For a FINTRAC-registered Money Services Business seeking registration as a Payment Service Provider under the Retail Payment Activities Act
A common misconception: an RPAA application is not a FINTRAC application
A common misconception is that an application under the Retail Payment Activities Act is submitted to, reviewed by or approved by FINTRAC. It is not. An RPAA registration application is submitted to the Bank of Canada, which is responsible for registering and supervising payment service providers under the RPAA.
A Canadian MSB registration with FINTRAC and a Payment Service Provider registration under the Retail Payment Activities Act are separate regulatory requirements.
FINTRAC administers the anti-money-laundering and anti-terrorist-financing regime under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act.
The Bank of Canada administers the Retail Payment Activities Act and registers and supervises payment service providers.
The Bank does not issue an “RPAA license.” It makes a registration decision and, if successful, places the legal entity on the public Registry of Payment Service Providers.
A FINTRAC MSB registration does not substitute for Bank of Canada registration.
The Bank sends prescribed application information to FINTRAC and provides the application to the Department of Finance for national-security screening.
Throughout this document, “RPAA approval” means successful Bank of Canada registration.
2. Immediate status check: determine whether the company is currently exposed
Since 8 September 2025, an applicant submitting a new RPAA application must be registered before it begins or continues performing in-scope retail payment activities. The earlier transition period is over.
Immediate decision
Complete this analysis before treating the matter as an ordinary application project:
Is the company currently performing one or more of the five statutory payment functions?
Are those functions performed as a service or business activity rather than merely incidentally to a non-payment business?
Do the functions relate to an electronic funds transfer in Canadian dollars, foreign fiat currency or another prescribed unit?
Does the company have a place of business in Canada?
If it has no Canadian place of business, does it perform activities for end users physically in Canada and direct those activities at persons or entities in Canada?
Is the company or the relevant activity covered by an exclusion?
Did this exact legal entity submit an RPAA application before 8 September 2025?
Is this exact legal entity already on the Bank of Canada PSP registry?
Escalation rule
If the company is currently performing in-scope retail payment activities, did not submit during the transition period and is not registered:
Escalate immediately to the CEO, board or accountable senior officer.
Obtain a written Canadian RPAA scope opinion.
Identify which activities are definitely in scope, potentially in scope and excluded.
Consider suspending or ring-fencing in-scope activity until registration is obtained.
Do not assume the FINTRAC MSB registration authorizes continued operation under the RPAA.
Preserve records of the company’s internal assessment, corrective actions and intended application.
Submit a complete application as quickly as practicable; a rushed, inaccurate application creates a separate refusal risk.
3. The four-part RPAA scope test
Do not begin filling in PSP Connect until this assessment has been documented.
Test 1 — Is the entity a Payment Service Provider?
The legal entity is generally a PSP when it performs at least one of the following payment functions as a service or business activity that is not incidental to another service or business activity:
Providing or maintaining an account held on behalf of one or more end users in relation to an electronic funds transfer.
Holding end-user funds until the funds are withdrawn or transferred to another person or entity.
Initiating an electronic funds transfer at an end user’s request.
Authorizing an electronic funds transfer, or transmitting, receiving or facilitating payment instructions in relation to an electronic funds transfer.
Providing clearing or settlement services.
Examples that commonly trigger the analysis include:
remittance and cross-border payment services;
digital wallets and stored-value accounts;
merchant acquiring, aggregation and payment facilitation;
payment gateways that do more than provide passive software;
bill-payment platforms;
marketplaces that receive or hold merchant proceeds;
payroll payment providers;
account-to-account payment initiation;
payment processing or orchestration;
payment-network and settlement services.
Test 2 — Is the activity a retail payment activity?
Confirm that the payment function is performed in relation to an electronic funds transfer involving:
Canadian currency;
foreign fiat currency; or
another prescribed unit.
Prepare an end-to-end funds-flow diagram showing where each electronic instruction, debit, credit, transfer, hold, release, clearing event and settlement event occurs.
Test 3 — Is the geographic perimeter met?
The regime can apply where:
the PSP has a place of business in Canada; or
the PSP has no place of business in Canada but performs retail payment activities for an end user physically in Canada and directs the activities at persons or entities in Canada.
A Canadian incorporation, physical office, employee, agent or mandatary can be relevant to the “place of business” assessment.
Test 4 — Is the entity or activity excluded?
Test every relevant exclusion separately. Potential exclusions include:
closed-loop instruments usable only with the issuing merchant or defined merchant group;
certain eligible financial contracts and prescribed securities transactions;
cash withdrawals at an ATM;
functions performed using a system designated under the Payment Clearing and Settlement Act;
certain transactions wholly between affiliated entities where no other PSP performs a payment function;
payment activities that are genuinely incidental to a non-payment service or business;
specified regulated entities, including banks, authorized foreign banks and certain provincially regulated financial institutions;
an agent or mandatary performing activities within the scope of, and properly disclosed by, a registered PSP.
Do not rely on labels such as “software provider,” “agent,” “processor,” “marketplace,” “technology company” or “MSB.” The Bank looks at the actual functions performed.
4. Confirm the correct applicant legal entity
This is one of the most common structural errors.
Identify every legal entity in the group.
Map each product, contract, bank account, customer relationship and payment function to the entity that actually performs it.
Confirm which entity contracts with the end user.
Confirm which entity receives payment instructions.
Confirm which entity has access to or control over end-user funds.
Confirm which entity operates the platform or payment account.
Confirm which entity contracts with banks, processors, custodians, insurers, guarantors, agents and material technology providers.
Confirm which entity is registered with FINTRAC.
Confirm that the FINTRAC legal name, incorporation details and ownership information match current corporate records.
Determine whether one or more affiliates must submit separate RPAA applications.
Each legal entity that independently performs in-scope retail payment activities may need its own registration. Group membership does not automatically consolidate the obligation.
5. Establish the internal RPAA project
Recommended project governance
Role | Primary responsibility |
|---|---|
Executive sponsor | Removes blockers, approves resources and accepts regulatory risk |
RPAA project lead | Owns the application, tracker, evidence room and regulator responses |
Canadian regulatory counsel | Confirms scope, exclusions, safeguarding structure and legal accuracy |
Compliance/FINTRAC officer | Confirms FINTRAC status, AML history and application consistency |
Chief operating officer | Validates actual operating model and controls |
Chief technology/security officer | Provides system architecture, data locations, operational-risk controls and incident response |
Finance/controller | Produces 12-month volumes, values, end-user-fund metrics, creditors and projections |
Treasury/banking lead | Confirms bank accounts, safeguarding accounts, clearing and settlement arrangements |
Corporate secretary/legal | Produces ownership, directors, officers, affiliates, incorporation and governance records |
Vendor-management lead | Identifies and assesses third-party service providers |
Board or designated senior officer | Approves required frameworks and final application representations |
Mandatory project controls
One master application tracker.
One controlled data room.
One approved source of quantitative data.
One version-controlled funds-flow narrative.
One list of all assumptions and unresolved issues.
One designated PSP Connect administrator.
One backup authorized user.
One regulatory-response protocol with a 24-hour internal turnaround target.
Written sign-off from legal, finance, operations, technology, compliance and the executive sponsor before submission.
6. Build the RPAA data room before opening the form
Use a structure such as the following:
RPAA-APPLICATION/
├── 00_Project-Control/
│ ├── Master-Tracker.xlsx
│ ├── RACI.md
│ ├── Issues-and-Assumptions-Log.xlsx
│ └── Submission-Approval-Memo.pdf
├── 01_Scope-and-Legal-Entity/
│ ├── RPAA-Scope-Memo.pdf
│ ├── Legal-Entity-Map.pdf
│ ├── Product-Scope-Matrix.xlsx
│ └── Exclusions-Analysis.pdf
├── 02_Corporate/
│ ├── Articles-and-Certificate.pdf
│ ├── Corporate-Registry-Extract.pdf
│ ├── Bylaws-or-Operating-Agreement.pdf
│ ├── Organization-Chart.pdf
│ ├── Ownership-and-Control-Register.xlsx
│ ├── Directors-and-Officers.xlsx
│ ├── Affiliates.xlsx
│ ├── State-Owned-Enterprise-Assessment.pdf
│ └── Five-Largest-Creditors.xlsx
├── 03_FINTRAC-and-Regulatory/
│ ├── FINTRAC-Registration.pdf
│ ├── FINTRAC-Registration-Details.xlsx
│ ├── Foreign-Regulators.xlsx
│ ├── Provincial-Registrations.xlsx
│ └── Enforcement-and-Litigation-Declaration.pdf
├── 04_Business-and-Payment-Flows/
│ ├── Products-and-Services-Description.pdf
│ ├── Payment-Function-Matrix.xlsx
│ ├── End-to-End-Funds-Flow.pdf
│ ├── Data-Flow-and-System-Architecture.pdf
│ ├── Clearing-and-Settlement-Narrative.pdf
│ └── Sample-Customer-and-Partner-Contracts.pdf
├── 05_Quantitative-Metrics/
│ ├── Monthly-EFT-Volumes-and-Values.xlsx
│ ├── End-User-Funds-Daily-Balances.xlsx
│ ├── End-User-Counts.xlsx
│ ├── Currency-Mix.xlsx
│ ├── PSP-Counterparties.xlsx
│ ├── Forecast-Model.xlsx
│ └── Metrics-Methodology-and-Reconciliation.pdf
├── 06_Safeguarding/
│ ├── Safeguarding-Applicability-Memo.pdf
│ ├── Safeguarding-Framework.pdf
│ ├── Trust-or-Segregated-Account-Agreement.pdf
│ ├── Insurance-or-Guarantee.pdf
│ ├── Bank-No-Set-Off-Confirmation.pdf
│ ├── Daily-Reconciliation-Procedure.pdf
│ ├── End-User-Funds-Ledger-Specification.pdf
│ └── Insolvency-Return-of-Funds-Plan.pdf
├── 07_Operational-Risk/
│ ├── RPAA-Risk-and-Incident-Response-Framework.pdf
│ ├── Asset-and-Process-Inventory.xlsx
│ ├── Operational-Risk-Register.xlsx
│ ├── Business-Continuity-and-Disaster-Recovery.pdf
│ ├── Incident-Response-Plan.pdf
│ ├── Cybersecurity-and-Access-Controls.pdf
│ ├── Testing-and-Assurance-Plan.pdf
│ └── Training-Plan.pdf
├── 08_Third-Parties/
│ ├── TPSP-Register.xlsx
│ ├── Materiality-Assessments/
│ ├── Contracts/
│ ├── Due-Diligence/
│ └── Technology-and-Data-Locations.xlsx
├── 09_Agents-and-Mandataries/
│ ├── Agent-Register.xlsx
│ ├── Agent-Contracts/
│ ├── Activity-and-Location-Matrix.xlsx
│ └── Oversight-Controls.pdf
├── 10_Data-and-Privacy/
│ ├── Data-Inventory.xlsx
│ ├── Data-Purposes.xlsx
│ ├── Data-Processing-Countries.xlsx
│ ├── Third-Party-Access-Register.xlsx
│ └── Privacy-and-Data-Security-Policies.pdf
└── 11_PSP-Connect-Submission/
├── Draft-Answers.md
├── Upload-Index.xlsx
├── Final-Application-Download.pdf
├── Payment-Receipt.pdf
└── Regulator-Correspondence/
7. Documents and data to collect, item by item
7.1 Corporate identity
Exact English legal name.
Exact French legal name, if applicable.
Main trade name.
Every other trade or operating name.
Incorporation or formation number.
Incorporation or formation date.
Country and jurisdiction of incorporation or formation.
Governing statute.
Current corporate registry extract.
Civic address.
Head-office address.
Primary mailing address.
Billing address.
Telephone, fax if any, email and website.
Confirmation whether any address is a dwelling house.
Operating launch date or planned launch date.
7.2 Ownership, control and governance
Corporate organization chart showing every controlling and controlled entity or individual.
Every direct and indirect holder of 10% or more of voting rights.
For a non-corporate entity, every direct or indirect holder entitled to 10% or more of profits or assets on dissolution.
Country of residence of every controller.
Citizenship of every individual controller and material owner.
Incorporation or formation country of every entity controller or material owner.
Complete board list.
For every director: legal name, mailing address, telephone, email, citizenship, residence and other board positions.
Top five most highly compensated senior officers for the last calendar year.
For each senior officer: legal name, mailing address, telephone, email, citizenship and residence.
Five largest creditors by amount owed at any time during the last calendar year.
Creditor identity, address, telephone, email, residence/citizenship or incorporation country.
Publicly traded status and exchanges.
State-owned-enterprise ownership, voting, veto or appointment rights.
7.3 FINTRAC and regulatory status
FINTRAC registration number.
FINTRAC registration issue date.
Copy of current FINTRAC registration record.
Confirmation that FINTRAC registration is active and not expired.
Reconciliation of FINTRAC legal name, trade names, addresses, ownership and activities against the RPAA application.
Details of any FINTRAC conviction, serious or very serious violation, compliance-order violation or penalty during the relevant five-year period.
Names of every foreign regulator supervising the applicant’s retail payment activities.
Statutes under which each foreign regulator supervises it.
Provincial or territorial retail-payment registration applications or registrations, if any.
Prior Bank of Canada RPAA applications, entity IDs, case IDs, refusal dates, revocation dates or change-of-control filings.
7.4 Products and payment functions
Prepare a product-by-product matrix containing:
product name;
legal entity providing it;
customer type;
payer and payee;
countries served;
currencies;
payment rail;
collection method;
payout method;
bank and processor involved;
whether the company receives instructions;
whether the company authorizes or facilitates an EFT;
whether the company provides or maintains a payment account;
whether the company holds funds;
duration for which funds may be at rest;
clearing function;
settlement function;
applicable exclusion, if claimed;
contract governing the service;
associated third parties, agents and affiliates.
7.5 Contracts
Collect representative executed or final-form copies of:
end-user terms and conditions;
merchant or business-customer agreements;
payment-processing agreements;
bank and safeguarding-account agreements;
processor, gateway, card-network or sponsor-bank agreements;
settlement and clearing agreements;
wallet or account terms;
remittance terms;
third-party service-provider contracts;
agent and mandatary agreements;
affiliate service agreements;
insurance or guarantee documents;
privacy terms and data-processing agreements.
7.6 Quantitative information
For an operating Canadian applicant, collect the preceding 12 months on a monthly basis:
number of EFTs for all end users;
total value of those EFTs in Canadian dollars;
number of EFTs for end users in Canada;
total value of Canadian-end-user EFTs in Canadian dollars;
average value of end-user funds held at the end of each day for all end users;
average value held for end users in Canada;
currency breakdown and percentage share of held funds;
other value-holding instruments;
number of end users;
number of end users in Canada;
PSP counterparties served during the previous two years;
PSP counterparties expected during the next two years.
For a foreign applicant, calculate the Canadian-end-user portions required by the form.
For a pre-operational applicant, create defensible first-year projections using documented assumptions.
7.7 Metrics methodology
The metrics package must explain:
how an EFT is counted;
treatment of reversals, refunds, rejected transfers and duplicates;
whether each payment is counted once or at multiple stages;
exchange-rate source and date used for CAD conversion;
definition and geolocation method for an “end user in Canada”;
calculation of daily closing balances;
calculation of monthly average end-user funds;
treatment of weekends and non-business days;
treatment of omnibus accounts;
treatment of funds in transit versus funds at rest;
reconciliation to bank statements, processor records, ledger data and general ledger;
assumptions used in projections;
approval and review performed by finance and operations.
8. Prepare the mandatory operational-risk framework
A superficial policy is inadequate. The framework must be written, tailored to the actual payment model and supported by operating evidence.
Required framework structure
Purpose, scope and legal basis
legal entity covered;
products, jurisdictions, systems and payment functions covered;
employees, affiliates, agents, mandataries and third parties covered.
Objectives
continuous performance of retail payment activities;
availability of relevant systems, data and information;
integrity and confidentiality of payment activities, systems, data and information.
Measurable reliability targets and indicators
service availability target;
recovery time objective;
recovery point objective;
transaction failure and reconciliation thresholds;
incident detection and response targets;
data-integrity and access-control indicators.
Governance
board oversight;
accountable senior officer;
first-line operational owners;
risk/compliance challenge function;
internal audit or independent assurance;
escalation thresholds.
Resources
required personnel;
skills and training;
financial resources;
external specialists;
reliable and timely access to emergency resources.
Asset and process inventory
payment applications;
databases;
APIs;
cloud infrastructure;
encryption and key-management systems;
customer and transaction data;
payment instructions;
bank connections;
reconciliation systems;
material manual processes;
critical vendors and agents.
Criticality and sensitivity classification
critical, high, medium and low classifications;
rationale;
system dependencies;
single points of failure.
Operational-risk identification
cyber risk;
fraud and internal misconduct;
technology failure;
data corruption or loss;
cloud or telecommunications outage;
third-party failure;
bank or settlement-partner failure;
process and human error;
business continuity;
physical security;
capacity and scalability;
legal and regulatory risk affecting operations.
Preventive and detective controls
access control and segregation of duties;
change management;
secure development;
vulnerability and patch management;
encryption;
logging and monitoring;
transaction monitoring and reconciliation;
backup and restoration;
vendor controls;
fraud controls;
exception management.
Incident-response plan
incident classification;
command structure;
immediate investigation;
root-cause analysis;
containment;
manual or alternative processing;
communication with affected end users and counterparties;
Bank of Canada material-incident notification;
evidence preservation;
final incident report and lessons learned.
Business continuity and recovery
crisis-management plan;
disaster-recovery plan;
alternate systems and workarounds;
recovery sequencing;
communication tree;
testing schedule.
Third-party service-provider risk
pre-contract due diligence;
materiality assessment;
contractual allocation of responsibility;
data ownership, integrity, confidentiality and availability;
audit and access rights;
incident notification;
continuity and exit planning;
ongoing performance assessment.
Agents and mandataries
minimum operational-risk criteria;
onboarding and monitoring;
prohibited activity outside authority;
incident reporting and record access;
termination controls.
Training
role-based training;
incident exercises;
annual refresher;
evidence of completion.
Review, testing and independent review
annual review;
control testing;
scenario tests;
penetration and resilience testing, where proportionate;
remediation tracking;
independent review cycle.
Approval and document control
senior-officer approval;
board approval where applicable;
version history;
controlled access;
prevention of unauthorized deletion or amendment;
retention of evidence.
9. Determine whether the company “holds end-user funds”
This determination cannot be based solely on whether the company calls itself a custodian.
Ask:
Does the company receive money before the next transfer is executed?
Can money remain in a wallet, balance or account?
Is payout scheduled for a later date?
Can the end user withdraw or redirect the balance?
Does the company control the timing or release of funds?
Are merchant proceeds accumulated before payout?
Are funds in transit continuously, or are they at rest at any stage?
Is the account legally and operationally controlled by the company?
Does the company’s ledger show a liability to the end user?
If the answer indicates holding, safeguarding obligations apply.
10. Prepare the safeguarding structure if end-user funds are held
The principal statutory alternatives are:
hold end-user funds in trust in a trust account used for no other purpose; or
use another prescribed method, if available and applicable; or
hold the funds in an account used for no other purpose and maintain insurance or a guarantee at least equal to the amount held.
A limited exception may apply to qualifying provincially insured or guaranteed deposits.
Required safeguarding evidence
Written legal analysis of the chosen safeguarding method.
Executed or near-final safeguarding account agreement.
Confirmation that the account is used only for end-user funds.
Valid express-trust analysis if using a trust structure.
Account-provider identity and regulator.
Confirmation that the account provider satisfies applicable regulatory standards.
Insurance policy or guarantee, if using that alternative.
Confirmation that insurer or guarantor is eligible and not an impermissible affiliate.
Coverage calculation demonstrating coverage equals or exceeds end-user funds.
No-set-off or compensation analysis and appropriate contractual protection.
Daily reconciliation procedure.
End-user funds ledger containing each end user’s name/contact information and daily amount held.
Shortfall identification and remediation procedure.
Liquidity arrangements supporting timely access.
Insolvency playbook for identifying, contacting and paying end users.
Third-party and agent roles in an insolvency payout.
Named senior officer accountable for safeguarding.
Board and senior-officer approval records.
Annual review procedure.
Independent review procedure at least once every three years.
Safeguarding framework contents
The framework should document:
reliable access to funds without delay;
payment of funds to end users as soon as feasible following insolvency;
account and liquidity arrangements;
daily end-user ledger and reconciliation;
legal and operational risks;
relevant jurisdictions;
trust, insurance or guarantee terms;
shortfall correction;
insolvency administrator access to records;
end-user contact process;
payout procedures;
governance, approval, review and evidence retention.
11. Identify every material third-party service provider
A third-party service provider should be assessed based on impact, not just contract labels.
Potential TPSPs include:
cloud hosting providers;
core payment-processing platforms;
card processors;
bank-as-a-service or sponsor-bank providers;
ledger and wallet platforms;
payment gateways and orchestration providers;
identity-verification vendors;
fraud and cybersecurity providers;
data-storage and backup providers;
communications providers;
settlement or reconciliation providers;
safeguarding-account providers where services extend beyond the account itself;
outsourced customer-service or operations teams.
For each TPSP, collect:
legal and trade names;
entity type;
civic, head-office and mailing addresses;
telephone, email and website;
payment functions supported;
exact services provided;
role in the end-to-end payment flow;
technology locations;
data-storage and processing countries;
access to personal or financial information;
country of residence or incorporation;
materiality assessment;
contract and due-diligence file;
operational-risk and safeguarding impact;
incident, audit, continuity and termination terms.
12. Identify every agent or mandatary
For each agent or mandatary:
classify it as agent or mandatary;
record legal and trade names;
record civic, mailing and activity-location addresses;
identify any dwelling-house address;
record telephone, email and website;
describe every retail payment activity performed on the applicant’s behalf;
identify each physical location where activity is performed;
retain the governing agreement;
document scope of authority;
document operational-risk criteria and oversight;
confirm access to records;
confirm the agent is listed accurately in the application.
Also determine whether the applicant itself acts as an agent or mandatary for another PSP and identify that PSP.
13. Map personal and financial information
The application requests national-security-related information about data collection, processing, storage and access.
Create an inventory covering:
personal identifying information;
financial data and confidential account information;
private communications;
geolocation data;
other sensitive information;
purposes for which each category is collected;
countries in which each category is stored or processed;
internal and external systems involved;
every relevant third party with access;
third-party legal name, address, contact details, residence/citizenship or incorporation information;
access purpose and technical permission level.
Do not answer only from the privacy policy. Validate against actual system architecture, cloud regions, support access, analytics, logging, backups and subcontractors.
14. Create the PSP Connect account correctly
Go to PSP Connect.
Use an email address controlled by the applicant legal entity.
Do not use a consultant’s personal account as the company’s primary administrator.
Note that one email address can be associated with only one application/entity.
Treat the person creating the account as the organization administrator.
Add the Bank’s notification sender to the email allow-list.
Add other company representatives as authorized users.
Add external counsel or consultants as delegates rather than owners of the account.
Appoint:
a designated contact for application questions; and
an authorized user responsible for fee payment.
Use a desktop browser and save the application regularly.
Maintain internal copies of every answer and uploaded document.
15. Complete the PSP Connect application — section by section
The Bank’s current step-by-step form contains 18 sections. The exact questions displayed can change based on earlier answers.
Section 1 — Preferred language
Select English or French.
Use the selected language consistently in the form and regulator correspondence.
Section 2 — Name, identification and operating status
2.1 Legal and trade names
Enter the full English legal name.
Enter the full French legal name if applicable.
State whether the company performs or plans to perform payment functions under other names.
Enter the main trade name.
Enter every other trade or operating name.
Where the portal requires a value but none exists, follow the portal guide’s permitted “N/A” convention.
2.2 Operating status
State whether the applicant is currently operating and performing retail payment activities.
If yes, provide the actual launch date.
If no, provide the planned launch date.
Control point: The answer must match the scope memo, transaction data, contracts, website and FINTRAC profile. Do not mark the applicant “not operating” merely because it is not yet RPAA-registered if it is in fact processing payments.
Section 3 — Previous submissions and invitations to the Retail Payments Supervision program
State whether the applicant previously submitted an RPAA registration application.
Select: no previous application, previously registered, or previously submitted but not registered.
If previously registered, provide the prior RPS entity ID and registration date.
State the outcome: revocation, cessation or re-registration following change of control.
Provide applicable revocation, cessation or re-registration dates.
If a previous application was submitted, provide the case ID.
State the prior application outcome and refusal date if applicable.
Do not use “withdrawal” where the Bank’s guide says it is not a valid outcome.
State whether this application follows a Bank invitation, warning, notice of violation or other enforcement correspondence.
Provide the entity ID and issue date shown on that correspondence.
Section 4 — Contact information
4.1 Applicant addresses and contacts
Civic address.
Confirm whether it is a dwelling house.
Confirm whether head office is the same address.
If different, enter the complete head-office address and whether it is a dwelling house.
Confirm whether primary mailing address is the same.
If different, enter the primary mailing address.
Confirm whether billing address is the same as civic or head office.
If different, enter billing address.
Telephone number with country and area code.
Fax, if any.
Company email address.
State whether the applicant has an active website or one under development.
Enter the website address.
4.2 Authorized users
Select the authorized user who is the designated application contact.
Select the authorized user responsible for payment of the registration fee.
Control point: Some contact information is published on the public PSP registry. Use durable company-controlled details.
Section 5 — Business structure
5.1 Organization chart
Upload one consolidated PDF showing all individuals and entities that control or are controlled by the applicant.
Show direct and indirect ownership percentages.
Show affiliates and intermediate holding companies.
Show country of incorporation/residence.
Ensure the diagram agrees with the shareholder register and FINTRAC records.
5.2 Entity type
Select corporation, individual/sole proprietor, limited partnership or other entity.
5.3 Corporation information
Where applicable:
incorporation number;
incorporation date;
country and jurisdiction;
governing legislation.
5.4 Holders of 10% or more voting rights
For each direct or indirect 10% holder:
legal name;
individual or entity classification;
residence and citizenship for an individual;
incorporation or formation country for an entity;
ownership percentage and chain, retained in the supporting file.
5.5 Individual applicant
If the applicant is an individual:
legal name;
date of birth;
country of residence.
5.6 Limited partnership
If applicable:
establishment date;
country and jurisdiction established;
country of residence;
each controlling general partner’s legal name, residence and citizenship.
5.7 Other entity
If applicable:
identify entity type;
establishment date;
country and jurisdiction established.
5.8 Holders of 10% or more profits/assets
For a non-corporate, non-limited-partnership applicant:
identify every direct or indirect holder entitled to 10% or more of profits or assets on dissolution;
provide legal name;
residence and citizenship or incorporation/formation country.
5.9 Public-market information
State whether publicly traded.
Identify each exchange.
5.10 State-owned-enterprise interests
State whether a state-owned enterprise owns an interest.
Name the state-owned enterprise.
Identify the foreign state.
Describe the interest.
State whether it carries veto or other special decision rights.
5.11 Board of directors
For each director:
legal name;
mailing address;
telephone;
email;
citizenship(s);
country of residence;
other board memberships and entity names.
5.12 Senior officers
Identify the five most highly compensated senior officers during the previous calendar year. For each:
legal name;
mailing address;
telephone;
email;
citizenship(s);
country of residence.
5.13 State-owned-enterprise appointment power
State whether an SOE can appoint the CEO, senior management, directors or similar governing persons.
Name the SOE.
Describe the power.
Identify the foreign state.
5.14 Five largest creditors
Identify the five creditors to which the applicant owed the greatest amount at any time during the previous calendar year. For each:
legal name;
mailing address;
head-office address;
telephone;
email;
citizenship/residence for an individual;
incorporation country for an entity;
amount and measurement date retained in internal evidence.
5.15 Controllers
For every person or entity that controls the applicant:
legal name;
individual/entity classification;
country of residence;
citizenship(s) for individuals;
legal basis for control retained in the supporting file.
Section 6 — Payment functions
6.1 Product and service description upload
Upload one consolidated PDF describing the applicant’s payment products, services and processes.
Explain each product in plain language.
Identify customer types, countries, currencies, rails, accounts, timing and counterparties.
6.2 Contract upload
Upload one consolidated PDF containing representative contracts or agreements with clients, end users, TPSPs and other relevant parties.
Include a table of contents and redact only information that is genuinely unnecessary; do not obscure regulatory substance.
6.3 Process diagrams
Upload diagrams and/or narratives showing the typical end-to-end process.
Identify every statutory payment function.
Distinguish the applicant’s actions from those of banks, processors, affiliates, agents and TPSPs.
Show the legal and operational location of funds at each stage.
6.4 Providing or maintaining a payment account
State whether the applicant provides or maintains an account for an end user in relation to an EFT.
Describe account creation, ledgering, balance display, instructions, access, withdrawals and closure.
6.5 Holding end-user funds
State whether the applicant holds or plans to hold funds until withdrawal or transfer.
Identify pre-funded, stored-value or balance products.
State the safeguarding method.
If using a trust account:
identify the account provider;
state whether it is OSFI-regulated or provincially regulated;
identify the relevant regulator.
If using insurance:
identify the insurer and regulator;
identify the safeguarding account provider and regulator;
retain policy terms and coverage calculations.
If using a guarantee:
identify the guarantor and regulator;
identify the safeguarding account provider and regulator;
retain guarantee terms and coverage calculations.
If relying on provincially insured deposits:
identify the statutory scheme and evidence that the funds qualify.
6.6 Initiating EFTs
State whether the applicant initiates EFTs at an end user’s request.
State whether it enables a payer or payee to launch, trigger or instruct the transfer.
Describe how initiation occurs.
State whether the applicant captures or packages EFT data.
Explain when and how the data is captured, formatted and sent.
6.7 Authorization, transmission, receipt or facilitation
Answer each functional question separately:
Does the applicant request end-user confirmation of sending or receiving an EFT?
Does it confirm sufficient funds?
Does it maintain an arrangement authorizing payment instructions?
Does it debit or credit an end-user account according to an instruction?
Does it send a payment instruction to another person or entity?
Does it receive a payment instruction from another person or entity?
Does it provide a platform, network or other infrastructure facilitating payment instructions?
6.8 Clearing and settlement
State whether the applicant performs clearing or settlement services.
Does it enable clearing?
Does it sort payee sales information?
Does it calculate net positions or otherwise help determine obligations?
Does it transform payment information or formats?
Does it perform security and integrity checks?
Does it sort transactions by instrument or recipient?
Does it transmit final positions?
Does it confirm availability of settlement funds?
Does it act as clearing agent?
Does it enable settlement?
Does it post credits or debits to another party’s account?
Does it conduct account adjustments?
Control point: Never select a function merely because it sounds commercially attractive. Every “yes” should be traceable to a specific system action, contract and process step.
Section 7 — EFTs, currencies and exclusions
State whether the applicant performs retail payment activities in relation to an EFT.
Describe how each activity relates to an EFT.
Select every currency used.
State whether any function relates to a closed-loop transfer.
State whether any function gives effect to an eligible financial contract or prescribed securities transaction.
State whether any function relates to an ATM cash withdrawal.
State whether any function uses a system designated under the Payment Clearing and Settlement Act.
State whether any function relates to an EFT between affiliates.
Confirm whether the applicant is one of those affiliates.
Confirm whether another PSP performs a payment function in relation to that EFT.
Identify whether the applicant is an excluded regulated entity, such as a bank, authorized foreign bank or another listed institution.
Select “none of the above” only after the entity-exclusion review is complete.
Section 8 — Geographic perimeter
Identify every Canadian financial institution where the applicant maintains an account and uses the institution as a clearing and settlement agent.
State whether the applicant has a place of business in Canada.
If not, state whether it directs services at persons or entities in Canada.
If not Canadian, confirm a Canadian agent or mandatary authorized to accept RPAA notices and orders.
State whether foreign regulators supervise the applicant’s retail payment activities.
Identify each foreign regulator.
Identify each governing statute.
Section 9 — Values and volumes
Operating applicant with a Canadian place of business
Describe current activities.
Enter, for each of the prior 12 months, average daily closing end-user funds for all end users in CAD.
Enter the equivalent for end users in Canada.
Identify currencies and percentage shares for all end users.
Identify currencies and percentage shares for Canadian end users.
Identify other value-holding instruments.
Enter monthly EFT number and total value for all end users.
Enter monthly EFT number and total value for Canadian end users.
Operating applicant without a Canadian place of business
Provide the required Canadian-end-user metrics for the preceding 12 months.
Do not insert worldwide totals into fields limited to Canadian end users.
Pre-operational applicant
Provide first-year projected average end-user funds.
Separate all end users and Canadian end users where required.
Provide projected currencies and shares.
Provide projected EFT number and value.
Retain a documented forecast methodology approved by finance and operations.
Control point: All figures must reconcile to a controlled workbook and methodology memo. Do not calculate directly inside PSP Connect.
Section 10 — End users and interconnectedness
State whether operations have begun.
For an operating Canadian applicant, provide the previous-year number of all end users.
Separately provide Canadian-end-user figures where required.
For a foreign applicant, provide the Canadian-end-user figure.
For a pre-operational applicant, provide first-year projections.
List PSPs for which the applicant performed retail payment activities during the previous two years.
List PSPs for which it plans to perform activities during the next two years.
For a foreign applicant, identify the relevant PSP counterparties having a place of business in Canada.
Where none exist, use the portal’s stated “Not applicable” method rather than leaving a mandatory field incomplete.
Section 11 — Risk-management and incident-response framework
State whether the applicant has established or plans to establish the framework.
Before submission, confirm that a complete written RPAA-specific framework exists or is at a sufficiently final and approved stage.
Record the accountable senior officer.
Record board approval where applicable.
Maintain evidence that the framework is implemented, not merely drafted.
Section 12 — Personal and financial information
State whether the applicant gathers or plans to gather personal or financial information relating to Canadian end users, employees or business partners.
Identify personal identifying information and its purpose.
Identify financial/confidential account information and its purpose.
Identify private communications and their purpose.
Identify geolocation data and its purpose.
Identify all other categories and purposes.
State whether data is or will be stored or processed.
List every storage and processing country.
State whether any external person or entity has or will have access.
For each such party, provide legal name, entity type, addresses, telephone, email and residence/citizenship/incorporation information.
Section 13 — Third-party service providers
State whether the applicant uses TPSPs in connection with retail payment activities.
State whether any has or will have a material impact on operational risk or safeguarding.
Create one entry for each material TPSP.
Select preferred language.
Enter legal and trade names.
Identify payment functions supported.
List and describe services.
Enter civic, head-office and mailing addresses.
Enter telephone, email and website.
Describe the TPSP’s role.
Identify geographic locations of technology.
State whether it stores or processes data.
List data-storage and processing countries.
State whether it accesses personal or financial information.
Identify whether it is an individual or entity and provide residence/citizenship/incorporation details.
State whether the applicant itself acts as a TPSP to another PSP and identify that PSP.
Section 14 — Agents and mandataries
State whether agents or mandataries perform retail payment activities under the applicant’s authority.
Create one entry per agent or mandatary.
Classify the relationship.
Enter preferred language, legal name and trade names.
Enter civic/head-office, mailing and activity-location addresses.
Identify any dwelling-house address.
Enter telephone, email and website.
Describe each retail payment activity performed.
State whether the applicant acts or plans to act as an agent or mandatary for another PSP.
Identify the other PSP.
Section 15 — Affiliated entities
State whether the applicant has affiliates.
Create one entry per affiliate.
Enter preferred language, legal name and trade names.
Enter civic and mailing addresses.
Enter telephone, email and website.
Enter country of residence.
Upload one consolidated corporate chart showing the relationship.
List retail payment activities performed by the affiliate on behalf of the applicant.
Separately determine whether the affiliate itself must register.
Section 16 — FINTRAC declaration
Select “Yes” if the exact applicant legal entity is registered with FINTRAC.
Enter the FINTRAC registration number exactly.
Enter the FINTRAC issue date in YYYY-MM-DD format.
Confirm the FINTRAC registration remains active.
Resolve any discrepancy in name, ownership, address or activities before submission.
The Bank may refuse registration if an applicant that is required to be registered with FINTRAC is not registered. FINTRAC enforcement history can also affect the decision.
Section 17 — Provincial or territorial registration
State whether the applicant has applied under any provincial or territorial statute respecting retail payment activities.
Identify each province or territory.
State whether the applicant is registered under such a statute.
Identify each jurisdiction of registration.
Section 18 — Fee payment and submission
Enter any necessary additional comments.
Select the payment method offered by PSP Connect.
Confirm every mandatory field is complete.
Confirm every uploaded PDF opens and is readable.
Confirm payment is processed.
Submit the application.
Save the submission confirmation.
Download the complete submitted application.
Save the fee receipt.
Record the case ID and entity ID.
Add the application to the regulatory-obligations calendar.
Registration fee
The Regulations index the base CAD 2,500 fee using the September all-items Canadian CPI. Based on the official September 2024 and September 2025 indices, the statutory formula produces approximately CAD 2,558.97 for an application submitted in 2026. Some Bank guidance still displays CAD 2,500. Use and pay the exact amount generated by PSP Connect at submission. The fee is one-time and non-refundable.
16. Pre-submission quality assurance
Legal consistency
Correct legal entity.
Scope memo finalized.
Claimed exclusions documented.
Payment-function answers match contracts and diagrams.
Safeguarding method legally valid.
Canadian agent appointed if required.
Corporate consistency
Legal name matches incorporation documents.
Trade names complete.
Ownership percentages reconcile.
Controllers, directors, officers and affiliates complete.
Creditor information verified.
FINTRAC consistency
FINTRAC registration active.
Legal name and number exact.
Activities align with FINTRAC profile.
Any compliance history disclosed accurately.
Operational consistency
Product description, contracts and diagrams agree.
All payment functions are identified.
All TPSPs, agents and affiliates are accounted for.
Data locations agree with system architecture and contracts.
Risk and incident framework is approved and implementable.
Safeguarding framework is approved and implementable if required.
Quantitative consistency
12-month data covers the correct period.
Canadian/end-user classification is documented.
CAD conversion methodology is consistent.
Figures reconcile to source records.
Forecasts are reasonable and approved.
No unexplained zeros or material fluctuations.
Submission control
Final application reviewed by two independent reviewers.
Executive sponsor signs the application approval memo.
All supporting files are frozen and hashed or otherwise version controlled.
Portal answers are copied into the internal answer file.
Regulator-response team and response deadlines are agreed.
17. What happens after submission
Stage 1 — Receipt and initial assessment
PSP Connect issues confirmation of receipt.
The Bank begins assessment after the required fee is paid.
The applicant may appear on the public list of applicants while the application is processed.
Being listed as an applicant is not registration and does not authorize a post-transition applicant to perform retail payment activities.
Stage 2 — Additional-information requests
The Bank may request additional information.
The statutory response period is generally 30 days.
Treat every request as a formal regulatory deliverable.
Do not answer through informal narrative alone when evidence is available.
Reconcile the response to the original application.
Explain and correct any change rather than silently contradicting the application.
Submit early where possible.
Stage 3 — Completeness determination
The Bank determines when it considers the application complete. This date is important because the Bank’s prescribed 45-day refusal window for most Bank-level refusal grounds begins after completeness.
Completeness is not the same as approval.
Stage 4 — FINTRAC information exchange
The Bank shares prescribed application information with FINTRAC. Keep the FINTRAC registration active and the application consistent with FINTRAC records throughout the review.
Stage 5 — Department of Finance national-security review
The application is provided to the Minister of Finance or designated authority.
The Minister generally has 60 days to decide whether a national-security review is required.
That decision period can be extended in further 60-day periods.
If a review is initiated, the prescribed review period is 180 days and can be extended.
Additional information, undertakings or conditions may be required.
The Minister can direct the Bank to refuse registration on national-security grounds.
Stage 6 — Bank registration decision
The Bank can register the applicant once the statutory review conditions have been satisfied and no refusal ground applies. The Bank then notifies the applicant and places the PSP on the public registry.
There is no reliable single end-to-end approval SLA. The often-quoted 45 days is not a guaranteed approval timeline; it relates to the Bank’s refusal window after completeness or expiry of an additional-information period. National-security review periods can materially extend the process.
Stage 7 — Go-live decision
Do not commence or resume in-scope retail payment activities merely because:
the application was submitted;
the company appears on the list of applicants;
the Bank has deemed the application complete; or
45 days have passed.
For a post-transition application, wait until the applicant is actually registered and appears on the Registry of Payment Service Providers.
18. Grounds that can cause refusal or severe delay
The Bank may refuse registration for reasons including:
failure to provide requested additional information within the required period;
false or misleading information;
relevant convictions under the federal AML legislation;
certain serious, very serious or compliance-order FINTRAC violations during the preceding five years;
failure to maintain required FINTRAC registration;
cessation of, or no genuine plan to perform, retail payment activities;
an RPAA violation;
unpaid prior Bank assessment amounts;
a determination that the RPAA does not apply to the applicant or its proposed functions;
a Ministerial direction to refuse following national-security review.
Practical delay triggers
unclear funds flows;
incorrect applicant entity;
missing indirect owners or controllers;
unresolved foreign ownership or state influence;
unexplained creditor relationships;
incomplete TPSP and data-location disclosures;
mismatch between portal answers and contracts;
inability to produce reliable 12-month metrics;
claiming not to hold funds despite funds being at rest;
safeguarding structure not legally effective;
generic risk framework copied from an AML manual;
inconsistent FINTRAC and Bank information;
changes in ownership, products or activity during review without prompt notification;
slow or incomplete responses to regulator questions.
19. If registration is refused
For a Bank refusal under the statutory refusal provisions:
The Bank provides written reasons.
The applicant generally has 30 days to request a prescribed review by the Governor and make written submissions.
The review decision is generally due within 90 days after the request.
A further appeal to the Federal Court is generally subject to a 30-day prescribed period.
A Ministerial national-security refusal follows a different review route. Obtain specialist Canadian counsel immediately upon any notice of potential refusal.
20. Obligations after registration
Registration is the beginning of supervision, not the end of the project.
Continuous obligations
Maintain the operational-risk and incident-response framework.
Maintain safeguarding arrangements and framework if end-user funds are held.
Keep sufficient records to demonstrate compliance.
Keep all required FINTRAC registrations active.
Maintain accurate public and non-public registration information.
Assess and manage TPSPs and agents.
Test, review and independently assess frameworks as required.
Maintain board and senior-officer oversight.
Incident reporting
A material incident must be reported to the Bank without delay and no later than 48 hours after the PSP determines that it is material. Maintain a procedure for initial, interim and final reporting.
Significant change or new activity
Notify the Bank at least five business days before making a significant change in how a retail payment activity is performed or before performing a new retail payment activity, where the statutory test is met.
Annual report
A PSP that performs retail payment activities during a calendar year must generally submit its annual report by 31 March of the following year.
Registration-information changes
Maintain a change-control matrix. Some changes must be reported within 30 days; other prescribed changes have different or accelerated timeframes. Ownership or control changes can require a new registration application.
Ongoing fees
Registered PSPs are subject to cost-recovery assessments in addition to the one-time application fee.
21. Recommended 30-business-day execution plan
This is an internal submission target, not a regulator processing estimate.
Business days | Workstream | Required result |
|---|---|---|
1–2 | Executive escalation and scope triage | Written status: operating, in-scope risk, interim controls |
1–3 | Project setup | Sponsor, project lead, counsel, tracker and data room |
2–6 | Legal entity and product mapping | Entity map, product matrix and initial scope memo |
3–8 | Corporate and FINTRAC collection | Complete corporate, ownership, officer and FINTRAC file |
4–12 | Funds-flow and contract review | Final payment-function matrix and diagrams |
5–15 | Metrics | Reconciled 12-month data or first-year projections |
5–16 | TPSPs, agents, affiliates and data | Complete registers, materiality assessments and locations |
6–20 | Operational-risk framework | RPAA-specific framework, procedures and approval draft |
6–22 | Safeguarding, if applicable | Legal structure, account/insurance/guarantee and framework |
15–23 | Draft PSP Connect answers | Complete offline answer pack and upload bundle |
21–25 | Challenge review | Legal, finance, operations, technology and compliance review |
25–27 | Governance approval | Senior officer/board approval and submission authorization |
27–29 | Portal entry and QA | PSP Connect completed and independently checked |
30 | Payment and submission | Fee paid, application submitted and downloaded |
If safeguarding arrangements or historical data are not available, those workstreams—not portal data entry—will determine the schedule.
22. Your first-week priority list
Confirm whether the exact legal entity is already on the Bank registry or applicant list.
Confirm whether it submitted before 8 September 2025.
Establish whether it is currently performing in-scope activities.
Obtain the existing product, customer, bank, processor and agent contracts.
Produce a one-page legal-entity and funds-flow map.
Reconcile the FINTRAC record to current corporate facts.
Determine whether the company holds end-user funds.
Identify the safeguarding account or the absence of one.
Identify all material TPSPs and data-storage countries.
Determine whether 12 months of reliable metrics can be produced.
Locate any existing operational-risk, incident-response, business-continuity and safeguarding documents.
Appoint the executive sponsor and accountable senior officer.
Open the controlled RPAA data room.
Create the PSP Connect account in the company’s name.
Set a formal submission date based on the longest unresolved workstream.
23. Definition of “application ready”
The application is ready only when all of the following are true:
Scope and correct legal entity are documented.
Current operating status is stated truthfully.
Corporate ownership and control are fully mapped.
FINTRAC status is active and consistent.
Payment products, functions and flows are understood.
Contracts support the stated model.
Quantitative metrics are reconciled and reproducible.
End-user-funds treatment has been legally analyzed.
Safeguarding arrangements are valid where required.
Operational-risk and incident framework is complete and approved.
TPSPs, agents, affiliates and data locations are complete.
National-security information is complete.
Every portal response has a named internal owner and source document.
Independent QA has found no material inconsistency.
Executive approval to submit has been recorded.
24. Primary official sources
Bank of Canada — Criteria for registering payment service providers
Bank of Canada — Supervisory framework and application process
Bank of Canada — How to complete a registration application: step-by-step guide
Bank of Canada — Frequently asked questions about retail payments supervision
Bank of Canada — Reporting retail-payment metrics at registration
Bank of Canada — Operational risk and incident response guideline
25. Final management position
The company should not treat RPAA registration as a short supplemental filing attached to its FINTRAC MSB registration. It is a separate prudential and operational-risk regime requiring a correct scope determination, detailed ownership and national-security disclosure, reliable activity metrics, a defensible payment-function analysis, material third-party disclosure, an implemented operational-risk framework and—where funds are held—a legally effective safeguarding structure.
The fastest credible route is not “complete the portal quickly.” It is:
identify the correct legal entity and present operating exposure;
freeze one accurate description of the business and funds flow;
build the missing frameworks and safeguarding evidence;
reconcile all corporate, FINTRAC, operational and quantitative information;
submit one complete, internally approved application; and
respond rapidly and consistently to the Bank and national-security reviewers.
Need Help With Your Canada RPAA Registration?
Faisal Khan LLC is a cross-border payments, licensing and regulatory-readiness consultancy. We help fintechs, payment companies, remittance operators, money services businesses and other payment service providers assess RPAA applicability, prepare Bank of Canada registration applications, align FINTRAC and corporate records, document payment flows, develop operational-risk and incident-response frameworks, and address end-user-funds safeguarding requirements.
If you need help preparing your Canada RPAA registration application—or you need an independent review of an application already in progress—get in touch.
Also See
© 2026 Faisal Khan LLC. All rights reserved. This document is provided for general informational purposes only and does not constitute legal, financial, compliance, regulatory or other professional advice. RPAA requirements, Bank of Canada guidance, regulatory interpretations, application procedures and fees may change. Always verify current requirements directly with the Bank of Canada and obtain advice from qualified Canadian legal and regulatory professionals regarding your company’s specific circumstances.
Our website: Faisal Khan LLC
