Operating a payment service or acquiring business in Canada without a clear grasp of the regulatory requirements is one of the fastest ways to lose banking. A crypto company that processes fiat payments, settles merchant transactions or routes card payments into a digital-asset platform sits squarely in the sights of the Retail Payment Activities Act regime administered by the Bank of Canada, the federal Proceeds of Crime (Money Laundering) and Terrorist Financing Act supervised by FINTRAC (the Financial Transactions and Reports Analysis Centre of Canada), and potentially provincial securities regulators. The legal question is not academic. It determines whether your PSP (payment service provider) agreement is enforceable, whether your fiat rails survive due-diligence scrutiny, and whether your acquiring bank stays on-side.
Canada sits at an interesting intersection. It is a G7 market with a sophisticated financial sector, an active crypto-asset industry, and a regulatory perimeter that has tightened materially over the past several years. For an inbound business – whether a European EMI (electronic money institution), an offshore crypto exchange seeking fiat rails, or a merchant acquiring platform with Canadian clients – the compliance stack is multi-layered and the consequences of a gap are immediate and operational, not merely theoretical.
The Canadian regulatory perimeter for PSPs and acquiring businesses
Canada's payment-services regime is built on three interlocking pillars: the Bank of Canada's registration regime for retail payment activities, FINTRAC's AML/CFT supervision, and, for businesses touching crypto-assets, the provincial securities regulatory framework administered by bodies such as the OSC (Ontario Securities Commission) and the CSA (Canadian Securities Administrators) collectively. Any business that executes payment functions for end users in Canada – including the end-to-end settlement of transactions involving digital assets – must map itself against all three.
The Retail Payment Activities Act (RPAA) introduced a registration obligation for payment service providers that perform certain defined retail payment activities for Canadian clients. Covered functions include initiating electronic fund transfers, holding funds on behalf of end users, and enabling payment transactions. Crucially, the regime has extraterritorial reach: a foreign PSP performing covered activities for Canadian end users is required to register with the Bank of Canada, even if its legal entity is domiciled outside Canada. This single point has caught a number of inbound operators off guard.
In parallel, FINTRAC registration is mandatory for any business classified as a money services business (MSB) or foreign MSB. Virtual currency exchange and transfer services are explicitly covered. An entity onboarding Canadian clients, converting fiat to crypto, or routing payments on their behalf must maintain a FINTRAC registration and comply with the full suite of AML/CFT obligations – transaction reporting, large cash transaction reports, suspicious transaction reports, know-your-client procedures and, increasingly, Travel Rule compliance for virtual-asset transfers.
Who needs a PSP agreement in Canada – and why the acquiring relationship matters
A PSP agreement in Canada is a commercial contract between a payment processor and a merchant or platform, but it sits within a regulated context that determines whether the contract is valid and whether the underlying payment flows are permissible. Any business receiving card payments, processing bank transfers or settling e-commerce transactions on behalf of Canadian merchants must either hold the right regulatory status itself or operate through a licensed acquiring bank or payment processor that does.
For digital-asset businesses, the acquiring relationship is the critical choke point. Acquiring banks and payment processors conduct their own due diligence on prospective clients. A crypto exchange or token issuer seeking a Canadian merchant account must demonstrate – to the acquiring institution's satisfaction – that it has the correct FINTRAC registration, that its AML/KYC program meets the Bank of Canada's and FINTRAC's expectations, and that its business model does not expose the acquirer to regulatory censure. Gaps in any of these will trigger refusal or, more commonly, mid-contract account closure.
We regularly advise clients at precisely this juncture. The operational effect of an acquiring bank's decision to exit a relationship is felt within days: payment acceptance stops, settlements freeze, and revenue halts. Loss of a payment rail at the wrong moment is an existential risk, not a manageable inconvenience.
Note for inbound operators: Canada's provincial securities regulators have been active in requiring crypto trading platforms to register as dealers or as restricted dealers. The CSA and OSC have issued a series of guidance documents and undertaken enforcement action against unregistered platforms serving Canadian clients. A business structure designed to avoid this layer – by routing transactions through an offshore entity and claiming no Canadian nexus – is increasingly difficult to sustain when Canadian users are actively solicited or served.
For a scoped assessment of your Canadian market-entry structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options
What does FINTRAC registration require, and how does an AML program need to be built?
FINTRAC registration is the baseline entry point for any business performing virtual currency or money services functions in Canada, and it is non-negotiable for any entity seeking a functional PSP or acquiring relationship. Registration alone is not sufficient: the FINTRAC regime requires a documented, tested and board-approved AML/CFT compliance program.
The core elements of a FINTRAC-compliant program are well-established. They include a designated compliance officer with clear authority, written policies and procedures calibrated to the business's specific risk profile, a risk assessment that identifies the business's exposure by product, channel, geography and client type, ongoing employee training, and an effectiveness review conducted at defined intervals. For a digital-asset business, the program must also address virtual-currency specific risks: peer-to-peer transaction exposure, mixing and tumbling risks, and the Travel Rule obligation that requires originator and beneficiary information to travel with virtual-asset transfers above the applicable threshold.
In our cross-border practice, we see two recurring failures. The first is a program built for the entity's home jurisdiction that is simply translated into English and submitted to FINTRAC. It will not pass scrutiny because the risk categories and reporting obligations differ. The second is a technically compliant program on paper that has never been operationalized: the staff are not trained, the transaction monitoring is not calibrated, and the reports are never filed. FINTRAC's examination process tests operational reality, not document architecture.
How does the RPAA registration process work for a foreign PSP?
The Bank of Canada's RPAA registration regime applies to any PSP – domestic or foreign – that performs covered retail payment activities for Canadian end users. The registration process involves submitting prescribed information about the applicant entity, its payment functions, its governance structure, its risk management framework, and its safeguarding arrangements for funds held on behalf of end users.
The safeguarding obligation under the RPAA is a materially important requirement. A PSP holding end-user funds must maintain those funds in a designated account held at a Canadian financial institution or a federally regulated trust company, or must hold an equivalent insurance or guarantee arrangement. For a foreign PSP that holds or transmits funds for Canadian users, this introduces a Canadian banking relationship as a structural necessity – not merely a convenience.
In practical terms, a foreign PSP seeking RPAA registration will typically need to demonstrate: a legal entity capable of contracting in Canada or a Canadian subsidiary; a designated complaints-handling and dispute-resolution mechanism; a safeguarding-compliant account structure; and a documented operational risk and incident-response framework. Timelines for registration vary depending on the completeness of the application and the Bank of Canada's assessment queue, and there is no registry figure we can state here with precision. Operators should plan for a process measured in months rather than weeks, with the substantive documentation preparation being the longest-lead element.
In a recent onboarding matter, a European payments company sought to expand its acquiring business into Canada. It held an EMI licence in an EU member state and assumed that passporting equivalence would simplify the Canadian process. No such equivalence exists: Canada operates its own distinct registration regime with domestic safeguarding and reporting obligations. We structured a Canadian subsidiary, mapped the fund-flow architecture against the RPAA safeguarding requirements, built the FINTRAC compliance program from the entity's specific risk profile, and coordinated the Bank of Canada registration filing. The matter concluded in a timeline the client considered acceptable, and the acquiring relationship with the Canadian partner was onboarded on the basis of the completed compliance stack.
How does the cross-border structure interact with tax and banking?
For any inbound business establishing a Canadian PSP or acquiring presence, the legal question does not end with regulatory registration. The tax and banking layers interact directly with the compliance structure and, if not addressed in sequence, will produce misalignments that each workstream then has to fix at cost.
On the banking side, Canadian chartered banks and most credit unions apply robust AML/CFT screening to corporate account applicants in the payments and crypto-asset sector. An entity that has completed its FINTRAC registration and has a documented compliance program is materially better positioned in that screening process than one that cannot demonstrate either. Banks frequently request copies of the FINTRAC registration, the compliance program summary, and the organizational chart showing beneficial ownership. A structure that obscures the ultimate beneficial owner – even unintentionally, through a multi-layer offshore holding arrangement – will not clear the bank's internal threshold.
On the tax side, a Canadian subsidiary established to hold the RPAA registration and the Canadian acquiring relationship will be a Canadian-resident corporation for income-tax purposes. Intercompany payment flows between the Canadian entity and an offshore parent – management fees, licensing fees, interest – must be structured on arm's-length terms and documented with a transfer-pricing rationale. Canada's transfer-pricing regime imposes penalties on inadequately documented related-party transactions. This is not a back-office issue. The fee arrangement between the Canadian operating entity and the offshore holding structure should be designed before the subsidiary is incorporated, not after the first audit notice arrives.
We structure licensing, banking and tax as one mandate rather than three disconnected workstreams. The reason is straightforward: a tax-driven holding structure that looks clean on paper can destroy the banking relationship if it obscures the compliance ownership chain. Conversely, a compliance structure built without tax advice can generate significant permanent-establishment exposure in a jurisdiction where the operator did not intend to be taxable.
What are the most common mistakes inbound operators make?
The first and most consequential mistake is assuming that a FINTRAC registration is all that is needed. It is necessary but not sufficient. An operator that registers with FINTRAC, builds a minimal compliance program, and then begins onboarding Canadian users without addressing the RPAA safeguarding obligations or the provincial securities registration question is exposed on two additional fronts simultaneously.
The second mistake is treating the PSP agreement as a purely commercial negotiation. In fact, the terms of a PSP agreement in Canada must be consistent with the operator's regulatory status. A payment processor that agrees to process transactions for a counterparty that lacks the correct registration may itself face scrutiny. Operators we advise are routinely surprised to find that the acquiring bank's due-diligence questionnaire is, in effect, an informal regulatory examination.
A common assumption among inbound businesses is that an offshore entity with a well-regarded licence – whether an EU CASP authorisation under MiCA, a VARA licence in Dubai, or a Singapore MAS DPT licence – provides sufficient credibility to obtain a Canadian banking or acquiring relationship without further local compliance work. That assumption is incorrect. Each of those regimes is credible in its own jurisdiction and may assist in demonstrating the operator's general compliance posture. None of them substitutes for FINTRAC registration, RPAA compliance, or the provincial securities analysis that Canadian regulators will apply.
The third mistake is underestimating the provincial layer. Canada has ten provinces, and securities regulation is provincial in character. A platform that trades crypto-assets classified as securities must engage with the relevant provincial regulator – and the CSA's guidance on crypto-asset trading platforms has made clear that the platform's physical location is not determinative of jurisdiction. Serving Canadian clients is the trigger.
If your prior application stalled or an account was closed, a fresh structural review can surface the underlying cause and identify the route back. Message us via t.me/oboluslaw or write to info@oboluslaw.com. Map your options
Decision matrix: which operator profile needs what in Canada
Different business profiles face different stacks of requirements. The analysis below is by profile, not by preference.
Profile A – Foreign EMI entering Canada to offer fiat payment accounts to crypto companies. This operator requires RPAA registration (triggered by holding end-user funds and initiating payment transactions), FINTRAC registration as a foreign MSB, a documented AML/CFT program calibrated to a high-risk client base, and a Canadian safeguarding account. The cross-border note: the EMI's home-jurisdiction license demonstrates regulatory standing but provides no passporting. Timeline for full operational readiness is typically a matter of several months. Key risk: safeguarding account procurement, which depends on finding a Canadian financial institution willing to hold the account given the client profile.
Profile B – Crypto exchange seeking a merchant-acquiring relationship to accept card payments from Canadian users. This operator requires FINTRAC registration (as a virtual currency exchange business), a compliance program meeting FINTRAC's expectations, likely a provincial securities registration or exemption analysis, and a commercial PSP/acquiring agreement with an institution whose risk appetite covers the crypto sector. Timeline is driven by the acquiring bank's diligence cycle, which compounds with the regulatory registration timeline. Key risk: no acquiring bank will onboard without a completed FINTRAC file and a clean compliance program in hand.
Profile C – Cross-border payment platform routing transactions for businesses with Canadian merchant clients. This operator must determine whether it is performing covered retail payment activities for Canadian end users (RPAA trigger) or merely settling between businesses outside the retail perimeter. That determination is fact-specific and turns on the structure of the payment flow. If the RPAA applies, registration and safeguarding are mandatory. FINTRAC registration turns on whether the platform transfers funds or exchanges virtual currency. Key risk: misclassifying the payment function and operating without registration.
Related practices
Related at OBOLUS
- Banking, Payments and EMI Onboarding – legal structuring for fiat rails, EMI relationships and payment-account access for digital-asset businesses
- De-risking and account closure defence in Estonia – strategies for responding to and preventing EMI and bank account termination in the EU
- Tax treatment of tokens in Bermuda – structuring analysis for token-holding and issuance in an offshore context
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of AML/CFT risk appetite constraints and insufficient compliance documentation from the account holder. In Canada, a chartered bank that cannot satisfy itself that a crypto client has a functioning FINTRAC-registered compliance program, clear beneficial ownership, and a business model it understands will exit the relationship. De-risking of entire sectors – rather than individual risk assessments – remains common, particularly where the client has not proactively provided compliance documentation at onboarding.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) seeking to onboard with an EMI must present a complete compliance file: AML/CFT program documentation, evidence of registration with the relevant national supervisor (FINTRAC in Canada), a beneficial ownership structure that traces to natural persons, and, increasingly, Travel Rule compliance capability. EMIs operating in Canada or serving Canadian-facing VASPs will apply their own due-diligence standards. VASPs that approach an EMI before completing their regulatory registrations routinely face rejection or prolonged delay.
What does client-money safeguarding require?
Under Canada's RPAA regime, a PSP holding end-user funds must segregate those funds from its own operating capital and maintain them in a qualifying account at a Canadian financial institution or federally regulated trust company, or hold an equivalent insurance arrangement. The obligation applies to funds held on behalf of Canadian end users. For a foreign PSP, this means establishing a Canadian banking relationship specifically to hold the safeguarding account – a requirement that adds both a legal-structuring and a banking-onboarding step to the market-entry process.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP registration, AML program structuring and PSP onboarding for cross-border digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.