RPAA Acquisition of Control: The Target Files, the Buyer Waits
- The registered PSP being acquired files the section 24 application, and it must be re-registered before the transaction closes, which puts the closing condition in the hands of the party the buyer is negotiating against.
- The Bank’s 45-day window is a period to decide whether to refuse a completed application, and the Minister of Finance sits behind it with 60 days to decide whether to open a national security review, extendable by further 60-day periods, and 180 days to run one, extendable again. No step in that chain has a statutory outer limit.
- Control lands at one-third of the votes that may be cast to elect directors, one-third of profits or dissolution assets for non-corporations, and the mere addition of a new general partner in a limited partnership. For a state-owned enterprise there is no floor at all.
- A FINTRAC problem is no longer only an indemnity item, because RPAA registration and re-registration decisions can turn on FINTRAC status and recent PCMLTFA enforcement history, and any CEO, president, director or 20% shareholder with a disqualifying conviction, foreign convictions included, makes the entity ineligible to register as an MSB at all.
- The Bank ordered XTM Inc. to cease all retail payment activities on 17 February 2026 after finding it had failed to safeguard end-user funds and caused a significant shortfall to accrue, which is an off switch rather than a fine, and the revision ten days later only let the business restart under a CCAA monitor.
Canada has built the only major change-of-control regime in payments where the company being sold files the application to approve its own sale. Under section 24 of the Retail Payment Activities Act, a registered payment service provider that knows it is about to be acquired must submit a fresh registration application taking the acquisition into account, and it must be re-registered under that application before the deal closes. The Bank of Canada states the allocation plainly in its supervisory policy, confirming that the PSP being acquired must submit the new application and that re-registration has to happen before closing. The acquirer hands over its ownership chain, its controllers and its post-closing organizational chart, pays for the privilege, and then owns no file it can prosecute.
Every comparable regime a cross-border deal team has seen runs the other way. The FCA requires the proposed controller to notify and obtain approval before acquiring or increasing control, gives itself up to 60 working days once the notification is complete, and makes it a criminal offense under section 191F of FSMA to close without that approval, so at least the party carrying the risk is the party holding the pen. FinCEN goes further in the other direction by making the MSB re-register after a transfer of more than 10% of voting power or equity, with Form 107 due within 180 days of the change, which is a housekeeping filing rather than a gate. Canada took the American allocation and the British consequence and combined them, so the applicant is the seller and the penalty for getting it wrong is that the transaction cannot complete.
That distinction stops being academic the first time a seller’s compliance function drags on an information request while the buyer watches its financing commitment age. And the buyer cannot fix it by filing itself, because the acquirer does not register merely by virtue of owning a PSP, and the target’s registration does not extend to the buyer’s other entities.
Nobody in this process owes you a closing date
The three clocks in the section 24 sequence look like a schedule and behave like an open-ended option. The Bank gives itself up to 45 days to determine whether to refuse an application it considers complete, which is a refusal window rather than a service standard, and completeness is the Bank’s call. Behind that sits the Minister of Finance, with up to 60 days from receipt to decide whether to conduct a national security review and the ability to extend that decision period by one or more further 60-day periods, and, if a review is opened, up to 180 days to complete it with further 180-day extensions available. Stack the extensions and there is no arithmetic that produces an outside date, which is the single most important thing to understand before signing anything with a fixed long-stop.
The Bank has also closed the obvious escape route, telling PSPs in the same policy that they “should not expect timelines for review to be expedited because they have not applied sufficiently in advance.” Read alongside the guidance’s instruction to apply as soon as the transaction has sufficient certainty, that puts the filing decision uncomfortably early in the deal, often before the parties are ready to name a structure publicly and well before they want the target’s compliance function pulling together a post-closing ownership chart.
A disclosure question sits in that sequencing which nobody has answered cleanly, because the Bank publishes a public list of applicants showing legal name, main trade name, head office country and date of application, and nothing in the acquisition guidance says a section 24 application is withheld from it. A buyer planning a confidential process should ask that question before filing rather than after, because the downside is a registered target’s name reappearing on a public applicant list while the deal is still under NDA.
The queue your section 24 filing joins
Registration is not a mature pipeline yet, which changes how a buyer should read the target’s own status. McCarthy Tétrault, reading the Bank’s published lists in March 2026, counted roughly 900 applicants still awaiting a decision as of 24 March 2026, some sixteen months after the November 2024 registration window opened, and 32 businesses on the refused or revoked list as of the day before. A section 24 application goes into the same operational pipe as those, and the buyer inherits whatever position the target occupies in it.
Sixteen of the 32 had stopped performing retail payment activities or were found not to be in scope at all, eight were refused because their business was primarily crypto or digital assets with payment activity that was incidental to it, and two were wholly owned subsidiaries of Canadian banks excluded under section 9(a). That is a perimeter problem showing up as an enforcement statistic, and it cuts both ways in diligence, because a target that believes it is registered may be sitting on an application that fails the incidentality test, while a target that assumed it was outside the Act may have been reading the exclusion for a business model it no longer runs.
The statutory perimeter is five payment functions performed as a service or business activity that is not incidental to another one, covering the provision or maintenance of an account held for an end user in relation to an electronic funds transfer, the holding of funds pending withdrawal or transfer, initiation of a transfer at the end user’s request, authorization of a transfer or the transmission, reception or facilitation of an instruction relating to one, and the provision of clearing or settlement services. A sixth function covering encrypted or tokenized payment instruments and the maintenance of an end user’s private key has been enacted and sits on Justice Laws as an amendment not in force, so a crypto-adjacent target is outside the current test and inside the one Parliament has already written, which belongs in the integration plan rather than the perimeter memo.
One-third of the votes, a new general partner, or no floor at all
The control thresholds in the Retail Payment Activities Regulations are lower and stranger than the ones a deal team carries around from other regimes. For a corporation, control lands at securities carrying one-third or more of the votes that may be cast to elect directors, which catches a large minority position that no one would describe as an acquisition. For other entities the test is an ownership interest entitling the holder to one-third or more of profits or of assets on dissolution. For a limited partnership, the addition of a new general partner is an acquisition of control on its own, so a fund restructuring that swaps the GP triggers a re-registration for a portfolio company nobody was buying or selling. Indirect acquisitions count, so gaining control of an entity that controls the PSP is the same event.
And for a state-owned enterprise, section 22 of the Regulations removes the floor entirely, sweeping in the acquisition of voting rights, ownership interests or the ability to appoint senior management with no minimum stake attached. A sovereign fund taking a small strategic position in a Canadian payments business is therefore in the same filing posture as a control buyer, which is worth knowing at term sheet rather than at signing.
Between 20% and one-third sits the trap. An investor at 25% clears the RPAA corporate control threshold without touching it, while FINTRAC’s ownership rules bite well below that, and the bite is unusually hard. An entity is ineligible to register as an MSB if its chief executive officer, president, a director, or any person owning or controlling 20% or more of its shares has been convicted of a listed offense, and the list runs from money laundering and terrorist financing through drug trafficking, human trafficking, extortion and Income Tax Act evasion, with substantially similar convictions under foreign law counting the same. That bar attaches to the post-closing ownership chart, so it sits on the buyer’s own principals as much as on the target’s, which makes it one of the few diligence items an acquirer has to run against itself.
Two registrations, two perimeters, and one that can revoke the other
Nothing about holding a FINTRAC MSB registration tells you whether an entity is a payment service provider, and the reverse holds too. FINTRAC supervises anti-money-laundering and terrorist-financing obligations under the PCMLTFA, charges no registration fee, and says openly that registration is neither a license nor an endorsement. The Bank supervises operational risk, incident response, safeguarding of end-user funds and reporting, charges a non-refundable C$2,500 application fee, and is equally clear that it maintains a registry and does not issue licenses. A cash-heavy foreign exchange dealer can be an MSB and perform no retail payment function. A payment initiation or orchestration platform can be a PSP and never touch a covered MSB service. Plenty of targets are both, and the two perimeter memos have to be written separately or the deal team ends up assuming a status the target does not hold.
The connection between them runs one way and it runs into closing certainty. RPAA registration and revocation decisions can take account of whether the PSP is properly registered with FINTRAC and whether it carries serious recent PCMLTFA enforcement history, which converts a historic AML file from a damages question into a question about whether the Bank will re-register the target at all. A buyer that files the section 24 application and leaves the AML review to a post-closing remediation covenant has sequenced the deal backwards, because the material AML findings need to be known, quantified and, where possible, closed before the target’s application goes in.
Québec makes it three perimeters rather than two. Revenu Québec licenses money-services businesses separately, and its published tariff for the year beginning 1 April 2026 charges C$826 for each service class covering currency exchange, funds transfer, check cashing and traveler’s checks, C$272 per automated teller machine, C$577 per cryptoasset ATM and C$163 per security clearance report. Those fees are trivial against a transaction, while the security clearance process behind them runs on individuals and on its own calendar, which is the part that lands on a closing checklist.
XTM shows what a safeguarding shortfall costs when the Bank stops asking
Safeguarding obligations under section 20 give a PSP holding end-user funds a short menu, being a trust account used for no other purpose, another prescribed account with prescribed safeguards, or an account used for no other purpose backed by insurance or a guarantee at least equal to the funds held. Read as a policy requirement it looks like a documentation exercise. Read as a diligence item it is a reconciliation of customer ledger liabilities against safeguarded cash on selected historical dates, and any gap is debt-like leakage that should come off the price rather than sit in a representation.
On 17 February 2026 the Bank used that machinery in public for the first time, when it ordered XTM Inc. to immediately cease performing any retail payment activities, including everything running through the AnyDay platform, on a finding that XTM “failed to safeguard end-user funds in its possession, and caused a significant shortfall in end-user funds to accrue.” The instrument was a temporary order under subsection 94(4), which lets the Bank act without first completing the ordinary representations process where delay could prejudice the public interest, and the order also required XTM to stop holding itself out as a registered PSP, file a compliance plan within seven days including arrangements to transition end users to another registered PSP, preserve its records, and make representations within fourteen days on why its registration should not be revoked. Ten days later the Bank issued a revised order permitting XTM to recommence under the supervision of a monitor appointed that day by the Ontario Superior Court of Justice under the Companies’ Creditors Arrangement Act.
Reading that as a penalty misses the shape of it. A fine is a number a buyer can indemnify against, while an order to cease retail payment activities is the business stopping, and a seven-day deadline to plan the migration of an end-user base to a competitor is the enterprise value leaving with them. Any target holding meaningful end-user balances should be underwritten on the assumption that the Bank will use this power again, which makes twelve months of average and peak safeguarded balances, daily reconciliation logs, reconciliation breaks, trust account terms and the exclusions and renewal dates on any insurance or guarantee a financial diligence request rather than a compliance one.
The penalty record moved while everyone was still reading the statute
The AML side has been enforcing for longer and the numbers now sit in a different weight class. FINTRAC’s C$176,960,190 penalty against Xeltox Enterprises Ltd., operating as Cryptomus and formerly Certa Payments, was imposed on 16 October 2025 across six violation types, and the detail that should frighten a buyer is the examination period, because the two violations carrying the volume, 1,068 unreported suspicious transactions and 1,518 unreported reports of virtual currency receipts of C$10,000 or more, both sit inside a single month of activity running 1 to 31 July 2024. Underlying conduct included laundering tied to trafficking in child sexual abuse material, ransomware payments and sanctions evasion, and Xeltox has appealed to the Federal Court.
The foreign-entity cases dismantle the domicile defense. Peken Global Limited, operating as KuCoin, a Seychelles company, drew C$19,552,000 on a notice issued 28 July 2025 for failing to register as a foreign money services business, for 2,952 unreported receipts of C$10,000 or more in virtual currency between 1 June 2021 and 8 May 2024, and for 33 unreported suspicious transactions. Binance Holdings Limited took C$6,002,000 in May 2024 on the same registration failure plus 5,902 unreported large virtual currency transactions. Both appealed. Neither had a Canadian establishment, and neither got anything for it.
Domestic MSBs are being worked over on the same theory at smaller amounts, with C$693,742.50 against 13010431 Canada Inc. operating as Necosmart on 27 March 2026 for reporting, compliance program, enhanced measures, risk assessment and record failures, and C$536,853.35 against MP Technology Services Ltd., operating as MoonPay, on 20 November 2025 as a foreign money services business. The cheapest case in the file is the one most likely to hit an acquirer, since TreasureMeta Corporation paid C$24,750 for a single serious violation consisting of not updating its FINTRAC registration within 30 days after a legal name change and an office address change. Both of those are ordinary post-closing housekeeping, and both are exactly what gets deprioritized in the first month after a deal signs.
The ceiling moved too. Bill C-12, which received royal assent on 26 March 2026, raised the PCMLTFA penalty maximums to C$40,000 for a minor violation, C$4 million for a serious one and C$20 million for a very serious one, and moved compliance program requirements into the very serious category. Set against the RPAA’s own maximums of C$1 million and C$10 million, the AML regime is now the more expensive of the two on paper, and the aggregation arithmetic in Xeltox shows how little the per-violation ceiling constrains the total.
Integration is a filing, and the target’s registration does not travel
Two provisions turn the post-closing plan into a regulated event. Section 87 makes a PSP liable for a violation committed by its employees, third-party service providers, agents or mandataries acting in the course of their employment, contract or authority, whether or not the person who committed it is identified, so outsourcing transaction monitoring, hosting or reconciliation moves the work and leaves the consequence exactly where it was. And a PSP must give the Bank notice at least five business days before a significant change or new retail payment activity comes into effect, with the threshold being a change that could reasonably be expected to have a material impact on operational risks or on the way end-user funds are safeguarded, expressly including substantive changes to trust account terms, to insurance or guarantee agreements, to third-party arrangements, and to technology, cloud providers included.
Which describes almost every integration plan written by an acquirer with a platform of its own. Migrating the core ledger, changing the safeguarding bank, consolidating onto the buyer’s cloud tenancy and retiring the target’s KYC vendor are four separate notice events, and the five business days run before implementation rather than after, so the compliance function has to be on the integration committee from the start rather than receiving the migration calendar as a fait accompli.
The registration itself does not spread. An acquirer that will not perform retail payment activities in its own name generally does not register merely because it owns a PSP, but any buyer entity or new affiliate that will perform a covered payment function needs its own registration, which inverts the usual risk calculus on an asset purchase. Buying assets can produce a cleaner allocation of historic liability and no acquisition of control at all, and it still leaves the acquiring entity unable to commence covered Canadian retail payment activities until the Bank registers it, which is the full application at the back of the queue rather than a re-registration. Share-versus-asset should therefore be decided against licensing continuity alongside historic liability, rather than on liability alone.
Drafting for a condition precedent with no outer limit
The condition precedent has to be written against completed re-registration and nothing softer. A CP satisfied by the target having “submitted” a section 24 application, or by the Bank acknowledging completeness, gives the buyer no protection at all, since the requirement is that the PSP be re-registered before the acquisition closes. What the buyer needs is written confirmation of re-registration reflecting the contemplated transaction, in a form that permits continued operation after closing.
Long-stop drafting should distinguish the ordinary case from the national security case, because they are different animals with different arithmetic. A base outside date that assumes a complete file, a domestic buyer and a simple chart is defensible at somewhere between three and six months, and it needs an automatic extension that triggers if the Minister formally opens a review, subject to a negotiated ultimate termination date, since a 180-day review with 180-day extensions available cannot be accommodated inside a normal outside date. Anything with a state-owned investor, a sensitive jurisdiction or a fund chain running through several layers should be modeled on the extension case rather than the base one.
Around that sit the covenants that keep the application accurate while it is pending. The seller should be restricted from launching a new payment product, changing the safeguarding bank, switching a material processor or altering the payment architecture without consent, because each of those can require its own notice to the Bank and can force an amendment to a filed application, resetting completeness and the 45-day window with it. The regulatory cooperation covenant needs to allocate who runs the dialogue with the Bank while preserving the buyer’s right to see anything material to closing, given that the applicant is the party across the table. And the transitional services arrangement has to keep the target’s monitoring, sanctions screening, safeguarding reconciliation and reporting systems running until the buyer’s own controls have been tested in parallel, because a migration that breaks reporting produces exactly the reporting-population failures that Xeltox and KuCoin were penalized for.
The C$2,500 application fee is the least interesting number in the file. What a buyer is really paying for is an unbounded regulatory timetable it cannot drive, a safeguarding position that can be a cash call rather than a covenant breach, an AML history that can decide whether the target gets re-registered at all, and an integration plan in which four routine technology decisions are notifiable events. Price the perimeter analysis at term sheet, finish the safeguarding reconciliation and the AML testing before signing, and treat section 24 as the closing gate it is rather than the registration formality it is named after.
Frequently Asked Questions (FAQ)
Who files the RPAA application when a payment service provider is acquired? +
The registered PSP being acquired files it. Section 24 requires the PSP to submit a new registration application taking the proposed acquisition into account, and the Bank of Canada's supervisory policy confirms that the PSP being acquired is the applicant. The acquirer supplies ownership, controller and post-closing structure information for that filing.
Can a deal close while the section 24 application is pending? +
No. The PSP must be re-registered under the new application before the acquisition closes. A purchase agreement whose condition precedent is satisfied by submission of the application, or by the Bank treating the file as complete, does not protect the buyer.
How long does RPAA re-registration take? +
There is no statutory outside date. The Bank has up to 45 days to determine whether to refuse a completed application, the Minister of Finance has up to 60 days to decide whether to open a national security review and can extend that by further 60-day periods, and an opened review runs up to 180 days with further 180-day extensions available. The Bank has said it will not expedite a review because an applicant filed close to its target closing date.
What counts as an acquisition of control under the RPAA? +
For a corporation, securities carrying one-third or more of the votes that may be cast to elect directors. For other entities, an ownership interest entitling the holder to one-third or more of profits or of assets on dissolution. For a limited partnership, the addition of a new general partner. Indirect acquisitions through a controlling entity count. For a state-owned enterprise there is no minimum threshold at all.
Does a minority investment below one-third avoid the filing? +
It can avoid the ordinary RPAA acquisition-of-control filing while still triggering obligations elsewhere. FINTRAC ineligibility attaches to any person owning or controlling 20% or more of an MSB's shares who has been convicted of a listed offense, foreign equivalents included, and a state-owned investor is caught by the RPAA at any size.
Does a FINTRAC problem affect RPAA registration? +
Yes. RPAA registration and revocation decisions can take account of whether the PSP is properly registered with FINTRAC and whether it has serious recent PCMLTFA enforcement history, which turns a historic AML file into a closing-certainty question rather than only an indemnity question.
What happens if a PSP fails to safeguard end-user funds? +
The Bank can issue a temporary order under subsection 94(4) without completing the ordinary representations process. It did so on 17 February 2026 against XTM Inc., requiring it to cease all retail payment activities immediately, stop holding itself out as registered, file a compliance plan within seven days including transition of end users to another registered PSP, and make representations within fourteen days on revocation.
Does the buyer need its own RPAA registration? +
Not merely by owning the PSP. But any buyer entity or affiliate that will itself perform a covered payment function needs its own registration, which is why an asset purchase can be operationally harder than a share purchase despite a cleaner historic-liability allocation.
What post-closing filings does an acquisition trigger? +
Confirmation to the Bank that the acquisition closed, within five business days. Notice at least five business days before any significant change or new retail payment activity, including changes to safeguarding arrangements, third-party providers and technology. And FINTRAC registration updates, which carry their own 30-day deadline and have already produced a penalty.
