HireACISO

vCISO work for OSFI regulated institutions

A federally regulated financial institution can use a vCISO, and cannot outsource the accountability. OSFI expects a senior individual inside the institution who is answerable for technology and cyber risk. The workable arrangement is an internal accountable officer with fractional expertise underneath, not a retainer holding the seat.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

OSFI does not prohibit a virtual or fractional CISO, and it does not recognise one either. Guideline B-13 on technology and cyber risk management expects clear accountability for technology and cyber risk at senior management level with appropriate board oversight, and Guideline B-10 on third-party risk is explicit that outsourcing an activity does not transfer accountability for it. Read together, that means a smaller federally regulated institution can buy the expertise fractionally and must still name someone internally who answers for it. Retainers for this work run $8,000 to $30,000 CAD a month, materially above the general market on vCISO pricing, because the person has to have been examined before.

Most people who land here are not OSFI regulated. If you are a software startup, a payments company without a federal charter, or any business that sells to a bank or an insurer rather than being one, none of the guidelines below apply to you directly. Read vCISO work for a Canadian fintech, which covers answering a regulated institution's supplier review. If a bank has sent you a questionnaire and nobody at your company owns security, start with the questionnaire with no owner.

Who this applies to

OSFI regulates federally incorporated banks, federally regulated trust and loan companies, insurers, and federally regulated private pension plans. It does not regulate provincially incorporated credit unions, most fintechs without a federal charter, provincial insurers, or securities dealers, who answer to provincial regulators and the Canadian Investment Regulatory Organization instead. Plenty of companies believe they are OSFI regulated because their customers are. If that is you, what applies to you is your customer's third-party risk process under B-10, which is a different and much more tractable problem.

The guidelines that set the expectations

OSFI guidance relevant to security leadership at a federally regulated institution
GuidelineSubjectWhat it means for the CISO seat
B-13 Technology and cyber risk management Expects clear senior accountability for technology and cyber risk, a risk management framework, and board oversight. This is the guideline an examiner opens
E-21 Operational risk and resilience Puts cyber inside operational resilience: critical operations identified, tolerances for disruption set, and severe-but-plausible scenarios tested. Security leadership has to speak this language
B-10 Third-party risk management Governs your use of the vCISO itself. Accountability is not transferable, and a critical arrangement carries due diligence, contractual and monitoring requirements
Technology and cyber incident reporting advisory Incident notification Reportable technology and cyber incidents are notified to your lead supervisor promptly, with follow-up reporting. Somebody has to know the criteria before the incident, not during it
Corporate governance guideline Board and oversight functions Sets the expectations for the independent oversight functions the security leader has to report into and be challenged by

Two things follow from that set. The first is that this is a governance job before it is a technical one: most of the work is framework, evidence, committee papers and challenge, and an examiner reads documents rather than firewalls. The second is that E-21 has changed the shape of the role. Framing security as controls is no longer sufficient. It has to be framed as tolerances for disruption to critical operations, which is a different conversation and one a lot of otherwise strong candidates cannot hold.

What a vCISO can own, and what stays internal

Splitting the security leadership role at an OSFI regulated institution
ResponsibilityFractionalInternalWhy
Named accountability for technology and cyber riskNoYesB-13 expects a senior individual within the institution, and B-10 says outsourcing does not move accountability
Attesting on behalf of the institution to the supervisorNoYesAn attestation is an act of the institution
Building the cyber risk management frameworkYesApprovesDrafting is expertise work. Approval is accountability
Board and risk committee reportingPrepares, often presentsOwns the contentCommittees expect a consistent face. See CISO board reporting
Incident notification decisionsAdvisesDecidesThe clock is short and the decision is the institution's
Scenario testing and resilience work under E-21YesParticipatesThis is the most transferable expertise on the list
Third-party and outsourcing risk assessmentsYesSigns off critical arrangementsVolume work with a judgement layer on top
Day to day operational securitySometimesUsuallyContinuous work does not fit a retainer

The pattern that survives an examination is a named internal accountable executive, frequently the chief risk officer or a head of operational risk at a smaller institution, with a fractional security leader supplying the technical depth, the framework drafting and the committee material. What fails examination is the institution pointing at an external retainer when asked who is accountable. The reporting line question is covered on who a CISO should report to, and under this guidance the answer skews towards risk rather than towards engineering.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Your vCISO is itself a third-party arrangement

This is the part institutions forget. Engaging a security leader is outsourcing, and B-10 applies to it. If the arrangement is assessed as critical, and security leadership at a small institution frequently is, expect the full treatment.

The exit plan clause is the one worth arguing over. A security program where the register, the evidence and the framework live in the provider's own systems is an operational resilience problem in its own right, and the kind of thing E-21 asks you to have thought about.

What to look for in a provider here

The general evaluation on how to choose a vCISO applies, with four additions that narrow the Canadian field to a small number of people.

  1. They have been through an OSFI examination or supervisory review. Ask which institution type, which year, and what the findings were about. Having read the guidelines is not the same as having been asked to evidence them.
  2. They speak E-21, not just B-13. If the conversation is entirely about controls and never about critical operations and tolerances for disruption, they are working from the previous decade of guidance.
  3. They have worked inside a three lines model. Security at a financial institution is challenged by an independent risk function and audited by internal audit. A leader who has only worked where nobody challenged them will find that first quarter difficult.
  4. They can write for a risk committee. Committee papers at a regulated institution have a house style, a length limit and an expectation of a clear recommendation. This is a real skill and it is not evenly distributed.

What it costs

vCISO retainers at Canadian federally regulated institutions, CAD per month
InstitutionRetainerShape
Small trust, loan or insurer, under 150 staff$8,000 to $15,000Fractional leader plus an internal accountable executive with another day job
Mid-size institution, 150 to 600 staff$15,000 to $30,000Usually a bridge to a permanent hire, or embedded cover during one
Larger institutionAdvisory onlyThe seat is internal. Fractional work is specialist: resilience testing, framework review, examination preparation

Those bands sit two to three times above the general Canadian market because the pool of people who have been examined is small and the exposure they accept is larger. Compare that against a permanent hire, where the OSFI premium also applies and pushes the loaded first-year cost well past the general figures on CISO salary in Canada. At a mid-size institution the two options converge, and the deciding factor is usually how quickly you can find anybody at all.

Find a vCISO who has been examined

Tell us your institution type, your supervisory situation and whether the accountable officer seat is filled. We will put it in front of Canadian providers with financial institution experience.

Get matched

Common questions

Can an OSFI regulated institution use a virtual CISO?

Yes, with a condition. OSFI expects clear accountability for technology and cyber risk at senior management level within the institution, and Guideline B-10 states that outsourcing an activity does not transfer accountability for it. So the expertise can be fractional and the accountability has to sit with a named internal executive. The arrangement that works is an internal accountable officer supported by a fractional security leader who drafts the framework and prepares committee material.

Does OSFI require a CISO by title?

No. The guidance is about accountability and oversight rather than an organisation chart, so the title can be head of technology risk, chief risk officer or something else. What matters is that a senior individual is clearly accountable, that the board has appropriate oversight, and that you can evidence both. A title with no budget, no reporting line to the board and no authority satisfies nothing.

Does B-10 apply to hiring a vCISO?

Yes. Engaging a security leader is a third-party arrangement, and if it is assessed as critical you should expect documented due diligence, audit and access rights extending to OSFI, control of subcontracting, attention to data location, an exit plan and ongoing monitoring. Institutions routinely apply B-10 rigorously to cloud providers and then engage a vCISO on a two page order form, which is the inconsistency an examiner notices first.

What is different about E-21 for security leadership?

E-21 frames cyber inside operational resilience rather than as a control domain. That means identifying critical operations, setting tolerances for disruption, and testing severe but plausible scenarios against them. In practice the security leader has to be able to say how long a given operation can be down before it matters, and to have tested it, rather than presenting a control maturity score.

We sell to a Canadian bank. Are we OSFI regulated?

No. OSFI regulates the institution, not its suppliers. What reaches you is the bank's own third-party risk process under B-10, which is why the diligence is heavy, why the contract has audit rights and incident notification windows in it, and why they ask who your accountable security person is. That is a vendor risk problem, covered on vendor risk management, and a vCISO is a normal and proportionate answer to it.