RPAA sets new Bank of Canada rules for MSBs and fintechs on safeguarding funds, risk management, and resilience. Non-compliance brings penalties.
Introduction
In recent years, Canada’s payment ecosystem has grown rapidly with the rise of digital wallets, remittance apps, and fintech innovations. While this growth creates opportunities, it also raises risks around customer protection, operational failures, and financial stability. To address these issues, the Government of Canada introduced the Retail Payment Activities Act (RPAA) and the Retail Payment Activities Regulations (RPAR).
The RPAA is overseen by the Bank of Canada and sets out new rules for payment service providers (PSPs), including many money services businesses (MSBs). If your business moves money, processes payments, or holds customer funds in Canada, you are likely impacted.
This blog explains why the RPAA matters, how it differs from existing AML and FINTRAC rules, and what can happen if MSBs fail to comply.
Why Canada Introduced the RPAA
The RPAA was designed to solve three main problems in Canada’s payment system:
- Customer protection – Before the RPAA, there were limited rules ensuring that customer funds held by PSPs were kept safe. Now, the law requires safeguarding measures such as trust accounts, daily reconciliations, and insurance or guarantee coverage. See the Bank of Canada’s guide on Safeguarding End User Funds.
- Operational resilience – Payments are essential to the economy. System outages, cyberattacks, or third party failures could disrupt wages, bills, or remittances. Under the RPAA, PSPs must have risk management, incident response, and business continuity plans. See the Bank of Canada’s Operational Risk and Incident Response guide.
- Consistency in oversight – While banks have long been supervised, many new PSPs and MSBs were not. The RPAA levels the playing field by requiring all retail PSPs to register with the Bank of Canada and follow common standards for governance, reporting, and resilience.
For MSBs, this means that operating as a remittance company, payment processor, or fintech wallet provider now comes with stricter obligations in addition to FINTRAC registration.
RPAA vs FINTRAC: Why MSBs Must Pay Attention to Both
Many MSBs are already familiar with FINTRAC rules under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). Those obligations focus on AML and ATF compliance such as knowing your customer (KYC), monitoring transactions, reporting suspicious activity, and preventing money laundering.
The RPAA, by contrast, is not about financial crime. It is about operational safety and customer protection. Key differences include:
- Safeguarding of Funds: RPAA requires customer funds to be separated from company funds, either in trust accounts or through insurance. AML rules do not cover this. See Bank of Canada’s At a glance guide to safeguarding funds.
- Risk and Incident Management: RPAA requires formal risk frameworks, classification of incidents, and reporting material incidents to the Bank of Canada within 48 hours. FINTRAC only requires suspicious transaction reporting. See Bank of Canada’s Incident Notification guide.
- Governance and Oversight: RPAA requires that Boards and senior officers take responsibility for compliance, with independent reviews and annual reporting to the Bank of Canada. FINTRAC compliance can often be delegated to a compliance officer.
- Business Continuity and Disaster Recovery: RPAA requires tested recovery plans, business impact analyses, and crisis communication frameworks. AML rules do not. See Bank of Canada’s Step by step guide to incident reporting.
In plain terms, FINTRAC looks at who you are transacting with, while RPAA looks at how you run your business and protect customer funds. MSBs need to comply with both laws to stay in business.
Consequences of Non Compliance
- Corrective measures – The Bank can require changes to your safeguarding framework, governance, or incident response plans.
- Administrative penalties – Non compliance can result in fines or enforcement actions under the RPAA.
- Operational disruption – If your business continuity or safeguarding framework is not adequate, you may be restricted from certain activities or even suspended.
- Loss of customer trust – Beyond regulation, failure to protect funds or maintain resilience can damage reputation and customer confidence.
The RPAA gives the Bank of Canada strong supervisory powers. If an MSB fails to comply, potential consequences include:
Consider that a single outage or insolvency without proper safeguarding could trigger mass customer losses. The RPAA was designed to prevent this outcome, and regulators will not hesitate to intervene.
How MSBs Can Stay Compliant
Fortunately, the RPAA provides a clear roadmap, and policy templates make implementation easier. To meet requirements, MSBs should adopt and maintain five core policies:
- Governance and Oversight Policy – Assign accountability to a senior officer and Board, ensure third party oversight, and integrate RPAA obligations with existing AML programs.
- Safeguarding of Funds Policy – Keep customer money separate, use eligible financial institutions, reconcile balances daily, and ensure trust or insurance protections.
- Risk and Incident Management Policy – Classify, detect, and escalate incidents. Notify the Bank of Canada within required timelines and conduct post incident reviews.
- Business Continuity and Disaster Recovery Policy – Test recovery plans annually, define recovery objectives, and ensure critical systems can be restored.
- Reporting and Record Keeping Framework – Maintain evidence of compliance, submit annual reports, and file significant change notices as required by Bank of Canada supervisory guidelines. See Annual Reporting requirements and the Notice of Significant Change guide.
By building these into daily operations, MSBs not only comply with the law but also improve customer confidence and reduce business risk.
Conclusion
The Retail Payment Activities Act (RPAA) represents a major shift in how Canada regulates payments. For MSBs, it means new responsibilities around governance, safeguarding of funds, risk management, and resilience. These obligations are different from, but just as important as, existing AML and FINTRAC rules.
Ignoring the RPAA could result in fines, restrictions, or even loss of business. But with the right policies and a clear compliance framework, MSBs can stay ahead of regulators, protect their customers, and strengthen their reputation.
At Comply North, we specialize in helping MSBs and PSPs implement the policies and controls needed to comply with the RPAA at competitive pricing.
Check out our pricing or contact us to learn how we can support your compliance journey.
Need help with this for your MSB?
Our RPAA Registration service handles this end to end, at honest, fixed-fee rates.