Our mission is to help Canadian fintech companies get registered, go live, and stay compliant.
If your business moves electronic money for other people and has a real connection to Canada, you probably need to register under the Retail Payment Activities Act (RPAA) with the Bank of Canada — and you need it before you start offering payment services, not after. The core trigger is a four-part test: you perform a payment function, tied to an electronic transfer of fiat funds, with a Canadian connection, and you are not excluded. Almost all payment companies also need separate FINTRAC MSB registration on top of this.
This guide covers what RPAA registration is, exactly when it applies, how it works alongside FINTRAC MSB registration, and what happens if you wait too long to register. To keep it concrete, we’ll follow one anonymized example throughout — a payments company we’ll call SambaPay, which expanded into Canada assuming a single registration would cover its whole business.
What is RPAA registration?
RPAA registration is the process of registering your business with the Bank of Canada as a payment service provider (PSP) under the Retail Payment Activities Act (RPAA). It is a registration, not an approval or a licence. The RPAA focuses on two things: managing operational risk — outages, fraud, cyber events, and incidents — and safeguarding the money you hold for users. You must register before you perform any payment activities.
The RPAA is a newer regime than Canada’s anti-money laundering rules, and it exists to protect end users. It wants payment companies to operate reliably, handle incidents properly, and keep customer funds safe if something goes wrong. In practice, that means a registered PSP has to maintain a risk-management framework, keep an accurate daily ledger of any funds it safeguards, and report incidents to the Bank of Canada. An electronic funds transfer (EFT) — moving money electronically — sits at the centre of almost everything the RPAA covers. You can read the Bank of Canada’s own guidance on criteria for registering payment service providers, and we explain how the process works in plain language on our RPAA registration page.
When does a payment company need to register with the Bank of Canada?
Let’s start with the short, simplified version of the test, because it gives you the right answer for almost every payment company. If you have a connection to Canada, and you either (a) help someone send electronic fiat funds to a third party, or (b) help someone receive electronic fiat funds from a third party, you almost certainly need RPAA registration. A connection to Canada means you have a place of business in Canada, are incorporated in Canada, or you target and serve users in Canada. Pay-in products, payout products, remittance companies, and most wallets all fall inside this simple rule.
That short rule is accurate the vast majority of the time. But the RPAA’s actual test is more detailed, and a few less common payment flows are captured by the full test even when the short version would miss them. Here is the complete four-part test the Bank of Canada applies.
You must register if all four parts of the Bank of Canada’s test are true: (1) you are a PSP, (2) you perform retail payment activities, (3) you have the required Canadian connection, and (4) you are not excluded. If even one part is false, RPAA registration does not apply. In our experience, most pay-in and payout products meet all four parts of the test.
Here is the four-part test in order:
- You are a PSP. You perform at least one of the five payment functions (below) as a service or business activity that is not merely incidental to some other, non-payment business.
- You perform retail payment activities. Your payment function relates to an EFT made in fiat currency (or a prescribed unit).
- You fall within the geographic scope. You either have a place of business in Canada, or you both direct your services at, and perform your services for, individuals or entities in Canada.
- You are not excluded. Banks, authorized foreign banks, and provincially regulated trust companies are excluded. So are incidental activities, securities-related transactions, and internal or closed-loop transactions.
The five payment functions
You are a PSP if you perform even one of these functions as a real service:
- Providing or maintaining an account for one or more end users.
- Holding funds on behalf of an end user (money kept at rest and available for later withdrawal or transfer).
- Initiating an EFT at an end user’s request.
- Authorizing an EFT, or transmitting, receiving, or facilitating a payment instruction in relation to an EFT.
- Providing clearing or settlement services.
The “holding funds” function catches more businesses than founders expect. If a user has a balance with you that they can draw down later — a wallet, a prepaid balance, or a delayed merchant settlement — you are likely holding funds at rest, which is squarely within the RPAA.
The Canadian connection
RPAA registration is harder to avoid than MSB registration. For MSB registration, there is a narrow “reverse solicitation” idea: a foreign business that does not actively market to Canadians may avoid a Canadian connection even if it occasionally serves Canadians. There is no comparable carve-out for the RPAA. If you serve Canadian users, assume the RPAA can apply.
Are you excluded?
The exclusions are specific, not general escape hatches. The securities-related transaction exclusion matters for some crypto and investment models, but it does not remove your payment flows from the RPAA if those flows are really payments. When you are unsure, the Bank of Canada offers a self-assessment tool to help you work through the test.
Are your payment functions incidental?
By far the exclusion we see most often is the incidental one. Go back to part 1 of the test: you are only a PSP if you perform a payment function as a service or business activity that is not merely incidental to some other, non-payment business. In plain terms, if moving money is just a by-product of the real non-payment thing you sell — not a service you offer in its own right — the RPAA does not treat you as a PSP, so registration is not required.
Non-custodial crypto trading: the classic example
The clearest example is non-custodial crypto trading. Your real business is letting a customer buy or sell crypto. The customer sends you fiat and immediately gets crypto back (or the reverse), and you never hold their funds at rest waiting to be sent somewhere later. Even though the Bank of Canada thinks you may be performing payment functions as a non-custodial crypto trading company, such payment functions are incidental to providing trading services (which is not a payment activity) — so you are not performing a stand-alone payment function, and according to the Bank of Canada, RPAA registration does not apply.
Two points are worth stressing:
- This does not get you out of FINTRAC. Dealing in virtual currency for other people still makes you a money services business, so non-custodial crypto trading needs MSB registration even though it escapes the RPAA.
- The exclusion depends on staying non-custodial and immediate-settlement. The moment you start holding customer balances — a wallet, a stored balance, or delayed settlement — you are holding funds at rest, which is a payment function in its own right and no longer incidental. At that point the RPAA applies again.
- See here for more details.
If your model sits anywhere near this line, get the fact pattern checked before you assume the incidental exclusion covers you.

Is RPAA registration the same as a PSP licence?
No. There is no “PSP licence” and no “Bank of Canada licence.” The correct term is RPAA registration, and the distinction is not just semantics. A licence implies a regulator reviews your business and grants permission. Registration means you meet the legal test, file the required information, and take on ongoing obligations. The Bank of Canada does not bless your business model — it registers you and then supervises you.
Why this matters in practice: teams that think they are waiting for “approval” often assume they cannot do anything until someone says yes, or assume that once they are registered they are “cleared.” Neither is right. You register because the law requires it, and registration is the start of ongoing risk-management and safeguarding duties, not a finish line. SambaPay is a case in point: it first came to us asking for “the Canadian licence,” expecting one approval to clear the whole business, when what it really faced was a set of registrations with ongoing obligations attached.
RPAA registration vs. FINTRAC MSB registration: do I need both?
Often, yes. A money services business (MSB) registers with FINTRAC (Canada’s anti-money laundering regulator) because it moves, exchanges, or deals in money or virtual currency for others. RPAA registration is a separate registration with the Bank of Canada focused on operational risk and safeguarding. They answer different legal questions, so a single product can trigger both at once. Most pay-in and payout products need both.
Here is how the two compare:
| Feature | FINTRAC MSB registration | RPAA registration (Bank of Canada) |
|---|---|---|
| Regulator | FINTRAC | Bank of Canada |
| Governing law | PCMLTFA | Retail Payment Activities Act (RPAA) |
| Core concern | Anti-money laundering and anti-terrorist financing | Operational risk and safeguarding user funds |
| Typical trigger | Transferring, exchanging, or dealing in money or virtual currency for others, with a Canadian connection | Performing a payment function tied to electronic transfers of fiat funds, with a Canadian connection |
| “Reverse solicitation” carve-out | Narrow carve-out may apply | No comparable carve-out |
| Rough timeline (2026, Renno-assisted) | ~5–6 months (9+ months solo) | ~2 months for a fresh application |
This is where SambaPay’s story comes together, because one company shows how all of these rules collide. SambaPay (again, an anonymized example) is a Brazilian payments company that processes high-volume merchant payments and decided to expand into Canada. Its product was not simple: it ran multi-currency wallets for its merchants, moved money in and out through fiat pay-in and payout rails, and converted between fiat and crypto in the back end. When it came to us, it asked for one thing — “the Canadian licence” — and had already built its launch timeline around getting that single approval and flipping the switch.
The problem surfaced the moment we mapped its real money flows against the rules instead of against its own label for the project. Three regimes were in play at once. The fiat pay-in and payout legs were textbook retail payment activities, so they required RPAA registration with the Bank of Canada. The crypto-conversion and currency-exchange leg meant SambaPay was dealing in virtual currency and fiat for other people, so it needed FINTRAC MSB registration. And because it served customers in Quebec, a separate provincial layer sat on top of both. The multi-currency wallet was the detail that made this unavoidable: holding balances for merchants is “holding funds at rest,” which is squarely a payment function, so there was no version of the product that one registration could cover.
The lesson SambaPay took away is the one we want you to take away: a modern payments stack usually needs both registrations at once — not one — and sometimes a provincial layer as well. Asking for “the Canadian licence” is the exact misconception that gets teams into trouble, because it hides how many separate obligations a single product can trigger. You can see how we handle the AML side on our Canadian MSB registration page, and our guide to MSB registration requirements walks through what that process involves.
See the below table providing an overview of which registrations you may need:
| Feature | MSB registration (FINTRAC) | RPAA registration (Bank of Canada / PSP) |
|---|---|---|
| Regulator | FINTRAC | Bank of Canada |
| Governing law | Proceeds of Crime (Money Laundering) and Terrorist Financing Act | Retail Payment Activities Act (RPAA) |
| Main purpose | Anti-money laundering and anti-terrorist financing (AML/ATF) | Operational risk management and safeguarding end-user funds |
| Core question | Can you spot and report money laundering and terrorist financing? | Can you run a safe, reliable payment operation and protect the money you hold for users? |
| Typical triggers | Foreign exchange dealing, money transfers, dealing in virtual currency, issuing or redeeming money orders | Typically involves receiving fiat funds from a third party on behalf of a client or sending fiat funds to a third party on behalf of a client |
| Covers crypto? | Yes — dealing in virtual currency is an MSB service (although be careful as some crypto activity may trigger securities registration) | Only indirectly — the RPAA applies to electronic transfers of fiat money, so the fiat leg of a crypto payment product (not the crypto itself) may trigger it |
| Register before you… | Offer MSB services in Canada | Perform retail payment activities |
Can I wait until I am fully live?
No. The RPAA requires you to register with the Bank of Canada before you perform any retail payment activities. Waiting until you are “fully live” gets the order backwards: registration is a condition of offering the service, not a formality you clean up afterward. Building the timeline into your launch plan is the single easiest way to avoid a forced pause.
The practical timelines are more manageable than they used to be. As of 2026, and based on our own market experience, a fresh RPAA registration is taking roughly two months. FINTRAC MSB registration takes longer — about five to six months when we manage the application, and market feedback suggests solo applicants can wait nine months or more. You can start both processes at the same time, so for companies that need both, MSB registration is often the bottleneck that sets your real launch date.
There is one nuance worth flagging. If you acquire a company that is already RPAA-registered, a change of control triggers re-registration with the Bank of Canada rather than a fresh application, and that has recently been running at roughly two weeks. That can be commercially meaningful, but acquisitions have to be handled carefully, so get advice before assuming a purchase is a shortcut.
What if a previous lawyer told me RPAA did not apply?
Treat an old “RPAA does not apply” conclusion as a starting point to re-check, not a final answer. The RPAA is a new regime and the Bank of Canada’s guidance has been updated over time (the criteria guidance was last updated in mid-2026). An opinion given earlier may predate the current guidance, or may have been based on how your product looked at the time.
The test is function-based and fact-specific, which is exactly where earlier conclusions can go stale. A prior “no” may have missed one of the five payment functions — most commonly the broad “transmitting, receiving, or facilitating an instruction” function. It is also common for the product to change after the advice was given: adding a wallet, introducing delayed settlement, or opening a new flow can flip the answer. If any of that sounds familiar, re-run the four-part test against your current product before you rely on the old conclusion. Book a call to chat with us about how the RPAA may apply to your business!
What about banking and Canadian presence?
Getting registered is only half the battle — banking is one of the hardest parts of the process. Many banks and account providers treat payment businesses as a high-risk category and will either decline to onboard them or apply heavy due diligence. Registration does not automatically solve this; it is the price of admission, not a guarantee of banking.
Two things move the needle with account providers. First, they expect to see a credible Canadian presence and a real anti-money laundering program before they onboard you. Many are now expecting to see your operational risk management framework (which is required under the RPAA). FINTRAC likewise expects a genuine Canadian physical presence — a business address tied to actual business, compliance, systems, or record-keeping activity, not a PO box or an empty virtual office. Second, they want your public registry details to line up, because a mismatch between your FINTRAC business address and your Bank of Canada head office address invites questions. If banking, Canadian presence, or account opening is your worry, it is worth a conversation early — book a call before you commit to a structure.
How Renno can help
If your analysis points to both registrations, you do not have to run two separate projects. Renno offers a bundled MSB + RPAA registration package that also includes preparation of the AML policy you need for MSB registration and the operational risk-management framework you need under the RPAA. That keeps the AML side and the payments side aligned instead of stitched together after the fact.
The most expensive mistake in this area is discovering, after you have started offering payment services, that your flows were captured all along. Before you launch a pay-in, payout, wallet, or remittance product with any Canadian connection, run the four-part test and confirm what you actually need. If you would like a second set of eyes on whether the RPAA applies to your specific flows, book a call — or fill out our form and we’ll get in touch — with our fintech team before you go live.
Disclaimer: This content is for informational purposes only and does not constitute legal advice.
Ready to get started?
Talk To UsBook a Free Consultation
Speak with our fintech legal advisor
about your registration


