Retail Payment Activities Act registration: what Bank of Canada supervision means for PSPs and their partners
Retail Payment Activities Act registration puts Canadian payment service providers under Bank of Canada supervision for operational risk and safeguarding.
- The RPAA requires payment service providers that perform retail payment activities for Canadian end users, or from a place of business in Canada, to register with the Bank of Canada; banks and other prudentially regulated entities are excluded.
- Registration opened in November 2024 and the substantive obligations, operational risk management and safeguarding of end-user funds, came into force on 8 September 2025.
- Safeguarding means holding end-user funds in trust or in a segregated account with insurance or a guarantee, so that funds can be returned promptly if the PSP fails.
- The regime is not an AML regime; FINTRAC registration and the PCMLTFA continue to apply separately, and a PSP may need both.
- A bank or MSB choosing a PSP partner should ask for the registration confirmation, the safeguarding framework, the incident notification procedure and the most recent annual report to the Bank.
Retail Payment Activities Act registration is the requirement, under Canada's RPAA, for a payment service provider that performs retail payment activities for end users in Canada, or from a place of business in Canada, to register with the Bank of Canada and then comply with the Bank's supervisory requirements on operational risk management and the safeguarding of end-user funds. The registration window opened in November 2024, and the operational risk and safeguarding obligations came into force on 8 September 2025, from which date the Bank has supervised registered PSPs. This article explains who must register, what the regime covers, the timeline as of mid-2026, and what a bank or MSB should ask a PSP partner to demonstrate.
Who must register under the Retail Payment Activities Act?
The Act applies to any individual or entity that performs one or more payment functions as a service or business activity that is not incidental to another service or business activity. The payment functions are defined in the Act: providing or maintaining an account held on behalf of an end user, holding funds on behalf of an end user until they are withdrawn or transferred, initiating an electronic funds transfer at the request of an end user, authorising an electronic funds transfer or transmitting, receiving or facilitating an instruction in relation to one, and providing clearing or settlement services. A PSP is in scope if it has a place of business in Canada, or if it performs those functions for an end user in Canada and directs services at Canadians.
The exclusions matter for readers of this article. Banks, credit unions, insurers and other entities already subject to prudential supervision are excluded from the RPAA, as are the Bank of Canada itself, Payments Canada and designated systems under the Payment Clearing and Settlement Act. Certain activities are also excluded, including transactions in cash, securities transactions, and, importantly, payment functions performed in relation to electronic funds transfers that are made with an instrument that is a unit of value not denominated in a fiat currency, which is why the treatment of stablecoin activity depends on whether the activity is characterised as fiat-denominated. A PSP whose service settles in a fiat-referenced stablecoin should take advice on characterisation rather than assume exclusion.
What does the regime actually cover?
The RPAA is deliberately narrow. It is not a licensing regime in the sense of a fit and proper test on ownership, and it is not an anti-money laundering regime. Its two substantive pillars are operational risk management and safeguarding of end-user funds, supported by registration, reporting and an incident notification duty. The Bank of Canada's supervisory framework describes a risk-based approach in which the Bank assesses PSPs, prioritises supervision by impact, and can take enforcement action including notices of violation and administrative monetary penalties.
- Operational risk management: the PSP must establish, implement and maintain a framework that identifies operational risks, protects the integrity, confidentiality and availability of its payment systems, data and information, and responds to incidents, with the framework reviewed and approved at a senior level.
- Incident notification: the PSP must notify the Bank of Canada, and any affected end users, other PSPs or clearing houses, of an incident that has a material impact on its retail payment activities, without delay.
- Safeguarding of end-user funds: funds held for end users must be held in trust, or in a segregated account at a prudentially regulated institution covered by insurance or a guarantee, so that they can be returned promptly if the PSP becomes insolvent.
- Safeguarding framework: the PSP must maintain a written framework covering how funds are identified, held, reconciled and returned, with independent review at defined intervals.
- Annual reporting: registered PSPs must submit an annual report to the Bank describing their activities, volumes and compliance with the operational risk and safeguarding requirements.
- Registry: the Bank maintains a public registry of registered PSPs, which allows a counterparty to verify a provider's status.
What is the timeline as of mid-2026?
The Act received royal assent in June 2021, and the Retail Payment Activities Regulations were finalised in late 2023. The Bank of Canada opened the registration window on 1 November 2024, with a transition period during which PSPs that submitted applications continued to operate while the Bank reviewed them. The requirements on operational risk management, incident notification and safeguarding came into force on 8 September 2025, and from that date the Bank began active supervision of registered PSPs. The first annual reports under the regime were due in 2026, and the Bank has published guidance and frequently asked questions through 2026 to clarify how it applies the requirements.
For a PSP that has entered the market since the initial window, registration is required before performing retail payment activities, and the Bank's review period applies before the PSP may begin. As of mid-2026 the regime is fully in force, with the public registry live, and the practical questions have moved from whether to register to how the Bank assesses a safeguarding framework in supervision. Readers should check the Bank of Canada's retail payments supervision pages for the current guidance rather than rely on summaries, because the Bank continues to refine its expectations.
The RPAA does not ask whether a payment service provider is honest. It asks whether the funds it holds for others would survive its failure, and whether its systems would survive a bad day.
How does safeguarding of end-user funds work in practice?
Safeguarding is the requirement that turns the RPAA from paperwork into an operational constraint. A PSP that holds end-user funds, even briefly between receipt and payout, must hold them in one of two ways. The first is a trust account, with the funds held in trust for the end users and the PSP's own funds kept separate. The second is a segregated account at a prudentially regulated financial institution, with the funds covered by insurance or a guarantee sufficient to return them if the PSP fails. In both cases the PSP must reconcile the safeguarded balance against its ledger of end-user entitlements at least daily, and must maintain a framework that describes how funds are identified, how a shortfall is detected and corrected, and how funds would be returned in an insolvency.
The concrete question for a stablecoin settlement flow is whether the PSP holds end-user funds at all. In a model where the institution keeps custody of its own wallets and the platform never takes possession of the stablecoins, the safeguarding obligation on the platform is narrow or absent for that leg, and the Bank's interest shifts to operational risk. In a model where the PSP holds fiat float for payouts, that float is end-user funds and must be safeguarded. A PSP should be able to state, leg by leg, which funds it holds and under which safeguarding arrangement.
How does the RPAA sit alongside FINTRAC and other regimes?
The RPAA and the Proceeds of Crime (Money Laundering) and Terrorist Financing Act are separate regimes administered by different bodies with different purposes. FINTRAC registration and the PCMLTFA obligations, including record keeping, reporting and the Travel Rule, apply to money services businesses regardless of RPAA status. A PSP that transfers funds on behalf of clients will usually be an MSB under the PCMLTFA and a PSP under the RPAA, and must hold both registrations. The Bank of Canada does not examine AML compliance, and FINTRAC does not examine safeguarding. A partner institution therefore needs to see both.
There is a further layer for PSPs that seek access to Canadian payment systems. Payments Canada membership and access to Real-Time Rail, when available, are expected to depend on RPAA registration for non-bank participants, which is one of the policy reasons the regime was created. Provincial consumer protection rules, Quebec's licensing regime for money services businesses, and the federal privacy law all continue to apply in their own right. The operational answer is a regulatory map, maintained by the PSP, that lists each regime, the registration or licence held, the supervisor, the last examination and the next reporting date.
What should a bank or MSB ask a PSP partner for?
A bank, credit union or MSB that relies on a PSP for cross-border settlement is outsourcing part of its payment chain, and its own regulator will expect it to have done due diligence. The request list below is what a practitioner should send before signing.
- Confirmation of Bank of Canada registration, verified against the public registry, together with the date of registration and any conditions attached.
- The safeguarding framework, or a summary of it, stating which end-user funds the PSP holds, whether by trust or by segregated insured account, at which institution, and how often reconciliation is performed.
- The operational risk management framework summary, including the incident response plan, the most recent independent review and the business continuity testing results.
- The incident notification procedure showing how and when the partner would be told of an incident affecting its payments, consistent with the RPAA's duty to notify affected PSPs and end users.
- The most recent annual report submitted to the Bank, or a summary of it, and confirmation of any enforcement action or notice of violation.
- Evidence of FINTRAC MSB registration and the AML compliance programme, since the RPAA does not cover money laundering controls and the partner needs both.
The partner should also ask how the PSP's settlement model interacts with safeguarding. A model in which the institution keeps custody of its own stablecoins and receives an ISO 20022 pacs.002 confirmation for each on-chain settlement, tracked by UETR, leaves fewer funds in the PSP's hands than one in which the PSP holds float. Fewer funds held means a smaller safeguarding exposure and a simpler recovery if the PSP fails.
Where StableNet fits
StableNet, built by SpendTheBits, is a cross border B2B payment and settlement platform for banks, credit unions, licensed money service businesses, exchange houses and remittance fintechs, offered through B2B, B2B2B and B2B2C commercial models. Settlement is in regulated stablecoins such as USDC and USDT on public blockchains, completing in minutes with on chain auditability, and customers keep custody of their own wallets, which limits the end-user funds a platform needs to hold. The platform is ISO 20022 native, with pacs.008 customer credit transfers, pacs.002 status reports and pacs.004 returns tracked end to end by UETR, and it also accepts and emits SWIFT MT103, so a partner institution receives a structured confirmation of every settlement and a tamper evident audit trail for its own regulator. Compliance is built in, including KYB and KYC onboarding, KYT, sanctions and PEP screening and Travel Rule data in IVMS101 form. SpendTheBits is a Bank of Canada registered payment service provider and a named finalist in the Swift Hackathon 2026 Technical Challenge.
See it on your corridors
Book a working session and we’ll map StableNet’s compliance and settlement to one of your live payment flows.