The Gap AI Automation Who we work with Approach Blog Start a conversation

Canada's RPAA Explained: What Payment Companies Must Do Before the Deadline

2026-08-17 Regulation

For years, Canada regulated payment companies primarily through FINTRAC's anti-money-laundering lens. The Retail Payment Activities Act changed that, putting payment service providers under the direct supervision of the Bank of Canada for the first time. If your company performs payment functions for Canadians, the RPAA is now part of your operating environment, and it is a different kind of regime than the one you knew.

Two regulators, two jobs

The first thing to internalize is that RPAA registration and FINTRAC MSB registration are separate obligations with separate purposes. FINTRAC cares about money laundering and terrorist financing. The Bank of Canada, under the RPAA, cares about operational reliability and the safety of end-user funds. Holding one registration does not cover the other. A payments business serving Canadian customers typically needs both.

Who is caught

The Act applies to anyone performing payment functions: providing or maintaining accounts, holding funds, initiating transfers, authorizing or transmitting payment instructions, or providing clearing and settlement services. The definitions are broad on purpose. Domestic companies are caught directly, and so are foreign companies that direct services at Canadian end users. If your product has Canadian customers moving retail payments, assume you are in scope and work backwards from there.

What supervision actually requires

Registration is the entry ticket, not the substance. The substance is two ongoing obligations. The first is an operational risk and incident management framework: documented, tested, with clear ownership, covering how you prevent disruptions and what you do when they happen anyway. Material incidents must be reported. The second is end-user fund safeguarding: customer money held in trust or insured arrangements, segregated from your own, with records that prove it continuously rather than annually.

Neither obligation is satisfied by a policy document alone. The Bank of Canada's supervisory approach looks at whether the framework is real: whether the tests happened, whether the records reconcile, whether the named people know they are named.

The scope-change trap

One subtlety that catches growing companies: your registration reflects the activities you described when you filed. Change the activities, and the registration needs to change with you. A company registered for fiat payment functions that adds crypto-linked flows, for example, needs to update its filing and, in practice, wait for the Bank's response before treating the new activity as covered. The timeline for that consent is not under your control, so it belongs in your product planning, not as an afterthought before launch week.

Practical priorities

If you are building or fixing RPAA compliance now, the order that works is: confirm scope honestly, file or update the registration, stand up the safeguarding structure with real segregation, then build the incident framework and test it once before the regulator asks. Companies that treat the RPAA as a serious operational regime rather than a form-filing exercise are having noticeably easier conversations with the Bank of Canada. That pattern will only strengthen as supervision matures.