Vendor risk for Canadian regulations
VendorBreach maps your vendors to OSFI B-10, OSFI B-13, PIPEDA, Quebec Law 25 and CPCSC, in the same compliance module used for NIS2 and DORA.
The Canadian framework pack
OSFI B-10
Federally regulated banks, insurers and pension plans
Third-party governance, due diligence, contracts, monitoring and exit plans.
OSFI B-13
Federally regulated financial institutions
Technology and cyber risk: operations, resilience, cyber security and incident response.
PIPEDA
Private-sector organisations across Canada
You stay accountable for personal information your vendors process. Safeguards and breach reporting.
Quebec Law 25
Organisations handling Quebecers' personal information
Written contracts, assessments before data leaves Quebec, incident register and notification.
CPCSC Levels 1–3
Defence suppliers
Switched on per vendor when you tag it as a defence supplier.
Bill C-8 (CCSPA)Pending legislation
Designated critical-infrastructure operators
Off by default. Reporting window set in your settings.
What's included
- Controls linked to questionnaire answers and outside-in scan signals
- A Canadian regulated vendor questionnaire, including data-residency questions
- PIPEDA switched on for Canadian workspaces, with the others suggested
- Canadian coverage section in every vendor PDF export
Where your data lives
Customer data is stored in the United States (AWS US-East-2, Ohio) today. Canadian data region coming.