Cybersecurity Compliance Training for Financial Services Organizations in Canada

Financial services organizations in Canada answer to two regulators on cybersecurity training, not one. OSFI Guideline B-13 sets cyber risk governance expectations for federally regulated banks and insurers. FINTRAC sets a separate written training obligation tied to anti-money laundering law. Miss either one and an examiner will flag a program built on paper alone.
Not sure where your current training program stands against both requirements? Request corporate training information and build a plan matched to your regulatory obligations.
Two Regulators, Two Training Obligations
Banks, trust companies, insurance companies, and their foreign branches answer to the Office of the Superintendent of Financial Institutions on technology and cyber risk. Reporting entities under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act answer to FINTRAC on a separate track, covering banks, credit unions, life insurers, and money services businesses. Most financial institutions sit under both regimes at once, and each names staff training as a distinct requirement, not a suggestion.
What OSFI Guideline B-13 Expects From Your Team
OSFI published Guideline B-13 in July 2022, and it sets three areas of expectation: governance and accountability, technology operations and resilience, and cyber security itself. On the training side, the guideline asks institutions to build a culture of risk awareness around technology and cyber risk across the organization, run employee awareness programs, and regularly test staff on their ability to spot cyber threats and use the reporting tools in place. A slide deck shown once a year does not meet the bar OSFI sets. Testing implies measurement, and measurement implies a record an examiner will ask to see.
What FINTRAC Requires in Writing
FINTRAC’s compliance guidance requires a written, ongoing training program covering your obligations under the Act, how money laundering and terrorist financing work, where your own operations sit exposed, and what staff do when they spot a suspicious transaction. The training reach is broad by design.
- Frontline staff and agents who deal with clients directly
- Anyone handling cash, funds, or virtual currency
- Compliance officers, senior management, IT staff, and auditors overseeing the program
FINTRAC leaves the schedule to you, provided it is documented. Monthly, annual, and semi-annual cycles all work, and a new hire or a procedure change should trigger training on its own rather than waiting for the next scheduled date.
Where Compliance Programs Fall Short
The gap between a training program on paper and one which holds up under review comes down to specifics. A generic session on password hygiene satisfies neither regulator. OSFI wants proof staff recognize and report cyber threats. FINTRAC wants proof staff understand how the institution itself is exposed to money laundering risk and what their own role is in catching it. Treating both requirements as one awareness session, or treating cybersecurity training as an IT department problem separate from compliance, leaves gaps in exactly the areas an examiner checks first.
Building One Program for Both Regulators
Split your curriculum by role instead of running one session for everyone. Frontline and client-facing staff need AML pattern recognition and reporting steps under the FINTRAC track. IT, security, and risk staff who manage the controls behind B-13 need deeper technical training on the systems they administer. Document every session with a date, a topic, and a completion list. An examiner reviews this record first, ahead of the training content itself.
For the technical side of this split, your IT and security staff benefit from structured, hands-on cybersecurity training going beyond awareness into the controls B-13 names directly: access management, incident detection, and secure system design. Pair this with the vendor and role-based options in the full certification course catalogue to match training to the specific role each employee holds.
Your Next Step
Two regulators, two training obligations, and one compliance file an examiner opens at the same time. Build your program to answer both instead of patching gaps after a review flags them. Book a team training consultation and get a curriculum split by role, documented by design, and ready before your next audit.
