Compliance News | July 25, 2024
The Financial Services Regulatory of Ontario (FSRA) released its IT Risk Management Guidance on April 1, 2024.
The guidance, which is in effect as of the release date, affects all FSRA-regulated entities, which include pension and benefits plans. The guidance includes seven practices for effective IT risk management and outlines the process for notifying FSRA in the event of an IT risk incident.
FSRA expects all regulated entities or individuals to follow these practices:
An IT incident may be considered material if:
After a material IT risk incident occurs, plan administrators should notify FSRA within 72 hours.
Plan administrators may notify FSRA of a material incident by completing the IT risk incident notification form and sending it to FSRA by:
FSRA has established a by following this three-phase process for material IT risk incidents:
Trustees should implement FSRA’s recommendations and follow the seven practices outlined in the guidance.
The guidance will be reviewed no later than June 2028.
Don't miss out. Join 16,000 others who already get the latest insights from Segal.