Compliance frameworks, security audits, and quality certifications this company maintains.
RBC complies with OSFI Guideline B-20 on residential mortgage underwriting, applying stress test requirements to ensure mortgage borrowers qualify at the higher of the contracted rate plus 2% or the Bank of Canada qualifying rate — a critical risk management framework given RBC's position as Canada's largest mortgage lender.
Regulatory
Basel III / FRTB
CompliantRBC meets Basel III capital adequacy requirements including the Fundamental Review of the Trading Book (FRTB) framework, maintaining a CET1 ratio of 13.1% as of Q4 2024 — well above OSFI's minimum and one of the strongest capital positions among global systemically important banks (G-SIBs).
Privacy
PIPEDA / Bill C-27
CompliantRBC complies with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and is preparing for the successor Consumer Privacy Protection Act under Bill C-27, governing how RBC collects, uses, and discloses personal financial data for 17 million Canadian banking clients.
RBC Capital Markets and RBC Wealth Management's European operations comply with the EU General Data Protection Regulation (GDPR), applying consent management, data subject rights, and cross-border transfer restrictions for client data across RBC's London, Amsterdam, and European offices.
Regulatory
SOX (Sarbanes-Oxley)
CompliantRBC complies with the U.S. Sarbanes-Oxley Act for its NYSE-listed securities and U.S. broker-dealer operations including City National Bank and RBC Capital Markets USA, maintaining internal controls over financial reporting audited by PricewaterhouseCoopers.
RBC's European operations are implementing the EU Digital Operational Resilience Act (DORA) requirements ahead of the January 2025 deadline, ensuring its ICT risk management framework, third-party vendor controls, and digital incident reporting procedures meet EU supervisory expectations.
RBC's information security management program maintains ISO 27001 certification for core banking infrastructure and client data systems, applying a systematic risk management framework that governs access controls, encryption standards, and incident response across RBC's global technology operations.
RBC maintains PCI DSS Level 1 certification for its credit and debit card processing operations — the highest compliance tier — covering transaction processing for RBC Avion Visa, RBC debit cards, and merchant acquiring services processing billions of card transactions annually.
RBC's digital banking platforms including RBC Online Banking and the RBC Mobile app comply with WCAG 2.1 Level AA accessibility standards, ensuring that clients with visual, auditory, motor, and cognitive disabilities can access RBC's full digital banking suite through screen reader support, keyboard navigation, and high-contrast display options.
Security
OSFI Guideline B-13
CompliantRBC complies with OSFI Guideline B-13 on technology and cyber risk management, implementing enterprise-wide controls to protect critical banking infrastructure, customer data, and digital banking services in alignment with Canada's federal financial sector cybersecurity expectations.