Skip to content
RPAA

RPAA Compliance Checklist: Everything Canadian PSPs Must Do by 2025

September 8, 2025 4 min read
RPAA Compliance Checklist: Everything Canadian PSPs Must Do by 2025

RPAA deadline Sept 2025: PSPs and MSBs must meet rules on governance, risk, safeguarding, reporting, and record-keeping. Learn how to comply.

Introduction

The Canadian payments industry is undergoing a major shift. The Retail Payment Activities Act (RPAA) and its supporting regulations set new requirements for payment service providers (PSPs) and money services businesses (MSBs). By September 2025, every PSP operating in Canada must be compliant with the RPAA.

The law covers five main areas: governance and oversight, risk and incident management, safeguarding of funds, business continuity, and reporting and record-keeping. The Bank of Canada supervises compliance and has issued detailed guidelines on how PSPs should prepare. PSPs that fail to meet these obligations risk regulatory penalties, reputational harm, and even the loss of their ability to operate.

This article explains the RPAA compliance checklist step by step, provides tips on structuring a compliance program, and outlines the most common challenges MSBs face when putting the framework into practice.

Step-by-Step Breakdown of RPAA Obligations

Risk Management and Incident Response

PSPs must establish a risk management and incident response framework that identifies, monitors, and mitigates operational risks. According to the Bank of Canada’s Operational Risk and Incident Response Guideline (source), the framework must include:

  • Processes for identifying risks from systems, people, and third parties
  • Preventive and detective controls
  • Incident classification and escalation pathways

Daily monitoring and post-incident reviews are also required. A well-documented process reduces downtime, protects customers, and demonstrates accountability.

Safeguarding End-User Funds

If a PSP “holds” customer funds, even briefly, those funds must be safeguarded. The RPAA and Retail Payment Activities Regulations (RPAR) require that customer money be placed in safeguarding accounts with eligible financial institutions or backed by insurance or guarantee (Safeguarding Guidance).

Key obligations include:

  • Daily reconciliation of customer balances
  • Immediate coverage of any shortfalls with the PSP’s own funds
  • Independent reviews of safeguarding arrangements at least every three years
  • Annual reporting of safeguarding methods and providers to the Bank of Canada

This ensures that customer money is protected from misuse, company creditors, or insolvency.

Governance and Oversight

The RPAA requires clear governance structures and accountability. Each PSP must designate a senior officer responsible for RPAA compliance and maintain board-level oversight. According to the Bank of Canada’s governance expectations (source), boards must:

  • Approve the RPAA compliance plan annually
  • Set risk appetite and tolerance levels
  • Oversee third-party service providers
  • Ensure independent reviews are carried out

Good governance ensures accountability and builds regulator confidence.

Reporting and Record-Keeping

The RPAA introduces strict reporting requirements. PSPs must submit:

  • Incident Reports for material disruptions

Records must be retained for at least five years and be accessible to regulators on request.

Structuring a Compliance Program

Building an RPAA compliance program before September 2025 requires a structured approach. Here are practical tips:

  • Map Obligations to Policies
    Align each RPAA requirement with an internal policy, such as safeguarding, governance, business continuity, and incident management.
  • Assign Clear Accountability
    Name a senior officer responsible for compliance, supported by risk and compliance teams. Accountability should be documented and reported at the board level.
  • Integrate with Existing Programs
    Many MSBs already have FINTRAC AML obligations. Where possible, integrate RPAA requirements into existing risk assessments, training, and reporting cycles.
  • Test and Review Regularly
    Conduct business impact analyses, reconciliation checks, and incident simulations. Document results and use them to refine your framework.
  • Leverage Technology
    Implement systems for automated reconciliation, incident tracking, and regulatory reporting to reduce manual errors and improve oversight.

Common Challenges and How to Avoid Gaps

MSBs face several hurdles when implementing the RPAA compliance checklist.

  • Safeguarding Complexity: Choosing between trust accounts, insurance, or guarantees can be difficult. Avoid gaps by documenting decisions and obtaining written confirmations from financial institutions.
  • Third-Party Risks: Many PSPs rely on cloud providers or outsourced vendors. Regulators expect contracts to include audit rights and continuity obligations. Perform due diligence and monitor regularly.
  • Incident Notification Timing: The 48-hour rule for reporting material incidents can be challenging. Establish pre-approved communication templates and escalation procedures.
  • Record-Keeping Burden: Keeping five years of evidence is demanding. Use centralized systems and ensure backups are secure and retrievable.
  • Cultural Change: Compliance is not just a checklist; it requires buy-in from leadership and staff. Regular training and awareness campaigns can help embed obligations into daily operations.

By addressing these challenges proactively, PSPs can avoid regulatory scrutiny and build trust with customers and partners.

Conclusion

The RPAA compliance checklist is not just a regulatory obligation but an opportunity for PSPs and MSBs to strengthen resilience, protect customers, and enhance their reputation. By September 2025, all firms must demonstrate robust governance, effective risk management, secure safeguarding of funds, and reliable reporting and record-keeping.

Firms that prepare early will gain a competitive edge, while those that delay risk penalties and reputational harm. To explore compliance solutions tailored for Canadian PSPs, visit Comply North’s pricing page or contact the experts for guidance.

Need help with this for your MSB?

Our RPAA Registration service handles this end to end, at honest, fixed-fee rates.

Ready to get your compliance handled by experts?

Get clear, effective compliance at a fraction of the typical cost. Book a free consultation and we’ll send a detailed, fixed-fee proposal.

Over 100 MSBs trust our compliance team. Claim your free, no-strings offer.

Claim a free offer