PLAIN QUANTUM
← Guide overview
Quantum Readiness for Banking Professionals · Chapter 7 of 8

Governance and the regulatory map

Quantum Readiness for Banking Professionals: all chapters
On this page
  1. Who owns it
  2. Put it on the risk register
  3. Measure what matters
  4. What regulators and standard setters are saying
  5. Funding a long programme
  6. Five questions for your next steering committee
  7. Sources and further reading

Everything in the previous chapters, from inventory and prioritisation to agility and suppliers, depends on one thing: someone owning the programme for long enough to see it through. Post-quantum migration runs into the mid-2030s, crosses almost every part of the bank, and competes with every other priority for budget. Without clear governance, it stalls in committee. This chapter covers who should own it, how to report on it, and what regulators actually expect.

Who owns it

The G7 Cyber Expert Group's roadmap for the financial sector calls for executive ownership of post-quantum migration, and for good reason. The work crosses security, infrastructure, applications, data, procurement, risk and the business lines. Each owns a piece; none owns the whole.

Larkfield settled on this structure:

RoleWho at LarkfieldResponsible for
Executive sponsorChief Information OfficerFunding, priority against other programmes, escalation, board reporting
Programme ownerA senior programme manager in the technology risk officePlan, sequencing, inventory ownership, progress tracking
Technical authorityHead of cryptographic services, with enterprise architectureAlgorithm choices, standards, agility requirements
Working groupLeads from applications, infrastructure, PKI, data, vendor management, payments operations and riskDelivering their part of the inventory and migration
Second lineTechnology and cyber risk managementIndependent challenge of risk ratings and progress
Third lineInternal auditPeriodic assurance that the programme is working as reported
An illustrative structure. The essential points are a single accountable owner and a sponsor senior enough to hold budget.

Notice where the programme owner sits: in the technology risk office, not in the security team. That was a deliberate choice. Security provides the expertise, but the work is mostly inventory, prioritisation, supplier management and change, and it needs someone whose job is to coordinate across teams.

Put it on the risk register

A risk that isn't recorded doesn't get managed. Larkfield's technology risk register now carries an entry along these lines:

Risk: Quantum computing advances could allow adversaries to decrypt recorded confidential data and forge digital signatures that rely on current public-key cryptography. Cause: widespread use of RSA and elliptic-curve cryptography across the bank and its suppliers, with limited inventory and crypto-agility. Impact: loss of customer and payment confidentiality, fraudulent payment instructions, regulatory and reputational harm. Current controls: pilot inventory, supplier questionnaire. Planned actions: see post-quantum roadmap.

Writing the risk this way does two things. It names the cause in terms the programme can actually change (inventory and agility), and it ties the risk to a plan that can be reported on.

Measure what matters

Quantum readiness is hard to report because nothing visible happens for long stretches. Larkfield chose a small set of measures that move as real work gets done.

  • Inventory coverage: the share of business-critical flows inventoried, and the share of records marked documented rather than inferred.
  • Certificate automation: the share of certificates renewed automatically.
  • Exposure reduced: the share of high-exposure connections using hybrid key agreement.
  • Supplier readiness: Tier 1 suppliers rated Ready or On track.
  • Blockers cleared: HSM and certificate authority readiness.
  • Agility debt: the number of hard-coded or pinned high-priority items remaining.

Six numbers, reported quarterly to the steering committee and twice a year to the board risk committee, proved enough. Avoid a single "quantum readiness percentage". It hides more than it shows.

What regulators and standard setters are saying

This is where programmes most often overstate their case. Precision builds credibility with risk committees and supervisors alike, so it's worth being exact about what each source says and whom it binds.

Last verified: 11 October 2026. Each source links to the primary document. Status types: an applicable obligation applies to Canadian banks today; a government milestone binds government systems; draft guidance may change; a planning signal shows direction without binding anyone.

SourceWhat it says, and for whomStatus for a Canadian bank
OSFI Guideline B-13Federally regulated financial institutions must manage technology and cyber risk, including cryptography, within their risk frameworksApplicable risk-management obligation. Quantum risk falls under it; it sets no post-quantum deadline
OSFI Guideline B-10Federally regulated financial institutions must manage third-party risk, including suppliers' technology risksApplicable risk-management obligation. Covers the supplier work in Chapter 6
Canadian Centre for Cyber Security, ITSM.40.001Government of Canada departments: plans by April 2026, high-priority systems by end of 2031, the rest by end of 2035Government migration milestone. Binds federal systems, not banks; sets the national tone and algorithm guidance
NIST IR 8547 (initial public draft)Proposes deprecating RSA and elliptic-curve cryptography from 2030 and disallowing them by 2035, for US federal useDraft transition guidance. Not binding on Canadian banks, but the most widely used reference timeline; suppliers will follow it
NSA CNSA 2.0US national security systems move to the strongest post-quantum parameters; new acquisitions compliant from 2027Binding only for US national security systems. A common mistake is to quote these as bank deadlines
EU coordinated roadmapEU member states: inventories by end of 2026, high-risk systems by 2030, the rest by 2035Regional planning roadmap. Not directly applicable; relevant to banks with EU operations
G7 Cyber Expert Group roadmapCoordinated financial-sector roadmap; calls for executive ownership and crypto-agilityIndustry planning signal. States that it doesn't set regulatory expectations, but signals where supervisors are heading
Recheck each row against its source whenever a standard or roadmap is updated.

OSFI's posture is worth stating carefully, because it's easy to overstate. There's no standalone post-quantum mandate for Canadian banks. OSFI expects quantum risk to be managed within existing technology and cyber-risk obligations, and in December 2023 OSFI and the Financial Consumer Agency of Canada surveyed financial institutions on their readiness for AI and quantum computing. The defensible summary for a committee is: there is no hard deadline aimed at us yet, but the direction is unmistakable, and we are expected to be managing the risk now.

Several independent authorities point to the same shape: inventories now, high-risk systems around 2030, everything by 2035. A bank doesn't need a deadline addressed to it personally to read that direction.

Funding a long programme

A programme that runs a decade can't be funded one year at a time without losing momentum. Larkfield structured its funding in three layers: a small standing budget for the programme office and inventory; agility and supplier work funded through existing technology refresh and procurement cycles wherever possible; and specific migration projects funded through the normal investment process, each tied to the risk register entry. Folding work into refresh cycles that are already planned is the cheapest way to make progress, and it only works if the requirement is known before the refresh is designed.

Five questions for your next steering committee

  1. Who is the single accountable owner, and who is the executive sponsor?
  2. Is quantum risk on the technology risk register, with a cause the programme can change?
  3. What do we report, to whom, and how often?
  4. Can we state precisely which regulatory sources apply to us, and which don't?
  5. Are post-quantum requirements built into upcoming technology refreshes and procurements?
Three things to remember
  • A long, cross-cutting programme needs one accountable owner, an executive sponsor and a place on the risk register.
  • Report a handful of measures that move with real work, not a single readiness percentage.
  • Be exact about regulation: in Canada, quantum risk sits under existing OSFI guidelines, while other dates signal direction rather than bind.

Sources and further reading

Larkfield Bank is fictional and its figures are illustrative. Everything else is drawn from the public sources below. Tags show what kind of source each one is. A standard or government guidance is an official document; a peer-reviewed paper has been checked by other experts; a preprint has not been peer-reviewed yet; an experiment reports a real-world demonstration; a company announcement is the company's own account. Checked on 11 October 2026. Spotted an error? Email hello@plainquantum.com.

  1. Government guidanceGuideline B-13: Technology and Cyber Risk ManagementOffice of the Superintendent of Financial Institutions (OSFI), 2022
  2. Government guidanceGuideline B-10: Third-Party Risk ManagementOffice of the Superintendent of Financial Institutions (OSFI), 2023
  3. Government guidanceRoadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)Canadian Centre for Cyber Security, 2025
  4. Government guidanceNIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography StandardsNIST, 2024
  5. Government guidanceNSA releases future quantum-resistant algorithm requirements for national security systems (CNSA 2.0)US National Security Agency, 2022
  6. Government guidanceA Coordinated Implementation Roadmap for the Transition to Post-Quantum CryptographyEuropean Commission / NIS Cooperation Group, 2025
  7. Industry guidanceG7 Cyber Expert Group: coordinated roadmap for the transition to post-quantum cryptography in the financial sectorG7 Cyber Expert Group (via US Treasury), 2026