RPAA deadline Sept 2025: PSPs and MSBs must meet rules on governance, risk, safeguarding, reporting, and record-keeping. Learn how to comply.
Introduction
The Canadian payments industry is undergoing a major shift. The Retail Payment Activities Act (RPAA) and its supporting regulations set new requirements for payment service providers (PSPs) and money services businesses (MSBs). By September 2025, every PSP operating in Canada must be compliant with the RPAA.
The law covers five main areas: governance and oversight, risk and incident management, safeguarding of funds, business continuity, and reporting and record-keeping. The Bank of Canada supervises compliance and has issued detailed guidelines on how PSPs should prepare. PSPs that fail to meet these obligations risk regulatory penalties, reputational harm, and even the loss of their ability to operate.
This article explains the RPAA compliance checklist step by step, provides tips on structuring a compliance program, and outlines the most common challenges MSBs face when putting the framework into practice.
Step-by-Step Breakdown of RPAA Obligations
Risk Management and Incident Response
PSPs must establish a risk management and incident response framework that identifies, monitors, and mitigates operational risks. According to the Bank of Canada’s Operational Risk and Incident Response Guideline (source), the framework must include:
- Processes for identifying risks from systems, people, and third parties
- Preventive and detective controls
- Incident classification and escalation pathways
- Notifications to the Bank of Canada within 48 hours for material incidents (Incident Notification Guide)
Daily monitoring and post-incident reviews are also required. A well-documented process reduces downtime, protects customers, and demonstrates accountability.
Safeguarding End-User Funds
If a PSP “holds” customer funds, even briefly, those funds must be safeguarded. The RPAA and Retail Payment Activities Regulations (RPAR) require that customer money be placed in safeguarding accounts with eligible financial institutions or backed by insurance or guarantee (Safeguarding Guidance).
Key obligations include:
- Daily reconciliation of customer balances
- Immediate coverage of any shortfalls with the PSP’s own funds
- Independent reviews of safeguarding arrangements at least every three years
- Annual reporting of safeguarding methods and providers to the Bank of Canada
This ensures that customer money is protected from misuse, company creditors, or insolvency.
Governance and Oversight
The RPAA requires clear governance structures and accountability. Each PSP must designate a senior officer responsible for RPAA compliance and maintain board-level oversight. According to the Bank of Canada’s governance expectations (source), boards must:
- Approve the RPAA compliance plan annually
- Set risk appetite and tolerance levels
- Oversee third-party service providers
- Ensure independent reviews are carried out
Good governance ensures accountability and builds regulator confidence.
Reporting and Record-Keeping
The RPAA introduces strict reporting requirements. PSPs must submit:
- Annual Reports on risk, incidents, and safeguarding (Annual Reporting Guidance)
- Significant Change Notices when introducing new products, outsourcing key services, or changing safeguarding methods (Notice of Significant Change Guide)
- Incident Reports for material disruptions
Records must be retained for at least five years and be accessible to regulators on request.
Structuring a Compliance Program
Building an RPAA compliance program before September 2025 requires a structured approach. Here are practical tips:
- Map Obligations to Policies
Align each RPAA requirement with an internal policy, such as safeguarding, governance, business continuity, and incident management.
- Assign Clear Accountability
Name a senior officer responsible for compliance, supported by risk and compliance teams. Accountability should be documented and reported at the board level.
- Integrate with Existing Programs
Many MSBs already have FINTRAC AML obligations. Where possible, integrate RPAA requirements into existing risk assessments, training, and reporting cycles.
- Test and Review Regularly
Conduct business impact analyses, reconciliation checks, and incident simulations. Document results and use them to refine your framework.
- Leverage Technology
Implement systems for automated reconciliation, incident tracking, and regulatory reporting to reduce manual errors and improve oversight.
Common Challenges and How to Avoid Gaps
MSBs face several hurdles when implementing the RPAA compliance checklist.
- Safeguarding Complexity: Choosing between trust accounts, insurance, or guarantees can be difficult. Avoid gaps by documenting decisions and obtaining written confirmations from financial institutions.
- Third-Party Risks: Many PSPs rely on cloud providers or outsourced vendors. Regulators expect contracts to include audit rights and continuity obligations. Perform due diligence and monitor regularly.
- Incident Notification Timing: The 48-hour rule for reporting material incidents can be challenging. Establish pre-approved communication templates and escalation procedures.
- Record-Keeping Burden: Keeping five years of evidence is demanding. Use centralized systems and ensure backups are secure and retrievable.
- Cultural Change: Compliance is not just a checklist; it requires buy-in from leadership and staff. Regular training and awareness campaigns can help embed obligations into daily operations.
By addressing these challenges proactively, PSPs can avoid regulatory scrutiny and build trust with customers and partners.
Conclusion
The RPAA compliance checklist is not just a regulatory obligation but an opportunity for PSPs and MSBs to strengthen resilience, protect customers, and enhance their reputation. By September 2025, all firms must demonstrate robust governance, effective risk management, secure safeguarding of funds, and reliable reporting and record-keeping.
Firms that prepare early will gain a competitive edge, while those that delay risk penalties and reputational harm. To explore compliance solutions tailored for Canadian PSPs, visit Comply North’s pricing page or contact the experts for guidance.
Need help with this for your MSB?
Our RPAA Registration service handles this end to end, at honest, fixed-fee rates.