Retail Payment Activities Act (RPAA) Resources

Practical guidance on cybersecurity, operational risk management, incident response, and regulatory compliance for payment service providers supervised by the Bank of Canada under Canada's Retail Payment Activities Act (RPAA).

The Retail Payment Activities Act establishes operational risk management and safeguarding expectations for payment service providers operating in Canada. Organizations that perform retail payment activities may be required to register with the Bank of Canada and demonstrate controls related to cybersecurity, operational resilience, incident response, and third-party risk management.

The resources below explain key RPAA compliance topics including operational risk frameworks, cybersecurity expectations, vendor oversight, incident response planning, and independent security reviews for payment platforms.

RPAA Compliance Topics