Canada's Office of the Superintendent of Financial Institutions (OSFI) issued a Technology Risk Bulletin on the implications of generative and agentic artificial intelligence for technology risk, cybersecurity, and operational resilience at federally regulated financial institutions (FRFIs). The bulletin is supervisory guidance issued under OSFI's mandate in the Office of the Superintendent of Financial Institutions Act. It does not amend OSFI's binding guidelines; instead, it applies existing obligations to AI-specific risk scenarios.
The bulletin maps AI-related risks to three existing binding guidelines. Guideline B-13 (Technology and Cyber Risk Management, effective January 1, 2024) requires FRFIs to maintain sound technology and cyber risk governance; the bulletin identifies hallucination of model outputs and autonomous deployment of AI-generated code as B-13-scope cyber and technology risks. Guideline E-21 (Operational Risk Management, as revised) requires operational resilience controls; the bulletin states that FRFIs must extend those controls to AI-driven processes where agentic systems execute automated decisions without human review at each step. Guideline B-10 (Third-Party Risk Management, 2023) applies when FRFIs procure generative AI capabilities from cloud providers or hosted model vendors.
The bulletin applies to all OSFI-supervised entities: banks and federally chartered trust and loan companies under the Bank Act, domestic and foreign insurance companies under the Insurance Companies Act, and federally regulated pension plans under the Pension Benefits Standards Act, 1985. Banks deploying large language model-based customer service or automated compliance screening tools must assess hallucination risk and implement output validation controls under B-13. Insurers using AI in underwriting or claims processing must address data accuracy and auditability. Any FRFI procuring generative AI through a third-party vendor must conduct enhanced due diligence and ongoing monitoring under B-10.
OSFI characterises agentic AI, which chains decisions and executes actions autonomously across systems, as amplifying existing technology and cyber risks by compressing the interval available for human review. FRFIs that allow agentic AI to deploy code into production environments or execute transactions without human confirmation at each step should reassess their operational resilience controls. OSFI has not specified a compliance deadline for addressing gaps identified against the bulletin's sound practices; institutions are expected to address gaps within existing annual risk management cycles.
Licentium advises financial institutions and fintech operators on AI governance and regulatory compliance in Canadian and international markets. Work we undertake includes B-13 and B-10 gap assessments for AI systems, agentic AI deployment risk reviews, third-party AI vendor due diligence programmes, and regulatory submissions to OSFI.