prospective applicant (and any of its parents that are not also prospective applicants) beneficially owns 10 percent or more of the voting rights (indicate by an asterisk whether any of the entities shown on the chart operate in Canada, and provide a summary of these operations);
    c. details regarding any voting agreement or other similar arrangements that involve persons exercising direct or indirect control over the prospective applicant;
    d. the names of all persons owning more than 10% of any class of shares or ownership interests in the prospective applicant (and in any of its parents that are not also prospective applicants), and the percentage of shares or ownership interests held (to the extent not already shown in the organization chart referred to in (b) above);
    e. details of any shares or ownership interests of the prospective applicant (and any of its parents that are not also prospective applicants) that are held by a government or a political subdivision, an agent or agency thereof, together with a summary of its involvement in the operation and affairs of the prospective applicant;
    f. a summary of the current and proposed financial services and other key activities carried on by the prospective applicant and its affiliates (other than the proposed FRFI), including a list of jurisdictions in which they operate and the nature and degree of regulatory oversight applicable to the financial services activities;
    g. a copy of the most recent annual report of the prospective applicant (and of any of its parents that are not also prospective applicants);
    h. the audited consolidated financial statements of the prospective applicant (and of any of its parents that are not also prospective applicants) for the last three years (balance sheet, income statement, statement of changes in shareholders’ equity); and
    i. details of whether the prospective applicant (and any of its affiliates that are not also prospective applicants) has been:
      i. denied a request to establish a financial institution or a branch in any jurisdiction; and
      ii. the subject of any criminal proceedings or administrative sanctions.
  1.2 Business Plan
  - Prospective applicant generally expected to provide a minimum five-year business plan for the proposed FRFI, including:
    a. the reasons why the prospective applicant is seeking to establish the proposed FRFI;
    b. an analysis of target markets and opportunities that the proposed FRFI will pursue and the plans to address them;
    c. an analysis of competitors, showing both challenges and opportunities, and plans to address them;
    d. the reasons why the prospective applicant believes that the proposed FRFI will be successful, and the overall strategy for achieving this success, including a discussion of key assumptions;
    e. the location(s) of the proposed branch(es) and head office of the proposed FRFI in Canada;
    f. a detailed description of each line of business to be conducted by the proposed FRFI and the products and services to be offered, including how the lines of business interrelate;
    g. for each year in the five-year business plan, details regarding the implementation of the Liquidity Adequacy Requirements (LAR), including on-going reporting on the Net Cumulative Cash Flow and Liquidity Coverage Ratio;
    h. the risk-based capital and leverage ratios for each year of the five-year business plan, including a breakdown of key elements used to calculate those ratios on a Basel III basis;
    i. five-year pro forma financial statements (base case) for the proposed FRFI, including balance sheet, income statement, details regarding key assumptions and an identification of major asset, liability, income and expense categories;
    j. contingency plans resulting from variations associated with key assumptions used in developing the base case business plan, including a sensitivity analysis showing the results of changes in key assumptions on the base case business plan under a worst-case scenario and a discussion of the changes in assumptions;
    k. details regarding the proposed organizational structure including senior management reporting lines key responsibilities within the organization;
    l. details regarding the proposed composition of the board of directors and senior management, and details regarding any persons selected or sought for those positions;
    m. a description of any proposed material outsourcing arrangements involving the proposed FRFI, how these arrangements would be managed, and copies of any material outsourcing arrangement contracts; and
    n. a copy of any proposed shareholders’ agreement.
  1.3 Other Information
  - Prospective applicant generally expected to provide:
    a. details regarding the proposed FRFI’s
      i. credit products and the underwriting criteria for those products,
      ii. trading and investment strategy,
      iii. information technology environment, and
      iv. exit-strategy in the event that it is unable to execute its business plan; and
    b. in the case of a continuance from another Act, details regarding the incremental costs associated with being regulated as a FRFI for each year in the five-year business plan.
- Business plan discussion with OSFI:
  - A second in-person meeting is scheduled once OSFI has considered information under sections 1.1 to 1.3.
  - Purpose: prospective applicant to demonstrate understanding of material risks associated with its business plan and mitigation methods.
  - Prior to meeting, OSFI provides agenda and specific issues to be addressed.
- OSFI Expectations Letter:
  - Sets out OSFI’s views and expectations regarding:
    a. any material risks or concerns with the proposed business plan and whether OSFI will expect those risks or concerns to be resolved in Phase-2 or Phase-3 of the application process; and
    b. additional information requirements, in addition to those already set out in this Guide, that the prospective applicant will be required to submit as part of its formal application in Phase-2.
  - OSFI will request a written timeline for submission of a formal application.

### Outsourcing and Third-Party Risk Management (Guideline B-10 Compliance)
- Applicants must describe any anticipated material outsourcing arrangements and ensure compliance with OSFI Guideline B-10 - Third-Party Risk Management.
- Guideline B-10 expectations (preserved wording):
  1. Governance and accountability structures are clear with comprehensive risk management strategies and frameworks in place.
  2. Risks posed by third parties are identified and assessed.
  3. Risks posed by third parties are managed and mitigated within the bank’s   RAF.
  4. Third party performance is monitored and assessed, and risks and incidents are proactively addressed.
  5. The FRFI’s third-party risk management program allows the FRFI to identify and manage a range of third-party relationships on an ongoing basis.

*Source: section 582). Pursuant to the Bank Act, the — 1canea2025007-source-pdf*

### 6.    Technology and cyber operations carried out by third parties are transparent, reliable and

### 6.    Technology and cyber operations carried out by third parties are transparent, reliable and secure.

### Licensing and incorporation requirements
- Applicants provide a description of the major risk management and control processes and policies for the new bank, board policies and practices, a conflict of interest policy and a description of the system of internal controls and policies the bank will follow to ensure legislative compliance.
- Applicants are asked to provide evidence on their technology and cyber risk management processes and controls.
- OSFI reviews policy statements that will govern operations, including the outsourcing policy and material outsourcing agreements to related or third parties.
- OSFI assesses the adequacy of the bank’s policies and procedures to protect against threats to integrity or security, including foreign interference (Integrity and Security Guideline).
- OSFI conducts a full vetting of the characteristics of each risk management control function, covering corporate governance, risk management and the overall control environment, concurrently with the review of the business plan.
- OSFI advises applicants that material weaknesses in policies and procedures must be remedied before OSFI will grant an order to commence and carry on business.

### Information sharing and legal basis
- OSFI may share and receive information from FINTRAC as part of the licensing process pursuant to subsection 53.31 (1) of the PCMLTFA.
- Text of subsection 53.31 (1): "For the purpose of assessing risks to the integrity of the Canadian financial system that may arise from the grant, revocation, suspension or amendment of an approval, the Minister, officers of the Department of Finance, the Director and the Superintendent of Financial Institutions may disclose to each other, and collect from each other, any information that relates both to the approval and to money laundering activities or terrorist financing activities."

### Foreign bank branches and cross-border considerations
- Pursuant to the Bank Act, the Minister must consider the soundness and feasibility of the plans of the foreign bank for the future conduct and development of its business in Canada (paragraph 526(b)).
- Guide to Foreign Bank Branching requirements include:
  - An analysis of target markets and opportunities and an overview of each line of business and the products and services to be offered.
  - Identification of risks the branch will be exposed to and a detailed description of the risk management and control systems utilized by the branch and their integration with the foreign bank on a global basis.
  - Description of branch management, reporting lines back to the foreign bank and level of involvement of senior foreign bank management in branch operations.
- OSFI’s review of foreign branch materials is similar to that for a proposed bank and may include dialogue with the home country regulator and open-source research.
- OSFI may prepare an internal home country report or send a questionnaire to the home country where unfamiliar with the home regulatory and supervisory regime.
- There has been a long time since the last foreign regulated institution applied; assessors had access to a non-objection letter delivered more than a decade ago.

### Financial strength, pro forma statements and capital (EC8)
- Applicants must submit pro forma financial statements for the first three years of operations, contingency plans resulting from variations associated with key assumptions and a breakdown of all elements used to calculate capital ratios.
- Applicants must provide details regarding the sources of initial capital and future capital in the form of a capital plan and funding policies.
- Assessment of adequacy of financial strength is addressed in part through ICAAP (submission required in the application process); OSFI requires that initial capital be sufficient to remain until the institution is profitable.
- Where a principal shareholder is a corporate entity, OSFI will review audited financial statements; where a principal shareholder is an individual, OSFI will review net worth statements.
- OSFI may seek a Support Principle acknowledgement, usually from the controlling shareholder.
- Foreign bank applicants must provide:
  - Pro forma financial statements for the first three years of operations of the branch and a breakdown of funding requirements for the same period.
  - Annual reports and copies of financial statements in the form submitted to the home supervisor for the last five years.
  - Detailed capital calculations according to the applicant’s home jurisdiction methodology and based on OSFI’s capital rules and recent credit-rating agency reports.
  - Current ICAAP (or equivalent) as submitted to the home regulator.
- OSFI assesses adequacy of financial strength through dialogue with the home country regulator/supervisor and independent research regarding the applicant’s financial strength and that of the home jurisdiction.
- Assessors found the level of analysis and critical assessment of financial projections, business plans and strategies of new entrants to be deep and comprehensive; concerns were shared and addressed or mitigants/recommendations issued and followed before the license was granted.

### Home supervisor cooperation and consolidated supervision (EC9)
- OSFI establishes that the home supervisor does not object and whether it practices global consolidated supervision when foreign banks establish a branch or subsidiary.
- For foreign bank subsidiaries (Schedule II banks), applicants must provide information on the type and scope of supervision in the home jurisdiction, confirmation that the home regulator is aware of the intention to establish a Canadian bank, and whether comprehensive consolidated supervision applies.
- The applicant must provide the name of a home regulatory contact and confirmation from the home regulator that it reports favorably on the applicant.
- OSFI contacts the home regulator to confirm submissions, discuss consolidated supervision and obtain the home regulator’s opinion regarding the applicant’s intention to establish a Canadian bank.
- Where OSFI is unfamiliar with the home country system, it may prepare an internal home country report and may ask the home country to complete a questionnaire inspired in part by the BCPs.
- The Bank Act specifies that the Minister must take into account the opinion of the Superintendent regarding the extent to which the proposed corporate structure of the applicant and affiliates may affect supervision and regulation of the bank (paragraph 27(g)).

### Monitoring new entrants and ongoing supervision (EC10 and EC11)
- Regular quarterly monitoring procedures identify and evaluate the quantity and quality of business conducted by the new entrant during each quarter.
- Business performance is measured against the business and strategic plans presented during the license application process.
- Specific review procedures to assess compliance with commitments/undertakings entered into with OSFI at commencement include:
  - Analytical review of performance against established metrics within the business plan;
  - Discussion with senior management and the board regarding performance against the business plan;
  - Discussion with the new entrant’s Internal Audit and Compliance Division management regarding their reviews of compliance with operating policies and commitments/undertakings.
- When applying for an order to commence and carry-on business, a bank must commit to providing adequate advance notification of any material proposed changes to the submitted business plan.
- Monitoring procedures, reviews and scrutiny are performed in practice; OSFI determines if the entity continues to be in compliance with commitments/undertakings established at commencement.
- Criteria for issuing licenses are applied on an ongoing basis; applicants must provide descriptions of risk management and control processes and policies, allowing OSFI to assess ability to manage and mitigate risks and comply with the Bank Act, regulations and OSFI Guidelines.
- Licensing typically accompanies a list of findings and recommendations for the bank to address after licensing, with ongoing supervision continuing that dynamic.
- Under the Supervisory Framework, OSFI applies a risk-based approach to assessing bank/branch safety and soundness on a consolidated basis. A bank’s ORR considers four main risk categories: business risk, financial resilience, operational resilience, and risk governance. OSFI rates each risk category by assessing the level of risk and the effectiveness of risk oversight and management controls. This approach is mirrored in the assessment of new bank/branch applicants.
- Example Ministerial consideration under the Bank Act: the nature and sufficiency of the financial resources of the applicant as a source of continuing financial support for the bank (paragraph 27(a)).
- OSFI requires applicants to prepare a draft ICAAP (using OSFI’s ICAAP Guideline) in the same format as existing banks; the ICAAP determines the new bank`s required capital in the same manner as for an existing bank.

_Italic: Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf_

### section 22 of the Bank Act) upon recommendation of the

### 1canea2025007-source-pdf - section 22 of the Bank Act) upon recommendation of the

### Licensing process and legal steps
- Applications for letters patent must be filed with the Superintendent together with such information, material and evidence as the Superintendent may require (subsection 25(1)).
- All applications for a banking license are accompanied by an analysis and recommendation by the Superintendent.
- A newly licensed bank may not commence operations until it obtains an order to commence and carry on business issued by the Superintendent (section 48(1); section 49).
- For companies continuing as a bank from another federal statute, letters patent of continuance and the order to commence and carry on business are generally issued at the same time.
- Conditions on the order to commence and carry on business (or on the letters patent) are very infrequent, but are a legal instrument available to OSFI (and the Minister of Finance for the letters patent).

### New entrant review framework and practices
- OSFI conducts a lengthy and thorough review of new entrants with several phases: submissions by the applicant; analysis of the submissions and drafting of an internal supervisory plan; internal consultation and external consultation including the closure of recommendations; external consultation and granting, conditioning or recommendation.
- Review aspects include: business and strategic plans; Board and senior management suitability; credit risk; operational risk; liquidity and funding risks; capital position; IRRBB; AML/CFT; governance.
- Reviews involve staff from the Approvals Division, supervisors and specialized subject-matter experts.
- Findings and recommendations are communicated to the new entrant for remediation before or after authorization; commitments are received from the new entrant as conditions (examples: not changing the business plan without OSFI’s LSs consent; specific ad entitatem capital and leverage ratios; promises regarding improvements in credit and operational risk management, governance or liquidity risk).
- OSFI’s Internal Risk Tolerance Framework for New Entrants guides analysis and contains expectations classified by impact category (depending, inter alia, on the amount of deposits), covering:
  - foreign regulatory and supervisory regime (takes into account FSAPs, RCAPs and other indicators);
  - business strategy (challenging or realistic, mitigants in place...);
  - capital (compliance with budget and targets in the medium term);
  - access to external sources of capital (markets, new investor, parent support);
  - earnings (losses projected);
  - liquidity (commensurate with funding profile, projected metrics);
  - stress testing (ranging from basic capabilities to rigorous stress testing for more impactful categories);
  - risk controls (comprehensive set of policies and procedures reviewed more extensively for higher impact categories);
  - three lines of defense (more admixture allowed, but independence of the third line is allowed for lower impact categories);
  - corporate governance (sound practices, fit and proper are required for all, less sophisticated RAFs may be allowed for low impact categories);
  - national security and AML/CFT have zero tolerance.

### Financial strength, capital planning and ICAAP
- As part of the Guide for Incorporating Banks, applicants must submit pro forma financial statements for the first three years of operations, contingency plans resulting from variations associated with key assumptions, and a breakdown of all elements used to calculate capital ratios.
- Applicants must provide details regarding sources of initial capital and future capital in the form of a capital plan and funding policies.
- ICAAP is required in the application process; OSFI requires that initial capital be sufficient to remain onside capital requirements until profitable (see EC6).
- Where a principal shareholder is a corporate entity, OSFI reviews audited financial statements; where a principal shareholder is an individual, OSFI reviews net worth statements.
- OSFI may seek a Support Principle acknowledgement, usually from the controlling shareholder, regarding support for operations and capital needs of the bank.
- Assessors found the level of analysis and critical assessment of financial projections, business plans and strategies of new entrants to be deep and comprehensive; concerns were shared and addressed, or mitigant commitments and recommendations were issued and followed before the license was granted.

### Foreign banks, home supervisor assessment
- For foreign banks establishing a branch or subsidiary, OSFI establishes that the home supervisor does not object and whether it practices global consolidated supervision.
- OSFI’s questionnaire to a home country regarding assessment of the home regulatory and supervisory regime is comprehensive and sufficient to characterize foreign banking supervision systems; some questions are based on or inspired by the BCPs.
- Assessors saw a non-objection letter to the opening of a new branch in Canada delivered by a foreign supervisor more than a decade ago, evidencing that OSFI requests this kind of assurance in practice.

### Supervision continuation after licensing
- A main goal of the thorough licensing process is to determine whether the new entrant is able from inception to show a high degree of compliance with all the regulations and guidance applicable to banks.
- Licensing is normally accompanied by a list of findings and recommendations for the bank to address after licensing (other, more pressing issues to be resolved before licensing).
- This dynamic continues with ongoing supervision of the bank.

### Recommendation
- OSFI should institute a policy of assessing the fitness and propriety of all new board members and new senior management executives.

### Principle 6 — Transfer of Significant Ownership: overview
- The supervisor has the power to review, reject and impose prudential conditions on proposals to transfer significant ownership or controlling interests in existing banks.

### EC1 — Definitions of significant ownership and control
- The Bank Act defines significant interest: a person has a significant interest in a class of shares of a bank if the aggregate of any shares of that class beneficially owned by that person and any shares of that class beneficially owned by entities controlled by that person exceed 10 percent of all the outstanding shares of that class (section 8).
- Control definitions: control of a body corporate (>50 percent beneficial ownership of voting shares to elect a majority of the board); unincorporated entity other than a limited partnership (>50 percent beneficial ownership of the ownership interests and ability to direct business and affairs); limited partnership (the general partner controls) (subsection 3(1)).
- A person also controls any entity if the person has any direct or indirect influence that, if exercised, would result in control in fact of the entity. A person who controls an entity is deemed to control any entity that is controlled, or deemed to be controlled, by the entity (subsection 3(2)). Securities beneficially owned by entities controlled by the person are considered (subsection 3(3)).
- OSFI’s Advisory on control in fact and Rulings (2007-02, 2008-03) provide guidance; Guidelines Respecting Control in Fact for the Purpose of Subsection 377(1) of the Bank Act describes policy objectives and factors for acquisitions of significant interest more than 10 percent but less than 20 percent in a widely-held bank.
- Acting in Concert: persons “acting jointly or in concert” are deemed a single person for beneficial ownership (section 9). OSFI Ruling (2017-01) details OSFI’s approach for assessing acting in concert.
- Ownership restrictions:
  - No person may be a major shareholder of a bank with equity of $12 billion or more (section 374).
  - A major shareholder is defined as beneficial ownership and control of entities with ownership >20 percent of voting shares or 30 percent of non-voting shares (section 2.2).
  - No person can control in fact a bank with equity of $12 billion or more (section 377).
  - Every bank with equity of $2 billion or more but less than $12 billion must generally have voting shares that carry at least 35 percent of the voting rights attached to all the outstanding voting shares of the bank and that are listed and posted for trading on a recognized stock exchange in Canada and not owned by a major shareholder in respect of voting shares or any entity controlled by such a shareholder (section 385). A Ministerial exemption is provided in section 388.

### EC2 — Approval and notification requirements
- Ministerial approval is required to acquire, or increase by at least 5 percent (in most cases), a significant interest in, and to acquire control of, a bank (sections 373, 377.1, 382 and 396).
- Transaction Instruction A No. 23 sets out information requirements and administrative guidance for applications for significant interest and/or control.
- Absent Ministerial approval, the Bank Act prohibits registration by a bank in its securities register of a transfer or issue of any share that would trigger a significant interest (section 379) and prohibits exercise of voting rights attached to those shares (section 392).
- If requisite approval is not sought, the Minister may direct the person to dispose of its shares (section 402), acting on OSFI’s recommendation.
- The Minister may impose any terms and conditions in respect of an ownership approval as necessary to ensure compliance with the Bank Act (section 397) and may impose any terms, conditions, or undertakings the Minister considers appropriate (section 973.02).

### EC3 — Power to reject or reverse changes in significant ownership
- The Bank Act allows rejecting applications for acquisition of a significant interest to ensure criteria comparable to licensing are met and permits revocation, suspension or amendment of approvals where based on false information.
- Applications for approval must be filed with the Superintendent and contain required information (section 395).
- Section 396 requires the Minister to take into account all matters considered relevant in deciding approval; these considerations mirror those under section 27 (licensing). In practice the Minister relies on OSFI’s analysis and recommendation.
- Where a change in significant ownership was based on false information, section 973.03 allows revocation, suspension or amendment of any approval. Offences for knowingly providing false information carry fines and imprisonment (sections 980, 980.1 and 985).
- Assessors were provided with a decade-old example of conditions imposed by the Minister on a significant interest approval to ensure OSFI’s ability to supervise the bank after the acquisition (including an undertaking to provide information to OSFI).

### EC4 — Information on significant shareholders and beneficial owners
- Prior approval being necessary from 10 percent means OSFI has information detailing significant shareholders or those that exert controlling influence; the legislative definition includes beneficial ownership and entities controlled by that person and control in fact.
- Reliance is placed on the bank and the significant shareholder to identify approval requirements; shareholders are responsible to seek approval where required.
- No person may be a major shareholder or control in fact a bank with equity of $12 billion or more, which covers 94 percent of total banking assets; this EC is primarily applicable to banks with equity of less than 12 billion.
- OSFI applies control-in-fact analysis to ensure complex ownership structures cannot obscure control.
- Supervisory monitoring (board minutes review, press/news monitoring) and Integrity & Security assessments (ownership structures, holdings of significant shareholders, public/private status, public records search) provide additional information on major shareholders.
- There have been examples of after-the-fact approvals (ex post authorizations where voting rights were automatically suspended). Assessors consider these examples (always from SMSBs) too frequent for a regulation of this importance and note non-compliance was self-reported by banks, suggesting outreach and awareness efforts could reduce recurrence.

### EC5 — Powers to address unauthorized changes of control
- The Bank Act provides the power to address a change in control that has taken place without the necessary approval.
- If a person does not seek the required significant interest or control approval, the Minister may, if deemed in the public interest, direct the person to dispose of its shares.

*Source: 1canea2025007-source-pdf - section 22 of the Bank Act)*

### section 402). The Minister would take such action upon

### 1canea2025007-source-pdf - section 402). The Minister would take such action upon

### EC6 — Notification requirement for material information affecting suitability of major shareholder or controlling party
- The notification requirement does not apply to “widely held” banks with equity of $12 billion or more as no person may be a major shareholder of such a bank and no person shall control in fact such a bank.
- EC6 applies only to small and mid-sized banks (SMSBs).
- As of April 30, 2024, the six largest Canadian banks (all prohibited from having major shareholders or controlling parties) held 94.5 percent of the assets held by all Canadian banks (domestic banks and foreign subsidiaries).
- OSFI is to be promptly advised by the bank’s senior management and/or board of any substantive or material issues affecting a bank’s safety and soundness, including material adverse events / fit and proper problems relating to its major shareholders.
- The OSFI Corporate Governance Guideline supervisory expectation: “Open communication between the Board and regulators helps promote the mutual trust and confidence essential to the efficiency of OSFI's principles-based approach to supervision. Accordingly, OSFI expects to be promptly notified of substantive issues affecting the FRFI.”
- Financial institutions are encouraged to report to CSIS and RCMP when there are reasonable grounds to believe an incident related to undue influence, foreign interference, or malicious activity has occurred; OSFI should be informed immediately of any such communications.

### Assessment of Principle 6 — Compliant
- OSFI has the power to review, reject and impose prudential conditions on proposals of transfers of significant ownership and controlling interests.
- The largest banks (with equity of $12 billion or more) must be “widely held” by virtue of the Bank Act; as at April 30, 2024, the six largest Canadian banks (all of which are prohibited from having major shareholders or controlling parties) held 96 percent of the assets held by all Canadian banks (domestic banks and foreign subsidiaries).
- There have been examples of after-the-fact approvals where banks reported consummated ownership changes and authorization was provided ex post; voting rights of the shares were automatically suspended in those cases.
- The assessors consider these after-the-fact approvals (always from SMSBs) too frequent for a regulation of this importance; non-compliance was in all cases self-reported by the banks and likely due to involuntary ignorance of the applicable law.
- The complexity of the legal framework in the Bank Act and its development regulations, and the fact that it mainly affects SMSBs, suggests outreach and awareness-increase efforts may be an effective prevention policy.
- OSFI’s Corporate Governance Guideline reiterates prompt advice to OSFI by senior management and/or board on substantive or material issues affecting safety and soundness, including suitability of the major shareholder.

### Recommendations (Principle 6)
- There is evidence of several cases where SMSBs carried out significant ownership transfers without reporting to OSFI. Efforts of outreach, increase of awareness and clarification of the complex legal regime may be undertaken.
- OSFI should consider establishing reporting requirements for banks that are not “widely held” regarding the list of their significant shareholders.

---

### Principle 7 — Major Acquisitions (overview)
- The supervisor has the power to: (i) approve or reject (or recommend to the responsible authority the approval or rejection of) and impose prudential conditions on major acquisitions or investments by a bank (including establishment of cross-border operations), against prescribed criteria; and (ii) determine that corporate affiliations or structures do not expose the bank to undue risks or hinder effective supervision.

### EC1 — Types and amounts requiring prior supervisory approval; cases where notification after suffices
- Substantial Investments:
  - A bank acquires a substantial investment if it acquires over 10 percent of the voting shares of an incorporated entity or over 25 percent of the ownership interests of an incorporated or a non-incorporated entity (section 10).
  - Except as permitted under Part IX of the Bank Act, a bank may not acquire control of, or a substantial investment in, another entity.
  - Permitted investments are set out in the Bank Act (section 468).
  - Permitted investments may require prior Ministerial approval (subsection 468(5)) or Superintendent approval (subsection 468(6)) depending on the nature of the investment.
  - Where Ministerial approval is required, OSFI reviews the application and provides its recommendation to the Minister; in practice, the Minister relies on OSFI’s recommendation.
- All Investments:
  - All investments by a bank in an entity are subject to the “reasonable and prudent person” standard (section 465).
- Material Asset Transactions:
  - Prior approval from the Superintendent is required where a bank wishes to acquire or transfer assets to a person in excess of 10 percent of the total value of the assets of the bank (section 482).
- Prudential Conditions:
  - Part XVI of the Bank Act allows the Minister or Superintendent to impose any terms, conditions, or undertakings in relation to an approval (section 973.02).

- Practical examples reviewed:
  - Superintendent’s approval of acquisition by a Canadian bank of a foreign bank where due diligence on governance, AML/CFT and risk management was presented; OSFI recommended establishing international investment oversight, AML/CFT improvements, enhanced due diligence.
  - Ministerial approval of a Canadian bank acquisition of another foreign bank where OSFI conducted prudential assessment; OSFI was satisfied with capital plan, due diligence on credit portfolio and the integration plan (to be monitored), among other prudential risks (liquidity, technology).

- Substantial Investments — No Approval (five narrow categories where no prior approval required):
  1. a permitted entity for which no approval is required;
  2. an entity held via a PFFI controlled by the bank (subsection 466(2)); approval required, however, to acquire control or a substantial investment in a PFFI;
  3. an entity to be held for a limited period of time (sections 471-473); approval required to extend a temporary investment;
  4. an entity held in accordance with the Specialized Financing Regulations (limits: $250 million per investment, 13-year limit, 10 percent and 25 percent of regulatory capital limits); acquisition of control of, or a substantial investment in, a specialized financing entity is subject to approval;
  5. an entity below the materiality threshold — subsection 468(7) establishes thresholds ranging from 0.5 percent to 2 percent of the acquiring bank’s assets, depending on size of the bank and whether control or non-controlling substantial investment is acquired.

- Substantial Investments — Notifications:
  - Laws/regulations do not specify notification requirements for the above categories; the Advisory on substantial investments notes OSFI may review investments in the course of ongoing supervision and may require detailed information.
  - In practice, there is open communication between OSFI and large banks and advance notice of all material acquisitions is provided; OSFI receives advance notice on material acquisitions regardless of approval requirements.

- Material Asset Transactions backstop:
  - Where no approval is required under the investments regime, approval is required pursuant to section 482 where the bank acquires assets valued in excess of 10 percent of the bank’s total assets.

### EC2 — Criteria to judge individual bank proposals for acquisitions and investments
- All investments are subject to the “reasonable and prudent person” standard (section 465).
- Primary criteria (Advisory on substantial investments): ensure the proposed investment would not expose the bank to undue risk or hinder OSFI’s ability to supervise the bank.
- Minister’s prior approval required for classes of transactions that relate to public policy matters.
- Transaction Instructions:
  - OSFI’s website contains transaction instructions for Superintendent or Ministerial approval requests (DA No. 13, A No. 8), extension of holding/divestiture periods for temporary investments (DA No. 15, 16, 17 and A No. 16, 17, 18), and asset transactions greater than 10 percent of bank’s assets (DA no. 18).
  - Transaction instructions set out information requirements and administrative guidance; OSFI may request additional information if initial submission is insufficient.
  - Information requirements for substantial investments include: detailed business description of target, business case (rationale, amount/type of consideration, anticipated impact on capital adequacy), a business plan with three years financial projections, most recent financial statements of the entity, identity of the primary regulator other than OSFI for the entity, regulatory contact person and details of any required regulatory approvals.
- Legislation requires Minister to consider whether acquisition of a foreign entity engaged in activities that would be considered financial activities in Canada would affect stability of the Canadian financial system and be in the best interests of the Canadian financial system.

### EC3 — Supervisor determines acquisitions/investments will not expose bank to undue risks or hinder supervision
- Advisory: approval process permits OSFI to ensure proposed investment would not expose the bank to undue risk or hinder OSFI’s ability to supervise the bank.
- Transaction Instructions: specify OSFI may request information to satisfy itself that implementation of corrective measures in the future will not be hindered; this could include recovery and/or resolution information.
- As a matter of practice, approvals may be advised by FISC (see CP3), where CDIC is present and resolvability concerns may be discussed.
- Consolidated Supervision:
  - Superintendent and Minister have discretion to refuse approval where criteria are not met, including where OSFI is not satisfied it could exercise adequate consolidated supervision.
  - A bank is required to obtain approval to directly acquire control of, or acquire or increase a substantial investment in, a PFFI.
  - Advisory on substantial investments notes OSFI’s approval process includes assessing the regulatory framework that applies to the PFFI being acquired (i.e., the “host country” regulator post-acquisition).
  - If prudential issues are identified, OSFI may enter into an agreement with that regulator concerning activities of the PFFI being acquired, or require undertakings from the bank addressing access to information and investment activities of the PFFI (subsection 470(3)).

*Source: 1canea2025007-source-pdf - section 402). The Minister would take such action upon*

### section 470). Note that, under the Bank Act,

### section 470). Note that, under the Bank Act,

### EC4 — Adequate financial, managerial and organizational resources for acquisitions
- Supervisor determination: OSFI determines that the bank has the necessary resources to handle the acquisition (see EC2 for application information requirements).
- Financial resources considerations:
  - Amount and type of consideration paid.
  - Impact on the bank’s capital adequacy (present and future impact).
  - Business plan for the acquisition, including three years of financial projections.
  - Any capital support expectations, including formalized capital support arrangements.
  - If a bank would be close to supervisory or internal minimum capital targets as a result of the proposed acquisition, OSFI may consider the bank’s mitigation and contingency plans to ensure it does not breach these targets.
- Managerial and organizational resources considerations:
  - Business activities of the proposed acquisition.
  - Bank’s rationale for the transaction.
  - Assessment against the bank’s business strategy and familiarity with the bank’s managerial and operational strengths and weaknesses.
- Supervisor may consider whether the acquisition or investment creates obstacles to the orderly resolution of the bank.

### EC5 — Risks from non-banking activities and mitigation
- Legal constraints:
  - Bank Act: a bank must not engage in, or carry on any business, other than the business of banking and such business generally as appertains thereto (section 409).
  - Investment regime restricts a bank’s investments to financial service entities, subject to exceptions.
- Permitted limited non-banking investments include:
  - Investments made by PFFIs, temporary investments, specialized financing investments.
  - Investments in entities that engage in information technology services or services to members of the bank’s group.
  - Limited investments to enhance merchant banking and venture capital activities (subsection 466(4)).
- Supervisor action: supervisor considers the ability of the bank to manage risks from non-banking activities prior to permitting investment.

### EC6 — Review of major acquisitions or investments by other group entities
- OSFI’s Advisory on substantial investments: OSFI shall review major acquisitions or investments by other entities in the banking group to determine they do not expose the bank to undue risks or hinder effective supervision or corrective measures.
- Substantial investment definition (FREs):
  - Acquires over 10 percent of the voting shares of an incorporated entity; or
  - Acquires over 25 percent of the ownership interests of an incorporated or an unincorporated entity.
- Practical note: no recent examples of major acquisitions by subsidiaries; main Canadian banking groups typically realize acquisitions at the parent bank level.
- Approval regimes:
  - Except as permitted under Part IX of the Bank Act, a bank may not acquire control of, or a substantial investment in, another entity.
  - A bank acquires a substantial investment if it acquires over 10 percent of voting shares of an incorporated entity or over 25 percent ownership interests of an incorporated or non-incorporated entity (section 10).
  - Permitted investments set out in the Bank Act (section 468).
  - Permitted investments may require prior Ministerial approval (subsection 468(5)) or Superintendent approval (subsection 468(6)).
  - Where Ministerial approval is required, OSFI reviews and provides recommendation to the Minister; in practice, the Minister relies on OSFI’s recommendation.
  - Prior approval from the Superintendent required where a bank wishes to acquire or transfer assets to a person in excess of 10 percent of the total value of the assets of the bank (section 482).
  - Part XVI (section 973.02) allows the Minister or Superintendent to impose terms, conditions, or undertakings in relation to an approval.
- Transparency and process:
  - OSFI’s website contains transaction instructions detailing information requirements and administrative guidance (DA No. 13, A No. 8; DA No. 15, 16, 17 and A No. 16, 17, 18; DA no. 18).
  - Information requirements for substantial investments include:
    - Detailed description of the business of the entity to be acquired.
    - Business case: rationale for investment, amount and type of consideration, anticipated impact on capital adequacy.
    - Business plan with three years financial projections.
    - Most recent financial statements of the entity.
    - If applicable, identity of the primary regulator other than OSFI, regulatory contact person, and details of any required regulatory approvals.

### Assessment of Principle 7
- Assessment: Compliant
- Comment: The Advisory on substantial investments provides an overview of how OSFI administers and interprets the substantial investment regime. All acquisitions of substantial investments in, and/or control of, a single entity, and all increases in such substantial investments, by a bank are subject to specific rules.

### Principle 8 — Supervisory Approach (overview)
- Objective: develop and maintain a forward-looking assessment of risk profiles proportionate to systemic importance; identify, assess and address risks from banks and the system; have an early intervention framework; and maintain resolution plans with other authorities.
- Essential Criteria EC1 focus: well-defined methodology and processes to determine and assess on an ongoing basis the nature, impact and scope of risks banks are exposed to and present to the safety and soundness of the system, addressing group structure, business model risks, forward-looking risk profile, internal control environment, and resolvability.

### OSFI supervisory methodology and processes (EC1)
- OSFI’s supervisory work guided by 3 phases:
  1. Planning Supervisory Work
     - Annual supervisory strategy for each bank.
     - Strategy identifies supervisory work necessary to keep bank’s risk profile current.
     - Outlines supervisory work planned for next three years, fuller description for upcoming year.
     - Intensity of supervisory work depends on nature, size, complexity and risk profile, including potential consequences of a bank’s failure.
     - Comparative process to ensure work effort across banks and allocate supervisory resources effectively.
  2. Executing Supervisory Work and Updating the Risk Profile
     - Continuum of work: monitoring (bank-specific and external), reviews (off-site or on-site), testing or sampling as necessary.
     - On-site reviews can include online live interactions, not necessarily physical presence.
     - Monitoring includes regular review of bank and industry information, analysis of financial results vis-à-vis plan and peers, and gathering information on non-regulated entities influencing the bank.
     - External environment scanning and ERC (Emerging Risk Committee) involvement for system-wide concerns.
     - Reviews include assessment of business processes, credit files, effectiveness testing; location based on scope; OSFI requests information in advance and conducts discussions with bank management.
  3. Reporting and Intervention
     - Annually the LS writes a Supervisory Letter summarizing key findings and recommendations; discloses or affirms the bank’s ORR and other lower-level ratings and the Intervention Rating.
     - Interim Supervisory Letters may be issued during the year for timely results.
     - Findings and recommendations are discussed with relevant bank management before letter issuance.
     - Under Strategic Alliance Agreement, OSFI shares letters with the CDIC.
     - Banks’ responses recorded in Vu; Findings and Actions maintained by LS and reviewed/updated regularly.

### OSFI Supervisory Framework and ORR (operational changes)
- Supervisory Framework revised and became effective on April 1, 2024.
- Framework assists OSFI in meeting statutory obligations under section 4 of the Office of the Superintendent of Financial Institutions Act (OSFI Act).
- Framework objective: assess safety and soundness, compliance with prudential regulations and legal requirements, and intervene timely when practices are imprudent or unsafe; supervision conducted on consolidated basis.
- ORR (Overall Risk Rating):
  - New rating scale: 1 to 8 representing level of overall risk to financial viability (risk of failure).
  - ORR Scorecard guides supervisors with risk categories, subcategories and attributes.
  - ORR scales and labels:
    - 1 (minimal risk)
    - 2 (low risk)
    - 3 (moderate risk)
    - 4 (watchlist)
    - 5 (early warning, Stage 1)
    - 6 (material risk, Stage 2)
    - 7 (serious risk, Stage 3)
    - 8 (non-viability imminent, Stage 4)
  - Staging:
    - ORR 1 to 4 categorized as Stage 0 (or not staged).
    - Staging signals when an institution needs to take early action to address supervisory concerns.
  - Ratings updated when new information indicates changing risks.
  - Previous Composite Risk Rating comparisons possible; all banks had been rated according to new methodology earlier in 2023; by April 2024 ratings were confirmed through extensive review.
  - Next annual rating update to be concluded by March 2025.
  - New ORR outcomes: more banks being staged (having a rating downgrade) and an easier process for banks to address supervisory issues.
  - ORR considers climate risk as a transverse risk across the scorecard.
  - ORR focuses on whole institution level; identified issues assessed relative to impact on viability.
  - ORR reacts quickly to most serious risk because each of four risk categories can drive the ORR outcome (no fixed weights).
  - OSFI is working to incorporate “integrity and security” risks in the ORR Scorecard and developing additional supervisory support material. Areas of focus include business and climate risks.
  - Most supervisory grids from previous CRR remain relevant for ORR.

### Supervisory resourcing and tiering
- LS assignment and teams:
  - One LS appointed for each institution responsible for managing and coordinating supervisory work through a team of supervisors and specialist divisions.
  - One LS for each of the six D-SIBs with a team of around 6 people.
  - Division responsible for SMSBs is composed of 62 people, with an average of around one supervisor responsible for two institutions (more staff assigned to Tier 2 banks than to Tiers 3 to 5).
  - Specialists’ teams vary in size; divisions dealing with emerging risks such as technology and climate risks have 32 and 26 people, respectively.
- Tiering assigned since end–2023; five tiers based on size, complexity and potential contagion:
  - Tier 1 (High): large and/or complex institutions with highest system impact–6 banks
  - Tier 2 (Medium-High): large and/or complex institutions with significant system impact–8 banks
  - Tier 3 (Medium): Mid-sized institutions with moderate system impact–17 banks
  - Tier 4 (Medium-Low): Smaller and/or less complex institutions with low system impact–33 banks
  - Tier 5 (Low): Smallest, least complex institution with very low system impact–38 banks
- Note: The quantity of banks in tiers does not consider institutions consolidated in bank groups; the sum of banks in the tiers is lower than the quantity of banks operating in Canada.
- Communication and quality assurance:
  - ORR generally communicated annually but can be changed based on supervisory work results.
  - Senior management can review bank ratings at any time.
  - OSFI has quality assurance to ensure rating consistency and supervisory strategy proportionate to risk profile.
  - Larger institutions (Tiers 1 to 4) receive ORR and ratings for each of four risk categories; the weakest category becomes the starting point for the ORR and the ORR cannot be better than any rated category.
  - ORR can be worse than category ratings where multiple issues lead to multiple categories being rated at the same level.
  - Tier 5 banks receive a sole ORR that considers all categories in aggregate.
  - Internal assessments of largest institutions (Tiers 1 to 3) include more detailed analysis of additional risks.

*Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf*

### 1. For the “Business Risk” category, which represents a forward-looking assessment of

### 1canea2025007-source-pdf - 1. For the “Business Risk” category, which represents a forward-looking assessment of

### Business Risk (business model sustainability)
- Business Model, Strategy, and Risk Appetite: sustainability of the business model, its viability and attainability of the strategic plan, also reflecting reputational risks.  
- Performance: assesses the performance of the institution in the context of the business model.  
- External Factors: extent to which the business model is susceptible to external factors, including climate risk and digital innovation.

### Financial resilience (ability to withstand financial stress)
- Capital: adequacy against both regulatory requirements and internally developed targets, to ensure resilience in stress scenarios (includes capital management and the ability to identify, measure, and monitor risk).  
- Liquidity: assesses liquidity adequacy and funding position for banks, to ensure resilience in stress scenarios (includes an assessment of liquidity management and the ability to identify, measure, and monitor risk).  
- Financial Risk Profile: assesses risk levels and exposures, as well as the effectiveness of risk oversight and controls (includes a net assessment of risk on an institution–wide basis, incorporating exposures as well as risk management and controls). For deposit-taking institutions/banks, typical considerations include credit risk and market risk in both the trading and banking book.

### Operational Resilience (ability to maintain operations)
- Technology: maintain a technological environment that is stable, scalable and resilient, including disaster recovery.  
- Cyber: maintain the confidentiality, integrity, and availability of technology assets.  
- Operations: identify, manage and mitigate operational risks, including related governance and risk management frameworks (business continuity, third party and data management), with emphasis on preparation, response and adaptation.

### Risk Governance
- Governance: control frameworks, processes and structures to effectively identify, assess and manage significant risks (including approach to the design, governance, management of culture and behavior to support sound decision making, prudent risk taking and effective risk management).  
- Business and Central Functions: business and central functions’ ability to maintain an effective control environment, manage day-to-day operations and oversee the execution of the business strategy.  
- Risk and Compliance Oversight: whether the enterprise-wide risk and compliance oversight functions provide independent oversight and objective challenge over business and central functions risk taking activities and compliance matters.  
- Internal Audit: whether it provides independent assurance to the board and senior management on the effectiveness of and adherence to internal controls, risk management and governance processes used by business and central functions and risk and compliance oversight.

### Climate Risk (transverse risk)
- Business Risk: external factors in the context of climate risks and incorporates implications into business model, strategy and risk appetite.  
- Risk Governance: the extent to which governance and accountability structures are in place to manage climate risks and to ensure they are accounted for within the ERM and RAFs.  
- Financial Resilience: the extent to which robust processes are in place to identify, measure and mitigate climate related risks.  
- Operational Resilience: the extent to which an institution actively mitigates and monitors climate risks to maintain operational resiliency.

### Broader supervisory framework notes and cross-sector processes
- Broader considerations regarding financial system stability and the macroeconomic environment are factored into the supervisory framework via the planning process, which can result in cross-sector reviews.  
- Consideration is given to the ERC discussion of risks in a heatmap that identifies priorities. The Applied Risk Research and Analytics Division is responsible for the studies and analysis presented at the ERC (examples noted: recent thematic reviews on commercial real estate, data governance, and corporate governance).  
- Regarding banks’ resolvability: CDIC is the resolution authority and provides depositor protection in Canada, responsible for banks’ resolution planning. The Guide to Intervention for Federally Regulated Deposit-Taking Institutions outlines coordination mechanisms between OSFI and CDIC from earlier stages of intervention up to the non-viability or insolvency stages. CDIC and OSFI cooperate in regards to recovery and resolution planning. An ORR that represents “staging” (ratings 5 to 8) has a direct impact in deposit protection cost incurred by the bank with CDIC, where additional premiums are paid by the bank.  
- Exposure of Tier 1 banks to risks of the wider group is limited, given restrictions in the composition of the conglomerate (as described in CP12, ECs1 and 2). The risk is not that limited for smaller banks that are not subject to the restriction. The supervisory framework does not incorporate the assessment of risks from the banks’ group structure for SMSBs. Assessors view that, given the size of SMSBs in Canada, this is not paramount in terms of supervisory priorities and that OSFI’s supervisory framework is sound and fit for purpose.

### EC2 — Assessment and designation of systemically important banks (D-SIBs)
- Framework history and practice:
  - The framework used by OSFI to assess and identify banks as D-SIBs has been in place in Canada since March 2013.  
  - OSFI designated six banks as D-SIBs via a published advisory: the Bank of Montreal, The Bank of Nova Scotia, Canadian Imperial Bank of Commerce, National Bank of Canada, Royal Bank of Canada, and The Toronto-Dominion Bank.  
  - Two of the D-SIBs are, as of October 2024, also designated global systemically important banks (G-SIBs): Royal Bank of Canada and Toronto-Dominion Bank.  
  - In 2016, the Bank Act was amended to allow for a more formal designation of the D-SIBs under the legislation. Pursuant to subsection 484.1(1) of the Bank Act, the Superintendent formally designated the six above-noted banks as D-SIBs on August 21, 2018. The Minister has override powers under the same subsection.  
  - The framework was subsequently incorporated into OSFI’s Capital Adequacy Requirements (CAR) guideline, and is set out in Annex 1 to Chapter 1.
- Inferences from current designation:
  - Size: (i) the largest six banks account for more than 90 percent of total banking assets; (ii) the differences among the largest banks are smaller if only domestic assets are considered; (iii) relative systemic importance declines rapidly after the top five banks and after the sixth bank.  
  - Inter-connections: measures of intra-financial assets and intra-financial liabilities point to the dominance of the largest Canadian banks.  
  - Substitutability: OSFI considers roles in domestic financial markets and infrastructures (e.g., underwriter rankings, shares of Canadian dollar payments through LVTS and the Automated Clearing and Settlement System), which indicate dominance of the largest Canadian banks.  
  - Additional information: the five largest banks are by far the dominant banks in Canada and consistently play central roles in a range of activities; rank-order importance varies by measure.
- OSFI’s stance and observables:
  - OSFI believes there are strong grounds for treating the D-SIBs in the same way rather than developing a single index with arbitrary weights. No degree of systemic importance is attributed among the D-SIBs.  
  - The designation of the six D-SIBs has not been reviewed since the formal designation in 2018. Assessors view the stability of the D-SIBs designation as coherent with the increasing concentration of the banking system in the six D-SIBs, where total assets held increased from 94 percent to 96 percent from end–2018 to end–2023.

### EC3 — Supervisory assessment of compliance with prudential regulations
- Description and findings:
  - The Bank Act establishes that banks have to provide the information required by OSFI (section 628), which has to periodically examine banks, including through having access to bank’s record and inquiring (sections 643 and 644).  
  - Supervisors assess compliance with prudential regulations and legal requirements as part of normal supervisory work performed using the Superintendent’s general powers.

*Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf*

### Section V of OSFI’s Corporate Governance Guideline establishes that OSFI supervises banks

### Section V of OSFI’s Corporate Governance Guideline establishes that OSFI supervises banks

### Supervisory mandate, frameworks and processes
- OSFI supervises banks "to assess their financial condition and monitor compliance with the applicable federal legislation." OSFI’s assessment criteria is described in EC1.
- The Regulatory Compliance Management Guideline (section III) requires banks to establish a Regulatory Compliance Management (RCM) Framework to enable a risk-based approach for identifying, assessing, communicating, managing and mitigating regulatory compliance risk.
- Compliance risk is assessed holistically and considers its potential impact to the viability of the bank or banking group.
- Supervisory assessments are registered in the system Vu and supporting supervisory documents are stored online. Supervisors communicate recommendations and required remedial actions through supervisory letters.
- Supervisory guides, assessment criteria and specialist advice (Culture & Compliance Risk Division) support supervisors in assessing risks, controls and oversight functions.

### Risk assessment, macro environment, and emerging risks (EC4)
- OSFI objects under the OSFI Act, section 4(2), include: "to monitor and evaluate system-wide or sectoral events or issues that may have a negative impact on the financial condition of financial institutions." (object 4(2)(d))
- Applied Risk Research and Analytics division responsibilities:
  - Conducting macro risk surveillance, including identification, quantification and prioritization related to external risks;
  - Monitoring and assessing OSFI’s overall response, resources, and prioritization on top external risks and in accordance with OSFI’s risk appetite statement;
  - Providing a forward-looking macro lens on emerging risks, and trends, including through the ARO;
  - Delivering forward-looking risk insights, effective challenge, and policy advice grounded in data, analytics, and modelling;
  - Advising on the approach, rates and levels for prudential tools, such as the Domestic Stability Buffer (DSB);
  - Leading and coordinating an enterprise-wide approach to housing and mortgage risks, in collaboration with the Regulatory Affairs Directorate and the Risk Advisory Hub (RAH).
- ERM Committee structure and function:
  - Provides advice to the Superintendent, the Executive Committee, the Management Oversight Committee, and the Supervision and Policy Oversight Committee.
  - Two subcommittees: the ERC (Enterprise Risk Committee) and the IRC.
  - ERC meets at least quarterly, assesses macroeconomic environment, financial system, industry and institution-specific emerging risks, and maintains a risk catalogue presented as a comprehensive heatmap.
- ERC heatmap risk factors include: Housing and Mortgage Risk, Commercial Real Estate (CRE), Liquidity and Funding Risk, Integrity Security Foreign Interference Risk, Cyber Risk, 3rd Party risk, (non-banking financial institutions) NBFI Risks, Climate Change, Artificial intelligence and Machine Learning (AI/ML), Financial Market Volatility, Asset-Liability Management (ALM) Risk, and Geopolitical Risk. Each factor is assessed by criteria such as systemic vulnerability, probability of materialization, and status of preparedness. Dashboard includes comparative information for D-SIBs.
- Surveillance and reporting:
  - Industry surveillance team issues a short weekly report and a more comprehensive quarterly macro-economic report to front line staff.
  - Horizon Risk Surveillance division (created in 2022) provides forward-looking applied research on early identification of emerging risks; reports include recommended actions and are shared internally and to ERC.
  - Examples of Horizon Risk work: private credit trends (2022), zombie companies (2022), connectivity between Alternative Asset Managers and Private Equity firms (2024).
- Climate-related risk work:
  - BoC-OSFI joint 2021 pilot on transition risk scenarios; two pilot exercises in 2023: "Understanding the systemic implications of climate transition risk: Applying a framework using Canadian financial system data" and "Climate-related flood risk to residential lending portfolios."
  - In 2024 OSFI undertook a portfolio alignment analysis of the six D-SIBs’ large corporate loan books with climate transition scenarios using the Paris Agreement Capital Transition Assessment (PACTA) methodology.
  - Guideline B-15: Climate Risk Management—most D-SIB expectations enter into force on October 1, 2024.
  - OSFI developed supervisory dashboards for physical and transition climate risks and engaged an external vendor for physical risk data by postal code.
  - OSFI finalized the Climate Risk Returns in March 2024 to collect standardized climate-related data on emissions and exposures; OSFI expects to collect data on D-SIBs at the end of fiscal year 2024.
- OSFI publishes the ARO; last ARO published on OSFI’s website on May 22, 2024, for fiscal year 2024–25.

### System-wide risk identification, coordination and monitoring (EC5)
- FISC (Financial Institutions Supervisory Committee) chaired by OSFI meets at least quarterly to exchange information among OSFI, DOF, BoC, CDIC and FCAC.
- OSFI participates in SRSC, HoA and other federal-provincial regulatory forums to discuss systemic risk issues.
- FINTRAC engagement: OSFI meets at least quarterly with FINTRAC; FINTRAC outputs are used for prudential assessments and included in supervisory work.
- Flow of emerging risk reports: typically tabled at ERC then cascaded to senior committees; ERC can recommend supervisory actions (information requests, guidance, advisories).
- OSFI issues the ARO and shares risk research with federal and provincial regulators (example: Private Equity and insurance results discussed at SRSC chaired by BoC).

### Resolvability and recovery (EC6)
- Roles:
  - OSFI leads on assessing Recovery Plans (recoverability) for banks.
  - CDIC is Canada’s resolution authority and leads assessments of resolvability. CDIC’s Resolution Planning By-law (June 2022) formalizes requirements for D-SIB resolution plans and processes to address deficiencies.
- Coordination:
  - Strategic Alliance Agreement between OSFI and CDIC provides coordination framework and information exchange.
  - Financial Information Committee (FIC), a FISC sub-committee (OSFI, BoC, CDIC) supports cost-effective data collection; FIC is a shared database of banks’ information.
- OSFI’s ORR incorporates assessment of the "Intervention Stage" from 0 to 4 (staging). Specific supervisory measures attach to each stage. Guide to Intervention outlines coordination mechanisms between OSFI and CDIC for each stage:
  - No stage/Stage 0 (ORR 1 to 4): normal information sharing and discussions.
  - Stage 1 (ORR 5): CDIC actions could include information requests, CDIC Watchlist, special examinations, premium surcharge.
  - Stage 2 (ORR 6): CDIC could send formal reports under section 30 of the CDIC Act, terminate deposit insurance (with notice), conduct preparatory examinations, or apply to Court for compliance orders.
  - Stage 3 (ORR 7): CDIC could support restructurings, acquire assets, make or guarantee loans, make or guarantee deposits.
  - Stage 4 (ORR 8): CDIC could cancel deposit insurance, initiate FIRP order, apply for winding-up order, or give public notice of termination/cancellation (subject to Minister’s advice).
- CDIC Resolution Plan Guidance 5.1.1 evaluates resolvability risks including: Legal structure suitability; Loss absorbency; Access to liquidity; Bail-in execution (including valuation); Trading book wind-down; Continuity of access to financial market infrastructures; Operational continuity, crisis capabilities and governance; Resolution plan testing program.
- Resolution plans and process:
  - Banks’ recovery plans inform resolution plans (restructuring options, de-risking, asset disposals).
  - OSFI’s recovery planning expectations include the 2012 Recovery Plan Principles and Technical Notes (internal, not published).
  - Full resolution plans first submitted in 2018 by D-SIBs; revised and resubmitted in 2019, 2021 and 2023; next submission in 2025.
  - CDIC’s plan review process: completeness check, horizontal component reviews (Capital, Crisis Capabilities, Funding & Liquidity, Trading Book Wind-down, Valuation, Financial Market Infrastructure access, Bail-in Execution) with teams of 3–5 people per component; vertical bank-dedicated teams ensure harmonization. Feedback shared with banks; banks receive notice of compliance. CDIC has not found plans non-compliant nor encountered impediments that would impede resolution strategies.
  - CDIC uses OSFI ratings as a basis for an Internal Member Rating (IMR).
- Recommendations regarding resolvability:
  - Increase OSFI’s participation in CDIC’s assessment of banks’ resolvability, establishing a process where OSFI would provide resolvability input and participate in the assessment of banks’ resolution plan, at least for Tier 1 banks, as required by EC6.

### Early intervention framework and staging (EC7)
- OSFI’s Guide to Intervention describes early intervention responsibilities:
  - No stage/Stage 0 (ORR 1 to 4): regular risk-based supervision; supervisory letter and ORR; annual reporting to Minister of Finance.
  - Stage 1 (ORR 5): formal notifications, remedial discussions, assessment surcharges, enhanced monitoring, prudential agreements, capital increases, business restrictions, directions of compliance.
  - Stage 2 (ORR 6): enhanced monitoring, increased supervisory reviews, remedial measures in business plans, external auditor scope increases, special audits, contingency planning for rapid control.
  - Stage 3 (ORR 7): direct external specialists, enhanced business restrictions, staff presence at bank, expanded contingency planning, communicate need to consider resolution options.
  - Stage 4 (ORR 8): OSFI may assume temporary control of assets or bank, take control subject to Minister’s advice, or request Attorney General to apply for winding-up order.
- Problem Situation Binder exists to guide staff in crises, including non-viability.
- CDIC resolution tools available under section 39 of the CDIC Act require Superintendent opinion on non-viability.

### Regulatory perimeter and non-bank activities (EC8)
- Superintendent is a member of HoA Committee (chaired by Governor of the Bank of Canada; includes DOF and four provincial securities regulators: OSC, AMF, ASC, BCSC) to exchange information and coordinate actions on issues like hedge funds, shadow banking and perimeter issues.
- OSFI monitors bank-like activities outside the regulatory perimeter (examples: SPEs, ABCP) and raises issues with responsible authorities at HoA, FISC, or SAC.
- OSFI is notified of significant bank restructurings; approvals consider financial stability and prudential considerations.
- Value-referenced crypto assets (VRCAs) issued by institutions not regulated on a consolidated basis would be outside OSFI’s regulatory perimeter, but Canadian Securities Administrators reaffirmed on October 5, 2023 that VRCAs may constitute securities/derivatives and thus fall within securities regulators’ perimeter.
- OSFI identified NBFI activities that may be bank-like (fintech deposit-substitute products, private credit funds with leverage/deposit-like features) but believes these are not material to the Canadian financial system.

### Supervisory techniques, tools and resourcing (Principle 9; EC1–EC12)
- Supervisory model and organization:
  - Supervisory Framework guides supervision; LS (Lead Supervisor) accountable for overall risk view.
  - Dedicated specialist teams for credit, market trading, market non-trading, liquidity and technology risks; further technical teams (RESL, non-RESL retail, CRE, modelling).
  - PASS tool supports planning; supervisory strategies and workplans are documented and accessible via PASS. Changes require justification and approval.
  - Vu is the system of record for supervisory risk assessments and ratings; all supervisory letters generated and stored in Vu.
  - Electronic Data Management System (EDMS) stores electronic information from banks; Power BI dashboards support monitoring.
- Supervisory activity mix:
  - Ongoing monitoring is mainly off-site using quarterly standardized returns plus banks’ internal risk reports, audit documents and ad-hoc data calls.
  - Regular touch points: at least quarterly meetings for Tier 1 and Tier 2 banks with CROs, CFOs and other senior staff; Tier 3–5 meetings generally not more than twice a year for better-rated banks.
  - Cross-sector/thematic reviews have increased; many are off-site and rely on bank questionnaires/surveys; on-site reviews more common for non-financial issues (technology, cyber).
  - HORT (horizontal on-site review team) leads cross-sector reviews for Tier 1 and 2 institutions; evidence shows most cross-sector reviews are conducted off-site with on-site follow-ups as needed.
- Information, analytics and stress testing:
  - Supervisors use regulatory returns, supervisory dashboards (Financial Institution view, Portfolio view, Capital, Earnings, Monthly credit view), bank internal and external audit reports, recovery plans, RESL and CRE data calls, media monitoring and rating agency reports.
  - MST (Macroeconomic Stress Test): every two years OSFI requires 6 D-SIBs and other large banks (totaling 11) to conduct MSTs under severe but plausible scenarios prescribed with BoC; projects selected financial statements and ratios over three years. MST inputs supervisory actions up to Pillar 2 capital/liquidity adjustments. New MST program will include mid-sized banks annually starting in 2026.
  - As of March 2024, OSFI had 252 regulatory and supervisory staff for banking, an increase of 35 percent since 2019; general supervision support increased more than 4 times and risk support grew by 31 percent. Growth concentrated in data management and emerging risks (climate, technology); teams dedicated to traditional risks remained stable or had staff losses.
- Use of third parties (EC11):
  - Legal authority to delegate inquiry powers via Bank Act sections 614, 644 and 958, but Superintendent’s prudential responsibilities cannot be outsourced.
  - Rigorous procurement and confidentiality agreements; third parties used for specialized reviews and rare event preparation (example: large accounting firm commissioned for on-site liquidity monitoring).
- Supervisory reporting and data (Principle 10; EC1–EC3):
  - Legal powers: Section 628 (bank must provide information as required); subsection 643(2) (access to records, cash, assets, auditors); subsection 308(4) (financial statements prepared in accordance with GAAP/IFRS).
  - Regulatory Reporting System (RRS) houses returns; BoC hosts RRS; data moved to OSFI data warehouse and accessible via BI tools. Reports published periodically with sensitivity protections.
  - Examples of returns: BCAR (capital adequacy) quarterly; Solo TLAC for D-SIBs; balance sheet (M4), Deposit Liabilities (K4), Interest Rate Risk (I3).
  - Climate Risk Returns finalized March 2024; data collection of D-SIBs and IAIGs expected to start based on fiscal year-end 2024 in early 2025.
  - OSFI requires IFRS for banks; instructions for returns updated annually (Annual Housekeeping Exercise); instructions reference applicable IFRS standards.
  - Valuation guidance: OSFI asked banks to follow Chapter 9 of the CAR guideline, section 9.4 (implements Basel CAP50). OSFI issued IFRS 9 Financial Instruments and Disclosures Guideline (June 2016, amended April [text truncated in source]).
- Quality assurance and review:
  - SQAD provides quality assurance on methodology design, adherence, and supervisory outputs; Group Rating Committee reviews Tier 1–2 banks’ ratings (binding); Entity Rating Panel (ERP) reviews ratings (non-binding).
  - Internal Audit (OSFI) performs periodic audits; most recent affecting supervision were 2022: "Human Capital Management" and "Supervisory Process of Systemically Important Banks Group."
  - OSFI committed to holistic supervisory framework reviews at least every 5 years; new framework came into force April 1, 2024, with a post-implementation review underway.

### Key findings, assessments and recommendations
- Assessment outcomes:
  - Principle 8: Compliant. OSFI’s ORR (effective April 2024) has been efficiently incorporated into supervisory processes; ORR is more agile, produced important rating changes and provides clearer remediation paths. Since end–2023 OSFI has been grouping banks into tiers to enhance proportionality.
  - Principle 9: Largely Compliant. OSFI supervision effective overall, but the assessors identified excessive reliance on off-site monitoring and bank-provided surveys/questionnaires for thematic reviews; core banking areas (credit, liquidity, IRRBB) have seen constrained supervisory resources.
- Specific findings:
  - Supervisory strategy relies heavily on information obtained from banks through monitoring and cross-sector reviews; many thematic reviews are questionnaire-based followed by analytical benchmarking.
  - Resource allocation example: 5 supervisors working on liquidity risk and 33 on credit risk, while 32 dedicated to technology risk, 26 to climate risk and 16 to integrity and security—leading to fewer deep institution-specific reviews in core areas.
  - Most supervisory work recorded in PASS is monitoring rather than deeper review.
- Recommendations (as stated in source):
  - Elaborate and publish guidelines (regulatory guidance) on recovery planning along the lines of the Recovery Plan Principles and the content of the Technical Notes that currently provide internal guidance to supervisors. A published guideline would provide more clarity on OSFI’s expectations for recovery plans, including on differentiating expectations for SMSBs, and would potentially facilitate the recovery and resolution planning processes.
  - Increase OSFI’s participation in CDIC’s assessment of banks’ resolvability, establishing a process where OSFI would provide resolvability input and participate in the assessment of banks’ resolution plan, at least for Tier 1 banks, as required by EC6.
  - Improve supervision of the wider group of SMSBs that are not widely held and have major shareholders, parent companies and affiliates. Areas to keep up to date: group structure (legal and operational, including intragroup relationships, such as contracts, services, loans and other exposures), list of significant shareholders, risk of excessive leverage (for example, through hidden liabilities above the parent level), capacity of the parent to provide solvency and liquidity support, reputation and contagion risks, relationship with the parent company (including quality of governance and influence on the subsidiary), affiliates and related parties.
  - Increase the number of deep and targeted reviews in which supervisors verify banks’ practices in core banking areas, including on-site reviews in areas such as credit, market, liquidity and operational risks, and IRRBB.
  - Establish and implement formally distinct supervisory cycles with different lengths for banks in different tiers, setting a minimum number of deeper reviews expected to be completed in a supervisory cycle for a specific bank, in accordance with its ORR.

*Source: Section V of OSFI’s Corporate Governance Guideline (as presented in the supplied IMF assessment text).*

### 2022. The Guideline provides application guidance to banks applying the FVO in

### 1canea2025007-source-pdf - 2022. The Guideline provides application guidance to banks applying the FVO in

### Scope and purpose
- Provides application guidance to banks applying the FVO in IFRS 9—Financial Instruments as issued by the International Accounting Standards Board (IASB).
- Clarifies that IFRS 9 allows entities to designate a financial asset or financial liability at fair value through profit or loss upon initial recognition.

### Supervisory expectations (purpose of issuing the guideline)
- Application of the FVO to meet the criteria set forth in IFRS 9 in form and substance.
- Appropriateness of risk management systems (including related risk management policies, procedures and controls) prior to initial application of the FVO for a particular activity or purpose and on an ongoing basis.
- No application of the FVO to instruments for which an institution is not able to reliably estimate fair values.
- Supplemental information to assist OSFI in assessing the impact of an institution’s utilization of the FVO.

### Restrictions and exceptions
- Generally, the FVO should not be used for:
  - loans to companies with annual gross revenue below $75 million,
  - loans to individuals,
  - portfolios made up of such loans.
- Exception noted: This requirement does not apply to life insurers’ loans if classified as Fair Value through Other Comprehensive Income.

*Source: 1canea2025007-source-pdf - 2022. The Guideline provides application guidance to banks applying the FVO in*

### Section 9.4.2 of Chapter 9 of the CAR guideline details the OSFI’s expectations in relation to

### 1. Moral suasion

### 1. Moral suasion

### OSFI’s approach and practice
- Assessors conclude moral suasion is the preferred approach at OSFI; formal use of statutory powers is regarded as an ultima ratio instrument and used only if other possibilities fail.
- Moral suasion tools used: meetings with management, supervisory letters, ORR rating downgrades, and staging (change in Intervention Stage from 0 to 1).
- OSFI may communicate non-binding restrictions on growth, dividends, or certain businesses in supervisory letters; banks generally comply despite the non‑binding nature of these communications.
- Supervisory Letters and Action Standard guidance:
  - “Since our guidelines are not legally binding, we issue recommendations when we identify deficiencies in relationship to guidelines.”
  - Supervisors should avoid requirement‑type language in letters when not intending to exercise statutory powers; consult Legal Services and Regulatory Affairs Directorate when considering formal exercise of statutory powers.

### Outcomes and examples of moral suasion in practice
- OSFI examples where moral suasion achieved remediation:
  - Case 1: Significant gaps in ERM and compliance, governance weaknesses, and underwriting remediation delays. Action: supervisory letter notifying staging; required demonstration of effective board, senior management, and oversight, operationalizing ERM, and remediation of credit risk/oversight findings. Recommendations monitored and in process of closure.
  - Case 2: Rapid growth with insufficient oversight enhancements. Action: supervisory letter notifying staging; required enhancement of risk management organizational structure and risk governance/appetite framework, succession and talent management plan, remediation of commercial real estate findings, and maintenance of a prudent capital and liquidity framework. Bank complied; third party expert to ensure remediation and possible de‑staging afterwards.
  - Case 3: Persistent credit risk management weaknesses in commercial real estate, weak capital buffers, funding concentrations, and operational risk controls for technology, fraud, and cyber. Action: supervisory letter notifying staging; required revised internal capital targets, capital contingency plan, ICAAP, stress testing, depositor concentration limits, restrictions on material capital‑reducing actions without OSFI written consent, strengthened operational resilience including thresholds and monitoring, fraud controls for digital payments, and multifactor authentication for commercial banking platform. Bank complied.
- These cases demonstrate reliance on supervisory meetings and supervisory letters to impose restrictions and obtain remedial actions without deploying statutory powers.
- Assessors informed that, had moral suasion been insufficient, OSFI could have resorted to its formal statutory powers.

### Formal statutory enforcement powers (availability and principles)
- Supervisory Letters and Action Standard: for more serious urgent concerns, the LS should notify the FRFI that formal statutory powers will be invoked if recommendations are not addressed; consult Legal Services and Regulatory Affairs Directorate. Examples of such situations:
  - “Matters that could cause significant harm to the safety and soundness of the FRFI”
  - “Matters of non-compliance with legal obligations set forth in statutes, regulations, and orders”
  - “Repeat findings that have escalated in importance due to insufficient attention or inaction”
- No recent examples where OSFI resorted to these powers to induce compliance, but they are available to address unsafe or unsound practices and regulatory non‑compliance (including deviations from non‑binding OSFI guidance or recommendations).

### Enumerated statutory powers under the Bank Act (selected items)
- Order regarding Security Interests — Superintendent may, pursuant to section 419, direct a bank to amend its policies regarding the creation of security interests and acquisition of beneficial interests in property subject to a security interest.
- Limit on Assets — Superintendent may, pursuant to section 54.1, recommend to the Minister to impose a limit on the assets held by a bank.
- Designation of Related Parties — Superintendent may, pursuant to section 486, designate any person as a related party of the bank even if that person does not meet the statutory definition.
- Repatriate Management Functions — Superintendent may, pursuant to section 495, order the repatriation of management functions where outsourcing of all or substantially all of those functions is deemed inappropriate.
- Revoke Auditor’s Appointment — Superintendent may, pursuant to section 317, revoke the appointment of an auditor.
- Require Board Meeting — Superintendent may, pursuant to section 187, require a meeting of a bank’s board of directors to address specific matters; Superintendent may attend and be heard.
- Veto over Appointment of a Director or Senior Officer — Superintendent may, pursuant to section 647, veto the appointment of a director or senior officer of a “problem” bank if of the opinion the person is not qualified.
- Removal of Director or Senior Officer — Superintendent may, pursuant to section 647.1, remove a director or senior officer if of the opinion the person is not qualified.
- Valuation of Assets — Superintendent may, pursuant to section 485, establish appropriate values of assets and so inform the bank.
- Expand Audits and Special Audits — Superintendent may, pursuant to section 325, require expansion of an external audit’s scope or require a special audit.
- Deny Approvals — Superintendent may, pursuant to section 973.01, take into account any relevant prudential considerations when deciding whether to grant an approval.
- Revoke, Suspend, or Amend an Approval — Superintendent may, pursuant to section 973.03, revoke, suspend, or amend an approval considering relevant prudential matters.
- Non‑compliance with Terms/Conditions/Undertakings — Superintendent may, pursuant to section 973.04, revoke, suspend, or amend an approval or apply for a court order in case of non‑compliance.
- Criminal offences and administrative sanctions (fines) — Non‑compliance with provisions of the Bank Act is a criminal offence that may be subject to criminal prosecutions (OSFI has never resorted to this possibility). Civil monetary penalties may be imposed under the Administrative Monetary Penalties (OSFI) Regulations.

### Court enforcement
- Sections 646 and 989 empower the Superintendent to apply to a court for an order requiring an institution or its representatives to cease a contravention of the Act, or to comply with a Direction of Compliance or Prudential Agreement.
- Court enforcement is never used in practice; OSFI considers it impractical, lengthy, and potentially exposing confidential information to public scrutiny.
- Court enforcement is the only legal avenue to force compliance in a recalcitrant institution, except for the taking of control (described below); OSFI’s administrative acts require judicial intervention to force compliance in common law settings.

### Taking control of the bank and other urgent intervention powers
- Taking Control — Superintendent may, pursuant to section 648, take control of the assets of, or take control of the bank for 16 days.
- Where the Superintendent intends to take/continue control of the assets for a period exceeding 16 days or take control of the bank itself, a non‑objection of the Minister of Finance is needed; the Minister can terminate the Superintendent’s intervention at any moment.
- Taking of control is normally the culmination of escalation and is typically undertaken when there are concerns about bank viability and after discussions with CDIC and other federal public bodies at FISC; often results in activation of resolution or liquidation powers:
  - Request a Winding‑up Order — Superintendent may, pursuant to section 651, after taking control, seek a winding‑up order.
  - Declare the Non‑Viability of the bank (see EC3).
- Subsection 648(1.1) sets conditions for taking control; control may be taken where any of the following apply (exact text preserved):
  - (a) the bank has failed to pay its liabilities or, in the opinion of the Superintendent, will not be able to pay its liabilities as they become due and payable;
  - (b) [Repealed, 2001, c. 9, s. 182]
  - (c) the assets of the bank are not, in the opinion of the Superintendent, sufficient to give adequate protection to the bank’s depositors and creditors;
  - (d) any asset appearing on the books or records of the bank or held under its administration is not, in the opinion of the Superintendent, satisfactorily accounted for;
  - (e) the regulatory capital of the bank has, in the opinion of the Superintendent, reached a level or is eroding in a manner that may detrimentally affect its depositors or creditors;
  - (f) the bank has failed to comply with an order of the Superintendent under paragraph 485(3)(a);
  - (g) the bank’s deposit insurance has been terminated by the Canada Deposit Insurance Corporation;
  - (g.1) in the opinion of the Superintendent, the bank’s depositors and creditors may be detrimentally affected because all of the common shares or membership shares of the bank must be disposed of under a direction made by the Minister or because there is a prohibition under this Act in respect of the exercise of the right to vote attached to all of the common shares or membership shares of the bank;
  - (h) in the opinion of the Superintendent, any other state of affairs exists in respect of the bank that may be materially prejudicial to the interests of the bank’s depositors or creditors or the owners of any assets under the bank’s administration, including where proceedings under a law relating to bankruptcy or insolvency have been commenced in Canada or elsewhere in respect of the holding body corporate of the bank;
  - (i) in the opinion of the Superintendent, the continued operation of the bank by the directors of the bank or by the officers of the bank responsible for its management would be materially prejudicial to its integrity or security; or
  - (j) in the opinion of the Superintendent, the continued operation of the bank by the directors of the bank or by the officers of the bank responsible for its management would pose a risk to national security.

### EC3 context (interaction with prudential thresholds)
- Supervisor uses powers where a bank falls below established regulatory threshold requirements, including prescribed regulatory ratios or measurements; supervisor intervenes at an early stage to require corrective action.
- Bank Act grants Superintendent powers for situations when a bank exceeds or falls below prudential thresholds:
  - Direction of Compliance — Superintendent may, pursuant to section 645, issue a Direction of Compliance to cause the bank to cease unsafe or unsound practices and order necessary remedial actions to ensure prudential thresholds continue to be met.
  - Prudential Agreement — Superintendent may, pursuant to section 644.1, enter into a Prudential Agreement to implement measures designed to maintain or improve safety and soundness, including ensuring prudential thresholds continue to be met.
- In almost four decades of OSFI history, use of these two statutory powers is rare; assessors could not review any relevant or recent examples. The effectiveness of moral suasion on a quotidian basis and the availability of taking of control underpin OSFI’s supervisory toolkit.

*Source: 1canea2025007-source-pdf - 1. Moral suasion*

### Section 648 BA when there is an imminent threat to safety and soundness had made them

### Section 648 BA when there is an imminent threat to safety and soundness had made them

### OSFI powers and corrective measures
- Limitations / Conditions on the Order to Commence and Carry on Business (sections 53 and 54): Superintendent may impose conditions/limitations by amending a banking license; used occasionally to restrict activities or businesses of a bank.
- Capital / Liquidity Order (subsection 485(3)): Superintendent may issue an Order to increase capital and/or liquidity; generally OSFI communicates a higher non-binding expectation in the supervisory letter without exercising this power.
- Divestment Order (section 480): Superintendent may direct disposal of loans, investments or interests made in contravention of statutory investment regime; reactive power only when a Bank Act investment limit has been breached.
- Undertaking Approvals (section 973.02): Minister and Superintendent may impose terms/conditions or require undertakings when granting approvals; used to secure access to information on non-regulated entities or parental support.
- Undertaking Investments (section 470): Superintendent may require a bank that controls a permitted entity to provide an Undertaking regarding that entity’s activities.
- Direction of Compliance (section 645), Prudential Agreement (section 644.1) and other formal measures exist but are "almost never used in practice" in recent examples.

### Intervention stages, escalation, and supervisory responses
- When very serious concerns exist (institution is Stage 3 "Future financial viability in serious doubt" or approaching Stage 4 "Non-viability/insolvency imminent"), OSFI would likely adopt measures from the Guide to Intervention for Federally Regulated Financial Institutions, including:
  - Directing external specialists or professionals to assess loan security, asset values, sufficiency of reserves, etc.
  - Enhancing the scope of business restrictions and/or increasing detail of information required from the institution.
  - OSFI staff presence at the institution to monitor the situation on an ongoing basis.
  - Expanding contingency planning.
  - Communicating importance of considering resolution options such as restructuring or seeking a prospective purchaser.
- The Guide to Intervention is a public document that establishes a presumption that predefined measures would be adopted unless a public interest justification exists to act differently.
- Internal OSFI policy addresses scenarios for use of main intervention powers (take control to liquidate via Attorney General winding-up order; declaring non-viability to trigger CDIC-led resolution; conversion of capital instruments into common shares). These powers may be combined and are linked to preventing breaches of regulatory thresholds or restoring normality.

### CDIC role and tools as OSFI escalates involvement
- CDIC and OSFI conduct more in-depth and frequent discussions; regular meetings at sub-FISC and FISC as required to discuss evolving situation and contingency planning.
- CDIC actions to minimize exposure to loss may include:
  - Acquiring assets from the member institution;
  - Making or guaranteeing loans or advances with or without security, to the member institution;
  - Making or guaranteeing a deposit with the member institution.
- If non-viability is imminent, CDIC may:
  - Cancel the policy of deposit insurance of a member institution if CDIC is of the opinion the member institution is or is about to become insolvent, subject to the Minister’s advice and after notifying the Superintendent (measure foreseen in law but "not likely" given financial stability effects).
  - Initiate a "FIRP" (Financial Institution Restructuring Provisions) or an E-FIRP (Enhanced Financial Institution Restructuring Powers for D-SIBs which allow bail-in) following a formal Superintendent’s report that the institution has ceased, or is about to cease, to be viable, involving CDIC asking the Minister of Finance to recommend a Governor in Council "FIRP" order under the CDIC Act if a restructuring transaction is likely and consistent with CDIC’s objects.
  - Apply for a winding-up order under the Winding-up and Restructuring Act if CDIC considers the member insolvent or about to become insolvent, unless the Minister advises otherwise; CDIC may act as liquidator or receiver if appointed.

### Actions available to Superintendent when non-viability is imminent
- Assuming temporary control of the assets of the institution and the assets under its administration if statutory conditions for taking control of assets exist.
- Taking control of assets or the institution if statutory conditions exist, unless the Minister advises OSFI it is not in the public interest to do so.
- Requesting that the Attorney General of Canada apply for a winding-up order where the assets or institution are under the Superintendent’s control.
- Declaring non-viability in accordance with Subsection 39.1(1) of the CDIC Act, which requires a written report to the Corporation where the Superintendent is of the opinion that:
  - (a) a federal member institution has ceased, or is about to cease, to be viable, and
  - (b) viability cannot be restored or preserved by the Superintendent’s powers under the Bank Act, the Trust and Loan Companies Act or the Cooperative Credit Associations Act,
  - after providing the institution a reasonable opportunity to make representations.

### Specific supervisory measures and constraints described (EC4 and related)
- Range of corrective measures OSFI may apply, consistent with gravity of the situation:
  - Restrict current activities of the bank (vary Order to Commence and Carry on Business section 54; issue Directions of Compliance section 645; require Undertakings under section 973.02 or section 470; enter Prudential Agreement section 644.1).
  - Impose more stringent prudential limits and requirements (Capital/Liquidity Order section 485; Direction of Compliance section 645; Undertakings; Prudential Agreement; place limit on assets held by a bank section 54.1).
  - Withhold approval of new activities or acquisitions (deny license amendment section 54; use Directions of Compliance section 645).
  - Deny approval of acquisitions constituting a substantial investment requiring Minister or Superintendent approval (section 468) or involving asset transactions comprising more than 10 per cent of the bank’s total assets (section 482).
  - Restrict/suspend payments to shareholders or share repurchases via Capital Order (subsections 79(4) and 485(4)), though OSFI generally uses moral suasion instead.
  - Restrict asset transfers (deny approval where transfers comprise more than 10 per cent of total assets section 482; Direction of Compliance section 645; Prudential Agreement section 644.1).
  - Secure Undertakings related to approvals or investments (sections 973.02 and 470), used in practice to obtain information on non-regulated group entities or parental support.
  - Bar individuals from the banking sector by removing directors or senior officers (section 647.1) or vetoing appointments where person is not qualified (section 647); fit and proper assessment is primarily the bank’s responsibility.
  - Replace or restrict powers of managers, board members or controlling owners, including:
    - When Superintendent takes control under section 648, powers/duties/functions/rights/privileges of directors and officers are suspended and assumed by the Superintendent (section 649).
    - Revocation, suspension, or amendment of approvals could in theory restrict powers of managers or the board; Minister may also revoke/suspend/amend approval related to acquisition of significant interest/control (section 973.03).
    - Statutory ownership rules require large banks be widely held and prohibit any shareholder from being a controlling owner for large banks.
    - Legislation restricts voting rights of shareholders who contravene statutory rules on significant interests, control, limits on shareholdings, undertakings (section 392). Minister may order disposal of shares held in contravention (section 402).
  - Facilitate takeover or merger with a healthier institution; Superintendent may encourage substitute bank to assume obligations and, when in control, must manage the bank to protect depositors’ rights and interests (section 649).
  - CDIC may restructure a bank or transfer its business to a bridge institution and Governor in Council may vest shares/subordinated debt in CDIC or appoint CDIC as receiver (subsections 39.1 through subparagraph 39.3722 of the CDIC Act).

### Interim management, license revocation, and sanctions
- Interim management (section 649):
  - When Superintendent takes control, directors’ and officers’ powers are suspended and assumed by the Superintendent.
  - Superintendent may appoint one or more persons to assist in managing the company.
- Revoking the banking licence: Superintendent may revoke a bank’s Order to Commence and Carry on Business (section 54).
- Administrative Monetary Penalties (OSFI) Regulations: Superintendent may impose administrative monetary penalties on a bank for non-compliance with prudential requirements, such as limits on investments in equities or real estate, or terms and conditions or undertakings.

### Sanctions regimes and criminal offences (EC5)
- Two regimes exist for sanctioning banks and individuals:
  1. Offences: Non-compliance with the Bank Act is a criminal offence (section 980). Every person who, without reasonable cause, contravenes any provision of the Bank Act or regulations is guilty of an offence. Punishment under section 985 can include monetary fines and/or imprisonment. Crown Prosecutor decides summary conviction or conviction on indictment. "Person" includes natural persons and legal entities, so criminal sanctions may apply to the bank, Board, management or individuals. OSFI has never resorted to these criminal provisions; the beyond reasonable doubt standard and criminal law nature make them impractical and they remain a theoretical possibility with scarce deterrence capacity.
  2. Administrative monetary penalties and corrective measures: Supervisor can apply sanctions to the bank and, when necessary, to management and/or the board or relevant individuals; corrective measures and sanctioning measures can be applied simultaneously, including financial penalties.

*Source: Section 648 BA when there is an imminent threat to safety and soundness had made them*

### 2. Administrative Monetary Penalties (AMPs). A bank or a person that is in

### 2. Administrative Monetary Penalties (AMPs)

### AMPs framework and penalty schedule
- The Schedule of the Administrative Monetary Penalties (OSFI) Regulations contains 72 infractions referred to provisions of the Bank Act divided in categories of seriousness: (i) Very Serious, (ii) Serious or (iii) Minor.
- The Penalty Schedule sets out the percentage ranges of the maximum penalties assessable pursuant to subsection 25(2) of the OSFI Act.
- “Maximum penalties
  (2) The maximum penalty for a violation is
  (a) in the case of a violation that is committed by a natural person, $10,000 for a minor violation, $50,000 for a serious violation and $100,000 for a very serious violation; and
  (b) in the case of a violation that is committed by an entity, $25,000 for a minor violation, $100,000 for a serious violation and $500,000 for a very serious violation.”
- To account for the varying sizes of financial institutions (FIs), a scaling factor is to be applied to the proposed penalty based on the size of the FI.

### Findings on effectiveness and use of AMPs
- The low amounts of monetary penalties that can be imposed do not serve as a deterrent for Canadian banks.
- The infrequent use of the AMPs by OSFI makes them a weak instrument to induce compliance on banks or to punish misconduct or wrongdoing on banks and individuals.
- There are no legal obstacles to imposing corrective action and sanctions simultaneously, although in practice this would be rare given OSFI’s preference for moral suasion.
- OSFI reports that an AMP has never been assessed on an individual.

*EC6 — Ring-fencing and corrective measures*

### Legal and operational approach to ring-fencing
- OSFI does not have a regulatory concept of “ring-fencing.” The concurrent or sequential application of supervisory powers, tools, and measures to address contagion risks from corporate-structure actions is tantamount to a ring-fencing regime.
- In practice, enhanced oversight of the bank is often (but not always) preceded by staging of the bank. OSFI’s use of ring-fencing measures can be intensified as concerns escalate.
- The measures and powers that OSFI typically uses to support ring-fencing may include:
  - Enhancing supervisory reporting requirements;
  - Targeting information requests at parent and/or affiliates and/or more frequent meetings with management of the bank and/or parent;
  - Monitoring of press reports, financial statements and other publicly available information on the parent and affiliates;
  - Monitoring of related party transactions;
  - Monitoring of dividend payments by the bank (if OSFI has not already recommended that they be suspended);
  - Designating a person as a related-party;
  - Increasing capital requirements for the bank and other federally regulated financial institutions in the group and/or securing capital commitments from upstream entities;
  - Theoretically, entering into Prudential Agreements or issuing Directions of Compliance to require the bank to take certain actions to further isolate it from affiliates;
  - Securing an Undertaking from a controlling entity in connection with a bank-related approval or use of an existing Undertaking from a controlling entity as well as moral suasion to compel corrective or preventative action;
  - Subject to a breach of the Bank Act, issuing a Divestment Order; and
  - If a bank’s viability is at risk, taking control of the bank.

### Examples of ring-fencing-equivalent supervisory actions
- OSFI took temporary control of the assets held by a foreign bank branch after an American regulator shut down the parent bank and named an independent American deposit insurer as the receiver; OSFI then took permanent control of the foreign bank branch’s assets and secured a winding-up order under subsection 10.1 of the Winding-up and Restructuring Act to enable an orderly, court-supervised process to restructure the branch.
- After a bank acquired a large Canadian personal lending provider for near-prime borrowers, OSFI:
  - Issued a Supervisory Letter to inform the bank that it was staged;
  - Required the bank to maintain a minimum Consolidated Total Capital Ratio and Consolidated Minimum Leverage Ratio with appropriate management buffers;
  - Restricted the bank from using brokered deposits sourced through the bank to fund the acquisition’s business, engaging in any intercompany lending with the acquisition’s legal entities, and introducing any new products until successful integration;
  - Directed that the bank shall not pay any dividends without OSFI’s prior consent;
  - Required sustainable and effective remediation of outstanding material findings.

*EC7 — Publication and confidentiality of sanctions*

### Legal confidentiality regime and disclosure exceptions
- Section 22 of the Office of the Superintendent of Financial Institutions Act (the OSFI Act) and section 636 of the Bank Act establish that, subject to limited exceptions, information about federally regulated financial institutions obtained by OSFI, and OSFI’s interaction with them, is deemed confidential and may only be used for lawful supervisory purposes.
- Permitted exceptions for sharing confidential information, if the Superintendent is satisfied information will be treated as confidential, include sharing:
  - To other government agencies or bodies that regulate or supervise financial institutions, for purposes related to that regulation or supervision;
  - To the CDIC or any compensation association designated by order of the Minister pursuant to subsections 449(1) or 591(1) of the Insurance Companies Act, for purposes related to its operation; and
  - To the Deputy Minister of Finance or any officer of the DOF authorized in writing by the Deputy Minister of Finance or to the Governor of the BoC or any officer of the BoC authorized in writing by the Governor of the BoC, for purposes of policy analysis related to the regulation of financial institutions.
- Section 637 of the Bank Act permits the Governor in Council to make regulations prohibiting, limiting or restricting the disclosure by banks of prescribed supervisory information (PSI).
- Section 1 of the Supervisory Information (Banks) Regulations provides that PSI includes, among other things:
  - Superintendent orders for a bank to increase its capital or to provide additional liquidity (subsection 485(3) of the Bank Act),
  - Prudential agreements entered into by a bank (subsection 644.1 of the Bank Act), and
  - Directions of Compliance issued by the Superintendent to a bank (section 645 of the Bank Act).
- Pursuant to section 2 of the Supervisory Information (Banks) Regulations, a bank shall not, directly or indirectly, disclose PSI, other than for limited exceptions. A bank may disclose PSI to its affiliates or to its directors, officers, employees, auditors, securities underwriters or legal advisors, or to those of its affiliates, if the bank ensures that the information remains confidential (section 3).
- Section 638 of the Bank Act states that PSI shall not be used as evidence in any civil proceedings and is privileged for that purpose, with very limited exceptions. One exception is that the Minister of Finance, the Superintendent, or the Attorney General of Canada may, in accordance with the regulations, use PSI as evidence in any proceeding (paragraph 638(3)(a) of the Bank Act).
- Under section 38 of the OSFI Act, along with the AMP Regulations, the Superintendent may impose notices of violation and penalties against financial institutions or natural persons in respect of violations set forth in the AMP Regulations. OSFI must keep a notice of violation and penalty confidential, pursuant to section 22 of the OSFI Act and section 636 of the Bank Act. Banks must keep a notice of violation and penalty confidential because it is considered to be PSI.
- Section 985 of the Bank Act provides that a person who is guilty of an offence under any of sections 980 to 984 is liable to a fine or imprisonment or both; punishment under this section would be carried out by the courts and would be publicly available information. In practice, these provisions are generally not used to deal with non-compliance under the Bank Act.
- Given the strict confidentiality regime, there is no policy on the publication of sanctions or enforcement measures, as any disclosure is completely illegal.

*EC8 — Coordination on orderly resolution*

### Domestic and international coordination when resolving problem banks
- In deciding when and how to effect the orderly resolution of a problem bank, OSFI would coordinate and collaborate with relevant domestic and, where applicable, international authorities.
- Domestically, the Financial Institutions Supervisory Committee (FISC) is the federal-level forum legislated to facilitate consultations and the exchange of information among its members on matters relating directly to the supervision of institutions, including discussing confidential prudential concerns with problem institutions and considering when and how to effect the orderly resolution of problem banks.
- OSFI’s Guide to Intervention outlines staging. When a bank reaches Stage 4: Non-viability/Insolvency Imminent, the bank will have experienced severe financial difficulties, and its condition deteriorated to such an extent that:
  - The bank failed to meet regulatory capital requirements in conjunction with an inability to rectify the situation on an immediate basis;
  - The statutory conditions for taking control will have been met; and/or
  - The bank failed to develop and implement an acceptable business plan, resulting in either of the two preceding circumstances becoming inevitable within a short period of time.
- Leading up to Stage 3 (or Stage 4, as appropriate), FISC meetings would increase in frequency and discussions would center on coordinating the implementation of intervention and resolution measures.
- Despite collaboration at FISC, sections 648 to 656 of the Bank Act grant the Superintendent the authority to determine when and how to trigger the orderly resolution of a problem bank. The Bank Act provides that the Superintendent may take control in circumstances including:
  - The bank has failed to pay its liabilities or, in the opinion of the Superintendent, will not be able to pay its liabilities as they become due and payable;
  - The assets of the bank are not, in the opinion of the Superintendent, sufficient to give adequate protection to the bank’s depositors and creditors;
  - Any asset appearing on the books or records of the bank or held under its administration is not, in the opinion of the Superintendent, satisfactorily accounted for;
  - The regulatory capital of the bank has, in the opinion of the Superintendent, reached a level or is eroding in a manner that may detrimentally affect its depositors or creditors;
  - The bank has failed to comply with an order to increase its capital;
  - The bank’s deposit insurance has been terminated by CDIC;
  - In the opinion of the Superintendent, the bank’s depositors and creditors may be detrimentally affected because all of the common shares or membership shares of the bank must be disposed of under a direction made by the Minister or because there is a prohibition under this Act in respect of the exercise of the right to vote attached to all of the common shares or membership shares of the bank;
  - In the opinion of the Superintendent, any or other state of affairs exists in respect of the bank that may be materially prejudicial to the interests of the bank’s depositors or creditors or the owners of any assets under the bank’s administration, including where proceedings under a law relating to bankruptcy or insolvency have been commenced in Canada or elsewhere in respect of the holding body corporate of the bank;
  - In the opinion of the Superintendent, the continued operation of the bank by the directors of the bank or by the officers of the bank responsible for its management would be materially prejudicial to its integrity or security; or
  - In the opinion of the Superintendent, the continued operation of the bank by the directors of the bank or by the officers of the bank responsible for its management would pose a risk to national security.
- When the Superintendent has decided to take control, the Superintendent has the option to:
  - Assume temporary control of the assets of the bank and the assets under its administration;
  - Take control of the bank’s assets, or taking control of the bank; or
  - Take control of the bank’s assets, or taking control of the bank and request that the Attorney General of Canada apply for a Winding-up Order under the Winding-up and Restructuring Act.
- A prudential determination of “non-viability” is the prerequisite trigger for CDIC to either restructure a financial institution, establish a bridge bank or carry out a conversion (“bail-in”) of a SIB to preserve critical bank functions and help maintain financial stability. Upon receipt of a non-viability opinion from the Superintendent, the CDIC Board would make a recommendation to the Minister of Finance on a resolution mechanism.

### International cooperation on resolution
- OSFI has entered into formal information sharing and supervisory cooperation arrangements (MoUs) with more than 30 foreign supervisory authorities and routinely exchanges information with foreign home and host regulators. Where recovery or resolution actions are contemplated in respect of an internationally active bank, OSFI would increase its efforts to coordinate and collaborate with foreign supervisors, as appropriate.

*EC9 — Coordination with related non-bank supervisors*

### Information-sharing and coordination with related non-bank supervisors
- The OSFI Act and the Bank Act grant the Superintendent and OSFI the discretionary authority to inform other domestic and foreign regulators of its actions, and to coordinate its actions with them, if deemed appropriate.

*Source: IMF country report chapter excerpt.*

### Section 22 of the OSFI Act and section 636 of the Bank Act establish rules for OSFI on the

### Section 22 of the OSFI Act and section 636 of the Bank Act establish rules for OSFI on the

### Legal confidentiality and information sharing
- Section 22 of the OSFI Act and section 636 of the Bank Act: information about federally regulated financial institutions obtained by OSFI, and OSFI’s interaction with them, is deemed confidential and may only be used for lawful supervisory purposes, subject to a limited number of exceptions.
- Permitted exception: sharing confidential information with other government agencies or bodies that regulate or supervise financial institutions for purposes related to that regulation or supervision.
- Confidential information can be shared with relevant supervisory authorities, both domestic and foreign, subject to:
  - Meeting OSFI’s confidentiality obligations.
  - Existence of a legitimate interest and valid supervisory purpose.
- International sharing: OSFI shares information with foreign regulators where there is a home-host relationship and an MOU; sharing also occurs through supervisory colleges or crisis management groups.

### Assessment of Principle 11 — Largely Compliant
- OSFI acts timely and at an early stage to correct deficiencies identified in banks through supervisory activities.
- Monitoring of findings is consistent and well-integrated into ongoing supervisory work.
- OSFI typically uses moral suasion (non-binding recommendations in supervisory letters) to induce compliance; statutory powers are rarely used.
- Assessors identify structural shortcomings in the sanctioning regime:
  - Limited scope and deterrence value of administrative monetary penalties.
  - Impracticality of criminal or court-based enforcement.
- Recommendation theme from assessors: strengthen the enforcement and sanctioning framework.

### Early communication of supervisory concerns; timelines and practices
- Main communication channels and timelines:
  - Annual and mid-year meetings with senior management followed by the issuance of an ASL; ASL communicates supervisory ratings, intervention level, key themes, summary of key findings from supervisory reviews, and current plans for upcoming year.
  - Frequent meetings between LS teams / RAH specialists and executives (quarterly for D-SIBs; sometimes weekly with some CROs).
  - ISL must be issued to a bank within 21 calendar days of the completion of supervisory reviews; ISLs are addressed to the CEO and copied to the Chair of the Audit Committee (and Risk Committee, where applicable).
  - Cross-system letters need to be sent within 45 calendar days of the last review in the cross-system; include a general part to all banks reviewed and an individual bank-specific part.
  - Rating change letters may be sent at any time outside ASL/ISL timelines.
- Response and follow-up expectations:
  - Supervisory letter requires a response (including a management action plan) within 30 calendar days of the date of the letter.
  - OSFI responds back to the bank within 30 days as to the appropriateness of proposed actions and timelines.
  - Findings are recorded in the Vu system for follow-up, including date stamps and deadlines.
  - For material and long-term issues, OSFI requires quarterly progress reports.
  - Satisfactory closing of complicated or structural findings often requires an internal check (independent review by internal audit or another control function).
- Performance metric:
  - OSFI’s expected threshold that signals underperformance is 80 percent of recommendations timely implemented and closed.
- Practical notes:
  - Agreed postponement of deadlines is not rare.
  - Follow-up, monitoring and closing of findings and recommendations is rigorous and well-managed, though delays can occur for structural issues.

### Supervisory tools, escalation and cooperation
- Two main approaches to spur compliance:
  1. Moral suasion toolkit:
     - Non-binding recommendations and restrictions (on growth, dividends, certain businesses) communicated in letters are generally respected despite not being legally binding.
     - Non-compliance can lead to downgrades in ORR risk categories (business risk, financial resilience, operational resilience, risk governance) per the supervisory scorecard.
     - “Staging” (change in Intervention Stage from 0 to 1) signals severe attention; associated with increased deposit insurance premiums according to CDIC regulations.
     - OSFI may recommend non-binding restrictions for staged entities (increased capital expectations, dividend restrictions, and more rarely other restrictions).
     - Assessors conclude moral suasion is the preferred and predominant approach; formal statutory powers are considered ultima ratio.
  2. Formal statutory enforcement powers:
     - Catalogue of powers includes the dimensions and tools required in EC4 and may address unsafe and unsound practices and regulatory non-compliance.
     - In almost four decades, use of the most versatile statutory powers (Directions of Compliance and Prudential Agreement) is rare; assessors found no relevant recent examples.
     - If a bank does not comply with a direction of compliance or prudential agreement, OSFI generally must resort to court enforcement to impose compliance.
- Court enforcement:
  - Court enforcement is never used in practice; OSFI views it as impractical, lengthy, and potentially exposing confidential information to public scrutiny.
  - Court enforcement is the only legal avenue to force compliance in a recalcitrant institution, with the exception of the taking of control.

### Taking control, winding-up and non-viability
- Taking Control under section 648:
  - The Superintendent may, pursuant to section 648, take control of the bank, or take control of the assets of the bank for 16 days.
  - To take/continue control of assets for a period exceeding 16 days or to take control of the bank itself requires non-objection of the Minister of Finance, who can terminate the Superintendent’s intervention at any moment.
  - Taking of control is subject to the occurrence of one of the conditions of Subsection 648(1.1) of the Bank Act.
  - Taking of control is normally the culmination of the escalation process and is usually undertaken when there are concerns about the viability of the bank and after discussions with CDIC and other federal public bodies at FISC.
  - Taking of control often results in subsequent activation of resolution or liquidation powers, including:
    - Request a Winding-up Order — pursuant to section 651, after having taken control of the bank, the Superintendent may seek a winding-up order.
    - Declare the Non-Viability of the bank — if the bank reaches the point of non-viability, OSFI will declare it (consulting with FISC); OSFI may have taken temporary control and CDIC may decide on resolution tools applicable based on the resolution plan and the prevalent situation.
- Court enforcement versus taking control: taking control provides immediate enforcement effects and avoids the delay of court enforcement.

### Intervention framework, ratings and flexibility
- ORR and Intervention Stage linkage:
  - The 8 levels of the Supervisory Framework’s ORR correspond with OSFI’s Intervention Stage ratings in the Guide to Intervention for Federally Regulated Financial Institutions.
  - The 5 Intervention Ratings measure and convey views on safety and soundness with respect to depositors and range from 0 to 4.
- Guide to Intervention:
  - Provides a table of expected or likely actions by OSFI and CDIC for each of the five Intervention Stages.
  - Emphasizes flexibility: “the intervention process is not a rigid regime... Circumstances may vary significantly from case to case and the Guide should not be interpreted as limiting the scope of action...”
  - Interventions described at one stage may be used at later or earlier stages depending on circumstances.
  - Because the Guide is a public document, it establishes a presumption that predefined measures would be adopted unless a public interest justification exists to act differently.
- Interagency cooperation:
  - Interagency cooperation at the federal level is well-established and very satisfactory (see CP3, EC8, EC9 references in source).

### Sanctioning regimes and deterrence
- Two regimes in Canadian legislation for sanctioning banks, board members, senior managers and related individuals:
  1. Offences under the Bank Act:
     - Non-compliance with the provisions of the Bank Act is a criminal offence subject to criminal prosecutions before a court.
     - OSFI has never resorted to these legal provisions; criminal standard (“beyond reasonable doubt”) makes them impractical and of scarce deterrence capacity.
  2. (The source text begins to describe a second regime but the provided content ends at the description of Offences; no further details on the second regime are supplied in the excerpt.)

*https://www.imf.org/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf*

### 2. Administrative Monetary Penalties (AMPs). A bank or a person that is in

### 2. Administrative Monetary Penalties (AMPs)

### Framework and current practice
- The Schedule of the Administrative Monetary Penalties (OSFI) Regulations contains 72 infractions referred to provisions of the Bank Act divided in categories of seriousness: (i) Very Serious (for example, carrying out banking activities without license, failure to take precautions to protect records), (ii) Serious or (iii) Minor.
- The maximum penalties according to Subsection 25(2) OSFI Act is CAD 500,000 for a very serious violation committed by an entity, CAD 100,000 for a very serious violation committed by an individual.
- OSFI reports that an AMP has never been assessed on an individual.
- The low amounts of monetary penalties that can be imposed, which do not serve as a deterrent for Canadian banks and the infrequent use of the AMPs by OSFI makes them a weak instrument to induce compliance on banks or to punish misconduct or wrongdoing on banks and individuals.
- OSFI must keep a notice of violation and penalty confidential, pursuant to section 22 of the OSFI Act and section 636 of the Bank Act.
- Banks must keep a notice of violation and penalty confidential because it is considered to be Prescribed Supervisory Information.
- Given this strict confidentiality regime, there is no policy on the publication of sanctions or enforcement measures, as any disclosure is completely illegal.

### Findings and supervisory implications
- AMPs are underused and limited in deterrence value due to:
  - A closed list of infractions that may omit delays, non-compliance with recommendations or requirements, misconduct and wrongdoing that OSFI may deem reasonable to sanction.
  - Statutory maximums (CAD 500,000 for entities; CAD 100,000 for individuals) that are low relative to bank profitability and not calibrated to ensure effective deterrence.
  - Strict confidentiality under section 22 (OSFI Act) and section 636 (Bank Act) which prevents reputational consequences from amplifying deterrence.
- The absence of published sanctions means reputational impact cannot serve as an additional incentive for compliance.
- Most formal statutory powers are not used in practice and risk becoming theoretical; credibility of enforcement is weakened unless powers are exercised with some frequency.
- AMPs may be imposed if the formally issued instructions are not timely complied with.

### Recommendations
- Reform the regime of AMPs to make it a useful supervisory tool, including:
  - Create a new list of infractions comprising all the cases of delays, non-compliance with recommendations or requirements, misconduct and wrongdoing that OSFI considers reasonable (emphasis may be put on fraud and manifest lack of controls or policies). This would make the catalogue of infractions a useful tool to induce compliance, signal unacceptable behavior and punish misconduct or recklessness.
  - Re-calibrate penalty amounts so that they are an effective deterrent for banks (reference to profitability of each bank may be useful, the scale of the bank should not be an obstacle to effective deterrence).
  - Provide a clause to allow the Superintendent to surpass the legislated quantitative limit in cases where the benefits of the infraction or the harm caused may be higher than the fines to be imposed.
  - Amend internal policies on AMPs to:
    - Allow for an increased use of the instrument in cases of infractions and long-standing and marked deviations from supervisory expectations, repeated findings that contradict regulations or guidance and other similar cases in which OSFI may reinforce its supervisory stance towards the system by making a statement.
    - Explicitly foresee the cases where individuals may be fined and the internal procedure to do so (including providing for the denunciation by the ongoing monitoring teams of the infractions by individuals that they may determine). In order to improve deterrence, it should be credible that individuals, Board members and managers may be fined.
- OSFI should consider issuing a policy on the publication of sanctions (reforms on the confidentiality regime of the concept of PSI should be made to allow this), so that the reputational impact on banks serves as an additional element of deterrence and incentivizes the banks to put the supervisory concern underpinning the sanction at the forefront of its priorities.
- To preserve the credibility of OSFI’s moral suasion and statutory powers:
  - Establish an internal policy for the use of the statutory powers that makes it credible that they may be used (or used not so infrequently).
  - Reinforce recommendations with the formal use of the statutory powers in cases that are not the business-as-usual relationship with banks (i.e., outside of Stage 0).
  - Consider using formal statutory powers where a bank is viable but does not comply with supervisory expectations or has repeated findings or long-standing unresolved problems (noting that forceful taking of control is used by OSFI for failing banks).

*Source: IMF assessment text from “2. Administrative Monetary Penalties (AMPs).”*

### conclusions of international assessments (for example, FSAPs) assist OSFI in determining the

### 1canea2025007-source-pdf - conclusions of international assessments (for example, FSAPs) assist OSFI in determining the

### EC4 — Home supervisor visits and cross-border on-site examinations
- Home supervisor visits foreign offices periodically; location and frequency determined by risk profile and systemic importance.
- Supervisor meets host supervisors during visits.
- Supervisor has a policy for assessing need for on-site examinations of foreign operations or requiring additional reporting, and has power and resources to act as appropriate.
- Description and findings:
  - OSFI’s cross-border supervisory reviews are part of the general annual supervisory strategy and plan (treated as ordinary reviews; do not require a dedicated internal policy).
  - Frequency and scope of on-site inspections at foreign locations are risk-based (factors: risk environment, materiality of the unit, risk profile, assessment and findings of host regulators).
  - OSFI conducts an annual visit to foreign supervisors and local management of material subsidiaries of D-SIBs, irrespective of whether cross-border inspections are planned.
  - Regular interaction with host regulators including: Australian Prudential Regulation Authority (APRA), Federal Reserve, Bank of England—Prudential Regulation Authority (PRA), Office of the Comptroller of the Currency.
  - On-site reviews of material foreign operations take place periodically; OSFI normally meets the host country supervisor during these reviews.
  - Examples of inspected scopes: material subsidiaries’ risk governance, credit cards portfolio, internal audit, compliance function, commercial real estate operations, leveraged lending or funding (in countries such as the US or Mexico).
  - Budgetary restrictions in recent years (see CP2) led OSFI to prioritize virtual reviews over fully on-site inspections due to travel budget cost-cutting.

### EC5 — Supervision of parent companies and affiliates
- EC5 requirement: supervisor reviews main activities of parent companies and affiliates that materially impact safety and soundness and takes appropriate supervisory action.
- Description and findings:
  - Widely-held banks: no major shareholder, no parent company, no affiliates of parent company; consolidated banking group perimeter coincides with wider group perimeter.
  - SMSBs can have major shareholders, parent companies and affiliates (including family-owned banks and banks owned by non-financial groups).
  - Domestic Banking division within the Risk Assessment and Intervention Hub supervises SMSBs.
  - LS teams supervising SMSBs do not regularly review the wider group’s activities; review is reactive when supervisory concern arises or approvals are triggered (licensing, significant interest acquisition, substantial investments — see CP5, CP6 and CP7).
  - Occasional information requests on parents/affiliates or use of open sources when parent is listed, but not regular or part of ongoing monitoring.
  - Information on shareholders and wider group structure of SMSBs is not regularly updated; capacity of parent to support regulated entity considered at licensing and not generally updated or overseen.
  - OSFI lacks power to review parent and affiliate activities on an ongoing basis except circumstances related to section 635 of the Bank Act; undertakings may be obtained at licensing but are not part of internal procedure or policy.

### EC6 — Powers to limit group activities and locations
- EC6 conditions for limiting activities or locations: (a) safety and soundness compromised; (b) inadequate supervision by other domestic authorities; (c) hindered effective consolidated supervision.
- Description and findings:
  - Bank Act provides Superintendent remedial powers (authorized foreign banks: sections 614.1 to 627; domestic and subsidiary banks: sections 644.1 to 656).
  - Main enforcement powers: Direction of Compliance, divestment order, restrict bank’s activities; these powers can target foreign operations including closing foreign offices (rarely used — see CP11).
  - Assessors reviewed a case where ring-fencing measures were adopted for a problem branch of a foreign bank; branch was liquidated and creditors did not suffer losses. Apart from this case, powers have not been required.

### EC7 — Solo supervision in addition to consolidated supervision
- EC7 requirement: responsible supervisor supervises individual banks on a solo basis and understands relationships within the group.
- Description and findings:
  - OSFI approach is eminently consolidated; prudential requirements are required on a consolidated basis (see Section 1.1. Scope of Application of the Capital Adequacy Requirements Guideline).
  - All banks must comply with prudential requirements on a consolidated basis; OSFI receives regulatory returns from both parent and subsidiary entities.
  - Non-compliance with a small subsidiary’s capital ratios would trigger supervisory action, but there is no general legal requirement for a legal-entity solo capital ratio for parent banks.
  - LS teams monitor regulatory compliance of subsidiary banks within the group.
  - OSFI assesses adequate capital distribution in the banking group; imbalances attract supervisory attention (see CP16, AC2).

### Additional Criterion AC1 — Fit and proper standards for senior management of parent companies
- Canada allows corporate ownership of banks. Part XV of the Bank Act regulates bank holding companies approved by the Minister of Finance (Section 922 BA: “Main business 922 (1) Subject to this Part, a bank holding company shall not engage in or carry on any business other than (a) acquiring, holding and administering investments that are permitted by this Part [chiefly, holding shares in banks and other permitted financial entities under Section 925 BA]; (b) providing management, advisory, financing, accounting, information processing and other prescribed services to entities in which it has a substantial investment; and (c) any other prescribed business.”).
- Bank holding companies are considered FRFIs and subject to equivalent prudential requirements (including capital and liquidity).
- Same fit and proper standards applicable to banks apply to bank holding companies (e.g., Corporate Governance Guideline — see CP14) and same rules on significant shareholders in the Bank Act and related regulations (see CP6).

### Assessment of Principle 12 — Consolidated supervision
- Assessment: Compliant.
- Comments / findings:
  - Consolidated supervision well-established in Canada.
  - OSFI’s legislation and guidance impose prudential standards and collect/analyze information on a consolidated basis (legal powers detailed in CP1, EC5 and EC7).
  - LS teams in charge of large banks reference the whole banking group, including foreign operations and domestic subsidiaries.
  - Ongoing monitoring reports routinely refer to the consolidated group; specialists and LSs understand foreign and domestic activities and regularly monitor them.
  - Off-site surveillance reviews group management reporting and standalone local reporting (credit portfolios/exposures, structural risks, other risks).
  - Supervisory Framework aspects (Business Risk, Financial Resilience, Operational Resilience and Risk Governance) are assessed group-wide with assistance from specialized supervisors (credit, capital, market, liquidity, operational, cyber...) of the RAH and the Emerging Risks Operations Directorate.
  - Cross-border inspections are part of ordinary supervisory planning; on-site reviews of material foreign operations occur periodically.
  - Budgetary restrictions (see CP2) caused prioritization of virtual reviews over fully on-site inspections.
  - Wider group perimeter relevance mainly for SMSBs. Section 374 of the Bank Act requires Canadian banks with equity greater than $12 billion (which includes the 6 D-SIBs that account for 97% of the banking sector’s assets) to be “widely-held,” with no person being a major shareholder (more than 20 percent of any class of voting shares).
  - LSs of SMSBs do not regularly review wider group activities; information on shareholders and wider group structure not regularly updated; parent capacity assessed at licensing only.
  - OSFI does not have power to review parent/company affiliates on an ongoing basis except under section 635 of the Bank Act; undertakings at licensing are not consistently obtained or internalized as procedure.

### Recommendations (from Principle 12 section)
- Improve supervision of the wider group of small and medium-sized banks that are not widely held and have major shareholders, parent companies and affiliates. Areas to keep regularly up to date:
  - Group structure (legal and operational, including intragroup relationships such as contracts, services, loans and other exposures).
  - List of significant shareholders.
  - Risk of excessive leverage (for example, through hidden liabilities above the parent level).
  - Capacity of the parent to provide solvency and liquidity support.
  - Reputation and contagion risks.
  - Relationship with the parent company (including quality of governance and influence on the subsidiary), its affiliates and related parties.
- Require undertakings (for access to information) to the parent companies of all banks that are not widely held as a matter of internal procedure.

---

### Principle 13 — Home-host relationships (overview and assessments)
- Principle 13: Home and host supervisors share information and cooperate for effective supervision and crisis handling; local operations of foreign banks required to meet same standards as domestic banks.
- Assessment: Compliant.

### EC1 — Supervisory colleges, CMGs, Outreach Panels
- Canada hosts forums to support interaction, cooperation and information-sharing for G-SIBs and all D-SIBs, structured to reflect banking group nature and supervisory needs:
  - Supervisory Colleges (hosted by OSFI).
  - CMGs for core host regulators and FISC partners (co-hosted by OSFI and CDIC).
  - Outreach Panel meetings for non-core host regulators (hosted by OSFI; CDIC active participant).
- Purpose of OSFI Supervisory Colleges: share information on top concerns, emerging risks, supervisory work results and plans, views on bank risk management and controls; discuss home-host collaboration opportunities.
- Typical participants: Office of the Comptroller of Currency, Federal Reserve, Bank of England’s PRA, Federal Deposit Insurance Corporation (FDIC), Central Bank of Trinidad & Tobago (CBTT), Eastern Caribbean Central Bank (ECCB), among others.
- 2024 Colleges theme: operational resilience with a focus on cyber; host supervisors asked to discuss top risks, operational and cyber resilience observations, recent/upcoming supervisory work.
- Host supervisors prepare and submit a completed presentation deck in advance.
- OSFI hosted June 2024 Supervisory College meetings and the 2024 Outreach Panel; Outreach Panels held once every two years and include updates on D-SIB designation and crisis management/intervention frameworks.
- Upcoming events noted in source:
  - Annual supervisory colleges for G-SIBs in Fall 2024.
  - Crisis Management Group meetings (recovery and resolution focus) from October 7 to 18 2024.
- Assessors had access to agendas and packages of recent colleges, CMGs and outreach panels and were satisfied with effectiveness.

### EC2 — Timely information sharing and MoUs
- OSFI has more than 30 information sharing and cooperation arrangements (MoUs) with foreign regulators; MoUs cover material risks, risk management practices, and supervisors’ assessments of safety and soundness.
- OSFI exchanges information routinely with key foreign home and host regulators; conducts regular (usually quarterly) meetings depending on the institution assessed.
- Between formal meetings, LS staff have ad hoc discussions for time-sensitive issues.
- Example: In 2023, a G-SIB complied with a host supervisor’s request (Jurisdiction of Bahamas) to share information on consolidated supervision of home Group’s financial condition; OSFI confirmed compliance and its assessment of the parent company.

### EC3 — Coordination and collaborative supervisory work
- OSFI has extensive collaborative relationships with key host authorities; home and host jurisdictions share supervisory concerns and work plans and coordinate supervision of cross-border banking groups.
- OSFI coordinates supervisory activities and consults host regulators when planning on-site reviews; offers host regulator participation and holds post-review meetings.
- Collaborative on-site reviews performed in multiple cases (example: January 2019 joint review with National Banking and Securities Commission of Mexico; OSFI led review of D-SIB local operations in Mexico).

### EC4 — Agreed communication strategy with host supervisors
- OSFI develops tailored communication strategies with relevant host supervisors prior to and after reviews, reflecting risk profile and cross-border operations.
- Following joint reviews, OSFI works with host supervisors to establish common views/messages to communicate to the bank and agree supervisory activities.

### EC5 — Cross-border crisis cooperation and coordination framework
- Domestic arrangements:
  - Financial Institutions Supervisory Committee (FISC) chaired by Superintendent; membership includes CEO of CDIC, Deputy Minister of Finance, Governor of the BoC, Commissioner of the FCAC; statutory body under section 18 of the OSFI Act; facilitates consultations and exchange of information on supervision and resolution; “every member of the committee is entitled to any information on matters relating directly to the supervision of [banks] that is in the possession or under the control of any other member.”
  - OSFI/CDIC Strategic Alliance Agreement and Guide to Intervention for Federally Regulated Deposit-Taking Institutions address crisis management communication and coordination.
- International arrangements:
  - OSFI has extensive information-sharing MoUs and collaborative relationships with foreign supervisory authorities.
  - In 2021 and 2023, OSFI and CDIC finalized cooperation agreements for Canada’s two G-SIBs; executed by Canadian, US, UK, ECB and SRB and signed in early 2023. Agreements establish framework for cooperation in event of G-SIB resolution where Parties have prudential, crisis management, recovery or resolution responsibilities.
  - OSFI and CDIC host annual bank-specific CMGs for G-SIBs and bi-annual CMGs for D-SIBs; CMGs facilitate information sharing relevant to recovery and resolution planning.
  - 2024 CMG scheduled for two weeks in October 2024; themes: lessons learned from the 2023 US/European banking crisis and impact of non-financial risk (focus on cyber, technology and third-party risk) on recovery triggers and actions.
  - OSFI participated in State Street’s May 2024 Crisis Management Group meeting hosted by the Federal Reserve Bank, Boston.

### EC6 — Group resolution planning and information sharing for resolvability
- Domestic collaboration between OSFI and CDIC via FISC and OSFI-CDIC Strategic Alliance Agreement supports recovery and resolution planning and anticipated actions.
- CDIC developed first-generation resolution plans for D-SIBs and G-SIBs in December 2012.
- CDIC received recent submissions of resolution plans from D-SIBs and G-SIBs in 2023 and performed resolvability assessments.
- Recovery plans:
  - First iteration submitted in 2011 (prepared per OSFI guidance).
  - Most recent recovery plans from D-SIBs and G-SIBs received by OSFI in June 2024 and shared with FISC partners (CDIC, Finance, BoC).
  - OSFI to perform assessment of credibility of recovery plans in time to share key takeaways with CMG authorities at October 2024 CMG meetings.
- International: OSFI liaises and shares recovery-action information with foreign supervisors under MoUs.
- Under section 45.2(2) of the CDIC Act, CDIC may disclose institution-specific information obtained from the Superintendent to relevant foreign authorities, in consultation with the Superintendent, if CDIC is satisfied recipient will treat information as confidential.

### EC7 — Prudential requirements for cross-border operations
- Bank Act covers both domestic and foreign banks in Canada; foreign bank subsidiaries and branches are subject to laws and regulations that, with few exceptions, are identical to domestic banks.
- All foreign bank operations subject to oversight, regular on-site inspections and regulatory reporting requirements.
- OSFI guidance does not distinguish between local and foreign bank branches.
- Specific references: subsection 619(2), subsection 648(1.1), sections 409 and 538.

### EC8 — Home supervisor on-site access to local offices and subsidiaries
- Under section 643 of the Bank Act, OSFI has authority to examine banks on-site (offices and subsidiaries) and access records to assess safety, soundness and due diligence compliance.
- OSFI notifies foreign host regulator when intending on-site examination per MoUs.

### EC9 — Booking offices and shell banks
- No booking offices operate in Canada.
- OSFI does not permit shell banks in Canada.
- There are 16 “representative offices” in Canada; representative offices may only promote services and act as liaison — not permitted to carry on any activity in Canada other than promoting services and acting as liaison.

### EC10 — Consultation before action based on another supervisor’s information
- As practice, OSFI will not act on information received from another supervisor unless it consults with that supervisor.
- Example (2023 OCC case):
  - OCC advised OSFI that a Canadian subsidiary was under scrutiny for excessive growth during the pandemic.
  - OSFI actions:
    - Participated in monthly meetings (and as needed) with the OCC and FRB to determine progress with remedial activities.
    - Included issues management as a standing agenda item for the subsidiary with the Group’s CRO at its weekly meetings.
    - Actively followed up on compliance function recommendations made in 2023.
    - Planned a 2024 review to include subsidiary governance focus.
    - Conducted on-site meetings at the US subsidiary office in June 2024.

### Summary comments on home-host relationship management
- OSFI’s home-host relationship management is adequate.
- Canada is mainly a home jurisdiction for internationally active banks; six largest banks are internationally active with material subsidiaries in the US, UK, Latin America and Asia.
- Forums and mechanisms (Supervisory Colleges, CMGs, Outreach Panels, FISC, OSFI-CDIC agreements) facilitate interaction, cooperation and exchange of information with foreign regulators on supervision, recovery and resolution.

*Source: 1canea2025007-source-pdf - conclusions of international assessments (for example, FSAPs) assist OSFI in determining the*

### 2023. These agreements establish a framework for effective cooperation in the event of a G-

### Prudential Regulations and Requirements — Principle 14 Corporate Governance

### Crisis Management Cooperation and Information Sharing
- Agreements establish a framework for effective cooperation in the event of a G-SIB resolution insofar as the Parties are responsible for prudential supervision, crisis management, recovery or resolution under their respective laws.
- OSFI, in collaboration with CDIC, hosts annual bank-specific CMGs with relevant domestic and key host and foreign regulators for its global systemically important banks and on a bi-annual basis for its domestic systemically important banks.
- The CMGs facilitate the sharing of information relevant to recovery and resolution planning efforts.
- There are foreign G-SIBs with operations in Canada; none of these businesses are considered systemically important domestically.
- OSFI engages in Crisis Management Group discussions depending on the materiality of G-SIB operations in Canada; example provided:
  - OSFI participated in State Street’s May 2024 Crisis Management Group meeting hosted by the Federal Reserve Bank, Boston.
- Outreach Panels:
  - Designed to engage with host jurisdictions not members of formal Crisis Management Groups where a Canadian D-SIB has operations potentially systemic to that host jurisdiction.
  - Hosted once every two years and provides opportunity to discuss crisis management related topics of relevance or interest.
- OSFI has more than 30 information sharing and cooperation arrangements MoUs in place with foreign regulators. These MoUs cover a wide range of information, including material risks and risk management practices of the bank, as well as supervisors’ assessment of the safety and soundness of the bank.
- OSFI routinely exchanges information with key foreign home and host regulators:
  - Conducts regular (usually quarterly) meetings with regulators of key jurisdictions, depending on the institution being assessed.
  - During bi-lateral meetings, OSFI provides updates on supervisory methodology, new regulatory guidelines, capital expectations, outcomes of supervisory reviews and recommendations, and upcoming planned supervisory activities.
  - Host supervisors provide updates on key risks and supervisory activities.
- LSs (the OSFI employees primarily responsible for the bank) have ad hoc discussions with key host regulators between formal meetings to address time-sensitive issues.

### EC1 — Legal and Guideline Framework for Board and Senior Management Responsibilities
- Legislative requirements:
  - Part VI – Corporate Governance of the Bank Act outlines duties.
  - Section 157 (“Directors and Officers–Duties”)—Duty to Manage:
    - (1) “Subject to this Act, the directors of a bank shall manage or supervise the management of the business and affairs of the bank.”
    - (2) Without limiting subsection (1), the directors shall:
      a) establish an audit committee to perform duties in subsections 194(3) and (4);
      b) establish a Conduct Review Committee to perform duties in subsection 195(3);
      c) establish procedures to resolve conflicts of interest, including techniques for identification of potential conflict situations and for restricting use of confidential information;
      d) designate a committee of the board to monitor the procedures in paragraph (c);
      e) establish investment and lending policies, standards and procedures in accordance with section 465.
  - Subsection 194(3) outlines duties of the Audit Committee.
  - Subsection 195(3) outlines duties of the Conduct Review Committee (CRC).
- OSFI’s Corporate Governance Guideline (2018) regulatory expectations:
  - “Corporate governance is a set of relationships between a company's management, its Board of Directors (Board), its shareholders, and other stakeholders. It also provides the structure through which the objectives of the company are set, and through which the means of attaining those objectives and monitoring performance are determined. The quality of FRFI corporate governance practices is an important factor in maintaining the confidence of depositors and policyholders, as well as overall market confidence. (...)”
  - Section II of the Guideline — Board duties (minimum essential duties):
    - (1) Approve and oversee:
      - Strategy:
        - Short-term and long-term business plan and strategy;
        - Significant strategic initiatives ( for example, mergers and acquisitions);
      - Risk management oversight:
        - RAF
        - Internal control framework;
        - Significant policies, plans and strategic initiatives related to management of, or that materially impact, capital and liquidity (for example, internal capital targets, share issuance);
        - Codes of ethics and conduct;
      - Board, senior management and oversight functions:
        - Appointment, performance review, and compensation of the CEO and other key members of senior management, including the heads of the oversight functions;
        - Succession plans with respect to the Board, CEO and other key members of senior management, including the heads of the oversight functions;
        - Mandate, resources and budgets for the oversight functions;
      - Audit plans:
        - External audit plan, including audit fees and the scope of the audit engagement; and
        - Internal audit plan.
    - (2) Provide challenge, advice and guidance to senior management on:
      - Operational and business policies: significant operational, business, risk and crisis management policies of the bank, including credit, market, operational, insurance, regulatory compliance and strategic risks; compensation policy consistent with FSB Principles for Sound Compensation;
      - Business performance and effectiveness of risk management: performance relative to Board-approved plan and strategy; effectiveness of the RAF; effectiveness of the internal control framework; effectiveness of oversight functions; effectiveness of significant policies and plans related to management of capital and liquidity (for example, stress testing, ICAAP report).
  - The Guideline: “The Board is not responsible for the ongoing and detailed operationalization of its decisions; this is the responsibility of Senior Management.”
- OSFI’s Supervisory Framework:
  - Incorporates a risk assessment category of “Risk governance” at banks.
  - Assessment of risk governance includes subcategories: “Governance,” “Business and central functions,” “Risk and compliance oversight” and “Internal audit.”

### EC2 — Supervisory Evaluation and Enforcement of Corporate Governance
- OSFI supervisors assess corporate governance policies and practices as part of ongoing supervisory work under Superintendent’s powers in sections 643 to 645 of the Bank Act.
- OSFI’s supervisory process and tiering:
  - Tiering approach from a 1 to 5 scale to each bank based on size and complexity and view of impact of its failure.
  - Rating system implemented from April 2024–ORR, structured according to four broad categories: “Business Risk,” “Financial Resilience,” “Operational Resilience,” and “Risk Governance.”
- Supervisory Framework guidance for assessing “Risk Governance”:
  - Considers culture, accountability structures, and extent to which oversight functions provide independent and objective challenges.
- Assessment mechanisms:
  - Quarterly monitoring and reviews, including cross-system reviews covering multiple banks.
  - For large banks, quarterly monitoring includes review of material approved by Board or committees: copies of corporate policies, strategy and risk appetite.
  - Specific reviews or rating reviews produce findings and recommendations; OSFI requires banks to correct deficiencies in a timely manner.
- ORR rating practice:
  - In assessing risks, OSFI considers level of risk to bank viability.
  - Banks in Tiers 1 to 4 are rated for “Risk Governance” on a scale of 1 (minimal risk) to 8 (non-viability imminent).
  - If a finding leads to a rating downgrade, OSFI updates rating assessments when supervisory concerns are appropriately addressed.
- Review evidence and interactions:
  - Reviews use pre-examination information including policies, board presentations and reports.
  - Meetings with key Board and Senior Management members are included.
- Cross-sector and corporate governance reviews:
  - 2023–24 Corporate Governance cross-system review: five of the six D-SIBs, five medium sized-banks, two small banks and two of the largest mortgage insurers.
  - Separate corporate governance reviews of the six D-SIBs were completed in 2022–23.
  - For large banks (Tiers 1 and 2), OSFI:
    - Reviews board/committee packages, including minutes and presentations from CRO, CFO, Chief Audit Executive, and other senior management;
    - Reviews quarterly and annual public information.
    - Meets annually with the full board to present the ORR and discuss findings made during the supervisory year;
    - Meets semi-annually with the Committee Chairs.
  - The assessors concluded the 2023-24 cross-system review was an off-site review based on banks’ questionnaire answers and corporate governance documents; online discussions were held with Chairmen and Risk Committee chairs. The review resulted in meaningful findings communicated via supervisory letters and followed-up for remedial actions.

### EC3 — Board Composition, Qualifications, and Independence
- Legislative requirements:
  - Bank Act section 159 (Qualification and Number–Directors):
    - (1) “a bank shall have at least seven directors,” and
    - (2) “at least half of the directors of a subsidiary of a foreign bank and a majority of the directors of any other bank must be resident Canadians.”
  - Subsection 163 (1) and (2): no more than two thirds of directors may be persons affiliated with the bank (not applicable if the bank is owned by another bank).
  - Section 164: “no more than 15 per cent of the directors of a bank may, at each director’s election or appointment, be employees of the bank or a subsidiary of the bank, except that up to four persons who are employees of the bank or a subsidiary of the bank may be directors of the bank if those directors constitute not more than one half of the directors of the bank.”
    - Interpretation: if four directors are employees, the minimum number of directors is eight.
- Affiliated Persons (Banks) Regulations (SOR-92-325) definitions for affiliation of a natural person with a bank include:
  a) officer or employee of the bank or an affiliate;
  b) significant interest in a class of shares or membership shares of the bank;
  c) substantial investment in an affiliate of the bank;
  d) significant borrower or related employee or controller of such an entity;
  e) provider of goods or services where more than 10 percent of annual billings comes from providing goods and services to the bank;
  f) has a loan not in good standing from the bank or affiliate, or is director/officer/employee of an entity with such a loan;
  g) spouse or common-law partner of a person described in (a) to (f).
- Practical findings:
  - For D-SIBs, Boards are comprised of independent directors, except for the President and CEO.
- EC3 expectations:
  - Board membership should comprise individuals with a balance of skills, diversity and expertise commensurate with the size, complexity and risk profile of the bank.
  - Board membership includes a sufficient number of experienced independent directors.
  - Board members are qualified individually and collectively, and effectively exercise “duty of care” and “duty of loyalty.”

*Source: 1canea2025007-source-pdf (2023) — excerpt on Crisis Management, OSFI supervisory practices, and Principle 14 Corporate Governance.*

### Section 160 of the Bank Act lists the disqualifications that prevents a person from being

### 1canea2025007-source-pdf - Section 160 of the Bank Act lists the disqualifications that prevents a person from being

### Legal disqualifications, statutory duties and legislative powers
- Section 160 of the Bank Act lists disqualifications that prevent a person from being a director of a bank, including:
  - a person who is less than eighteen years of age;
  - a person who is of unsound mind as found by a court in Canada or elsewhere;
  - a person who has the status of a bankrupt;
  - a person who is an agent or employee of the government of a foreign country or any political subdivision thereof.
- Subsection 158 (1) of the Bank Act establishes the “duty of care” and encompasses the “duty of loyalty,” requiring directors to:
  - (a) act honestly and in good faith with a view to the best interests of the bank; and
  - (b) exercise the care, diligence and skill that a reasonably prudent person would exercise in comparable circumstances.
- Removal powers under the Bank Act:
  - 647.1 (1) The Superintendent may, by order, remove a person from office as a director or senior officer of a bank if the Superintendent is of the opinion that the person is not suitable to hold that office on the basis of competence, business record, experience, conduct or character, or because the person has contravened or contributed to contravention of specified statutory provisions, directions, orders, conditions or prudential agreements.
  - 647.1 (2) In forming an opinion under subsection (1), the Superintendent must consider whether the interests of the depositors and creditors of the bank have been or are likely to be prejudiced by the person’s holding office as a director or senior officer.
  - No incidents have yet resulted in the Superintendent exercising these powers (as of the material provided).

### OSFI guidance on character, integrity and board suitability
- Guideline E-17 Background Checks on Directors and Senior Management (February 2008) sets expectations for banks to have internal processes assessing ongoing suitability and integrity of directors.
- The Integrity and Security Guideline (January 2024) establishes expectations that:
  - “responsible persons and leaders are of good character and demonstrate integrity through their actions, behaviors, and decisions.”
  - “the more senior someone is in an organization, the more power and influence they typically wield. It is, therefore, particularly important that responsible persons demonstrate integrity through their actions, behaviors, and decisions.”
- Guideline E-17 requires banks to have a written Assessment Policy for Responsible Persons that:
  - requires pre-appointment assessments except in imprudent-to-delay cases (then within a number of days specified in the Assessment Policy);
  - expects sufficient information on appointment such as criminal records, records of securities-related sanctions or disciplinary actions, evidence of education/skills/professional qualifications/experience, attestation on civil liability related to misconduct/fraud/mismanagement, and attestation on conflicts of interest;
  - expects senior management to determine suitability, take mitigating actions if necessary, and elevate concerns to the board.

### Corporate Governance Guideline: board composition, independence and skills
- Board composition and skills expectations:
  - Board should be diverse and collectively bring a balance of expertise, skills, experience, competencies and perspectives, considering strategy, risk profile, culture and operations.
  - Board should have a skills and competency evaluation process integrated with Board succession/renewal plans and pay particular attention to Chair of the Board and Chairs of Board Committees.
  - “Relevant financial industry and risk management expertise are key competencies for the Board. There should be a reasonable representation of these skills at the Board and Board Committee levels.”
- Board independence and structure:
  - “The Board collectively should be independent from Senior Management and the operations of the” bank.
  - OSFI expects the Board’s behavior and decision-making processes to be independent, objective and effective.
  - Specific expectations:
    - “Board and Board committee chairs should be independent, non-executive directors.”
    - “The role of the Board Chair should be separate from the CEO.”
    - Boards should have a director independence policy considering shareholder/ownership structure and director tenure.
    - Recruitment and director profile development should emphasize independence from Senior Management.
- Committee-specific requirements:
  - Audit Committee: federal legislation requires an Audit Committee comprised of non-employee directors, a majority of whom are not “affiliated” with the institution; OSFI has discretion to determine affiliation; limitation does not apply where the bank is owned by another federally regulated financial institution (Affiliated Persons Regulations).
  - Board-level Risk Committee: members should be non-executives with understanding of risks, and techniques/systems to identify, measure, monitor, report on and mitigate risks; for SMSBs, the Board may rely on collective skills instead of a separate Risk Committee.
- No formal expectation for a Board Compensation Committee, though most supervised banks are in compliance with the 2009 FSB Principles for Sound Compensation Practices.

### Board oversight responsibilities, reporting and supervisory interaction
- Board responsibilities include approving and overseeing:
  - the bank’s strategy (including business plan);
  - the bank’s RAF (risk appetite framework) and significant policies related to capital and liquidity management;
  - corporate culture, codes of conduct, and conflict of interest policies;
  - Board, Senior Management and oversight functions, and Audit Plans.
- OSFI receives Board-approved strategy, RAF, Board-approved policies and similar documents via regular submission to LS teams.
- OSFI’s Integrity and Security Guideline (January 2024) expectations for governance and culture:
  - important decisions around business plans, strategies, risk appetite, culture, internal controls, and oversight of senior management should be subject to effective governance;
  - behavioral expectations should be codified in documents such as codes of conduct and conflict of interest policies and procedures, with clear communication on non-compliance resolution and disclosure;
  - codes of conduct should highlight avoiding conflicts of interest, bribery and other unacceptable influences;
  - “Culture should be deliberately shaped, evaluated, and maintained.”
- OSFI supervisory practices include:
  - quarterly monitoring process with submissions and touchpoints with senior management and the board;
  - on-site interviews of board members as part of cross-sector reviews (example: 2022–23 D-SIBs cross-sector review);
  - cross-system reviews and thematic examinations (examples: 2023–24 Corporate Governance cross-system review; data governance and management reviews).

### Governance assessments (EC4–EC10) — supervisory findings and expectations
- EC4 (nomination/appointment, performance assessment, renewal):
  - OSFI’s Corporate Governance Guideline requires transparency of selection process and submission of candidates’ qualifications to OSFI.
  - Board should “regularly assess its practices and those of the Board committees” and have a skills/competency evaluation integrated with succession/renewal plans.
  - Guideline E-17 reinforces ongoing suitability assessments.
- EC5 (board approves and oversees strategy, RAF, culture, conflicts and controls):
  - Board responsible for business plan, strategy, RAF, culture; OSFI receives Board-approved artifacts as part of ongoing supervision.
  - Integrity and Security Guideline requires governance over business plans, strategies, risk appetite, culture, internal controls, codes of conduct and conflict procedures.
- EC6 (fit and proper standards, allocation of authority, succession, oversight of senior management):
  - Corporate Governance Guideline prescribes Board roles and Senior Management responsibilities (CEO and direct reports including CFO, CRO, Chief Compliance Officer, Chief Internal Auditor, Chief Actuary).
  - Board responsible for approving/overseeing succession plans for Board, CEO and key Senior Management, with attention to diversity.
  - Guideline E-17 specifies assessment policy details for Responsible Persons, required evidence types and escalation to boards.
- EC7 (compensation oversight and alignment with prudent risk-taking):
  - Board to provide challenge, advice and guidance on compensation consistent with FSB Principles for Sound Compensation Practices and related Implementation Standards.
  - CRO compensation should not be linked to performance of specific business lines.
  - April 2009 Assistant Superintendent letter required compliance with FSB Principles; larger institutions also to comply with Implementation Standards.
  - OSFI conducted a 2015 cross-system review of compensation among D-SIBs and issued supervisory letters with recommendations.
- EC8 (understanding operational structures, including subsidiary governance and opaque structures):
  - Corporate Governance Guideline highlights governance of subsidiaries and complex organizational structures.
  - Risk Committee should understand types of risks and techniques/systems to identify, measure, monitor, report on and mitigate those risks.
  - OSFI evaluates understanding and mitigation of risks associated with organizational structures including subsidiaries, offshore operations and associated parties.
- EC9 (notification/disclosure of material issues affecting fitness and propriety):
  - Corporate Governance Guideline (September 2018) notes banks “should notify OSFI, as early as possible (...) of any potential changes to the membership of the Board and Senior Management, and any circumstances that may adversely affect the suitability of Board members and Senior Management.”
  - Assessors found evidence banks notify issues affecting fitness and propriety.
- EC10 (supervisor power to require board composition changes):
  - Statutory removal authority summarized above (647.1) — Superintendent may remove directors/senior officers found unsuitable; no removal orders yet issued in observed period.
  - Supervisory examples exist where OSFI raised concerns regarding appropriate risk management expertise on boards.
- Assessment outcome cited in the material:
  - Assessment of Principle 14 — Compliant.
  - Comments note that minimum requirements on boards are established in the Bank Act and OSFI guidelines, supervisory framework emphasizes corporate governance with the new supervisory framework including a rated category “Risk Governance” and subcategory “Governance.”

### Risk Management Process (Principle 15) — framework, supervisory tools and key expectations
- Principle 15 overview:
  - Banks must have comprehensive risk management processes to identify, measure, evaluate, monitor, report and control or mitigate all material risks (including digitalization, climate-related financial risks and emerging risks), assess capital and liquidity adequacy and sustainability of business models, and develop/review contingency arrangements and recovery plans commensurate with risk profile and systemic importance.
- OSFI supervisory framework and resources:
  - Each bank is overseen by an LS and a dedicated team; dedicated teams of around 6 people for each of the six D-SIBs; SMSBs are part of portfolios assigned to teams where, on average, each team is responsible for 2 institutions.
  - Supervisory teams are assisted by experts in credit, market, operational risk, and corporate governance.
  - OSFI’s Supervisory Framework feeds into the ORR (Overall Risk Rating) with specific risk categories including “Risk governance,” “Operational resilience,” “Financial resilience,” and “Business risk.”
- Key guidelines and instruments referenced:
  - Guideline E-21 Operational Risk and Resilience (August 2024; revised from 2016 version) — forward-looking RAF and reporting, use of scenario analyses, change management, data risk management; specifies data governance, architecture, classification, lineage, protection, incident escalation and training.
  - Guideline B-13 Technology and Cyber Risk Management (July 2022) — expectations related to technology and cyber risk management; OSFI used self-assessments and as at 1 January 2024, from 13 of D-SIBs and larger insurance companies, 4 indicated they are fully compliant; plans to address gaps to be assessed by OSFI by 2025/26.
  - Intelligence-led Cyber Resilience Testing (I-CRT) launched in 2023 and conducted every three years for D-SIBs; non-D-SIBs may request I-CRT on a case-by-case basis.
  - Guideline B-15 Climate Risk Management (March 2023) — senior management accountability, transition planning, incorporation into RAF and enterprise risk framework, climate risk data expectations and scenario analysis; phase-in implementation: D-SIBs expected to meet expectations by fiscal year-end 2024, other banks by fiscal year-end 2025; OSFI issued a Guideline B-15 readiness self-assessment questionnaire.
  - Guideline E-19 ICAAP for Deposit-Taking Institutions (2010) — ICAAP six components: (i) senior management oversight, (ii) sound capital assessment and planning, (iii) comprehensive assessment of risks, (iv) stress testing, (v) monitoring and reporting, (vi) internal control review.
  - Guideline E-23 Enterprise-Wide Model Risk Management for Deposit-Taking Institutions (September 2017) — enterprise-wide model risk management expectations; distinguishes Internal Models approved institutions and other Standardized institutions; requires inventories, identification of most material models, governance and control requirements, independent validation and testing.
  - Stress Testing Guideline and top-down MSTs for biggest banks.
- Supervisory practices and findings on risk management:
  - OSFI requires banks to conduct regular stress tests including macroeconomic scenarios; top-down MSTs are required for biggest banks according to OSFI-prescribed scenarios.
  - OSFI performs supervisory letters following exercises (example: supervisory letter following 2023 MST exercise).
  - OSFI’s supervisory work includes on-site examinations and reviews, cross-system reviews and follow-up supervisory letters requiring action plans.
  - Example findings include legacy data systems, data dictionaries and data management framework issues identified in a data governance review of big banks; banks required to develop action plans.
  - OSFI conducts reviews of compensation and links CRO compensation guidance to risk appetite.
  - OSFI has a team of 4–5 people focused on modeling reviews merged into Credit Risk Division; assessors noted resource constraints for deep credit risk model reviews and recommended more deep reviews related to model outputs.
  - OSFI had a 2023–24 data management and governance review scoped at 3 D-SIBs with many findings; remediation monitored through standard follow-up.
- Risk data aggregation and reporting (EC7–EC8):
  - Guideline E-21 (August 2024) details data risk management and risk data aggregation/reporting capabilities, including governance, architecture, lineage, classification, protection, integrity/adaptability/confidentiality/availability, incident escalation, and training.
  - OSFI assesses bank maturity on data aggregation/reporting through quarterly monitoring and on-site reviews; 2022 BCBS239 self-assessments resulted in follow-ups.
- ICAAP, capital and liquidity assessments (EC5):
  - ICAAP returns: quarterly from Tier 1 banks and annually for Tiers 2 to 5; OSFI applies proportionality in ICAAP requirements.
  - OSFI integrates ICAAP and liquidity risk management into Supervisory Framework rather than separate assessments; ICAAP embedded in ORR “Financial resilience” risk category.
  - Cross-sector review in 2023 on “Internal Targets” produced findings and supervisory letters on internal capital targets, ICAAP procedures, capital contingency plans, recovery plans and stress testing.

### Model risk, information systems and operational resilience
- Model risk management expectations:
  - Guideline E-23 requires regular and independent validation and testing of models; supervisors assess validation/testing results.
  - OSFI’s expectations are adequately drafted; assessors considered OSFI should conduct more deep dives into model outputs and modeling choices.
  - IRB usage: all D-SIBs use IRB; credit risk accounts for more than 80 percent of RWA for the big 6 banks (as noted in the material).
  - Modeling review resources: team of 4–5 people focused on modeling; constraints noted.
- Information systems and reporting (EC7):
  - Guideline E-21 (August 2024) contains a full set of expectations on data risk management and operational resilience.
  - OSFI assesses adequacy of information systems and reporting under normal and stressed circumstances using resolution and recovery plans and ORR “Operational resilience,” subcategory “Operations.”
  - Evidence of supervisory reviews includes the 2023–24 Data Management and Governance review at 3 D-SIBs with many findings resulting in supervisory letters.
- Cyber and incident reporting:
  - Incident reporting mandatory; within Technology Risk Division a team of 5 people handles reported incidents.
  - Cyber security self-assessment tool revised in 2021; I-CRT launched 2023.
  - OSFI expects banks to: establish technology and cyber risk frameworks, identify security risks/vulnerabilities, classify/protect data, maintain continuous situational awareness, and conduct intelligence-led testing.

### Supervisory assessments, cross-system reviews and remedial actions
- OSFI supervisory approach:
  - Supervisory Framework includes ratings, scorecards and the ORR; “Risk governance” is a rated category with subcategory “Governance.”
  - Supervisory activities include off-site monitoring, on-site inspections, thematic/cross-system reviews, cross-sector reviews and targeted examinations.
  - Findings from thematic reviews are communicated by supervisory letters and remediation actions are monitored through standard follow-up.
- Examples of supervisory reviews and timelines:
  - 2022–23 cross-sector review of D-SIBs included board member interviews to verify oversight duties.
  - 2015 cross-system review of D-SIB compensation practices led to supervisory letters and recommendations.
  - 2023–24 Corporate Governance cross-system review produced findings communicated to banks.
  - Guideline B-15 phase-in: D-SIBs by fiscal year-end 2024; others by fiscal year-end 2025; OSFI issued a Guideline B-15 readiness self-assessment questionnaire.

*Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf*

### Section V of the Corporate Governance Guideline sets the expectation that banks should

### Section V of the Corporate Governance Guideline sets the expectation that banks should

### Corporate governance: notification and CROs
- Banks should notify OSFI, as early as possible in the process, of any potential changes to senior management.  
- The LS for the bank is normally notified before a removal or appointment of a CRO.  
- There is no requirement for public disclosure of CRO removals; however, if the bank is listed, which is the case of all D-SIBs, it needs to disclose.  
- OSFI conducts exit interviews with CROs and other board members, providing useful information on banks’ risk oversight functions and risk management process.  
- OSFI has not directed any specific bank to establish a dedicated risk management function, but would recommend establishment if supervisors concluded that risks were not being adequately controlled and overseen. In practice, even the small banks have a CRO.

### Standards related to risk types (EC12)
- OSFI has issued Guidelines covering:
  - Liquidity risk management principles: Guideline B-6 Liquidity Principles, of January 2020.
  - Liquidity adequacy requirements: Guideline LAR, of January 2022.
  - Interest rate risk in the banking book (IRRBB): Guideline B-12 Interest Rate Risk Management, of May 2019.
  - Operational risk and resilience: Guideline E-21, of August 2024, updating the 2016 Guideline.
  - Large exposures: Guideline B-2, from November 2019.
- Credit and market risk guidance are primarily contained in the Capital Adequacy Requirements (CAR) Guideline, of November 2023, which implements the Basel III capital framework in Canada, effective January 2024. Capital requirements for operational risk are also set in the CAR Guideline.
- Regarding Basel III capital floors:
  - On 12 February 2025, OSFI announced the deferral of further increases to the Basel III standardized capital floors (or “output floor”) until further notice.
  - Therefore, the output floor will remain at 67.5 percent and there is no clear timeline to implement the Basel III 72.5 percent capital floor level applicable to capital requirement calculations under internal models.
- The ICAAP Guideline E-19, of October 2010, and the ICAAP Advisory suggest a template for ICAAP submissions and contemplate expectations on general risk management, capital assessment and planning, and on credit, market, liquidity and operational risks, in addition to risk concentrations and IRRBB.
- The ORR scorecard establishes risk rating explanatory guides for supervisors to rate the risk category “Financial resilience,” encompassing the subcategories “Financial risk profile,” “Capital” and “Liquidity.” Banks in Tiers 1 and 2 are further assessed for “Credit risk,” “Market risk (trading)” and “Market risk (non-trading).” Operational risk management is further assessed under the risk category “Operational resilience.”

### Contingency arrangements and recovery planning (EC13)
- OSFI’s recovery planning expectations include the 2012 Recovery Plan Principles, a detailed table of contents outlining major elements, and Technical Notes; these documents are not published.
- All D-SIBs are required to submit recovery plans. All other banks are required to submit recovery plans on a risk-basis, as needed. OSFI has used this prerogative in practice (e.g., asked a SMSB with a higher ORR rating to submit a recovery plan).
- All banks are required to submit liquidity contingency plans and business continuity plans, per Guideline B-6 Liquidity Principles, of January 2020, Section E, and Guideline E-21 Operational Risk Management and Resilience, of August 2024, Section 4.
- For the two G-SIBs, recovery plans are required since 2010; for the remaining D-SIBs, since 2011.
- Starting in 2023, OSFI, along with CDIC and the BoC, agreed with banks’ request to change the annual submission of recovery plans to a bi-annual submission, every June of the year they are due.
  - The last recovery plan submission by D-SIBs was at the end of June 2024.
- Main requirements of the recovery plan include:
  - corporate overview (legal entities, separability analysis);
  - sensitivities and scenarios (stress testing for systemic, idiosyncratic events);
  - scenarios and contingency plans (assessment of options, contingency funding plans, capital recovery plans);
  - crisis management process (activation of the recovery plan, crisis communication plan);
  - data requirements (aggregation and reporting).
- Banks are required to provide detailed appendices supporting the main requirements.
- OSFI has a dedicated Crisis Readiness Unit staffed with five full time employees, two of which have crisis management responsibilities to develop recovery plan expectations, perform comparative review of recovery plans, and plan Crisis Management Group Meetings and Outreach Panel Meetings.
- OSFI shares recovery plans with CDIC, the BoC and the DOF, members of Canada’s safety net.
- In non-submission years, OSFI expects banks to review and update recovery plans at least annually, or when there is a material change to strategy, business, corporate structure, operations, aggregated risk exposure or any other change with material impact; OSFI and other agencies should be notified of resulting changes.
- Recovery plans should be refreshed whenever the bank encounters a severe stress situation, or at the request of OSFI or other agencies.
- Supervisory assessment of contingency plans is considered in the ORR process: in “Financial resilience,” capital and liquidity contingency plans are rating attributes, including contingency funding plans.
- Supervisors perform on-site reviews of business continuity risk management programs, assessing business continuity plans, business impact analyses, communication protocols, testing and action plans.
- OSFI assesses business resumption and contingency plan quality and effectiveness by observing ability to respond during disruptive events; expectations are in 2024 Guideline E-21 Operational Risk Management and Resilience.
  - OSFI does not expect financial institutions to have identified their critical operations and completed mapping dependencies until September 1, 2025, but supervisors have verified that business continuity plans and business impact analyses highlight more critical functions and systems.
- The assessors had access to evidence of the supervisory work.

### Stress testing (EC14)
- Guideline E-18 Stress Testing, of December 2009, sets expectations for banks to perform forward-looking stress tests on a regular basis. Results of stress testing are required to be included in the bank’s risk management processes.
- Selected expectations from Guideline E-18:
  - “Stress testing should be embedded in enterprise-wide risk management.”
  - “A stress testing program as a whole should be actionable, playing an important role in facilitating the development of risk mitigation or contingency plans across a range of stressed conditions. It should feed into the institution's decision-making process, including setting the institution's risk appetite, setting exposure limits, and evaluating strategic choices in longer term business planning.”
  - A stress testing program should serve purposes of (i) risk identification and control; (ii) provide complementary risk perspective to other risk management tools; (iii) support capital management; (iv) improve liquidity management. The risks to be included are detailed in section E of the guideline.
  - A bank’s stress testing infrastructure and information systems should be commensurate with the nature and complexity of the bank and its risk profile.
- Guideline E-21 Operational Risk and Resilience (2024) sets expectations for scenario testing related to tolerances for operational disruption, including:
  - testing a range of severe but plausible scenarios;
  - testing concurrent and longer duration events;
  - ensuring that senior management and the board receive results of scenario testing;
  - requiring that testing results of previous testing inform future testing.
- Institutions are not yet expected to adhere to expectations related to testing tolerances for disruption, but supervisors apply the above expectations to business continuity and disaster recovery testing.
- The ORR process incorporates assessment of stress testing; examinations feed into rating of “Financial resilience” in “Financial risk profile” and “Capital” sub-categories. For Tier 1 and 2 banks, stress test results and their impact in capital planning enter ratings of “Capital management” and “Capital adequacy” of the sub-category “Capital.”

### Internal pricing, performance measurement and new product approval (EC15)
- For D-SIBs, issues related to significant business activities appear in ongoing monitoring through the information package LSs receive quarterly (e.g., information about and discussions on banks’ internal Key Performance Indicators (KPIs)).
- When an issue is identified through monitoring or a related supervisory review, OSFI assesses via specific review whether banks appropriately identify and mitigate risks related to internal pricing and performance measurement, including existing, changed and new products, services and processes.
- Supervisory assessments of internal pricing factor into the ORR, entering risk ratings of “Business risk,” “Financial risk profile” and “Financial resilience,” in evaluating operation management and capital and risk management.
- Evidence that OSFI occasionally reviews specific issues of EC15 was provided to assessors.
- Examples:
  - Market and Liquidity Risk Division monitors large banks’ funds transfer pricing practices.
  - Operational Risk Division data governance and management thematic review of the D-SIBs resulted in multiple findings related to data key performance indicators.
  - Acquisition of a portfolio of buy now-pay later loans by a medium-sized institution was recently assessed, considering business risk, financial, operational, and compliance-related implications.

- Assessment of Principle 15: Largely Compliant.

- Comments:
  - Risk management processes of banks in Canada are generally included in OSFI’s supervisory framework through ongoing monitoring or dedicated reviews on corporate governance.
  - Examples of supervisory considerations reflected in the ORR include impacts of risks on financial and operational resilience, emerging risks, and discussions on adequacy of capital, liquidity and business risk with senior management and boards.
  - Macroeconomic conditions are included through stress testing and business risk in supervisory process.
  - OSFI has invested significantly in supervision of non-financial risks in recent years, reflected in reviews covering contingency arrangements and operational resilience.
  - However, banks’ model outputs are not being deeply reviewed. Supervisory review of banks’ models could be reinforced given the importance and complexity of the banking system in Canada, home to 6 D-SIBs, including 2 G-SIBs.
  - Greater scrutiny regarding the use of models by banks, as per EC6, is warranted. Supervisors should more deeply assess compliance with supervisory standards on the use of models and challenge the reasonability of model outputs.
  - This is particularly important where all Canadian D-SIBs use internal models to calculate their credit risk capital requirements, which represent more than 80 percent of their RWAs. See CP17.

- Recommendation:
  - Increase the frequency, the range and the depth of reviews on banks’ internal models used in Canada to manage and assess risk and to calculate capital requirements, providing effective challenge to modelling choices, assumptions and outcomes. This would enhance banks’ modeling practices in Canada and provide better assurance that risk assessment techniques are adequate.

### Capital adequacy (Principle 16) — legal and supervisory framework (EC1)
- Subsection 485(1) of the Bank Act requires banks to maintain adequate capital and liquidity in appropriate form. Subsection 485(1.1) requires domestic systemically important banks (D-SIBs) to maintain the minimum capacity to absorb losses (for example, TLAC). The legal basis of OSFI’s TLAC requirements is subsections 485(1.1) and (1.2) of the Bank Act.
- Pursuant to section 485 of the Bank Act:
  - The definition by OSFI of the amount that constitutes the D-SIB’s minimum capacity to absorb losses is subject to consulting with FISC (subsection (1.2)), however the Minister may advise the Superintendent of this amount, if they are of the opinion that the amount provided for by the Superintendent is not in the public interest (subsection 1.3);
  - The Governor in Council may make regulations, and the Superintendent may make guidelines on the maintenance of adequate capital, liquidity, and the maintenance by D-SIBs of the minimum capacity to absorb losses (subsection (2));
  - Even when a Bank complies with formal requirements, the Superintendent may order the bank to increase its capital or to provide more liquidity, and the bank must comply within a time specified by the Superintendent (subsection (3));
  - For D-SIBs, after consulting with members of FISC, the Superintendent may take any measures considered appropriate where a bank is not maintaining its minimum TLAC requirements, including limiting growth of the bank’s total assets, limiting or prohibiting acquisitions of assets, limiting or prohibiting discretionary capital distributions, limiting or prohibiting reductions in the bank’s stated capital, and limiting or prohibiting the opening of new branches by the bank (sub-sections (3.1) and (3.2));
  - The Superintendent may also override the bank’s appraisal of asset values (subsection (5)).
- Section 949 of the Bank Act imposes similar requirements on bank holding companies and gives the Governor in Council and the Superintendent similar powers to direct bank holding companies to increase capital or liquidity. Holding companies are not relevant for Canada.
- OSFI guidelines and advisories provide the framework within which the Superintendent assesses whether a bank maintains adequate capital, liquidity, or TLAC pursuant to section 485 of the Bank Act.
- OSFI’s minimum capital requirements are stipulated in section 1.6 of Chapter 1 of the Capital Adequacy Requirements (CAR) Guideline.
  - In addition to minimum capital requirements, as set out in section 1.10 of Chapter 1 of the CAR Guideline, OSFI expects all banks to maintain supervisory targets equal to or greater than the minimum capital ratios plus various buffers.
- Minimum and authorized leverage requirements are set out in part IV of OSFI’s Leverage Requirements Guideline.
- Minimum TLAC requirements applicable to D-SIBs are set out in OSFI’s TLAC Guideline with the minimum TLAC requirements prescribed by orders of the Superintendent dated August 21, 2018, effective November 1, 2021. TLAC levels are disclosed by banks in Pillar 3.
- OSFI implemented the final Basel III reforms through modifications to its guidelines effective February 1, 2023.
  - On July 5, 2024, OSFI announced a one-year delay to the increase of the capital floor level (or “output floor”) up to the 72.5 percent established by the Basel Standards in RBC20, subject to the transitional arrangement as in RBC90.
  - The new date for the full implementation of the output floor in Canada, fiscal year 2027 (November 1, 2026), is in line with the RBC90, which established the date of January 1, 2028.

*Italic: Content adapted from 1canea2025007-source-pdf - Section V of the Corporate Governance Guideline sets the expectation that banks should*

### Chapter 2 of the CAR Guideline establishes the definition of capital for banks, which is a key

### 1canea2025007-source-pdf - Chapter 2 of the CAR Guideline establishes the definition of capital for banks, which is a key

### Definition and scope of capital
- Chapter 2 of the CAR Guideline establishes the definition of capital for banks to ensure loss-absorption capacity on a going concern basis.
- The CAR Guideline is applicable to banks (including federal credit unions), bank holding companies, federally regulated trust companies and federally regulated loan companies.
- Section 1.1 of Chapter 1 specifies application on a consolidated basis to D-SIBs and SMSBs; the consolidated entity includes all subsidiaries except insurance subsidiaries.
- OSFI expects institutions to hold capital within the consolidated group consistent with the level and location of risk. For D-SIBs, OSFI receives capital information on a sub-consolidated basis as part of ongoing monitoring.

### Findings on composition of CET1, AT1 and T2; preferred shares treatment
- BCBS assessment under the RCAP (June 2014) found a potentially material deviation: preferred shares are considered equity in Canada and enter AT1 (paragraph 13, “l,” of Chapter 2 of the CAR Guideline).
- Because preferred shares in Canada are considered equity instead of liabilities as per Basel standards, preferred shares are not required to have the automatic conversion trigger at the capital ratio of 5.125 percent of RWA (CAP10, 10.11, (11)).
- OSFI’s view: better to keep preferred shares eligible to AT1 under the definition of equity rather than introduce an automatic conversion clause because introducing automatic conversion would lead to the shares being considered liability for accounting purposes, with potential adverse implications on financial stability.
- Note: in Canada a long-standing preferred share market is primarily focused on retail investors.
- Given concerns that AT1 retail investors may amplify an institution’s distress and hinder recovery and resolution efforts, OSFI has limited issuance of AT1 instruments to institutional investors since July 2020.
- Since July 2020 limited recourse capital notes have been issued by banks and are expected to substitute retail preferred shares.
- Assessors recommend OSFI to continue to closely monitor the capital composition of banks, including the effectiveness of AT1 capital to absorb losses, also considering current international discussions.

### AT1 composition as of Q2 2024
- AT1 of banks in Canada were composed of:
  - 23 percent of retail preferred shares
  - 12 percent of institutional preferred shares
  - 56 percent of limited recourse capital notes
  - 9 percent of other AT1

### D-SIBs capital ratios (percent)
- D-SIBs Capital Ratios in Canada:
  - CET1: 2020: Q4 — 12.2; 2021: Q4 — 13.3; 2022: Q4 — 13.6; 2023: Q4 — 13.4; 2024: Q2 — 13.1
  - AT1: 2020: Q4 — 1.7; 2021: Q4 — 1.7; 2022: Q4 — 1.8; 2023: Q4 — 1.8; 2024: Q2 — 1.8
  - Tier 2: 2020: Q4 — 2.1; 2021: Q4 — 2.0; 2022: Q4 — 2.0; 2023: Q4 — 1.9; 2024: Q2 — 1.9
  - Total Capital: 2020: Q4 — 16.0; 2021: Q4 — 16.9; 2022: Q4 — 17.4; 2023: Q4 — 17.0; 2024: Q2 — 16.8
- Assessment: D-SIBs have the most significant amount of preferred shares in AT1, but CET1 is enough to cover the current total Pillar 1 capital requirement of 11.5 percent, including buffers.

### OSFI implementation of Basel III and other standards
- OSFI implemented the final Basel III reforms, with effective dates:
  - Capital Definition: 2013: Q1
  - Credit risk: 2023: Q2
  - Fundamental Review of the Trading Book (FRTB): 2024: Q1
- Basel standards implementation dates (with phase-in arrangements): December 2015 for the definition of capital; due to the COVID-19 pandemic, January 1, 2023 for the revised credit risk and market risk frameworks.
- OSFI has adopted Basel standards for capital adequacy covering the definition of capital and related buffers, and credit, market and operational risks, generally aligned with standards but with instances of higher thresholds or limits and more stringent expectations.
- For internationally active banks, the definition of capital, risk coverage, method of calculation and thresholds for prescribed requirements are not lower than those established in the applicable Basel standards (applied on a fully consolidated basis).

### Instances where OSFI’s treatment differs from Basel framework
- Credit card exposures: increased credit conversion factor for all credit card exposures from 10 percent to 25 percent and decreased the risk weight (RW) for transactors from 40 percent to 15 percent.
- Exposures to corporate: permits ECRA approach to internally rate unrated corporate borrowers as IG or non-IG and apply a 65 percent RW to IG and a 150 percent RW to non-IG.
- Exposures to covered bonds: reduced the overcollateralization requirement for eligible covered bonds from 10 percent to 5 percent; exposures treated as exposures to banks and subject to risk weights one notch higher than in the Basel framework.
- Exposures to Public Sector Entities (PSEs): created a separate asset class under IRB, permitting A-IRB for exposures to PSEs.
- Securitization framework:
  - Basel: all undrawn securitization exposures subject to 100 percent CCF; SA credit risk framework applies a 40 percent CCF to undrawn exposure where applicable. OSFI applies the SA treatment in relevant cases (does not apply to ABCP liquidity backstop facilities).
  - OSFI added another method to calculate tranche maturity for drawn exposures and undrawn revolving facilities based on the EBA implementation.
  - OSFI allows SEC-ERBA or SEC-IAA instead of SEC-IRBA for third party originated securitizations where excess spread is a significant credit risk mitigant (not applicable where bank is originator).
- Market risk:
  - Allows repo-style transactions recorded on an accrual accounting basis or held for liquidity management to reside in the banking book for regulatory capital purposes.
  - Allows exemptions for arms-length transactions between trading book and banking book (CAD and non-CAD L1 and L2A liquid assets as defined under the LCR issued by Canadian entities).
  - Reduced the PD floor from 3bps to 1bp only for Canadian sovereign exposures when banks use internal models for DRC.
- Leverage: permits use of the unmodified SA-CCR for all derivative exposures.
- OSFI notes some less stringent expectations but considers these do not lead to a significant decrease in capital requirements.

### Target capital ratios, buffers and other supervisory expectations
- Target Capital Ratios (percent):
  - SMSBs: Target CET1 capital — 7.0; Target Tier 1 capital — 8.5; Target Total capital — 10.5
  - D-SIBs: Target CET1 capital — 8.0 plus DSB; Target Tier 1 capital — 9.5 plus DSB; Target Total capital — 11.5 plus DSB
- Basel minimums reflected in CAR Guideline, Chapter 1, section 1.6: CET1 — 4.5 percent; Tier 1 — 6 percent; Total Capital — 8 percent.
- Additional components:
  - Capital Conservation Buffer (CCB) of 2.5 percent as per subsection 1.7.1.
  - D-SIB Surcharge equal to 1 percent as defined in section 1.8, applicable to all D-SIBs as an extension of the CCB.
- Domestic Stability Buffer (DSB):
  - Established in CAR Guideline, Chapter 1, section 1.9 to cover systemic vulnerabilities not adequately captured in Pillar 1.
  - Level ranges from 0 to 4 percent of a D-SIB’s total RWA; as of October 2024 it was set at 3.5 percent.
  - The DSB is not a Pillar 1 buffer; breaches do not result in automatic constraints on capital distributions described in section 1.7.
  - DSB is adjusted twice a year.
  - OSFI views the DSB as a financial stability buffer and argues it goes beyond the Basel III CCyB.
  - If a D-SIB breaches the DSB, a restoration plan must be presented.
  - OSFI recognizes overlap between DSB and CCyB but applies DSB naturally to D-SIBs only; as of December 2023 D-SIBs held 96 percent of the Total Assets of banks supervised by OSFI.
  - A working group composed of OSFI and the BoC conducts studies used in DSB definition; decisions are made in consultation with FISC.
  - Assessors had an indication that, given DSB implementation, OSFI does not see activation of the CCyB in Canada as probable.
- Countercyclical Capital Buffer (CCyB): can be established ranging from 0 percent to 2.5 percent of total RWA; as of September, 2014, the Canadian CCyB is zero.
- Minimum leverage ratio expectations:
  - At least 3.5 percent for D-SIBs
  - At least 3 percent for all other institutions
  - Set out in Part IV of the Leverage Requirements Guideline (paragraphs 7 and 13).
- D-SIBs are currently subject to a supervisory target risk-based TLAC ratio of [text cuts off in source].

*Source: OSFI and BCP assessors’ calculations.*

### 21.5 percent of RWA and TLAC Leverage ratio of 6.75 percent as set out in the

### 21.5 percent of RWA and TLAC Leverage ratio of 6.75 percent as set out in the

### TLAC and leverage requirements; supervisory discretion (EC3)
- TLAC Leverage ratio: 6.75 percent as set out in the Superintendent’s order dated August 21, 2018.
- Addition of the DSB: 3.5 percent.
- Addition of the D-SIB leverage ratio buffer: 0.5 percent.
- Total required TLAC ratio for D-SIBs: 25 percent.
- Total required leverage ratio for D-SIBs: 7.25 percent.
- Superintendent has discretion to set higher targets for individual institutions where appropriate.
- Breaches of TLAC requirements, which is 25 percent for D-SIBs, does not trigger early intervention measures.

### Supervisor powers and calculation of prescribed capital requirements (EC3 findings)
- Supervisor can impose a specific capital charge and/or limits on all material risk exposures, including risks not adequately transferred or mitigated through transactions (for example securitisation transactions).
- Both on-balance sheet and off-balance sheet risks are included in the calculation of prescribed capital requirements.
- Subsection 485(1.2) of the Bank Act: OSFI shall, after consulting with FISC, provide for the amount that constitute the D-SIBs minimum capacity to absorb losses, implemented in the TLAC requirement and the D-SIB Surcharge.
- Section 485(3) of the Bank Act: OSFI may direct banks to increase their capital in addition to complying with capital requirements and specific requirements for D-SIBs.
- OSFI evaluates capital adequacy and capital management continuously through supervisory monitoring.
- Banks are subject to regulatory minimum requirements and to more onerous supervisory targets reflected in section 1.10 of Chapter 1 of the CAR Guideline:
  - OSFI expects that all banks maintain target capital ratios equal to or greater than the minimum capital ratios plus the CCB;
  - The targets are triggers for supervisory intervention consistent with OSFI’s Guide to Intervention. If an institution is offside the relevant target ratios, supervisory action will be taken proportional to the shortfall and circumstances that caused the shortfall and may include, but is not limited to, restrictions on capital distributions;
  - The Superintendent may set higher target capital ratios for individual institutions or groups of institutions where circumstances warrant, including in respect of idiosyncratic and/or systemic risks that are not adequately captured by institutions’ Pillar 1 capital requirements and buffers, which was the case for the establishment of the DSB;
  - The need for additional Pillar 2 capital and corresponding higher target capital ratios would consider how robust existing capital ratios are in light of an institution’s allowances, stress testing program, and ICAAP results.
- OSFI’s early intervention generally commences upon breaches of the capital targets or, in some cases, breaches of banks’ own higher internal targets or early warning thresholds.

### Pillar 2, ICAAP, stress testing, and supervisory adjustments (EC3 / EC4)
- OSFI’s capital requirement framework follows the Basel standards with few deviations; calculations include risks from on- and off-balance sheet exposures.
- OSFI imposes a leverage requirement via the Leverage Requirements Guideline on all banks, incorporating on- and off-balance sheet exposures, including derivatives and securities financing transactions.
- OSFI’s ICAAP Guideline requires banks to consider all material risks including large exposures and risk concentration, securitization, and complex structured instruments, with focus on risks not adequately captured under Pillar 1.
- Guideline requires banks to consider whether minimum regulatory capital requirements fully capture risks, especially when business has been securitized and risk transfer may not be complete.
- Canadian banks are required to use stress tests to help assess and manage risks; ICAAPs and stress tests help identify capital requirements and provide basis for supervisory action.
- OSFI applies supervisory Pillar 2 add-ons where appropriate to increase a bank’s risk-based and/or leverage supervisory targets for reasons including incurred or expected loss, macroeconomic vulnerability, or erosion of controls or governance.
- Where a bank is subject to a supervisory adjustment to its capital targets, OSFI conveys the change via a formal supervisory letter and a meeting with senior management and, where appropriate, the Board of Directors.
- Pillar 2 capital requirements do not add to TLAC capital requirements.
- Practical actions:
  - In September 2022, given rising interest rates and other potential macro-economic risks, OSFI communicated additional capital expectations for selected SMSBs that were particularly vulnerable in this macro-economic environment.
  - As of October 2024, three D-SIBs have Pillar 2 capital add-ons in place, generally on the grounds of deficiencies on risk management and corporate governance.

### Risk-sensitive requirements, TLAC holdings adjustment, and leverage limits (EC4)
- Prescribed capital requirements reflect risk profile and systemic importance, constrain build-up of leverage, and reduce contagion risk.
- Supervisor focuses on:
  - (a) the potential loss absorbency of instruments included in the bank’s capital base;
  - (b) the appropriateness of risk weights as a proxy for the risk profile of exposures;
  - (c) the adequacy of provisions and reserves to cover expected losses; and
  - (d) the quality of risk management and controls.
- OSFI’s Pillar 1 capital requirements in the CAR Guideline reflect risk profile according to methodologies in the final Basel III reforms.
- D-SIBs are subject to capital and leverage targets as reflected in Chapter 1 of the CAR Guideline; certain buffers (D-SIB surcharge, DSB, Leverage Ratio D-SIB buffer) apply to D-SIBs only, while CCB and CCyB apply to all banks.
- All D-SIBs are subject to TLAC expectations in line with the FSB TLAC standard as set out in OSFI’s TLAC Guideline.
- OSFI extended the Basel III regulatory capital adjustment for banks’ TLAC holdings to include instruments issued by any G-SIB or a Canadian D-SIB to mitigate interconnectedness and contagion.
- An absolute limit on leverage is achieved through the Basel III Leverage ratio as implemented in OSFI’s Leverage Requirements Guideline and the TLAC Leverage Ratio in OSFI’s TLAC Guideline.
- Pillar 2 framework (Guideline E-19 ICAAP and Guideline E-18 Stress Testing) requires consideration of system-wide interactions and macro-economic conditions when assessing appropriate capital levels.
- OSFI may impose more stringent supervisory expectations, including capital add-ons and/or more stringent leverage ratios, where capital may not adequately cover idiosyncratic and/or systemic risks.
- Under OSFI’s Supervisory Framework, in the “Financial resilience” category OSFI evaluates:
  - financial risk indicators, financial buffers (including provisioning), and capital and risk management;
  - banks in Tiers 1, 2 and 3 are specifically rated in subcategories “Capital” and “Financial risk profile”;
  - Tiers 1 and 2 banks are further rated on “Credit,” “Capital adequacy” and “Capital management.”
- OSFI assesses capital adequacy for financial resilience in severe but plausible stress scenarios, considering composition and loss absorbency of capital base, adequacy of provisioning, capital management, contingency plans, stress test results, and access to capital.

### Use and supervision of internal models for regulatory capital (EC5)
- Use of banks’ internal assessments of risk as inputs to regulatory capital is approved by the supervisor subject to qualifying conditions (a)–(e).
- As of October 2024:
  - For credit risk, all six D-SIBs are approved to use A-IRB. Five of the six D-SIBs were A-IRB approved as of Basel II implementation in 2008. The last of the D-SIBs to achieve A-IRB approval was in 2010.
  - Foundation IRB (F-IRB) is only used for asset classes when A-IRB is not permitted (for example, exposures to Banks and Large Corporates).
  - CCR: two D-SIBs are approved to use the Internal Models Method (IMM) for CCR; one implemented the IMM as of 2016: Q2, the other implemented as of 2020: Q2.
  - Market risk framework (“FRTB”): all Canadian banks subject to the market risk framework are under the standardized approach (FRTB-SA); however, such banks have the option to adopt internal model subject to OSFI’s approval. Prior to FRTB adoption, all six D-SIBs were approved to use the advanced market risk framework as of 1996.
  - Operational risk: prior to the implementation of Basel III, the majority of D-SIBs was approved to use Advanced Measurement Approaches (AMA), which is not allowed anymore.
- Bank internal models are subject to OSFI’s review and approval as per the Implementation Note on Assessment of Regulatory Capital Models for Deposit-Taking Institutions, of January 2021.
- The Implementation Note establishes OSFI’s Capital Model Assessment Program (CMAP) covering the entire capital model lifecycle: new model applications, subsequent modifications, performance monitoring, periodic ongoing compliance reviews and model decertification.
- The CMAP defines rigorous acceptance standards used for all model assessments for regulatory capital:
  1. Methodology: assessment of the model's quantitative approaches to segment and measure risk.
  2. Integration: assessment of the model's integration into the institutions' risk management practices.
  3. Operations: assessment of the model's implementation, application and monitoring in a production environment.

*Source: 1canea2025007-source-pdf - 21.5 percent of RWA and TLAC Leverage ratio of 6.75 percent as set out in the*

### 4. Controls: an assessment of the effectiveness of oversight applied to the internal

### 4. Controls: an assessment of the effectiveness of oversight applied to the internal models.

### Approval, governance, and conditions for model use
- All model applications are subject to the approval of the Capital Model Review Committee (CMRC), which is comprised of OSFI senior managers.
- The review team will put a recommendation forward for the CMRC’s consideration: (1) Approval; (2) Approval with conditions; (3) Pause; and (4) Decline.
- Certain decisions are referred from CMRC to the Supervision Committee for final approval, in accordance with the internal document “Approval Authorities Standard, of June 2024.”
- Conditions are frequently applied to approvals and can include floors or ceiling to inputs or outputs, requirements to perform and report further work, and deadlines for work required. OSFI supervisors verify compliance with those deadlines and that recommendations for permanent processes are followed.
- According to the Implementation Note on Assessment of Regulatory Capital Models for Deposit Taking Institutions, banks must submit a self-assessment of compliance and indicate the materiality of the business covered by the model in the exploratory phase to use models for regulatory capital or to extend their use beyond the original approved scope. Banks must also indicate the impact of the model’s use on Pillar 1 capital requirements.
- Before a bank is allowed to use internal models for regulatory capital, OSFI reviews readiness including data and systems, compliance with the minimum Basel III requirements, and performance in measuring risk. OSFI evaluates a selection of inputs and models to assess the institution’s understanding of standards and processes.
- Once accredited, banks are expected to maintain robust controls, report model performance through regular monitoring, remedy deficiencies, and report intentions to develop or apply internal models for new uses with implementation plans. OSFI’s supervisory review extent may be influenced by portfolio materiality, but immateriality does not exempt models from supervisory review.

### Validation, inventories, and monitoring
- OSFI’s CAR guideline, Chapter 5, Section 5.8.7 Validation of Internal Estimates, specifies requirements for validation by banks; the Implementation Note Validating Risk Rating Systems at IRB Institutions elaborates on these CAR requirements.
- Banks must establish an effective validation framework observing principles of purpose, responsibility, independence, documentation, continuity, scope, response, and perspective.
  - In terms of responsibility, OSFI requires banks to designate specific groups responsible for design and performance of the validation process, including outputs.
  - In terms of documentation, validation must be properly documented to ensure reviewers can understand objectives, scope, methodology, and conclusions.
- Banks are required to maintain inventories of models used for regulatory capital calculation and logs of all modifications to approved models, enabling OSFI awareness of changes and supervisory action.
- OSFI monitors model performance and adherence to qualifying standards when banks introduce or modify models. As part of quarterly monitoring, if an outlier bank is identified from modelling results, OSFI inquires of the bank and follows up. OSFI also compares implementation across banks in special reviews.

### Resources, external reviews, and frequency of supervisory model assessments
- OSFI has specialist teams dedicated to risk measurement and analytics with staff experienced in model development at financial institutions.
- Issues related to resource constraints on modeling reviews at OSFI are discussed in CP15, EC6, and CP17.
- Example: for a large bank, there were 6 reviews on different aspects of internal models within 5 years, covering both market and credit risks (although, after the implementation of the FRTB, the bank does not use internal model for market risk anymore).
- Some reviews are conducted by third parties commissioned by OSFI (and paid by the banks) due to resource constraints and the need for specialized knowledge.
- Despite examples of reviews and follow-up measures, the assessors consider there are not sufficient reviews of internal models used by banks, as described in CP15.

### Recent modeling approval triggers and model change monitoring
- Recent approval requests included portfolios bought by banks and from bank acquisitions and mergers (for example, the acquisition of HSBC Canada by RBC).
- Approvals triggered by material changes in models are rare because it is the bank’s call to identify a material change in the models.
- OSFI monitors model changes via access to banks’ internal reports and documentation to senior management and oversight function.

### Output floors and model risk in Pillar 2
- OSFI has imposed output floors for regulatory capital above the minimum transitional floors of the Basel text.
- Banks are expected to take model risk into account in evaluating their Pillar 2 capital requirements pursuant to OSFI’s Guideline E-19 ICAAP, ICAAP return template, and Guideline E-23 Enterprise-Wide Model Risk Management for Deposit-Taking Institutions, of September 2017.
- As stated in OSFI’s CAR guideline, banks may not abandon internal models used in the calculation of capital (unless directed to do so by OSFI), except in rare circumstances such as the divestiture of a large business unit, and then only with OSFI’s permission.

### EC6 — Forward-looking capital management and contingency planning
- OSFI requires banks to adopt a forward-looking approach to capital management through Guideline E-19 ICAAP and Guideline E-18 Stress Testing.
- The ICAAP process links capital requirements to anticipated risks and requires stress testing to be an integral part of that process.
- Tier 1 (D-SIBs) and Tier 2 (Mid-sized SMSBs) institutions must submit a quarterly Capital and TLAC Planning Template which includes at least 12 rolling quarters of projections for risk-based capital ratios, leverage ratio, and TLAC ratios (D-SIBs only).
- OSFI uses ICAAP and stress testing processes and results as part of the Supervisory Framework to assess capital adequacy and management. Inadequate processes, results, or capital adequacy may affect a bank’s ORR and can lead to intervention, including directions under subsections 485(3) or 949(3) of the Bank Act.
- ICAAP Guideline E-19 explicitly expects banks to:
  - “Factor in the potential difficulties of raising additional capital during downturns or other times of stress” (page 6);
  - “Develop prudent contingency plans specifying how it would respond to capital pressures that arise when access to securitization markets is reduced” (page 8); and
  - “Incorporate the risk measures, stress testing results and contingency plans into its risk management processes and its ICAAP to set an appropriate level of capital under Pillar 2 in excess of the minimum requirements commensurate with the risk appetite statement” (page 8).
- The quality of a bank’s capital contingency plan is considered in evaluating capital adequacy, capital management, and the quality of recovery and resolution plans.
- The Stress Testing guideline highlights stress testing’s role in facilitating risk mitigation or contingency plans across stressed conditions (Stress Testing Guideline, page 3).

### EC7 — Leverage ratio implementation
- OSFI implemented the Basel III leverage ratio through the Leverage Requirements Guideline, of January 2023, providing a non-risk-based backstop to risk-based capital requirements.
- The leverage ratio requires Tier 1 Capital to be no less than 3 percent (or 3.5 percent for D-SIBs) of a bank’s total exposures (including on-balance sheet, derivative, securities financing transactions, and off-balance sheet exposures).
- In other words, a bank cannot take on exposures that would leverage the institution to more than ~33.33 times (~ 28.57 times for D-SIBs) of its Tier 1 capital.
- Prior to implementing the Basel III leverage ratio in 2015: Q1, OSFI had its own leverage ratio called the Asset to Capital Multiple (ACM). There was no material impact when OSFI transitioned from the ACM to the Basel III leverage ratio in 2015.
- OSFI considers the leverage ratio a critical backstop because it is risk-neutral and less sensitive to model risk, particularly effective for banks with low-risk densities where it may be the binding constraint.

### AC1 — Capital framework for non-internationally active banks and SMSBs segmentation
- OSFI’s CAR Guideline is applicable to all banks, but market risk capital requirements (Chapter 9) apply to internationally active institutions and all banks designated by OSFI as D-SIBs; OSFI retains the right to apply the framework to other institutions on a case-by-case basis.
- OSFI segments SMSBs into three categories per the SMSBs Capital and Liquidity Requirements Guideline, of January 2022, effective in April 2023:
  1. Category I: SMSBs reporting more than $10 billion in total assets;
  2. Category II: SMSBs reporting less than $10 billion in total assets, if they meet any of the following criteria:
     a. report greater than $100 million in total loans
     b. enter into interest rate or foreign exchange derivatives with a combined notional amount greater than 100 percent of total capital
     c. have any other types of derivative exposure
     d. have exposure to other off-balance sheet items greater than 100 percent of total capital;
  3. Category III: SMSBs reporting less than $10 billion in total assets that do not meet any of the criteria in “2.” These institutions may request OSFI to be in Category II, to use the capital and liquidity requirements for this Category.
- Subsidiaries of SMSBs are subject to the same capital and liquidity requirements as their parent institution. Some subsidiaries of SMSBs may be exempted from minimum liquidity requirements provided exemption criteria in section 1.2 of the LAR Guideline are met. Subsidiaries of D-SIBs are considered Category I for capital and liquidity requirements.
- The SMSBs guideline specifies which capital and liquidity requirement applies to Categories I, II, and III, with Annex 1 summarizing frameworks for the three categories.
- Category III SMSBs are subject to a Simplified Risk-Based Capital Ratio (SRBCR) defined in section 1.6.2 of Chapter 1 of the CAR Guideline. SRBCR minimum capital ratios are equivalent to regular ones for D-SIBs and other SMSBs; the denominator uses adjusted total assets plus RWA for operational risk under the Simplified Standardized Approach, making the denominator more conservative.
- Because leverage is somewhat incorporated into the SRBCR, Category III SMSBs are not subject to a separate minimum Pillar 1 leverage requirement and are not subject to the LCR, NSFR and NCCF requirements, but are subject to Operating Cash Flow Statement (OCFS) requirements per Chapter 5 of the LAR Guideline.
- Assessors consider the described framework broadly in line with Basel standards, except regarding new Chapters 8 and 9 on market risk; the market risk framework includes capital requirements for exposures in foreign exchange and commodities regardless of TB or BB classification.
- As of December 2023, according to data provided by OSFI, Category I SMSBs have zero market risk capital requirements; within SMSBs, only foreign banks in Categories II and III have market risk capital requirements, with market risk RWA representing around 2 percent of total RWA.
- Assessors suggest OSFI could implement a simple market risk capital requirement for non-D-SIBs currently exempted but with exposures to foreign currencies or commodities to simplify current case-by-case supervisory action.

### AC2 — Distribution of capital within banking groups and Solo TLAC
- OSFI’s CAR Guideline requires capital adequacy determination at parent-bank consolidated and sub-consolidated levels. Paragraph 4, Chapter 1 of CAR defines consolidated entity to include all subsidiaries except insurance subsidiaries.
- OSFI expects banks to hold capital within the consolidated group consistent with level and location of risk. OSFI obtains capital composition and requirement data of key sub-consolidated D-SIB subsidiaries and supervisory dashboards are available for supervisors; some subsidiaries are subject to Pillar 3.
- OSFI’s Parental Standalone TLAC Framework for D-SIBs (Solo TLAC) Guideline, effective November 1, 2023, aims to ensure non-viable D-SIBs have sufficient loss absorbing capacity on a stand-alone legal entity basis. Following two submissions of data since the guideline entered into force, OSFI is of the view that the banks have adequate capital.
- OSFI noted implementation of Solo TLAC expectations followed an informal framework in which some similar expectations had been in place for ten years.
- OSFI’s ICAAP Guideline (page 3) specifies that while an ICAAP should cover consolidated operations from the top-level regulated entity in Canada, OSFI expects capital planning to consider risks of foreign operations and availability of capital and assets in Canada to protect Canadian depositors; Canadian subsidiaries of foreign banks may borrow from consolidated group methodologies but must reflect their own circumstances.

### AC3
- EC2 describes the buffers implemented by OSFI and applicable to banks.

*Source: 4. Controls: an assessment of the effectiveness of oversight applied to the internal models.*

### Chapter 1, section 1.7 of the CAR Guideline establishes that banks are required to hold a CCB

### Chapter 1, section 1.7 of the CAR Guideline establishes that banks are required to hold a CCB

### Capital buffers, macroprudential tools, and calibration
- CCB and CCyB: Chapter 1, section 1.7 requires banks to hold a CCB and a CCyB. The intent is to increase institutions’ resilience going into a downturn and provide a mechanism for rebuilding capital during early recovery.
- Restoration measures when buffers drawn down (Paragraph 44):
  - Possible actions: reducing dividends or other discretionary payments on shares or other capital instruments, share buy-backs, discretionary staff bonus payments.
  - Institutions may choose to raise new capital from the private sector as an alternative to conserving internally generated capital.
  - Institutions should implement a capital restoration plan to rebuild buffers within a reasonable timeframe or, if breach expected to be corrected promptly, a plan providing assurance that the capital conservation buffer will be restored on a sustained basis.
  - The capital restoration plan should be discussed with OSFI as part of the capital planning process.
- CCyB purpose and Canadian practice:
  - “CCyB aims to ensure that banking sector capital requirements take account of the macro-financial environment... deployed when excess aggregate credit growth is judged to be associated with a build-up of system-wide risk...”
  - OSFI, in consultation with FISC, monitors credit growth and other indicators for system-wide risk build-up.
  - The CCyB has never been activated by the Canadian authorities.
- Current calibrations and related buffers:
  - The 2.5 percent CCB implemented by OSFI and applicable to all SMSBs is supplemented by the D-SIB Surcharge of 1 percent (considered an extension of the CCB applied to the six OSFI designated D-SIBs).
  - D-SIBs are also subject to the DSB. Following a 2022 review, the DSB’s range is between 0–4 percent of RWA and is applied equally to all D-SIBs.
  - As of October 2024, the DSB is set at 3.5 percent of RWA.
  - The DSB can be released at OSFI’s discretion; example: a decrease from 2.25 percent to 1 percent of RWA in March 2020 during COVID-19.
  - Breaches of the DSB do not attract automatic capital distribution restrictions but prompt an institution to prepare a capital restoration plan and other supervisory interventions as appropriate.
- Complementary capital and leverage framework:
  - OSFI implemented final Basel III reforms through guideline modifications effective February 1, 2023.
  - On February 12, 2025, OSFI announced the deferral of further increases to the Basel III standardized capital floors (“output floor”) until further notice; the output floor will remain at 67.5 percent and there is no clear timeline to implement the Basel III 72.5 percent capital floor for internal models.
  - Minimum TLAC requirements for D-SIBs set out in OSFI’s TLAC Guideline and prescribed by orders dated August 21, 2018, effective November 1, 2021.
  - TLAC levels are disclosed by banks in Pillar 3.

### Supervisory expectations and constraints on capital distributions
- Capital distribution constraints:
  - Constraints are imposed when capital levels fall within buffers’ conservation range; banks can continue business as normal while their capital levels fall within the buffers’ range as they experience losses.
- Supervisory imposition of higher capital targets:
  - OSFI imposes specific capital charges to D-SIBs and SMSBs mainly through idiosyncratic higher capital targets linked to macroeconomic factors or to observed deficiencies (internal controls, risk management, corporate governance).

### Assessment of Principle 16 and related findings
- Assessment: Compliant.
- Observations:
  - OSFI’s minimum capital requirements stipulated in section 1.6 of Chapter 1 of the CAR Guideline; supervisory targets expected to be equal to or greater than minimum capital ratios plus buffers per section 1.10.
  - Use of IRB by D-SIBs is sensitive given credit risk importance; issues in OSFI’s supervision of model outputs have impacted assessment of CPs15 and 17 but did not affect CP16 grading.
  - SMSBs are negligible in aggregate, holding 3 percent of Total Assets of supervised banks; assessors view that market risk capital requirements for SMSBs could be simplified and not triggered by individual supervisory action when trading activity is relevant for a specific bank.
- Recommendation (explicit):
  - Establish a simplified market risk capital requirement for non-D-SIBs that have exposures to foreign currencies or commodities. Rationale: international standards establish capital requirements for all exposures in foreign currencies and commodities regardless of whether the instrument is in the TB or BB; a simplified requirement would remove the need for specific and individual supervisory action where “trading activities are a large proportion of overall operations.”

### Credit risk supervision, governance, and OSFI guidance
- Regulatory/legal basis:
  - Sections 628, and 643 to 645 BA of the Act provide OSFI with information request, examination and access to records powers.
  - Section 465 of the Bank Act: directors must establish and the bank must adhere to investment and lending policies, standards and procedures that a reasonable and prudent person would apply.
  - Guideline B-1 Prudent Person Approach sets factors for senior management and boards in establishing policies.
- OSFI guidance and supervisory expectations for credit risk (selected list from source):
  - Guideline- IFRS 9 Financial Instruments and Disclosures
  - Guideline B-1 Prudent Person Approach
  - Guideline B-20 Residential mortgage underwriting practices and procedures (2017)
  - Advisory - Clarification on the Treatment of Innovative Real Estate Secured Lending Products under Guideline B-20 (June 2022)
  - Guideline - Large Exposure Limits (1994)
  - Guideline-Large Exposure Limits for Domestic Systemically Important Banks (2019)
  - Guideline E-2 Commercial Lending Criteria
  - Guideline-E-23 Enterprise-Wide Model Risk Management for Deposit-Taking Institutions (2017)
  - Guideline B-7 Derivatives Sound Practices (2014)
  - Guideline B-11 Pledging
  - Guideline B-4 Securities Lending Deposit-taking institutions -(1996)
  - Guideline E-22 Margin Requirements for Non-Centrally Cleared Derivatives (2020)
  - Guideline E-24 Settlement Risk in Foreign Exchange Transactions (2013)
  - Guideline B-3 Classification of Loans Guaranteed by a Parent of the Bank
  - Guideline B-5A Asset Securitization by Foreign Bank Branches

### Ongoing monitoring, supervisory reviews, and resource constraints
- Ongoing monitoring:
  - Quarterly credit risk monitoring by OSFI’s LS team includes meetings with CRO, Senior Risk Management and Chief Credit Risk Officers; regular returns and ad hoc information requests used to monitor exposures.
  - CRD within the RAH is responsible for ongoing monitoring and supervisory reviews on credit risk; CRD has 33 full-time employees and average tenure reduced from circa 5 years to 4.3 years.
  - CRD units: subject-matter units aligned to portfolios (mortgages, non-mortgage retail and ECL monitoring, corporate/commercial, CRE, and Model Risk); each unit has 4 or 5 people.
  - CRD monitoring frequency: units produce monitoring reports every 90 days; reports include standardized management information, detailed credit metrics, model outcomes, data inaccuracies and actionable conclusions.
- Model Risk unit and IRB monitoring:
  - Model Risk unit within CRD has 5 full-time employees (2 analysts and 2 senior specialists, there is a vacancy for the director's position).
  - Monitoring regime includes quarterly model monitoring (QMM) meetings with D-SIBs but, due to resource constraints, frequency is generally semi-annual.
  - Model Risk unit prepares a quarterly Model Vulnerability Dashboard (traffic lights) covering at least 65 portfolio models across 11 categories for the six large IRB banks.
  - LS teams annually receive CRO letters and internal audit positive assurance, list of approved capital models, and list of waivers/exemptions/migrations as part of CMAP guidance.
- Supervisory review planning and execution:
  - Reviews decided during annual supervisory planning, informed by ARO and institution-specific concerns.
  - ARO updated semi-annually and used to prioritize supervisory activity. For 2024–25 top risks include Real Estate Secured Lending and mortgages, Wholesale credit, Funding and liquidity risk and Integrity, Security and Foreign Interference.
  - Credit Risk Reviews (CRRs) scope: strategies and business plans, enterprise-wide exposure views, transaction-level file reviews to evidence underwriting, administration and monitoring, and file-level testing (sampling methodologies considered sound).
  - Supervisory review outputs: initial scope letter/data call, discovery meetings, on-site file review when scope allows, end-of-review meetings, supervisory letter sent in approximately 5 days, action plan expected in 30 days.

### Findings on IRB models and supervisory capacity
- IRB model reliance and vulnerabilities:
  - More than 90 percent of the RWAs of Canadian D-SIBs come from credit risk and almost all are calculated using IRB models.
  - OSFI approved more than 60 IRB models for the six D-SIBs (historically in early 2000s); guidance expects at least 80 percent of exposures of a banking group covered by an IRB model.
  - Canada’s historical loss data is “outstandingly benign”; OSFI has warned banks about over-reliance on benign historical data and required recalibrations and margins of conservatism for outlier banks.
- Supervisory resourcing and scope limitations:
  - CRD’s staff did not grow in the last five years while other departments expanded; CRD faces a resource constraint that forces efficiency and selectivity in supervisory reviews.
  - The resource constraint affects the ability to perform deep supervisory reviews and to evaluate banks’ models through deeper reviews; scoping of internal models’ reviews often assigns intensity levels (High, Medium, Low) reflecting resource optimization.
  - Assessors noted circa 30 supervisory reviews were provided, differing greatly in scope and depth; more frequent in-depth reviews of credit risk and model risk would strengthen long-term discipline.

### Methodologies, review frameworks, and supervisory judgments
- Supervisory frameworks:
  - CAR Guideline (2024) sets bank-wide credit risk management requirements for capital risk weighting (CAR-Chapter 4 and 5).
  - OSFI’s Supervisory Framework (2024) and internal assessment criteria provide approaches and checklists tailored by portfolio and depth (abridged/extended versions).
  - Credit lifecycle coverage: underwriting, evaluation, ongoing management for loans and investments including CCR.
- Model assessment frameworks:
  - Capital Models Assessment Framework (CMAP) and IRB Implementation Notes (multiple thematic notes) underpin supervisory reviews of internal models.
  - Supervisory reviews and model approval standards conceptualized in four broad categories framing capital model assessments (the MIOC framework).

*Source: Chapter 1, section 1.7 and related sections of the CAR Guideline, as presented in the provided PDF content.*

### 1.    Methodology: an assessment of the model's quantitative approaches to segment and

### 1.    Methodology: an assessment of the model's quantitative approaches to segment and measure risk.

### Methodology, Integration, Operations, Controls — scope and key considerations
- Methodology: an assessment of the model's quantitative approaches to segment and measure risk.
- Integration: an assessment of the model's integration into the institutions' risk management practices.
- Operations: an assessment of the model's implementation, application and monitoring in a production environment.
- Controls: an assessment of the effectiveness of oversight applied to internal models.
- The methodology reflects that IRB models’ outcomes are enormously influenced by methodological choices, assumptions, data quality, adequate maintenance, performance measuring, backtesting, statistical representativeness, risk differentiation, the number of grades or pools, time period selected for estimation of the PD long run or the LGD downturn, overlays, overrides policies, role of human judgement, rating assignment process, the inclusion or not of external data, truly independent and competent internal validation and assurances from internal audit, etc.

### Anecdotal supervisory findings and vulnerabilities
- Assessors found anecdotal evidence of opportunistic behaviour detected by OSFI in modelling choices that excluded for data quality reasons certain data of a past real estate downturn, improving estimations (the bank did not report this explicitly; OSFI spotted it in the model log data the banks submit quarterly).
- OSFI recommended caution to a bank regarding model changes that resulted in reduced RWA, given the current risk environment and the kind of risk environment prevailing in the data.
- OSFI found that banks were not proactive in reviewing model assumptions, limitations and adequacy of RWA, nor in incorporating early warning indicators (such as non-retail lending delinquency rates as an anticipated indicator of mortgage portfolio deterioration).
- Inspection of capital models is triggered by material changes and initial approval requests, and recently also by detection of outlier outcomes (certain banks had parameter estimations well below the average of their peers).
- Assessors reviewed several material change applications for IRB models; rejections occurred where models lacked fitness for extension to portfolios originated with different underwriting criteria and context.

### Supervisory adequacy and frequency concerns
- From documentation, when carried out, supervisory reviews of IRB models applying the MIOC methodologies were considered adequate and well-fitted for determining if approval conditions were complied with.
- Assessors consider supervisory review work is not as frequent as it should be if supervisory planning is based on risk, mainly due to:
  - The small size of the Model Risk unit and their onerous responsibilities (ongoing monitoring, assistance with other models of other types of risk...) makes proactive reviews (i.e., those not triggered by an initial approval or a material change approval) infrequent.
  - The absence of express guidance by OSFI on the definition of material changes to models. Each bank’s internal policies define what is a material change; banks notify OSFI only when changes are egregiously material (for example, extension of the model to a new portfolio or due to mergers and acquisitions), making material change reviews infrequent.

### EC2 — Board oversight and supervisory practices
- The supervisor determines that a bank’s board approves and regularly reviews the credit risk management strategy and significant policies for identifying, measuring, evaluating, monitoring, reporting and controlling or mitigating credit risk (including counterparty credit risk), consistent with risk appetite; and that the board oversees management to ensure implementation and integration into the bank’s overall risk management process.
- Description and findings re EC2:
  - OSFI observes Board and senior management activities through ongoing monitoring, presentations, reporting packages, frequent meetings and information requests.
  - Supervisors assess presence of prudent policies/processes/limits, compliance monitoring and reporting, appropriate approval levels (Board if enterprise-wide), implementation by senior management, and control/oversight by second and third lines of defence (risk management, internal validation, compliance and internal audit).
  - Supervisory practice determines approval and review of policies by the Board and effective implementation; effectiveness and adherence must be tested periodically to check reliability of bank’s information and practices.
  - Example: Board’s oversight of credit risk taken by a material subsidiary was challenged by OSFI; improvements in portfolio risk reporting and RAF indicators and limits were recommended.

### EC3 — Controlled credit risk environment requirements and supervisory findings
- EC3 requires that policies and processes establish an appropriate and properly controlled credit risk environment, covering:
  - (a) documented and effectively implemented strategy and sound policies/processes for assuming credit risk, without undue reliance on external credit assessments;
  - (b) well defined criteria and policies/processes for approving new exposures, renewing/refinancing exposures, and identifying appropriate approval authority;
  - (c) effective credit administration policies/processes including borrower ability/willingness analysis, monitoring of documentation/covenants/collateral and appropriate grading/classification;
  - (d) effective information systems for accurate and timely aggregation and reporting of credit risk exposures to board and senior management;
  - (e) prudent and appropriate credit limits consistent with risk appetite, profile and capital strength;
  - (f) exception tracking and reporting ensuring prompt action at appropriate senior levels; and
  - (g) effective controls around use of models to identify and measure credit risk and set limits (including data quality and validation procedures).
- Description and findings re EC3:
  - Supervisory CRRs verify underwriting strategy alignment with risk appetite and CAR Guideline due diligence requirements.
  - Supervisors detected implementation shortcomings: heavy reliance on the first line, lack of mechanisms for risk management to oversee risk taking, sparse/non-integrated portfolio reporting, reactive underwriting/monitoring, insufficient risk management expertise.
  - Renewing/refinancing and ECL provisioning/non-performing loans are examined; adherence to underwriting/renewal/refinancing criteria is tested in full scope CRR file reviews.
  - Examples of deficiencies found and recommended remediation: approval procedures not conforming with regulatory guidance, inadequate forbearance policies and deficient reporting/approval frameworks.
  - Credit administration: file reviews inspect documentation, covenant compliance, collateral security and rating/provisioning accuracy; examples of findings include excessively benign loan monitoring scorecard data, inconsistent statistical representativeness metrics, outdated property valuations, and non-reported exceptions.
  - Information systems: portfolio reporting and data quality issues found (incomplete data coverage, unclear ownership in data governance, accuracy and completeness problems).
  - Credit limits and exception reporting: deficiencies included no exception reporting to the Board, insufficient reporting on forbearance activities and limits, and files granted exceptions without procedure or justification.
  - Controls on credit risk model use: refer to EC1 detailed supervisory activities regarding credit risk models.

### EC4 — Monitoring total indebtedness and FX risk
- EC4 requires banks to have policies/processes to monitor total indebtedness of obligors and any risk factors that may result in default, including significant unhedged foreign exchange risk.
- Description and findings re EC4:
  - OSFI expects monitoring via effective aggregation at adjudication and regular (minimum annual) review of credit exposures with confirmation of credit needs/capacity.
  - OSFI assesses banks’ ability to aggregate borrower and connected credit exposures across the institution, including FX risk where applicable; CRD tests aggregation in CRRs for all credit types (retail and wholesale).
  - Banks use private credit bureaus (for example, Transunion and Equifax) to track total indebtedness and scoring indicators; OSFI has only recently purchased access to these private credit bureau services to assist supervision.
  - The B-20 Guideline requires verification of total indebtedness and payment obligations for Debt Service ratio calculations and sets expectations for debt serviceability metrics and income verification (including special treatment for borrowers relying on income from sources outside Canada).
  - Examples of supervisory activity: OSFI required prudent haircuts/estimations where income verification for foreign income in a newcomer program was challenging; OSFI recommended enhanced due diligence when foreign sources of income were used in underwriting.
  - FX lending is not common for Canadian banks; most lending is denominated in Canadian dollars.

### EC5 — Conflict-free credit decisions
- EC5 requires that banks make credit decisions free of conflicts of interest and on an arm’s length basis.
- Description and findings re EC5:
  - (Content ends at the EC5 heading in the provided source.)

*Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf*

### Part XI - Self-dealing of the Bank Act establishes rules around related party transactions. The

### Part XI - Self-dealing of the Bank Act establishes rules around related party transactions. The

### Related party regime and self-dealing
- The provisions define who are related parties and establish prohibited and permitted related party transactions, and any related limitations.
- The Related Party Transactions (Banks) Regulations describe prescribed related party transactions for foreign bank subsidiaries operating in Canada.
- CP20 contains more details and explanations on the deficiencies of the related party regime (referenced in source).

### Credit risk supervisory reviews and conflict of interest
- Credit risk supervisory reviews (see EC1) ascertain whether reporting lines and compensation structures could potentially compromise the independence of critical functions (for example, the existence of sales targets, profitability goals as performance metrics within the loan adjudication function).
- OSFI expects institutions to prevent conflict of interest and to operate on an arm’s length basis.
- Assessors’ review of supervisory files included examples where OSFI detected lack of arm’s length lending policies:
  - OSFI found during a credit risk review that the company of one of the directors was benefiting from non-arm’s length conditions; a remedial plan was sought and the bank corrected its policies.
  - Another bank had no special policies for staff loans; remedial action included submitting those loans to escalation of authority and special procedures for underwriting.

### EC6 — Board or senior management approval of major/specialty exposures
- EC6 requirement: the supervisor requires that the credit policy prescribes that major credit risk exposures exceeding a certain amount or percentage of the bank’s capital must be decided by the bank’s board or senior management; same for especially risky exposures or those not aligned with core business activities.
- Description and findings re EC6:
  - OSFI expects banks to maintain clear lending authorities requiring higher scrutiny and approval as exposure size and transaction risk increase, subject to adequate governance such as periodic review and effectiveness testing (see EC3).
  - OSFI does not explicitly prescribe thresholds for the authorization of major or specialty credit risk exposures to go to the Board or senior management.
  - OSFI does not expressly foresee in its regulatory guidance that the credit policies should have this kind of threshold.

### EC7 — Access to information and supervisory data requests
- EC7: The supervisor has full access to information in the credit and investment portfolios and to the bank officers involved in assuming, managing, controlling and reporting on credit risk.
- Description and findings re EC7:
  - Sections 628 to 644 of the Bank Act provide OSFI with full access to credit and investment information and to the bank officers responsible for any aspect of credit risk at the bank.
  - The CRD and the LSs receive as part of their quarterly ongoing monitoring a suite of regulatory returns on credit risk and additional information periodically (see EC1).
  - Supervisors often request ad hoc data with datapoints such as geographical breakdown, portfolio performance, forbearance data, Stages of IFRS 9, watchlist, delinquency days, PD, LGD, loan level data, granular information for monitoring ECL models (base case, downside and upside scenario outcomes or expert credit judgement amounts).
  - Pre-exam material for credit risk supervisory reviews may be very extensive and can include: scope description of policies and process, charts, all policy architecture, organizational structure, staff CVs, compensation, internal governance, limit setting and monitoring, RAF implementation, policy internal review process, loan review function (file level testing methodologies, quality assurance), adjudication framework, debt service calculation, collateral management and collections policies.

### Assessment of Principle 17 — Largely Compliant
- OSFI has established principles-based regulatory guidance for banks on credit risk that establish expectations on adequate credit risk management policies covering the full credit lifecycle (see EC1 and EC3) and processes embedded in a RAF subject to Board, senior management and control function oversight.
- OSFI’s supervisory approach and methodologies for credit risk are described as mature and sound. OSFI supervisors apply an appropriate Supervisory Framework (2024) and related credit risk assessment criteria, including orientating checklists and criteria to evaluate policies, procedures and practices.
- Different sets of assessment criteria are developed for each portfolio (for example, mortgages, wholesale lending, retail lending, commercial real estate), with an extended version for more in-depth supervisory reviews.
- CRD and ongoing monitoring:
  - The CRD within the RAH is responsible for ongoing monitoring of credit risk and supervisory reviews on credit risk.
  - CRD has 33 full-time employees.
  - CRD’s average tenure reduced from circa 5 years to 4.3 years.
  - CRD’s staff did not grow during the last five years like other OSFI departments; increases were focused on emerging risks, the second line of defense and non-financial risks.
  - CRD suffers from a resource constraint affecting planning of supervisory reviews and the ability to perform deep and targeted supervisory reviews.
  - OSFI’s budget is aligned with the cost-cutting initiatives of the Government of Canada, with the Minister of Finance ultimately approving OSFI’s budget; CRD capacities to carry out deep supervisory reviews are affected by resource constraints.
- Model risk and IRB models:
  - More than 80 percent of the RWA of Canadian D-SIBs come from credit risk and almost all of them are calculated using IRB models.
  - At least 80 percent of the exposures of a banking group should be covered by an IRB model as per regulatory guidance.
  - OSFI approved for use more than 60 IRB models for the six D-SIBs.
  - The Model Risk unit within the Credit Risk Department has 5 full-time employees (2 analysts and 2 senior specialists, there is a vacancy for the director’s position).
  - When carried out, supervisory reviews of IRB models applying the MIOC methodologies were assessed as adequate.
  - Canada’s historical losses data are described as outstandingly benign and underpin IRB model calculations; OSFI has warned banks about over-reliance on benign time periods.
  - Certain banks identified as outliers with consistently lower risk parameters (PD, LGD) than peers.
- Constraints affecting model supervision and material change reviews:
  - The small size of the Model Risk unit and their responsibilities make proactive reviews infrequent.
  - Absence of express guidance by OSFI on the definition of material changes to models; each bank’s internal policies define material change and notification thresholds are at banks’ discretion.
  - Material change reviews are infrequent; banks notify changes as material only when egregiously material (for example, extension of the model to a new portfolio or due to mergers and acquisitions).
  - OSFI does not explicitly establish a supervisory expectation for banks to set thresholds for authorization of major or specialty credit risk exposures to go to the Board or senior management, as required by EC6.

### Recommendations (from the source)
- Reinforce the credit risk department, especially with respect to model specialists.
- Issue guidance on minimum thresholds for material changes of IRB models. Notification thresholds should not be at the discretion of the banks.
- Foster downturn preparation challenging model outcomes (ECL and capital) based on benign historical data. In the case of ECL, if accounting standards do not allow for prudent adjustments, OSFI’s prudent ECL estimates (which reflect timely recognition of expected losses) may be reflected as ad hoc CET1 deductions.
- The supervisor should require that the bank’s credit policies prescribe that major credit risk exposures exceeding a certain amount or percentage of the bank’s capital, exposures that are especially risky or otherwise not in line with the mainstream of the bank’s activities, are to be decided by the bank’s Board or senior management.
- As recommended in CP9, increase the weight of credit risk on-site supervisory reviews in the mix of supervisory activities to limit reliance on banks’ information and risk measurement methodologies. More frequent deep reviews would enable a more effective application of OSFI’s supervisory framework and assessment methodologies and a long-term discipline in the management and measurement of credit risk.
- As recommended in CP15, increase the frequency of credit risk model reviews and include a reliability verification component in most on-site reviews (for example, a file review walkthrough to check model outcomes, human intervention, rating assignment, data quality, missing treatments, overrides) to establish the expectation that OSFI relies only in a limited way on banks’ information.
- Tie findings of model reviews to quantitative impact on capital (margins of conservatism, add-ons), including qualitative findings (for example, those on control functions, model governance).

### Principle 18 and EC1 — Problem exposures, provisions and reserves
- Principle 18: The supervisor determines that banks have adequate policies and processes for early identification and management of problem exposures and the maintenance of adequate provisions and reserves.
- EC1 essential criteria summary:
  - Laws, regulations or the supervisor require banks to formulate policies, processes and methodologies for grading, classifying and monitoring all credit exposures (including off-balance sheet and forborne exposures) and identifying and managing problem exposures.
  - Regular reviews by banks of their credit exposures are required (at individual or portfolio level for homogeneous characteristics) to ensure appropriate exposure classification, detection of deteriorating exposures and timely identification of problem exposures.
- Description and findings re EC1:
  - Classification of exposures follows the IFRS 9 expected credit losses framework. OSFI’s Guideline- IFRS 9 Financial Instruments and Disclosures establishes supervisory expectations.
  - OSFI receives quarterly credit risk information and balance sheet and performance information by way of supervisory returns for all banks.
  - For IRB institutions, wholesale borrowers and facilities must have their ratings refreshed on at least an annual basis.
  - For retail exposures, the bank must review the loss characteristics and delinquency status of each identified pool at least on an annual basis.
  - According to Principle 3 of OSFI Guideline ifrs-9-financial-instruments-disclosures, banks should have a credit risk rating process to appropriately group lending exposures on the basis of shared credit risk characteristics.
  - Quoted expectations from the Guideline include:
    1. The credit risk rating process should include an independent review function.
    2. The credit risk grade on initial recognition may be based on criteria including product type, terms and conditions, collateral type and amount, borrower characteristics and geography, and may change due to factors such as industry outlook, business growth rates, consumer sentiment and changes in economic forecasts (such as interest rates, unemployment rates and commodity prices) as well as weaknesses in underwriting identified after initial recognition.
    3. The credit risk rating system should capture all lending exposures to allow appropriate differentiation and grouping and enable identification of migration of credit risk and significant changes in credit risk.
    4. A bank should clearly define each credit risk grade and designate personnel responsible for design, implementation, operation and performance of the system as well as those responsible for periodic testing and validation (i.e. the independent review function).

*Source: 1canea2025007-source-pdf - Part XI - Self-dealing of the Bank Act establishes rules around related party transactions. The*

### 5. Credit risk grades should be reviewed whenever relevant new information is received or a

### 5. Credit risk grades should be reviewed whenever relevant new information is received or a bank's expectation of credit risk has changed

### Review frequency and timeliness of ECL updates
- Credit risk grades assigned should receive a periodic formal review (for example, at least annually or more frequently if required in a jurisdiction) to reasonably ensure that those grades are accurate and up to date.
- Credit risk grades for individually assessed lending exposures that are higher-risk or credit-impaired should be reviewed more frequently than annually.
- ECL estimates must be updated on a timely basis to reflect changes in credit risk grades for either groups of exposures or individual exposures.

### Supervisory review practices and problem loan oversight (references to CP17, EC1)
- CRRs include reviewing and assessing the bank’s established policies and procedures around problem recognition and remedial loan management.
- OSFI expectations include regular, frequent review of problem loans, and appropriate reporting to senior management and the Board.
- File review components in supervisory reviews assess:
  - effectiveness of policies in practice,
  - appropriateness of risk ratings,
  - adequacy of provisions.

### EC2 — Policies, processes and methodologies for provisions and write-offs
- Laws, regulations or the supervisor require banks to formulate policies, processes and methodologies for consistently establishing provisions and ensuring appropriate and robust provisioning levels.
- Laws, regulations or the supervisor require banks to formulate policies and processes for writing off problem exposures where recovery is unlikely or where the exposures have very little recovery value.

Description and findings re EC2 (OSFI Guideline — IFRS 9 Financial Instruments and Disclosures, paragraph 30)
- A bank should adopt and adhere to written policies and procedures detailing the credit risk systems and controls and senior management roles and responsibilities. Robust methodologies generally will:
  - a. include a robust process to know the level, nature and drivers of credit risk upon initial recognition and ensure subsequent changes can be identified and quantified;
  - b. include criteria to duly consider the impact of forward-looking information, including macroeconomic factors; identify factors that affect repayment (borrower incentives, willingness or ability, or lending terms); economic factors (such as unemployment rates or occupancy rates) must be relevant and may be international, national, regional or local;
  - c. include, for collectively evaluated exposures, a description of the basis for creating groups of portfolios with shared credit risk characteristics;
  - d. identify and document the ECL assessment and measurement methods (such as a loss rate method, probability of default (PD)/loss-given-default (LGD) method, or another method) to be applied to each exposure or portfolio;
  - e. document reasons why the selected method is appropriate and be able to explain rationale and quantitative impacts of changes in measurement approach;
  - f. document inputs, data and assumptions used in the allowance estimation process (such as historical loss rates, PD/LGD estimates and economic forecasts), how life of an exposure is determined, time period for historical loss evaluation, and any adjustments for differences between historical and current/forecasted conditions;
  - g. include a process for evaluating appropriateness of significant inputs and assumptions; basis for inputs and assumptions should generally be consistent period to period and rationale for changes documented;
  - h. identify situations leading to changes in ECL measurement methods, inputs or assumptions (for example, moving from collective PD/LGD to individual discounted cash flow upon borrower-specific information);
  - i. consider relevant internal and external factors affecting ECL estimates, such as underwriting standards at origination and changes in industry, geographical, economic and political factors;
  - j. address how ECL estimates are determined (for example, historical loss rates or migration analysis as starting point, adjusted for current and expected conditions); a bank should have an unbiased view of uncertainty and risks when estimating ECL;
  - k. identify factors considered when establishing historical time periods; a bank should maintain sufficient historical loss data (ideally over at least one full credit cycle);
  - l. determine extent to which collateral and other credit risk mitigants affects ECL;
  - m. outline policies and procedures on write-offs and recoveries;
  - n. require that analyses, estimates, reviews and other tasks/processes are performed by competent and well-trained personnel and validated by personnel independent of lending activities; documentation should include clear explanations;
  - o. document methods used to validate models for ECL measurement (for example, backtests);
  - p. ensure ECL estimates appropriately incorporate forward-looking information, including macroeconomic factors, that has not already been factored into individual allowances; experienced credit judgment may be required;
  - q. require a process to assess the overall adequacy of allowances in accordance with relevant accounting requirements.

Supervisory findings and practice under EC2
- Assessors observed a credit risk supervisory review showing banks’ IFRS9 methodologies were consistently underestimating provisions due to inadequate risk drivers, deficiencies in back testing and lack of responsiveness to macroeconomic deterioration; OSFI expected remediation and increased interim expert judgment provisions.
- A cross-sector review (including several small and medium-sized banks) on IFRS 9 impairment for commercial real estate and mortgages focused on stage migration, modelling approaches (input data, methodology, human judgement, macro scenarios) and governance and validation.

### EC3 — Board approval and oversight of classification and provisioning policies
- The supervisor determines that the bank’s board approves and regularly reviews significant policies for classifying exposures, determining provisions and managing problem exposures and write-offs, and that the board oversees management to ensure effective implementation and integration into overall risk management.

Description and findings re EC3
- Principle 1 of OSFI’s Guideline — IFRS 9: board of directors and senior management are responsible for appropriate credit risk assessment processes and effective internal controls to determine provisions consistently with policies, accounting framework and supervisory guidance.
- Paragraph 39 (senior management oversight) lists fact patterns potentially indicative of inadequate ECL estimates, including:
  - a. granting credit based on fragile income streams or with no/limited verification;
  - b. high debt service requirements relative to borrower cash flows;
  - c. flexible repayment schedules (payment vacations, interest-only, negative amortization);
  - d. lending amounts equal to or exceeding property value or failing to provide adequate collateral margin;
  - e. undue increases in restructurings/modifications due to borrower financial difficulties or competitive pressures;
  - f. circumvention of classification and rating requirements, including rescheduling, refinancing or reclassification;
  - g. undue increases in volume of credit relative to market peers;
  - h. increasing volume and severity of delinquent, low-quality and impaired credit.
- CRRs review bank policies/procedures around problem recognition and remedial loan management; OSFI expects regular review and reporting to senior management and the Board.

### EC4 — Adequacy of provisioning and independent validation
- The supervisor determines banks have adequate policies, processes, methodologies and organizational resources for establishing provisions and write-offs; measurement methodologies appropriate to ensure timeliness and realistic recovery expectations; and that provisions/write-off methodologies are subject to effective review and validation by a function independent of risk-taking.

Description and findings re EC4
- OSFI’s Guideline expects banks to have policies, processes, methodologies and resources for establishing provisions and write-offs (see EC2).
- Assessors flagged risks from the benign dataset used to estimate IFRS 9 provisions given long-standing stability of Canadian banking sector.
- Prevailing interpretation of IFRS9 concept of “lifetime losses” for Stage 2 exposures subject to a SICR may understate risk due to contractual mortgage maturities (typically 3–5 years) versus real maturity (20 or 30 years); SICR borrowers may remain with bank for real maturity, raising odds that SICR loans stay on balance sheet for decades.
- OSFI monitors provisioning levels leveraging peer comparisons and risk-adjusted metrics; CRD specialists monitor provisions evolution, stage migration and non-performing amounts.
- OSFI developed an internal guide for line supervisors to challenge bank management claims on root causes of provisions evolution, focusing on performing loans expected credit losses.
- OSFI conducts periodic examinations and supervisory reviews on provisioning and write-offs, including:
  - A D-SIB cross-sector review of IFRS9 implementation;
  - A broader cross-sector review on provisioning methodologies for RESL and CRE conducted in 2024;
  - Examinations of provisioning approaches within broader credit risk reviews;
  - Regular reviews of internal and external auditors’ assessment of FI’s IFRS9 process.

### EC5 — Policies, processes and resources for identifying and managing problem exposures
- The supervisor determines banks have adequate policies, processes and organizational resources for:
  - (a) reviewing and classifying exposures;
  - (b) early identification of deteriorating exposures;
  - (c) ongoing oversight of problem exposures;
  - (d) collecting past due obligations.

Description and findings re EC5
- OSFI’s regulatory guidance and supervisory processes on these topics are discussed in CP17, EC1.
- Assessors examined evidence from CRRs assessing adequacy of policies, procedures, and scalable organizational resources for early identification, on-going oversight, and loan workout/collection.
- File review results (when included) support assessment and test appropriateness of loan classification.

### EC6 — Regular access to detailed classification, collateral, provisions and write-off information
- The supervisor obtains information regularly and in relevant detail or has full access to information concerning classification of exposures, collateral and other risk mitigants, provisions and write-offs, and requires banks to have adequate documentation to support classification and provisioning.

Description and findings re EC6
- OSFI’s LSs’ teams and CRD obtain regular, detailed information (including regulatory returns) and have full access to classification, collateral, mitigants, provisions and write-offs.
- Guideline — IFRS 9 requires analyses, estimates, reviews and other inputs/outputs to be performed by competent personnel and validated by personnel independent of lending activities; documentation should clearly explain analyses and methods used to validate models for ECL.
- B-20 Guideline (loan documentation expectations) lists documentation items to be maintained at origination and updated on refinancing, including: description of loan purpose; employment status and verification of income; debt service ratio calculations and verification; LTV ratio, property valuation and appraisal documentation; credit bureau reports; documentation verifying source of down payment; purchase and sale agreements; explanation of mitigating criteria for higher credit risk; property insurance agreements; rationale for decision; record from mortgage insurer validating commitment to insure where applicable.
- FRFIs should update borrower and property analysis periodically and review factors if borrower condition or property risk changes materially.
- OSFI has loan level data enabling peer comparisons to identify classification outliers.

### EC7 — Supervisor assessment of appropriateness of classification and provisioning and remedial powers
- The supervisor assesses whether banks’ classification of exposures is appropriate and provisioning levels adequate for prudential purposes, and evaluates treatment of exposures to identify material circumvention (for example, forbearance).
- If policies, processes or methodologies are inadequate, or if classifications/provisions are inaccurate or inadequate, the supervisor can require a bank to:
  - (a) revise policies, processes or methodologies for classification and provisioning;
  - (b) adjust classifications of exposures;
  - (c) increase levels of provisioning, reserves or capital;
  - (d) impose other remedial measures if necessary.
- Assessments may be conducted by external experts, with supervisor review of the external experts’ work.

Description and findings re EC7
- OSFI’s supervisory reviews on credit risk (see CP17, EC1) have covered classification of exposures, identification of material circumvention (focus on forbearance) and provisioning inaccuracies or understatement.
- Guideline — IFRS 9 paragraph 38 requires accounting policies and allowance methodology to address:
  - a. restructurings/modifications: methodology should robustly assess and measure ECL such that allowance reflects collectability of substance of restructured exposure; restructurings should not automatically be assumed to decrease credit risk; repayment performance should be demonstrated over a reasonable period before credit risk is considered to have decreased; lending staff should promptly notify accounting when exposures are restructured/modified and maintain communication for complex cases;
  - b. purchased or originated credit-impaired lending exposures: cash flow estimates should be reviewed each reporting period, updated as necessary, properly supported, documented and approved by senior management.
- Assessors reviewed supervisory files where OSFI examined forbearance policies, performed file reviews to verify provisioning practices and Stage migration, assessed ECL model choices and assumptions (risk driver selection, macro adjustment variables), model performance (backtesting, management overlay) and governance (validation).
- An IFRS 9 cross-sector review produced findings on classification migration, indicators determining classification, delays in recognition of Stage 2 and uneven definitions of indicators in banks’ internal policies.

### EC8 — Valuation of risk mitigants and collateral
- The supervisor requires banks to have appropriate mechanisms for regularly assessing the value of risk mitigants, including guarantees, credit derivatives and collateral.
- The valuation of collateral should reflect net realizable value, considering prevailing market conditions and time required for realization.

Description and findings re EC8 (B-20 Guideline — Principle 4)
- FRFIs should have sound collateral management and appraisal processes; valuation should be risk-based and use a combination of valuation tools: on-site inspections, third-party appraisals and/or automated valuation tools.
- On-site inspections should validate occupancy, condition and existence of the property.
- Third-party appraisals should be prepared by designated, licensed or certified appraisers independent from acquisition/loan decision process.
- Automated valuation tools should be monitored for ongoing effectiveness and controls should ensure appropriate use by lending officers.
- FRFIs should not rely on a single valuation method and should implement frameworks to challenge assumptions and methodologies; more comprehensive valuation for higher-risk transactions (high LTV, illiquid properties, rapid price increases).
- Valuations should be realistic, substantiated and supportable to reflect current price level and property’s function as collateral over mortgage term; legal enforceability of claim on collateral should be ensured or title insurance obtained.
- FRFIs should impose contractual terms securing full protection under applicable law and maintain action plans for borrower default covering likely recourses, parties against whom recourses may be exercised, and strategies for exercising options prudentially.
- OSFI expects regular updating of valuations of guarantees, credit derivatives and/or collateral; effectiveness tested in credit file reviews.
- Lack of updating of property valuations and related provisions (through LGDs) was noted for several banks in a cross-sector review.

### EC9 — Criteria for problem, non-performing, reclassification and forborne exposures
- Laws, regulations or the supervisor establish criteria for an exposure to be:
  - (a) identified as a problem exposure;
  - (b) identified as non-performing (exposures where full repayment is unlikely or which are 90 days past due for a material amount, or defaulted exposures under either the Basel Framework or the applicable prudential regulation, or credit-impaired exposures according to the applicable accounting framework);
  - (c) reclassified as performing (counterparty has no material exposure more than 90 days past due, repayments have been made when due over a continuous repayment period, situation has improved so full repayment is likely in accordance with contractual terms, and exposure is no longer defaulted or impaired);
  - (d) classified as a forborne exposure.

Description and findings re EC9
- OSFI uses IFRS 9 concepts and definitions; some are open-ended allowing varying accounting policies across reporting entities.
- Exposures in Stage 2 and Stage 3 will be considered problem loans in Canada in an informal way since a formal definition is not provided.
- Non-performing exposures in Canada’s capital adequacy framework follow verbatim the Basel definition (see Section 265 CAR Guideline).
- Stage 3 of IFRS 9 will be the accounting framework indicator of non-performing exposures.
- OSFI explicitly recommends banks align capital and accounting definitions of default (use same temporal thresholds and unlikeliness to pay indicators).
- Guideline — IFRS 9 paragraph 91: “IFRS 9 does not directly define default, but requires entities to define default in a manner consistent with that used for internal credit risk management. IFRS 9, paragraph B5.5.37, also includes a rebuttable presumption that default does not occur later than 90 days past due. OSFI recommends that the definition of default adopted for accounting purposes is guided by the definition used for regulatory purposes.”

*Source: Excerpt from OSFI-related supervisory findings and Guideline — IFRS 9 Financial Instruments and Disclosures (as presented in the supplied content).*

### Chapter 6 of OSFI's Capital Adequacy Requirements guideline (paragraph 452 of the Basel

### Chapter 6 of OSFI's Capital Adequacy Requirements guideline (paragraph 452 of the Basel capital framework)

### IFRS 9 default indicators and banks’ internal definitions
- Chapter 6 includes both:
  - a qualitative criterion by which "[t]he bank considers that the obligor is unlikely to pay its credit obligations to the banking group in full, without recourse by the bank to actions such as realizing security (if held)" ("unlikeliness to pay" events);
  - an objective indicator where "[t]he obligor is past due more than 90 days on any material credit obligation to the banking group,” equivalent to the rebuttable presumption in IFRS 9, paragraph B5.5.37.
- Banks define key concepts and terms in their internal provisioning or credit risk policies; OSFI uses IFRS 9 concepts and definitions but some are open-ended and allow for varying accounting policies across reporting entities.

### OSFI supervisory focus on RESL, forbearance, and provisioning
- OSFI is more prescriptive with RESL lending through underwriting limits:
  - portfolio maximum average Loan To Income ratio (LTI);
  - origination Minimum Qualifying Rate (MQR) — described as "a sort of sensitivity test to interest rate changes that the borrowers payment capacity must resist".
- OSFI issued a letter to the banks on RESL forbearance on March 2024 with recommendations on timely recognition of expected and unexpected losses due to account vulnerabilities or adverse shifts in the risk environment.
- Supervisory activity:
  - intense monitoring of the evolution of IFRS 9 provisions;
  - a cross-sector review on expected credit losses;
  - several supervisory reviews and full-scope and targeted examinations that include verificative file review activities.
- Observed practice: most Canadian banks do not consider the granting of forbearance measures to be a SICR indicator; policy is typically to re-assess the borrower’s risk, so forborne loans usually continue being in Stage 1.
- Risk noted: expectations on cure periods were often not communicated or left excessive leeway, potentially allowing delinquency concealment and circumvention of accounting provisions.

### Findings on supervisory capacity and data usage (EC10, EC11, EC12)
- EC10 (board information on credit portfolio): OSFI oversees that banks provide problem account reporting to senior management and the board, including:
  - summary results of the latest credit exposure review process;
  - comparative trends in the overall quality of problem exposures;
  - measurements of any existing or anticipated deterioration in exposure quality and losses expected to be realized.
- EC11 (individual assessment for significant exposures):
  - CAR Guideline Chapter 5, paragraph 238 requires ratings refreshed at least on an annual basis and more frequent review for higher risk or problem exposures; banks must initiate a new rating if material information comes to light.
  - Regulatory retail exposures must comply with CAR Guideline Chapter 5, paragraph 83: "low value of individual exposures—the maximum aggregated retail exposure to one counterparty cannot exceed an absolute threshold of CAD $1.50 million."
  - OSFI expects, at a minimum, all individual non-retail exposure risk ratings be assessed annually and impaired exposures be assessed for an individual allowance.
- EC12 (system-wide trends, concentrations, adequacy of provisions):
  - OSFI receives granular data on watchlist, stage 1, 2, 3, impaired loans and ECLs; data used for quarterly monitoring and industry benchmarking.
  - Transaction-level data used to compare practices (e.g., PD assignment, sensitivity to borrower characteristics).
  - The Strategy, Risk and Governance sector’s Applied Research and Analytics division provides system-wide trend insights (housing market, mortgage lending, commercial real estate, private credit).
  - CRD specialists monitor provisions, stage migration and non-performing amounts and produce ECL monitoring reports decomposing changes (forward looking information, expert credit judgment, effect of scenarios, raw model results).
- Assessment of Principle 18: Compliant. OSFI is proficient at exploring problem asset trends and concentrations and provides forward-looking insights.

### Specific concerns about lifetime loss estimation and contractual maturity
- Prevailing interpretation: "lifetime losses" for Stage 2 exposures subject to a SICR are often estimated using contractual maturity, which in Canadian mortgages is typically 3–5 years despite real payment periods of 20 or 30 years.
- Concern: borrowers subject to SICR are less able to refinance or move, increasing the probability the loan remains on the bank’s balance sheet for the full real maturity; thus lifetime loss estimation based on short contractual maturity may underestimate risk.
- Recommendation: lifetime losses for RESL loans may have to be estimated during a much longer horizon (equivalent to the real payment period of the loan, irrespective of the shorter contractual maturity).

### Risks from forbearance and cure-period practices
- Forbearance is identified as an indicator of increased credit risk and a weak point for accurate and reliable reporting; historically used globally to mask delinquency and asset quality deterioration.
- Banks that generally provide reliable information may become prone to delinquency concealment when under stress.
- The assessors consider OSFI should prescribe minimum conservative cure periods to reduce bank discretion and limit circumvention of provisioning rules while retaining principles-based approach to impose higher standards based on risk profile.

### Recommendations (explicit)
- OSFI should define in its regulatory guidance the main concepts of the provisioning framework in a uniform way to increase comparability and prevent circumvention of provisioning rules. In particular:
  - OSFI should define forbearance with reference to maximum quantitative threshold of write-off and extensions granted to the borrower ("generous concessions should be deemed as presumptive of forbearance instead of a modification or renovation with no added credit risk").
  - OSFI should establish a minimum cure period for Stage improvement (especially when the loan was flagged as forborne).
  - OSFI should establish a more exigent minimum supervisory expectation for banks’ internal policies on SICR to promote a timely recognition of expected credit losses (for example, forbearance should be considered a SICR indicator difficult to rebut).
  - OSFI should provide guidance on unlikeliness to pay indicators for Stage 3.
  - OSFI may retain a principles-based guidance and require more during supervisory activities than what is in the definition to banks (if it is commensurate with their systemic importance, risk profile...), but the uniform minimum helps anchoring practices at a minimum prudent level and reduces discretion and the risk of circumvention.
- Lifetime losses for RESL loans may have to be estimated during a much longer horizon (equivalent to the real payment period of the loan, irrespective of the shorter contractual maturity). OSFI should study this issue and adopt opportune measures for the banks to have adequate provisioning levels in this respect.
- As recommended in CP17, OSFI should foster downturn preparation by challenging model outcomes (ECL and capital) based on benign historical data. If accounting standards do not allow for prudent adjustments in ECL, OSFI’s prudent ECL estimates (which reflect timely recognition of expected losses) may be reflected as ad hoc CET1 deductions.

*Source: Chapter 6 of OSFI's Capital Adequacy Requirements guideline (paragraph 452 of the Basel capital framework), material provided in the IMF source PDF.*

### Section 465 (General Constraints on Investments) of the Bank Act states that “the directors of

### Section 465 (General Constraints on Investments) and OSFI Guidance on Concentration and Large Exposures

### Legal and statutory framework
- Section 465 of the Bank Act: “the directors of a bank shall establish, and the bank shall adhere to investment and lending policies, standards and procedures that a reasonable and prudent person would apply in respect of a portfolio of investments and loans to avoid undue risk of loss and obtain a reasonable return.”
- Section 645 of the Bank Act: Superintendent may order a bank to “cease or refrain from committing” an act that is “unsafe or unsound” and “perform such acts as in the opinion of the Superintendent are necessary to remedy the situation.”
- Section 467 of the Bank Act: Governor in Council may make regulations limiting loans to persons or connected persons, and may specify how to determine connection.

### OSFI guidelines and supervisory expectations
- Guideline B-1 Prudent Person Approach (January 1993):
  - Expectation for written investment and lending policies.
  - Establish limits on exposure to a person or group of associated persons from on-balance sheet and off-balance sheet items.
  - Establish limits where applicable on exposures to industries and geographic regions.
  - Maintain readily available portfolio information (asset quality and concentration).
- Guideline Large Exposure Limits (1994, applicable to non-D-SIBs):
  - Defines exposure criteria and risk management expectations, including management information and control systems.
  - Total exposure to any connection is measured as a percentage of total capital, with the limit set at 25 percent.
  - Banks should establish lower internal limits; 25 percent regulatory limit to be used only on an exceptional basis.
  - Higher limits, up to 100 percent of total capital, are applicable to subsidiaries of banks in Canada under certain conditions.
- Guideline B-2 Large Exposure Limits for D-SIBs (November, 2019):
  - Defines “exposure” as all on-and off-balance sheet exposure in both banking and trading books, and instruments with CCR.
  - Aggregation rules for connected exposures; defines common risk through control relationship and economic interdependence.
  - Limit to a counterparty or group of connected counterparties is 25 percent of banks’ Tier 1 capital.
  - Limit of 15 percent for G-SIBs’ exposures to another G-SIB (aligned with Basel standard).
- Guideline E-18 Stress Testing:
  - Requires stress testing programs to consider risk concentrations arising directly from risk-taking and indirectly from mitigation actions.
- CAR Guideline (Chapters 4 and 5):
  - Expectations to establish strict lending requirements and conservative financial policies, including risk concentration limits (per country, sector, individual exposure and credit category) and a large exposures framework.
  - Identify and control concentration risk in credit risk mitigation and its interaction with overall credit risk profile.
  - Identify and aggregate similar risk exposures across firm and legal entities, banking or trading book, on and off-balance sheet.
  - Monitor CCR, particularly concentrations in trades or securities held as collateral.
- Guideline E-19 ICAAP:
  - Banks to establish bank-specific ICAAP and discuss concentration risk issues; comprehensive assessment of credit risk including large exposures and concentrations.
- Guideline Liquidity Adequacy Requirements (LAR):
  - Expectations for banks to assess concentration of funding sources.
- Corporate Governance Guideline:
  - RAFs should contain a risk appetite statement and risk limits, which may include line of business or product level limits such as concentration limits.

### Large exposure limits, scope and reporting
- Regulatory and internal limits:
  - D-SIBs: 25 percent of Tier 1 capital per counterparty or group of connected counterparties (Guideline B-2).
  - G-SIBs: 15 percent for exposures to another G-SIB.
  - Non-D-SIBs / SMSBs: 25 percent of total capital limit under 1994 guideline; Canadian subsidiary of a foreign bank can have exposure up to 100 percent of the subsidiary’s total capital under conditions in the 1994 guideline.
- Reporting requirements:
  - D-SIBs must submit quarterly Large Exposures Return and report exposure values before and after credit risk mitigation for:
    - All large exposures (equal or above 10 percent of Tier 1 Capital);
    - All exposures that would be large in the absence of risk mitigation;
    - All exempted exposures as defined by the guideline;
    - The 20 largest exposures to counterparties subject to large exposure limits.
  - D-SIBs also submit a quarterly data call containing all wholesale connections with exposure above $10,000,000 CAD.
  - SMSBs (holding 4 percent of Total Assets of OSFI-regulated banks, as of October 2024) are not subject to the 2019 Large Exposure Limits for D-SIBs and do not report large exposures to OSFI.

### Data aggregation, monitoring and supervisory practices
- OSFI supervisory monitoring:
  - Supervisory dashboards provide facility-level credit portfolio information and allow views by sector, geography, borrower and other perspectives.
  - A specific dashboard for CRE launched in February 2024; development underway for other areas.
  - Quarterly risk monitoring across D-SIBs and selected smaller deposit-taking institutions includes meetings with management and ongoing data calls.
  - Ad hoc requests for aggregate exposures to single names/connections or industries of concern provide evidence of banks’ ability to collect and report exposures timely.
  - Supervisory reviews include sample file reviews testing identification and active management of connected exposures.
  - When information system issues are identified, supervisors request clarifications and issue supervisory letters with remediation expectations and follow-up until remediation.
- OSFI credit risk reviews:
  - Include assessment of ability to identify and aggregate credit risk exposures to single counterparties or connections, covering on-and off-balance sheet items and instruments giving rise to CCR.
  - Assess senior management reporting on concentration risk, compliance with board-approved concentration limits, periodic board review of limits, and escalation/resolution of limit breaches.
  - Assess processes for establishing and monitoring limits across credit, market and operational risks and metrics (geography, industry, product type).
  - Expectation that risk management maintains independent processes to identify, monitor and control concentrations.

### Definitions and aggregation of connected counterparties
- Connected counterparties criteria (from guidelines and supervisory practice):
  - Two or more natural or legal persons deemed a group of connected counterparties if at least one of:
    - (a) Control relationship: one counterparty, directly or indirectly, has control over the other(s).
    - (b) Economic interdependence: if one counterparty experiences financial problems, the other(s) would likely encounter financial difficulties.
  - Guidelines specify indicators such as “expected source of repayment,” belonging to a “corporate group,” and “material financial interdependence.”
  - Guideline B-2 (2019) paragraphs 64–73 detail minimum conditions for assessing control relationship and economic interdependence and grant OSFI discretion to require aggregation where exposures constitute a common risk.
- Supervisory testing and examples:
  - Supervisory work identified cases such as inaccurate aggregation of residential mortgage exposure to reflect full exposure to a single borrower, and a study assessing aggregation of exposures to a very big Canadian corporation with activities in different economic areas.

### Evaluation against Core Principles (selected ECs) and findings
- EC2 (data aggregation and timely identification of concentrations):
  - OSFI’s framework and supervisory reviews test banks’ abilities; frequent ad hoc requests and sample file reviews provide evidence of timely aggregation and reporting capabilities. Supervisory follow-up on remediation documented.
- EC3 (thresholds, communication, and board reporting):
  - OSFI assesses senior management reporting, board-approved limits, regular board review, and escalation of breaches. Supervisory reviews evaluate processes for establishing and monitoring limits across risk types and metrics.
- EC4 (information to review concentrations):
  - D-SIB quarterly Large Exposures Return and quarterly data call of wholesale connections > $10,000,000 CAD; supervisory dashboards and ad hoc requests support concentration assessments. CRE dashboard launched February 2024.
- EC5 (definition and supervisory discretion on connected counterparties):
  - Guideline B-2 (2019) and 1994 guideline provide definitions and indicators; Section 645 and Section 467 of the Bank Act provide supervisory powers and regulatory instrument to define connections on a case-by-case basis where necessary.
- EC6 (prudent requirements and measurement of exposures):
  - Guideline B-2 requires consideration of all on- and off-balance sheet exposures in banking and trading books and instruments with CCR for aggregate exposure measurement. Banks must seek OSFI approval to temporarily exceed large exposure limits; supervisory reviews assess accurate identification, aggregation, and reporting.
- AC1 (non-internationally active banks thresholds and limits):
  - (a) 10 percent or more of a bank’s Tier 1 capital is defined as a large exposure;
  - (b) 25 percent of a bank’s Tier 1 capital is the limit for an individual large exposure to a private sector non-bank counterparty or a group of connected counterparties.
  - SMSBs hold 4 percent of Total Assets of OSFI-regulated banks, as of October 2024, and remain subject to the 1994 25 percent limit; OSFI expects SMSBs to set lower internal limits and monitors this quarterly via internal reports and risk oversight documentation.
- Assessment of Principle 19: Compliant.
  - OSFI guidelines set supervisory expectations for identification, measurement, evaluation, monitoring, reporting and control of concentration risk; CAR Guideline and Corporate Governance Guideline set expectations on risk limits, controls, mitigation and data aggregation; Stress Testing guideline and ICAAP reinforce supervisory oversight. ORR process incorporates concentration risk into ratings for “Financial resilience” and “Risk governance.”

### Key policy recommendation from assessors
- Recommendation: Lower the 100 percent of total capital limit for large exposures applicable to foreign bank subsidiaries in Canada (as per the 1994 Large Exposures guideline) to make the large exposure framework in Canada more consistent and coherent with observed practices.

### Transition to related supervisory area (Transactions with Related Parties)
- Principle 20 introduction: Supervisor requires banks to transact with related parties on an arm’s length basis, monitor and control risks, and write off exposures to related parties per standard policies and processes.
- EC1 note on related parties: Laws, regulations or the supervisor should set a comprehensive definition of “related parties” considering elements such as subsidiaries and affiliates, major shareholders and beneficial owners, board members and senior management and their close family members, with supervisory discretion for case-by-case application.

*Source: Section 465 (General Constraints on Investments) and related OSFI guidelines and supervisory findings as presented in the provided PDF content.*

### Part XI of the Bank Act is dedicated to “Self-dealing” and section 486 defines the term

### Part XI of the Bank Act is dedicated to “Self-dealing” and section 486 defines the term

### Definition of "related party" (section 486) and scope
- The related party definition covers:
  - a person with significant interest in the bank’s shares (paragraph 486(1)(a)) and their direct or indirect interests (paragraphs 486(1)(d & e));
  - board members, senior management (paragraph 486(1)(b)) and their direct interests (paragraph 486(1)(d));
  - their spouse or common-law partner, or a child who is less than 18 years of age (paragraph 486(1)(c)) and their direct or indirect interests (paragraphs 486(1)(d and f)).
- Companies included by definition:
  - Controlled by persons mentioned in subsections 486(a), (b) and (c) (subsection 486(1)(d));
  - In which the following persons have a substantial investment:
    - i. a person who controls the bank (paragraph 486(1)(e));
    - ii. the spouse or common-law partner, or a child who is less than 18 years of age, of a person who controls the bank (paragraph 486(1)(f));
  - Designated under subsections 486(3) or (4), or deemed under subsection 486(5) (paragraph 486(1)(g)).
- "Significant interest" (subsection 486(1)(a)) aligns with “major shareholders” per section 8(1): any shares beneficially owned by the person or by entities controlled by the person in excess of 10 percent of the outstanding shares of the bank.
- The definition in paragraph 486(1)(c) covers only spouses/partners and children less than 18 years old (less comprehensive than “close family members”).
- When determining "substantial investment" (paragraphs 486(1)(e) and (f)) or "control" (paragraph 486(1)(d)), “control” and “controlled” shall have the same meaning as in section 3, but without regard to the control in fact provision in paragraph 3(1)(d) (subsection 486(7)).

### Exceptions and non-related parties (section 486(2), 486(6), subsections 487)
- Subsection 486(2) exception:
  - An entity is not a related party of the bank if a person who controls the bank controls or has a substantial investment in the entity, but this comes only from having a controlling interest in the bank. Consequence: subsidiaries and entities that the bank has a substantial investment in are generally not considered related parties of the bank.
- Superintendent powers:
  - Section 486(6): The Superintendent may, by order, designate a class of non-voting shares of a bank exempted from being considered in the related party definition. OSFI is not aware of any Superintendent approvals under this subsection in the last 20 years.
  - Subsection 486(3): The Superintendent may designate a person a related party where they “might reasonably be expected to affect the exercise of the best judgment of the bank in respect of a transaction” or if the person is acting in concert in shareholding or ownership interests.
- Subsections 487(2) and (3) list transactions not subject to the related party regime, including:
  - issuance of shares fully paid in money; issuance from conversion of other shares or securities; issuance as a share dividend; issuance in exchange for shares of a bank continued under “incorporation and continuance”; issuance in accordance with amalgamation or conversion; issuance by way of consideration in accordance with a sale agreement; issuance in exchange for shares of another body corporate with written approval of the superintendent; payment of dividends; payment of salaries, fees, stock options, pension benefits, or other benefits or remuneration to persons who are related parties in their capacity as directors, officer or employees, and to persons providing services to the bank; transactions approved by the minister to incorporate/continue/amalgamate bank holding companies or insurance holding companies; transactions approved by the superintendent that are part of a restructuring of the holding company or of any entity controlled by it, if the bank is controlled by a widely held bank holding company.
  - Subsection 487(4): A holding body corporate of the bank, if it is a Canadian bank, trust and loan company, cooperative or insurance company, is considered not to be a related party. Subsection 487(5): Any entity in which the holding body corporate has a substantial investment is also exempted if that substantial investment is the only reason for related party status.

### Definition of "transaction" (section 488) and deemed related party in contemplated transactions (subsection 486(5))
- Section 488 defines "transaction" to include:
  - (a) making a guarantee on behalf of a related party;
  - (b) making an investment in any securities of a related party;
  - (c) taking an assignment of, or otherwise acquiring a loan made to, a related party, with loan meaning any arrangement for obtaining funds or credit;
  - (d) taking a security interest in the securities of a related party.
- Subsection 486(5): Where, in contemplation of a person becoming a related party, the bank enters into a transaction with that person, the person is deemed to be a related party of the bank in respect of that transaction.

### Market terms requirement and permitted exceptions (EC2 and related provisions)
- Section 501: “except as provided in subsections 496(4) to (6), any transaction entered into with a related party of the bank shall be on terms and conditions that are at least as favorable to the bank as market terms and conditions.”
- Exceptions permitting departures from market terms:
  - Loans to officers and their spouses, and terms on financial services more beneficial than market terms and conditions are permitted if approved by the bank’s CRC (subsections 496(4 to 6)).
  - Payment of salaries, fees, stock options, pension benefits, incentive benefits or other benefits to directors, officers or employees of the bank are exempted from the related party regime (paragraph 487(2)(c)).

### Permitted related party transactions and board/supervisor approvals (EC3)
- General rule: bank prohibited from entering into any transaction with a related party unless the Bank Act or related regulations provide otherwise (section 489).
- Exceptions listed (selected):
  - (a) Transactions with a financial institution controlled by the bank if incorporated/formed under provincial laws and subject to satisfactory regulation/supervision (subsection 489(3));
  - (b) Transactions immaterial or nominal to the bank (section 490); OSFI Bulletin E-6 Materiality Criteria for Related Party Transactions (1999) provides criteria;
  - (c) Loans/guarantees fully secured by Government of Canada or provincial securities, or loans to natural persons secured by mortgage of principal residence (section 491);
  - (d) Deposits for clearing purposes (section 492);
  - (e) Borrowing/taking deposits/issuing debt to a related party (section 493);
  - (f)-(l) Various transactions in ordinary course, securities purchases of government-guaranteed instruments, asset sales if fully paid in money and active market, leases in ordinary course, transactions under sale agreements approved by Minister, transactions consistent with company’s ordinary course of business (section 495), etc.;
  - (m) Loans to full time officers up to, in aggregate, the greater of twice the officer’s annual salary and $100,000, not including certain residential mortgage loans or margin loans (subsection 496(2));
  - (n) Loans to senior officer, to their spouse or partner, on more favorable conditions than those offered to the public, if approved by the CRC (subsections 496(4) and 496(5)); other financial services to officer/spouse/minor child on more favorable conditions if offered to all employees and approved by CRC (subsection 496(6));
  - (o) Margin loans in section 498 and loans under subsections 496(4) and (5) cannot exceed 2 percent of the regulatory capital of the bank, unless there is concurrence of at least two thirds of the directors present at a meeting of the board of directors (subsection 497(1));
  - (p) Loans with directors, officers and their interests, except transactions in “b,” “c” and up to the $100,000 limit, cannot exceed 50 percent of the regulatory capital of the bank (subsections 497(2) and 497(3));
  - (q) Transactions exempted by the Superintendent (subsection 499(1)), if they are not influenced in a significant way by and does not involve in any significant way the interests of a related party of the bank (subsection 499(2));
  - (r) Prescribed transactions (section 500), as per “Related Party Transactions (Banks) Regulations” SOR/92-309;
  - (s) Except for loans and other financial services under subsections 496(4) to (6), transactions entered into with a related party shall be on terms and conditions that are at least as favorable to the bank as market terms and conditions (section 501).
- Board approval requirements where permitted transactions are material:
  - Materiality criteria must be established by the bank’s CRC and approved by the Superintendent (section 490). OSFI’s Bulletin E-6 deems a bank’s criteria to be approved where they are at least as stringent as set out in the Bulletin. Transaction Instruction DA No. 20 (April 2009) sets out information requirements where a bank seeks to adopt less stringent criteria.
  - Prior board approval required for material permitted related party transactions such as:
    - Related party transactions with another financial institution (subsection 494(3)) or as part of a restructuring (subsection 494(4)) — Superintendent approval required; one criterion is senior officer sign-off that they are satisfied as to market terms and conditions. A 3rd party opinion on market terms may be required where assets are not securities traded on a recognized stock exchange or over-the-counter market.
    - Offering loans to senior officers and their spouses and other financial services on terms more beneficial than market terms requires CRC approval (section 496).
    - Board must approve loans, guarantees and investments with directors, officers and their interests if aggregate value to that related party would exceed 2 percent of the bank’s regulatory capital (subsection 497(1)). Transactions with all such related parties are limited to 50 percent of the bank’s regulatory capital (subsection 497(2)).

### Governance, conflicts of interest, supervisory monitoring (EC4)
- Bank governance obligations:
  - Directors required to establish a CRC, procedures to resolve conflicts of interest, techniques for identification of potential conflict situations, and designate a committee to monitor conflict of interest procedures (paragraphs 157(2)(b to d)). This committee may be the CRC or another board committee.
  - As part of licensing, OSFI confirms the proposed bank has established a CRC and that its composition conforms to Bank Act requirements (section 195). Applicants must provide descriptions of risk management and control processes, including a conflict of interest policy, and internal controls and policies to ensure compliance with the Bank Act.
  - CRC duties include requiring management to establish procedures for complying with Part XI, reviewing these procedures and their effectiveness, and reviewing practices to ensure material related party transactions that may affect stability or solvency are identified. The bank must report to the Superintendent on the CRC’s mandate and procedures; directors must report yearly to the Superintendent on CRC activities (section 195).
- Exclusion of conflicted board members:
  - Board members with conflicts of interest are excluded from the approval process for granting and managing related party transactions (subsections 202(1) and 203(1)).
- Supervisory monitoring and reporting:
  - OSFI determines during licensing that banks have policies/processes to deal with conflicts of interest and comply with related party regime; expectation banks continue to follow those policies post-licensing.
  - Normal supervisory work includes reviewing related party transaction reports to/from board committees as part of ongoing monitoring. Reports include attestations from senior management on compliance with related party and conflict of interest policies and adequacy of policies.
  - Banks do not report related party transactions to OSFI directly; OSFI receives related party information via banks’ internal documents in monitoring packages. Related party transactions are not included in supervisory reviews unless flagged by the monitoring documents or other indications.

### Limits, large exposures, and capital treatment (EC5)
- Exposure limits:
  - OSFI’s Large Exposure Limits guideline (applicable to SMSBs): aggregate exposure of a bank to a single counterparty or connection shall not exceed 25 percent of total capital (the sum of Tier 1 and Tier 2 capital); banks are expected to establish lower internal limits and employ the 25 percent limit on an exceptional basis. These limits apply regardless of related party status.
  - For D-SIBs, the limit is 25 percent of Tier 1 Capital (Guideline B-2 Large Exposure Limits for Domestic Systemically Important Banks), according to international standards.
  - For aggregate exposures to directors, officers and their interests, the 50 percent limit under the Bank Act applies (subsection 497(2)).
- Specific quantitative limits within related party rules:
  - Loans to full time officers up to, in aggregate, the greater of twice the officer’s annual salary and $100,000 (subsection 496(2)).
  - Margin loans in section 498 and loans under subsections 496(4) and (5) cannot exceed 2 percent of the regulatory capital of the bank, unless two thirds of directors present concur (subsection 497(1)).
  - Transactions with directors/officers and their interests (except certain small exceptions) cannot exceed 50 percent of regulatory capital (subsections 497(2) and 497(3)).
- Capital adequacy and related party treatment:
  - While substantial investments and subsidiaries of the bank are not considered related parties under the Bank Act (subsection 486(2)), this distinction is noted in the context of assessing capital adequacy.

*Source: Part XI and related sections of the Bank Act as described in the provided PDF content.*

### Chapter 2 of the CAR guideline, definition of capital (section 2.3.1), substantial and

### Chapter 2 of the CAR guideline, definition of capital (section 2.3.1), substantial and

### Capital, investments and intercompany instruments
- Substantial and non-substantial investments in financial entities are subject to regulatory capital adjustments, including potential capital deductions, as set out in section 2.3 of the CAR Guideline.
- Investments in insurance subsidiaries are required to be excluded in calculating a banking group’s consolidated capital adequacy (CP 16).
- For closely-held banks (i.e. the subsidiary of another entity), Chapter 2 of the CAR Guideline establishes expectations around intercompany capital instruments:
  - The rate and terms of capital instruments issued to a parent firm must be on terms at least as favorable to the issuer as market terms and conditions.
- Collateralization of exposures under the Bank Act:
  - A bank may make a loan to or a guarantee on behalf of a related party of the bank or take an assignment of or otherwise acquire a loan to a related party of the bank if the loan or guarantee is fully secured by securities of or guaranteed by the Government of Canada or the government of a province (section 491).

### Related party transactions — supervisory expectations and findings (EC6, EC7; Principle 20)
- Supervisor determines banks have policies and processes to:
  - (a) identify individual exposures to and transactions with related parties as well as the total amount of exposures; and
  - (b) monitor and report on them through an independent credit review or audit process.
- Supervisor determines exceptions to policies, processes and limits are reported to appropriate senior management and, if necessary, to the board; senior management monitors related party transactions on an ongoing basis and the board provides oversight.
- Bank Act requires the bank’s CRC review the effectiveness of procedures for complying with the self-dealing provisions (section 195); exceptions to related party policies, processes and limits would be reflected in reporting to the CRC and such reporting is obtained by OSFI in the ongoing monitoring process.
- Identified shortcomings and findings:
  - OSFI does not set expectations for banks to have policies and processes dedicated to related party transactions because, under the Bank Act, these transactions are generally prohibited in Canada.
  - More attention is needed at the bank level in monitoring these transactions and at OSFI level in monitoring and reviewing banks’ related risk management policies and procedures because:
    - (i) the definition of related party in Canada is narrower that the international standard;
    - (ii) the range of exceptions where related party transactions are permitted is big and complex, sometimes allowing them under multiple exceptions.
  - Transactions with related parties are reviewed by the external auditor; auditors apply Canadian Auditing Standard 550–Related Parties (substantially the same as International Standard on Auditing 550).
  - There are no specific requirements that exposures to related parties are regularly sent to OSFI; some information may reach OSFI via monitoring packages or external audit reports.
- Assessment of Principle 20: Materially Non-Compliant.
- Comments explaining non-compliance:
  - The related party framework is based on prohibition (section 489(1) of the Bank Act) but in practice:
    - The definition of related party in section 486 of the Bank Act is narrower than the international standard; the only close family members included are spouses, common-law partners and children less than 18 years of age; exercising significant influence over the board or senior management is not within the definition.
    - An array of related party transactions is exempted from the prohibition, including designation of Superintendent under certain conditions, making the framework complex and subject to exceptions that may not be prudent.
  - The narrower definition means related party transactions per international standards may occur without control by banks and without OSFI awareness or monitoring.
  - OSFI does not have information, qualitative or quantitative, on related party transactions; banks do not report related party transactions to OSFI and OSFI does not monitor these transactions systematically.
  - OSFI believes related party transactions are not a prudential concern in Canada given the Bank Act prohibition subject to limited exceptions.
  - Canada has not implemented past FSAP recommendations on this core principle.
- Recommendations:
  - Implement a prudential framework on transactions with related parties, incorporating the definition according to the international standard and establishing an internal expectation for supervisors to monitor related party transactions in ongoing monitoring, particularly for SMSBs.
  - Lower the current limit in subsection 497(2) of the Bank Act, whereby aggregate exposures to directors, officers and their interests is limited to 50 percent of total capital, in view of the Large Exposure guidelines that establish a limit of 25 percent in relation to “Total Capital” and “Tier 1 capital,” and take into account issues related to “connection” and “economic interdependence” of counterparties.

### Country and transfer risk — supervisory expectations and findings (Principle 21; EC1–EC5)
- Principle summary:
  - Supervisor determines banks have adequate policies and processes to identify, measure, evaluate, monitor, report and control or mitigate country risk and transfer risk in international lending and investment activities on a timely basis.
- Definitions:
  - Country risk: the risk of exposure to loss caused by events in a foreign country (broader than sovereign risk).
  - Transfer risk: the risk that a borrower will not be able to convert local currency into a foreign currency and so will be unable to make debt service payments in a foreign currency.
- Findings (EC1):
  - OSFI’s credit risk management guidelines (see CP17, EC1) do not deal with country and transfer risk.
  - During CRRs, OSFI supervisors cover international lending operations, and sophisticated large banks probably consider country and transfer risk in their policies and procedures, but OSFI is not systematically determining whether this is the case or assessing adequacy and effectiveness.
  - OSFI’s assessment criteria for CRRs do not contain references to country and transfer risk and supervisors do not specifically examine banks’ international loan portfolios.
  - Instances where OSFI guidance treats country and transfer risk:
    - ICAAP for Deposit-Taking Institutions Guideline (2010):
      - Cross border lending subsection notes increased risks including country risk, concentration risk, foreign currency risk (market risk), regulatory, legal, compliance and operational risks; recommends reflecting these in ICAAP; institutions may require additional capital for cross-border lending.
      - OSFI recommends institutions consider country risk as a possible source of underestimation of their Pillar 1 capital calculations; banks may or may not consider country risk in their ICAAPs.
    - Capital Adequacy Requirements Guideline mentions country and transfer risk in relation with rating system design:
      - 5.8.3 Rating System Design–paragraph 203: exceptions for country transfer risk where an institution may assign different borrower grades depending on whether the facility is denominated in local or foreign currency.
  - Shortcomings in regulatory treatment and supervisory methodology cause lack of supervisory attention by OSFI on these matters.
- Findings (EC2–EC5):
  - EC2: OSFI does not generally determine that banks’ strategies and policies for country and transfer risk have been approved by boards or that boards oversee effective implementation.
  - EC3: OSFI does not generally determine that banks have information systems, risk management systems and internal control systems to aggregate, monitor and report country exposures timely and ensure adherence to country exposure limits.
  - EC4: OSFI does not generally oversee whether a bank is setting appropriate provisions to cover country and transfer risk; IFRS 9 allows methods that may include country and transfer risk but OSFI is not verifying systematically.
  - EC5: OSFI does not require regulatory returns on country risk; LS teams and CRD may receive management or Board packages but are not required to receive or analyze them systematically.
- Assessment of Principle 21: Materially Non-Compliant.
- Comments:
  - OSFI’s credit risk management guidelines do not deal with country and transfer risk; OSFI is not determining whether banks engaging in international operations are managing these risks adequately.
  - OSFI’s assessment criteria for CRRs do not reference country and transfer risk.
- Recommendation:
  - OSFI should establish supervisory expectations on country and transfer risk in OSFI’s credit risk regulatory guidance, include these risks in the assessment criteria for the credit portfolio, and assess them when reviewing the international lending portfolio of banks.

### Market risk — supervisory expectations and findings (Principle 22; EC1)
- Principle summary:
  - Supervisor determines banks have an adequate market risk management process that considers risk appetite, risk profile, market and macroeconomic conditions, and the risk of a significant deterioration in market liquidity.
- Findings (EC1):
  - OSFI’s Corporate Governance guideline establishes the role of the board, including responsibility for the bank’s culture and approving and overseeing the bank’s RAF and significant policies, plans and strategic initiatives related to the management of capital and liquidity.
  - RAF guidance excerpts:
    - “The RAF should set basic goals, benchmarks, parameters and limits (for example, level of losses) as to the amount of risk” the bank “is willing to accept, taking into account various financial, operational and macroeconomic factors. It should consider the material risks” to the bank, “as well as the institution's reputation vis-à-vis policyholders, depositors, investors and customers.”
    - Risk limits allocation guidance across risk categories, business units, lines of business and more granular levels.
    - “Where the RAF sets aggregate limits that will be shared among different units, the basis on which such limits will be shared should be clearly identified and communicated.”
  - Corporate Governance Guideline expectations for Board Risk Committee:
    - Seek assurances from the CRO that the risk management function is independent from operational management, adequately resourced, and has appropriate status and visibility.
    - “The CRO and risk management function should not be directly involved in revenue-generation or the management and financial performance of any business line or product.”
  - All large and more complex banks in Canada have dedicated risk management functions overseen by a CRO.

*Source: Chapter 2 of the CAR guideline, definition of capital (section 2.3.1), substantial and non-substantial investments; related extracts on Principles 20–22 from the supplied PDF content.*

### Chapter 9 of the CAR Guideline, paragraph 56, require banks to prepare, evaluate and have

### Chapter 9 of the CAR Guideline, paragraph 56, require banks to prepare, evaluate and have

### Reporting and desk-level information requirements
- Chapter 9, paragraph 56 requires banks to prepare, evaluate and have available for OSFI the following information, for all trading desks:
  - (i) inventory ageing reports;
  - (ii) daily limit reports including exposures, limit breaches, and follow-up action;
  - (iii) reports on intraday limits and respective utilization and breaches for institutions with active intraday trading; and
  - (iv) reports on the assessment of market liquidity.
- OSFI receives mandatory monthly regulatory reporting on market risk in Schedule 986 from the banks current subject to market risk capital requirements, which correspond to the D-SIBs plus one foreign bank subsidiary (D-SIBs+1).
  - Schedule 986 includes information on the computation of capital requirements down to the desk level.
  - Schedule 986 provides monthly information on banks’ daily Value-at -Risk (VaR), both at the top-of-house level and down to the equivalent desk levels, as well as measures of the stress losses based on the worst-case stress scenarios both at top-of-house and for each desk.
- In monitoring risks, OSFI relies on submissions of the banks’ monthly and/or quarterly internal reports of market risk, which provide information on management VaR and stress testing results, and risk factor sensitivity exposures across the various market risk classes.

### OSFI expectations for market risk measurement and controls
- OSFI guideline B-7 Derivatives Sound Practices sets out expectations for FRFIs with respect to derivatives activities. Examples of specific expectations for market risk include:
  - Defining market risk limits based on risk appetite and identifying market risk drivers.
  - Measuring market risk using techniques that:
    - Are fully documented and at a minimum must evaluate impact on earnings and capital from adverse risk factor movements.
    - Use Measurement techniques for dealers and active-position takers that include VaR or Expected Shortfall over a two-week holding period.
    - Generates valuation and estimation of amounts at risk daily that can be reported at a frequency that is commensurate with the size of the FRFI’s involvement and features of the instruments and portfolios being measured.
    - Have capacity to update historical data and underlying assumptions to facilitate reviews of related policies by senior management.
    - Takes into account all valuation adjustments used when pricing derivatives.
- OSFI has detailed internal guidance for supervisors on the assessment of controls and reporting for trading market risk, including expectations that an institution has:
  - a risk management system capable of flagging breaches of limits;
  - an escalation process to appropriate levels of management with proposed remediation;
  - evidence of management responses that are prompt and effective; and
  - means to track response and management follow-up.

### Supervisory framework, monitoring and resources
- OSFI’s new 2024 Supervisory Framework evaluates all banks in the risk category “Financial resilience,” defined as ability to withstand financial stress, assessing financial risk profile, capital, and liquidity across activities including market risk in the TB.
- The Supervisory Framework rates the subcategory “Market (trading)” for Tier 1 and 2 banks by looking at:
  - a) Market risk indicators such as value-at -risk (VaR), capital requirements and stress-testing and determination of how these indicators relate to established limits.
  - b) Operational management such as integrity of market operations, adequacy of books and records and internal controls, segregation of duties, and processes to report risk measures and escalate breaches.
  - c) Risk assessment capabilities including integrated risk management framework, scope for each trading desk, risk limits at various levels, identification of elevated market risks, thoroughly reviewed and validated risk measurement models, and risk governance.
- The review process yields a rating from 1 (best) to 8 (worst) for “Market risk (Trading).” Banks are assessed through ongoing monitoring, specific reviews and cross-sector reviews.
- Supervisory resources involved include LS teams, Market and Liquidity Risk Division, and Banking, Capital and Liquidity Standards Division.
  - Market and Liquidity Risk Division staff are dedicated specifically to covering the trading market risks of the six D-SIBs, meeting quarterly with the banks and producing a quarterly report on market risk.
- OSFI conducts approximately one annual thematic review involving trading market risk and two or three bank-level reviews on market risk annually. Examples include the 2024 Foreign Exchange Settlement Risk review and an Interest Rate Derivatives desk review.

### Boundary, capital treatment, valuation and controls
- Chapter 9 of the CAR Guideline (the CAR on market risk) is applicable only to D-SIBs and to banks with significant trading activity, as identified by OSFI (D-SIBs+1).
  - As of December 2023, D-SIBs held 96 percent of the Total Assets held by OSFI supervised banks.
  - OSFI informed that TB are in practice limited to D-SIBs, and, as of October 2024, two institutions that are non-D-SIBs reported TBs.
- While market risk corresponded to 4 percent of RWA for D-SIBs, as of December 2023, some banks have 25 percent of earnings coming from trading book activities.
- Section 9.2 of Chapter 9 contemplates the boundary between BB and TB.
- Paragraph 55 (b) requires that a trading desk has clearly-defined limits based on business strategy and appropriate market risk metrics.
- Paragraph 128 requires banks’ usage of own-risk-factor-sensitivities as an input in determining Standardized Approach Capital requirements.
- Section 9.4 of the CAR Guideline requires adequate systems and controls for valuation:
  - Paragraph 96: systems integrated with other risk management systems, documented policies and procedures for valuation, and clear independent reporting lines for the valuation department.
  - Paragraph 98: requires institutions to mark-to-market as much as possible.
  - Paragraph 99: governance and controls when marking-to-model is used.
  - Paragraph 100: expectations to establish an independent price verification function distinct from daily mark-to-market.
  - Paragraphs 104–107: expectations for valuation adjustments for less liquid positions and potentially holding additional capital requirements against these positions.
    - Currently, the D-SIBs plus one foreign bank subsidiary (D-SIBs+1) deduct from capital, in aggregate, the equivalent of 1.9 percent of market risk RWA as a valuation adjustment for their less-liquid positions.
- Paragraph 103 summarizes OSFI’s expectations for valuation adjustments: unearned credit spreads, close-out costs, operational risks, early termination, investing and funding costs, future administrative costs and, where appropriate, model risk.
- Banks are subject to capital requirements associated with the volatility of their credit valuation adjustments to counterparties from over-the-counter derivatives holdings under Chapter 8.

### Supervisory findings, gaps and assessments
- The assessors noted that the basis for exempting banks from the market risk framework is the size of their trading activities, while the market risk framework also covers the risk from BB exposures to foreign exchange and commodities.
- The assessors discussed supervisory work and had evidence of supervisory effectiveness through supervisory letters to banks but concluded that more frequent, deeper and targeted reviews on market risk are warranted.
- OSFI assessed banks’ adherence with CAR guideline, Chapters 8 and 9, through a cross-sector review as part of FRTB implementation, including delivery of survey answers and verification by independent review functions.
- Assessment of Principle 22: Compliant.
  - OSFI regularly assesses banks in relation to the management of market risk with key minimum expectations set at the Corporate Governance guideline and more specific expectations in Chapter 9 of the CAR guideline, applicable to D-SIBs and banks with significant trading activity.
  - These banks held more than 96 percent of the Total Assets of OSFI supervised banks, as of October.

*Source: Chapter 9 of the CAR Guideline (excerpt provided).*

### 2024. Therefore, the fact that market risk capital requirements are not generally applicable to

### Principle 23 — Interest Rate Risk in the Banking Book

### Overview and supervisory framework
- Principle: The supervisor determines that banks have adequate systems to identify, measure, evaluate, monitor, report and control or mitigate interest rate risk in the banking book on a timely basis. These systems consider the bank’s risk appetite, risk profile and market and macroeconomic conditions.
- OSFI’s new 2024 Supervisory Framework evaluates all banks in the risk category “Financial resilience,” defined as the ability to withstand financial stress. OSFI assesses this by considering a bank’s financial risk profile, capital, and liquidity across activities, including market risk in the TB and IRRBB.
- Guideline references:
  - OSFI’s Guideline B-12 Interest Rate Risk Management, May 2019, implemented for D-SIBs in January 2020 and for non-D-SIBs in January 2021.
  - Corporate Governance guideline, 2018 (board expectations).
  - Guideline E-21, Operational Resilience and Operational Risk Management, August 2024 (data risk management and risk data aggregation and reporting).

### OSFI expectations and supervisory monitoring
- Key expectations from Guideline B-12 (selected quoted expectations preserved):
  - “(...) be familiar with all potentially material elements of interest rate risk, to actively identify their IRRBB exposures and to take appropriate steps to measure, monitor and control IRRBB”;
  - “(...) identify the interest rate risks inherent in their BB products and activities undertaken, and ensure that these are subject to adequate procedures and controls. Significant hedging or risk management initiatives should be approved by appropriate committees before being implemented”;
  - “Products and activities that are new to an institution should undergo a careful pre-acquisition review to ensure that the IRRBB characteristics and model risks are well understood and subject to a predetermined test phase before being fully rolled out”;
  - Have IRRBB management integrated within the broader risk management framework and aligned with its business planning and budgeting activities.
- Monitoring practices:
  - Periodic monitoring of key quarterly data, the monitoring package, and regular discussions with banks’ senior management.
  - Monitoring and review work commensurate with institution’s nature, size, business, complexity, economic significance and risk profile (e.g., Tier 2 banks may meet semi-annually).
  - A dashboard with information from banks’ regular returns is used as a supervisory tool.
  - The ORR process considers IRRBB in the risk category “Financial resilience”; banks in Tiers 1 and 2 are rated for the subcategory “Market (non-trading).”

### Model governance, measurement and data
- Guideline B-12 requires governance around measurement, assumptions, systems integrity, model governance, public disclosure, capital adequacy and outlier test; Principle 5 requires understanding key behavioural and modelling assumptions; Principle 6 and Principle 7 specify measurement systems and regular reporting aligned with ALCO meetings.
- Guideline E-21 (August 2024) articulates expectations related to data risk management in section 4.7; risk data aggregation and reporting capabilities are subsets of data risk management.
- Reporting requirements:
  - OSFI requires all banks, D-SIBs and SMSBs (including trust and loan companies) to report interest rate risk gap position quarterly through OSFI I3—Interest Rate Risk.
  - The return requires measured sensitivity on net interest income (NII) and economic value of equity (EVE) using the prescribed stress testing outlined in OSFI’s Guideline B-12 (2019), which includes standardized interest rate shock scenarios.

### Supervisory gaps, findings and assessments
- Capacity and resourcing:
  - The market non-trading team comprises four people (with one covering insurance) responsible for monitoring IRRBB in Tier 1 and Tier 2 banks; LSs monitor Tiers 3 to 5 with specialist support as needed.
- Model review practices and recent actions:
  - OSFI has not yet conducted supervisory reviews of banks’ IRRBB models; a survey has been recently finalized and will trigger follow-up actions in two banks.
  - External consultants commissioned by OSFI are conducting a hypothetical portfolio exercise covering the D-SIBs.
  - After the March 2023 turmoil, closer monitoring was established, with specific data-calls for subsequent quarters.
  - An example bank-specific review (triggered by low reported risk versus peers) led to multiple supervisory findings and recommendations covering risk measurement, model governance, and management structure and strategy.
- Identified supervisory themes where actions have typically fallen:
  - Weak risk governance (inadequate policies and frameworks, limited internal reporting).
  - Ineffective processes or systems for internal oversight (lack of risk management resources and system capabilities).
  - Simplified risk methodologies (stress testing, risk measurement, and behavioural modelling).
- Assessment conclusions:
  - OSFI regularly assesses banks in relation to IRRBB and has set key minimum expectations via the Corporate Governance guideline and Guideline B-12 (May 2019).
  - Ongoing monitoring allows peer comparisons and review of ALCO and board materials, internal audit reports, and other internal documents to identify gaps that may lead to focused reviews.
  - However, OSFI has not conducted specific supervisory reviews of banks’ IRRBB measurement systems and models, creating a risk that industry benchmarking may be misleading if the underlying models underassess IRRBB.
  - The assessors believe deep supervisory reviews are paramount, especially for D-SIBs, to check key behavioural and modelling assumptions, accuracy of risk measurement, data integrity, documentation, testing and controls.
- Formal assessment of Principle 23: Largely Compliant.

### Findings on capital and internal measurement systems
- OSFI’s Guideline B-12, Principle #9 (capital adequacy and outlier test) expects capital adequacy for IRRBB to be considered as part of the ICAAP and approved by senior management, in line with the institution's IRRBB risk appetite.
- IRRBB is considered a material Pillar 2 risk that Canadian banks are expected to measure and hold capital for pursuant to OSFI’s ICAAP Guideline.
- Current OSFI approaches to assess IRRBB capital adequacy include:
  - An industry-wide survey on IRRBB models and measurement (recently finalized), triggering follow-up actions in at least two large banks and informing a range of practice view;
  - Review of Pillar 2 capital (ICAAP) for IRRBB;
  - Ongoing supervisory monitoring of key risk and committee reports, including model and back-testing performance;
  - Structured dashboards and risk/position analysis based on quarterly regulatory return data;
  - Focused supervisory reviews triggered by issues identified during monitoring.
- Gap: OSFI has not yet conducted deep supervisory reviews of IRRBB models and systems (notably for D-SIBs), which limits assurance that internal capital assessments adequately capture IRRBB.

### Recommendation
- Conduct supervisory reviews of banks’ IRRBB internal measurement systems, with sufficient depth for the supervisors to have a view on the adequacy of banks’ internal models in capturing IRRBB. This would provide OSFI with more elements to apply the supervisory framework and to assess IRRBB in the ORR process.

*1canea2025007-source-pdf - 2024*

### 2020. OSFI also incorporated the standardized Basel III liquidity monitoring tools in 2015. The

### 1canea2025007-source-pdf - 2020. OSFI also incorporated the standardized Basel III liquidity monitoring tools in 2015. The

### Overview of LAR guideline structure
- The LAR guideline entails the following chapters:
  - Chapter 1– Overview
  - Chapter 2– LCR: applied D-SIBs and Category I and II SMSBs
  - Chapter 3– NSFR: applied to D-SIBs and Category I SMSBs with more than 40 percent of wholesale funding, calculated on a standardized manner as per Annex 1
  - Chapter 4– Net Cumulative Cash Flow (NCCF)
  - Chapter 5– Operating Cash Flow Statement (OCFS)
  - Chapter 6– Liquidity Monitoring Tools
  - Chapter 7– Intraday liquidity Monitoring Tools

### Proportionality framework and segments (effective April 2023)
- OSFI introduced a proportionality framework applied to the SMSBs to right size liquidity expectations for smaller institutions.
- The proportionality framework for liquidity requirements considers the following segments:
  - D-SIBs
  - Category I SMSBs
  - Category II SMSBs
  - Category III SMSBs
- For a description of the different categories, see CP16, AC1.
- Reference documents cited: BCBS, High-level considerations on proportionality, July 2022; BCBS, Principles for sound liquidity risk management and supervision, September 2008; [LCR10], [LCR20], [LCR30], [LCR31], [LCR40], [LCR99], [NSF10], [NSF20], [NSF30], [NSF99].
- Guideline source: Small and Medium-Sized Deposit-Taking Institutions (SMSBs) Capital and Liquidity Requirements – Guideline (2023) - Office of the Superintendent of Financial Institutions (osfi-bsif.gc.ca).

### Proportional liquidity requirements (explicit rules)
- The proportional liquidity requirements are:
  1. The LCR is applied to all segments, except Category III SMSBs;
  2. The NSFR is applied to D-SIBs and to Category I SMSBs, if they meet the significant wholesale funding reliance threshold, set at 40 percent;
  3. The cashflow based requirements are:
     - Comprehensive NCCF: D-SIBs and Category I SMSBs
     - Streamlined NCCF: Category II SMSBs
     - OCFS: Category III SMSBs

### Mapping to supervisory tiers and OSFI discretion
- Simplified mapping of categories to supervisory tiers:
  - D-SIBs are Tier 1 banks
  - Category I SMSBs are Tier 2 banks
  - Category II and III SMSBs belong to Tiers 3 to 5
- OSFI has discretion to move institutions between tiers and this relationship between tiering and segments may not always hold.
- The SMSBs guideline explicitly states that subsidiaries of D-SIBs are considered to be in Category I.

### Subsidiary treatment and exemptions (sub-consolidated basis)
- A subsidiary regulated by OSFI can be exempted from the LCR on a sub-consolidated basis if the subsidiary operates strictly in Canada and the operations are primarily Canadian dollar-related.
- If the ultimate Canadian parent of a subsidiary:
  - Is a D-SIB: the LCR is applicable to the subsidiary; and the NSFR, the NCCF and the monitoring tools of chapter 6 are not applicable to the subsidiary.
  - Is not a D-SIB: the subsidiary is exempted from the LCR, NSFR, NCCF and monitoring tools.

*Source: 1canea2025007-source-pdf - 2020. OSFI also incorporated the standardized Basel III liquidity monitoring tools in 2015. The (canonical PDF).*

### Section 1.2 of Chapter 1 also establishes that, regardless of the scope of application of

### 1canea2025007-source-pdf - Section 1.2 of Chapter 1 also establishes that, regardless of the scope of application of

### Liquidity monitoring tools and supervisory metrics
- NCCF (Net Cumulative Cash Flow)
  - Supervisory tool applied on a consolidated and sub-consolidated basis that measures a bank's cash flows beyond the 30-day horizon to capture the risk posed by funding mismatches between assets and liabilities.
  - Captures gaps between contractual inflows and outflows for various time bands up to a 12-month time horizon.
  - Introduced for domestic supervisory use by OSFI in 2015.
  - Allows OSFI to customize liquidity survival horizon and buffer expectations for institutions.
  - OSFI communicated updated NCCF threshold expectations to each supervised bank (D-SIBs and Category I SMSBs).
  - Regular expected survival horizon is 3 months on average, with 4-months and 5-months requirements active for some banks.
  - OSFI reassesses and updates NCCF thresholds during supervision as liquidity risk profiles change.
- OCFS (Operational Cash Flow Snapshot)
  - A cash flow forecasting supervisory tool that factors limited behavioral aspects via prescribed inflow and outflow rates.
  - Provides data on stock of unencumbered liquid assets, contractual cash inflows, and contractual cash outflows over a one-year horizon.
- Additional OSFI tools
  - Liquidity Activity Monitor (LAM).
  - Forecast of operational expenses and non-interest income (for non-D-SIBs).
  - Intraday liquidity monitoring tools.

### Scope and focus of monitoring
- OSFI monitors:
  - contractual maturity mismatch;
  - concentration of funding;
  - available unencumbered assets;
  - LCR by significant currency;
  - market-related data at differing levels.
- Liquidity monitoring captures cash flows, balance sheet structure, available unencumbered collateral, and certain market indicators.
- Supervisory monitoring inputs include collection and monitoring of bank liquidity and funding data (at holding company and entity level), regulatory data, management information reports, meetings with management, market data, industry trend monitoring, and social media.
- Enhanced monitoring for banks with elevated supervisory concerns/ratings uses more frequent and ad hoc reporting.

### Supervisory resourcing and organization
- Liquidity risk team in Market and Liquidity Risk Division: composed of 5 people, responsible for monitoring liquidity risks for Tier 1 and Tier 2 banks.
- LSs monitor liquidity risks for Tiers 3 to 5.
- OSFI’s Market and Liquidity Risk Division, Industry Surveillance teams, and communication teams (when needed) are involved in liquidity monitoring.

### Supervisory framework and assessment practices
- OSFI’s Supervisory Framework guides liquidity risk assessment via regular monitoring and reviews.
- ORR process: liquidity at Tiers 1 and 2 banks assessed by level and quality of liquidity management; Tiers 3 to 5 incorporated into subcategory “Liquidity” within “Financial resilience” or directly into the ORR (Tier 5 banks).
- Internal supervisory tools support quality and effectiveness of assessments.
- Liquidity risk reviews vary based on monitoring-identified issues and supervisory priorities (example: 2023 review on contingency plans).
- Analytical tools used to flag SMSB liquidity risk aspects for deeper LS scrutiny.

### Supervisory actions and examples
- OSFI may impose additional supervisory expectations and a range of supervisory actions when liquidity requirements/expectations are not met.
- Example discussed: a bank issuing a funding instrument that circumvented the LCR was subject to an increased NCCF survival period until remediation and policy fixes; the bank faced a downgrade in rating; OSFI recalibrated the NCCF for the whole industry.

### Incorporation of market and macroeconomic context (EC2)
- Prescribed liquidity requirements reflect banks’ liquidity risk profiles in the context of markets and macroeconomic conditions.
- Guideline B-6 Liquidity Principles (January 2020) expectations highlighted:
  - Principle #2: banks should clearly articulate a liquidity risk tolerance appropriate to business strategy, size, sophistication, funding markets and overall risk appetite.
  - Guideline page 14: factors for determining appropriateness of stock of liquid assets relative to liquidity risk profile.
  - Principle #11: manage market access and maintain ongoing presence in chosen funding markets and strong relationships with fund providers.
- Application of expectations is proportional to size, complexity and risk profile; thresholds for LCR and NCCF are relatively less strict for largest banks and more stringent for small banks.

### Liquidity management framework (EC3 and EC4)
- Guideline B-6 Principles (January 2020) key expectations:
  - Principle 1: robust liquidity risk management framework including cushion of unencumbered HQLA to withstand a range of stress events.
  - Principle 3: senior management roles/responsibilities for strategy, policies and practices; board review and approval.
  - Principle 4: comprehensive bank-wide view considering legal entities, business lines and currencies.
  - Principle 2 (EC4): board responsibility for articulating liquidity risk tolerance.
  - Principle #12: active intraday liquidity management under normal and stressed conditions.
  - Principle 5: sound processes for measurement, monitoring and control, including systems and personnel for timely reporting.
  - Principle #8: active management of collateral positions or larger stock of liquid assets if unable to actively manage collateral.

### Funding strategy and liquidity buffers (EC5)
- Guideline B-6 expectations for funding strategies and monitoring:
  - Principle 1: documented tolerance for liquidity risk in policies, strategies, and risk management processes.
  - Principle 7: regular stress testing for short-term and protracted institution-specific and market-wide scenarios; outcomes used to adjust strategies, policies, positions, and contingency plans.
  - Principle 11: effective diversification across products, tenors, legal entities and business lines; critical assessment of fungibility of foreign currencies and internal limits on concentration by counterparty or market.
  - Principle 7 and others: periodic assessment of capacity to monetize assets; conservative liquidity reassessed annually by senior management as part of stress testing reviews.

### Contingency funding plans (EC6)
- Principle 9 (Liquidity Principles Guideline): banks should have formal CFPs outlining strategies for liquidity shortfalls, clear lines of responsibility, invocation/escalation procedures, regular testing and updates.
- All banks in Canada have documented CFPs approved by their boards, including enterprise-wide initiatives, action plans for stress scenarios, roles/responsibilities, and communication plans.
- 2023 cross-sector review of CFPs at SMSBs: most SMSBs conduct some CFP testing and include scenarios leading to reduced liquidity levels and remediation actions; some SMSBs lack operational robustness testing elements.
- Comprehensive CFP testing program components:
  - (1) operational robustness testing;
  - (2) transaction level testing (periodic monetization of assets, e.g., repo or sale);
  - (3) tabletop exercises (less frequent).
- As of October 2024, OSFI is surveying CFPs of larger banks focusing on preparedness, cross-border impediments, and capacity to monetize assets in stress.

### Stress testing (EC7)
- Principle 6 (Liquidity Principles Guideline) and Guideline E-18 Stress Testing (2009) set expectations for stress testing programs:
  - Regular stress testing including systemic and idiosyncratic scenarios; short- and long-term effects considered.
  - Stress testing includes sensitivity and scenario analysis to assess sufficiency of liquidity and adequacy of NCF limits.
- OSFI regularly reviews banks’ liquidity stress-testing; evidence shows banks conduct stress testing consistent with expectations.
- Annual reviews include sensitivity analyses for deposits, commitments, and total cash flows; results inform policy updates, risk strategies, forecasts and plans.
- Bank stress testing addresses both short-term acute and chronic stress conditions.

*Source: 1canea2025007-source-pdf - Section 1.2 of Chapter 1 also establishes that, regardless of the scope of application of*

### 1. Frequently updating and assessing stress test results for short-term and longer-term

### 1. Frequently updating and assessing stress test results for short-term and longer-term

### Foreign-currency liquidity (EC8)
- Supervisor expectation:
  - Banks with significant foreign currency business or significant exposure in a given currency must undertake separate analysis of strategy and monitor liquidity needs separately for each significant currency.
  - Use of stress testing to determine appropriateness of mismatches in that currency and, where appropriate, set and regularly review limits on the size of cash flow mismatches for foreign currencies in aggregate and for each significant currency individually.
  - Supervisor monitors bank’s liquidity needs in each significant currency and evaluates ability to transfer liquidity across jurisdictions and legal entities.
- OSFI practices and tools:
  - Management of foreign-currency liquidity is covered in Principle 4 of Guideline B-6 Liquidity Principles; banks expected to document management of foreign currency positions, limits, internal support arrangements, and transferability concerns.
  - OSFI liquidity risk returns collect information on LCR and NCCF by currency when foreign currencies are significant for banks.
  - Banks’ reports and internal documents to and from senior management, including ALCO, provide information on foreign currency liquidity; developments in treasury closely monitored for larger Canadian banks operating in the US.
  - Analysis of banks’ CFPs provide important information on currency flows and jurisdiction mismatches.
  - Liquidity risk specialist team is developing analytical tools to better combine information; next year information from recovery plans will be added.
  - Banks dependent on wholesale funding and money markets with funding in foreign currencies expected to have strong monitoring and control processes, internal limits, well supported and documented assumptions around foreign currency fungibility, and systems to actively measure/monitor and report against limits.
- Thresholds and stress testing expectations:
  - Under Principle #6 of Guideline B-6, banks are expected to implement separate measurement and reporting of foreign currencies if in aggregate the foreign currency represents more than 5 percent of total funding or total assets.
  - Principle #6 expects stress testing for foreign currencies to consider additional scenarios assessing impact of a disruption to material cross-border funding channels and currencies.

### Encumbered assets and collateral (EC9)
- Supervisor expectation:
  - Supervisor determines that bank’s level of encumbered balance sheet assets is managed within acceptable limits to mitigate risks to cost of funding and sustainability of long-term liquidity.
  - Supervisor requires banks to commit to adequate disclosure and set appropriate limits to mitigate identified risks.
- OSFI guidance and data collection:
  - Principle 8 of Guideline B-6 Liquidity Principles: banks expected to actively manage collateral positions (encumbered and unencumbered), re-assess actual encumbrance and potential for liquid assets to become encumbered, and comply with OSFI-mandated internal pledging policies.
  - Guideline B-11 on Pledging (May 2003) expects enterprise-wide pledging policies; OSFI recognizes this guideline is outdated and work is ongoing to include relevant expectations in Guideline B-6, including internal limits on pledging and quantitative limits on an individual bank officer’s ability to execute transactions that require pledging.
  - Chapter 2 of the LAR guideline requires banks to measure and monitor LCR to ensure adequate stock of unencumbered HQLA for a 30 calendar-day liquidity stress scenario.
  - Pillar 3 Disclosure requirements expect banks to publicly disclose encumbered and unencumbered assets using Template ENC.
  - OSFI captures asset encumbrance data mainly through H4 Collateral and Pledging Report and U3 Pledging and Repos data returns on at least a monthly basis; data presented through customized internal dashboards.
  - OSFI’s LCR return captures banks’ LCR calculations and data described in Chapter 2 of the LAR Guideline; trends monitored through customized dashboards and compared against LCR limit information submitted monthly by banks.

### Assessment of Principle 24 (Liquidity risk)
- Assessment result: Compliant
- Key findings:
  - OSFI is at the forefront regarding liquidity risk requirements and supervisory practices, with thresholds for supervisory action closely monitored and acted upon when deficiencies identified (most of the time based on banks’ internal targets and above regulatory minimums).
  - Banks expected to use liquidity adequacy tools such as the NCCF and the OCFS to provide a more complete picture of liquidity risks.
  - Qualitative requirements are broad and followed through ongoing monitoring and varied supervisory reviews, many based on banks’ answers to surveys and questionnaires.
  - Cross-sector qualitative liquidity supervisory reviews provided OSFI with a clear view of best practices, shaping expectations on contingent funding and stress-testing.
  - Supervisory dashboards are used in monitoring and are continuously enhanced.
  - Recent work by liquidity risk experts produced important findings and close monitoring through a proportional framework; changes in banks’ liquidity risk assessments are actively reflected in banks’ ORR.
- Recommendation/observation:
  - Given complexities and many angles of liquidity risk, more frequent bank-specific deep-dive reviews could be done to verify practices in this core banking area; this issue is reflected in the grade of CP9 and in a recommendation on frequency of deeper on-site supervisory reviews.

### Operational Risk and Operational Resilience (Principle 25, EC1–EC3)
- Principle summary:
  - Supervisor determines banks have an adequate operational risk management framework and operational resilience approach considering risk profile, risk appetite, business environment, tolerance for disruption to critical operations, and emerging risks.
  - Framework includes policies and processes to: (i) identify, assess, evaluate, monitor, report and control or mitigate operational risk; and (ii) identify and protect against threats and potential failures, respond and adapt, recover and learn from disruptive events to minimize impact on delivering critical operations through disruption.
- Guideline E-21 (2024) and transition timelines:
  - OSFI’s 2024 Guideline E-21 Operational Risk and Resilience, issued August 2024, expands the 2016 Guideline to include operational resilience expectations and contributors such as business continuity management, disaster recovery, change management, and data risk management.
  - The 2024 Guideline E-21 is divided into sections:
    - 1. Governance: roles and responsibilities of senior management, business and central functions, independent oversight function and independent assurance;
    - 2. Operational risk management: minimum aspects of the framework, including definition of risk appetite, risk management tools and monitoring and reporting;
    - 3. Operational resilience: identification and mapping, tolerance for disruption and scenario testing;
    - 4. Key areas of operational risk management that strengthen operational resilience: business continuity risk management, disaster recovery risk management, crisis management, change management, technology and cyber risk management, third-party risk management and data risk management.
  - Implementation expectations and timelines:
    - Sections 1 and 2 are immediately in effect.
    - Full adherence to section 4 is expected from September 1, 2025.
    - By September 1, 2026, full adherence to the guideline is expected, recognizing operational resilience programs will mature over time: banks should have completed identification, mapping and setting tolerances for disruption of critical operations and developed scenario testing methodology and begun testing so that, by September 1, 2027, testing has been completed for all critical operations.
  - These expectations were communicated in the letter announcing the new guideline on 22 August 2024.
  - The final guideline’s expectations are substantively the same as the draft released for consultation on 13 October 2023; OSFI is already communicating that plans should be well underway.
- Supporting guidelines:
  - 2016 Guideline E-21 expectations on integrating operational risk management into overall risk management and on senior management accountability remain relevant.
  - Guideline E-21 is supported by Guideline B-10 (Third Party Risk Management) and Guideline B-13 (Technology and Cyber Risk Management).
  - The Integrity and Security Guideline sets expectations related to protecting operations, premises, people, technology assets, and data against threats including foreign interference.
- Supervisory resources and monitoring:
  - For Tier 1 and 2 banks, operational risk and resilience is assessed on an ongoing basis by teams of specialists through periodic monitoring implemented in 2023.
  - OSFI specialists in the area: 26 people in the technology risk division and 17 people in the operational risk division.
  - The LS of Tier 3 to 5 banks are in charge of monitoring operational risk and operational resilience.
  - Monitoring package includes banks’ reports and internal documents such as operational risk committee reports, information on major initiatives, key operational risk types, operational incidents, and metrics measuring risk levels against risk limits and risk appetite; meetings with senior management held within monitoring.
  - Monitoring is risk-based and not necessarily conducted quarterly; for banks that are not staged, meetings with senior management held at least annually.
  - A dashboard on operational risk loss events is currently available; OSFI plans to develop further operational risk metrics.
  - The new ORR process has “Operational resilience” as a risk factor with specific ratings for subcategories “Technology,” “Cyber” and “Operations” for banks in Tiers 1 to 3; supervisory framework includes internal guidance to assess governance and frameworks, and management and controls.
- Supervisory reviews and sample activity:
  - Full scope reviews are conducted for each D-SIB at least every two to three years.
  - In the last 3 years, approximately 16 reviews of individual banks and 15 cross-sector reviews were conducted.
  - As of October 2024, 4 reviews on operational risk have been concluded.
  - In 2022, OSFI conducted a cross-sector review of D-SIBs’ business continuity plans to understand adaptation to the hybrid working environment, built on banks’ questionnaire responses and supporting materials.
  - Cloud computing reviews were conducted in seven banks over 9 months, starting August 2021.
  - In 2023, a cross-sector review was conducted on technology currency risk monitoring, resulting in a comparative analysis shared with nine target institutions.
  - OSFI concluded a review on business continuity and disaster recovery plans in 8 SMSBs, with an industry letter summarizing results sent in May 2024.
  - In the fall of 2024, a cross-sector monitoring review was scheduled to be conducted on third-party risk and criticality rating methodologies.
- Tools used by banks:
  - Banks use risk and control self-assessments, key risk indicators, scorecards, data on internal and external loss events, and penetration testing to measure, identify and manage operational risk and build resilience.
- EC2 (Board oversight and functions):
  - OSFI’s Corporate Governance Guideline expects the board to approve and oversee business plans and key policies, generally including operational risk and resilience policies, and to provide challenge, advice and guidance to senior management.
  - 2016 Guideline E-21 expects operational risk management to be fully integrated within the institution’s overall risk management function; first line of defense responsible for day-to-day operations and identifying and managing inherent operational risks.
  - OSFI supervisors assess board and senior management adherence through monitoring and reviews; supervisory view feeds bank’s ORR.
- EC3 (Identification and mapping of critical operations):
  - 2024 Guideline E-21 clearly articulates expectation that banks identify critical operations and map internal and external dependencies necessary for delivery of critical operations through disruption.

*Source: 1canea2025007-source-pdf - 1. Frequently updating and assessing stress test results for short-term and longer-term*

### Section 3.1 of the Guideline expects that critical operations mapping should:

### Section 3.1 — Expectations and Supervisory Findings on Operational Resilience (critical operations mapping, response/recovery, testing, ICT, reporting, third-party, change management)

### Critical operations mapping (Section 3.1 expectations)
- Guideline expectation: critical operations mapping should:
  - View critical operations end to end;
  - Consider people, technology, processes, information, facilities, third parties, and connections or dependencies among them;
  - Focus on the activities that are needed to deliver the critical operations; and
  - Identify vulnerabilities, which can inform scenario testing for operational resilience.
- Deadline for banks to meet these expectations: September 2026.
- OSFI observation: some of the larger banks already do some of what is expected regarding the mapping of critical operations.
- From supervisory reviews: banks’ business continuity plans and business impact analyses already highlight the most critical functions and systems.
- Regulatory deadline for identification of critical operations and completion of mapping dependencies from end-to-end: 1 September 2026.

### Response and recovery planning (EC4) — expectations and supervisory practice
- Supervisor expectation (EC4): banks develop and implement response and recovery plans to manage incidents that could disrupt the delivery of critical operations in line with the bank’s risk appetite and tolerance for disruption; continuously improve incident response and recovery plans by incorporating lessons learnt from previous incidents.
- Guideline references:
  - Sections 4.1, 4.2 and 4.3 of 2024 Guideline E-21 Operational Risk and Resilience — expectations for business continuity risk management, disaster recovery risk management and crisis management.
  - Guideline B-13 Technology and Cyber Risk Management, July 2022 — additional expectations for disaster recovery plans.
- Key expectations for response and recovery plans include:
  - Establishing protocols for invoking plans;
  - Setting recovery time targets;
  - Developing internal and external communication plans;
  - Testing plans and addressing gaps;
  - Developing failover and backup plans; and
  - Undertaking lessons learned.
- Incident reporting and post-incident process:
  - Incidents are reported to OSFI under the Advisory Technology and cyber incident reporting;
  - Once the incident is contained, institutions are expected to provide OSFI with a post-incident report and lessons learned;
  - Supervisors frequently identify weaknesses via incidents that may result in OSFI issuing a supervisory letter with findings and recommendations; recommendations and subsequent banks’ actions are closely followed-up and registered in the supervisory system Vu;
  - Supervisors test if the bank’s remediation is effective and sustainable before closing the recommendation.

### Scenario testing and exercises (EC5)
- Guideline expectation: 2024 Guideline E-21 expects financial institutions to conduct regular scenario testing to ensure critical operations’ tolerances remain within their tolerances for disruption.
- Deadline for completing testing: September 2027.
- Supervisor requirement (EC5): banks conduct business continuity exercises under a range of severe but plausible scenarios to test their ability to deliver critical operations through disruption.
- Supervisor review focus:
  - Quality and comprehensiveness of business continuity and disaster recovery plans to assess ability to deliver critical operations and minimize losses and interruptions (including service provider disruptions and disturbances in payment and settlement systems).
- Supervisory review scope (business continuity and disaster recovery):
  - Business continuity plan testing, including a range of severe but plausible scenarios such as prolonged disruptions and disruptions involving critical third parties;
  - Processes and methodologies for business continuity plan testing to validate effectiveness under a range of severe but plausible scenarios;
  - Disaster recovery testing scenarios and associated test plans and procedures to validate effectiveness under a range of severe but plausible scenarios and of environments;
  - Whether bank periodically tests the disaster recovery scenarios using a risk-based approach;
  - Whether the bank ensures that offline backups are available and regularly tested for all critical assets;
  - Whether the bank develops and implements a training and awareness program for disaster recovery.

### ICT and cyber resilience (EC6)
- Requirement (EC6): laws, regulations or the supervisor require banks to implement a robust information and communication technology (ICT) framework (including cyber security) within their operational risk management framework and operational resilience approach.
- Supervisor determines banks have established appropriate policies and processes to identify, assess, mitigate, monitor and manage ICT risks; board oversight and senior management responsibilities specified.
- Guideline references and tools:
  - OSFI’s Guideline B-13 Technology and Cyber Risk Management — expectations and outcomes including:
    - Technology and cyber risks governed through clear accountabilities and structures, and comprehensive strategies and frameworks;
    - A technology environment that is stable, scalable, and resilient, kept current and supported by robust and sustainable technology operations and recovery processes;
    - A secure technology posture that maintains the confidentiality, integrity, and availability of banks’ technology assets.
  - OSFI’s Advisory Intelligence Led Cyber Resilience Testing (I-CRT) Framework, April 2023 — requires D-SIBs to conduct Intelligence-led cyber resilience testing using targeted threat intelligence to simulate advanced tactics, techniques, and procedures.
  - OSFI leverages industry standards and best practices including NIST, CoBiT, COSO and ISO 27001.
- OSFI assessments check that banks:
  - Establish a technology and cyber risk framework that includes policies, standards and processes governing technology and cyber risk;
  - Establish processes to identify security risks and vulnerabilities;
  - Classify and protect data;
  - Maintain continuous situational awareness; and
  - Conduct intelligence-led testing.
- OSFI information sources for cyber threat landscape:
  - OSFI Advisory Technology and Cyber Security Incident Reporting (first published March 2019, refreshed August 2021);
  - G7 Cyber Expert Group (monthly touch base);
  - US Treasury Cyber Forum (monthly);
  - Federal Financial Sector Technology and Cyber Forum (CFACT);
  - Canadian Centre for Cyber Security (bi-weekly and monthly meetings);
  - Canadian Financial Resiliency Group (CFRG), a public-private sector forum.
- OSFI engagement with cloud providers: occasionally meets with cloud providers (for example, Google, Microsoft, Amazon), although OSFI does not regulate them.

### Monitoring, loss data, metrics and reporting (EC7 and EC8)
- EC7 expectations: supervisor assesses whether banks have processes and effective information systems to:
  - (a) regularly monitor operational risk profiles and material operational exposures;
  - (b) compile and analyze operational risk event data, which include internal loss data, and, when feasible, external operational loss event data; and
  - (c) facilitate appropriate reporting mechanisms at the board, senior management, independent risk function and business unit levels.
- Observations and supervisory practice:
  - Tier 1 and 2 banks submit board material to OSFI quarterly in the monitoring package, including Operational Risk Committee reports — supervisors can monitor banks’ risk profiles, material loss exposures, and reporting mechanisms.
  - OSFI collects quarterly internal loss data for the six D-SIBs, providing insights into each D-SIB’s ability to collect and compile loss data.
  - Execution risk in manual errors is the most frequent loss event in Canada.
  - OSFI plans to initiate work to refine the operational risk loss data reported by banks, and to expand the requirement to Tier 2 banks and insurance companies.
  - Incident reporting and operational risk loss events reporting are not compared at any stage, because they are triggered for different reasons.
  - In 2022, due to implementation of Basel III and the use of the Internal Loss Multiplier (ILM) in calculating operational risk capital using the standardized approach under Chapter 3 the CAR guideline, banks were requested to have the adequacy of controls/processes/systems supporting this calculation assessed by an external consultant using an Assessment Tool Operational Risk Capital; OSFI provided oversight and issued interim supervisory letters with recommendations.
  - Assessors’ view: OSFI should periodically review the processes related to banks’ operational risk internal loss database, not only at the inception of the use of the ILM.
  - OSFI uses internal loss data, incident trends, and effectiveness of an institution’s response to events to help assess effectiveness of management and control systems.
  - Information on banks’ internal loss data is currently available through Power BI to help supervisors in monitoring operational risk.
  - OSFI initiated a project to develop some non-financial risk metrics covering domains such as business continuity, third-party, cyber and technology, expected to be implemented for a selected number of institutions by mid-2025.
  - In monitoring, OSFI examines how reported losses fit in banks’ risk appetite and conducts peer reviews.
  - For reviews, criteria grids are developed to help ensure consistency of assessments.
- EC8 expectations and practice (incident reporting):
  - OSFI’s Advisory Technology and Cyber Security Incident Reporting, refreshed August 2021, outlines requirements for banks to report technology and cyber incidents to OSFI within 24 hours, including incidents that could disrupt critical operations; OSFI encourages reporting of incidents that are uncertain or do not meet criteria.
  - Incident management resourcing: dedicated team in Technology Risk Division grew from one person to five in the past two years.
  - Incident volumes and composition:
    - Annually, around 2,000 incidents are reporting;
    - 80 percent related to technology and 20 percent on cyber (for example, malware);
    - One third of the reported incidents involve a third-party service provider.
  - Incident reporting initiated in 2019.
  - Institutions do not quantify the losses from reported technology and cyber security incidents, and the operational risk loss events data does not identify technology or cyber-related losses.

### Third‑party risk management (EC9)
- EC9 expectations: laws, regulations or the supervisor require the board and senior management to understand risks associated with bank activities performed by service providers and ensure effective policies/processes to manage these risks; supervisor determines banks’ third-party risk management policies should cover items (a) through (h) as listed in the source (due diligence; structuring; managing/monitoring; control environment and register; managing dependencies; contingency planning and exit strategies; comprehensive contracts/SLA; right to inspect and supervisor access).
- Guideline reference: OSFI’s Guideline B-10, Third Party Risk Management, April 2023 — articulates expectations including:
  - Due diligence considerations such as service provider’s experience, technical competence and capacity, financial strength, and information security programs;
  - Specific considerations for contracts, including roles and responsibilities;
  - Criteria to assess criticality of the service provider;
  - Requirement to develop comprehensive contingency and exit plans;
  - Consideration of third-party outages in banks’ business continuity plans.
- Observations and limitations:
  - Guideline B-10 superseded a previous OSFI guideline on outsourcing from around 2008.
  - OSFI does not have legal authority to inspect third-party providers of core banking services and require corrective actions; it would rely on banks to access service provider documentation and data, which aligns with item “h” though banks’ inspection on service providers is at its infancy.
  - OSFI has not yet concluded a bank-specific review taking into account Guideline B-10. For 2024, a review of how a bank’s first line of defense executes the third-party framework is being conducted; a cross-sector review encompassing 9 institutions focusing on third-party monitoring will be conducted; OSFI conducted third-party reviews for two D-SIBs in 2024.
  - Considering the recency of Guideline B-10 and practical difficulties for banks to establish effective policies with third parties (ownership/confidentiality of data, monitoring, managing dependencies), banks in Canada are not yet meeting all the requirements of the updated guideline; work is progressing.

### Change management (EC10) — introduction
- EC10 expectation: supervisor determines that senior management has established a change management process that is comprehensive, appropriately resourced, adequately divided between risk management and control functions, and conducive to assessment of potential effects on delivery of critical operations and their interconnections and interdependencies.
- Context note from source: a bank’s operational risk exposure evolves when it initiates change (examples provided); change management should assess evolution of associated risks throughout the full life cycle of a product or service.

*Source: Section 3.1 and related EC descriptions from the supplied PDF chapter/section.*

### Section 2.5 of Guideline B-13 Technology and Cyber Risk Management, of July 2022,

### Section 2.5 of Guideline B-13 Technology and Cyber Risk Management, of July 2022

### Expectations on change and release management
- Articulates expectations for IT change and release management; section 4.4. of the 2024 Guideline E-21 Operational Risk Management and Resilience articulates expectations for change management.
- Effective change management processes should align with general expectations for operational risk management set out in section 2, which includes risk appetite and limits, policies and procedures, and monitoring tools to evaluate risks and controls.
- Outcome objective: minimization of disruption.
- Supervisory assessment methods: monitoring, reviews, and investigations of incidents.
- Evidence provided to assessors: an OSFI criteria matrix previously used to assess change management in banks, and evidence of a supervisory recommendation issued on IT change management.

### Supervisory work on third-party concentration risk (AC1 / AC2)
- AC1 requirement: supervisor regularly identifies common points of exposure across banks to operational risk or potential vulnerability (examples cited: common service provider reliance, disruption to payment and settlement service providers, exposures from physical risks or geopolitical events).
- AC2 requirement: supervisor assesses concentration risk-related arrangements and potential systemic risks from concentration of services provided by specific service providers to banks within its jurisdiction.

Findings and actions:
- In 2022, OSFI started collecting third-party data to assist understanding systemic concentration risk.
- First data call: issued early 2022; collected information at the contract level as of January 31, 2022, including supplier name, supplier’s parent company, location of services, risk rating, and subcontractors.
- Second data call: issued in the fall of 2023; collected data as of September 20, 2023; information collected expanded to include cloud service providers, location of data storage and whether the service provider supported critical services.
- A third data call is planned for early 2025; the template for the third data call is being enhanced, with the removal of redundancies.
- Coverage:
  - First data call collected information from 16 federally regulated financial institutions (FRFIs), including the six D-SIBs.
  - Second data call collected data from 29 FRFIs (some of them are not banks).
- Data quality:
  - Phase 2 data quality improved but still contains inconsistencies (examples: multiple variations of the same third-party name and missing parent company).
  - OSFI is considering developing a list of potential providers to assist with data quality and is developing a level 2 taxonomy.
- Use of collected information:
  - Preliminary assessments of concentration risk in third-party service providers were conducted, including counting the number of FRFIs with the same supplier, considering the direct third party and the third party’s parent and geography.
  - Information is being used to help identify impacted financial institutions when there are incidents at third parties.
  - OSFI plans to share with banks information about third-party concentration.
- Additional supervisory engagement: meetings with banks to inquire about internal contingency plans on third parties.
- OSFI note: all banks have components of core activities being outsourced (example given: payments).

Limitation:
- OSFI does not have legal authority to inspect third-party providers of core banking services and require corrective actions (assessors note this is not a CP25 requirement but suggest OSFI could explore mechanisms to increase legal and regulatory power over third-party providers).

### Regulatory developments and supervisory expectations (Principle 25 context)
- Assessment of Principle 25: Largely Compliant.
- OSFI has issued updated guidance:
  - Guideline E-21 Operational Risk and Resilience, issued in August 2024, expands the 2016 Guideline E-21 Operational Risk Management to include expectations related to operational resilience and contributors such as business continuity management, disaster recovery, change management, and data risk management.
  - The 2024 Guideline E-21 is gradually entering into force and full adherence is expected by September 1, 2026.
  - OSFI expects banks to have completed identification, mapping and setting tolerances for disruption of their critical operations and to have developed scenario testing methodology and begun testing so that, by September 1, 2027, testing has been completed for all critical operations.
- ORR process:
  - New ORR process includes “Operational resilience” as a separate risk factor; subcategories “Technology,” “Cyber” and “Operations” can drive a bank’s rating for this category and potentially the final ORR because there are no fixed weights in the rating system.
- Supervisory activity:
  - Supervisory reviews of non-financial risks (technology and cyber risks, business continuity) are more frequent compared to credit and liquidity risks.
  - Cross-sector reviews are used to assess progress on operational resilience topics.
- Ongoing gaps:
  - Implementation of procedures and best practices related to business disruptions and disaster recovery; identification and mapping of critical operations and systems; and understanding risks from third-party service providers, is described as a work in progress.
  - Supervisory reviews and monitoring actions in more traditional aspects of operational risk are warranted (example: review of processes related to the operational risk internal loss database and linking reported incidents to registered losses).

Recommendations (Principle 25):
- Continue the development of supervisory practices on emerging issues related to operational resilience to achieve full implementation of OSFI’s principles-based guidelines and sponsor best practices in banks.
- Conduct supervisory reviews focused on more traditional aspects of operational risk identification, evaluation, and management, including on banks’ operational risk loss database, to increase market discipline and assurance that operational risks are prudently measured.
- Explore the possibility of linking incident reporting to the operational risk loss database, by exploring the quantification of losses from incidents or by requiring that technology and cyber-related losses are identified in the operational risk loss database, to contribute to an integrated evaluation of operational risk and operational resilience.

### Internal control, compliance, and internal audit (Principle 26)
- Assessment of Principle 26: Largely Compliant.
- Principle 26 summary: supervisor determines banks have adequate internal control frameworks, including delegation of authority, separation of functions, reconciliations, safeguarding assets, and appropriate independent internal audit and compliance functions.

Key supervisory expectations and findings:
- EC1: Laws, regulations or the supervisor require banks to have internal control frameworks adequate to establish an effectively controlled and tested operating environment; responsibilities rest with the bank’s board and/or senior management.
  - Bank Act section 193 details minimum requirements on Committees of the Board.
  - OSFI’s Corporate Governance Guideline expects Board approval of the Internal Control Framework and oversight functions’ mandates, resources and budgets.
- EC2: Appropriate balance in skills and resources of back office, control functions and operational management.
  - OSFI guidance: Guideline E-21 (June 2016), Guideline B-13 (July 2022), Guideline E-21 (August 2024) emphasize adequate resourcing for control functions.
  - New supervisory framework (ORR) assesses banks in Tiers 1 to 4 against risk categories including “Risk governance” with subcategory “Risk and compliance oversight.”
  - Internal supervisory guides exist to ensure consistency when assessing “Risk and compliance oversight.”
  - Supervisory practice: regular monitoring and focused reviews, with on-site deep reviews conducted when identified by monitoring.
  - Example: a significant compliance function review completed 3 years ago led to a remediation plan; August 2024 cross-sector Internal Audit review included more than 30 institutions and resulted in important findings.
  - Assessors recommend increasing the number of deep reviews to test effectiveness and verify adherence to internal control and audit policies.
- EC3: Adequately staffed, permanent and independent compliance function with board oversight.
  - OSFI’s Corporate Governance Guideline and Guideline E-13 Regulatory Compliance Management (November 2014) set expectations for the compliance function, including the CCO having a clearly defined mandate, unfettered access, and for functional purposes a direct reporting line to the Board.
  - Culture & Compliance Risk Division (CCRD) assesses compliance risk and board oversight; all banks except the smallest operate a segregated compliance function with dedicated CCOs.
- EC4 / EC5: Independent, permanent and effective internal audit function with sufficient resources, independence, authority, methodology, audit planning, and access to assess outsourced functions.
  - Subsection 157(2) of the Bank Act requires an audit committee.
  - Corporate Governance Guideline: audit committee should approve audit plans; internal audit plans should be risk-based and address activities over a measurable cycle.
  - OSFI conducts on-site reviews of internal audit functions periodically; assessors suggest these reviews should be more frequent.
  - OSFI’s Guideline B-10 Third-Party Risk Management (April 2023) under 2.3.3.3 expects the bank and OSFI be able to evaluate risks arising from arrangements and access audit reports.
  - ORR Scorecard attributes for “Internal Audit” include: Independence and influence; Delivery and execution; Findings and reporting.
  - Supervisory monitoring: quarterly and ongoing meetings with Chief Internal Auditor for D-SIBs and higher risk SMSBs; monitoring packages include sample audit reports, Audit Committee reports, annual audit plans, strategies, resource plans, and audit function self-assessments.

Recommendation (Principle 26):
- Increase the number of bank-specific and deep on-site reviews on internal control and audit to test effectiveness and verify adherence to internal controls and regulatory compliance frameworks, fostering implementation of adequate practices in banks.

### Financial reporting and external audit (Principle 27) — selected context
- Principle 27: supervisor determines banks maintain adequate and reliable records, prepare financial statements in accordance with accounting policies widely accepted internationally, publish information that fairly reflects financial condition and performance, and bear an independent external auditor’s opinion; supervisor also determines governance and oversight of external audit.
- EC1: supervisor holds board and management responsible for ensuring financial statements are prepared in accordance with accounting policies and practices widely accepted internationally and supported by recordkeeping systems.
- Legal and standard-setting context:
  - Bank Act section 308(4) establishes financial statements are prepared under Generally Accepted Accounting Principles (which are IFRSs for federally regulated financial institutions) except as otherwise specified by the Superintendent.
  - Canadian Accounting Standards Board (AcSB) is the accounting standard-setter; AcSB is overseen by the Reporting & Assurance Standards Oversight Council (RASOC); OSFI has a seat in RASOC.
  - There is not any significant difference between IASB IFRSs and AcSB GAAP; CPA handbook incorporates IFRS and assurance standards based on International Auditing Standards.
  - For banks that have issued listed securities (all D-SIBs and several SMSBs), securities regulators require financial statements prepared in accordance with the exact version of the IFRS as issued by the IASB.

*Source: Section 2.5 of Guideline B-13 Technology and Cyber Risk Management, of July 2022 (as excerpted in the supplied content).*

### Section 308 of the Bank Act requires the Board of a bank to place before the shareholders at

### Section 308 of the Bank Act requires the Board of a bank to place before the shareholders at every annual meeting

### Audit and financial statement requirements (Section 308, 323, 326)
- Section 308 requires the Board to place before shareholders at every annual meeting:
  - “(a) a comparative annual financial statement (in this Act referred to as an “annual statement”) relating separately to (i) the financial year immediately preceding the meeting, and (ii) the financial year, if any, immediately preceding the financial year referred to in subparagraph (i);
  - (b) the report of the auditor or auditors of the bank; and
  - (c) any further information respecting the financial position of the bank and the results of its operations required by the by-laws of the bank to be placed before the shareholders or members at the annual meeting.”
- Financial statements are signed by the CEO and one Board director (Section 309).
- Bank Act section 323(2) requires external audits to be conducted in accordance with generally accepted auditing standards (GAAS) as set out in the Handbook of the Chartered Professional Accountants of Canada; Canadian Auditing Standards are aligned with International Standards on Auditing (ISAs).
- Bank Act section 326(2) requires auditors to state whether, in their opinion, the annual statement presents fairly, in accordance with the accounting principles referred to in Bank Act section 308(4), the financial position and results for the financial year.

### OSFI reliance on auditors, scope, and supervisory interaction
- OSFI relies on independent and qualified accountants to opine whether financial statements are prepared in all material respects in accordance with IFRS; the audit opinion (qualified or unqualified) indicates adequacy of recordkeeping systems and internal controls.
- Deficiencies in recordkeeping or data would result in qualified or adverse opinions; supervisors review annual financial statements and audit opinions for compliance.
- OSFI may require assurance services beyond the audit for liquidity monitoring, valuations in sale or purchase of assets, credit risk file review, governance and risk management; commissions are subject to conflict-of-interest criteria.
- Banks usually pay for audits, but OSFI defines the audit scope and is in charge of the audit; by Subsection 325(4) of the Bank Act, audit expenses are payable by the bank on being approved by the Superintendent.
- For D-SIBs, a representative from OSFI’s Accounting Policy Division normally attends quarterly meetings with external auditors and with the CFO; Accounting Policy Division assists LS teams to interpret and monitor auditing findings and accounting questions.
- OSFI receives all Board of Director materials, including communications from the auditor to the Audit Committee, and meets with auditors as required; OSFI engages regularly with external auditors on crisis management.

### Valuation practices and accounting standards (EC3, EC5)
- IFRS is the basis for both external and regulatory reporting for interim and annual financial statements; Bank Act requires preparation and audit under IFRS including IFRS 13 Fair Value Measurement.
- Auditors provide an opinion that financial statements are prepared in all material respects in accordance with IFRS.
- Banks submit capital returns that reconcile financial reporting and capital reporting (Schedule 10.070 of the BCAR regulatory returns contains a reconciliation of risk exposures with balance sheet items); differences are disclosed as part of Pillar III reporting.
- OSFI has issued guidance on applying IFRS 9 and guidance for expected credit losses provisioning (IFRS 9: Financial Instruments and Disclosures).

### Audit scope, standards, and supervisory powers (EC4, EC5, EC6)
- CAS 315 Identifying and Assessing the Risk of Material Misstatement requires a risk-based approach; CAS 320 Materiality in Planning and Performing an Audit requires a materiality-based approach.
- The Superintendent may, pursuant to Section 325 of the Bank Act, require enlargement or expansion of the scope of an external audit, or require a special audit.
- Bank Act section 317(2) provides the Superintendent the power to revoke the appointment of an auditor at any time; OSFI has not recently exercised this power but would do so in cases such as low-quality audit and would report to CPAB.

### Auditor independence, rotation, and restrictions on non-audit services (EC6, EC7)
- Auditors must be independent and abide by Canadian provincial and territorial independence rules; audit firms in international networks also conform with the International Code of Ethics for Professional Accountants.
- OSFI does not have legislative powers to require auditor rotation of firms; professional accounting bodies adopted Rule 204.4(20) Harmonized rule of professional conduct requiring audit partner rotation every 7 years followed by a 5-year cool down period.
- In practice banks generally rotate partners and not firms; one large systemically important bank changed its large auditing firm 9 years ago (rare event).
- Harmonized Rule 204 contains restrictions on non-audit services to protect independence; OSFI supervises audit committee charters as part of risk governance reviews.
- Restrictions in Harmonized Rule 204 include services related to:
  - Valuation services (Rule 204.4(25)(a)-(b))
  - Actuarial services (Rule 204.4(26))
  - Internal Audit services (Rule 204(27)(a)-(b))
  - IT services (Rule 204(28)(a)-(b))
  - Litigation services (Rule 204(29)(a)-(b))
  - Legal services (Rule 204(30)-(31))
  - HR services (Rule 204.4(32))
  - Corporate finance services (Rule 204.4(33))
  - Tax services (Rule 204(34)(a)-(b))

### Engagement with external auditors and Auditor Advisory Committee (EC8)
- OSFI’s examination methodology includes periodic meetings with external audit firms to discuss common interest issues; meetings are quarterly for D-SIBs and ad hoc for SMSBs.
- Once a year OSFI receives well-being reports ordained by Section 328 of the Bank Act.
- OSFI meets periodically (at least twice a year) with the Auditor Advisory Committee (AAC), consisting of lead audit and lead technical partners of the big four accounting firms (PwC, Deloitte, E&Y, KPMG).

### Auditor reporting to supervisor and legal privilege (EC9, AC1)
- Bank Act section 328(1) requires the auditor to report in writing to the bank any transactions or conditions affecting the well-being of the bank that are not satisfactory and require rectification; Section 328(2)(d) requires the auditor to provide the Superintendent with a copy of such report. These reports are issued every year for every institution.
- Bank Act section 333 provides that any report under the Act by the auditor has qualified privilege.
- Bank Act section 643(2) states the Superintendent has a right to access any records and may require the auditor to provide information and explanations regarding the condition and affairs of the banks; OSFI recently received and reviewed audit working papers for ECL for several large and medium-sized banks to evaluate judgement and rules for migration to Stage 2.

### Assessment and compliance (Principle 27)
- Assessment of Principle 27: Compliant.
- Comments:
  - OSFI relies on independent and qualified accountants to opine whether financial statements are prepared in all material respects in accordance with accounting standards and provide a true and fair view of banks and banking groups.
  - Canadian accounting standards applicable to listed banks are IFRS as issued by the IASB; Canadian GAAP applicable to the few unlisted federal banks are also based on IFRS with no material deviations.
  - External auditors must be independent and follow independence standards with partner rotation and cooling-off periods; internal policies of banks’ audit committees and auditing firms reflect these standards.
  - OSFI and external auditors meet frequently and collaborate on accounting policy standard setting.

### Disclosure and Transparency (Principle 28) — public disclosures and Pillar 3
- EC1 findings:
  - Banks are required to prepare annual financial statements that follow IFRS, requiring consolidated preparation and specific disclosure requirements; financial statements are available to the public for publicly listed banks.
  - OSFI requires all banks to follow Basel III Pillar 3 disclosures and OSFI disclosure requirements set out in various OSFI Guidelines, such as Guideline IFRS 9 Financial Instruments and Disclosures.
  - OSFI practices consolidated supervision and requires disclosures on a consolidated basis; OSFI posts key financial data including the income statement and the statement of financial position on its website as required under Section 639 of the Bank Act.
  - Banks do not publicly disclose solo financial statements; OSFI receives quarterly submissions from Canadian D-SIBs on solo TLAC levels, which are not publicly disclosed by OSFI or the banks. Some Canadian D-SIBs have voluntarily disclosed compliance with solo TLAC regulatory expectations.
  - OSFI has legislative authority to require banks to issue solo financial statements if appropriate (Subsection 308(4) states a bank’s annual and certain other financial statements shall, except as otherwise specified by the Superintendent, be prepared in accordance with GAAP, which are IFRSs for banks).
  - OSFI discloses consolidated data for every bank on its financial data page on a quarterly and monthly basis as required under section 609 of the Bank Act, within 45 days of the reporting period.
- OSFI issued Pillar 3 Disclosure Guideline for Domestic Systemically Important Banks (D-SIBs) – Guideline (2024) and Pillar 3 Disclosure Guideline for Small and Medium-Sized Deposit-Taking Institutions (SMSBs) – Guideline (2024); these complement earlier Pillar 3 guidelines and implement a proportional framework for SMSB disclosures.
- OSFI set expectations for Canadian D-SIBs to implement risk disclosure recommendations from the FSB’s Enhanced Disclosure Task Force (EDTF) Report (October 2012); EDTF has 32 recommendations. OSFI allows removal of EDTF disclosures effectively covered by Pillar 3 templates but expects retention of EDTF disclosures not covered.
- OSFI established additional disclosure expectations to address prudential risks in Canada, for example increased disclosures on residential mortgage underwriting practices via Guideline B-20 Residential Mortgage Underwriting Practices and Procedures.

*Source: 1canea2025007-source-pdf - Section 308 of the Bank Act requires the Board of a bank to place before the shareholders at every annual meeting.*

### Chapter 2 of the IFRS Conceptual Framework for IFRSs addresses the qualitative

### Chapter 2 of the IFRS Conceptual Framework for IFRSs addresses the qualitative

### Qualitative characteristics: timeliness, relevance, reliability
- Timeliness
  - Preparers are required to comply with Chapter 2 of the IFRS Conceptual Framework.
  - Subsection 308(1) of the Bank Act requires all banks to present their financial statements to their shareholders at every annual meeting which, pursuant to paragraph 137(1)(a), is to be held not later than six months after the end of each financial year.
  - Timeliness of issuance for publicly listed banks is further dictated by securities regulators.
- Relevance
  - Chapter 2 of the IFRS Conceptual Framework addresses the qualitative characteristics of useful financial information.
- Reliability
  - Subsection 308(1) of the Bank Act requires every bank to have a report from an auditor on the annual financial statements.

### OSFI specification of IFRS options and additional disclosure
- Legal and standard basis
  - Where options are available for different accounting treatments or disclosures, OSFI can dictate one specific accounting treatment as per Subsection 308 (4) of the Bank Act.
  - OSFI’s ability to make specifications for additional disclosure or to specify an IFRS option is addressed in ISA 210 and CAS 210.
- Practice and examples
  - OSFI makes specifications in rare situations where there is a strong prudential need for additional accounting guidance, while remaining consistent with IFRS.
  - Guideline example: Guideline IFRS 9: Financial Instruments and Disclosures restricts use of the Financial Instruments Designated as Fair Value Option for:
    - loans to companies having annual gross revenue below $75 million,
    - loans to individuals,
    - portfolios made up of such loans.

### Disclosure scope and Pillar 3 (EC2)
- Supervisor expectations
  - Required disclosures include qualitative and quantitative information on: financial performance, financial position, risk management strategies and practices, risk exposures (including information that will help in understanding a bank’s risk exposures during a financial reporting period), aggregate exposures to related parties, transactions with related parties, accounting policies, business models, management, governance (including major share ownership and voting rights) and compensation practices.
  - Scope and content and level of disaggregation are commensurate with the risk profile and systemic importance of the bank.
  - For internationally active banks, disclosure requirements are not less stringent than the applicable Basel standards.
- OSFI implementation and findings
  - OSFI’s Guidelines on Pillar 3 address qualitative and quantitative information on risk management strategies and practices, risk exposures, business, management, governance and remuneration.
  - Pillar 3 guideline for D-SIBs implements the standards for internationally active banks; D-SIBs are expected to retain high levels of public confidence and public disclosure practices covering financial condition and risk management activities.
  - Pillar 3 guideline for SMSBs establishes disclosure expectations applied proportionately; SMSBs are expected to retain high levels of public confidence with disclosure appropriate for their risk profile, nature, size, and complexity.
  - All IFRSs address qualitative and quantitative disclosure requirements on financial performance and financial position; IAS 24 addresses aggregate exposures to related parties and transactions with related parties.
  - OSFI’s additional disclosure requirements include Guideline IFRS 9: Financial Instruments and Disclosures and Guideline B-20 Residential Mortgage Underwriting Practices and Procedures.

### Disclosure of group structure (EC3)
- Legal requirements
  - Section 308(3)(a) of the Bank Act requires disclosure of all material entities in the group structure in the bank’s annual statement.
  - IFRS 12 Disclosure of Interest in other Entities includes disclosure requirements of subsidiaries.
- Practice
  - Banks provide disclosure of material subsidiaries in annual financial statement notes and annual information forms.

### Review and enforcement of disclosures (EC4)
- Audit and review
  - Disclosures in annual reports are either audited or, if not in the financial statements but part of the annual report, are reviewed by external auditors as per IAS 720 “The auditor's responsibilities relating to other information in documents containing audited financial statements.”
- Pillar 3 compliance requirements under OSFI Guideline
  - Pillar 3 information must be subject, at a minimum, to the same level of internal review and internal control process as the information provided for financial reporting (i.e., same level of assurance as for information in management discussion and analysis).
  - The internal audit function should review compliance with the guideline on initial application and subsequently on a periodic basis. The initial review should be conducted within one year after implementation of this Guideline. Subsequent reviews should be conducted on a periodic basis consistent with the institution’s normal reporting verification cycle.
  - Issues of non-compliance will be addressed by OSFI on a case-by-case basis through bilateral discussions with the institution.
- Parliamentary reporting
  - Section 642 of the Bank Act requires the Superintendent to prepare an annual report to Parliament respecting disclosure of information by banks and describing progress in enhancing disclosure in the financial services industry.
- Supervisory action
  - Assessors had evidence of examples in which OSFI acted to ensure adequacy of banks’ disclosures.

### Aggregate publication of banking-system information (EC5)
- OSFI publications and timelines
  - OSFI publishes aggregate banking system information on its website on a quarterly and monthly basis as required under section 609 of the Bank Act within 45 days of the reporting period.
  - Aggregate information includes monthly consolidated balance sheet and quarterly data on: the consolidated balance sheet, the consolidated statement of comprehensive income, allowances for expected credit losses, BCAR capital components, and BCAR derivative components.
- Bank of Canada publications
  - The BoC issues weekly financial statistics for banks and more comprehensive financial statistics on a monthly basis.
- Open data initiative
  - OSFI is moving public disclosures to OpenGov: https://open.canada.ca/en to make data fully searchable and downloadable.
  - OSFI plans to complete this project within approximately 6–12 months.
  - The first stages will transfer “Who We Regulate” and “Financial Data for Banks” information (aimed for end of the 2024 fiscal year) and insurance data shortly thereafter.

### Assessment and overall comments
- Assessment of Principle 28: Compliant
  - The Pillar 3 international standards have been implemented by OSFI, with proportional application via SMSB segmentation and specific guidelines.
  - Banks follow IFRS disclosure requirements in financial statements. Securities regulator disclosure requirements also apply to public issuers.
  - OSFI participates in a Canadian government initiative to improve publicly available banking system information.

### Abuse of financial services; AML/CFT supervisory roles (Principle 29, EC1–EC2)
- Allocation of responsibilities
  - FINTRAC is Canada’s AML/CTF Supervisor and Financial Intelligence Unit under the PCMLTFA.
  - FINTRAC’s mandate (Section 40) includes ensuring compliance of reporting entities and generating financial intelligence for police, law enforcement and national security agencies to assist in investigations of money laundering, terrorist activity financing, sanctions evasion offences, and threats to the security of Canada.
  - FINTRAC is headquartered in Ottawa with regional offices in Montréal, Toronto, and Vancouver and reports to the Minister of Finance.
  - FINTRAC acts at arm’s length and is independent from police services and law enforcement agencies to which it discloses financial intelligence.
  - OSFI does not have direct supervisory responsibilities for AML/CFT compliance under the PCMLTFA; that function is entrusted solely to FINTRAC.
- Interaction with prudential supervision
  - OSFI remains attentive to prudential implications of AML/CFT non-compliance and criminal activities.
  - When FINTRAC identifies serious or repeated deficiencies, OSFI may factor those findings into its supervisory assessment of a bank’s risk control environment, governance effectiveness, and compliance culture.
  - OSFI may initiate supervisory action if deficiencies point to broader weaknesses that could compromise safety and soundness.
  - Guideline E-13 on Regulatory Compliance Management and the Corporate Governance Guideline require institutions to maintain robust compliance frameworks and promote a culture of integrity, including managing AML risks appropriately.
- FINTRAC activities
  - Receiving financial transaction reports and voluntary information in accordance with the PCMLTFA and Regulations;
  - Safeguarding personal information under its control;
  - Ensuring compliance of reporting entities with the PCMLTFA and Regulations;
  - Maintaining a registry of money services businesses in Canada;
  - Producing financial intelligence relevant to investigations of money laundering, terrorist activity financing, sanctions evasion, and threats to the security of Canada;
  - Researching and analyzing data from a variety of information sources that shed light on trends and patterns in money laundering and terrorist activity financing;
  - Enhancing public awareness and understanding of money laundering and terrorist activity financing.
- International collaboration
  - FINTRAC is part of the Egmont Group and contributes to FATF, APG and CFATF multilateral fora.
- Reporting entity scope under PCMLTFA Section 5 (excerpted list)
  - All Canadian banks, foreign banks in Canada, and full service and lending foreign bank branches in Canada (established under the Bank Act and regulated by OSFI);
  - Financial services cooperatives, savings and credit unions and caisses populaires regulated by a provincial Act; credit union centrals when they provide services to any person or entity that is not a member;
  - Trust companies and loan companies regulated under the federal Trust and Loan Companies Act or an equivalent provincial Act;
  - Unregulated trust companies;
  - Departments, agents and mandataries of the Crown that accept deposit liabilities when providing financial services to the public.

*Source: Chapter content from the provided PDF.*

### 6. Life insurance companies, or entities that are life insurance brokers or agents, in respect

### 6. Life insurance companies, or entities that are life insurance brokers or agents, in respect

### Scope and exemptions
- Applies to life insurance companies, or entities that are life insurance brokers or agents, in respect of loans or prepaid payment products that they offer to the public and accounts that they maintain with respect to those loans or prepaid payment products, other than:
  - loans that are made by the insurer to a policy holder if the insured person has a terminal illness that significantly reduces their life expectancy and the loan is secured by the value of an insurance policy;
  - Loans that are made by the insurer to the policy holder for the sole purpose of funding the life insurance policy; and
  - Advance payments to which the policy holder is entitled that are made to them by the insurer.

### Reporting entities under PCMLTFA and supervisory responsibility
- Section 5 of PCMLTFA also encompasses: Accountants, British Columbia notaries, Casinos, Dealers in precious metals and precious stones, Money services businesses (including Armored cars), Mortgage administrators, brokers and lenders, Real estate brokers, sales representatives and developers, and Securities dealers.
- FINTRAC is the sole public body entrusted to carry out the functions of financial intelligence unit since 2000 and is the AML/CFT supervisor since 2021 (it was created in 2000, but prior to 2021 had delegated some supervisory responsibilities to OSFI).
- PCMLTFA requires all reporting entities, including financial institutions, to have policies and procedures to assess the risk of a money laundering or terrorist activity financing offence (PCMLTFA subsection 9.6 (2)) and to ensure compliance with PCMLTFA and its regulations (PCMLTFA 9.6(1)), including reporting suspicious transactions under PCMLTFA section 7.

### Mandatory compliance program elements (PCMLTFA 9.6(1) and FINTRAC guidance)
- Reporting entities must implement a compliance program including ongoing monitoring and reporting requirements.
- Specific elements all reporting entities must implement:
  - Appoint a compliance officer who is responsible for implementing the program
  - Develop and apply written compliance policies and procedures that are kept up to date and, in the case of an entity, are approved by a senior officer
  - Conduct a risk assessment of the entity’s business to assess and document the risk of a money laundering or terrorist activity financing offence occurring in the course of its activities
  - Develop and maintain a written, ongoing compliance training program for its employees, agents or mandataries, or other authorized persons
  - Institute and document a plan for the ongoing compliance training program and deliver the training (training plan)
  - Institute and document a plan for a review of the compliance program for the purpose of testing its effectiveness, and carry out this review every two years at a minimum (two-year effectiveness review)

- Requirements for the reporting entities’ compliance policies and procedures:
  - Written and in a form or format accessible to its intended audience
  - Kept up to date (including changes to legislation or internal processes)
  - Approved by a senior officer
  - Made available to all those authorized to act on behalf of the reporting entity (employees, agents, others dealing with clients/transactions)

- Minimum coverage required in policies and procedures:
  - Compliance program elements (compliance officer, risk assessment, training program and plan, two-year effectiveness review and plan)
  - Know your client (verifying client identity, politically exposed persons, heads of international organizations, family members and close associates, beneficial ownership, third party determination)
  - Business relationship and ongoing monitoring
  - Record keeping
  - Transaction reporting
  - Travel rule requirements (risk-based policies to determine suspension/rejection of transfers lacking travel rule information)
  - Ministerial directive requirements

- Processes and controls to document:
  - When an obligation is triggered
  - The information that must be reported, recorded, or considered
  - The procedures to ensure the reporting entity fulfills a requirement
  - Timelines and methods of reporting (if applicable)
  - Steps for obligations that require taking reasonable measures

- Tailoring and proportionality:
  - Generic industry association policies must be tailored to the reporting entity’s business
  - Level of detail depends on size, structure, complexity, and exposure to ML/TF and sanctions evasion risks

### FINTRAC organizational resources and structure
- FINTRAC main departments and full-time equivalents:
  - Intelligence (the FIU functions): 90 full-time equivalents
  - Legal: 10
  - Supervision: 12 (including support, IT and administrative staff)
- Operations division (within the Supervision sector) responsible for assistance, assessment and enforcement activities: 60 staff
- Operations division internal organization divided into four units:
  - one for non-bank financial institutions (the Financial Institutions or the FI unit),
  - one for money service businesses,
  - one for other professionals and reporting entities,
  - and the Financial Institutions (FI) unit in charge of AML/CFT supervision of banks.
- FI unit supervisory scope for banks: 35 domestic banks, 15 foreign banks, and 29 foreign bank branches.
- The FI unit that supervises all Canadian banks consists of 17 full-time equivalents and is led by an executive; team leaders focus on regulatory relationship, assessment and enforcement and comprise senior compliance officers and compliance officers.

### Supervisory activities and tools used by FINTRAC’s FI unit
- Ongoing monitoring:
  - Quarterly monitoring meetings with banks to discuss: implementation of action plans, risk profile monitoring, resolution of Voluntary Self-Declarations of Non-Compliance, new policies or regulations, and FIU intelligence perspectives
  - Annual meeting with the banking sector and regime partners to share insights and best practices
  - Off-site analysis of information and data regularly sent by banks, including:
    - organization, documentation, policies and procedures, material changes, new hires and resource changes of the CAMLO department
    - Inherent AML risk measurement (products, services, channels, geographies, technologies, methodologies, clients, business relationships, foreign affiliates)
    - Status of AML controls (control gaps, remediation, findings identified by Internal Audit or FINTRAC)
    - FIU metrics dashboard (number of alerts, unusual transaction reports UTRs, production orders created/closed/escalated, aging of alerts in 30 days buckets, percentage of conversion to investigation, percentage of STR conversion; high-risk clients metrics; number of Suspicious Transactions Reports filed; average days from reasonable grounds determination to filing)
    - Action Plan monitoring
  - FINTRAC receives periodically the report of the two-year effectiveness review (conducted every two years at a minimum by an internal or external auditor)
  - External information used: Intelligence department outputs, past enforcement action, media attention, Voluntary Self-Declarations of Non-Compliance, information from other authorities and partners
  - Monitoring insights may trigger in-depth review or request for action plan; FINTRAC rigorously checks action plan closure via second-line-of-defense and internal audit opinions and working papers and sample testing as needed

- Compliance reviews and other examinations:
  - Resource constraints result in an excessively long supervisory cycle for high-risk entities; FINTRAC is only able to perform one thorough compliance review every 6 years on each large bank
  - Senior compliance officers lead, on average, one compliance review examination each year
  - Less resource-consuming examination types introduced to increase engagement frequency:
    - Desk reviews called “blitzes” (wide in scope but superficial); modular blitzes introduced in 2022–23 (example: 2024 modular blitz on mortgage lending risks)
    - Targeted reviews focusing on a single component (e.g., electronic fund transfer rules, correspondent banking reporting quality, suspicious transactions reporting), normally triggered by ad hoc events or information
  - Thorough compliance reviews are wide in scope and deep (test effectiveness, review self-assessment reports, meet executives, perform file reviews)
  - Governance and organization evaluated with a group-wide perspective; effectiveness testing of actual records and transactions may only be conducted with client files of authorized Canadian banks due to Section 5 domestic supervisory focus
  - FI unit compliance reviews include meetings with high-level executives; interviews with more junior personnel are less frequent and risk-based

### Typical compliance review timeline and procedures
- Typical compliance review procedural timing:
  - Notification letter establishes a circa four months preparation period for the bank
  - Exam letter sent; bank has 30 days to provide documentation
  - FI unit personnel review documentation for approximately one month and sample files for file review
  - Meetings with bank executives and employees convened and held for two weeks
  - Additional evidence gathered and conclusions shared with the bank for review and comment during examination
  - After approximately three months a letter with findings and recommendations is sent
  - Bank is expected to provide an action plan for remediation; FINTRAC comments on feasibility, adequacy and deadlines and follows implementation in monitoring meetings

### Observations on supervisory effectiveness and challenges
- Case evidence: FINTRAC identified significant non-compliance in a bank in successive cycles; earlier action plans were closed but subsequent analysis identified continued high-risk bulk cash payments dating back to 2020 and unreported suspicious transactions—indicating persistent, unresolved serious compliance failures years after initial review
- Assessors’ view: the supervisory cycle is excessively long to allow for timely and effective remediation and to induce self-discipline and attention to AML compliance in banks
- FI unit’s small size and complexity of activities contribute to long supervisory cycles; senior compliance officers lead on average one compliance review annually and supervisors rotate between components

### Coordination with OSFI and other authorities
- OSFI’s role:
  - Not the designated AML/CFT supervisor for banks (role lies with FINTRAC), but plays a broader role in promoting high ethical and professional standards and ensuring institutions maintain sound compliance and governance frameworks
  - Expectations embedded in Corporate Governance Guideline, Guideline E-13 on Regulatory Compliance Management, Guideline E-17 on Background Checks
  - Issued in 2024 a new Integrity and Security Guideline following expansion of mandate; emphasizes securing banks against threats to integrity, including compliance failures, foreign interference, deliberate misconduct
  - In ongoing supervision OSFI reviews governance and risk management structures, including independence and effectiveness of compliance functions (see CP14 and CP15)
  - When AML/CFT compliance deficiencies raise concerns about prudential soundness, OSFI may adjust supervisory strategy (intervention grounded in prudential responsibilities, not AML/CFT enforcement per se)

- Information sharing and cooperation (FINTRAC–OSFI):
  - FINTRAC shares information with OSFI by means of an MoU and provides copies to OSFI of results of all its examinations on banks
  - FINTRAC and OSFI meet frequently; at minimum, quarterly formal touchpoints to discuss AML/CFT supervisory activities and findings
  - Ad hoc operational meetings occur as often as needed (weekly to monthly) for licensing, mergers and acquisitions, and operational context
  - FINTRAC’s FI Unit holds scheduled monthly touchpoints with OSFI’s Policy and Intergovernmental Affairs Division to maximize supervisory information sharing
  - FINTRAC has a tactical intelligence disclosure relationship with OSFI due to OSFI’s expanded integrity and security mandate
  - FINTRAC may disclose non-compliance to appropriate law enforcement agencies when it suspects on reasonable grounds information would be relevant to investigating or prosecuting an offence arising out of contravention of PCMLTFA
  - As FIU, FINTRAC shall disclose information under PCMLTFA section 55(1)(c) when it has reasonable grounds to suspect relevance to investigation or prosecution of money laundering, terrorist financing, or sanctions evasion

### EC3–EC5 findings summarized
- EC3: Banks report suspicious activities to FINTRAC; Section 7 PCMLTFA requires reporting where there are reasonable grounds to suspect transactions are related to money laundering, terrorist activity financing, or sanctions evasion.
- EC4: FINTRAC became sole AML/CFT supervisor in April 2021; historical coordination evolved from separate to joint examinations and now to FINTRAC sole supervisory role, with ongoing coordination and frequent information sharing with OSFI.
- EC5: CDD measures codified in Part 3 of PCMLTFR (sections 105, 109, 112), record keeping for PEP accounts in PCMLTFR s.123, and on-going monitoring in PCMLTFR section 123.1; subsection 9.6(1) and 9.6(2) and PCMLTFR sections 156 and 157 require establishment of compliance program. Key CDD programme elements include:
  - (a) customer acceptance policy identifying business relationships the bank will not accept or will terminate;
  - (b) ongoing customer identification, verification and due diligence programme, including beneficial ownership verification and risk-based reviews;
  - (c) policies and processes to monitor transactions on an ongoing basis and identify unusual or potentially suspicious transactions and individuals/entities subject to UN sanctions;
  - (d) enhanced due diligence on high-risk accounts with escalation to senior management for decisions on entering/maintaining relationships;
  - (e) enhanced due diligence on politically exposed persons including escalation to senior management;
  - (f) clear rules on records to be kept on CDD and individual transactions with at least a five-year retention period.

- FINTRAC guidance and supervisory practice require verification of identity for persons and entities and obtaining beneficial ownership information when verifying identity of an entity; guidance references include Methods to verify the identity of persons and entities, When to verify identity, and Beneficial ownership requirements.

*Source: 1canea2025007-source-pdf - 6. Life insurance companies, or entities that are life insurance brokers or agents, in respect (IMF).*

### Section 7 of the PCMLTFA outlines obligations of REs to report transactions where there is

### 1canea2025007-source-pdf - Section 7 of the PCMLTFA outlines obligations of REs to report transactions where there is

### Reporting obligations and scope (Section 7)
- REs must report transactions where there are reasonable grounds to suspect the commission or the attempted commission of a money laundering, terrorist financing and/or sanctions evasion offence.
- The sanctions evasion offence captures obligations under the United Nations and associated Security Council Resolutions.
- Compliance with the reporting obligation is supervised by FINTRAC and guidance is publicly available.
- FINTRAC may disclose cases of non-compliance to law enforcement when it suspects on reasonable grounds that the information would be relevant to investigating or prosecuting non-compliance offences under the PCMLTFA.

### Measures for high-risk clients, PEPs, and record keeping
- For high-risk clients and business relationships, REs are required to adopt prescribed special measures, including:
  - taking additional steps to verify the identity of clients;
  - taking enhanced measures to ensure that client information including beneficial ownership information is updated at a frequency that is appropriate for the level of risk;
  - conducting ongoing monitoring of business relationships at a frequency that is appropriate for the level of risk.
- PCMLTFA s. 9.3 requires REs to determine when dealing with a politically exposed person (PEP), heads of international organizations and their close associates; guidance referenced: Politically exposed persons and heads of international organizations guidance for account-based reporting entity sectors (canada.ca).
- REs must obtain the approval of senior management in prescribed circumstances and take prescribed measures as per current guidance notes.
- Record keeping requirements and responsibilities:
  - As per Section 6 of the Act and section 148 of the PCMLTFR, the general retention period is at least 5 years.
  - Record keeping obligations in the PCMLTFR include sections 12–14 (account and transaction records for financial entities), 108 (verifying identity), 144 (reporting to FINTRAC), 145 (purpose of business relationship), 146 (measures taken to conduct ongoing monitoring).

### Correspondent banking requirements and EC6
- Supervisory expectations for correspondent banking and similar relationships include policies and processes to:
  - gather sufficient information about respondent banks to understand their business, customer base, reputation, supervision, and any money laundering/terrorist financing/proliferation financing investigations or regulatory actions;
  - prohibit establishing or continuing correspondent banking relationships with banks that do not have adequate controls, that are not effectively supervised, or that are shell banks;
  - require senior management approval for entering into new correspondent banking relationships.
- Specific obligations for entities regarding prescribed foreign entities include obtaining and maintaining prescribed information such as:
  - a record of the foreign financial institution’s name and address, primary business line, names of directors;
  - a copy of the foreign financial institution’s most recent annual report or audited financial statement;
  - written obligations between the reporting entity and the foreign entity regarding correspondent banking services.
- Due diligence and ongoing monitoring expectations (preserve text as guidance):
  - Take reasonable measures to verify, based on publicly available information, if civil or criminal penalties have been imposed on the foreign financial institution for not respecting anti-money laundering, or anti-terrorist financing requirements.
  - If penalties have been imposed, the reporting entity must monitor all transactions conducted in the context of the correspondent banking relationship to detect any suspicious transactions that must be reported to FINTRAC.
  - Take reasonable measures to assess, based on publicly available information, the reputation of the foreign financial institution with respect to AML/ATF compliance, the quality of AML/ATF supervision of the jurisdiction(s), the nature of the clientele and markets served, and whether AML/ATF policies and procedures are in place.
  - If reasonable measures fail or policies/procedures are not in place, the reporting entity must take reasonable measures to monitor all transactions conducted in the context of the correspondent banking relationship for the purpose of detecting suspicious transactions.
  - As part of the reporting entity’s risk assessment within the compliance program, the reporting entity must assess and document ML/TF risks related to correspondent banking relationships.
- No person or entity shall have a correspondent banking relationship with a shell bank as defined in the regulations (section 9.4(2) of the PCMLTFA).
- Banks must perform an analysis of the correspondent relationship at the outset and continuously; FINTRAC includes correspondent banking components in compliance reviews and may extract samples of transactions and evaluate transaction monitoring.
- Senior management approval is required before entering into a correspondent banking relationship (PCMLTFA section 9.4(1)(c)).
- Regulatory change: As of September 24, 2024, new regulations require that a financial entity that enters into a correspondent banking relationship shall conduct ongoing monitoring of the relationship, at a frequency appropriate to the level of risk, based on a risk assessment referred to in subsection 9.6(2) of the Act and the information collected in respect of the foreign financial institution. These changes address shortcomings cited during the last FATF evaluation.

### Controls, supervision, and EC7–EC8 (systems, risk-based supervision, and sanctions)
- FINTRAC shifted to risk-based supervision, heightening its oversight and introducing new assessment tools aligned with FATF guidance; tools include assistance activities (ongoing monitoring and outreach), assessment activities (in-depth examinations, frequent monitoring touchpoints, single-issue multiple-entity reviews) and are adjusted throughout the year.
- OSFI, while not the designated AML/CFT supervisor, assesses banks’ internal control systems and governance frameworks capable of preventing abuse of financial services; OSFI may adjust supervisory strategy based on FINTRAC information and OSFI and FINTRAC may exchange relevant compliance-related information (see EC4).
- Civil and criminal sanction frameworks:
  - FINTRAC may issue administrative monetary penalties (AMPs) when it has reasonable grounds to believe a reporting entity has violated the Act and its regulations.
  - Subsection 73.1(2) of the PCMLTFA caps the maximum penalties that may be issued at CAD 100,000 for an individual, and CAD 500,000 for an entity.
  - In 2023–24, FINTRAC issued 12 Notices of Violation in the amount of CAD 26.1 million (largest AMPs in FINTRAC history).
  - The amounts of current penalties are assessed as too low to serve as a deterrent in some cases, particularly with banks; the Canadian government announced in its 2024 Fall Economic Statement the intent to propose legislative changes increasing AMPs for breaches of AML/CFT requirements.
  - Regulatory maximum penalty ranges per SOR/2007-292 (Section 5):
    - $1 to $1,000 in the case of a minor violation;
    - $1 to $100,000 in the case of a serious violation;
    - $1 to $500,000 in the case of a very serious violation.
  - Budget Implementation Act of 2024: additional details on the nature of violations are now provided in public notices for all penalties imposed on a reporting entity (including reasons, relevant facts, analysis, and considerations).
  - Criminal offence penalties under Part 5 and Section 75 of the PCMLTFA:
    - On summary conviction, to a fine of not more than CAD 1,000,000 and/or to imprisonment for a term of not more than two years less a day;
    - On conviction on indictment, to a fine of not more than CAD 2,000,000 and/or to imprisonment for a term of not more than five years.
  - The report assesses the sanctioning framework (AMPs or criminal enforcement) as a weak instrument to induce compliance or to punish misconduct or wrongdoing.
- FINTRAC has statutory corrective powers such as compliance agreements under Section 73.16 of the PCMLTFA, though their use is very infrequent.

### Compliance programs, governance, and EC9–EC11 (internal controls, compliance functions, training, whistleblower protections)
- All REs must establish and implement a compliance program with prescribed elements (consult section 156 of the PCMLTFR).
- Internal/external audit and review requirements:
  - Section 156(3) of the PCMLTFR requires a review of an RE’s compliance program to be carried out and documented by an internal or external auditor, or by the person/entity if they do not have an auditor.
  - FINTRAC reviews the internal audit function as part of compliance examinations to determine reliance and to discuss assurance report findings.
- Compliance officer and compliance function requirements:
  - Reporting entities must appoint a compliance officer responsible for implementing the compliance program; the officer must have necessary authority and access to resources.
  - The compliance function must have adequate powers, reporting independence, staff and other resources.
  - CAMLO department and compliance function are examined in compliance reviews and monitored quarterly through regular information received.
- Training and staffing:
  - Compliance programs must include a written, ongoing compliance training program for employees, agents, mandataries, or other authorized persons; a training plan must be instituted, documented, delivered, and its effectiveness assessed during FINTRAC examinations.
  - Ongoing training programs must cover CDD and methods to monitor and detect criminal and suspicious activities.
- Reporting by staff:
  - An employee is expected to report suspicious transactions to FINTRAC in rare instances where they believe their employer has not submitted a Suspicious Transaction Report as required; an employee may use a paper report form provided on the FINTRAC website in such scenarios.
  - Laws provide that a member of a bank’s staff who reports suspicious activity in good faith either internally or directly to the relevant authority cannot be held liable. The PCMLTFA provides immunity for those who report suspicious activity in good faith.
- Management information and internal reporting processes:
  - FINTRAC guidance expects REs to include in compliance policies and procedures the triggers for obligations, information to be reported/recorded/considered, procedures to ensure requirements are met, timelines, methods of reporting, and steps to take when required to take reasonable measures (e.g., asking the client).
  - These aspects are generally included in FINTRAC compliance review scopes; FINTRAC receives and discusses monitoring figures and data on unusual transaction reporting, alerts and STR conversion during quarterly monitoring meetings.

*Source: 1canea2025007-source-pdf - Section 7 of the PCMLTFA outlines obligations of REs to report transactions where there is*

### Section 10 of the PCMLTFA states “No criminal or civil proceedings lie against a person or

### 1canea2025007-source-pdf - Section 10 of the PCMLTFA states “No criminal or civil proceedings lie against a person or

### Legal protections, reporting and cooperation (EC12)
- Section 10 of the PCMLTFA states “No criminal or civil proceedings lie against a person or entity for making a report [...] in good faith, or for providing FINTRAC with information about suspicious of money laundering or of the financing of terrorist activities.”
- OSFI has the legal authority to collect alleged wrongdoing information directly or anonymously from whistleblowers.
- Sections 65 (1) and (2) of the PCMLTFA allow FINTRAC to receive and disclose compliance information domestically.
- Sections 65.1 (1) & (2) provide for Agreements and arrangements for FINTRAC to directly or indirectly cooperate with relevant foreign financial sector authorities to ensure compliance.
- FINTRAC’s Supervision Sector has several MOUs with foreign AML/CFT supervisors and regulators.
- Compliance cooperation with the United States:
  - The Compliance MOU between FINTRAC and FinCEN has been in place since 2011.
  - FINTRAC formalized cross-border cooperation with U.S. banking supervisors in September 2024 by signing a multilateral Statement of Cooperation with the Office of the Comptroller of the Currency (OCC), the Board of Governors of the Federal Reserve System, and the Federal Deposit Insurance Corporation.
- As an FIU, FINTRAC shall disclose information to relevant designated authorities if it has reasonable grounds to suspect designated information would be relevant to investigating or prosecuting a money laundering offence or a terrorist activity financing offence (PCMLTFA s.55(3)).
- Under section 56.1 (1) of PCMLTFA, FINTRAC may disclose designated information to an institution or agency of a foreign state or of an international organization with powers and duties similar to those of FINTRAC.

### In-house intelligence, outreach and limitations (EC13)
- FINTRAC’s Strategic Intelligence and Research unit produces strategic intelligence to identify emerging characteristics, trends and tactics used by criminals to launder money or fund terrorist activities.
- FINTRAC maintains and updates strategic intelligence products on its website, which currently displays 24 strategic intelligence reports, including Operational Alerts, Special Bulletins, Operational Briefs, and Sectoral and Geographic Advisories.
- Topics covered include: laundering proceeds through underground banking, laundering proceeds from illegal wildlife trade, the role of virtual currency ATMs, and the use of legal professionals in money laundering and sanctions evasion.
- FINTRAC’s Annual Reports provide insights on ML/TF trends, including issues related to economic and institutional integrity, financing of violent extremism, and virtual currencies.
- Canada’s National Inherent Risk Assessment provides foundational risk analysis of national ML/TF threats and vulnerabilities.
- FINTRAC engages in public-private partnerships and convenes an annual banking sector meeting; it conducts outreach particularly for SMSBs.
- Limitations and findings:
  - Given the vast number of reporting entities under FINTRAC’s oversight, opportunities for direct strategic intelligence-sharing with banks remain limited in practice.
  - Banks could benefit from more frequent engagement, tailored strategic intelligence-sharing, and enhanced risk-specific advisories focused on sectoral typologies and evolving methodologies.
  - Recommendation: FINTRAC should explore whether existing intelligence-sharing mechanisms adequately meet the operational needs of banks, particularly for timely insights on emerging risks, typologies, and evolving criminal methodologies.

### Group-wide AML/CFT programs, supervisory capacity and effectiveness (EC14 and Principle 29 assessment)
- FINTRAC conducts group-wide supervision as the majority of banks’ AML/CFT controls are centralized in Canada; evaluation of governance and organization can be done at group-level, while effectiveness testing requires file reviews related to services and accounts interacting with institutions operating in Canada.
- Assessment of Principle 29: Materially Non-Compliant.
- FINTRAC is legally empowered to supervise banks’ internal controls and enforcement regarding AML/CFT and prevention of proliferation financing through sanctions-evasion supervision, using information requirements, inspection and sanctioning powers (noted as insufficient in EC8).
- OSFI, while not the AML/CFT authority, plays a complementary prudential role assessing governance, internal control frameworks, and compliance functions; OSFI may intervene when issues pose prudential concerns.
- Operational capacity and resourcing:
  - The FI unit that supervises all Canadian banks consists of 17 full-time equivalents and is led by an executive.
  - FINTRAC is only able to perform on average one thorough compliance review every 6 years at each large bank.
  - Senior compliance officers lead the one compliance review examination they are able to perform each year; other supervisors rotate among components and other supervisory tasks.
- FINTRAC’s salary scales and professional profiles are restricted by public sector rules; FINTRAC lacks a flexible delegation instrument comparable to OSFI.
- Sanctioning framework weaknesses:
  - The sanctioning framework is a weak instrument to induce compliance or punish misconduct; current penalties are too low to serve as a deterrent for non-compliance, particularly for banks.
  - The Canadian government announced in its 2024 Fall Economic Statement the intent to propose legislative changes increasing administrative monetary penalties for breaches of AML/CFT requirements.
  - Effectiveness of sanctions is generally limited to the period inspected in compliance reviews, usually scoped at 1 year of operations.
  - The maximum amount of an AMP is severely capped by Section 5 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Administrative Monetary Penalties Regulations (SOR/2007-292).

### Recommendations (extracted verbatim)
- The supervision sector of FINTRAC should conduct more proactive, frequent and in-depth compliance reviews. In particular, ensure adequate efforts and resources are dedicated to supervising high-risk entities. In addition, consider reviewing the hiring rules applicable to FINTRAC to facilitate the timely recruitment and retention of staff with specialized AML/CFT expertise. Reform the sanctioning framework (including both criminal sanctions and AMPs) so it becomes an effective dissuasion instrument.
  - Review the catalogue of infractions so that it becomes a useful tool to induce compliance, signal unacceptable behavior and punish misconduct or recklessness. Review the categorization of the infractions.
  - The infractions cannot be limited to the period analyzed in the compliance review (usually 1 year, as counted from the date of the letter of commencement of the examination). If FINTRAC detects long-standing issues (further inquiries may be needed and should be made to determine this), it should more frequently sanction the bank for infractions committed before the usual one-year scoping period.
  - The amount of the penalties needs to be re-calibrated so that they are an effective deterrent for banks (reference to profitability of each bank may be useful, the scale of the bank should not be an obstacle to effective deterrence).
  - Apart from the increased fixed amounts, a clause should be provided to allow FINTRAC to surpass the legislated quantitative limit in cases where the benefits of the infraction or the harm caused may be higher than the maximum fines to be imposed.
- Increase coordination and cooperation (not limited to exchange of information or conclusions of examinations) with OSFI in matters of common interest. OSFI’s supervision of integrity and security and also Risk Governance and the Risk and compliance oversight subcomponent of the safety and soundness Supervisory Framework should assist FINTRAC in its evaluation of the compliance control and the effectiveness of the second line and the third line. In a similar vein, FINTRAC’s detected deficiencies in compliance should help OSFI spot weak controls and governance deficiencies.
- FINTRAC should evaluate whether its current intelligence-sharing mechanisms—including strategic reports, public-private partnerships, and sector-specific engagement—adequately address banks’ operational needs for actionable insights on ML/TF and proliferation financing risks. If gaps exist, FINTRAC should explore ways to enhance the frequency, accessibility, and practical relevance of its intelligence products to better assist banks in detecting and mitigating emerging threats.

### Selected exact figures and factual points
- 24 strategic intelligence reports currently displayed on FINTRAC’s website.
- Compliance MOU with FinCEN in place since 2011.
- Multilateral Statement of Cooperation with three U.S. agencies signed in September 2024.
- The FI unit supervising all Canadian banks consists of 17 full-time equivalents.
- On average, FINTRAC performs one thorough compliance review every 6 years at each large bank.
- Compliance review scoping is usually 1 year of operations.
- Reference to legislative cap: Section 5 of SOR/2007-292 limits maximum AMP amounts.
- Government intent announced in the 2024 Fall Economic Statement to propose legislative changes increasing AMPs.

*Source: 1canea2025007-source-pdf (IMF).*

### 3. Cooperation and

### 3. Cooperation and collaboration

### Cooperation with federal entities
- OSFI collaborates closely and effectively with other government entities, including the DOF, the BoC, CDIC, and FCAC.
- These institutions shape the safety net for Canadian federal banks through policymaking and supervision.
- Canadian law and administrative practice provide forums for public bodies to communicate supervisory priorities and discuss strategies and action plans for problem supervised entities and emerging issues.
- Mechanisms for federal-provincial cooperation in banking supervision are not as well-established and institutionalized as at the federal level; policy and regulatory coordination has improved markedly since 2019.
- The lack of exchange of information with provincial authorities is mainly due to legal confidentiality barriers.

### Permissible activities
- The term “bank” and permissible activities of banks are clearly defined in federal legislation (Bank Act and TLCA) and includes federal credit unions, and subsidiaries and branches of foreign banks.
- Federal deposit taking institutions are defined by Section 8 of CDIC Act, including banks, trust and loan companies and federal credit unions.
- The vast majority of deposit-taking from the public is undertaken by federally regulated financial institutions.
- Deposit-taking institutions incorporated and regulated under provincial law (provincial trust and loan companies and credit unions) are not considered “banks” but are subject to regulation, supervision and deposit insurance in their provinces of incorporation.
- The use of the word “bank” and its derivations is generally limited to banks; the Bank Act generally restricts the use of the word “bank, “banker” or “banking” in a name.

### Licensing criteria
- Two-step application process for incorporating a bank in Canada:
  - (i) letters patent of incorporation, issued by the Minister of Finance upon recommendation of the Superintendent;
  - (ii) order to commence and carry on business, issued by the Superintendent.
- OSFI conducts a lengthy and thorough review of new entrants including: business and strategic plans, Board and senior management suitability, credit risk, operational risk, liquidity and funding risks, capital position, IRRBB, AML/CFT and governance.
- Review involves staff from the Approvals Division, supervisors and specialized subject-matter experts.
- Findings and recommendations are communicated to the new entrant for remediation before or after authorization; commitments are received from the new entrant as a way to condition the first steps as a federally regulated bank.
- OSFI’s analysis is guided by its Internal Risk Tolerance Framework for New Entrants, which considers that OSFI should have a low risk tolerance for loss to depositors and other creditors.

### Transfer of significant ownership
- OSFI can review, reject and impose prudential conditions on proposals of transfers of significant ownership and controlling interests.
- The largest banks (with equity of $12 billion or more) must be “widely held” as no person may be a major shareholder and no person shall control in fact such a bank.
- The six largest Canadian banks (all widely held) accounted for 96 percent of the assets held by all Canadian banks.

### Major acquisitions
- All acquisitions of substantial investments in, and/or control of, a single entity, and all increases in such substantial investments, by a bank are subject to specific rules.
- Except as permitted under Part IX of the Bank Act, a bank may not acquire control of, or a substantial investment in, another entity.
- Under Part I of the Bank Act, a bank acquires a substantial investment if it acquires over 10 percent of the voting shares of an incorporated entity or over 25 percent of the ownership interests of an incorporated or a non-incorporated entity.
- Permitted investments are set out in the Bank Act and may require prior Ministerial approval or Superintendent approval depending on the nature of the investment.

### Supervisory approach
- OSFI implemented, in April 2024, a new supervisory framework for risk rating, the ORR, which significantly enhanced how supervisory issues are indicated to banks and led to more clarity towards remediation.
- ORR assesses comprehensive, forward-looking risk categories.
- The Guide to Intervention provides a clear early intervention framework for OSFI and CDIC to coordinate actions; it has been working in cases where banks are “staged” (for example, have lower ratings).

### Supervisory techniques and tools
- OSFI’s supervisory process is based on ongoing monitoring, analyzing quarterly standardized returns and additional monitoring package information.
- Annual supervisory planning is interactive, incorporating broader supervisory priorities with institution-specific or thematic issues identified by LS and specialized teams.
- OSFI defines its supervisory approach as risk-based; cross-sector reviews are increasingly common compared to institution-specific reviews.
- Current strategy relies heavily on information obtained from banks through monitoring and cross-sector reviews circumscribed by banks’ answers to surveys and questionnaires.
- Core banking areas such as credit risk and IRRBB have been affected by resource constraints, resulting in fewer deep and targeted on-site reviews.

### Supervisory reporting
- OSFI collects, reviews and analyses financial and prudential returns from banks on a consolidated and sub-consolidated basis for D-SIBs, and on a consolidated basis for SMSBs.
- Canadian banking groups generally do not conduct non-financial activities due to legal prohibition, making wider group risks less relevant.
- SMSBs hold 3 percent of the banking assets in Canada as of October 2024 and could be exposed to non-financial wider group risks.
- The Assurance guideline issued in 2022 aims to get further certainty regarding banks’ calculations of capital, liquidity and leverage returns.
- Some assurance from banks’ internal auditors has been deferred for two years from the original schedule.
- Low value of administrative monetary penalties, and their applicability only to regulatory returns required by law, undermines the sanctioning framework related to submission of supervisory reporting.

### Corrective and sanctioning powers of supervisors
- OSFI acts timely and at an early stage to correct deficiencies identified in banks; monitoring of findings is consistent and well-integrated.
- OSFI typically uses moral suasion: non-binding recommendations in supervisory letters often induce compliance.
- Statutory powers of OSFI are rarely used; the sanctioning framework is not fit for purpose.
- Administrative monetary penalties (AMPs) available under current regulations are low and do not serve as a meaningful deterrent; OSFI’s infrequent use further weakens effectiveness.
- OSFI reports that an AMP has never been assessed on an individual.
- Sanctions are never published because they are considered confidential supervisory information.
- Assessors consider OSFI would benefit from strengthening the enforcement and sanctioning framework as part of downturn preparation efforts.

### Consolidated supervision
- Consolidated supervision is well-established; legislation and OSFI guidance impose prudential standards on a consolidated basis for banking groups.
- OSFI collects and analyzes financial and other information on a consolidated basis; supervisory teams reference the whole banking group including foreign operations and domestic subsidiaries.
- Supervisory review scopes often refer to portfolios or areas related to subsidiaries; cross-border inspections are part of ordinary supervisory planning.
- The “widely held” rule for large banks makes wider group considerations relevant mainly for SMSBs, which are circa 3 percent of the banking system.
- LSs of SMSBs do not regularly review wider group activities, only reactively when there is a supervisory concern or an approval procedure is triggered.

### Home-host relationships
- OSFI’s home-host relationship management is adequate.
- The six largest Canadian banks are internationally active with material subsidiaries and business in the US, the UK, Latin America and Asia; Canada is mainly a home jurisdiction.
- Canada hosts several forums to support interaction, cooperation and information exchange with foreign regulators for G-SIBs and all D-SIBs: Supervisory Colleges; CMGs for core host regulators and FISC partners (co-hosted by OSFI and CDIC); Outreach Panel meetings for non-core host regulators (hosted by OSFI, with CDIC as active participant).
- OSFI has more than 30 information sharing and cooperation arrangements MoUs in place with foreign regulators.
- OSFI conducts regular (usually quarterly) meetings with regulators of key jurisdictions, depending on the institution being assessed.

### Corporate governance
- Minimum requirements on boards and responsibilities are established in the Bank Act and OSFI guidelines, aligning with international standards and best practices.
- OSFI’s supervisory framework gathers extensive information on board and senior management discussions via quarterly monitoring and establishes touchpoints with senior management and the board.
- The new supervisory framework emphasizes assessment of corporate governance.
- A cross-system corporate governance review was held in 2023–24; it resulted in many findings communicated to banks through supervisory letters, followed up for remedial actions.

### Risk management process
- Risk management processes are included in OSFI’s supervisory framework through ongoing monitoring and reviews of corporate governance.
- Macroeconomic conditions are included via stress testing and business risk in risk management assessments.
- OSFI has invested significantly in supervision of non-financial risks; supervisory reviews cover contingency arrangements and operational resilience.
- Banks’ model outputs are not being deeply reviewed. All Canadian D-SIBs use internal models to calculate their credit risk capital requirements, which represent more than 80 percent of RWA.
- Supervisory review of banks’ models could be reinforced given the importance of credit risk; use and results of IRB models deserve more scrutiny.

### Capital adequacy
- OSFI expects banks to maintain supervisory targets equal to or greater than minimum capital ratios plus various buffers, in addition to minimum capital requirements set out in the CAR Guideline.
- OSFI implemented the final Basel III reforms effective February 1, 2023, but the implementation of the output floor has been deferred until further notice.
- OSFI imposes specific capital charges to D-SIBs and SMSBs through idiosyncratic higher capital targets linked to macroeconomic factors or specific deficiencies, often related to internal controls, risk management or corporate governance.

### Credit risk
- OSFI has principles-based regulatory guidance on credit risk covering full credit lifecycle and processes embedded in a RAF subject to Board, senior management and control function oversight.
- OSFI’s supervisory approach and methodologies for credit risk are mature and sound.
- CRRs are thorough if conducted with sufficient staff, wide scope and assurance activities, so banks expect reasonable checking of information.
- Model risk receives insufficient supervisory coverage: lack of specialists, insufficient onsite reviews, and lack of a material changes prescriptive framework cause underreporting by banks and fewer model inspections.
- Parameters are judged mainly with reference to peers whose models may also underestimate risks.
- CRD monitors credit risk, IRB models and expected loss provisions and participates in credit risk supervisory reviews.
- CRD staff did not grow during the last five years like other OSFI departments; personnel increases focused on emerging risks, the second line of defense and non-financial risks.
- CRD suffers resource constraints that force selectivity in planning supervisory reviews.

### Problem assets, provisions, and reserves
- OSFI’s supervisors use sound criteria and clear methodology to challenge banks’ management claims on IFRS 9 provisions, focusing on performing loans expected credit losses.
- Supervisors produce insightful ECL monitoring reports for cohorts of banks, comparing practices and evolution of provisions.
- OSFI monitors quarterly changes in provisions, decomposing IFRS 9 multi-factorial, point-in-time and dynamic model results and changes.
- OSFI conducts periodic examinations of banks’ practices to ensure adequate policies for early identification and management of problem assets and maintenance of adequate provisions and reserves.
- OSFI lacks a definition of forbearance, does not define cure periods, and granting concessions by a bank does not generally trigger a Stage 2 presumption.
- Recommendation: OSFI should define in regulatory guidelines the main concepts of the provisioning framework in a uniform way to increase comparability and prevent circumvention of impairment rules.
- Observation: Lifetime losses for RESL may have to be estimated over a much longer horizon (equivalent to the real payment period of the loan, irrespective of the shorter contractual maturity) to reflect likely holding period.

### Concentration risk and large exposure limits
- OSFI’s guidelines set supervisory expectations for banks to identify, measure, evaluate, monitor, report and control concentration risk.
- Framework is set by the CAR Guideline and Corporate Governance Guideline, establishing expectations on risk limits, controls, mitigation and data aggregation.
- The Stress Testing guideline sets expectations on banks’ stress testing programs as part of enterprise-wide risk management.
- The 2019 and 1994 guidelines on Large Exposure Limits define such limits for D-SIBs and SMSBs, respectively; the most recent guideline represents implementation of the large exposure standard in Canada.
- Concentration risk is also addressed through banks’ ICAAP supervisory reviews.

### Transactions with related parties
- Related party framework is based on prohibition in section 489(1) of the Bank Act, but in practice:
  - (i) the Bank Act’s definition of related party is much narrower than international standard;
  - (ii) many related party transactions are exempted from the prohibition, including designation of Superintendent under certain conditions.
- The framework is complex and subject to exceptions that may not be prudent.
- Banks do not report related party transactions to OSFI; OSFI does not monitor these transactions.
- OSFI only identifies issues reactively via self-reported bank documents or when triggered by approvals; OSFI does not conduct proactive reviews to control related party transaction risks.
- Recommendation: Implement a related party prudential framework in accordance with international standards.

### Country and transfer risks
- OSFI’s credit risk management guidelines do not deal with country and transfer risk.
- OSFI is not assessing adequacy and effectiveness of banks’ country and transfer risk management, policies and processes.
- OSFI’s assessment criteria for CRRs contain no references to country and transfer risk.
- These regulatory and supervisory shortcomings explain the lack of supervisory attention by OSFI on country and transfer risks.

*Source: 3. Cooperation and collaboration — 1canea2025007-source-pdf*

### 22. Market risk C

### 22. Market risk C

### Market risk assessment and framework
- OSFI regularly assesses banks in relation to market risk management, with key minimum expectations set at the Corporate Governance guideline and more specific expectations related to risk measurement and controls established in Chapter 9 of the CAR guideline, which is applicable to D-SIBs and to banks with significant trading activity.
- These banks held more than 96 percent of the Total Assets of OSFI supervised banks, as of October 2024.
- The fact that market risk capital requirements are not generally applicable to SMSBs is not considered a deviation from the international standards, but a use of proportionality in supervision and regulation.
- A recommendation regarding the absence of capital requirements for SMSBs exposures to foreign currencies or commodities is made in CP16.

### 23. Interest rate risk in the banking book (IRRBB) — LC
- OSFI regularly assesses banks in relation to IRRBB, with key minimum expectations set at the Corporate Governance guideline and more specific expectations related to risk measurement and controls established in Guideline B-12 Interest Rate Risk Management, of May 2019, applicable to all banks.
- OSFI has not conducted reviews of banks’ IRRBB models, and therefore assesses the adequacy of banks’ IRRBB measurement by the ongoing monitoring process, which allows comparisons of exposures and model results among peer groups.
- Regular review of ALCO and board materials, in addition to receipt of internal audit reports and other internal documents, provide a channel for supervisors to identify potential gaps and may lead to a focused review.
- Recommendation: The supervisory evaluation of the adequacy of internal capital measurement systems of banks in capturing IRRBB should be informed by minimum focused reviews of the banks’ models and systems.

### 24. Liquidity risk — C
- OSFI is at the forefront regarding liquidity risk requirements and supervisory practices, with thresholds for supervisory action (most of the time based on banks’ internal targets and above regulatory minimums) closely monitored and acted upon when deficiencies in liquidity risk management are identified.
- Banks are expected to use specific liquidity adequacy tools, such as the NCCF and the OCFS, that help providing a more complete picture of liquidity risks in the banking system.
- Assessors found relevant and deep work on liquidity risk is being conducted, resulting in important findings and in a close monitoring of liquidity risk measurement and management practices in banks, through a well-construed proportional framework.
- Changes in banks’ liquidity risk assessments are actively reflected in banks’ ORR.
- Recommendation: Given the complexities and many angles of liquidity risk, more frequent bank-specific deep-dive reviews could be done to verify practices in this core banking area.

### 25. Operational risk and operational resilience — LC
- OSFI has been investing in enhancing the operational risk and operational resilience framework in Canada’s banking system by issuing new guidelines in line with the international discussions and perceived risks, and by promoting supervisory processes and practices that channel enhancements at banks.
- The risk management framework in relation to policies, processes, responsibilities and oversight functions is coherent with the framework for other risks, established in the Corporate Governance Guideline, of 2018, and is complemented by specific principles-based guidelines on Operational Risk and Resilience, Technology and Cyber Risk Management and Third Party Risk Management.
- Supervisory reviews of non-financial risks at individual banks, especially related to technology and cyber risks and business continuity, are more often conducted, as compared to other core banking areas.
- Supervision has resorted to a series of cross-sector reviews to assess progress in important topics related to operational resilience.
- Ongoing work: Implementation of procedures and best practices related to business disruptions and disaster recovery; identification and mapping of critical operations and systems; and understanding the risks from third-party service providers is a work in progress.

### 26. Internal control and audit — LC
- OSFI’s regulatory framework adequately sets expectations for banks to have effective internal control frameworks.
- The principles-based Corporate Governance guideline covers the role of the board and senior management, oversight functions, the risk governance framework and the role of the audit committee.
- The guidelines on operational risk management and resilience and technology and cyber risks management establish further detailed expectations regarding the control environment and resourcing.
- Guideline E-13 Regulatory Compliance Management covers the compliance function.
- Supervision frequently verifies internal control and audit in the context of reviews dedicated to specific risks. Some deep reviews generally result in very relevant findings that can potentially trigger much needed remediation in banks.
- Recommendation: More bank-specific and deeper reviews are important to test and verify the effectiveness and adherence to reported banks’ internal control and audit policies and procedures.

### 27. Financial reporting and external audit — C
- OSFI relies on independent and qualified accountants with appropriate experience to provide an opinion as to whether the financial statements are prepared in all material respects in accordance with the IFRS accounting standards and provide a true and fair view of the financial status, results and evolution of the banks and banking groups.
- OSFI and the external auditors meet very frequently and have a fluid relationship.

### 28. Disclosure and transparency — C
- The Pillar 3 international standards have been implemented by OSFI, and its application has become more proportional with the segmentation of SMSBs and the issuance of a specific guideline.
- Banks follow IFRS and all its disclosure requirements in financial statements.
- Disclosure requirements set by securities regulators are also applicable to banks that are public issuers.
- OSFI is part of a Canadian government initiative to improve the public available information of the banking system.

*Source: 22. Market risk C (1canea2025007-source-pdf - 22. Market risk C).*

### 29. Abuse of

### 29. Abuse of financial services

### Key findings and supervisory capacity
- FINTRAC’s Financial Institutions (FI) unit that supervises all Canadian banks consists of "17   full-time equivalents" that conduct assistance (outreach, guidance, and policy interpretation), assessment (detect and verify compliance, regular engagement meetings, request information, etc.) and enforcement (serious non-compliance, AMPs, ratings) activities.  
- FINTRAC’s salary scales and professional profiles are restricted by the general rules applicable to the public sector employees.  
- FINTRAC’s FI unit is also in charge of examining the banks. The small size of the unit and the complexity and scope of its activities contribute to an excessively long supervisory cycle for higher-risk entities, such as banks.  
- FINTRAC is only able to perform on average "one thorough compliance review every 6 years at each large bank." Targeted and cross-sectional reviews are not frequent or deep enough to mitigate the long cycle.  

### Sanctioning framework and effectiveness
- The PCMLTFA and related regulations and guidelines provide a sound financial crime prevention framework, however the sanctioning framework (criminal and AMPs) is a weak instrument to induce compliance or to prevent wrongdoing.  
- The amounts of the current penalties are "too low to serve as a deterrent for non-compliance" or even to surpass the benefits of the infraction in some cases.  
- The Canadian government announced in its "2024 Fall Economic Statement" the intent to propose legislative changes increasing administrative monetary penalties for breaches of AML/CFT requirements.  
- The effectiveness of the sanctions is generally limited to the period inspected in the compliance reviews (generally corresponding to "1 year of operations"). The maximum amount of an AMP is severely capped by legislation.

### Recommended actions — summary across supervisory and prudential Principles
- Principle 1
  - Establish clearly and in a highlighted way in the OSFI Act that the safety and soundness of banks and the banking system is the primary and overriding objective of OSFI and explicitly subordinate all its other activities and legal mandates to this goal.
  - Clarify or suppress the references to “the need to allow financial institutions to compete effectively and take reasonable risks” in OSFI Act, so that safety and soundness goal clearly prevails.
  - Always ensure due consideration to OSFI’s opinions and recommendations when developing or before issuing legislation or regulation on prudential matters.
- Principle 2
  - Foster OSFI’s technical autonomy so that its full discretion to set prudential policy and take any supervisory actions or decisions on banks under its supervision is fully protected from potential government influence.
  - Suggested legislative changes include:
    - Reduce accountability towards the Minister of Finance strictly to aggregate reports on the discharge of OSFI’s duties and what is necessary for constitutional/public-money obligations.
    - Circumscribe interaction with the DOF to matters of common interest and protect microprudential policy under OSFI’s exclusive purview.
    - Codify that the Superintendent of OSFI has full discretion to set prudential policy and take supervisory actions, and that no other branch, division or agency of the Government of Canada may instruct or influence it regarding these matters.
    - Review authorizations and decisions that require Ministerial approval under the Bank Act and the TLCA to grant OSFI full discretion when purely prudential considerations should prevail.
    - Fix by law the scope of matters that OSFI can regulate, including development and technical detailing of all prudential matters related to safety and soundness.
  - Protect OSFI’s budgetary autonomy by:
    - Enabling OSFI to define its budget and table it in Parliament without the approval of the Minister of Finance, with parliamentary control for accountability.
    - If full budgetary independence is unfeasible, consider alternatives: make Minister’s role consultative; limit ministerial intervention to narrowly defined circumstances (examples: legal compliance issues, material operational inefficiencies, extraordinary national economic crises); subject OSFI’s budget to parliamentary oversight, possibly via a specialized parliamentary committee.
    - Attribute to OSFI the capacity to set its salary scales and compensation schemes for executive and non-executive personnel, subject to appropriate audit.
  - Ensure the terms and conditions of the Public Service Commission delegation do not undermine OSFI’s organizational autonomy; consider conferring Public Service Employment Act’s powers to OSFI in legislation.
- Principle 3
  - Promote establishment of a joint provincial-federal taskforce to determine legal barriers to share institution-specific information and design a roadmap to enable such exchange.
- Principle 5
  - Institute a policy of assessing the fitness and propriety of all new board members and new senior management executives.
- Principle 6
  - Address cases where SMSBs carried out significant ownership transfers without reporting to OSFI through outreach, awareness, and clarification; consider establishing reporting requirements for non-“widely held” banks regarding significant shareholders.
- Principle 8
  - Elaborate and publish guidelines on recovery planning along the lines of the Recovery Plan Principles and existing Technical Notes; increase OSFI’s participation in CDIC’s assessment of banks' resolvability (at least for Tier 1 banks); improve supervision of the wider group of SMSBs not widely held.
- Principle 9
  - Increase the number of deep and targeted reviews (including on-site reviews in credit, market, liquidity, operational risks, IRRBB); establish formally distinct supervisory cycles with different lengths for banks in different tiers and set a minimum number of deeper reviews per supervisory cycle according to ORR.
- Principle 10
  - Avoid excessive reliance on assurances from banks’ senior management and auditors; require minimum supervisory intrusiveness on calculations of capital, leverage and liquidity; revise sanctioning framework for misreporting and persistent reporting errors, including increasing administrative sanctions and broadening scope to include qualitative internal control requirements.
- Principle 11
  - Reform the legal regime of AMPs to be a useful supervisory tool by: reviewing infractions (focus on fraud and manifest lack of controls), re-calibrating penalties, allowing benefit/harm of infraction to be used to exceed caps, and amending internal policies on AMPs.
  - Consider issuing a policy on publication of sanctions (require reforms on confidentiality regime of PSI) to enhance reputational deterrence.
  - Make credible use of formal statutory powers by establishing an internal policy for use of statutory powers and reinforcing recommendations with formal powers (including use of AMPs when instructions are not timely complied with).
- Principle 12
  - Improve supervision of small and medium-sized banks not widely held with major shareholders/parents/affiliates; regularly update group structure, list of significant shareholders, risk of excessive leverage, capacity of parent to provide support, reputation and contagion risks; require undertakings for access to information from parent companies as internal procedure.
- Principle 15
  - Increase frequency, range and depth of reviews on banks’ internal models used in Canada; provide effective challenge to modelling choices, assumptions and outcomes.
- Principle 16
  - Establish a simplified market risk capital requirement for non-D-SIBs with exposures to foreign currencies or commodities to simplify current framework.
- Principle 17
  - Reinforce the credit risk department, especially model specialists; issue guidance on minimum thresholds for material changes of IRB models (notification thresholds should not be at banks' discretion); foster downturn preparation to challenge model outcomes (ECL and capital); require board or senior management decision for major credit risk exposures exceeding certain amounts/percentages of capital; increase weight of credit risk on-site reviews; increase frequency of credit risk model reviews and include reliability verification in on-site reviews; tie model review findings to quantitative impact on capital.
- Principle 18
  - Define main concepts of the provisioning framework in regulatory guidance to increase comparability and prevent circumvention; specific recommendations include defining forbearance with reference to quantitative thresholds, establishing minimum cure period for Stage improvement, setting more exigent supervisory expectations for SICR, providing guidance on unlikeliness to pay indicators for Stage 3, and considering longer horizons for RESL lifetime loss estimation.
  - If accounting standards do not allow prudent ECL adjustments, OSFI’s prudent ECL estimates may be reflected as ad hoc CET1 deductions.
- Principle 19
  - Lower the "100 percent of total capital" limit for large exposures applicable to foreign bank subsidiaries in Canada, per the 1994 Large Exposures guideline.
- Principle 20
  - Implement a prudential framework on related-party transactions aligned with international standards; lower current limit in subsection 497(2) of the Bank Act (aggregate exposures to directors, officers and their interests limited to "50 percent of total capital") in view of Large Exposure guidelines that establish a limit of "25 percent" in relation to "Total Capital" and "Tier 1 capital."
- Principle 21
  - Establish supervisory expectations on country and transfer risk in OSFI’s credit risk regulatory guidance and include these risks in credit portfolio assessments.
- Principle 23
  - Conduct supervisory reviews of banks’ IRRBB internal measurement systems with sufficient depth for supervisors to assess adequacy.
- Principle 25
  - Continue development of supervisory practices on emerging issues related to operational resilience; conduct supervisory reviews on traditional operational risk identification and measurement, explore linking incident reporting to operational risk loss database and identification of technology and cyber-related losses.
- Principle 26
  - Increase bank-specific and deep on-site reviews on internal control and audit to test effectiveness and adherence to internal controls and regulatory compliance frameworks.
- Principle 29 (FINTRAC-specific)
  - The supervision sector of FINTRAC should conduct more proactive, frequent and in-depth compliance reviews, ensure adequate resources are dedicated to supervising high-risk entities, and consider reviewing hiring rules to facilitate timely recruitment and retention of staff with specialized AML/CFT expertise.
  - Reform the sanctioning framework (criminal sanctions and AMPs) so it becomes an effective dissuasion instrument:
    - Review the catalogue and categorization of infractions so it induces compliance, signals unacceptable behavior and punishes misconduct or recklessness.
    - Extend scope of infractions beyond the period analyzed in compliance reviews (usually "1 year"); sanction detected long-standing issues more frequently for infractions committed before the usual one-year scoping period.
    - Re-calibrate penalty amounts so they are an effective deterrent (reference to profitability of each bank may be useful).
    - Include a clause to allow FINTRAC to surpass the legislated quantitative limit in cases where the benefits of the infraction or the harm caused may be higher than the maximum fines.
  - Increase coordination and cooperation with OSFI in matters of common interest; OSFI’s supervision of integrity and security and Risk Governance should assist FINTRAC in evaluating compliance control effectiveness, and FINTRAC’s detected deficiencies should inform OSFI’s work.
  - Evaluate whether current intelligence-sharing mechanisms adequately address banks’ operational needs for actionable ML/TF and proliferation financing risk insights; if gaps exist, enhance frequency, accessibility, and practical relevance of intelligence products.

*Source: 1canea2025007-source-pdf - 29. Abuse of (excerpt).*

### 77.      Canadian authorities thank the IMF mission team for its significant effort in preparing

### Canadian authorities thank the IMF mission team for its significant effort in preparing this assessment of compliance with the updated and strengthened BCP.

### Key acknowledgements and summary
- Canadian authorities thank the IMF mission team for its significant effort in preparing this assessment (paragraph 77).
- Canada welcomes the IMF’s acknowledgement of Canada’s "mature and well-functioning banking system" and the demonstrated success of the institutional arrangements that underpin it (paragraph 81).
- Canadian authorities will carefully review this Assessment and explore practical opportunities to further enhance oversight of Canada’s strong and stable banking sector (paragraph 88).

### Regulatory and supervisory improvements since the 2014 Detailed Assessment
- Since the last BCP Detailed Assessment conducted in 2014, Canada has made a number of improvements to its frameworks for banking regulation and supervision (paragraph 78).
- OSFI strengthened standards on capital and liquidity, including reforms that meet virtually all Basel III standards and the 2017 reforms (paragraph 78).
- OSFI placed greater focus on catastrophe risks and non-financial risk areas: operational resilience, third party, culture, technology and cyber, and integrity and security (paragraph 78).
- OSFI introduced a new Supervisory Framework and associated technology and data investments, enhancing its ability to identify, assess, and act on prudential risks at banks (paragraph 79).

### Banking sector resilience and crisis response
- Canadian banks proved resilient to the global pandemic and associated economic shocks, including historic shifts in interest rates (paragraph 80).
- Banks have robust capital and liquidity buffers, and operational capacity to weather these shocks and ensure sustained access to credit to Canadian households and businesses (paragraph 80).
- Canadian authorities demonstrated the ability to act swiftly through effective coordination and clear mandates (paragraph 80).
- Canada enters the current period of economic uncertainty "with the highest level of financial sector resilience in Canada’s history" (paragraph 80).

### Views on OSFI’s mandate, independence, and supervisory intensity
- OSFI operates under a prudential mandate that recognizes sound management of both financial and integrity and security risks and promotes safety and soundness of regulated financial institutions; it pursues a singular safety and soundness objective while having "due regard" for the need to enable banks to compete and take reasonable risks (paragraph 81).
- Canada disagrees with the IMF’s assessment that OSFI’s technical autonomy is impacted by its relationship with the Department of Finance and that OSFI lacks budgetary autonomy (paragraph 82).
- Canada disagrees with the IMF’s "materially non-compliant" rating on BCP 2 regarding the independence of OSFI and finds that it is not an accurate characterization of the Canadian regime (paragraph 82).
- Canada asserts that Canada’s institutional arrangements are substantially aligned with the BCP and compare favorably with other mature national frameworks (paragraph 82).
- "OSFI is one of the most independent entities in the Canadian Government." Canada states it is unable to implement the IMF’s provided recommendations for BCP 2 as they are inconsistent with fundamental principles of Canada’s Parliamentary democracy and Ministerial accountability (paragraph 83).
- Canada acknowledges the IMF’s position that further increasing the frequency and intensity of prudential reviews would enhance supervisory outcomes and notes OSFI will consider this, mindful of the resilience evident in the Canadian financial system (paragraph 84).
- OSFI has continued to increase in-person presence for all aspects of its supervisory work since restrictions were lifted; initiatives to renew OSFI’s Supervisory Framework, technology and data are a priority (paragraph 84).
- Achieving greater scope and depth of supervisory work will require additional resources, as noted in this Assessment, which will need to be prioritized (paragraph 84).

### Related parties regime (BCP 20)
- Canada has an advanced related parties regime designed according to principles that have worked well in a Canadian context, where compliance with legislation is reliance based, and the regulator rigorously supervises financial institutions and addresses issues of non-compliance (paragraph 85).
- Canada understands the IMF perspective and will reflect on the IMF’s rating and recommendations in this area (paragraph 85).

### AML/CFT supervision (BCP 29) and FINTRAC
- Canada welcomes the IMF’s conclusion that Canada’s legislation, regulations and guidance provide a sound financial crime prevention framework (paragraph 86).
- Canada appreciates and will carefully consider the IMF’s recommendations to enhance the AML/CFT framework and supervision by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) (paragraph 86).
- Canada disagrees with the rating of "materially non-compliant" for BCP 29, arguing the cited deficiencies (frequency of in-depth compliance reviews, attributed to resource constraints, and insufficiently high AML/CFT penalties) do not meet the threshold for "materially non-compliant," which requires "severe shortcomings" that render supervision ineffective or raise doubts about the authority's ability to achieve compliance (paragraph 86).
- Since it assumed sole responsibility for AML/CFT supervision of banks, FINTRAC has developed specialized expertise, enhanced its risk-based supervisory program and received increased resources to fulfill its supervisory role, while continuing to collaborate with OSFI (paragraph 87).
- Canada believes recommendations to enhance the AML/CFT supervisory framework should look beyond resourcing alone as a solution (paragraph 87).
- The Canadian government introduced legislation proposing to strengthen the AML/CFT penalty framework (paragraph 87).

*Excerpt from Canadian authorities’ response to the IMF Detailed Assessment (paragraphs 77–88).*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1canea2025007-source-pdf.pdf_
