OSFI Guideline E-21

Operational resilience you can actually test

Critical operations, defensible tolerances, dependency maps that reach the fourth party, and a scenario testing programme ready well before the September 1, 2027 deadline.

Book a briefing
The obligation

Adherence has passed. Testing is what is left.

Guideline E-21 asks institutions to identify their critical operations, set tolerances for disruption, map the people, processes, technology, data and third parties each one depends on, and then prove through testing that they can stay inside those tolerances in severe but plausible conditions.

Adherence was expected from September 1, 2026; scenario testing is due September 1, 2027. Most institutions have the documentation. Far fewer have run a test that produced findings they had to act on, which is the part supervisors read closely.

Where programmes break

Four common gaps.

Critical operations defined too broadly

When everything is critical, tolerances become meaningless and testing has no focus. We narrow to the operations whose failure causes intolerable harm, with the reasoning written down.

Tolerances with no basis

A four-hour tolerance nobody can defend is a finding. Tolerances need to trace to harm — to clients, to the institution, to financial stability.

Dependency maps that stop at the system

Resilience fails at the fourth-party, the single expert, and the manual workaround nobody documented. The map has to reach those.

Testing designed to pass

A scenario that everyone survives teaches nothing. Tests should be severe enough to generate findings, and the remediation record is the evidence.

Programme

The sequence we run.

  1. 01

    Identify

    Critical operations named, justified and approved, with the harm rationale documented.

  2. 02

    Map

    End-to-end dependencies including people, third and fourth parties, data flows and workarounds.

  3. 03

    Set tolerances

    Disruption tolerances tied to harm, with current capability measured honestly against them.

  4. 04

    Test and remediate

    Severe-but-plausible scenarios run, findings logged, gaps closed and reported to the board.

Deliverables

What you leave with.

  • An approved critical operations register with documented rationale
  • End-to-end dependency maps, including third and fourth-party concentration
  • Disruption tolerances traced to client, institutional and systemic harm
  • A scenario testing programme with the first test designed, run and documented
  • A findings and remediation log with owners, dates and residual-risk positions
  • Board reporting that shows where you are inside tolerance and where you are not
FAQ

Common questions.

How does E-21 relate to our BCP?
Business continuity plans for the institution's recovery; E-21 asks you to protect the delivery of the operation to the client, whatever happens internally. Existing BCP and disaster recovery work feeds in, but the framing and the tolerances are different.
How does AI fit into resilience?
Once a model sits inside a critical operation, it is a dependency like any other — and often a concentrated one, since the provider, the data pipeline and the expertise all tend to sit with a single party.
What does a first scenario test look like?
One critical operation, one severe but plausible disruption, run with the actual people who would respond. Half a day, honest findings, and a remediation plan that reflects what really happened rather than what the plan says would happen.

Book a 30-minute briefing

A short conversation is usually enough to tell you whether this is the right first move — and what it would cost.

Book a briefing