BriteBase
Payments regulation

Retail Payment Activities Act (RPAA): a plain-English explainer for Canadian payment service providers

The Retail Payment Activities Act is the federal Canadian law that brought payment service providers under direct Bank of Canada supervision. It sits alongside the PCMLTFA, not in place of it: many Canadian PSPs now have two registrations to maintain, two sets of obligations to track, and two regulators to satisfy.

By BriteBase team · Published June 8, 2026 · 9 min read

The Retail Payment Activities Act (RPAA) is the federal Canadian law that established a supervisory framework for retail payment service providers. The Bank of Canada is the supervisor. The law's purpose is to make retail payments operationally safe (resilient, well-managed, with funds protected) and to bring previously unregulated PSPs into a registration regime. The RPAA does not replace anti-money-laundering law: many PSPs are also money services businesses under the PCMLTFA and registered with FINTRAC.

This explainer covers what the RPAA is, who has to register, the five core obligations, where it meets the PCMLTFA, the penalty regime, and what a Canadian PSP should be doing now.

What is the RPAA?

The RPAA is a prudential and operational statute. Where the PCMLTFA exists to combat money laundering and terrorist financing, the RPAA exists to make sure that when an end user moves money through a Canadian PSP, that PSP is running its operations safely and the user's funds are not at risk because of an internal failure. The Bank of Canada is named in the statute as the regulator and supervisor, and the obligations under the law are operational rather than transactional.

The framework rests on three pillars: a registration regime, an operational risk and safeguarding regime, and an incident-and-information reporting regime. Each PSP has to register with the Bank of Canada, establish and maintain frameworks to manage operational risk and safeguard end-user funds, and report material incidents to the Bank of Canada within prescribed timeframes.

Who has to register under the RPAA?

The RPAA defines five retail payment functions. A person or entity that performs one or more of these functions as a service to an end user, in Canada or for users in Canada, generally has to register.

  1. Provision or maintenance of an account that, in relation to an electronic funds transfer, is held on behalf of one or more end users.
  2. Holding of funds on behalf of an end user until the funds are withdrawn or transferred to another individual or entity.
  3. Initiation of an electronic funds transfer at the request of an end user.
  4. Authorisation of an electronic funds transfer or the transmission, reception, or facilitation of an instruction in relation to such a transfer.
  5. Provision of clearing or settlement services.

Several categories are explicitly excluded. Banks and other prudentially supervised financial entities are out of scope: their primary regulator already covers operational risk and safeguarding. Pure technical service providers who never take possession or control of end-user funds (acting only as message movers) are typically out of scope as well. Internal payments within a single corporate group, payments related to securities settled by a clearing house, and certain agent arrangements are also excluded or treated as part of another regulated activity.

The practical test for most firms is functional rather than nominal. If a firm holds end-user funds even briefly, initiates an electronic funds transfer on a user's instruction, or facilitates the authorisation of such a transfer between parties, it almost certainly performs a retail payment function under the RPAA. Whether the firm calls itself a payment service provider, a fintech, a wallet, a remittance company, an embedded-finance provider, or something else does not change the analysis.

What are the five core RPAA obligations?

Once registered, a PSP has to maintain compliance with five operational obligations on an ongoing basis.

1. Registration with the Bank of Canada

Registration is the threshold obligation. A PSP applies to the Bank of Canada, provides information about ownership, operational structure, and the retail payment functions it performs, and obtains a decision. Registration can be refused or, after the fact, revoked where the Bank of Canada concludes the applicant does not meet the requirements. Operating as a PSP without being registered is itself a violation of the Act.

2. Operational risk management framework

Every registered PSP must establish, implement, and maintain a documented framework to manage operational risk. The framework has to identify the risks the PSP faces (cyber, fraud, third-party, business continuity, operational error), set out the controls used to mitigate them, define the governance over those controls, and demonstrate testing and continuous improvement. The framework is reviewed annually and updated as the business changes.

3. Safeguarding of end-user funds

If the PSP holds end-user funds, those funds have to be safeguarded. Options include holding the funds in a designated trust account at a Canadian financial institution, holding them in a separate account combined with insurance or guarantees that meet prescribed requirements, or holding them in another manner prescribed by regulation. The PSP must be able to identify, at any time, the amount held on behalf of each end user, and to return those funds promptly in the event of insolvency or wind-down. Safeguarding is the obligation most often misunderstood by early-stage PSPs that treat customer balances like operating cash.

4. Incident reporting

The PSP must notify the Bank of Canada of any incident that has a material impact on an end user, another PSP, or a clearing house. The notification has to be made as soon as feasible after the PSP becomes aware of the incident, and follow-up information must be provided as the incident is resolved. Internal incident logs and post-mortems become part of the program of record; an examiner will read them.

5. Sanctions compliance

The RPAA explicitly incorporates Canadian sanctions law. A PSP is responsible for screening counterparties and end users against Canadian sanctions lists, applying restrictions where required, and reporting required matters. Sanctions compliance under the RPAA is not a substitute for the firm's sanctions obligations under the PCMLTFA where those also apply; both regimes run in parallel.

How do the RPAA and the PCMLTFA overlap?

The RPAA and the PCMLTFA cover different objectives but overlap substantially in scope. The same firm can be:

  • A registered PSP under the RPAA (Bank of Canada), with operational risk and safeguarding obligations.
  • A registered MSB under the PCMLTFA (FINTRAC), with KYC, screening, monitoring, reporting, and recordkeeping obligations.

Where this is the case, the firm has two regulators, two ongoing registration obligations, two examination postures, and two parallel sets of records. Reconciliation between the two is where most early-stage PSPs lose time. A practical compliance program treats both regimes as one operational program with two regulatory outputs: the firm runs a single set of controls (onboarding, screening, monitoring, incident management) and surfaces evidence to each regulator in the format that regulator expects. The detail on the PCMLTFA side is in our PSP compliance primer.

What penalties apply under the RPAA?

The RPAA authorises Administrative Monetary Penalties for violations. AMPs are graded by category (minor, serious, very serious), with separate caps for natural persons and for entities. Operating as a PSP without registering is itself a violation. Failure to maintain an operational risk management framework, failure to safeguard end-user funds, failure to report a material incident within the prescribed period, and failure to meet sanctions obligations are all enforceable individually.

The Bank of Canada may also refuse, suspend, or revoke registration where requirements are not met. Loss of registration is more consequential than an AMP for an operating PSP: it stops the regulated activity at the source.

What should a Canadian PSP do now?

Six steps tighten the program against an examiner.

  1. Confirm the activity classification. Map the firm's services against the five retail payment functions and document the answer. If any function applies and no exclusion fits, the firm must register.
  2. Register, or confirm the registration is current. Provide accurate information about ownership, functions, jurisdictions, and material third parties. Update as the business changes.
  3. Stand up the operational risk management framework on paper. Most early-stage PSPs already manage operational risk in practice; few have it written down to the standard the Bank of Canada will expect. The written framework is the artefact an examiner reads first.
  4. Audit the safeguarding arrangement. Confirm the trust account or alternative mechanism in use, the reconciliation cadence, the per-user balance reporting, and the wind-down procedure. Most material RPAA findings concentrate here.
  5. Build the incident-reporting muscle. Define what counts as a material incident, who decides, who notifies, and the timing. Run a tabletop exercise so the obligation does not collide with a real incident the first time.
  6. Reconcile the RPAA and PCMLTFA program. Run both regimes as a single operational program. The savings are in time and headcount, not in software.

How does BriteBase help Canadian PSPs?

On the PCMLTFA side, the BriteBase screening platform handles sanctions, PEP, and adverse-media screening, ongoing monitoring, and alert triage, with every disposition recorded as audit-ready case history for the FINTRAC file.

FAQ

What is the Retail Payment Activities Act (RPAA)?

The Retail Payment Activities Act is the federal Canadian law that established a supervisory framework for retail payment service providers, with the Bank of Canada named as the supervisor. Its purpose is to make retail payments operationally safe, so that when an end user moves money through a Canadian PSP, that PSP is running its operations resiliently and the user's funds are not at risk from an internal failure. It is a prudential and operational statute, and its obligations are operational rather than transactional. The framework rests on three pillars: a registration regime, an operational risk and safeguarding regime, and an incident-and-information reporting regime. In practice that means a PSP must register with the Bank of Canada, establish and maintain frameworks to manage operational risk and safeguard end-user funds, report material incidents within prescribed timeframes, and meet Canadian sanctions obligations. The Act does not replace anti-money-laundering law; many PSPs are also FINTRAC-registered money services businesses.

Who has to register under the RPAA?

A person or entity that performs one or more of the five retail payment functions as a service to an end user, in Canada or for users in Canada, generally has to register with the Bank of Canada. The five functions are: provision or maintenance of an account tied to an electronic funds transfer, holding funds on behalf of an end user, initiation of an electronic funds transfer, authorisation or transmission of an instruction relating to such a transfer, and provision of clearing or settlement services. Several categories are excluded. Banks and other prudentially supervised financial entities are out of scope, because their primary regulator already covers operational risk and safeguarding. Pure technical service providers that never take possession or control of end-user funds are typically excluded too, as are internal payments within a corporate group and certain agent arrangements. The test is functional rather than nominal: what the firm actually does, not what it calls itself.

How does the RPAA differ from the PCMLTFA?

The two laws pursue different objectives but overlap heavily in scope. The RPAA is a prudential and operational law: its aim is to make sure retail payments are operationally safe and end-user funds are protected, and the Bank of Canada supervises it. The PCMLTFA is an anti-money-laundering and counter-terrorist-financing law administered by FINTRAC, with KYC, screening, monitoring, reporting, and recordkeeping obligations. Many PSPs are captured by both: they register under the RPAA with the Bank of Canada and, if they meet the activity tests, register under the PCMLTFA as money services businesses with FINTRAC. A firm in that position has two regulators, two registration obligations, two examination postures, and two parallel sets of records. Reconciliation between them is where most early-stage PSPs lose time. The practical answer is to run a single set of controls, onboarding, screening, monitoring, and incident management, and surface evidence to each regulator in the format it expects.

What are the five core RPAA obligations?

Once registered, a PSP has to maintain five operational obligations on an ongoing basis. First, registration with the Bank of Canada, the threshold obligation, since operating as a PSP without being registered is itself a violation. Second, an operational risk management framework, documented, that identifies the risks the PSP faces, sets out mitigating controls and their governance, and demonstrates testing and continuous improvement, reviewed annually. Third, safeguarding of end-user funds, so that any funds the PSP holds are protected and can be returned promptly on insolvency or wind-down. Fourth, incident reporting, notifying the Bank of Canada of any incident with a material impact on an end user, another PSP, or a clearing house as soon as feasible. Fifth, sanctions compliance, screening counterparties and end users against Canadian sanctions lists and applying restrictions where required. The obligations are operational and continuous, not one-time filings, and each is enforceable individually.

What does safeguarding actually require?

Safeguarding applies whenever a PSP holds end-user funds, and it requires those funds to be protected through a prescribed mechanism. The options are holding the funds in a designated trust account at a Canadian financial institution, holding them in a separate account combined with insurance or guarantees that meet prescribed requirements, or holding them in another manner set out in regulation. Whichever mechanism is used, the PSP has to be able to identify, at any time, the exact amount held on behalf of each individual end user, and to return those funds promptly in the event of insolvency or wind-down. That drives a reconciliation cadence, per-user balance reporting, and a documented wind-down procedure. Safeguarding is the obligation most often misunderstood by early-stage PSPs, and most material RPAA findings concentrate here. The classic error is treating customer balances like operating cash, which both breaks the segregation the Act requires and leaves the firm unable to prove per-user amounts.

What are the penalties for RPAA non-compliance?

The RPAA authorises Administrative Monetary Penalties for violations, graded by category (minor, serious, and very serious) with separate caps for natural persons and for entities. Operating as a PSP without registering is itself a violation, and it is not the only one: failure to maintain an operational risk management framework, failure to safeguard end-user funds, failure to report a material incident within the prescribed period, and failure to meet sanctions obligations are each enforceable individually, so a single set of facts can attract multiple penalties. Beyond monetary penalties, the Bank of Canada may refuse, suspend, or revoke a registration where the requirements are not met. For an operating PSP, loss of registration is the more consequential outcome, because an AMP is a cost while revocation stops the regulated activity at the source. Treat both the framework and the safeguarding obligation as live exposures, not paperwork, since findings there drive the most serious consequences.

What should a Canadian PSP do first?

Start by confirming the activity classification: map the firm's services against the five retail payment functions and document the answer. If any function applies and no exclusion fits, the firm must register, so register with the Bank of Canada, or confirm the existing registration is current, providing accurate information about ownership, functions, jurisdictions, and material third parties. Then stand up the operational risk management framework on paper, because most early-stage PSPs already manage operational risk in practice but few have written it down to the standard the Bank of Canada expects, and the written framework is the artefact an examiner reads first. Audit the safeguarding arrangement, confirming the trust account or alternative, the reconciliation cadence, the per-user balance reporting, and the wind-down procedure. Build the incident-reporting muscle and run a tabletop exercise. Finally, reconcile the RPAA and PCMLTFA programs into one set of controls feeding two regulators.

Back to all resources

Reading is useful. A conversation is faster.

Book a platform demo and we will walk you through real-time sanctions, PEP, and adverse-media screening and the data coverage that fits your firm.

Book a call
Prefer to talk now? Email hello@gobritebase.com