Vendor risk for Canadian regulations

    VendorBreach maps your vendors to OSFI B-10, OSFI B-13, PIPEDA, Quebec Law 25 and CPCSC, in the same compliance module used for NIS2 and DORA.

    The Canadian framework pack

    OSFI B-10

    Federally regulated banks, insurers and pension plans

    Third-party governance, due diligence, contracts, monitoring and exit plans.

    OSFI B-13

    Federally regulated financial institutions

    Technology and cyber risk: operations, resilience, cyber security and incident response.

    PIPEDA

    Private-sector organisations across Canada

    You stay accountable for personal information your vendors process. Safeguards and breach reporting.

    Quebec Law 25

    Organisations handling Quebecers' personal information

    Written contracts, assessments before data leaves Quebec, incident register and notification.

    CPCSC Levels 1–3

    Defence suppliers

    Switched on per vendor when you tag it as a defence supplier.

    Bill C-8 (CCSPA)
    Pending legislation

    Designated critical-infrastructure operators

    Off by default. Reporting window set in your settings.

    What's included

    • Controls linked to questionnaire answers and outside-in scan signals
    • A Canadian regulated vendor questionnaire, including data-residency questions
    • PIPEDA switched on for Canadian workspaces, with the others suggested
    • Canadian coverage section in every vendor PDF export

    Where your data lives

    Customer data is stored in the United States (AWS US-East-2, Ohio) today. Canadian data region coming.