Steadpoint IT (416) 000-0000 Book an assessment

Home / Industries / Insurance Brokerages & MGAs

IT Support for Insurance Brokerages & MGAs

If your brokerage or MGA places business with a federally regulated insurer, you are a third party under OSFI Guideline B-10, which took effect on 1 May 2024. That means the carrier is now required to assess you: incident notification triggers and deadlines written into your contract, audit and log access rights, tested business continuity and incident response plans. The questionnaire arrives addressed to a twelve-person office with no IT department, and almost every published guide on the subject is written for the institution doing the assessing rather than the firm being assessed.

What actually goes wrong in this sector

  • OSFI B-10 third-party risk questionnaires from carriers you cannot afford to lose
  • Broker management systems holding personal and financial data under PIPEDA
  • Cyber insurance renewal on a business whose entire product is insurance
  • Staff working from home on personal devices touching client files
  • No internal IT, and a principal broker who is already the compliance officer

Where we usually start

Check this for yourself

Every obligation named on this page comes from a published source. Here they are, so you do not have to take our word for any of it.

Not sure what you actually need?

Book a 20-minute call. We will tell you plainly whether you have a problem worth paying to solve, including when the answer is that you do not.