Compliance frameworks, security audits, and quality certifications this company maintains.
BMO adheres to OSFI Guideline B-20 on residential mortgage underwriting practices, requiring stress-testing of all uninsured mortgage borrowers at the higher of the Bank of Canada qualifying rate or the contractual rate plus 2%, governing BMO's $120B+ CAD residential mortgage portfolio.
Regulatory
Basel III / FRTB
CompliantBMO maintains capital ratios exceeding OSFI's Basel III requirements, with a Common Equity Tier 1 (CET1) ratio above 12.5% and compliance with the Fundamental Review of the Trading Book (FRTB) market risk capital framework governing BMO Capital Markets' trading book positions.
Regulatory
CDIC Deposit Protection
CompliantBMO is a member institution of the Canada Deposit Insurance Corporation, providing eligible depositors with up to $100,000 CAD in protection per insured category. BMO's CDIC compliance covers deposit product structures, disclosure requirements, and annual CDIC assessment contributions.
BMO's Anti-Money Laundering program complies with FINTRAC regulations under Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act, including transaction monitoring, large cash transaction reporting, suspicious transaction reporting, and know-your-customer verification across all BMO business lines.
As a NYSE-listed company, BMO complies with the Sarbanes-Oxley Act Section 404, requiring annual management assessment and external auditor attestation of BMO's internal controls over financial reporting. PricewaterhouseCoopers serves as BMO's external auditor for SOX purposes.
BMO maintains PCI DSS Level 1 certification for its credit card processing infrastructure covering BMO Mastercard consumer and business card portfolios, merchant payment solutions, and BMO's card-not-present e-commerce payment processing systems.
BMO's Canadian personal information handling practices comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's evolving Consumer Privacy Protection Act (CPPA), governing data collection, consent, retention, and breach notification for BMO's 12 million+ Canadian customer records.
BMO's information security management system is certified to ISO 27001, covering cybersecurity controls for BMO's enterprise IT infrastructure, online banking platforms, mobile app security, and third-party vendor risk management across BMO's North American technology environment.
Environmental
TCFD Climate Disclosure
CompliantBMO publishes annual Task Force on Climate-related Financial Disclosures (TCFD)-aligned climate reports covering physical and transition climate risk in BMO's loan portfolio, scenario analysis for 1.5°C and 2°C pathways, and progress toward BMO's $300B CAD sustainable finance commitment.
BMO's online banking platform and BMO Mobile Banking app conform to Web Content Accessibility Guidelines (WCAG) 2.1 Level AA, ensuring BMO's digital banking services are accessible to customers with visual, auditory, motor, and cognitive disabilities across web and mobile interfaces.