Governance and the regulatory map
Quantum Readiness for Banking Professionals: all chapters
- 1. What quantum threatens in a bank, and what it doesn't
- 2. Where cryptography lives in a payments estate
- 3. Building a cryptographic inventory
- 4. Deciding what to fix first
- 5. Crypto-agility first
- 6. Vendors and third parties
- 7. Governance and the regulatory map
- 8. A phased roadmap
- Readiness self-assessment
- Glossary
On this page
Everything in the previous chapters, from inventory and prioritisation to agility and suppliers, depends on one thing: someone owning the programme for long enough to see it through. Post-quantum migration runs into the mid-2030s, crosses almost every part of the bank, and competes with every other priority for budget. Without clear governance, it stalls in committee. This chapter covers who should own it, how to report on it, and what regulators actually expect.
Who owns it
The G7 Cyber Expert Group's roadmap for the financial sector calls for executive ownership of post-quantum migration, and for good reason. The work crosses security, infrastructure, applications, data, procurement, risk and the business lines. Each owns a piece; none owns the whole.
Larkfield settled on this structure:
| Role | Who at Larkfield | Responsible for |
|---|---|---|
| Executive sponsor | Chief Information Officer | Funding, priority against other programmes, escalation, board reporting |
| Programme owner | A senior programme manager in the technology risk office | Plan, sequencing, inventory ownership, progress tracking |
| Technical authority | Head of cryptographic services, with enterprise architecture | Algorithm choices, standards, agility requirements |
| Working group | Leads from applications, infrastructure, PKI, data, vendor management, payments operations and risk | Delivering their part of the inventory and migration |
| Second line | Technology and cyber risk management | Independent challenge of risk ratings and progress |
| Third line | Internal audit | Periodic assurance that the programme is working as reported |
Notice where the programme owner sits: in the technology risk office, not in the security team. That was a deliberate choice. Security provides the expertise, but the work is mostly inventory, prioritisation, supplier management and change, and it needs someone whose job is to coordinate across teams.
Put it on the risk register
A risk that isn't recorded doesn't get managed. Larkfield's technology risk register now carries an entry along these lines:
Risk: Quantum computing advances could allow adversaries to decrypt recorded confidential data and forge digital signatures that rely on current public-key cryptography. Cause: widespread use of RSA and elliptic-curve cryptography across the bank and its suppliers, with limited inventory and crypto-agility. Impact: loss of customer and payment confidentiality, fraudulent payment instructions, regulatory and reputational harm. Current controls: pilot inventory, supplier questionnaire. Planned actions: see post-quantum roadmap.
Writing the risk this way does two things. It names the cause in terms the programme can actually change (inventory and agility), and it ties the risk to a plan that can be reported on.
Measure what matters
Quantum readiness is hard to report because nothing visible happens for long stretches. Larkfield chose a small set of measures that move as real work gets done.
- Inventory coverage: the share of business-critical flows inventoried, and the share of records marked documented rather than inferred.
- Certificate automation: the share of certificates renewed automatically.
- Exposure reduced: the share of high-exposure connections using hybrid key agreement.
- Supplier readiness: Tier 1 suppliers rated Ready or On track.
- Blockers cleared: HSM and certificate authority readiness.
- Agility debt: the number of hard-coded or pinned high-priority items remaining.
Six numbers, reported quarterly to the steering committee and twice a year to the board risk committee, proved enough. Avoid a single "quantum readiness percentage". It hides more than it shows.
What regulators and standard setters are saying
This is where programmes most often overstate their case. Precision builds credibility with risk committees and supervisors alike, so it's worth being exact about what each source says and whom it binds.
Last verified: 11 October 2026. Each source links to the primary document. Status types: an applicable obligation applies to Canadian banks today; a government milestone binds government systems; draft guidance may change; a planning signal shows direction without binding anyone.
| Source | What it says, and for whom | Status for a Canadian bank |
|---|---|---|
| OSFI Guideline B-13 | Federally regulated financial institutions must manage technology and cyber risk, including cryptography, within their risk frameworks | Applicable risk-management obligation. Quantum risk falls under it; it sets no post-quantum deadline |
| OSFI Guideline B-10 | Federally regulated financial institutions must manage third-party risk, including suppliers' technology risks | Applicable risk-management obligation. Covers the supplier work in Chapter 6 |
| Canadian Centre for Cyber Security, ITSM.40.001 | Government of Canada departments: plans by April 2026, high-priority systems by end of 2031, the rest by end of 2035 | Government migration milestone. Binds federal systems, not banks; sets the national tone and algorithm guidance |
| NIST IR 8547 (initial public draft) | Proposes deprecating RSA and elliptic-curve cryptography from 2030 and disallowing them by 2035, for US federal use | Draft transition guidance. Not binding on Canadian banks, but the most widely used reference timeline; suppliers will follow it |
| NSA CNSA 2.0 | US national security systems move to the strongest post-quantum parameters; new acquisitions compliant from 2027 | Binding only for US national security systems. A common mistake is to quote these as bank deadlines |
| EU coordinated roadmap | EU member states: inventories by end of 2026, high-risk systems by 2030, the rest by 2035 | Regional planning roadmap. Not directly applicable; relevant to banks with EU operations |
| G7 Cyber Expert Group roadmap | Coordinated financial-sector roadmap; calls for executive ownership and crypto-agility | Industry planning signal. States that it doesn't set regulatory expectations, but signals where supervisors are heading |
OSFI's posture is worth stating carefully, because it's easy to overstate. There's no standalone post-quantum mandate for Canadian banks. OSFI expects quantum risk to be managed within existing technology and cyber-risk obligations, and in December 2023 OSFI and the Financial Consumer Agency of Canada surveyed financial institutions on their readiness for AI and quantum computing. The defensible summary for a committee is: there is no hard deadline aimed at us yet, but the direction is unmistakable, and we are expected to be managing the risk now.
Several independent authorities point to the same shape: inventories now, high-risk systems around 2030, everything by 2035. A bank doesn't need a deadline addressed to it personally to read that direction.
Funding a long programme
A programme that runs a decade can't be funded one year at a time without losing momentum. Larkfield structured its funding in three layers: a small standing budget for the programme office and inventory; agility and supplier work funded through existing technology refresh and procurement cycles wherever possible; and specific migration projects funded through the normal investment process, each tied to the risk register entry. Folding work into refresh cycles that are already planned is the cheapest way to make progress, and it only works if the requirement is known before the refresh is designed.
Five questions for your next steering committee
- Who is the single accountable owner, and who is the executive sponsor?
- Is quantum risk on the technology risk register, with a cause the programme can change?
- What do we report, to whom, and how often?
- Can we state precisely which regulatory sources apply to us, and which don't?
- Are post-quantum requirements built into upcoming technology refreshes and procurements?
- A long, cross-cutting programme needs one accountable owner, an executive sponsor and a place on the risk register.
- Report a handful of measures that move with real work, not a single readiness percentage.
- Be exact about regulation: in Canada, quantum risk sits under existing OSFI guidelines, while other dates signal direction rather than bind.
Sources and further reading
Larkfield Bank is fictional and its figures are illustrative. Everything else is drawn from the public sources below. Tags show what kind of source each one is. A standard or government guidance is an official document; a peer-reviewed paper has been checked by other experts; a preprint has not been peer-reviewed yet; an experiment reports a real-world demonstration; a company announcement is the company's own account. Checked on 11 October 2026. Spotted an error? Email hello@plainquantum.com.
- Government guidanceGuideline B-13: Technology and Cyber Risk ManagementOffice of the Superintendent of Financial Institutions (OSFI), 2022
- Government guidanceGuideline B-10: Third-Party Risk ManagementOffice of the Superintendent of Financial Institutions (OSFI), 2023
- Government guidanceRoadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)Canadian Centre for Cyber Security, 2025
- Government guidanceNIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography StandardsNIST, 2024
- Government guidanceNSA releases future quantum-resistant algorithm requirements for national security systems (CNSA 2.0)US National Security Agency, 2022
- Government guidanceA Coordinated Implementation Roadmap for the Transition to Post-Quantum CryptographyEuropean Commission / NIS Cooperation Group, 2025
- Industry guidanceG7 Cyber Expert Group: coordinated roadmap for the transition to post-quantum cryptography in the financial sectorG7 Cyber Expert Group (via US Treasury), 2026