Skip to content
RPAA

How to File Your Annual Report Under the Retail Payment Activities Act

September 8, 2025 4 min read
How to File Your Annual Report Under the Retail Payment Activities Act

Filing your RPAA annual report? Learn what to include, how to submit on PSP Connect by March 31, and tips to simplify compliance.

Filing your annual report under the Retail Payment Activities Act (RPAA) may feel like a heavy lift, but it does not have to be. The Bank of Canada has laid out clear expectations for what information must be included, how it should be submitted through PSP Connect, and the importance of keeping accurate records throughout the year. Getting this process right not only ensures compliance but also builds trust with customers, partners, and regulators.

Annual reports are more than a formality. They show the Bank of Canada that your governance, safeguarding, risk management, and continuity frameworks are working as intended. They also provide a snapshot of how you are protecting end-user funds, managing operational risks, and maintaining resilience. By preparing carefully and keeping evidence throughout the year, you can avoid a last-minute scramble and file with confidence.

What Information the Annual Report Must Include

The RPAA requires payment service providers to provide comprehensive information covering governance, safeguarding of funds, incident history, and third-party assessments. The Bank of Canada sets out the expectations in its supervisory guidance on annual reporting (Bank of Canada Annual Reporting).

Your annual report should include:

  • Governance and Oversight Frameworks: Details on how your board and senior officers oversee RPAA compliance, including policies, reviews, and independent audits. Evidence should show accountability and oversight as outlined in the Governance and Oversight Policy.
  • Safeguarding of Funds: A description of how you segregate and protect end-user funds, whether through safeguarding accounts, trust arrangements, or insurance coverage. Daily reconciliations, shortfall coverage, and independent reviews must be documented in line with the Bank of Canada’s safeguarding guidance (Safeguarding End-User Funds) .
  • Incident History: A record of material incidents from the year, how they were handled, and lessons learned. This should align with the incident reporting and operational risk guidance (Operational Risk and Incident Response) .
  • Third-Party Assessments: Evidence of oversight of critical service providers, including due diligence, monitoring, and independent reviews. Outsourcing arrangements must meet RPAA standards and be documented clearly.
  • Continuity and Resilience Measures: Results of business impact analyses, recovery objectives, and continuity testing to show that disruptions can be managed effectively.

The key is to provide information that demonstrates not just the existence of policies but also evidence of how they are applied in practice.

How and When to Submit Through PSP Connect

The Bank of Canada requires PSPs to submit their annual report electronically through the PSP Connect system. This secure portal is the main channel for filing reports, incident notifications, and significant change notices.

The critical deadline for submission is March 31 each year. Missing this deadline is considered non-compliance and could lead to supervisory measures. Reports must be certified by your senior officer, showing that your leadership takes direct accountability for the accuracy of the information.

The step-by-step guidance on annual reporting makes it clear that you should upload the prescribed information, attach supporting evidence where required, and retain confirmation of submission for your records (Bank of Canada Annual Reporting).

To avoid issues, schedule your internal reporting well before March 31. Many PSPs aim to have drafts ready by early February, leaving time for review, corrections, and approvals.

Best Practices for Collecting Evidence Throughout the Year

The biggest challenge in annual reporting is not the actual submission but the collection of evidence. By the time March arrives, scrambling to find reconciliation logs, incident reports, or board minutes can be overwhelming.

Here are some best practices to make the process smoother:

  • Maintain a Compliance Calendar: Set monthly reminders to update ledgers, review safeguarding accounts, and document governance meetings. This ensures records are current and easy to access.
  • Log Incidents as They Happen: Maintain an incident register with dates, classification, responses, and resolutions. The RPAA requires material incidents to be reported within 48 hours (Incident Notification), and having the same data ready for the annual report will save time.
  • Store Evidence in a Central Repository: Keep safeguarding account confirmations, audit reports, BIA results, and training logs in a single secure location. This reduces the risk of missing or incomplete evidence during reporting.
  • Conduct Periodic Internal Reviews: Quarterly checks of your RPAA frameworks will highlight gaps early and prevent year-end surprises. Independent reviews required under the Act should be factored into your compliance schedule.
  • Prepare for Third-Party Scrutiny: Keep copies of due diligence on cloud providers, IT vendors, and banking partners. The Bank of Canada expects PSPs to retain evidence of third-party oversight and monitoring.

By adopting a “little and often” approach to evidence collection, PSPs can turn annual reporting into a straightforward process instead of a last-minute compliance headache.

Conclusion

Filing your annual report under the RPAA is not just about meeting a regulatory requirement. It is about showing the Bank of Canada that your business has the right safeguards, governance, and resilience in place to protect end users and the broader payment ecosystem.

By understanding what information to include, planning ahead for the March 31 PSP Connect deadline, and collecting evidence throughout the year, you can file with confidence and strengthen your compliance standing.To see how compliance tools can simplify your reporting, visit Comply North’s pricing page for a competitive edge, or contact their experts for tailored support.

Need help with this for your MSB?

Our RPAA Registration service handles this end to end, at honest, fixed-fee rates.

Ready to get your compliance handled by experts?

Get clear, effective compliance at a fraction of the typical cost. Book a free consultation and we’ll send a detailed, fixed-fee proposal.

Over 100 MSBs trust our compliance team. Claim your free, no-strings offer.

Claim a free offer