Fintech Licensing & AML Compliance in Canada

Book a Meeting

Call us: +1 778 762 1715

Email us: [email protected]

In: Canada MSB Fintech Compliance
FINTRAC vs RPAA Registration: When a Payment Business May Need Both

FINTRAC registration and RPAA registration are not alternative names for the same approval. They address different regulatory risks and can apply to the same payment model.

Updated: July 2026Reading time: ~8 min
The short answer: FINTRAC administers federal anti-money laundering and anti-terrorist financing obligations. The Bank of Canada supervises payment service providers under the Retail Payment Activities Act. A business must test each framework separately.
Complium Canada
Regulatory strategy, registration and AML compliance in one project

Complium assesses the business model first, then coordinates the Canadian structure, FINTRAC or RPAA work and the compliance framework required for launch.

  • Regulatory-scope assessment
  • Registration preparation and regulatory support
  • Business-model-specific AML policies and controls

Request a Regulatory Assessment →

Section 01

Two Frameworks, Two Regulatory Purposes

Framework Primary focus Typical result
FINTRAC / PCMLTFA Money laundering and terrorist financing controls, records and regulatory reporting MSB or Foreign MSB registration where the applicable test is met
Bank of Canada / RPAA Operational risk, safeguarding end-user funds and incident-related obligations for in-scope payment service providers RPAA registration and ongoing supervisory requirements where the applicable test is met

Registering with one authority does not remove the need to consider the other. The same business may transmit funds for FINTRAC purposes while also performing retail payment functions under the RPAA.

Section 02

The Five RPAA Payment Functions

The RPAA analysis concerns retail payment activities related to electronic funds transfers. The statutory functions include:

  • providing or maintaining an account held on behalf of an end user;
  • holding funds on behalf of an end user until they are withdrawn or transferred;
  • initiating an electronic funds transfer at an end user’s request;
  • authorizing an electronic funds transfer, or transmitting, receiving or facilitating an instruction in relation to one; and
  • providing clearing or settlement services.

A product may perform more than one function. The analysis must also consider geographical scope and available exclusions. It is therefore risky to decide based only on whether the company calls itself a payment service provider.

Section 03

When Both Registrations May Apply

A cross-border wallet, remittance platform, merchant payment product or embedded-payment provider may have overlapping obligations. For example, transmitting customer funds can be relevant to FINTRAC, while maintaining payment accounts, initiating transfers or holding end-user funds can be relevant under the RPAA.

Common misconception: RPAA registration is not an upgrade to MSB registration and MSB registration is not a substitute for RPAA registration. The business model should be mapped against both tests.

Additional requirements may also sit outside these two federal frameworks, including provincial money-services rules, securities requirements, privacy obligations and laws in other markets.

Section 04

How to Assess the Payment Model

A useful scope review follows the actual lifecycle of a transaction:

  1. Customer: who uses the service and where are they located?
  2. Instruction: who receives, transmits or authorizes the payment instruction?
  3. Funds: does the business possess, control or safeguard end-user funds?
  4. Settlement: who clears or settles the transaction?
  5. Contract: which entity provides each function and under which terms?
  6. Market: where is the business established and where are services directed?

This functional map determines whether the company needs FINTRAC registration, RPAA registration, both, or a different regulatory route.

Section 05

Examples of Potential Overlap

Digital wallet

A wallet provider may maintain an account for an end user, hold funds and initiate or facilitate transfers. Those functions can be relevant to the RPAA. If the provider also remits or transmits funds as a business, the FINTRAC MSB analysis must be completed separately.

Merchant payment platform

A platform may transmit payment instructions between merchants, customers, processors and financial institutions without holding funds itself. The absence of custody does not end the RPAA analysis because authorization, transmission and facilitation of instructions are separate functions.

Cross-border remittance product

A remittance provider may clearly perform a prescribed money service for FINTRAC purposes. Depending on how it receives instructions, maintains accounts, holds funds and completes transfers, it may also perform one or more RPAA payment functions.

Embedded payment service

A fintech may provide the regulated payment layer inside another company’s customer journey. The contractual chain matters: the parties should identify which entity performs each payment function, which entity controls the customer relationship and where the end users are located.

Section 06

Documents That Support a Reliable Scope Assessment

A clear regulatory conclusion normally requires more than a product presentation. Useful materials include:

  • a group and ownership chart;
  • customer terms and partner agreements;
  • a step-by-step funds-flow diagram;
  • descriptions of wallets, accounts and balances;
  • the role of banks, processors, card schemes and settlement partners;
  • customer and merchant locations;
  • who receives and transmits payment instructions;
  • how end-user funds are held or safeguarded; and
  • forecast transaction volumes and launch markets.

The same factual record can then support the FINTRAC description, RPAA assessment, AML risk work and counterparty onboarding.

Section 07

Common Mistakes When Planning the Two Workstreams

  • Assuming registration with FINTRAC settles the RPAA question. The frameworks have different tests and objectives.
  • Reviewing only whether funds are held. RPAA includes other payment functions, including initiating transfers and transmitting instructions.
  • Using inconsistent funds-flow descriptions. Regulators, banks and partners should not receive conflicting explanations.
  • Leaving operational controls until after filing. Governance, safeguarding, incident response and AML processes need owners, systems and evidence.
  • Ignoring other jurisdictions. Canadian registration does not authorize services in every market where customers are located.
Section 08

How Complium Coordinates FINTRAC and RPAA

Complium maps the payment model once and uses that analysis across both regulatory workstreams. We then prepare a coordinated project plan covering corporate structure, application information, governance, AML compliance and operating procedures.

This helps founders avoid duplicate discovery exercises and makes the final regulatory narrative more consistent. Where a specialist conclusion is required for a related area, such as securities, tax or another jurisdiction, it can be identified before the company commits to launch assumptions.

Section 09

Frequently Asked Questions

Does every Canadian MSB need RPAA registration?

No. RPAA scope depends on whether the business performs in-scope retail payment functions and meets the other statutory tests. Some MSBs will not perform those functions.

Does RPAA registration replace an AML program?

No. FINTRAC obligations remain separate. An entity subject to the PCMLTFA must maintain the required AML compliance framework regardless of its RPAA position.

Can a foreign payment business fall within the RPAA?

Potentially. The geographical-scope rules should be assessed for foreign payment service providers that direct and perform retail payment activities for end users in Canada.

Should the two applications be prepared together?

Where both apply, coordinated preparation can reduce contradictions across the business description, funds-flow mapping, governance and operational documentation.

What happens if the payment model changes after registration?

New products, custody arrangements, payment partners or markets can change the regulatory analysis. The business should reassess scope and update its registrations, governance and controls where required.

Can Complium prepare both workstreams as one project?

Yes. Complium can use one verified business-model and funds-flow assessment to coordinate the FINTRAC, RPAA and connected compliance workstreams while keeping each authority’s requirements distinct.

Important: This guide is a high-level overview. The correct route depends on the facts of the business, including where it is established, the services it performs, its customers and how funds move.
Need one clear answer across FINTRAC and RPAA?

Complium maps the complete payment flow, confirms the registrations that may apply and coordinates the compliance work required for launch.

Assess Your Payment Model →