When Does a Crypto Business Fall Under Canada’s RPAA?

When Does a Crypto Business Fall Under Canada’s RPAA?
Table of contents
    • A crypto business falls under Canada’s Retail Payment Activities Act when it performs at least one of five defined payment functions, does so as a business activity rather than incidentally, ties that function to an electronic funds transfer made in Canadian or foreign currency, and falls inside the Act’s geographic scope without qualifying for an exclusion. All four conditions have to hold at once.
    • The decisive question is currency. The RPAA reaches electronic funds transfers made in fiat or in a unit prescribed by regulation, and no unit has been prescribed as of August 2026. Crypto-to-crypto activity therefore sits outside the Act, while fiat on-ramps, off-ramps and card programs frequently sit inside it.
    • Registration with the Bank of Canada is separate from registration with FINTRAC. A crypto business can be a money services business without being a payment service provider, or both at once, and the two determinations run on different tests.
    • Enforcement arrived in 2026. The Bank of Canada issued its first order under the Act against XTM Inc. in February 2026 and, by late August 2026, every published notice of violation concerned the same failure: performing retail payment activities without being registered.
    • The perimeter is set to widen. Bill C-15 received royal assent on 26 March 2026 and adds a sixth payment function covering an end user’s encrypted or tokenized payment instrument or private key. That provision is law but awaits an order in council.

    The Question Every Canadian Crypto Business Has to Answer

    Canada supervises non-bank payment companies through the Retail Payment Activities Act, and the Bank of Canada has run that supervision as a live regime since November 2024. The Act took effect in stages, with registration opening on 1 November 2024 and the substantive obligations for operational risk and end-user fund safeguarding following on 8 September 2025. For crypto businesses, the consequence is a scoping decision that cannot be postponed indefinitely, because performing retail payment activities without being registered is itself a very serious violation under the regulations.

    The confusion is understandable. A crypto exchange in Toronto already holds a FINTRAC money services business registration, may operate under a pre-registration undertaking with a provincial securities regulator, and now discovers a third federal regulator with its own registry, application fee and enforcement powers. Whether that third registration applies turns on a narrow technical question rather than on how crypto-heavy the business feels.

    This guide works through the Bank of Canada’s four-step test, applies it to the crypto business models the Bank has published guidance on, separates the RPAA from the FINTRAC regime, and sets out what the stablecoin amendments change.

    What Does the RPAA Regulate?

    The RPAA regulates the movement of money by non-bank payment companies through a registration and supervision model rather than a licensing model. Parliament passed it as section 177 of chapter 23 of the Statutes of Canada, 2021, and it received royal assent on 29 June 2021. The Bank of Canada supervises compliance, maintains a public registry of registered payment service providers, and holds enforcement powers including compliance orders and administrative monetary penalties.

    The Act’s stated purposes explain how its scope is drawn. Its preamble points to mitigating operational risks, safeguarding end-user funds, and building confidence in the retail payment sector. Anti-money laundering sits outside that list, which is why the RPAA and the Proceeds of Crime (Money Laundering) and Terrorist Financing Act capture overlapping but distinct populations of businesses.

    Two defined terms carry most of the weight. A payment service provider is an individual or entity that performs payment functions as a service or business activity that is not incidental to another service or business activity. A retail payment activity is a payment function performed in relation to an electronic funds transfer made in the currency of Canada or another country, or using a unit that meets prescribed criteria. Section 2 defines an electronic funds transfer as a placement, transfer or withdrawal of funds by electronic means initiated by or on behalf of an individual or entity.

    That last definition is where crypto businesses should slow down. The Act leaves “funds” undefined, so the currency limb of the retail payment activity definition sets the perimeter. A payment function performed in relation to anything other than fiat currency counts only if the underlying unit has been prescribed by regulation.

    The Four-Step Test That Decides Whether You Register

    The Bank of Canada has distilled the statutory scope into a four-part test published in its supervisory policy on criteria for registering payment service providers, last updated on 29 June 2026. Registration is required only if all four statements are true, which means a business that fails any single step falls outside the regime.

    Do You Perform One of the Five Payment Functions as a Business?

    Section 2 lists five payment functions, and performing any one can be enough: the provision or maintenance of an account held on behalf of end users in relation to an electronic funds transfer, the holding of funds on behalf of an end user, the initiation of an electronic funds transfer at an end user’s request, the authorization of an electronic funds transfer or the transmission, reception or facilitation of an instruction in relation to one, and the provision of clearing or settlement services.

    Each function is broader than its plain-language name suggests. The Bank treats account provision as engaged whenever a business stores any personal or financial information about an identifiable end user, where one purpose of storing it is to conduct future electronic funds transfers. Holding funds is engaged when a business is indebted to a payer or payee for funds sitting at rest, meaning funds received without a concurrent instruction for immediate transfer. Funds in transit, and immediate transfers delayed by fraud or money laundering screening, fall outside that function, including delays running overnight.

    The word “incidental” then does the filtering. A business performing payment functions only to directly support a non-payment activity likely falls outside the definition of a payment service provider. The Bank assesses this contextually against three indicators: whether the function generates revenue or a direct commercial advantage, what end users reasonably expect when they deal with the business, and whether the business markets the payment features. It has been explicit that it may decide on as few as one indicator where the facts warrant, and that a function once assessed as incidental can stop being incidental when a business model changes.

    Is the Transfer Made in Fiat Currency?

    Step two decides most crypto cases. A business performs retail payment activities only when its payment function relates to an electronic funds transfer made in Canadian currency, a foreign currency, or a unit meeting prescribed criteria. The statutory text has carried that third option since 2021, drafted to let the government extend the regime to digital units later.

    No unit has been prescribed to date. The Department of Finance has confirmed the direction of travel in its published stablecoin framework, which states that the Bank of Canada will supervise payment service providers performing payment functions in a fiat-backed stablecoin subject to that stablecoin being prescribed in regulation. Until that prescription happens, a payment function performed purely in bitcoin, ether or an unprescribed stablecoin does not amount to a retail payment activity.

    Where Are Your Business and Your End Users Located? 

    Sections 4 and 5 of the Act set the geographic perimeter, and they catch foreign platforms as readily as domestic ones. A business is inside the scope if it has a place of business in Canada, which the Bank reads as having a physical location in Canada including a home office, being incorporated federally or provincially, or having employees, agents or mandataries in Canada.

    A business without a place of business in Canada is still caught when it both performs retail payment activities for an end user in Canada and directs those activities at individuals or entities in Canada. The Bank lists concrete indicators, including marketing aimed at people in Canada, a “.ca” domain, a Canadian business directory listing, and a payments-related agreement or working relationship with someone in Canada. It may also weigh pricing in Canadian dollars, support for users in Canada, or a target market with a high proportion of Canadian end users.

    One detail differs from the FINTRAC approach and matters for cross-border platforms. The Bank assesses whether an end user is in Canada by actual physical presence, treating someone as outside Canada while temporarily living, studying, working or vacationing abroad. FINTRAC’s guidance for foreign money services businesses takes the opposite view, so a platform can reach different conclusions under the two regimes on the same customers.

    Does an RPAA Exclusion Apply to You?

    Even a payment service provider operating inside the geographic scope may be excluded. The entity-based exclusions in section 9 cover banks, authorized foreign banks, provincially regulated credit unions and caisses populaires, insurance companies, trust and loan companies, the Canadian Payments Association and the Bank of Canada itself. Regulations add the SWIFT messaging network.

    The activity-based exclusions matter more to crypto businesses. Section 6 excludes payment functions relating to closed-loop merchant instruments, to transfers giving effect to an eligible financial contract as defined in the Canada Deposit Insurance Corporation Act or a prescribed securities transaction, and to cash withdrawals at an automated teller machine. Section 7 excludes functions performed using a system designated under the Payment Clearing and Settlement Act, and section 8 excludes transfers between affiliated entities where no other payment service provider is involved.

    The securities exclusion under paragraph 6(b) is the one crypto trading platforms reach for, and both its limbs must be satisfied. The retail payment activity must give effect to a transaction in relation to a security, and the entity performing it must be regulated or exempted under Canadian securities legislation as defined in National Instrument 14-101. The Bank adds an important qualifier: regulated or exempted status does not exclude all of an entity’s activities, and retail payment activities performed for purposes unrelated to securities transactions can still fall inside the RPAA.

    Four Crypto Business Models, and How the Bank of Canada Reads Them

    Applying that test is easier because the Bank has already done it. In October 2024 it published fictional case scenarios on providers of services backed by cryptocurrencies, still the clearest official statement of where the line sits. The scenarios are designed to be read in sequence, because each adds a fiat element the previous one lacked.

    The First Scenario

    The first scenario involves a platform dealing only in cryptocurrency. Customers complete know-your-customer checks, hold wallets on the platform, and trade one cryptocurrency for another, with each trade recorded in an internal ledger. The Bank concludes that this business performs payment functions, and that none relate to an electronic funds transfer made in fiat or a prescribed unit. It therefore performs no retail payment activity and does not register.

    The Second Scenario

    The second scenario adds fiat rails to the same model. Customers fund accounts by transferring fiat into the platform’s pooled bank account, hold fiat balances alongside crypto, and buy and sell crypto for Canadian or foreign currency, though they cannot transfer fiat to other users. The Bank finds that this platform performs four of the five payment functions, then declines to require registration for two independent reasons. Those functions exist only to facilitate crypto purchases and sales, generate no incremental revenue, and customers understand the business as an exchange, so they are incidental. Separately, the paragraph 6(b) exclusions for prescribed securities transactions and eligible financial contracts apply.

    The Fourth Scenario

    The third scenario triggers registration. A virtual currency exchange offers an open-loop prepaid card, maintains payment accounts for users, and partners with a bank that issues the cards. When a user spends, the exchange receives an authorization request through the card network, checks that the purchase is covered by the fiat value of the customer’s crypto, authorizes it, debits the crypto account, and instructs the partner bank to release funds. The Bank finds two payment functions in scope: the provision and maintenance of an account, and the authorization of an electronic funds transfer.

    The reasoning behind that conclusion is the template for how the Bank thinks about crypto-linked payment products. The card generates its own revenue through interchange fees, the business advertises it, and users expect to make fiat payments with it, so the functions are performed as a distinct business activity. The securities exclusion fails because card transactions cover a broad range of ordinary purchases rather than acquiring rights to crypto in the nature of a securities or derivatives transaction. The Bank adds that the same company’s other exchange activities may still be excluded under paragraph 6(b), which shows that scope is assessed activity by activity rather than company by company.

    The Fourth Scenario

    A fourth scenario covers a cash-only currency exchange, which performs no payment function and falls outside the Act entirely.

    Business model Payment functions performed Fiat EFT involved Bank of Canada conclusion
    Crypto-only exchange with hosted wallets Yes, several No Outside the RPAA, because no retail payment activity occurs
    Centralised exchange with fiat balances and fiat funding Provision of an account, holding funds, initiation, authorization Yes Outside the RPAA, on incidental grounds and under the paragraph 6(b) securities exclusion
    Exchange offering an open-loop crypto-backed prepaid card Provision of an account, authorization of an EFT Yes Registration required, assuming the other criteria are met
    Cash-only fiat currency exchange None No Outside the RPAA

    Two patterns run through that table. Fiat is necessary to bring a crypto business into scope but insufficient on its own, as the second scenario shows. What converts a fiat touchpoint into a registration obligation is the payment function becoming a product in its own right, measured by revenue, marketing and user expectation.

    When Does a Crypto Business Fall Under Canada's RPAA?
    Different types of crypto business models. Source: Bank of Canada

    RPAA Registration Is Separate From FINTRAC Registration

    Because the case scenarios turn on fiat handling, crypto businesses often assume the RPAA is a payments-flavoured extension of the anti-money laundering rules they already follow. The two regimes are built on different tests and pursue different objectives, and a business needs to run both assessments independently.

    The PCMLTFA captures money services businesses through an enumerated list of services that includes dealing in virtual currency, remitting or transmitting funds, foreign exchange dealing and operating crowdfunding platforms. Because dealing in virtual currency is itself a listed service, a crypto-only exchange with no fiat rails can sit squarely inside the FINTRAC regime while falling entirely outside the RPAA. The RPAA takes the opposite approach, ignoring the asset class and asking only whether a defined payment function attaches to a fiat electronic funds transfer.

    The regimes do connect at the registration gate, and the connection runs in one direction. The Bank of Canada can refuse or revoke an RPAA registration based on information provided by FINTRAC, and a notice of violation issued under the PCMLTFA for a serious or very serious violation is relevant to that decision. An anti-money laundering problem can therefore cost a crypto business its payments registration, while the reverse linkage does not operate the same way.

    A related gap catches foreign platforms by surprise. Providers subject to the RPAA must register with the Bank of Canada whether or not they are incorporated in Canada and whether or not they hold a foreign money services business registration with FINTRAC. A platform that concluded it had no Canadian obligations under the anti-money laundering rules cannot carry that conclusion across.

    What Registration Costs and What It Obliges

    For a crypto business inside the perimeter, registration begins an ongoing supervisory relationship. Applications go through the Bank’s PSP Connect portal and carry a one-time fee that the Retail Payment Activities Regulations set at $2,500 for the year the provision came into force, indexed for inflation thereafter. Registered providers also pay annual assessment fees combining a fixed base amount with a variable amount allocated by each provider’s share of retail payment activity.

    Timing is a live constraint rather than a formality. Businesses that missed the 1 to 15 November 2024 transition window must apply at least 60 days before they start performing retail payment activities, and those applying on or after 8 September 2025 must receive a registration decision first. Every application also goes to the Minister of Finance, who has a prescribed 60-day period to decide whether a national security review is necessary, with a further 180-day period for a formal review the Minister may extend.

    The substantive obligations landed on 8 September 2025. Registered providers have to maintain a risk management and incident response framework, safeguard end-user funds they hold, report incidents that materially affect end users, and file an annual report covering those frameworks, their insurance or guarantees, and their end-user fund holdings. Providers also give advance notice of significant changes to how they perform retail payment activities and keep compliance records for five years.

    Enforcement Stopped Being Theoretical In 2026

    Those obligations acquired teeth this year, and the pattern of early enforcement bears directly on the scoping question. The Bank of Canada issued its first order under the RPAA on 17 February 2026, directing XTM Inc. and its affiliated entities to immediately cease performing retail payment activities. The Bank acted under section 94(4), citing serious concerns that the Toronto-based company had failed to safeguard client funds connected to its AnyDay platform, later branded Everyday, and that allowing it to continue could be prejudicial to the public interest. The order also barred XTM from holding itself out as a payment service provider and required a compliance plan within seven days. An amended temporary order followed on 27 February 2026.

    XTM is a tip management business rather than a crypto company, and that is precisely why the case travelled. It showed that safeguarding rules reach any business holding end-user funds, however it describes itself, and that the Bank will halt operations rather than negotiate quietly.

    The Second Signal

    The second signal concerns scope rather than safeguarding. On 12 June 2026 the Bank announced that it would begin publishing notices of violation on its website, describing each violation and any penalty, and recording it against the provider’s entry in the public registry. Published decisions remain accessible for five years.

    According to analysis by Bennett Jones published on 26 August 2026, every enforcement decision published as of 25 August 2026 concerned the same contravention: a breach of section 23, which requires registration before performing any retail payment activities. The firm reports a total penalty of zero dollars in each case, the Bank having noted that the providers took steps to comply and mitigated harm by submitting registration applications. In one matter, Equals Money PLC asked for the notice to be replaced with a warning letter, and the Bank’s delegate concluded that subsection 78(2) did not authorise that remedy.

    The lesson sits in the composition of that first enforcement wave. Section 23 is classified as a very serious violation carrying a potential penalty of up to $10 million, with serious violations carrying up to $1 million, and subsection 76(4) states that the purpose of a penalty is to promote compliance with the Act. The businesses caught so far escaped fines, but they were named, and their violations sit on the public registry for five years. Every one of those cases began with a scoping judgment that turned out to be wrong.

    What Changes When the Stablecoin Amendments Come Into Force

    While businesses have been assessing themselves against the current four-step test, Parliament has already rewritten part of it. Bill C-15, the Budget Implementation Act, 2025, No. 1, received royal assent on 26 March 2026 as chapter 3 of the Statutes of Canada, 2026. It created the Stablecoin Act, expanded the Bank of Canada’s mandate to supervise fiat-backed stablecoin issuers, and made two consequential amendments to the RPAA that reach further into crypto business models than anything in the current Act.

    Section 604 of that statute adds a sixth payment function to section 2 of the RPAA, covering the transmission or maintenance of an end user’s encrypted or tokenized payment instrument, or an end user’s private key, whether or not the private key is encrypted or tokenized. Section 605 adds a category of prescribed individuals and entities that must be notified of incidents relating to a unit meeting prescribed criteria.

    Enforcement Expected in 2027

    Neither provision is in force. Both sit on the Justice Laws website under amendments not in force, coming into force on a day fixed by order of the Governor in Council. Implementing regulations for the stablecoin framework are expected over roughly twelve to eighteen months from assent, with commentators anticipating the framework operating from 2027.

    The drafting deserves attention from anyone running custody infrastructure. Maintaining an end user’s private key describes custodial wallet provision, and it is written as a payment function in its own right rather than as an activity that must attach to a fiat electronic funds transfer. Read alongside the Department of Finance framework, which ties the Bank’s supervision of stablecoin payment functions to the underlying stablecoin being prescribed in regulation, the direction is clear: Canada intends to bring digital-asset custody inside mainstream payment registration rather than build a separate crypto licensing track.

    When Does a Crypto Business Fall Under Canada's RPAA?
    Timeline of Canada’s retail payments perimeter.

    A Practical Scoping Checklist

    Bringing the analysis back to a working process, a crypto business can reach a defensible position by documenting three things and revisiting them whenever the product changes.

    • Inventory the fiat touchpoints and map them to the five payment functions. Cover every point at which Canadian or foreign currency enters, rests in, or leaves the business, including partner bank accounts, pooled client accounts, card programs and settlement flows.
    • Test the incidental question honestly. Ask whether the payment feature earns revenue or a commercial advantage, whether it appears in marketing, and whether users would call the business a payments provider. Interchange revenue on a card program answers all three at once.
    • Record the reasoning and diarise the sixth payment function. The Bank expects providers to reassess as models evolve, and a contemporaneous analysis beats a reconstruction assembled after a notice of violation arrives.

    Frequently Asked Questions (FAQ)

    Does a crypto-only exchange need to register under the RPAA? +

    No. A platform that lets customers trade one cryptocurrency for another, holds only crypto balances, and never processes fiat performs no retail payment activity. The RPAA reaches payment functions tied to electronic funds transfers made in fiat currency or a prescribed unit, and no unit has been prescribed as of August 2026.

    Does holding customer fiat balances automatically trigger RPAA registration? +

    No, though it makes registration more likely. The Bank's second crypto case scenario involves a platform holding fiat balances that still falls outside the Act, because its payment functions exist only to support crypto trading and the paragraph 6(b) securities exclusion applies. The analysis turns on whether those functions are a distinct business activity.

    Do crypto-backed prepaid cards require RPAA registration? +

    Generally yes. The Bank's third case scenario concludes that an exchange offering an open-loop prepaid card performs the account provision and authorization functions as a distinct business, because the card earns interchange revenue, is advertised, and lets users pay merchants in fiat. The securities exclusion does not cover ordinary retail purchases.

    Is RPAA registration the same as FINTRAC MSB registration? +

    No. The regimes run separate tests for different purposes. Dealing in virtual currency is itself a money services business activity under the PCMLTFA, while the RPAA ignores the asset class and asks whether a payment function attaches to a fiat electronic funds transfer. Many crypto businesses need both, and some need only one.

    Does the RPAA apply to a crypto business based outside Canada? +

    It can. A business with no place of business in Canada falls inside the Act when it both performs retail payment activities for end users in Canada and directs those activities at people in Canada. Indicators include Canadian-targeted marketing, a ".ca" domain, a Canadian directory listing, and payments agreements with Canadian counterparties.

    What happens if a crypto business registers late? +

    Performing retail payment activities without registration breaches section 23, a very serious violation carrying penalties of up to $10 million. Every notice of violation published as of 25 August 2026 concerned that breach, each carrying a zero-dollar penalty where the business had applied to register, though the violations stay publicly visible for five years.

    When will stablecoin payment services come under the RPAA? +

    The amendments are law but await commencement. Bill C-15 received royal assent on 26 March 2026 and adds a sixth payment function covering private keys and tokenized payment instruments, to come into force on a date fixed by order in council. Supporting regulations are expected within twelve to eighteen months of assent, with the framework anticipated from 2027.

    Regulation
    Canada’s Crypto Travel Rule: Required Data and Transfer Decisions
    The required travel rule data for a virtual currency transfer is the name, address, and account number or other reference number (if any) of the person or entity who requested the transfer, plus the name, address, and account number or other reference number (if any) of the beneficiary. The commonly cited CAD 1,000 threshold appears […]...
    2 days ago
    Crypto LicenseRegulation
    The Canada MSB Registry of Convenience
    Xeltox Enterprises, trading as Cryptomus, was a registered money services business throughout the conduct that drew a $176,960,190 FINTRAC penalty in October 2025, roughly seven times the more than $25 million FINTRAC issued across all 23 Notices of Violation in 2024-25. The penalty is under appeal in Federal Court. The public registry runs four statuses, […]...
    3 days ago
    Crypto LicenseRegulation
    RPAA Acquisition of Control: The Target Files, the Buyer Waits
    The registered PSP being acquired files the section 24 application, and it must be re-registered before the transaction closes, which puts the closing condition in the hands of the party the buyer is negotiating against. The Bank’s 45-day window is a period to decide whether to refuse a completed application, and the Minister of Finance […]...
    3 days ago