Federal officials signal a more risk-based approach to AML compliance
A new regulatory streamlining initiative could create opportunities to reduce unnecessary compliance burden while maintaining the effectiveness of Canada's
The Office of the Superintendent of Financial Institutions (OSFI) has released a significant package of prudential and digital financial guidance, including finalized updates to the Capital Adequacy Requirements (CAR) Guideline, Guideline B-12 on Interest Rate Risk Management, and the Capital and Liquidity Treatment of Crypto-Asset Exposures Guideline. OSFI also issued a statement clarifying the regulatory treatment of tokenized deposits, providing additional guidance for institutions exploring digital asset and tokenization initiatives.
The guidelines were published on September 10, 2026, and will take effect on November 1, 2026, for institutions with an October 31 fiscal year-end and January 1, 2027, for institutions with a December 31 fiscal year-end.
While the requirements apply directly to federally regulated deposit-taking institutions, including federal credit unions where applicable, OSFI guidance often influences supervisory expectations and regulatory approaches adopted by provincial regulators. The guidelines, therefore, may have implications for the broader credit union sector.
OSFI’s finalized CAR Guideline includes revisions in response to consultation feedback on credit risk, securitization, and market risk. Some changes align the final guideline more closely with the policy intent of the draft, while others align it with current practice.
Of particular interest to smaller institutions, OSFI has introduced a streamlined application and approval process for small and medium-sized banks, or SMSBs, interested in applying to use the internal ratings-based, or IRB, approach to credit risk.
The IRB approach allows an approved institution to use internal estimates of specified credit-risk components when calculating regulatory capital. The streamlined process could therefore create a more accessible pathway for eligible smaller institutions that have the necessary data, risk-management systems, modelling capabilities, and governance arrangements to pursue approval.
To support the revised process, OSFI has updated Chapters 1 and 5 of the CAR Guideline and released a revised implementation note for the Assessment of Regulatory Capital Models for Deposit-Taking Institutions. OSFI has also consolidated its IRB implementation notes on data maintenance, risk quantification, collateral management, validation of risk-rating systems, the use of ratings and estimates of default and loss, and oversight expectations into a single document, Minimum Requirements for Internal Ratings-Based Approaches.
The finalized CAR Guideline also includes a number of substantive changes:
The finalized Guideline B-12 updates OSFI’s expectations for identifying, measuring, monitoring and controlling interest rate risk.
OSFI reports that stakeholders were generally supportive of the proposed amendments and did not identify issues requiring changes to the consultation draft. The finalized guideline, therefore, retains the central elements of the proposal. Compared with the 2019 version, the key changes include: target updates to Annex 1 reflecting the revised interest rate shocks published by the Basel Committee on Banking Supervision in July 2024, updated guidance on evaluating balance-sheet scenarios against earnings measures, and removal of detailed public-disclosure provisions, which have been replaced by a reference to OSFI’s Pillar 3 disclosure guidelines. Credit unions should review their interest rate risk scenarios, modelling assumptions, earnings measures, governance documentation, and related disclosures against the finalized requirements. While the guideline applies directly to federally regulated institutions, the revisions may also help inform the evolution of provincial interest rate risk frameworks and supervisory expectations.
OSFI has finalized its 2027 guideline governing the capital and liquidity treatment of crypto-asset exposures for banks, including federal credit unions. At the same time, OSFI released a separate statement clarifying the regulatory treatment of tokenized and other digitally represented deposits.
The crypto-asset guideline establishes the prudential capital and liquidity treatment for direct and indirect crypto-asset exposures and sets expectations regarding supervisory notification. It covers exposures to crypto-assets and certain related activities but does not determine whether an institution is permitted to issue a particular digital asset or engage in a specific activity.
In response to consultation feedback, OSFI made two notable revisions to the final guideline:
OSFI clarifies treatment of tokenized deposits
For credit unions exploring tokenization initiatives, OSFI issued a statement confirming that tokenized deposits are not legally distinct from traditional deposits. According to OSFI, the technology used to represent a deposit does not change its legal nature or regulatory treatment. Instead, financial products should be assessed based on their underlying rights, obligations, and economic substance rather than the technology used to deliver them.
This clarification is significant because it reinforces OSFI's technology-neutral approach to financial innovation. A deposit represented on a distributed ledger or blockchain remains a deposit, rather than becoming a new category of digital asset simply because it has been tokenized.
While tokenized deposits continue to be treated under existing deposit-taking rules, institutions pursuing tokenization initiatives remain responsible for complying with applicable prudential, technology, cybersecurity, and third-party risk management requirements.
Additionally, federally regulated institutions should engage with their lead supervisors before launching novel products or services. The statement specifically highlights the continued relevance of existing supervisory expectations for institutions exploring tokenization, including technology and cyber risk management and third-party risk management requirements.
Credit unions subject to the guidelines should begin reviewing the final requirements against their existing capital, interest rate risk, and digital-asset frameworks. Key areas for implementation planning may include:
Provincially regulated credit unions should monitor how provincial regulators respond to the finalized OSFI guidance, particularly where provincial frameworks reference federal or Basel-based prudential standards.
CCUA will continue to monitor the implementation and implications of these regulatory developments and provide members with updates as Canada's prudential framework for capital, interest rate risk management, digital assets, stablecoins, and tokenized financial products continue to evolve.
If you have any questions, please don't hesitate to contact me at rmckendry@ccua.com