The Gap the RPAA Closed
Until November 2024 a non-bank neobank existed in Canadian regulation in one capacity only: a money services business registered with FINTRAC, supervised purely along the AML axis. Nobody tested whether it would survive an outage or a cyberattack. Nobody required it to hold user money separately from its own. Nobody had the power to stop it for operational negligence. The Department of Finance stated the gap plainly: the absence of requirements and oversight creates a risk of financial loss from provider insolvency, inadequate risk management and data breaches (RIAS to SOR/2023-229).
The Retail Payment Activities Act (RPAA, S.C. 2021, c. 23, s. 177) and its regulations, SOR/2023-229, closed exactly that gap: prudential and operational supervision of a payments business without a banking licence, administered by the Bank of Canada. It does not replace FINTRAC and does not extend it — it is a second regime alongside, with its own perimeter, duties and sanctions.
And it is not only a cost. Registration became the entry ticket to three adjacent regimes: membership in Payments Canada (Canadian Payments Act s.4(2)(i)), participation in the Real-Time Rail, and accreditation as a participating entity under the Consumer-Driven Banking Act (s.17). The sensible way to schedule registration is backwards from your infrastructure launch date, not forwards from penalty risk.
The Perimeter: Four Steps, "Incidental" and Geography
The Bank has formalised the in-scope test into four steps (Criteria for registering PSPs, 29 June 2026). One: are you a PSP — do you perform a payment function as a business in its own right. Two: is it a retail payment activity — a function in relation to an electronic funds transfer in Canadian currency, another currency or a "prescribed unit". Three: geography. Four: does an exclusion apply.
The decisive word is "incidental". Under RPAA s.2 a PSP performs payment functions "as a service or business activity that is not incidental to another service or business activity", and RPAR s.3 expressly carves out incidental activity. Of the 44 published refusals, 28 (64%) were issued on the ground that the Act does not apply to the applicant or to its payment functions (RPAA s.48(1) plus RPAR s.30(b)(ii)); another 12 because the applicant had ceased or no longer planned retail payment activities, and 4 for failing to answer an information request under s.29(3). The Bank publishes named reasons, which makes this the rarest thing in payments regulation — a public corpus of scope decisions. Crypto exchanges Netcoins, Bitcoin4U, BitNational and Web3Exchange were refused as acting "incidentally to its business of buying and selling cryptocurrency"; London Currency Exchange as incidental to currency exchange itself; Mercedes Pay USA as incidental to selling vehicle options; Yodlee because data aggregation is not a payment function at all; and Visa Canada Corporation because it "is not a PSP as defined by the RPAA" (refusals and revocations).
Geography bites harder on foreign providers than most assume. RPAA s.4 catches anyone with a place of business in Canada; s.5 catches anyone without one who "directs retail payment activities at" persons in Canada and actually serves them — both limbs cumulative. A place of business needs only one indicator: premises, including a home office; Canadian incorporation, federal or provincial; Canadian employees, agents or mandataries. "Directs at" likewise needs only one: marketing aimed at Canadians, a .ca domain, listings in Canadian business directories, or working relationships with Canadian counterparties on retail payments. Settlement in CAD, customer support for Canadians and a high share of Canadian end users are weighed on top. Expansion plans alone do not trigger registration — only actual provision of services does; and a registered foreign PSP must appoint a Canadian agent to receive notices (FAQ, 8 January 2026).
The exclusions are a closed list: closed-loop instruments, prescribed securities transactions and ATM cash withdrawals (s.6); functions performed through systems designated under s.4 of the Payment Clearing and Settlement Act — Lynx, CDSX (s.7); intragroup transfers, but only where no other PSP is involved in the EFT (s.8), three cumulative conditions and a frequent trap for group treasury centres; banks, credit unions, insurance and trust companies (s.9), plus SWIFT named expressly in RPAR s.4; and agents of a registered PSP, but only those on the agent list it has filed (s.10).
Regime Calendar: What Is Live and What Is Coming
| Date | Milestone |
|---|---|
| 29 June 2021 | RPAA receives royal assent |
| 22 November 2023 | Final regulations (SOR/2023-229) and the RIAS costing the regime |
| 1 November 2024 | Registration and enforcement provisions in force; the filing window opens |
| 1–15 November 2024 | Transitional window of 15 days — 1,204 applications filed |
| 16 November 2024 | s.23 in force — performing RPA without registration prohibited; window applicants shielded by s.108 pending the Bank's decision |
| 8 September 2025 | ss.17–22 (RMIRF, incidents, safeguarding, annual report), 24–27 (registry), 45–48, 50, 52–60 in force — supervision begins |
| 6 October 2025 | First actual registry entry — a month after supervision began |
| 17 and 27 February 2026 | First compliance order under s.94(4) — XTM Inc., then a revised order and a CCAA Monitor |
| 26 March 2026 | Royal assent to S.C. 2026, c. 3 (Stablecoin Act and the sixth payment function) and c. 4 (rewriting RPAA ss.48, 52; raising PCMLTFA penalties) |
| 31 March 2026 | First PSP annual report, for calendar 2025; annually thereafter |
| 12 and 29 June 2026 | Publication of Notices of Violation begins; policies on registration criteria and reporting changes |
| 13 August 2026 | Registry snapshot: 1,562 registered / 459 in review / 44 refused / 15 revoked |
| Q4 2026 | Real-Time Rail launch; industry solution assurance testing from Q3 |
| 8 September 2028 | Deadline for the first triennial independent review for the cohort whose duties started 8 September 2025 |
| undetermined | Coming into force of the Stablecoin Act and the sixth payment function — by order of the Governor in Council |
The commencement dates are fixed by SI/2023-70. There is no single date on which operating became unlawful: applicants from the November 2024 window operate lawfully under s.108 until the Bank decides, while those filing from 8 September 2025 must wait for a decision before starting. The rule is best stated by cohort, not by date.
The Registry as of 13 August 2026
The public PSP registry renders in JavaScript, but the data sits in an open JSON API at the Bank of Canada. As of 13 August 2026 it holds 2,080 accounts: 1,562 registered, 459 in review, 44 refused, 15 revoked. The registry changes daily, so every figure below is tied to that date. The RIAS forecast was "approximately 2,500 PSPs in scope"; the live population is 2,021, and the Bank has not commented on the gap.
Foreign providers account for 253 registrations, or 16.2%: United States 135, United Kingdom 36, Singapore 6, Latvia 4, UAE 3, then single entries. Yet only 9 of the 44 refusals involved foreign applicants — it is Canadian filers, applying just in case, who get pushed out of the perimeter.
The least comfortable figure is the queue. Of the 1,204 applications from the November window, 896 were registered, 38 refused, 13 revoked — and 257 remain in review: 21% of the cohort has waited 21 months without a decision. The Bank names the bottleneck directly: the registry is published "as the screenings are finalized and names are provided to the Bank by the Department of Finance" (BoC, 8 September 2025). That is the national security review under ss.32–47, where RPAR ss.26–27 allow 60 days to decide whether to review and a further 180 for the review itself.
What registered PSPs actually do, from a sample of 446 registry records:
| Payment function (RPAA s.2) | Share of PSPs |
|---|---|
| (d) authorisation or transmission of a payment instruction | 82.5% |
| (c) initiation of an electronic funds transfer | 77.6% |
| (a) provision or maintenance of an account | 59.9% |
| (b) holding of funds for end users | 46.0% |
| (e) clearing and settlement services | 24.0% |
Line (b) is the real dividing line on compliance cost: almost half of all registered PSPs hold end-user funds and therefore carry the entire safeguarding block.
Duties: Two Frameworks and Four Reporting Streams
The first framework is the RMIRF, the risk management and incident response framework (RPAA s.17, RPAR ss.5–10), and it must be in writing. RPAR s.5(1) requires measurable reliability targets, a description of human and financial resources, roles including a distinct challenge function, an inventory of assets and processes by criticality, identification of eleven categories of operational risk (from cybersecurity and fraud to change management and third parties), mitigation measures, continuous monitoring and an incident response plan covering incidents at agents and third-party providers. Separately, the document must name a senior officer personally accountable for compliance with RPAR ss.6–10 and RPAA ss.17(1), 18, 19(3). Internal review is required at least annually and before any material change (s.8); testing follows a written methodology (s.9); and an independent review is required every three years — but only where the PSP has an internal or external auditor (s.10).
The second framework is safeguarding (RPAA s.20, RPAR ss.13–17), and it is stricter. Two options work in practice: a trust account used for nothing else, or a segregated account plus insurance or a guarantee for no less than the balance held; the third option, a prescribed manner, was never activated by the regulations. The account provider must come from the RPAA s.9 list or be a foreign institution under a comparable supervisory regime; the insurer must come from the same circle and must not be affiliated with the PSP, with the policy surviving the PSP's insolvency and any restructuring of its obligations, and the Bank notified 30 days before cancellation. The Safeguarding Framework itself (s.15) requires a daily ledger recording each end user's name, contact details and balance, plus a description of how an insolvency practitioner would access records and close a shortfall. RPAR s.16 adds continuous self-testing: identify "as soon as feasible" every instance in which funds would not have been paid out on a triggering event. The safeguarding independent review is also triennial but carries no auditor proviso — it binds everyone holding funds. And s.20(3) bars the bank operating such an account from asserting set-off against those funds.
| Event | Deadline | Provision |
|---|---|---|
| Incident with material impact | Without delay, and no later than 48 hours after the PSP determines materiality; final notice once root cause is established | RPAA s.18; RPAR ss.11–12 |
| Significant change or new activity | At least 5 business days before the change | RPAA s.22 |
| Change to registration information | In several cases 30–60 days before the change | RPAA ss.59–60 |
| Annual report | By 31 March of the following year | RPAR s.18(1) |
| Acquisition of control or prescribed change | New application and re-registration BEFORE the change | RPAA s.24 |
The deadlines are consolidated in the Bank's reminder of 29 June 2026; everything is filed through the PSP Connect portal. Cost of entry per the RIAS: a CAD 2,500 registration fee, one-off and non-refundable, indexed to September CPI (RPAR s.25); average annual compliance cost of CAD 9,719 per PSP against CAD 24.3m a year industry-wide, with 96.4% of PSPs being small businesses under CAD 5m in revenue. The annual assessment fee contemplated by s.99 exists in the statute, but as of 13 August 2026 neither the methodology nor the amounts have been published.
Penalties: the AMP Scale and the First Case
Administrative monetary penalties are set by RPAR ss.46–50 on two levels: a serious violation up to CAD 1,000,000, a very serious violation up to CAD 10,000,000. Paperwork breaches — the annual report, significant change notices, registration information updates — have their own regime: CAD 500 per day for delays up to 30 days, and a range of CAD 15,000 to 1,000,000 beyond that. A missed annual report stops being an administrative footnote on day 31.
Two multipliers deserve separate attention. The cascade: two or more serious violations of the same provision in one notice are reclassified as a single very serious violation (s.47(3)), lifting the ceiling from 1m to 10m — a systemic defect repeated across a portfolio collapses legally into one very serious breach. And the compliance agreement: it buys a 50% reduction (RPAA s.76(2)(b)), but breaching it automatically makes the violation very serious (s.47(2)) and adds a penalty equal to the original amount (s.50). The Act states that the purpose of a penalty is "to promote compliance … and not to punish" (s.76(4)); due diligence remains a full defence (s.86(1)), a violation is not an offence (s.85), and the appeal route runs through representations to the Governor within 30 days and then to the Federal Court.
The sharpest instrument in the regime is not a fine. RPAA s.94(4) allows a temporary compliance order without any opportunity to be heard where waiting would be prejudicial to the public interest; it runs 30 days and renews automatically. That is precisely what happened to XTM Inc. (the AnyDay platform), registered on 17 October 2025: on 17 February 2026 the Bank ordered it to cease all retail payment activities immediately, to stop initiating transactions and debits, to stop holding itself out as a registered PSP, and to file a compliance plan within seven days. The ground: it "failed to safeguard end-user funds in its possession, and caused a significant shortfall to accrue". On 27 February the order was amended to permit activity under a Monitor appointed by the Ontario Superior Court of Justice in CCAA proceedings. The size of the shortfall has not been disclosed in any public Bank document.
Since 12 June 2026 the Bank publishes Notices of Violation once the representation period expires, stating the nature of the violation and the penalty, with records kept for five years. The enforcement decisions page was still empty on 13 August 2026, yet six PSPs already carry a violations flag in the registry: Felix Payment Systems, GoDaddy Payments Services Canada, PAYTRAK PAYROLL SERVICES, Quikcard Solutions, Teranet and UpperBee Pay — all registered between March and July 2026, meaning the breaches were recorded after registration. XTM, meanwhile, still shows as Registered with no flag at all: a s.94 compliance order is not a Part 5 violation and never reaches the registry. The public register does not show the regime's hardest case.
RPAA and FINTRAC: Interlocked, Not Duplicated
The two regimes barely overlap in substance and are tightly coupled in consequence. PCMLTFA breaches are a direct ground to refuse RPAA registration (s.48(1)(c)–(e)) and to revoke it (s.52(b)–(d)); the absence of FINTRAC registration under PCMLTFA s.11.1 is a standalone ground on its own. In the other direction, the Bank notifies FINTRAC of every refusal (s.51) and revocation (s.57), and FINTRAC shares with the Bank under PCMLTFA s.65.03. Bill C-12 (S.C. 2026, c. 4) rewrote exactly these paragraphs; the AML side is covered in Canadian MSB and FMSB: FINTRAC Registration and the Bank of Canada PSP Regime.
| Parameter | RPAA / Bank of Canada | PCMLTFA / FINTRAC |
|---|---|---|
| Objective | Operational resilience, safety of end-user funds, national security | AML/CFT, sanctions, financial intelligence |
| Trigger | A payment function performed as a business, not incidentally, in relation to a fiat EFT | An MSB service: FX, money transfer, money orders, dealing in virtual currency, crowdfunding, cash transport, cheque cashing |
| Crypto | Out of scope — no "prescribed unit" was ever prescribed | In scope — a direct registration trigger |
| Registration | CAD 2,500, non-refundable, indexed; open-ended, but a fresh application on change of control | Free; renewal every 2 years |
| Refusal and national security | Yes — s.48, with published reasons (s.27); Finance review, 60 + 180 days | Refusal and revocation under ss.11.1x; no pre-registration screening of this kind |
| Operational risk and cyber resilience | Yes — RMIRF: 11 risk categories, targets, testing, senior officer | No |
| Segregation of client funds | Yes — trust or insured segregated account; daily ledger; set-off prohibited | No |
| AML programme, KYC, travel rule | No | Yes — compliance officer, policies, risk assessment, training |
| Independent review | RMIRF every 3 years where an auditor exists; safeguarding every 3 years for everyone holding funds | Effectiveness review every 2 years |
| Routine reporting | Annual report by 31 March; incidents within 48 hours | LCTR, STR, EFTR, large virtual currency transaction reports — per transaction |
| Penalty ceiling | serious 1m, very serious 10m | minor 40k, serious 4m, very serious 20m — raised by Bill C-12 and in force |
| Emergency shutdown power | Yes — compliance order, including a temporary one without a hearing (s.94(4)) | No direct equivalent |
Which inverts the usual narrative: in pure money terms the Canadian AML risk is twice the size — 20m against 10m. The RPAA risk is of a different kind, operational and immediate: you can be stopped within a day, without a hearing. The perimeters split as follows. RPAA only — acquirers and processors that do not move funds as such, payment gateways, marketplaces controlling the revenue account, payroll neobanks, BNPL infrastructure; the registry even includes Teranet, a land registry operator. FINTRAC only — crypto exchanges, currency dealers whose payment leg is incidental, cash transport, cheque cashing. Both — classic money transmitters, unlicensed neobanks, multi-currency fiat wallets, cross-border B2B payouts. Neither — banks and their wholly owned subsidiaries under consolidated OSFI supervision (RBC PayEdge), credit unions, card networks (Visa Canada), SWIFT, data aggregators (Yodlee) and agents listed by a registered PSP (TSYS Managed Services Canada).
Vetting a Provider Against the Bank of Canada Registry
The Bank of Canada registry is a free due-diligence tool, and three things matter in it: the status must read Registered, not in review; the Violations field in the record; and — most underused — which payment functions are declared. If a provider holds your money but has not declared function (b), holding of funds, the declaration and the facts do not match.
The gap between Registered and in review is material: 459 applicants sit in review, 257 of them having filed back in November 2024. They operate lawfully under s.108, but they have not been reviewed by the Bank, nor screened by the Department of Finance. "Not prohibited" and "vetted" are different states.
Safeguarding is not deposit insurance: CDIC does not cover money held at a PSP. Ask the provider specifically which s.20(1) option applies; who operates the account and whether it satisfies RPAR s.13; and if insurance is used, who the insurer is, whether it is unaffiliated (s.14(1)(b)), whether the policy survives restructuring (s.14(2)(c)) and whether the Bank is given 30 days' notice of any cancellation. The wider logic of segregating client money, and where it fails, is set out in the piece on safeguarding and correspondent accounts.
XTM marks the boundary of the protection: a registered PSP let a significant shortfall accrue, the regulator stopped it in a day without a hearing, and CCAA followed. Registration does not guarantee your money is there; it gives the regulator a fast intervention tool and gives you publicity — and it lags events. The real picture comes from combining the registry with enforcement decisions and regulatory news. One cross-border point: a foreign provider with a .ca site, Canadian-facing marketing or CAD settlement is required to be in the registry, and its absence is a red flag rather than a reassurance that it "isn't Canadian". How the same logic plays out elsewhere is visible in the EU payments reform and in non-bank access to Fed accounts.
Where the Money Sits in This Regime
The first decision belongs to architecture, not compliance. The direct read-through from the Bank's marketplace policy: take revenue into an account you control and you are a PSP carrying the full safeguarding load; route the flow end-to-end through third-party PSPs without touching funds and your functions are incidental, with no registration. Money at rest triggers safeguarding even on a fixed weekly payout schedule. This is a product-design choice, and it determines the whole downstream compliance stack.
The holding-of-funds flag is the most expensive one in the regime. It adds a separate written Safeguarding Framework, a daily per-user ledger, constraints on account providers and insurers, continuous shortfall monitoring and a triennial independent review — with none of the "no auditor" escape that the RMIRF review offers. If the product can work without holding funds, that is the single largest compliance saving available in Canada.
The standard mistakes are legible straight from the published refusals. Filing just in case, without running the incidental test yourself: 28 of the 44 refusals, and the CAD 2,500 fee is not refunded. Failing to answer an s.29(3) information request: 4 more. Answering without substance: Keystones Partners was refused for "insufficient detail", so a partial answer is treated as silence. Filing for an entity that is in truth only an agent of a registered affiliate instead of using s.10 and the agent list (TSYS). Filing as a wholly owned subsidiary of a bank under consolidated OSFI supervision (RBC PayEdge).
On transactions: s.24 requires a fresh application and completed re-registration before closing any acquisition of control. With a queue in which 257 applications have been pending for 21 months, that is a live M&A timing risk and belongs in the term sheet as a regulatory condition precedent alongside antitrust. Finally, the s.86(1) due diligence defence is real but only if documented — review records, test results and senior officer reports are defence material, not paperwork. Why accountability in payments cannot be outsourced to somebody else's licence is set out in licence renting and the regulatory perimeter trends.
Crypto, Stablecoins and the Sixth Function
Crypto fell outside the RPAA not by design but through an empty line in the regulations. The Act defines a retail payment activity by reference to an EFT "made in the currency of Canada or another country or using a unit that meets prescribed criteria" — and RPAR, the only instrument made under the Act, never prescribed those criteria. No crypto unit therefore qualifies today, and crypto-denominated transfers sit structurally outside the regime: Galias Services and Juno X were refused because each "does not perform any payment functions using the currency of Canada, another currency, or a prescribed unit". The hook is built into the statute and simply switched off — bringing stablecoins inside the RPAA would take one regulatory amendment, no legislation.
In parallel Canada enacted two crypto regimes, and as of 13 August 2026 neither is in force. The Stablecoin Act (S.C. 2026, c. 3, s. 600, assented 26 March 2026) is marked "Not in force" in its entirety, awaiting an order of the Governor in Council. Its shape: reserves at no less than the par value of outstanding stablecoins, held only in the reference currency or HQLA denominated in it (s.37); no encumbrance of the reserve (s.38); a qualified custodian with segregation and creditor protection (s.39); an outright ban on paying holders any interest or yield in any form (s.32); and a ban on presenting a stablecoin as legal tender, a deposit or an insured instrument (ss.33–34). It reaches only stablecoins used interprovincially or internationally and does not apply to closed-loop arrangements, financial institutions or central banks; issuance under the Act is expressly neither securities dealing nor deposit-taking. For comparison across jurisdictions, see the stablecoins overview.
The second deferred provision is the sixth RPAA payment function (S.C. 2026, c. 3, s. 604), likewise enacted and awaiting commencement: "transmission or maintenance of an end user's encrypted or tokenized payment instrument or an end user's private key, whether or not the private key is encrypted". Read literally it captures custodial and, potentially, non-custodial wallets, token service providers and anyone storing tokenised card credentials. How far it reaches will depend on whether the new function is tied to the incidental exclusion and on future guidelines. It is the key fork of 2027 — and many of those it will catch are currently confident the RPAA has nothing to do with them.
Q/A
Does a foreign provider with no Canadian office need to register
Yes, if it directs retail payment activities at persons in Canada and actually serves them — both limbs of RPAA s.5 are cumulative. A single indicator suffices for "directs at": marketing aimed at Canadians, a .ca domain, a listing in Canadian business directories, or working relationships with Canadian counterparties on retail payments. Expansion plans alone do not trigger registration. A registered foreign PSP must appoint a Canadian agent to receive notices; as of 13 August 2026 foreign entities account for 253 of the 1,562 registrations.
How the RPAA differs from FINTRAC registration
In purpose and in content. FINTRAC is AML: a compliance programme, KYC, transaction reporting, an effectiveness review every two years, free registration renewed every two years. The RPAA is operational resilience and safety of funds: an RMIRF covering eleven risk categories, safeguarding with a daily ledger, 48-hour incident notification, a CAD 2,500 fee. The overlap is not in the duties but in the consequences: PCMLTFA breaches are grounds to refuse or revoke RPAA registration, and the two regulators exchange information.
Are crypto businesses caught by the RPAA
Not today. A retail payment activity is tied to an EFT in fiat or in a "prescribed unit", and no criteria for such a unit exist in the regulations, so crypto transfers sit structurally outside the regime: Netcoins, Bitcoin4U, BitNational, Web3Exchange and others were refused as acting "incidental to its business of buying and selling cryptocurrency". But the sixth payment function covering wallets and private keys has been enacted and awaits commencement, as has a standalone Stablecoin Act. Neither is in force as of 13 August 2026, and bringing crypto inside the RPAA would require only a regulatory amendment defining the prescribed unit.
What is the maximum penalty a registered PSP faces
CAD 1,000,000 for a serious violation and CAD 10,000,000 for a very serious one (RPAR s.48(1)). Two or more serious violations of the same provision in one notice are reclassified as a single very serious violation, lifting the ceiling to 10m. Reporting delays cost CAD 500 a day up to 30 days and CAD 15,000 to 1,000,000 thereafter. A compliance agreement halves the penalty, but breaching it makes the violation very serious and adds a penalty equal to the original amount. The harshest tool, though, is not a fine but a s.94(4) compliance order, which stops the business without a hearing.