OSFI E-21: Scenario Testing Moves from Methodology to Evidence
September 1, 2026 marked an important milestone for federally regulated financial institutions in Canada. Under OSFI’s Guideline E-21 on Operational Risk Management and Resilience, institutions should now have identified and mapped their critical operations, established tolerances for disruption, developed their scenario testing methodology, and begun testing.
The next milestone is already approaching.
By September 1, 2027, scenario testing should be completed for all critical operations.
That creates a different challenge for resilience teams. The question is increasingly moving from Do we have a scenario testing framework? to What is our testing actually telling us about our ability to operate through disruption?
What OSFI expects from scenario testing
E-21 makes an important distinction between operational risk scenario analysis and operational resilience scenario testing.
Scenario analysis can be used to identify potential risk events and consider their impacts, controls and mitigating actions.
Scenario testing goes further. OSFI describes it as assessing whether critical operations can continue within established tolerances for disruption under severe but plausible conditions. The testing should take an end-to-end view across the people, processes, technology, information, facilities and third parties required to deliver a critical operation.
That distinction matters.
A scenario can generate a productive discussion and still provide limited evidence about whether an organization can actually stay within its tolerance for disruption.
Under E-21, the exercise needs to help answer a more concrete question:
What happens to this critical operation when the assumptions supporting it begin to fail?
The scenarios should create meaningful pressure
OSFI expects institutions to test a range of severe but plausible conditions. Its examples include power outages, large-scale technology failures, critical third-party disruptions, cyber incidents, natural disasters and pandemics.
It also explicitly calls for consideration of concurrent scenarios and disruptions of longer duration.
This is where scenario design becomes important.
Critical operations rarely depend on one system, one team or one supplier. A technology failure may create customer impacts. A third-party outage may force employees onto manual processes. A cyber event may simultaneously affect technology availability, communications, decision-making and external stakeholders.
Testing those dependencies requires scenarios that evolve far enough to expose them.
For resilience teams, that means moving beyond the single-event tabletop toward exercises that can introduce changing conditions, consequences and decisions while tracking what happens to the critical operation as a whole.
Testing methodology should match the question
E-21 does not prescribe one testing format.
OSFI specifically identifies tabletop exercises, simulations and live-systems testing among the methodologies institutions can use, with the approach determined by the criticality and risk of the operation being tested. That gives institutions room to build a testing portfolio rather than forcing every scenario into the same exercise format.
- A tabletop may be appropriate for exploring executive decisions and escalation.
- A simulation can put a larger group of participants through evolving conditions and capture how they respond.
- Live-system testing can validate whether technical capabilities actually perform as expected.
Together, these approaches can create a much richer body of evidence about resilience.
Scenario testing is supposed to evolve
One of the most important lines in E-21 may also be one of the easiest to overlook:
Scenario testing is iterative.
OSFI expects testing to become more sophisticated over time, with results from previous tests informing the design of future ones. Testing frequency and intensity should reflect the criticality and risk of the operation, and significant changes in the risk environment can warrant testing outside the normal cycle.
That changes the role of an exercise.
Each scenario becomes an input into the next.
Which dependencies consistently create friction? Where do participants struggle to make decisions? Which assumptions fail under pressure? Where does the organization approach or breach its tolerance? Were previously identified weaknesses actually addressed?
Over time, those signals can provide a much clearer picture of capability than a collection of individual exercise reports.
The 2027 milestone creates a scale challenge
For many institutions, the practical challenge over the next year will be volume.
Every critical operation needs to be tested by September 1, 2027. Testing needs to consider end-to-end dependencies. Critical third parties should be involved where possible. The scenarios need to be severe but plausible. And the program is expected to mature based on what previous testing reveals.
Doing that across an enterprise creates a significant design, facilitation and evidence-management workload.
It also creates an opportunity to rethink how scenario testing is delivered.
Instead of treating every exercise as a standalone event, institutions can build a continuous testing capability: reusable scenario components, different testing modalities, structured evidence capture, repeatable measurement and insights that accumulate across exercises.
That makes it possible to test more frequently without simply multiplying the administrative burden.
From exercises to capability intelligence
At iluminr, we think the value of scenario testing extends beyond demonstrating that a test occurred.
Every response generates evidence.
How quickly did people recognize the problem? Where did escalation stall? Which dependencies became constraints? How consistently did teams make decisions? Which capabilities held up as conditions changed? Where did the operation begin approaching its tolerance for disruption?
When that evidence is captured consistently across scenarios, testing becomes a way to understand how organizational capability is changing over time.
That is particularly relevant to E-21.
OSFI’s expectations create a clear testing requirement. The larger opportunity is to use that testing program to build a continuously improving understanding of how critical operations actually perform under pressure.
By September 2027, Canadian financial institutions will need to have tested all of their critical operations.
The more useful question may be what they will have learned about them along the way.





.png)