News

Draft Guideline Consultation on E-21: Operational Resilience and Operational Risk

Published Date: Oct 18, 2023

Last week, the Office of the Superintendent of Financial Institutions (OSFI) launched two consultations. The first relates to a new Integrity and Security guideline and the second, of which this summary is concerned, relates to an updated draft Guideline, E-21: Operational Resilience & Operation Risk (Guideline). Along with this guidance, OSFI sees operational resilience and operational risk management as contributing to the integrity and security of financial institutions.

Guideline E-21 is intended to modernize OSFI's guidance on operational risk management, including new expectations for business continuity management, crisis management, change management, and data risk management. It builds on the consultation held in 2021 and supports Guideline B-13, Technology and Cyber Risk Management, and Guideline B-10, Third-Party Risk Management. First launched in 2016 with the title of Operational Risk, it was retitled to Operational Resilience and Operational Risk Guideline to encapsulate the broader focus on risks that are viewed as inevitable threats, which the FRFI may take steps to address and ensure its long-term resilience.

OSFI defines operational resilience with an emphasis on the end-to-end performance of a FRFI’s critical operations across the organization. As the FRFI’s operational resilience approach matures, the operational risk management underpinning it should transition from a business-unit approach to one that focuses on the performance of operations end-to-end. Operationally resilient organizations understand that disruptions can and will occur. They respond, adapt to, recover, and learn from such disruptive events.

Skip to content