Global fintech and funding innovation ecosystem

Category Archives: Research

Canada Stablecoin Regulations Guide

July 2, 2026 | NCFA Resource | Digital Assets Blockchain And Tokenization, Regulation And Policy, Payments And Market Infrastructure

Canada stablecoin regulations guide covering issuer oversight, reserves, redemption, AML and market readiness

Canada Stablecoin Rules, Oversight And Market Readiness

NCFA has published a comprehensive guide to stablecoin regulations in Canada. It brings together the Stablecoin Act, Bank of Canada supervision and the related requirements administered by FINTRAC, Canadian securities regulators, OSFI and FCAC.

The guide explains how Canada’s framework may affect stablecoin issuance, reserve management, redemption at par, governance, data security, trading platform access, payment activity, custody and consumer protection.

Canada has enacted the Stablecoin Act, but its substantive requirements are not yet in force. Supporting regulations, registration mechanics and Bank of Canada implementation materials remain under development.

What The Guide Covers

The resource organizes Canada’s stablecoin requirements as a connected regulatory framework.

A single stablecoin business model may involve several legal and supervisory layers. Depending on its activities, a firm may need to assess issuer registration, money services business obligations, payment service provider requirements, securities rules, custody controls and prudential treatment.

The guide covers:

  • The Stablecoin Act and its expected regulatory perimeter
  • Bank of Canada registration and issuer supervision
  • Reserve backing and liquidity requirements
  • Redemption at par and user protection
  • FINTRAC registration, AML controls and the Travel Rule
  • RPAA considerations for stablecoin payment activity
  • CSA treatment of value referenced crypto assets
  • OSFI prudential treatment for regulated financial institutions
  • Consumer disclosure and understanding

Who Gets Value

This resource is designed for stablecoin issuers, fintech founders, crypto platforms, custodians, payment companies, banks, compliance teams, investors, policymakers and market infrastructure providers.

It is particularly useful for teams assessing:

  • Stablecoin issuance and market entry
  • Reserve structure and treasury controls
  • Redemption models and user disclosures
  • AML registration and wallet monitoring
  • Payment use cases and RPAA exposure
  • Trading platform and custody requirements
  • Governance, reporting and operational readiness

Strengths And Limits

The guide’s principal strength is its integrated view of Canada’s regulatory structure. Readers can identify which authorities are involved, what Parliament has enacted and which implementation questions remain unresolved.

It also connects regulation with market development. Clear rules for reserves, redemption, custody and compliance could support tokenized financial infrastructure, stablecoin payments and institutional settlement services.

Firms can use the guide to begin preparing legal perimeter assessments, issuer control maps, reserve policies, governance models, data security plans, redemption procedures, AML files and Bank of Canada engagement materials.

Canada’s stablecoin regime is still under development. The guide provides regulatory intelligence and planning support, but it is not legal, financial, investment, compliance or professional advice. NCFA will update the Regulatory Intelligence page as regulations, supervisory materials and implementation dates are confirmed.

Key Resources

Stablecoin Regulations In Canada (primary NCFA Regulatory Intelligence guide)

Deloitte And Stablecorp Bring QCAD To Banks (Canadian stablecoin infrastructure)

Tokenization Starts Looking Like Financial Infrastructure (tokenized market infrastructure)

Finance Canada Stablecoin Framework (primary government source)


National Crowdfunding and Fintech Association of Canada

The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking, funding opportunities and services to thousands of community members. NCFA works with industry, government, partners and affiliates to support a vibrant and innovative fintech and funding industry in Canada.

Decentralized and distributed, NCFA engages with global stakeholders and supports projects and investment across fintech, alternative finance, crowdfunding, peer to peer finance, payments, digital assets, tokens, artificial intelligence, blockchain, cryptocurrency, regtech and insurtech.

Join Canada’s Fintech & Funding Community free, or become a contributing member to receive additional benefits. Visit NCFA Canada for more information.

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Stablecoin Regulations In Canada

NCFA Regulatory Intelligence - Canada's Stablecoin Regulatory Framework
NCFA Canada | Regulatory Intelligence | Rules | Stablecoins | Last updated July 2, 2026 | Status framework enacted, regulations pending
NCFA Regulatory Intelligence | Rules
This guide organizes Canada’s stablecoin framework into a practical reference for fintechs, issuers, platforms, investors and policy teams, with global comparison handled separately from the rule-layer explorer.
Stablecoin Regulation In Canada Stablecoin Act, Bank of Canada oversight, reserves, redemption and compliance

Stablecoin Regulations In Canada

Stablecoins are regulated in Canada through federal and provincial laws, regulatory guidance and supervisory requirements. Canada has enacted the Stablecoin Act, but its substantive requirements are not yet in force while supporting regulations and implementation arrangements are completed.

This guide explains Canada’s stablecoin regulatory framework, who may be covered, which authorities are involved and how the rules affect issuance, reserves, redemption, trading, custody, payments and market access.

Coverage includes the Stablecoin Act, Bank of Canada registration and supervision, reserve requirements, redemption at par, governance, data security, FINTRAC obligations, RPAA overlap, CSA value referenced crypto asset treatment, OSFI prudential rules and consumer protection.

Stablecoin Regulation In Canada At A Glance

Are stablecoins regulated in Canada?

Yes. Existing payments, AML, securities, prudential and consumer protection requirements can apply, while the enacted Stablecoin Act establishes a new federal regime whose substantive requirements are not yet in force.

Who will supervise covered issuers?

The Bank of Canada will register and supervise covered issuers under the federal framework.

What are the principal issuer requirements?

The framework addresses reserves, redemption at par, governance, risk management, data security, reporting and recovery planning.

Can foreign issuers be covered?

Foreign issuers may be covered when they make applicable stablecoins available to people in Canada.

Are all stablecoins treated the same way?

No. Treatment depends on the stablecoin, issuer, activity and distribution model, including whether securities, derivatives, payments, AML or prudential rules apply.

When Will Canada’s Stablecoin Rules Take Effect?

Canada has progressed from interim securities treatment and policy discussion to an enacted federal stablecoin mandate. The next phase depends on regulations, Bank of Canada registration design and how federal, provincial and securities requirements work together in practice.

Policy and interim controls
Legislation and rule buildout
Implementation and supervision
2023 to 2024CSA InterimVRCA terms for crypto trading platforms
2025Budget 2025federal stablecoin framework proposed
26 Mar 2026Royal AssentBill C-15 enacts Stablecoin Act
31 Mar 2026Finance Frameworkscope and policy objectives published
2026 to 2027Draft RegulationsCanada Gazette consultation expected
2026 to 2027Registry DesignBank of Canada issuer supervision buildout
2027 targetFramework Liveissuer registration and obligations
After launchMarket Usepayments, trading and settlement adoption

Who Regulates Stablecoins In Canada?

Navigate the main authorities, obligations and implementation layers that make up Canada’s stablecoin framework. This reference supports the regulation-to-market pathway below by giving readers a deeper view of each regulatory component.

Framework
Regulatory Layers

Are Stablecoins Regulated In Canada?

Requirements

Canada’s stablecoin framework applies to fiat-backed stablecoins and focuses on non-financial institutions that create stablecoins and make them available to persons in Canada. The policy framework centres on reserves, par redemption, data security, governance and Bank of Canada supervision.

  • Finance Canada defines fiat-backed stablecoins as stablecoins pegged to one fiat currency of reference
  • The Stablecoin Act creates the legal mandate for regulating issuers
  • The Bank of Canada will register and supervise stablecoin issuers
  • FINTRAC will require stablecoin issuers to register as MSBs dealing in virtual currency
  • Existing CSA terms remain relevant for value-referenced crypto assets traded on crypto platforms
  • OSFI’s cryptoasset exposure rules matter for federally regulated financial institutions holding or exposed to cryptoassets
Implementation

Firms should treat the framework as a stack. Issuer obligations, AML registration, trading platform access, custody controls, payment activity and prudential exposure can all apply to the same business model.

NCFA Perspective

Canada’s framework is finally becoming clearer, but it still needs practical alignment. The opportunity is a regulated Canadian stablecoin market that can support payments, tokenized settlement and responsible platform access without leaving key obligations split across agencies.

What Does The Stablecoin Act Require?

Requirements

The Stablecoin Act was enacted through Bill C-15. It applies to persons that create a stablecoin and make it available for purchase, directly or indirectly, by persons in Canada. Detailed operational requirements will depend on regulations and Bank of Canada implementation materials.

  • The Act establishes Canada’s federal stablecoin framework
  • The focus is stablecoin issuance by non-financial institutions
  • The framework covers reserve backing, redemption, governance and risk management
  • Issuers should expect registration, reporting, governance, operational and compliance obligations once regulations are in force
Implementation

Issuers should prepare a legal perimeter memo, issuer control map, reserve policy, governance model, data security plan, redemption model, AML registration plan and Bank of Canada engagement file before regulations arrive.

Regulatory Considerations

The Act answers the threshold policy question. It doesn’t yet answer all operating questions. The next source of detail will be regulations, Bank of Canada standards and any coordination with securities, payments and AML authorities.

NCFA Perspective

The Stablecoin Act gives Canada a federal anchor. The next challenge is execution. If the rules are too slow or fragmented, Canadian firms may continue building around foreign stablecoin infrastructure.

Bank of Canada Oversight

Requirements

The Bank of Canada’s stablecoin supervision will focus on issuers being fully backed by high-quality liquid assets, redeemable at par and issued in a way that protects users and the financial system. The Bank says it will register issuers, supervise compliance, monitor issuance and redemption risks and take enforcement action where obligations aren’t met.

  • Maintain a public stablecoin issuer registry
  • Supervise issuer compliance
  • Monitor issuance and redemption risks
  • Use enforcement powers where obligations aren’t met
  • Apply oversight experience from payment systems and retail payments
Implementation

Issuers should prepare for Bank of Canada supervision with board-approved policies, reserve reporting, redemption data, incident logs, operational risk controls, third-party oversight and evidence that user funds are protected.

NCFA Perspective

The Bank of Canada becomes the central supervisor for stablecoin issuer trust. That puts reserves, redemption and operational continuity at the centre of market access.

Reserves and Backing

Requirements

The framework is built around full backing by high-quality liquid assets. The Bank of Canada has also stated that stablecoins should be pegged one to one to a central bank currency and backed by assets that allow conversion to cash at par.

  • Reserve assets should support stable value and redemption at par
  • High-quality liquid assets are central to the framework
  • Reserve composition, segregation, custody and disclosure will be major rule areas
  • Issuers should expect reporting and monitoring requirements tied to reserve quality and liquidity
Implementation

Issuers should build reserve governance, daily reserve monitoring, liquidity stress scenarios, custody agreements, reconciliation workflows, independent attestations and disclosure processes. Treasury operations will become a regulated control function.

NCFA Perspective

Reserve design is the trust layer. Canada’s market won’t develop around slogans about digital money. It’ll develop around confidence that a token can be redeemed at par under stress.

Redemption and User Protection

Requirements

Canada’s framework identifies redemption at par as a core feature. Conditions for redemption, timing, fees and user access will be important implementation details. FCAC evidence also shows consumer understanding is still a live policy issue.

  • Stablecoins should be redeemable at par
  • Redemption terms need clear disclosure
  • Consumer protection depends on users understanding that stablecoins are not the same as insured deposits
  • Issuer arrangements must address operational access, dispute handling and failure scenarios
Implementation

Issuers should document redemption workflows, service standards, fee policies, client disclosures, complaint handling, outage procedures, wallet-provider responsibilities and user communications. Redemption operations should be tested under high-volume and stress conditions.

NCFA Perspective

Redemption is where consumer trust becomes operational. If users can’t understand and access redemption rights, the product won’t meet the policy promise.

FINTRAC and AML

Requirements

FINTRAC states stablecoin issuers will be required to register as money services businesses dealing in virtual currency. Coming into force depends on regulations to be developed and published in Canada Gazette, Part II.

  • Stablecoin issuers will be MSBs dealing in virtual currency
  • AML obligations will overlap with issuer supervision
  • Travel Rule and virtual currency reporting requirements remain relevant
  • Wallet screening, sanctions, suspicious transaction reporting and onboarding controls are central implementation areas
Implementation

Issuers and platforms should connect reserve and redemption controls to customer due diligence, wallet monitoring, Travel Rule processes, sanctions screening, suspicious transaction escalation and record keeping.

NCFA Perspective

Stablecoin adoption will depend on financial crime controls that work at payment speed. That creates room for Canadian regtech, blockchain analytics and compliant wallet infrastructure.

Payments and RPAA

Requirements

Bank of Canada commentary and federal budget materials connect stablecoin regulation with Canada’s broader retail payments framework. Stablecoin payments are expected to interact with retail payment oversight, especially where stablecoins are used as a means of payment.

  • Stablecoin payments may trigger RPAA-related obligations depending on business model
  • Payment service providers need to understand whether stablecoin payment activities fall under retail payment supervision
  • Operational risk, safeguarding and end-user fund protection remain core themes in Canadian payments policy
Implementation

Firms should map stablecoin issuance separately from stablecoin payment activity. A wallet, payment processor, platform or merchant service may have different obligations than the issuer itself.

NCFA Perspective

The payment layer is where stablecoins become more than trading infrastructure. Canada’s rules need to support legitimate payment use while avoiding confusion between issuer regulation and payment activity oversight.

CSA and Trading Platforms

Requirements

The CSA’s interim approach applies to value-referenced crypto assets, commonly called stablecoins, on crypto asset trading platforms. The CSA has permitted certain fiat-backed crypto assets to continue trading where platforms and issuers meet terms and conditions.

  • CTPs must assess whether a VRCA and issuer satisfy applicable terms
  • Issuer undertakings and platform conditions are key controls
  • Platforms must disclose risks, including that secondary market value may deviate from par and reserves may not satisfy all redemptions
  • Platforms need policies for halting or suspending purchases or deposits if conditions are no longer met
Implementation

Platforms should maintain VRCA due diligence files, issuer undertaking records, reserve disclosure links, risk disclosures, product monitoring, halt and suspension playbooks and client-facing stablecoin risk language.

NCFA Perspective

The securities layer won’t disappear just because Canada now has a federal stablecoin framework. Trading, distribution and platform access will remain important parts of the Canadian stablecoin operating model.

OSFI and Prudential Treatment

Requirements

OSFI’s cryptoasset exposure guideline sets regulatory capital and liquidity treatment for banks, federal credit unions, bank holding companies, federally regulated trust companies and federally regulated loan companies. Separate insurance guidance applies to insurers. The banking guideline took effect on January 1, 2026.

  • FRFIs must classify and treat cryptoasset exposures for capital and liquidity purposes
  • The guideline does not decide whether an institution is permitted to issue or hold a cryptoasset
  • Institutions should notify OSFI regarding cryptoasset exposures where required
  • CBDCs are outside the scope of the guideline
Implementation

Banks and regulated financial institutions should assess direct and indirect stablecoin exposures, custody arrangements, issuer relationships, tokenized asset products, capital treatment, liquidity implications and OSFI notification triggers.

NCFA Perspective

OSFI’s layer matters because stablecoin infrastructure may rely on banks for custody, settlement, treasury and institutional distribution. Prudential treatment can affect how quickly incumbents participate.

Consumer Understanding

Requirements

FCAC research shows stablecoin awareness and understanding are still policy issues. It also noted that stablecoins and cryptoassets were not covered by federal or provincial deposit insurance at the time of the research. Consumer understanding matters because stablecoins may sound safer than they are.

  • Consumers need clear information on how stablecoins differ from cash, bank deposits and insured accounts
  • Disclosures should explain backing, redemption, custody, fees, issuer risk, platform risk and loss scenarios
  • Consumer protection depends on plain language, not only technical compliance
Implementation

Issuers and platforms should test consumer disclosures, avoid deposit-like language unless legally accurate, explain insolvency and redemption risk, and make sure users understand who is responsible for each part of the product.

NCFA Perspective

Consumer trust can’t be built on the word stable. It has to be earned through reserve transparency, redemption rights, clear platform roles and language people can understand.

Which Stablecoin Businesses Are Covered?

  • When will detailed regulations be published in Canada Gazette, Part II?
  • How will Bank of Canada registration work for domestic and foreign issuers?
  • How will the framework treat CAD stablecoins versus USD stablecoins made available in Canada?
  • How will issuer supervision interact with CSA platform conditions for VRCAs?
  • Which activities trigger stablecoin issuer obligations versus RPAA payment service obligations?
  • How will reserve custody, disclosure, attestations and redemption timing be defined?
  • Will Canada’s framework support tokenized settlement and programmable payments at scale?

How Canada Compares With Other Stablecoin Regimes

Canada’s framework is easier to understand beside other mature stablecoin regimes. Select a jurisdiction to compare implementation status, primary authority, regulatory model and strategic relevance for Canada.

Canada is building a federal framework for fiat-backed stablecoin issuance by non-financial institutions, with Bank of Canada supervision and existing payments, AML, securities and prudential layers around it.

The approach is broad, but still incomplete until regulations define registration, reserve, redemption, reporting and implementation mechanics.

Regulatory model

Stablecoin Act framework with Bank of Canada issuer oversight, Finance Canada policy direction and surrounding FINTRAC, CSA, RPAA and OSFI requirements.

Key focus
  • 1:1 reserve backing
  • At-par redemption
  • Governance, disclosure and data security
  • Issuer registration and supervision
Strategic observation

Canada’s value depends on coordination. The rules need to work across issuer obligations, platform access, AML, payments and prudential treatment.

The UK has final FCA rules for non-systemic qualifying stablecoins covering issuance, backing assets, redemption, safeguarding and disclosures. Systemic payment stablecoins sit in the Bank of England perimeter.

This gives Canada a useful comparison for issuer design, backing assets, custody, redemption and how to separate retail-market and systemic payment oversight.

Regulatory model

FCA stablecoin issuance rules inside the wider UK cryptoasset regime, with separate treatment where payment stablecoins become systemic.

Key focus
  • Backing asset pools
  • Redemption and safeguarding
  • Issuer governance
  • Custody, conduct and operational resilience
Strategic observation

The UK separates stablecoin issuance from broader cryptoasset activity while tying stablecoins to custody, disclosure and conduct rules.

MiCA creates a harmonized EU regime for cryptoassets, including asset-referenced tokens and e-money tokens. The stablecoin elements were among the earliest parts of MiCA to apply.

For Canada, the EU is the strongest example of a large market using a passportable stablecoin and cryptoasset framework across multiple member states.

Regulatory model

Single-market cryptoasset regulation with specific stablecoin categories for ARTs and EMTs.

Key focus
  • Authorization and white papers
  • Reserve assets and own funds
  • Redemption rights
  • Significant token supervision
Strategic observation

MiCA gives Europe an integrated market structure advantage. Canada does not have equivalent passporting, so interoperability and provincial coordination matter more.

The U.S. framework centres on payment stablecoin issuers, reserve assets, redemption, federal and state supervision, bank involvement and dollar stablecoin competitiveness.

For Canada, the U.S. comparison matters because most global stablecoin liquidity is U.S. dollar based and Canadian platforms, users and issuers may rely on U.S. dollar stablecoin infrastructure.

Regulatory model

Federal payment stablecoin legislation with implementation rules, AML treatment and state-federal supervisory questions.

Key focus
  • Permitted issuers
  • Reserve quality and 1:1 backing
  • Redemption and disclosures
  • Banking and dollar-market role
Strategic observation

Canada needs practical rules for USD stablecoins made available in Canada, not only Canadian-dollar issuance.

Singapore’s framework focuses on single-currency stablecoins pegged to the Singapore dollar or G10 currencies and issued in Singapore, with strong emphasis on reserve backing, redemption and disclosure.

It is useful for Canada because it shows how a smaller financial centre can set a high-trust stablecoin regime without trying to cover every possible cryptoasset activity at once.

Regulatory model

MAS single-currency stablecoin framework connected to Payment Services Act amendments and digital payment token oversight.

Key focus
  • Reserve asset quality
  • Redemption at par
  • Disclosure
  • Issuer capital and governance
Strategic observation

Singapore’s approach is narrow and trust-centred. Canada can use a similar discipline while accounting for securities and federal-provincial overlays.

Hong Kong has an active licensing regime for fiat-referenced stablecoin issuers, with HKMA supervision and a policy objective tied to virtual asset market development and financial stability.

For Canada, Hong Kong is a useful comparison because it connects stablecoin licensing with a broader digital asset market strategy and clear issuer licensing.

Regulatory model

Dedicated stablecoin issuer licensing under the Stablecoins Ordinance.

Key focus
  • Issuer licensing
  • Reserve asset management
  • Redemption arrangements
  • Governance and risk controls
Strategic observation

Hong Kong is treating stablecoins as part of financial centre strategy. Canada’s framework will need a clearer market-development lane if it wants domestic issuance, not only control of foreign tokens.

Japan permits stablecoin issuance through regulated channels such as banks, trust companies and fund transfer service providers, with stablecoins treated through payment services and electronic payment instrument rules.

The Japanese model anchors stablecoin issuance in regulated financial institutions and payment functions rather than a broad open issuer perimeter.

Regulatory model

Payment Services Act and related rules for electronic payment instruments, with issuance through regulated financial channels.

Key focus
  • Bank, trust company and fund transfer service pathways
  • Redemption and user protection
  • Payment services use
  • Transfer and intermediary rules
Strategic observation

Japan offers a more institution-led comparison. Canada’s non-financial issuer mandate is broader, so its controls need to be clear enough for market trust.

The FSB’s global stablecoin recommendations seek consistent regulation, supervision and oversight of global stablecoin arrangements while allowing jurisdictions to implement domestic approaches.

This is important for Canada because cross-border stablecoin use depends on compatible standards for governance, risk management, redemption, reserve assets, data sharing and regulatory cooperation.

Regulatory model

High-level recommendations rather than domestic law. They set a baseline for authorities designing local frameworks.

Key focus
  • Governance and risk management
  • Financial stability monitoring
  • Redemption and reserve quality
  • Cross-border cooperation
Strategic observation

Canada’s framework should be easy for other authorities to recognize. That matters for cross-border use and domestic credibility.

Strategic Takeaways for Canada

Regulatory operating quality

The main difference between leading jurisdictions is not whether stablecoins, payments, AML, digital assets and consumer protection are regulated. Most serious markets are building rules across those areas. The practical difference is how clearly those rules connect. Jurisdictions with coordinated rulebooks, visible implementation timelines and clear supervisory entry points give firms a better path from compliance planning to market launch.

Market structure

Stablecoin regulation is converging around reserve quality, redemption rights, issuer governance and disclosure. The strategic difference is market design. The EU offers passporting, Hong Kong and Singapore connect licensing to financial-centre strategy, Japan limits issuance to regulated financial channels, and the U.S. focuses on dollar stablecoin scale.

Canada’s coordination challenge

Canada’s stablecoin framework now adds an important federal layer, but firms will still need to connect Bank of Canada supervision, FINTRAC registration, CSA cryptoasset treatment, OSFI prudential rules and payments law in practice. That may improve control, but only if registration, platform access and redemption obligations are easy to follow.

Cross-border use

Canadian users and platforms will likely interact with USD stablecoins regardless of domestic issuance. The framework therefore needs rules for foreign stablecoins made available in Canada, not only rules for Canadian issuers.

Market opportunity

The opportunity is compliant settlement infrastructure. If Canada can make reserves, redemption, custody and AML controls clear, stablecoins can support programmable payments, tokenized settlement and cross-border transaction flows without relying entirely on foreign operating models.

Where Canada Aligns

  • Reserve backing
  • Redemption at par
  • Issuer governance
  • AML and sanctions controls
  • Disclosure and consumer understanding

Where Canada Differs

  • Bank of Canada registration model
  • CSA value-referenced crypto asset overlay
  • FINTRAC MSB obligations
  • RPAA payment activity overlap
  • Federal and provincial coordination burden

Global Direction

Major jurisdictions are converging around high-quality reserves, redemption rights, issuer governance, disclosures and AML controls. They continue to diverge on market access, supervisory structure, passporting, foreign issuer treatment and how directly stablecoin policy connects to national competitiveness.

Canada’s challenge is less about whether stablecoins are regulated and more about how clearly the federal, securities, payments, AML and prudential layers work together for firms trying to launch or participate.

What The Rules Mean For Canadian Firms

NCFA’s regulation-to-market pathway shows how Canada’s stablecoin framework can move from policy and supervision into market capabilities and innovation opportunities. The visual is not a legal hierarchy. It is a market-development map showing how regulatory functions connect to the operating capabilities firms need to build trusted digital money infrastructure.

ParliamentStablecoin Act
Finance CanadaPolicy and regulations
Bank of CanadaIssuer supervision, reserves, redemption
FINTRACMSB registration, AML, Travel Rule
CSA / CIROTrading platforms, VRCAs, custody
OSFI / FCACPrudential exposure, consumer understanding
Stablecoin IssuersGovernance, reserves, redemption, reporting
Wallets and PSPsPayment activity, safeguarding, access
Custodians and BanksCustody, reserves, controls, attestations
Stablecoin PaymentsWallet flows, merchant acceptance, cross-border use
Tokenized SettlementDigital asset workflows, programmable transactions, cash leg
Treasury and Reserve ServicesReserve banking, attestations, liquidity controls
Institutional CustodySafeguarding, operational controls, platform access
Compliance AutomationAML, identity, wallet screening, reporting

Stablecoin Infrastructure And Market Opportunities

These opportunity areas align with the capabilities in the pathway above. Only the published NCFA Opportunity Brief receives a primary call to action; the other nodes show where future research or Innovation Map coverage can expand.

Consumer and Merchant

Stablecoin PaymentsPublished Opportunity Brief
Merchant AcceptancePoint-of-sale and wallet payment rails
Cross-border RemittancesLower-friction money movement
Wallet ServicesConsumer and small business access

Business and Institutional

Tokenized SettlementCash leg for digital asset workflows
Treasury and Reserve ServicesReserve banking, attestations, liquidity controls
Institutional CustodySafeguarding and operational infrastructure
Programmable PaymentsBusiness rules embedded in payment flows

Compliance and Infrastructure

AML AutomationMonitoring, reporting and sanctions controls
Wallet ScreeningRisk scoring and transaction intelligence
Digital Identity and TrustKYC, verification and reusable trust layers
Regulatory ReportingIssuer, PSP and platform reporting tools

Continue Exploring

Use these links to go deeper into the adjacent regulations, market evidence and infrastructure themes connected to Canada’s stablecoin framework.

Guide: PSP Registration with Bank of Canada under RPAARetail payment supervision is a key adjacent layer for stablecoin payment activity and PSP participation.Open RPAA guide
Canada’s Proposed Consumer-Driven Banking RulesRelated Regulatory Intelligence on Canada’s open banking framework, data portability and implementation path.Open related guide
Stablecoin Data Shows Payments Reality GapMarket evidence on stablecoin usage, payment adoption and infrastructure gaps.Read related analysis

NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights

NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

FCA Emerging Technology Horizon Scan 2026 Resource

Jul 2, 2026 | NCFA Resource | Artificial Intelligence And Data, Digital Assets Blockchain And Tokenization, Risk Compliance And Regtech
NCFA Resource – FCA Emerging Technology Horizon Scan 2026 Resource

FCA Emerging Technology Horizon Scan 2026 Resource

On June 10, 2026, the UK Financial Conduct Authority published the FCA Emerging Technology Horizon Scan 2026. The report examines how AI agents, synthetic financial crime and programmable finance could affect consumers, firms, markets and financial infrastructure through 2030.

NCFA's FCA Emerging Technology Horizon Scan guide turns the report into an interactive regulatory foresight resource. It separates the FCA's findings from implementation considerations, NCFA interpretation and Canadian relevance.

What It Covers

The FCA organizes the Horizon Scan around three technology convergence themes:

  • Personalised Intelligence: AI agents, digital twins, consumer delegation and the proxy economy.
  • Synthetic Insecurity: Synthetic identity, deepfakes, autonomous financial crime, market abuse and cyber resilience.
  • Programmable Finance: Tokenization, stablecoins, CBDCs, smart contracts, digital identity, smart data and interoperable infrastructure.

The guide also connects the Horizon Scan with later FCA work, including the Mills Review, the Supercharged Sandbox and the joint frontier AI cyber resilience statement.

What It Does In Practice

The resource helps fintech leaders assess technology combinations rather than treating AI, distributed ledgers, identity, data, payments and cyber risk as separate issues.

Readers can use the interactive explorer to review:

  • What the FCA says
  • Implementation considerations
  • Strategic and market implications
  • NCFA perspective
  • Canadian reference points
  • Questions for firms and policymakers

The FCA Horizon Scan sits before formal regulation. It identifies early indicators that may affect product governance, consumer protection, financial crime controls, market surveillance, operational resilience and infrastructure design.

Who Gets Value

This resource is useful for fintech founders, financial institutions, AI developers, digital asset firms, regtech providers, compliance teams, cybersecurity leaders, investors, policymakers and market infrastructure firms.

It is especially relevant to teams assessing AI agent governance, synthetic identity, deepfake risk, automated financial crime, tokenized finance, programmable payments, stablecoins, digital identity, smart data and operational resilience.

Strengths And Limits

The resource's main strength is its focus on convergence. It shows how AI agents, identity systems, synthetic media, tokenized assets, smart contracts and payment infrastructure may operate together.

It also supports practical planning. Firms can use it to test product assumptions, fraud controls, data strategy, identity plans, tokenized financial infrastructure and board level governance.

The FCA Horizon Scan is not regulatory guidance, a rulebook or a prediction. It does not create requirements or confirm that its scenarios will occur. Readers should use the guide for regulatory intelligence, scenario planning and strategic review, not as legal, financial, investment, compliance or professional advice.

Key Resources

FCA Emerging Technology Horizon Scan (interactive NCFA Regulatory Intelligence guide)

FCA Emerging Technology Horizon Scan 2026 (primary FCA source)

The Mills Review (FCA review of AI and retail financial services through 2030)

Frontier AI And Cyber Resilience (FCA, Bank of England and UK Treasury statement)

AI Agents Enter Governed Financial Workflows (AI governance and controls)

Tokenization Starts Looking Like Financial Infrastructure (programmable finance context)

MIT AI Risk Repository For Fintech Governance (AI risk taxonomy resource)


NCFA CanadaThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer to peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit www.ncfacanada.org.

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

FCA Emerging Technology Horizon Scan 2026

NCFA Regulatory Intelligence - FCA Emerging Technology Horizon Scan 2026
NCFA Canada | Regulatory Intelligence | Strategy | AI, Programmable Finance and Financial Crime | Last updated July 19, 2026
NCFA Regulatory Intelligence | Regulatory Foresight
This regulatory foresight guide translates the FCA Emerging Technology Horizon Scan 2026 into scenario analysis, supervisory context, implementation questions and Canadian relevance. The FCA states that the report is not regulatory guidance or a prediction document.
NCFA Regulatory Intelligence | Regulatory Foresight FCA Emerging Technology Horizon Scan 2026

FCA Emerging Technology Horizon Scan

The FCA Emerging Technology Horizon Scan 2026 sets out three plausible ways emerging technologies could combine across financial services. It focuses on early indicators, potential risks and strategic questions rather than binding rules.

Use this guide to understand how the FCA frames technology convergence across Personalised Intelligence, Synthetic Insecurity and Programmable Finance, how later FCA work develops those themes, and what they may mean for fintech strategy, supervision and financial infrastructure.

Coverage includes AI agents, digital twins, proxy economy risks, synthetic identity, deepfakes, autonomous financial crime, synthetic market abuse, operational resilience, tokenization, stablecoins, CBDCs, digital identity, smart data, Finternet, cross border interoperability and current FCA developments.

Primary SourceFCA Emerging Technology Horizon Scan 2026
Document type: Regulatory strategy and horizon scan, not formal guidance or a rulebook.

Technology Convergence Journey

The Horizon Scan sits before formal regulation. It identifies plausible technology pathways that could affect consumer protection, financial crime prevention, operational resilience, infrastructure modernization and future supervisory focus.

Signals and research
Adoption and risk formation
Supervisory and market response
Global Pressures2024 to 2026
AI, geopolitics, energy and infrastructure constraints
Horizon ScanJune 2026
FCA publishes its first external technology scan
Mills ReviewJuly 2026
FCA publishes seven AI recommendations
Testing And Adoption2026
Firms test agents, identity, tokenization and controls
Supervisory FocusCurrent
Risk, resilience, fraud and consumer outcomes
2030 ScenariosOngoing
Agentic finance, synthetic risk and programmable infrastructure

Strategic Themes at a Glance

The FCA report is organized around three technology convergence themes that cut across AI, fraud, cyber, digital assets, payments and infrastructure modernization.

AI agentsPersonalized tools could become the main interface between consumers and firms
Digital twinsNew data sources could support real time personalization and bespoke financial products
Synthetic financial crimeAI can industrialize deception, identity fraud, cyberattacks and market manipulation
Programmable financeDLT, stablecoins, CBDCs and smart contracts could reshape financial plumbing
Smart dataOpen finance and cross-sector data may support agentic, context-aware services
Digital identityIdentity becomes a core layer for interoperable financial infrastructure
FinternetInterconnected financial ecosystems could allow capital to move like information
Trust systemsFinancial services may need new methods to verify authenticity and evidence

Technology Strategy Explorer

Navigate the FCA Horizon Scan by strategic theme. Each section separates what the FCA says, implementation considerations and NCFA perspective.

Overview Personalised Intelligence Synthetic Insecurity Programmable Finance

Overview

What the FCA says

The FCA says the Horizon Scan is its first external publication of this kind. It is not a prediction report or regulatory guidance. It presents three plausible ways emerging technologies could combine to affect consumers, firms and markets, and it highlights early signals of new risks.

  • The report is built around the FCA's strategic priorities: helping consumers navigate financial lives, fighting financial crime and supporting growth and innovation in the UK
  • The three main themes are Personalised Intelligence, Synthetic Insecurity and Programmable Finance
  • The report frames technology change as convergence, where AI, DLT, digital identity, smart data, stablecoins, CBDCs, smart contracts and cyber capabilities combine rather than develop in isolation
  • The FCA intends the report to support collaboration, informed debate and knowledge-sharing across the financial services ecosystem
Implementation considerations

Firms should treat the report as a strategic risk and opportunity map. It can inform board horizon scanning, innovation planning, product governance, cyber risk, fraud controls, data strategy, digital identity planning, tokenization strategy and operational resilience assessment.

Strategic implications
  • Firms may need stronger ways to verify AI generated evidence, identities and decisions
  • Consumer protection may depend on tools that preserve agency while using AI assistants
  • Fraud and cyber controls may need to account for synthetic media and autonomous attacks
  • Programmable finance may require infrastructure for settlement, compliance, identity and cross border interoperability
NCFA perspective

This is an upstream regulatory strategy signal. It shows where future supervision may focus before formal rules appear. For NCFA, it connects directly to AI, digital identity, fraud, open finance, tokenization, stablecoins, CBDCs, cybersecurity, payments modernization and programmable market infrastructure.

State of the World

What the FCA says

The FCA frames emerging technology against broader global pressures, including AI competition, geopolitical tension, trade disputes, energy demand, critical materials, data centre growth, environmental pressure and divergent regulatory approaches. It notes that AI debate often runs faster than measurable evidence, while practical adoption is already taking root in customer engagement and agentic payments.

  • AI is becoming an economic, geopolitical and societal force
  • AI energy and chip demand may affect climate goals, hardware access and scaling economics
  • AI enabled customer engagement and agentic payment systems are already visible
  • Live deepfakes, synthetic identities and coordinated cyberattacks may undermine trust
  • Different AI regulatory models, including the UK approach and EU AI Act, may create a multiple standard environment
  • CBDCs, digital assets and stablecoins could reshape parts of the international financial architecture
  • Digital public infrastructure such as IndiaStack is gaining momentum in developing markets
Implementation considerations

Boards should connect technology strategy to geopolitical supply chains, energy exposure, cloud concentration, vendor dependency, AI model access, regulatory divergence and cross border interoperability. Technology adoption should be assessed against measurable outcomes rather than hype.

NCFA perspective

The FCA is treating technology strategy as market structure strategy. The signals are not only about tools. They are about who controls interfaces, identity, compute, data, payment rails, settlement and trust verification.

Personalised Intelligence

What the FCA says

Personalised Intelligence examines how AI, personal data, edge computing, digital twins and adaptive interfaces could change consumer outcomes. AI agents could become the main interface between consumers and firms, making financial services more personalized, automated and embedded in daily life.

  • Consumers may delegate daily financial management to AI agents
  • Adaptive interfaces may replace separate financial apps and comparison tools
  • AI agents may turn consumer intent into action and make decisions on behalf of users
  • Wearables, biometric data and behavioural data could support real time digital twins
  • Small language models and edge computing may enable offline, private intelligence on devices
  • Financial markets may become more opaque as products are tailored to each consumer
Implementation considerations

Firms need to decide whether they are designing for human users, AI representatives or both. Product governance, disclosure, consent, suitability, accessibility, fair value and complaints processes may need to reflect agent-mediated consumer journeys.

Market implications
  • Trusted personal finance agents
  • AI interface compliance assessment
  • Consumer consent and delegation dashboards
  • Financial product comparability tools for agent-mediated markets
  • Explainability layers for hyper-personalized financial products
NCFA perspective

The key question is whether AI increases consumer capability or quietly transfers decision power to opaque systems. The opportunity is strong, but consumer agency, privacy, accessibility and accountability become central design requirements.

AI Agents

What the FCA says

The report describes escalating cognitive delegation, progressing from assistive mode to advisory mode and then autonomous action mode. In autonomous action models, proxies may negotiate, transact, optimize bills, reallocate investments or dispute charges within dynamic constraints.

  • Assistive mode explains products, compares options, pre-fills forms and flags risks while humans decide
  • Advisory mode recommends specific actions for consumers to accept
  • Do-it-for-me mode allows proxies to act autonomously within constraints
  • Consumer attention may shift to escalation cases rather than everyday financial management
  • Marketing and product design may target AI proxies rather than humans
Implementation considerations

Firms should assess how products appear to AI agents, how consent is collected, how human review is triggered and how agent decisions can be audited. Customer support should anticipate cases where consumers do not understand actions taken by their AI representatives.

NCFA perspective

AI agents could become the next distribution layer in financial services. The competitive question is not only who has the best app, but whose product is selected, negotiated and trusted by a consumer's agent.

Digital Twins

What the FCA says

The report describes digital twins as AI representations that could draw on financial data, device data, behavioural signals, wearables and broader preferences. Firms could use these tools to offer more personalized products and support by interacting with a consumer's digital twin or AI agent.

  • Digital twins may help consumers simulate choices and negotiate financial products
  • Wearables and biometric data may support real time personalisation
  • Firms may engage with a consumer's AI representative rather than the consumer directly
  • Financial products may become bespoke, dynamic and harder to compare
  • The line between serving a consumer and serving their AI representative may become unclear
Implementation considerations

Digital twin use raises data minimization, consent, explainability, vulnerability, discrimination, product governance and audit questions. Firms need controls to avoid overfitting products to sensitive traits or creating exclusion through complexity.

NCFA perspective

Digital twins may support inclusion and better advice, but they could also create high-risk personalization. The market will need guardrails around what data should be used, who controls the twin and how decisions can be challenged.

Proxy Economy

What the FCA says

The FCA describes a potential proxy economy where AI proxies act for consumers and competition shifts from human attention to algorithmic negotiation. The report warns that consumers may accept proxy permissions casually, similar to how web cookies are often accepted today.

  • AI proxies may filter, rank and act on behalf of consumers
  • Firms may optimize marketing and product design for proxies rather than people
  • Consumers may lose oversight of how decisions are made
  • New dark patterns may target AI recommendation logic
  • Mis-selling may occur through adversarial optimization rather than direct persuasion
Implementation considerations

Consumer protection may need to account for proxy choice architecture, permission design, escalation rules, audit trails and agent conflicts. Firms should review whether their own AI interfaces favour the firm over the consumer.

NCFA perspective

The proxy economy could rewrite financial distribution. It may reduce consumer inertia, but it may also create a new layer of algorithmic gatekeeping. This is a high value area for future NCFA question posts and opportunity analysis.

Synthetic Insecurity And Financial Crime

What the FCA says

Synthetic Insecurity examines how AI expansion of human thought, labour, value chains and digital infrastructure could make simulated data difficult to distinguish from real data. The FCA describes a future where fabricated truth becomes harder to separate from actual truth.

  • AI can create synthetic identities, convincing images and automated applications
  • Frontier models can mimic human reasoning and persuasion
  • Fraud can become personalized, automated and scalable
  • AI systems may generate synthetic evidence trails that look professionally credible
  • Trust and evidential integrity become core financial stability issues
Implementation considerations

Financial crime, fraud, onboarding, audit, dispute resolution and supervisory evidence processes should be assessed against synthetic documents, synthetic identities, narrative laundering, deepfakes and coordinated AI agent activity.

NCFA perspective

This is one of the most important sections for fintech and regulators. If evidence itself can be fabricated at scale, financial services need stronger verification layers, not only better detection of obvious fakes.

Deepfakes and Trust

What the FCA says

The report says deepfake risks are progressing from manipulation of the senses to manipulation of sense-making. AI may generate credible synthetic narratives, evidence trails and interactions that bypass both human and algorithmic judgment.

  • Deepfakes are no longer limited to images, audio or video
  • Cognitive warfare may influence how people decide what is true
  • Attention and cognitive bandwidth become attack surfaces
  • Synthetic evidence can support narrative laundering and conceal misconduct
  • Suspicious perfection may become a signal of criminal activity
Implementation considerations

Firms need layered authentication, source verification, provenance controls, document forensics, voice and video verification, separate channel confirmations and controls for high-risk actions. Regulators may also need tools to assess evidentiary integrity.

NCFA perspective

Trust infrastructure is becoming a market opportunity. Identity, provenance, verification, secure communications and evidence integrity could become core financial infrastructure rather than operational controls.

Autonomous Crime

What the FCA says

The FCA warns that agentic AI could democratize high-complexity crime. A single individual may be able to deploy, manage and scale a global criminal organization through software, with AI agents performing phishing, scams, cyberattacks and manipulation.

  • AI reduces the gap between malicious intent and technical capability
  • Crime-as-a-Service may become more effective through AI agents
  • Autonomous AI routines may probe bank networks for weaknesses
  • AI can personalize deception, build trust and run extended scam interactions
  • Concentration in shared AI platforms could create systemic vulnerability
Implementation considerations

Fraud and cyber teams should model autonomous attackers, not only human fraud rings. Controls need to detect rapid, adaptive, multilingual, personalized and multiple channel attacks that may operate continuously.

NCFA perspective

This section points to an arms race in financial crime operations. The opportunity is not only fraud prevention. It is coordinated intelligence sharing, AI defensive assessment and cross-sector resilience.

Synthetic Market Abuse

What the FCA says

The report describes synthetic market abuse risks where autonomous multiple agent systems may engage in insider trading, collusion, spoofing, pump and dump activity, sentiment manipulation or synthetic consensus cascades.

  • Agents may execute strategies human analysts cannot detect
  • Collusion may emerge from multiple agent interactions
  • Synthetic social proof can manufacture false legitimacy around entities or assets
  • Sentiment manipulation may occur through coordinated AI activity on social platforms
  • Market integrity may depend on detecting emergent behavior rather than only individual intent
Implementation considerations

Market surveillance should expand beyond order book and transaction data to include social sentiment, agentic behavior, synthetic content, coordinated narratives and cross-platform activity. Governance should define accountability when autonomous systems create abusive outcomes.

NCFA perspective

Synthetic market abuse links directly to crypto, tokenized markets and digital investor communities. This is a strong candidate for future Question Intelligence and regulatory comparison work.

Operational Resilience

What the FCA says

The FCA describes adaptive and invisible threats to firms' operational resilience. Frontier AI models may identify zero-day vulnerabilities, while adaptive malware may rewrite itself, imitate normal activity and operate inside systems in real time.

  • AI can accelerate vulnerability discovery for attackers and defenders
  • Attack surfaces are expanding across firms, cloud providers and third parties
  • The time between discovery and exploitation of vulnerabilities may compress
  • Adaptive malware may alter behaviour to avoid detection
  • Financial sector resilience may depend on collaboration between firms, AI providers and governments
Implementation considerations

Firms should assess AI-enabled cyber scenarios, cloud concentration risk, third-party software compromise, adaptive malware, rapid vulnerability response, model provider dependency and coordinated sector response. Resilience planning should assume faster attack cycles.

NCFA perspective

Operational resilience and AI risk are converging. The firms best positioned for the next phase will combine cybersecurity, vendor governance, model risk, incident response and trusted information sharing.

Programmable Finance

What the FCA says

Programmable Finance examines the convergence of DLT and financial concepts. The FCA says financial infrastructure is becoming more modular, with shared ledgers, tokenisation, programmable money and smart contracts contributing to protocol-based financial systems.

  • Traditional finance and DeFi are converging into TradFi with protocol capabilities
  • Rules that once lived in documents and procedures can be expressed and audited in software
  • Programmable money, assets and transactions could automate workflows and reduce reconciliation
  • UK strategy links digital identity, smart data, settlement and payment infrastructure, programmable money and cross border interoperability
  • Infrastructure modernization connects to the National Payments Vision, future retail payments infrastructure and RTGS renewal
Implementation considerations

Firms should map how programmable finance affects products, settlement, custody, compliance, legal documentation, data sharing, identity, payment triggers and risk controls. The question is how to design programmable systems that are interoperable, auditable and commercially usable.

NCFA perspective

This is the strongest bridge to NCFA's existing tokenization, stablecoin, payments and open finance work. The FCA is describing a transition from digitized services to programmable financial infrastructure.

Tokenization

What the FCA says

The report situates tokenisation within programmable finance and protocol-based infrastructure. Tokenized assets are part of the transition toward financial instruments that can settle, execute and interact through software rather than manual reconciliation.

  • DLT and smart contracts support digital representation of value and rights
  • Tokenized assets may become part of shared ledger or interoperable financial systems
  • Protocol capabilities may be absorbed into established financial infrastructure
  • Tokenization interacts with identity, custody, settlement, programmable money and compliance
  • Economic value may depend on bridges across money, markets and jurisdictions
Implementation considerations

Tokenization projects should identify the real workflow being improved, the settlement asset, custody model, legal rights, data permissions, interoperability approach, compliance logic and operational fallback process.

NCFA perspective

The report supports NCFA's existing view that tokenization is becoming measurable financial infrastructure. The market opportunity is not token issuance alone. It is regulated rails, data, custody, liquidity, compliance and settlement.

Stablecoins and CBDCs

What the FCA says

The Horizon Scan links stablecoins, CBDCs, digital assets and programmable money to changes in international financial architecture. It notes that cross border CBDC pilots such as mBridge are reaching minimum viable product scale in some regions.

  • New payments technology may reduce reliance on fiat currency in some contexts
  • CBDCs, digital assets and stablecoins could reshape cross border payment and settlement systems
  • Programmable money may support faster, more automated and conditional payment flows
  • Stablecoins may be part of shared ledger and Finternet style futures
  • Fragmented systems could create new enforcement and interoperability challenges
Implementation considerations

Payment and stablecoin projects should evaluate settlement finality, reserve or backing structure, redemption, interoperability, AML controls, sanction screening, user protection, data standards and integration with domestic payment systems.

NCFA perspective

This connects directly to the UK Cryptoasset Regulations And FCA Final Rules and NCFA's Programmable Stablecoin Payments Opportunity Brief. The strategic opportunity is compliant stablecoin infrastructure that can operate across regulated payment, settlement and tokenized asset systems.

Smart Data and Digital Identity

What the FCA says

The report identifies smart data and digital identity as interlocking layers in the UK's infrastructure-first strategy. Smart data, identity and payments may support more context-aware and programmable financial services.

  • The UK approach spans digital identity, smart data, settlement and payment infrastructure, programmable money and cross border interoperability
  • Digital public infrastructure such as IndiaStack is gaining momentum globally
  • Open finance and smart data may support context-aware services and real time personalization
  • Identity becomes a key building block for programmable financial stacks
  • Cross-sector data and DLT-enabled programmability could collapse trade, insurance and payment into atomic events
Implementation considerations

Firms should assess consent, data portability, identity assurance, verifiable credentials, cross-sector data standards, fraud risk, agent access and consumer control. Smart data strategy should be linked to product design and consumer protection.

NCFA perspective

Smart data is the bridge between open banking and programmable finance. Canada should treat consumer-driven banking, digital identity and payment modernization as connected infrastructure, not isolated files.

Finternet and Interoperability

What the FCA says

The FCA highlights the BIS Unified Ledger and Finternet concepts alongside mBridge and sovereign programmable financial stacks. It describes two possible futures: a more unified global ledger approach, or interoperable islands of domestic programmable ecosystems.

  • The BIS Unified Ledger combines CBDCs, tokenized deposits and assets into shared programmable infrastructure
  • mBridge points toward a modular network of sovereign ledgers connected through interoperable protocols
  • National approaches vary by speed, inclusion, sovereignty, privacy and wholesale interoperability
  • Future advantage may depend on building technical, legal and regulatory bridges across financial stacks
  • Capital may operate through multiple interconnected ecosystems rather than one monolithic infrastructure
Implementation considerations

Interoperability planning should address legal finality, messaging standards, identity, compliance, settlement assets, cross border controls, dispute handling, data governance and resilience across networks.

NCFA perspective

The Finternet discussion is highly relevant for NCFA's global intelligence work. It creates a framework for comparing Canada, the UK, EU, India, Singapore, Brazil and other jurisdictions by infrastructure readiness rather than only by regulation.

Canada Relevance

What the FCA says

The FCA report is UK-focused, but many themes are transferable because the same technologies, fraud risks and infrastructure choices are appearing across major financial markets.

  • Consumer agency and AI proxy risks are relevant to Canadian financial institutions, fintechs and consumer protection agencies
  • Synthetic identity, deepfakes and AI-enabled fraud are directly relevant to Canadian banking, payments and open finance
  • Programmable finance connects to Canada's work on payments modernization, consumer-driven banking, digital identity and stablecoin policy
  • International infrastructure concepts create comparison points for Canada's future market infrastructure strategy
  • Regulatory divergence matters for Canadian firms operating across the UK, EU, US and Asia-Pacific markets
Canadian reference points
NCFA perspective

The FCA Horizon Scan gives Canada a useful external reference. It connects AI, digital identity, fraud, open finance, payments and tokenization into one strategic view of financial infrastructure change. These files should not be treated as isolated policy tracks.

Implementation Questions

The FCA Horizon Scan does not impose obligations, but it raises strategic questions firms and policymakers should consider before technology adoption outpaces governance.

  • How should firms design financial products when AI agents, not people, may become the first decision interface?
  • What controls are needed when identity, documents, video, voice and transaction evidence can be synthetic?
  • How should market surveillance adapt to AI agents, synthetic sentiment and machine-speed manipulation?
  • Which programmable finance use cases have real infrastructure value rather than pilot level appeal?
  • How should Canada connect consumer-driven banking, digital identity, payments modernization and stablecoin policy into one infrastructure strategy?

Current FCA Developments

The FCA Emerging Technology Horizon Scan now sits within a larger programme on AI adoption, agentic systems, cyber resilience and regulatory capability.

The Mills ReviewPublished July 6, 2026, the review considers AI in retail financial services through 2030 and sets out recommendations for firms, consumers, competition and regulation.Read the FCA review
Supercharged SandboxThe second cohort focuses on advanced and agentic AI use cases, including payment, compliance and customer service agents.Review the sandbox programme
Frontier AI And Cyber ResilienceThe FCA, Bank of England and UK Treasury call for stronger protective, detective, containment, response and recovery capabilities.Read the joint statement

FCA Horizon Scan Questions

What is the FCA Emerging Technology Horizon Scan?

It is the FCA's first external technology horizon scan. The 2026 report examines plausible combinations of emerging technologies across Personalised Intelligence, Synthetic Insecurity and Programmable Finance.

Is the FCA Horizon Scan regulatory guidance?

No. The FCA states that it is not regulatory guidance or a prediction. It is a foresight document intended to support discussion, planning and early risk assessment.

What is synthetic financial crime?

Synthetic financial crime uses generated identities, documents, voices, images, narratives or transaction evidence to commit fraud, evade controls or manipulate financial systems.

What is programmable finance?

Programmable finance combines technologies such as tokenization, smart contracts, stablecoins, digital identity and smart data to automate financial transactions and infrastructure functions.

Why is the FCA Horizon Scan relevant in Canada?

It has no direct legal effect in Canada, but its scenarios are useful for Canadian work involving AI governance, synthetic identity, fraud prevention, consumer driven banking, payments modernization, stablecoins, tokenization and operational resilience.

Continue Exploring

Canada Open Banking RulesRegulatory Intelligence on Canada's consumer driven banking rules, oversight and implementation.Open the regulatory guide
UK Cryptoasset Regulations And FCA Final RulesCompanion Regulatory Intelligence page for final FCA cryptoasset implementation requirements.Open the regulatory guide
How Tokenization Became a Business Investors Can MeasureRelated story on tokenization becoming measurable, investable financial infrastructure.Read the story
How Is Crypto Custody Regulation Changing?Useful for custody, safeguarding, institutional trust and operational control questions.Read the question post
Programmable Stablecoin PaymentsOpportunity Brief connected to stablecoins, programmable money and compliant payment infrastructure.Open the Opportunity Brief
Stablecoin Data Shows Payments Reality GapMarket intelligence on the gap between stablecoin activity and real payment adoption.Read the analysis

From Strategy to Opportunity

The FCA Horizon Scan points to practical innovation themes across AI agents, identity, cyber resilience, fraud prevention, programmable finance, tokenization, stablecoins and interoperable financial infrastructure.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights

NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

UK Cryptoasset Regulations And FCA Final Rules

NCFA Regulatory Intelligence - UK FCA Final Cryptoasset Rules
NCFA Canada | Regulatory Intelligence | Digital Assets, Cryptoassets and Blockchain | Last updated July 19, 2026 | Status final FCA rules
NCFA Regulatory Intelligence
This guide explains UK cryptoasset regulations and the FCA final rules for authorisation, market access, implementation, compliance and opportunity analysis. Sources include FCA policy statements PS26/9 to PS26/13, finalised guidance FG26/5 to FG26/7 and the aggregate cost benefit analysis.
FCA Cryptoasset Regime Final rules for UK regulated cryptoasset activities

UK Cryptoasset Regulations And FCA Final Rules

The FCA published its final cryptoasset rules and guidance on 30 June 2026. The application period runs from 30 September 2026 to 28 February 2027, and the new regime starts on 25 October 2027. Use this guide to understand what the final rules require, what firms need to build, how the consultation outcome changed the design and where regulation creates market opportunities. Coverage includes admissions, disclosures, market abuse, stablecoin issuance, trading platforms, intermediaries, lending, borrowing, staking, safeguarding and custody, prudential requirements, Consumer Duty, governance, operational resilience, financial crime, reporting, redress, international firms and DeFi.

What Are The UK Cryptoasset Regulations?

The UK cryptoasset regulations bring specified cryptoasset activities into Financial Conduct Authority supervision under the Financial Services and Markets Act. The FCA final rules cover authorisation, trading platforms, intermediaries, stablecoin issuance, custody, lending, staking, disclosures, market abuse, prudential requirements, Consumer Duty, governance and operational resilience. The regime starts on 25 October 2027.

Final Rules Published30 June 2026
Applications Open30 September 2026
Application Deadline28 February 2027
Regime Starts25 October 2027
RegulatorFinancial Conduct Authority
Existing RegistrationMLR registration does not automatically convert to FSMA authorisation

UK Cryptoasset Regulation Journey

The UK has completed perimeter design, consultation and final FCA rulemaking. Firms now have an implementation period to prepare authorisation, governance, capital, custody, trading, stablecoin, market abuse and conduct systems before the regime starts.
Policy and consultation
Final rules and buildout
Implementation and supervision
Perimeter2023 to 2024 Cryptoasset activities brought into scope
Consultations2025 to 2026 CP25 and CP26 industry feedback
Final Rules30 June 2026 PS26/9 to PS26/13
Applications And Buildout30 Sep 2026 to 28 Feb 2027 Authorisation and systems preparation
Regime Starts25 October 2027 Handbook instruments commence
Supervision2027 onward Market conduct and resilience

Impact Analysis

Selected figures from the FCA aggregate cost benefit analysis and policy statements.
8%UK adults with cryptoasset holdings in 2025
£2,250Estimated average UK consumer crypto holding
£1.315BEstimated quantified firm costs over 10 years
£735MEstimated value of improved regulatory protections
£25MExample trading platform 10 year PV costs
£10MExample FSMA custodian entering crypto custody
£8MExample stablecoin issuer 10 year PV costs
£285MEstimated prudential requirement PV costs

What Firms Should Do Now

Firms that carry out or plan to carry out regulated cryptoasset activities should prepare their authorisation and implementation evidence before the application deadline.

  1. Map every UK activity against the regulated activity perimeter and identify any exclusions or special treatment.
  2. Determine whether the firm needs a new FCA authorisation or a variation of permission.
  3. Prepare a complete application for the period from 30 September 2026 to 28 February 2027 and apply as early as practical.
  4. Assign accountable owners across CRYPTO, CASS, CRYPTOPRU, Consumer Duty, SYSC, SM&CR, financial crime and reporting.
  5. Build evidence for governance, financial resources, custody, resilience, outsourcing, consumer outcomes and operational controls.
  6. Test systems and remediation plans before the regime starts on 25 October 2027.

Regulatory Intelligence Explorer

Navigate the FCA final cryptoasset regime by rule area. Each section separates requirements, implementation work, consultation outcome and NCFA’s strategic perspective.

Overview

Requirements The FCA package creates a full UK cryptoasset regime rather than a single rule. It combines designated activity rules for admissions and market abuse, regulated activity rules for trading platforms, intermediaries, lending, borrowing, staking and safeguarding, stablecoin issuance rules, prudential requirements and cross cutting FCA Handbook standards. The Handbook instruments commence on 25 October 2027.
  • The regime covers UK qualifying cryptoasset trading platforms, cryptoasset intermediaries, qualifying stablecoin issuers, custodians, lending and borrowing services, staking services and firms carrying on regulated cryptoasset activities in or into the UK
  • The final package includes CRYPTO sourcebook rules, CASS 16 for stablecoin backing assets, CASS 17 for safeguarding qualifying cryptoassets, CRYPTOPRU and COREPRU prudential rules, Consumer Duty, COBS, SYSC, SM&CR, DISP, FOS access, reporting and operational resilience requirements
  • The commencement sequence includes stablecoins, admissions, market abuse, intermediaries, trading platforms, lending, borrowing and staking, safeguarding, client asset consequentials, conduct and firm standards, and prudential instruments
  • The FCA kept the broad policy architecture but made targeted changes for proportionality, including stablecoin backing asset simplification, best execution clarification, removal of principal dealers from pre trade transparency, and operational resilience guidance
Implementation Firms should build a regime map by activity, not by document title. A single firm may need authorisation, admissions controls, disclosures, surveillance, custody arrangements, CASS controls, prudential calculations, Consumer Duty evidence, financial crime controls, operational resilience testing and regulatory reporting. The implementation plan should assign accountable owners for each CRYPTO, CASS, SYSC, COBS, SM&CR, DISP and CRYPTOPRU dependency.
Consultation Outcome
  • The FCA moved from consultation to final rules while preserving the regime design
  • Respondents generally supported a comprehensive regime, but pushed for proportionality, international competitiveness and operational clarity
  • The FCA responded with targeted refinements rather than a lighter perimeter
  • Remaining open items include further guidance on DeFi decentralisation and separate DLT operational resilience guidance
NCFA Perspective This is a regulatory market structure event. The UK is setting a supervised operating model for crypto as financial infrastructure. The strategic question is which firms can turn authorisation, custody, stablecoin operations, market surveillance, prudential analytics and conduct evidence into repeatable operating capability before the regime goes live.

Scope and Authorisation

Requirements The regime applies to regulated cryptoasset activities brought into scope by the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 and implemented through FCA Handbook instruments. Activities include operating a qualifying cryptoasset trading platform, dealing, arranging, qualifying cryptoasset lending and borrowing, staking, safeguarding and qualifying stablecoin issuance. Firms conducting those activities will need FCA authorisation unless an exclusion or specific treatment applies.
  • UK QCATP operators require authorisation where they operate in the UK or serve UK consumers from overseas
  • International firms are assessed against threshold conditions including location of offices, effective supervision, appropriate resources, suitability and business model
  • Dual regulated firms may operate in the UK through a branch where the PRA is satisfied threshold conditions and ongoing requirements are met
  • The FCA expects an authorisation gateway before the regime goes live, with firms preparing systems, controls and evidence in advance
  • Existing cryptoasset MLR registration does not replace FSMA authorisation for regulated cryptoasset activities
Implementation Firms should map every UK facing activity to the regulated activity perimeter and authorisation pathway. The implementation file should include corporate structure, UK presence, branch or subsidiary analysis, overseas service model, governance, financial resources, systems and controls, operational resilience, outsourcing, financial crime and Consumer Duty evidence.
Consultation Outcome
  • The FCA clarified its approach to international firms and branches following feedback
  • The final approach remains cautious about cross border firms serving UK consumers without clear UK accountability
  • The FCA did not create a broad equivalence shortcut in the final package
  • The authorisation runway becomes a key commercial dependency for firms seeking UK market access
NCFA Perspective Scope is the competitive gate. The UK is giving global crypto firms a route into a regulated market, but the route depends on authorisation evidence, supervision, governance and operational substance. That is different from simply allowing offshore activity to reach UK users.

Admissions and Disclosures

Requirements The admissions and disclosure framework governs admission of qualifying cryptoassets to trading on UK QCATPs and offers to the public of qualifying cryptoassets admitted to trading. It uses qualifying cryptoasset disclosure documents, admission criteria, due diligence, responsibility allocation and disclosure obligations to create a baseline for market entry.
  • UK QCATP operators must establish admission criteria and assess whether a qualifying cryptoasset should be admitted to trading
  • Offerors and relevant issuers must produce qualifying cryptoasset disclosure documents where required
  • Disclosure documents must support informed decisions and include material information about the cryptoasset, rights, risks, technology, governance and project context
  • Trading platforms need procedures for disclosure review, admission decisions, record keeping and ongoing monitoring
  • Relevant issuers and offerors face responsibility for statements and omissions in disclosure documents
  • Protected forward looking statements have specific treatment under the regime
  • Firms must manage the link between admissions, disclosures, market abuse controls and post admission monitoring
Implementation Implementation requires an admissions committee or equivalent control function, written admission criteria, due diligence checklists, disclosure templates, issuer and offeror attestations, legal review, technology risk review, conflict checks, decision records and post admission triggers. Platforms should prepare a repository for disclosure documents, versions, approvals, rejection reasons and ongoing updates.
Consultation Outcome
  • The FCA retained the admissions and disclosure framework after consultation
  • The final rules are designed to support market integrity without importing traditional securities listing rules wholesale
  • Firms will need to show how disclosures are complete, fair and understandable for the relevant market
  • The burden falls heavily on platforms because admission decisions become a regulated control point
NCFA Perspective Admissions are where market access becomes a regulated quality filter. The practical opportunity is not only listing more tokens. It is building repeatable disclosure, due diligence, legal review and issuer data infrastructure that can support credible cryptoasset markets.

Market Abuse

Requirements The market abuse regime addresses insider dealing, unlawful disclosure of inside information and market manipulation in qualifying cryptoassets and related instruments. The FCA rules and guidance set out concepts, prohibited behaviours and systems requirements for UK QCATP operators and cryptoasset intermediaries.
  • CRYPTO 4 provides guidance on inside information, insider dealing, unlawful disclosure and market manipulation
  • UK QCATP operators and cryptoasset intermediaries must prevent, detect and disrupt cryptoasset market abuse
  • Operators need systems and procedures for monitoring orders, transactions, communications, suspicious behaviour and abusive patterns
  • Firms must receive and store notifications securely with completeness, integrity and confidentiality
  • Market abuse arrangements must address crypto specific risks such as cross venue trading, on chain activity, token issuance events, concentrated holdings and information asymmetry
  • Outsourcing or delegation does not remove responsibility for compliance
  • Firms need records that can support investigation, escalation and regulator engagement
Implementation Firms should build surveillance scenarios for insider dealing, pump and dump activity, spoofing, wash trading, manipulation around token admissions, misuse of issuer information, coordinated social activity and suspicious on chain transfers. Platforms should integrate order book data, trade data, wallet data where available, issuer announcements, disclosure documents and escalation logs.
Consultation Outcome
  • The final package applies a market abuse model tailored to cryptoasset markets while drawing on familiar FCA concepts
  • The FCA expects trading venues and intermediaries to operate proactive controls rather than relying only on post event enforcement
  • Secure notification and evidence handling are explicit operational requirements
  • The regime creates a compliance technology need across surveillance, data integrity and case management
NCFA Perspective Market abuse is the credibility test for regulated crypto trading. The UK framework will only support institutional adoption if market surveillance, disclosure timing and manipulation controls are strong enough to distinguish regulated markets from speculative venues.

Stablecoin Issuance

Requirements PS26/10 sets final rules for non systemic UK issued qualifying stablecoins, covering issuance, backing assets, redemption, safeguarding and disclosures. CASS 16 governs management and safeguarding of backing asset pools. The FCA’s approach treats stablecoins as money like instruments where trust depends on backing, segregation, redemption, reconciliation and clear disclosures.
  • Issuers must maintain a backing asset pool for each qualifying stablecoin product and segregate it from the firm’s own assets and from other backing pools
  • Backing pools must be held in backing funds accounts or backing assets accounts meeting CASS conditions
  • Issuers using expanded backing assets must calculate the backing asset composition requirement every redemption day
  • The core backing asset requirement is the higher of 5% and the highest redemption percentage over the previous 180 redemption days or shorter operating history
  • Issuers must promptly notify the FCA if they cease to comply with specified backing asset requirements, with a limited exception for rebalancing after a daily calculation
  • Backing assets are held on statutory trust for holders of the qualifying stablecoin
  • Backing asset pools for different stablecoin products must be separate, distinct, independently managed and held in different accounts
  • Stablecoin funds must be promptly paid into a backing funds account or invested in assets held in a backing assets account
  • Issuers must conduct internal and external safeguarding reconciliations, identify and resolve discrepancies and maintain records
  • Redemption requirements include T+1 expectations, with KYC checks completed before the redemption period begins
  • Issuers must provide disclosures and make holders aware of withdrawal rights
  • The FCA allows limited intragroup custody subject to safeguards and allows a 5% excess in the backing asset pool
Implementation Stablecoin issuers need a dedicated operating model for backing assets, liquidity, reconciliation, redemption, disclosures, trust accounting, custodian oversight and holder communications. Implementation should include product level backing pool ledgers, daily BACR calculations where expanded assets are used, reconciliation workflows, FCA notification triggers, redemption queue logic, KYC timing controls, disclosure history and governance over tokenized versions of backing assets.
Consultation Outcome
  • The FCA simplified the backing asset composition requirement after feedback that forward looking redemption estimates were complex and burdensome
  • The FCA kept the range of permissible backing assets and rejected broader LVNAV and non UK UCITS MMF expansion because of stability concerns
  • Tokenized versions of permissible backing assets are not prohibited if they comply with CASS 16 and custody requirements
  • Redemption timelines were adjusted so KYC checks are completed before the redemption period begins
  • The FCA confirmed statutory trust arrangements and made refinements to third party and intragroup custody treatment
NCFA Perspective Stablecoin issuance is where compliance becomes product architecture. The winners will not be the firms that simply issue tokens. They will be the firms that can evidence backing, redemption, liquidity, disclosure and custody controls well enough for consumers, institutions and regulators to treat stablecoins as usable financial infrastructure.

Trading Platforms

Requirements PS26/11 sets rules for UK qualifying cryptoasset trading platforms. The framework covers location and authorisation, platform access, operating rules, conflicts, settlement arrangements, transparency, record keeping and reporting. The FCA expects platforms serving UK consumers to operate through an authorised UK model or an acceptable international firm structure.
  • UK QCATP operators require FCA authorisation if operating in the UK or serving UK consumers from overseas
  • Platforms must have operating rules, admission processes, access standards and controls for orderly trading
  • Retail customer focused requirements apply where platforms serve retail clients
  • Platforms must manage conflicts of interest, including risks around affiliated activities, proprietary activity, token admissions and market data
  • Settlement arrangements must be clear, reliable and consistent with safeguarding and operational resilience requirements
  • Transparency, record keeping and reporting obligations apply to orders, transactions and platform operation
  • Best execution expectations interact with authorised execution venues and periodic post trade analysis
  • Principal dealers were removed from pre trade transparency requirements in the final approach
  • Platforms need market abuse prevention, detection and disruption arrangements under PS26/9
Implementation Platform implementation should include authorisation planning, operating rulebook, access policy, admission governance, conflicts register, surveillance tooling, settlement design, order and trade records, client reporting, market data controls, resilience mapping and incident response. Firms should evidence why venue access, matching, settlement, custody and conflict controls protect consumers and market integrity.
Consultation Outcome
  • The FCA clarified location, incorporation and international firm expectations after feedback
  • Principal dealers were removed from pre trade transparency requirements
  • Best execution was clarified so firms should check prices from at least three reliable UK authorised execution venues where possible but do not need mechanical transaction by transaction checks or execution on those venues
  • The FCA retained the broader platform framework and added guidance rather than reducing the venue perimeter
NCFA Perspective Trading platforms are the centre of the regulated market. The commercial question is whether UK authorised venues can offer credible liquidity, transparent execution and institutional controls without losing users to offshore platforms that do not meet the same standard.

Intermediaries

Requirements The intermediary rules cover firms dealing in qualifying cryptoassets as principal, arranging deals and providing related intermediation services. They connect execution quality, client communication, conflicts, payments for order flow, authorised venue interaction, conduct obligations and prudential requirements.
  • Intermediaries must understand which regulated activity they perform and whether they deal, arrange, route, introduce or support client execution
  • Execution arrangements must be effective and supported by periodic post trade analysis
  • Firms should check prices from at least three reliable UK authorised execution venues where possible
  • The FCA clarified that firms are not required to execute on those venues or perform mechanical transaction by transaction checks if effective arrangements are in place
  • Conflicts, remuneration, inducements and payments for order flow require controls
  • Client communications and conduct obligations apply through COBS and Consumer Duty where relevant
  • Intermediaries may be subject to prudential requirements, financial crime controls, operational resilience and reporting
Implementation Intermediaries should build an execution policy, venue assessment framework, periodic price review, conflicts assessment, client disclosure process, order routing records, remuneration review and evidence that client outcomes are monitored. Firms with global routing models need controls showing how UK clients receive fair treatment under the UK regime.
Consultation Outcome
  • The FCA responded to feedback by clarifying best execution rather than imposing venue execution mandates
  • The final rules seek to balance execution quality with the reality of fragmented global crypto liquidity
  • Concerns about the arranging perimeter and international firms were addressed through guidance and refinements
  • Intermediaries remain a high implementation burden because conduct, execution, financial crime and prudential requirements overlap
NCFA Perspective Intermediation is where user experience meets regulatory discipline. Firms that can route orders well, evidence execution quality and manage conflicts may turn compliance into trust. Firms that treat execution as a black box will struggle under the new model.

Lending and Borrowing

Requirements The lending and borrowing chapter applies to authorised cryptoasset firms providing qualifying cryptoasset lending or borrowing services to retail clients who are not overseas retail clients, with certain requirements also applying to clients who are not overseas clients. Firms remain responsible where they comply through third parties such as custodians or service providers.
  • Firms must provide retail clients with information about the firm and the qualifying cryptoasset lending or borrowing service before the client is bound or before service provision
  • Information must be provided in a durable medium or through a qualifying website, mobile application or digital medium
  • Where clients give express prior consent for yield to be used in further lending, firms may not need to repeat the information requirement for that yield use
  • Retail protections apply to lending and borrowing service design, client information and risk communication
  • Firms remain responsible for compliance when using third party custodians or service providers
  • Rules and controls must address collateral, yield, client reporting, service risk, counterparty risk and return of assets
  • Lending and borrowing firms will also need prudential, safeguarding, operational resilience, financial crime and Consumer Duty evidence
Implementation Implementation should include client information templates, durable medium controls, express consent capture, yield treatment logic, collateral policy, counterparty due diligence, risk disclosures, client reporting, third party contracts, custody links, withdrawal and return processes, and complaint handling. Firms should stress test whether clients understand rehypothecation, loss, yield, liquidity and counterparty risk.
Consultation Outcome
  • The FCA confirmed retail protections for lending and borrowing as part of the final PS26/11 package
  • The rules preserve firm accountability even where service delivery uses third parties
  • Final refinements address collateral and service design issues but keep lending and borrowing inside a regulated conduct baseline
  • This is one of the areas where Consumer Duty evidence will matter because product risk can be hard for retail clients to understand
NCFA Perspective Crypto lending is no longer being treated as a purely private yield product. The UK regime pushes it toward regulated product governance, clear client information and controlled service design. That could reduce high risk models but may also create room for safer institutional and collateral services.

Staking

Requirements The staking framework in PS26/11 confirms retail protections and targeted refinements to staking rules, including treatment of auto staking. Staking services create operational, validator, custody, disclosure and client outcome risks that connect to safeguarding, operational resilience and Consumer Duty.
  • Firms providing staking services must identify whether the service is within the regulated perimeter and which client protections apply
  • Client information should explain staking arrangements, validator risk, lockups, slashing, rewards, fees, liquidity, tax or reporting context where relevant and operational dependencies
  • Auto staking treatment was refined in the final rules
  • Where staking uses validators, node operators, custodians or other service providers, the authorised firm remains accountable for regulated obligations
  • Operational resilience guidance identifies validator risk and validator outages as crypto specific risks
  • Firms need records showing staking instructions, rewards, fees, losses, slashing events, service disruptions and client communications
Implementation Implementation should include validator due diligence, staking policy, client consent flows, reward calculation controls, fee disclosure, slashing incident workflow, exit queue process, asset segregation, outsourcing or third party arrangements and resilience testing for validator outages. Firms should connect staking risk to Consumer Duty outcomes and complaint handling.
Consultation Outcome
  • The FCA retained staking inside the final activity framework while making targeted refinements
  • Operational resilience guidance specifically highlights validator risks and outages
  • The final approach does not remove staking risk but requires firms to evidence controls and client understanding
  • Further market practice will likely shape supervisory expectations after go live
NCFA Perspective Staking is a good example of regulation translating crypto native activity into financial services controls. The opportunity is not simply offering yield. It is making staking understandable, monitored, resilient and institutionally acceptable.

Safeguarding and Custody

Requirements The FCA applies safeguarding requirements through CASS 17 for qualifying cryptoassets and related CASS amendments. Custody and safeguarding are central to the regime because many cryptoasset failures come from weak asset control, poor segregation, private key compromise, unclear client ownership or inadequate third party oversight.
  • Firms safeguarding qualifying cryptoassets must comply with CASS 17 requirements tailored to cryptoasset custody
  • Safeguarding requirements interact with CASS 16 where tokenized stablecoin backing assets or qualifying stablecoin custody is involved
  • Firms need arrangements for holding, recording, reconciling and protecting client cryptoassets
  • Private key management, wallet infrastructure, access controls, signing authority and recovery procedures are core operational controls
  • Third party custody or infrastructure arrangements require due diligence, contractual protections and ongoing oversight
  • Client reporting must ensure clients can access information, including where information is available on chain
  • Custody controls link to operational resilience, financial crime, Consumer Duty, dispute resolution, complaints and prudential requirements
Implementation Custodians and firms using custodians should document wallet architecture, key ceremony, MPC or HSM controls, cold and warm wallet policies, access roles, transaction approval, reconciliation, incident response, third party oversight, bankruptcy analysis, client asset records, insurance or financial resources and client reporting. Firms should test private key loss, unauthorized signing, chain outage, custodian failure and reconciliation breaks.
Consultation Outcome
  • The FCA confirmed application of safeguarding requirements under CASS 17 with cryptoasset specific adjustments
  • The FCA did not create a separate SM&CR prescribed responsibility for digital asset custody because existing custody PRs cover custody of a broad range of assets
  • Limited intragroup custody is permitted for stablecoin backing arrangements subject to safeguards
  • The final regime gives custody a central role in institutional trust and consumer protection
NCFA Perspective Custody is likely to be the most important infrastructure layer in the regime. Regulated crypto markets cannot scale without credible asset control, private key governance, reconciliation and failure recovery. This is where specialist infrastructure providers may gain durable advantage.

Prudential Requirements

Requirements PS26/12 creates a prudential framework for regulated cryptoasset firms covering capital, own funds, concentration risk, liquid assets, overall risk assessment and public disclosure. It uses CRYPTOPRU and COREPRU amendments to establish a baseline that reflects cryptoasset risks without simply importing bank prudential rules.
  • Firms must meet own funds definition and composition requirements
  • Own funds requirements include fixed overhead and K factor based components where applicable
  • The operational risk K factor for stablecoin issuance was reduced from 2% to 1% in the final rules
  • The revised market risk framework applies a single 40% net cryptoasset position requirement for K NCP where assets can be prudently valued and are admitted to a UK QCATP
  • Cryptoassets that do not meet the conditions are deducted from regulatory capital and subject to a 100% volatility adjustment for K CCD
  • Concentration risk and liquid asset requirements apply to support resilience
  • Firms must conduct overall risk assessments and maintain adequate financial resources
  • Public disclosure obligations are included with proportionality refinements
  • Prudential obligations apply alongside activity specific conduct, custody, stablecoin and Handbook requirements
Implementation Firms should build prudential models by activity and balance sheet exposure. Required work includes own funds classification, K factor calculation, stablecoin issuance exposure, custody and platform activity mapping, cryptoasset valuation policy, capital deduction logic, liquid asset monitoring, concentration risk limits, stress testing, management information, public disclosure process and board sign off.
Consultation Outcome
  • The FCA largely maintained the prudential architecture but recalibrated key areas for proportionality
  • Stablecoin operational risk capital was reduced from 2% to 1%
  • The market risk framework was simplified to a 40% treatment for qualifying prudently valued assets admitted to a UK QCATP and deduction or 100% volatility adjustment for others
  • The public disclosure regime was made more proportionate
  • Respondents supported prudential clarity but raised concerns about calibration, competitiveness and operational burden
NCFA Perspective Prudential rules turn crypto firms into regulated financial businesses with capital and liquidity discipline. The effect may be fewer casual entrants, but stronger survivors. The commercial opportunity is prudential analytics, treasury management, disclosure tooling and capital efficient operating models.

Consumer Duty and Conduct

Requirements PS26/13 applies key FCA Handbook standards to regulated cryptoasset activities, including Consumer Duty, COBS, conduct rules, dispute resolution, compensation treatment and reporting. Most firms carrying on regulated cryptoasset activities will be subject to these cross cutting obligations, with specific exceptions for certain professional client platform activity and platform member transactions.
  • Consumer Duty applies to relevant cryptoasset activity subject to defined scope and exclusions
  • Principles 6 and 9 and Consumer Duty do not apply when operating a qualifying CATP for professional clients
  • Certain Principles and Consumer Duty do not apply to transactions concluded between members or participants under the rules of a qualifying cryptoasset trading platform
  • The FCA clarified Consumer Duty guidance on territorial scope, fair value, consumer support, consumer understanding and manufacturer or distributor roles
  • COBS standards apply to relevant cryptoasset conduct and communications
  • Firms need evidence that products, services, support and communications deliver appropriate outcomes
  • DISP and Financial Ombudsman Service access apply to relevant complaints
  • Compensation and redress rules are part of the broader Handbook application
Implementation Implementation should include Consumer Duty outcome mapping by activity, customer journey review, product governance, fair value assessment, communication testing, support standards, vulnerability considerations, complaints data, MI dashboards and board reporting. Crypto firms should prove that customers understand custody, stablecoin, staking, lending, execution and volatility risks before and after purchase.
Consultation Outcome
  • The FCA made clarifications rather than retreating from applying Consumer Duty and conduct standards
  • UK issued qualifying stablecoins were excluded from the definition of restricted mass market investments
  • Consumer Duty guidance was clarified across fair value, support, understanding and supply chain roles
  • The final approach signals that crypto conduct standards should converge with regulated financial services expectations
NCFA Perspective This is one of the strongest differences between regulated crypto and offshore crypto. The UK model requires firms to evidence consumer outcomes, not only publish risk warnings. Firms that can make complex products understandable may have a material trust advantage.

Governance and SM&CR

Requirements The FCA applies Senior Management Arrangements, Systems and Controls and the Senior Managers and Certification Regime to cryptoasset firms. Governance requirements cover risk management, controls, accountability, prescribed responsibilities, operational resilience, financial crime, custody and board oversight.
  • SYSC 4 to SYSC 10 apply to qualifying cryptoasset firms according to firm type and common platform status
  • SM&CR applies to relevant cryptoasset firms with proportionality and threshold treatment
  • The enhanced SM&CR threshold for qualifying UK stablecoin issuers is set at £20 billion, intended to capture the most significant stablecoins over time
  • Smaller and medium sized stablecoin issuers are not expected to fall into enhanced SM&CR at commencement
  • Existing prescribed responsibilities are used for custody rather than creating separate digital asset custody PRs
  • Senior management responsibilities include financial crime, operational resilience, compliance, safeguarding, prudential risk and conduct outcomes where relevant
  • Governance must support FCA supervision, authorisation evidence and ongoing compliance
Implementation Firms should build a management responsibilities map, committee structure, board reporting pack, policy owner register, control owners, prescribed responsibility allocation, SMF evidence, certification population, conduct training, breach escalation and decision records. Stablecoin issuers should monitor whether scale could bring enhanced SM&CR into scope over time.
Consultation Outcome
  • The FCA adjusted the enhanced threshold for qualifying UK stablecoin issuers in light of Bank of England proposals
  • The FCA expects the £20 billion threshold to capture 1% or less of the firm population and likely no firms at commencement
  • The FCA declined to create separate prescribed responsibilities for cryptoasset custody
  • Governance requirements were largely maintained with targeted proportionality refinements
NCFA Perspective Governance is where regulatory permission becomes accountable execution. The UK is not just authorising products. It is assigning responsibility to named leaders, boards and control functions. That will shape who can credibly scale.

Operational Resilience

Requirements The FCA extends SYSC 15A operational resilience to cryptoasset firms and provides FG26/6 to explain cryptoasset specific risks. Firms must identify important business services, set impact tolerances, map dependencies and conduct scenario testing. SYSC 4, SYSC 7 and SYSC 8 complement the framework through risk management, controls and outsourcing requirements.
  • Firms must have sound, effective and comprehensive strategies, processes and systems proportionate to their nature, scale and complexity
  • Important business services must be identified and mapped across people, processes, technology, facilities and information
  • Impact tolerances must be set and tested through severe but plausible scenarios
  • Crypto specific risks include smart contract vulnerabilities, private key security risks, validator risks, service disruptions, cyber risks, DLT dependencies and emerging technologies such as AI and quantum computing
  • FG26/6 highlights cyber and technology resilience, cryptographic key and infrastructure safeguarding, continuity and disruption planning
  • Outsourcing expectations cover custody infrastructure, MPC and HSM providers, validator services, cloud providers and security critical transaction signing infrastructure
  • Permissionless DLT use should not be treated as outsourcing under SYSC 8.1.1R, but firms remain responsible for operational resilience controls
  • Firms should conduct targeted vulnerability scans, penetration tests and maintain monitoring and logging evidence
Implementation Implementation should produce a live resilience map for every important business service. Firms need dependency mapping, wallet and key infrastructure controls, validator due diligence, smart contract testing, cyber controls, incident playbooks, impact tolerance testing, penetration testing, cloud and third party oversight, logging, operational dashboards and board reporting. Scenario tests should include private key compromise, smart contract failure, validator outage, chain disruption, trading outage, stablecoin reconciliation failure and custodian failure.
Consultation Outcome
  • 91% of respondents supported extending SYSC 15A to cryptoasset firms and 88% supported the guidance approach
  • 98% supported the view that permissionless DLTs should not be treated as outsourcing
  • The FCA kept the extension of operational resilience while adding crypto specific guidance
  • Further non Handbook guidance on DLT operational resilience is expected later
NCFA Perspective Operational resilience is where the FCA regime becomes more than conduct regulation. Crypto firms are technology firms with financial risk. The UK framework makes uptime, key security, third party dependency and recovery capability part of the regulatory value proposition.

Financial Crime

Requirements PS26/13 applies the financial crime elements of SYSC 6, the Financial Crime Guide and Financial Crime Thematic Reviews to firms conducting regulated cryptoasset activities. These obligations sit alongside the Money Laundering Regulations and Travel Rule obligations already applicable to UK cryptoasset exchange providers and custodian wallet providers.
  • Cryptoasset firms conducting regulated activities must follow the same financial crime framework as other FSMA authorised firms where applicable
  • Relevant Handbook references include SYSC 6.1.1R adequate policies and procedures, SYSC 6.3.1R systems and controls, SYSC 6.3.3R financial crime risk assessments, SYSC 6.3.8R senior manager responsibility and SYSC 6.3.9R MLRO
  • Firms must comply with MLRs and the Travel Rule alongside FSMA obligations
  • Policies and procedures must be comprehensive and proportionate to the nature, scale and complexity of activities
  • Controls should identify, assess, monitor and manage money laundering, sanctions, fraud, terrorist financing, bribery, corruption and market abuse related risk
  • Financial crime evidence must connect to onboarding, transaction monitoring, wallet screening, custody, stablecoin issuance, trading, lending and staking
Implementation Implementation should include risk assessment, customer due diligence, wallet and blockchain analytics, sanctions screening, Travel Rule workflow, suspicious activity reporting, transaction monitoring, fraud controls, stablecoin redemption screening, market abuse escalation, MLRO governance, senior manager accountability, periodic control testing and audit trails.
Consultation Outcome
  • The FCA retained the proposal to apply financial crime rules and guidance to cryptoasset firms
  • The FCA views the same financial crime baseline as proportionate for cryptoasset firms despite sector specific risks
  • The regime operates alongside MLR registration and Travel Rule obligations, so firms face overlapping compliance layers
  • Financial crime controls become part of authorisation readiness and ongoing supervision
NCFA Perspective Financial crime is central to regulatory legitimacy. The UK regime will reward firms that can combine on chain analytics with traditional financial crime governance. This is also a clear opportunity for regtech, wallet intelligence and compliance automation.

Reporting and Redress

Requirements PS26/13 applies reporting, dispute resolution and redress architecture to regulated cryptoasset activities. Firms need to report to the FCA, maintain records, handle complaints, provide access to the Financial Ombudsman Service where relevant and preserve evidence across product, custody, execution, conduct and prudential areas.
  • Regulatory reporting applies to cryptoasset firms under the Handbook application package
  • Firms need data on activities, clients, complaints, prudential position, operational resilience, financial crime controls and other supervisory metrics
  • DISP and access to the Financial Ombudsman Service apply where relevant
  • Complaint handling must connect to Consumer Duty, client reporting, custody, execution, lending, staking and stablecoin redemption issues
  • Record keeping requirements apply across admissions, market abuse, client orders, transactions, lending, borrowing, staking, safeguarding and reporting
  • Public disclosure obligations apply in the prudential regime with proportionality refinements
  • Firms need evidence retention policies that allow supervisory reconstruction of decisions and client outcomes
Implementation Firms should build a reporting data model before go live. Required work includes regulatory returns ownership, data lineage, complaints taxonomy, FOS workflow, prudential reporting data, custody records, client statements, execution data, surveillance cases, operational incidents, financial crime alerts and board MI. Manual reporting will be risky given the breadth of the regime.
Consultation Outcome
  • The FCA made focused amendments to reporting requirements in PS26/13
  • The prudential disclosure regime was made more proportionate
  • The overall approach keeps crypto inside existing FCA supervisory and redress architecture
  • Reporting and redress obligations will expose weak data governance quickly after authorisation
NCFA Perspective Reporting is the regime’s memory. Firms that cannot reconstruct decisions, client outcomes, custody records or prudential positions will struggle to defend their operating model. Good reporting infrastructure becomes a strategic asset, not only a compliance cost.

International Firms

Requirements The FCA’s approach to international cryptoasset firms sets expectations for firms seeking UK authorisation while serving UK consumers. It focuses on threshold conditions, location of offices, effective supervision, appropriate resources, suitability and business model. The final guidance clarifies branch treatment for dual regulated firms where PRA conditions are satisfied.
  • International firms requiring FCA authorisation must meet minimum standards at application and on an ongoing basis
  • The FCA considers location of offices, effective supervision, appropriate resources, suitability and business model
  • The FCA identifies higher consumer and market harm risk where international firms serve UK customers through branches rather than UK legal entities
  • Dual regulated firms may operate through a UK branch where the PRA is satisfied threshold conditions and ongoing requirements are met
  • International models must demonstrate accountability, supervision, client protection, operational resilience and financial crime controls
  • Cross border liquidity access may be relevant, but does not remove UK authorisation and governance expectations
Implementation International firms should prepare a UK market access file covering branch or subsidiary choice, governance, UK senior managers, service model, outsourcing, group support, capital, liquidity, client disclosures, data location, custody, financial crime, operational resilience and how UK customers are protected if overseas operations fail.
Consultation Outcome
  • The FCA clarified the international firm approach after feedback in CP26/4
  • The final guidance acknowledges branches for dual regulated firms where PRA expectations are met
  • The FCA did not make overseas access easy simply because liquidity is global
  • The approach tries to balance global liquidity with UK accountability and effective supervision
NCFA Perspective This is where the UK tries to attract global crypto firms without importing offshore risk. The strongest firms will treat UK authorisation as a credible market badge, not a light touch registration.

DeFi

Requirements The FCA’s current approach to decentralised finance is to apply rules where there is an identifiable controlling entity, with separate guidance to follow on how decentralisation will be assessed in practice. DeFi is treated as a range of financial services marketed with a high degree of automation rather than as a blanket exemption from regulation.
  • Rules apply where there is an identifiable controlling entity
  • Separate guidance is expected on how decentralisation will be assessed
  • DeFi interfaces, arrangements and controlling entities may fall within regulated activity analysis
  • Automation does not by itself remove regulatory obligations
  • Firms must assess governance, control, user interface, protocol dependency, custody, financial promotion, market abuse, lending, staking and consumer risk
  • DeFi related activity may also raise operational resilience, financial crime, Consumer Duty and international firm issues
Implementation Firms should document who controls the interface, protocol parameters, governance keys, admin rights, fee flows, custody, upgrade authority, user onboarding, compliance controls and consumer communications. A DeFi implementation file should show whether the business is genuinely decentralised or whether an identifiable entity directs regulated activity.
Consultation Outcome
  • The FCA retained the principle that identifiable controlling entities bring DeFi activity within regulatory reach
  • The FCA acknowledged the need for separate guidance on decentralisation assessment
  • The final approach avoids treating DeFi labels as determinative
  • This remains a watch area because future guidance will likely affect interface operators, protocol sponsors and infrastructure providers
NCFA Perspective DeFi is the frontier test for the regime. The key issue is control. If a business can control access, fees, governance, listings or user experience, regulators are unlikely to treat it as outside the market structure simply because the protocol uses smart contracts.

UK Cryptoasset Regulations FAQ

When do the UK cryptoasset regulations start?

The new FCA cryptoasset regime starts on 25 October 2027.

When can firms apply for FCA cryptoasset authorisation?

The scheduled application period runs from 30 September 2026 to 28 February 2027. Firms seeking to rely on saving and transitional provisions should apply within that period.

Does an existing MLR registration become FCA authorisation?

No. Existing registrations and permissions do not automatically convert. A firm carrying on an in scope regulated cryptoasset activity will need the relevant FSMA permission.

Which cryptoasset activities are covered?

The regime covers activities including operating qualifying cryptoasset trading platforms, dealing, arranging, stablecoin issuance, custody, lending, borrowing and staking. Admissions, disclosures and market abuse rules also apply.

Which FCA rulebooks apply to cryptoasset firms?

The package includes the CRYPTO sourcebook, CASS 16 and CASS 17, CRYPTOPRU and COREPRU, plus relevant Consumer Duty, COBS, SYSC, SM&CR, DISP, reporting and operational resilience requirements.

What should firms prioritise before applying?

Firms should confirm scope, prepare governance and financial resource evidence, document custody and resilience controls, assess Consumer Duty outcomes and build a complete authorisation file for their business model.

Continue Exploring

How Tokenization Became a Business Investors Can MeasureConnects the FCA regime to the shift from crypto speculation toward measurable, investable tokenized infrastructureRead the story
How Is Crypto Custody Regulation Changing?Useful for custody, safeguarding, CASS 17, institutional trust and operational control questionsRead the question
UK FCA Plans Full Crypto Licensing Regime by 2026Background on the UK path from policy design and consultation toward a full cryptoasset regimeReview the buildout
FCA Chair on Crypto, Stablecoins and Digital Asset RegulationPolicy signal connecting crypto regulation, stablecoins, consumer risk, scams and the FCA's long running supervisory directionRead the speech context
Stablecoin Data Shows Payments Reality GapMarket evidence on why stablecoin payments need trust, liquidity, distribution and operating infrastructureRead the analysis
Tokenized Infrastructure Is Changing How Markets OperateMarket infrastructure context for tokenized cash, settlement, collateral, custody and regulated railsRead the insight

From Regulation to Opportunity

The FCA regime creates demand for regulated infrastructure across stablecoins, custody, market surveillance, disclosure, trading systems, prudential analytics, operational resilience, Consumer Duty evidence, reporting and compliance automation. The closest NCFA opportunity layer is the Programmable Stablecoin Payments brief, which examines where compliant stablecoin infrastructure can create practical payment and settlement use cases.

Open the Stablecoin Payments Opportunity Brief


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights

NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Canada’s Open Banking Regulatory Intelligence Guide

Jun 29, 2026 | NCFA Resource | Open Banking Open Finance, Regulation And Policy

Last updated: September 11, 2026

Canada open banking and Consumer Driven Banking regulatory intelligence guide

Canada Open Banking Rules For Readiness And Consultation

NCFA has published a new Regulatory Intelligence guide to Canada Open Banking and Consumer Driven Banking Rules. The interactive resource organizes the proposed regulations, implementation requirements, consultation questions and strategic issues shaping Canada’s regulated open banking framework.

For a broader view of Open Banking and Consumer-Driven Finance, including the Canadian market map, 146 learning modules, company intelligence, global benchmarks and interactive discussions, explore NCFA Open Banking & Consumer-Driven Finance Interactive Intelligence.

The guide tracks accreditation, data scope, consent, authentication, security, technical standards, liability, reporting, complaints, national security review, fees and administrative monetary penalties. It also explains why consumer trust, fraud prevention and clear accountability are central to implementation. For further analysis, see Canada's Open Banking Strategy Starts With Trust.

What It Does In Practice

The resource gives readers a structured way to understand what the proposed Consumer Driven Banking Regulations would require before final rules are published.

Instead of treating the regulations as one long legal document, the guide breaks them into operating topics. Each section separates regulatory requirements, implementation work, consultation considerations and NCFA’s strategic perspective.

Canada’s open banking framework is progressing from policy design into regulatory implementation. Firms need to understand more than API access. They need to prepare evidence for accreditation, consumer consent flows, registry checks, authentication records, security safeguards, breach response, complaint procedures, service standards, reporting obligations and board level accountability.

The 60-day Canada Gazette consultation closed on August 26, 2026. The proposed regulations remain subject to finalization, while firms continue preparing for accreditation, supervision, data-sharing, consent, security and operational requirements.

Who Gets Value

This resource is useful for fintech founders, open banking platforms, financial institutions, credit unions, payment service providers, data aggregators, regtech providers, compliance teams, investors, policymakers and industry associations.

It is especially useful for organizations assessing accreditation, product design, consent architecture, data sharing duties, technical standards, cybersecurity, consumer protection and implementation costs.

Strengths And Limits

The strength of this resource is its focus on regulatory readiness. It converts the proposed Consumer Driven Banking Regulations into a practical intelligence layer that can support planning, consultation, product design and ecosystem coordination.

The guide connects the proposed regulations to Canada’s policy objectives, including stronger consumer protection, fraud mitigation, secure financial data sharing, competition and confidence in the open banking framework.

It also connects regulation to commercial opportunity. The guide identifies where read access, data portability, identity and income verification, cash flow analysis, embedded workflows, write access and open finance may create future product and infrastructure demand.

The regulations remain proposed and may change following consultation. Readers should use the guide for ecosystem intelligence and planning, not as legal, financial, investment, compliance or professional advice.

Key Resources

Canada Open Banking and Consumer Driven Banking Rules (primary NCFA Regulatory Intelligence guide)

NCFA Open Banking & Consumer-Driven Finance Interactive Intelligence (market map, 146 learning modules, company intelligence, discussions and global benchmarks)

Canada's Open Banking Strategy Starts With Trust (consumer protection and fraud readiness)

Open Banking In Canada Opportunity Brief (commercial opportunity layer)

NCFA Financial Innovation Map (ecosystem context)

Proposed Consumer-Driven Banking Regulations (official Canada Gazette source)


National Crowdfunding and Fintech Association of CanadaThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Canada Open Banking and Consumer Driven Banking Rules

NCFA Regulatory Intelligence - Canada Open Banking And Consumer Driven Banking Rules
NCFA Canada | Regulatory Intelligence | Open Banking and Consumer Driven Banking | Last updated September 11, 2026 | Status proposed regulations, consultation closed
NCFA Regulatory Intelligence
This guide explains Canada’s open banking framework through the proposed Consumer Driven Banking Regulations, including accreditation, consent, data sharing, security, liability, supervision and implementation. Sources include the Canada Gazette, the Regulatory Impact Analysis Statement, the Consumer Driven Banking Act, Finance Canada, Bank of Canada materials and the Office of the Privacy Commissioner of Canada’s August 26 submission.
Canada Open Banking

Proposed Consumer Driven Banking Regulations

Canada Open Banking and Consumer Driven Banking Rules

Canada’s proposed Consumer Driven Banking Regulations establish the operating framework for open banking. They address accreditation, consumer consent, data sharing, security, technical standards, liability, complaints, reporting, national security review and enforcement.

Use this guide to understand the proposed requirements, the implementation work they create and the post-consultation issues that may affect banks, credit unions, payment service providers, fintechs, consumers and small businesses.

The 60-day consultation closed August 26, 2026. The regulations remain proposed while Finance Canada considers feedback and prepares the next regulatory steps. Firms can use the published draft for planning, but final requirements and implementation timing may still change.

For a broader view of Open Banking and Consumer-Driven Finance beyond the regulatory framework, explore NCFA Open Banking & Consumer-Driven Finance Interactive Intelligence, including the Canadian Market Map, 146 learning modules, company intelligence, discussions, innovation themes and global benchmarks.

Canada’s Open Banking and Consumer Driven Banking Journey

Canada has advanced from open banking policy development into proposed Consumer Driven Banking Regulations under Bank of Canada oversight. The consultation closed on August 26, 2026. The current stage is regulatory finalization and supervisory preparation.
Launch read access and data mobility
Next write access
Consultation2018 to 2022 open banking policy review
Framework2023 to 2024 Consumer Driven Banking design
2026 Currentconsultation closed, final rules pending Bank of Canada supervision framework and implementation preparation
Read Accesslaunch phase secure data sharing and data mobility
Data Productsnear term verification, cash flow and embedded workflows
Write Accessnext phase payment initiation and account actions
Open Financelonger term broader financial product scope

Impact Analysis

Key figures from the Regulatory Impact Analysis Statement and proposed regulations.
$13.2BEstimated 10 year benefits
$457.7MEstimated 10 year costs
9MCanadians using data sharing services
680Affected businesses in central scenario
578Small businesses affected
$89,133Average annualized small business cost estimate
99.5%Monthly endpoint availability
$10MMaximum entity or ATPSP penalty

Regulatory Intelligence Explorer

Navigate the proposed regulations by topic. Each section separates requirements, implementation work, post-consultation issues to watch and NCFA’s strategic perspective.

Overview

Requirements The proposed regulations support implementation of the Consumer Driven Banking Act and create the operating layer for Canada’s open banking framework. They prescribe the data covered by the Act, accreditation information and requirements, accreditation fees, review timelines, revocation notices, accredited third party service provider requirements, national security information requirements, Ministerial review timelines, data sharing duties, exceptions to sharing, service standards, security safeguards, breach reports, responsible officer information, authentication steps, consumer signs, change notices, annual reporting, record keeping, liability related consumer notices, complaint procedures, technical standards body reporting, evidentiary privilege, assessments, administrative monetary penalties and coming into force rules.
  • Definition of Act and prescribed covered data
  • Accreditation applications for federal or provincial financial institutions, RPAA registered payment service providers, other entities and accredited third party service providers
  • Bank of Canada electronic application system, accreditation fee, refusal review and revocation processes
  • National security information package, Ministerial decision period, review period, extensions and review rights
  • Registry based verification before sharing data and exceptions where sharing can be withheld
  • Service standards for response times, endpoint availability, planned outages and traffic management
  • Security safeguards, breach reporting and responsible officer reporting
  • Authentication, acknowledgement and consent connected to secure data sharing
  • Notices, annual reporting, record keeping, liability, complaints, technical standards body reporting, assessments and violations
Implementation Organizations should build a regulatory inventory that maps each requirement to a system, policy owner, evidence file and supervisory reporting obligation. The Bank of Canada says its supervisory framework will cover participating entities, governance, risk management, operational resilience and monitoring of trends and issues. The first implementation work is not only API build. It includes accreditation evidence, national security information, data classification, registry checks, consent design, authentication records, breach playbooks, service monitoring, complaint intake, record retention, change notices, fee modelling, ATPSP contracts and board level accountability.
Post-Consultation Watch
  • Whether the framework gives enough implementation runway between final regulations, Bank of Canada guidance and coming into force
  • Whether proportionality is strong enough for small firms and RPAA registered payment service providers without reducing consumer trust
  • Whether guidance should clarify connections between fraud, consent, complaints, liability, security events and record keeping
  • Whether the technical standards body, conformance testing and service performance rules should be clearer before launch
  • Whether the cost and reporting model supports competition or favours organizations with existing compliance infrastructure
  • Whether consumers and SMEs will be able to understand which entities are accredited, which data is covered and how complaints or deletion requests work
August 26 Privacy Commissioner Submission The Office of the Privacy Commissioner of Canada supports the aims of consumer-driven banking and several privacy protections in the proposed regulations, but recommends changes before finalization.
  • Specify the individual data elements covered by the framework more clearly so consumers can understand what may be shared
  • Strengthen accreditation evidence in several pathways, including safeguards, complaints, authentication, dashboards, technical-standard evidence and selected insurance or integrity requirements
  • Narrow the consent exception for publicly available data so it does not capture information where a consumer has a reasonable expectation of privacy
  • Add an overarching requirement for safeguards appropriate to the sensitivity of the data as technology and threats change
  • Clarify coordination between the Privacy Commissioner and the Bank of Canada where privacy and supervisory responsibilities intersect
NCFA Perspective This is a trust and market structure test. Canada is defining the participation standard for a regulated financial data market. The strongest framework will not be the one with the most rules. It will be the one that makes safe participation practical, keeps consumer control understandable and lets credible new entrants compete without pushing the ecosystem into a narrow, incumbent led implementation path.

Application and Data

Requirements The regulations define the Act and prescribe the data to which the consumer driven banking framework applies. Covered data includes data relating to consumers of the covered products or services, account and product identifiers, the terms under which products and services are provided, balances or amounts owing, completed, pending and pre authorized transactions, and information about products or services available or offered to consumers. The data scope is tied to the products and services referred to in the Act and must be shared only through the regulated framework once the relevant duties apply.
  • Identity related data for consumers of covered products or services
  • Account numbers, branch numbers, transit numbers and other product or service identifiers
  • Product and service terms, including fees, interest rates and authorizations
  • Current and past balances or amounts owing
  • Completed, pending and pre authorized transaction data
  • Information about products or services available or offered to consumers, including terms
  • Historical limits apply in the data sharing rules for balances, transactions and available or offered products and services older than 24 months
  • Covered data must be tied to a valid data sharing request, participant verification, consumer authentication and consent
Implementation Participants need a data inventory that maps each covered category to source systems, product owners, API fields, consent screens, retention rules, deletion workflows, complaints, liability records and service monitoring. Data providers should identify where product terms, balances, transaction history and account identifiers are stored, how far history is available, what data is excluded, and how data quality issues will be handled when another participant relies on the information.
Post-Consultation Watch
  • Whether Finance Canada adopts the Privacy Commissioner’s recommendation to specify the individual data elements within each covered category more clearly
  • Whether the treatment of derived, inferred or enriched data needs clearer boundaries
  • Whether the 24 month historical limit is sufficient for SME finance, lending, accounting and cash flow use cases
  • Whether business accounts, joint accounts, delegated authority and multi user permissions need more detailed guidance
  • Whether future open finance expansion should be signalled earlier to reduce later redesign
  • Whether data quality, correction and dispute processes need a clearer connection to complaints and liability
NCFA Perspective Data scope is the first market boundary. A narrow read access model can still support verification, underwriting, cash flow analysis, switching, accounting and embedded workflows. The larger Canadian opportunity depends on whether this foundation can expand cleanly into write access, payment initiation and broader open finance without rebuilding the trust layer from scratch.

Accreditation

Requirements The accreditation rules prescribe different application pathways for federal or provincial financial institutions, RPAA registered payment service providers, other entities and accredited third party service providers. Applications must be submitted through the Bank of Canada electronic system. Common information includes legal and trade names, formation details, civic and mailing addresses, contact information, website, application contact, organizational and governance structure, regulatory or supervisory oversight, foreign open banking registration or accreditation status, designated officer or employee details, consumer complaint contact information, technical standard evidence and national security information. RPAA registered PSPs and other entities must also provide Canadian place of business declarations, whether they operate from a dwelling house, independent third party confirmation of security safeguards, insurance or guarantee evidence, and integrity and good character policies for individuals with significant responsibility. Other entities must additionally describe how they will meet specified Act requirements, complaint procedures, external complaints body membership status and estimated consumer numbers.
  • Federal or provincial financial institution applications include security compliance declaration, designated officer details, complaint contact, technical standard evidence and national security information
  • RPAA registered PSP applications include Canadian place of business, dwelling house declaration, independent security confirmation, technical standard evidence, insurance or guarantee and integrity policy or good character information
  • Other entity applications include similar information plus descriptions of how they will meet specified duties, complaint procedures, external complaints body membership and estimated consumer numbers
  • RPAA registered PSPs and other entities must maintain place of business, insurance or guarantee and integrity or good character requirements after accreditation
  • The accreditation fee is $2,500 in the first year and then indexed to September CPI, rounded to the nearest $100, with no decrease from the previous year
  • An applicant has 30 days to request Governor review of an accreditation refusal, and the Governor has 120 days after giving an opportunity to make representations to accredit or confirm refusal
  • Participating entities requesting voluntary revocation must provide consumers with name and contact, planned request date, impact assessment, deletion notice and complaint resolution information
  • A participating entity has 30 days to request Governor review of a notice of intent to revoke accreditation, and the Governor has 60 days after giving an opportunity to make representations to revoke or withdraw the notice
  • Former participating entities must notify consumers of revocation date, reasons, impact, deletion request requirement and complaint process
  • Accredited third party service provider applications include legal information, activity description, participating entity relationships, Canadian place of business, independent security confirmation, technical standard evidence, contract and policy information and national security information
Implementation Applicants should build a complete accreditation evidence file before applying. That file should include corporate and governance documents, regulatory status, technical standard evidence, security confirmation, insurance or guarantee evidence, complaint process, designated officer details, integrity policy, national security information, contracts with participants where relevant and consumer impact notices for potential exit. RPAA registered PSPs should map which information can be reused from RPAA registration and which requirements are new under CDB.
Post-Consultation Watch
  • Whether final accreditation rules adopt the Privacy Commissioner’s recommendations for stronger evidence in selected pathways, including safeguards, complaints, authentication, dashboards, technical-standard compliance, insurance or guarantees and integrity checks
  • Whether the independent third party confirmation of security safeguards should have defined qualifications or assurance standards
  • Whether insurance or guarantee sufficiency needs guidance so applicants can price participation
  • Whether the dwelling house declaration could create unnecessary ambiguity for remote first firms
  • Whether refusal, revocation and review timelines are workable for firms planning launch and funding milestones
  • Whether ATPSP accreditation requirements are clear enough for infrastructure providers that will support multiple participating entities
NCFA Perspective Accreditation sets the practical threshold for market participation. If evidence requirements are too light, the framework risks weak trust. If they are too heavy, innovation may concentrate among large institutions and compliance funded platforms. The policy challenge is not choosing between safety and competition. It is designing entry rules that reward credible operators without making participation uneconomic for the firms most likely to create new consumer and SME products.

Authentication and Consent

Requirements The proposed rules connect data sharing to verification, consumer authentication and consent. A participant receiving a request must verify the requesting entity and confirm through the registry that it is an accredited participating entity and not suspended in a way that prevents receiving data. A participant requesting data must verify the provider and confirm through the registry that the provider is accredited and not suspended in a way that prevents providing data. Authentication requires confirmation of the consumer’s authentication information using multi factor authentication. The consumer must acknowledge the requesting participant’s name, the nature of the request and the accounts from which the requested data will be provided before the data is shared and the consumer is redirected.
  • Requester and provider verification against the registry before sharing
  • Confirmation that accreditation has not been suspended or restricted by Bank conditions
  • Multi factor authentication of the consumer’s authentication information
  • Consumer acknowledgement of the requesting entity, nature of the request and relevant accounts
  • Data sharing only after verification, authentication and acknowledgement requirements are met
  • Renewal may be required after circumstances where data sharing was not required or consent has not yet been renewed
  • Consent evidence must connect to records, deletion requests, liability, complaints and annual reporting
Implementation Participants need registry lookup, accreditation status checks, suspension condition logic, MFA, acknowledgement capture, consent evidence, renewal workflows, revocation and deletion links, exception handling and audit trails. Authentication and consent should not be built as a user interface layer only. They need to produce evidence that can support annual reporting, complaint resolution, breach response, liability allocation and supervisory review.
Post-Consultation Watch
  • Whether the registry verification workflow is operationally clear for real time data sharing
  • Whether MFA requirements align with existing bank and fintech authentication journeys
  • Whether consent and acknowledgement guidance makes the sharing scope sufficiently specific for consumers to understand what information is captured
  • Whether consent renewal triggers and failed renewal situations need clearer examples
  • Whether consumer dashboards, consent receipts and cross provider visibility should be addressed in guidance
  • Whether consent evidence is sufficient to resolve liability, complaint and deletion disputes
NCFA Perspective Consent is one of the highest trust points in the framework. The market will not fail because consent screens are hard to build. It will fail if consumers cannot understand them, if participants cannot prove what was authorized, or if revocation and deletion are too hard to execute. This is where compliance design and product design become the same problem.

Security

Requirements The regulations prescribe detailed security safeguards for participating entities. Safeguards include vulnerability identification and remediation, regular updates, secure default configuration, security software, robust authentication, access management policies, unique accounts, data encryption and backup, network security controls, external storage policy, bans on unauthorized devices and applications, network traffic monitoring, suspicious content controls, inventory of systems and devices, third party service provider contract protections, employee cyber threat training and an incident response plan with log auditing and periodic exercises based on extreme but plausible scenarios. Safeguards must be proportionate to data sensitivity and network segmentation is permitted. Federal and provincial financial institutions are presumed to have implemented safeguards unless OSFI or the relevant provincial authority has identified deficiencies and directed remediation.
  • Vulnerability management and regular updates
  • Secure configuration by default
  • Security software on relevant systems and devices
  • Robust authentication methods
  • Role based access management policies
  • Unique accounts and minimized shared accounts
  • Encryption and regular backup of stored data
  • Network security controls for data in transit
  • External storage policy
  • Prohibition on unauthorized devices and applications
  • Monitoring and control of network traffic
  • Suspicious content identification, quarantine or blocking
  • Inventory of systems and devices used for sharing and storing covered data
  • Contract terms requiring third party service provider protection of data
  • Employee cyber threat training and ongoing updates
  • Incident response plan with detection, response, recovery, log auditing and scenario exercises
  • Responsible officer or employee details must be provided to the Bank without delay after designation
  • Breach reports to the Bank must include circumstances, known cause, date or period, affected data, number of consumers, potential impacts, mitigation and contact information
Implementation Participants should treat security as an accreditation and operating evidence file. Required work includes asset inventory, vulnerability program, configuration standards, endpoint and system security, identity and access controls, encryption, backup, network monitoring, third party contract review, cloud and vendor risk, cyber training, incident response testing, breach reporting templates and escalation paths to the Bank. Security records should be aligned with annual reporting, complaint records and liability evidence.
Post-Consultation Watch
  • Whether final rules add the Privacy Commissioner’s recommended overarching requirement for safeguards appropriate to data sensitivity as technology and threats change
  • Whether independent third party confirmation should follow a defined assurance framework
  • Whether breach reporting timing, consumer notification thresholds and report updates need more prescriptive examples
  • Whether third party and cloud contract requirements should include subcontractor and data location obligations
  • Whether small entrants can meet the same security evidence burden without shared infrastructure
  • Whether fraud, identity, authentication and cyber controls should be addressed together in Bank guidance
NCFA Perspective Security is the trust anchor. Consumer driven banking exists partly to replace unsafe credential sharing with supervised data access. That only works if security is operationally real, not a paper control. The framework must be strong enough to protect consumers and flexible enough that security compliance does not become the reason only the largest organizations can participate.

Technical Standards

Requirements The technical standard provisions operate through the Act and the regulations. Applicants must provide evidence of compliance with the technical standard referred to in the Act. Participating entities must declare technical standard compliance in annual reports. Data sharing systems must meet response time expectations consistent with generally accepted international standards, maintain 99.5 percent monthly availability excluding planned outages, and use traffic management only for technical stability or security in a proportionate, non discriminatory way. The technical standards body must submit an annual report to the Bank within seven days after each anniversary of its designation order. That report must describe vulnerabilities in the technical standard or standards body that had or could have had an impact on the security of data sharing, non technical descriptions of changes to data fields, features, functionality or other security relevant aspects of the technical standard, rationale and decision process for those changes, and changes relevant to the body’s designation.
  • Applicants must provide technical standard compliance evidence
  • Participating entities must report annual technical standard compliance
  • API or electronic system response times must align with generally accepted international standards
  • Data sharing systems must meet 99.5 percent monthly availability, excluding planned outages
  • Rate limiting, throttling and preferencing are restricted to stability and security purposes
  • Traffic management must be proportionate, non discriminatory and must not degrade consumer outcomes
  • Technical standards body annual report is due within seven days after each designation anniversary
  • Technical standards body must report vulnerabilities, causes, impacts, mitigation and contact person
  • Technical standards body must describe changes to data fields, features, functionality or security relevant aspects, plus rationale and decision process
  • Technical standards body must describe changes relevant to its designation factors
Implementation Technical teams need API inventory, conformance evidence, performance monitoring, availability measurement, outage notification, traffic management governance, test environment planning, error handling, historical data readiness, change management and documentation that can support Bank supervision. Firms should prepare for technical standard versioning and for annual evidence that systems remained compliant through the reporting year.
Post-Consultation Watch
  • Whether the technical standards body should be identified or its governance clarified before final implementation planning
  • Whether conformance testing should be mandatory before production access
  • Whether response time expectations should be converted into measurable standards
  • Whether 99.5 percent availability is sufficient for higher value financial workflows
  • Whether public reporting of availability, outages and API performance would strengthen trust
  • Whether technical standard changes should have notice periods, backwards compatibility expectations and migration timelines
NCFA Perspective Technical standards are where the framework becomes real infrastructure. Canada’s competitive position will depend less on whether APIs exist and more on whether standards, testing, versioning and change management let participants build once and scale. Ambiguity here can turn regulatory permission into integration drag.

Liability

Requirements The liability provisions clarify consumer responsibility and the allocation of responsibility between participating entities. Every participating entity must inform consumers of the consequences of gross negligence or, in Quebec, gross fault in safeguarding authentication information. It must advise consumers of reasonable measures they can take to safeguard authentication information. It must not intentionally mislead consumers about the extent of their liability or adopt policies that presume consumer liability contrary to the Act. Where a consumer is not liable for a financial loss arising from loss, unauthorized access or unauthorized use of data shared under the Act, liability between participating entities is determined by where the loss, access or use occurred. The requester is liable to the extent it occurs in relation to the requester securely receiving or managing the data. The provider is liable to the extent it occurs in relation to provider authentication or secure provision of the data.
  • Consumers must be informed about gross negligence or gross fault consequences for authentication information
  • Consumers must be advised of reasonable safeguarding measures
  • Participants must not mislead consumers about liability
  • Participants must not adopt policies presuming consumer liability contrary to the Act
  • Requester liability follows failures connected to receiving or managing data
  • Provider liability follows failures connected to authenticating the consumer or securely providing data
  • Liability evidence depends on consent, authentication, registry checks, transmission logs, receipt records, complaint files and incident records
Implementation Participants should prepare consumer notices on authentication information, avoid default liability language, align customer support scripts with the Act, and preserve records that show where an event occurred. Liability operations require authentication logs, consent evidence, registry verification, data transmission records, receipt confirmations, access logs, incident investigations, complaint handling and remediation decisions.
Post-Consultation Watch
  • Whether gross negligence or gross fault communications will be understandable for consumers
  • Whether liability allocation is clear enough for multi party flows involving ATPSPs
  • Whether examples should clarify direct financial loss, unauthorized access, data loss and failed revocation
  • Whether consumer support and complaint processes need stronger alignment with liability rules
  • Whether records required to prove liability should be specified more explicitly
  • Whether fraud and scam scenarios are sufficiently covered by the liability architecture
NCFA Perspective Liability will be tested in edge cases, not in clean diagrams. The strategic issue is whether the framework can resolve consumer harm quickly without turning every incident into a multi party blame exercise. Clear evidence rules can build trust. Unclear responsibility can undermine adoption even if the technology works.

Reporting Requirements

Requirements The proposed regulations require change notices, annual reports and records sufficient to demonstrate compliance. Changes that must be reported include names or contact information, organizational structure, RPAA registration status for entities accredited under the RPAA pathway, Canadian regulatory oversight, foreign open banking registration or accreditation, designated officer contact, complaint contact, external complaints body membership, significant responsibility individuals and integrity status, insurance or guarantee sufficiency, technical standard compliance and national security information. Some changes must be reported within 30 days after they occur, some as soon as feasible after awareness, some at least 30 days before taking effect and some at least 60 days before taking effect. Annual reports must provide monthly metrics on non sharing events, express consents, consent renewals, withdrawals, deletion requests, system availability, data sharing counterparties, successful data provisions and average response time. They must also include changes, policy and procedure updates, breach summaries, planned and unplanned outages, technical standard declaration, financial metrics, supervisory deficiency declarations for financial institutions and security safeguard implementation descriptions for certain accredited entities. Records must be sufficient to demonstrate compliance, kept electronically in a format intelligible to the Bank, retained for five years after they cease to demonstrate current compliance unless otherwise specified, and protected against loss, destruction, falsification, inaccuracy and unauthorized access or use.
  • Notice of change categories cover identity, structure, registration, oversight, foreign accreditation, officers, complaints, EBC membership, significant responsibility individuals, insurance or guarantee, technical standard compliance and national security information
  • Notice timing includes 30 days after occurrence, as soon as feasible, at least 30 days before certain changes and at least 60 days before certain data storage or processing country changes
  • Annual report metrics include monthly non sharing counts and reasons
  • Annual report metrics include express consents, renewals, withdrawals and deletion requests
  • Annual report metrics include uptime, data sharing counterparties, delivery counts and average response time
  • Annual report must include changes, policy updates, breach summary, outages, technical compliance declaration and financial metrics
  • Records must demonstrate compliance with the Act and regulations
  • Records must be electronic and intelligible to the Bank
  • Records must generally be kept for five years after they cease to demonstrate current compliance
  • Records must be protected from loss, destruction, falsification, inaccuracies and unauthorized access or use
  • ATPSPs must keep compliance records, contracts with participants and policies or procedures relating to services they perform for participants, with the same electronic form and protection rules
  • Certain supervisory information, Bank directions, compliance agreements and supervisory correspondence are privileged for civil evidence purposes, with specified exceptions for use by the Minister, Governor, Bank, Attorney General of Canada, participants or ATPSPs in certain proceedings
Implementation Participants need a compliance data model that captures events as they happen. Manual annual reporting will be fragile. Systems should collect consent events, renewal events, withdrawal events, deletion requests, non sharing reasons, uptime, response time, outage data, breaches, policy changes, material changes, complaint records and financial metrics. Record retention and protection should be built into the architecture before production data flows begin.
Post-Consultation Watch
  • Whether the notice timing categories are clear enough for operational teams to apply consistently
  • Whether annual reporting should align with RPAA and other Bank of Canada reporting regimes where possible
  • Whether public transparency reporting on uptime, outages, complaints and non sharing events would strengthen trust
  • Whether smaller firms need proportional reporting without weakening supervisory visibility
  • Whether five year record retention is practical across all evidence categories
  • Whether privileged supervisory information rules strike the right balance between supervision, litigation risk and transparency
NCFA Perspective Reporting and records are the hidden operating system of regulated open banking. They may matter more than any single product feature because they determine whether trust can be audited, problems can be reconstructed and smaller firms can participate without building a bank sized compliance department.

Complaints

Requirements The regulations require complaint handling information at accreditation and connect complaints to revocation notices, consumer contact information, external complaints body membership and records. Other entity applicants must describe intended complaint procedures, the officers or employees to be designated for complaint responsibilities, and the contact information consumers will use. A participating entity requesting revocation or a former participating entity whose accreditation has been revoked must provide consumers with information about the process for resolving outstanding complaints. Annual reporting must describe changes to complaint related procedures. Record keeping must support compliance and complaint evidence. ATPSPs must keep contracts and related policies or procedures where they perform activities for participating entities.
  • Complaint contact information is required in accreditation applications
  • Other entity applications must describe complaint procedures and designated complaint roles
  • External complaints body membership status is required for certain applicants
  • Revocation and former participant notices must include complaint resolution information
  • Complaint processes connect to annual reporting and record keeping
  • Complaint evidence should align with consent, authentication, data sharing, security, breach and liability records
Implementation Participants should design complaint intake, triage, escalation, evidence review, consumer communication, external complaints body routing, remediation, root cause analysis and reporting. Complaint workflows should identify whether the issue relates to access, failed sharing, revoked consent, deletion, fraud, data quality, breach, liability or service availability.
Post-Consultation Watch
  • Whether complaint timelines and escalation expectations should be more explicit
  • Whether consumers will know whether to contact the provider, requester, ATPSP, bank or external complaints body
  • Whether SMEs need distinct complaint pathways for business account use cases
  • Whether complaint data should feed into supervisory or public transparency reporting
  • Whether complaints involving data quality, failed sharing, deletion or fraud require specific treatment
NCFA Perspective Complaint handling will be a public trust signal. Consumers rarely judge infrastructure by how it works on a perfect day. They judge it by what happens when something breaks, money is lost, access fails or nobody knows who is responsible.

National Security Review

Requirements The regulations prescribe extensive information for national security review and timelines for Ministerial decisions. Applicants must provide information about legal name, trade names, jurisdictions, addresses, contact information, business activities, financial services, affiliates, ownership and control, individuals or entities with significant voting or ownership interests, board members, highly compensated senior officers, major creditors, state owned enterprise ownership or appointment powers, categories of personal or financial information gathered or planned to be gathered, countries where the applicant or third party service providers store or process that information, and individuals or entities outside employees or agents that may receive access to that information. The Minister has 60 days after receiving the application copy to decide whether to review, with extensions in 60 day periods. If a review proceeds, the Minister has 180 days, with 180 day extensions. Applicants have 30 days to request review of a directive to refuse accreditation. Applicants must provide requested additional information within 30 days. For suspension and revocation, participants or ATPSPs have 30 days to request review of a notice of the Minister’s intent to direct revocation. Former participants and former ATPSPs must provide specified information to consumers or participating entities. Additional information requested by the Bank must be provided within 15 days.
  • Ownership, control, affiliates, significant influence and voting or ownership interest information
  • Countries of residence, citizenship, incorporation or formation for relevant individuals and entities
  • Board member and five most highly compensated senior officer information
  • Five largest creditors and credit agreement terms
  • State owned enterprise ownership, voting interest or appointment powers
  • Categories of personal and financial information gathered or planned, including identifying information, financial data, private communications and geolocation data
  • Countries where applicant or third party service providers store or process information
  • Non employee or non agent individuals or entities that may access the information
  • 60 day Ministerial decision window to review, extendable by 60 day periods
  • 180 day national security review period, extendable by 180 day periods
  • 30 day applicant review request period for refusal directive
  • 30 day period to provide additional requested information under subsection 54(2)
  • 30 day review request period for notice of intent to direct revocation
  • 15 day period to provide additional information requested by the Bank under subsection 71(2)
Implementation Applicants should prepare a national security file before applying, not after questions arrive. That file should include ownership charts, control analysis, citizenship and residency information, affiliates, creditors, SOE exposure, data categories, data storage and processing locations, cloud and vendor access, third party access, board and senior officer information, and change monitoring. Deal teams should assess how fundraising, acquisitions, data residency, vendor changes and cross border processing could affect review risk.
Post-Consultation Watch
  • Whether the national security information package is proportionate for lower risk applicants
  • Whether significant influence, creditor exposure and third party access require clearer guidance
  • Whether data residency and cross border processing expectations should be clarified before applications begin
  • Whether the 60 day and 180 day review timelines could materially affect investment, partnership and launch planning
  • Whether applicants should have a pre filing process or informal guidance pathway for complex ownership structures
  • Whether national security review should be harmonized with broader financial infrastructure, digital identity and cloud risk policy
NCFA Perspective This connects open banking to financial infrastructure security. It is not a side process. National security review can affect who enters the market, which investors participate, where data is processed, which vendors are acceptable and how exits are structured. If handled clearly, it can strengthen trust. If handled opaquely, it can slow capital and partnership formation.

Assessments and Fees

Requirements The regulations set an indexed accreditation fee and annual assessments. The accreditation fee is $2,500 in the year the section comes into force. In later years it is calculated as $2,500 multiplied by the ratio of the September all items CPI for Canada in the year before application to the September CPI in the year the section comes into force, rounded to the nearest $100, with no decrease from the previous year. Participating entity assessments are calculated as base assessment plus variable assessment minus interim assessments. Base assessments depend on total asset value. Entities with at least $1 trillion in assets pay a $150,000 base amount; $100 billion to under $1 trillion pay $100,000; $10 billion to under $100 billion pay $50,000; $1 billion to under $10 billion pay $20,000; and under $1 billion pay $10,000. Variable assessment shares allocate remaining Bank costs after deductions by asset tier using 0.4, 0.3, 0.2 and 0.1 factors for the larger asset tiers, while the under $1 billion category has no variable amount. Subsidiary assets are excluded where the subsidiary is itself a participating entity. ATPSPs are assessed $10,000 per year less interim assessments. The external complaints body is assessed $50,000 per year less interim assessments, reduced proportionally for a partial year. Information requested about assets must be provided by March 31 following the relevant calendar year when requested by December 31, or within 15 days for other requests. If asset information is not provided on time, the entity is treated as being in the highest asset category for assessment purposes.
  • $2,500 first year accreditation fee
  • CPI indexed accreditation fee after first year, rounded to nearest $100 and not allowed to decrease
  • Participating entity assessment equals base assessment plus variable assessment minus interim assessment
  • Base assessment tiers of $150,000, $100,000, $50,000, $20,000 and $10,000 based on total assets
  • Variable assessment shares of 0.4, 0.3, 0.2 and 0.1 for larger asset tiers
  • No variable assessment for entities with less than $1 billion in assets
  • ATPSP annual assessment of $10,000 less interim assessments
  • External complaints body annual assessment of $50,000 less interim assessments, prorated for partial year designation
  • Asset information deadline of March 31 in specified cases and 15 days in other cases
  • Failure to provide asset information can result in assessment as if the entity were in the highest asset category
Implementation Participants should model accreditation fees, annual assessment tier, possible variable assessment, interim assessments, ATPSP fees, external complaints body implications, insurance or guarantee costs, technical build, security assurance, reporting systems and compliance staffing. Smaller firms should assess whether direct participation, ATPSP services, partnership or staged entry creates a viable cost structure.
Post-Consultation Watch
  • Whether the base assessment tiers are proportionate for mid sized and smaller participants
  • Whether the zero variable assessment for under $1 billion firms is enough to support competition
  • Whether ATPSP fixed fees support shared infrastructure economics
  • Whether asset based assessment is the right proxy for supervisory cost or market impact
  • Whether fee predictability is sufficient for early entrants and investors
  • Whether the highest tier default for missing asset information is too punitive or necessary for compliance discipline
NCFA Perspective The fee schedule is only one part of participation cost. The strategic issue is total regulatory operating cost. If cost scales poorly, Canada could see a market where participation is open in law but concentrated in practice. Shared infrastructure, clear guidance and proportionate reporting may determine whether smaller innovators can enter.

Administrative Monetary Penalties

Requirements The regulations designate violations for contraventions of a long list of Act provisions, specified regulation provisions, non compliance with compliance agreements and non compliance with Bank directions. The designated Act provisions include obligations related to accreditation, suspension conditions, former entity notices, ATPSP activities, prescribed information, data sharing, use of registry, privacy, security, designated officer, breach reporting, authentication, consent, deletion, notices, liability, complaints, records, technical standards, reporting, Bank information requests and other framework duties. The designated regulation provisions include failure to notify another participating entity of non sharing reasons, data sharing service standards, responsible officer information, specified reporting and notice provisions, record keeping provisions and ATPSP record keeping provisions. The Act provides maximum penalties of up to $1 million for individuals and up to $10 million for participating entities or ATPSPs.
  • Contraventions of numerous Act provisions are designated as violations
  • Contraventions of selected regulation provisions are designated as violations
  • Non compliance with compliance agreements is designated as a violation
  • Non compliance with specified Bank directions is designated as a violation
  • Regulation violations include non sharing notice failures, service standard failures, officer reporting failures, notice failures, annual reporting failures and record keeping failures
  • Maximum penalty of $1 million for individuals
  • Maximum penalty of $10 million for participating entities or ATPSPs
  • Penalty exposure connects to accreditation, data sharing, registry use, privacy, security, breach reporting, authentication, consent, deletion, liability, complaints, technical standards, reporting, records and Bank information requests
  • Coming into force is staged by Act sections, with most regulations coming into force when section 44 of the Act comes into force, data sharing and many operational obligations when section 76 comes into force, and assessment provisions when section 140 comes into force
Implementation Participants should map every designated violation to an internal control, evidence record and accountable owner. Enforcement readiness should cover consent, registry checks, non sharing notices, uptime, breach reporting, annual reporting, records, complaints, officer information, Bank information requests, compliance agreements and directions. Boards and senior leaders should understand which failures create individual or organizational exposure.
Post-Consultation Watch
  • Whether violation categories are clear enough for participants to map controls before launch
  • Whether penalty exposure is proportionate across firms of different size and role
  • Whether remediation and self reporting should affect penalty treatment
  • Whether public enforcement disclosure will be used to strengthen market discipline
  • Whether staged coming into force gives firms enough time to build controls before penalties apply
  • Whether individual exposure could affect senior officer recruitment and governance design
NCFA Perspective Penalty risk is less about the headline maximum and more about whether an organization can prove it had controls, records and remediation processes in place before something went wrong. Enforcement should strengthen trust without chilling responsible innovation. That balance will matter as Canada tries to turn regulatory credibility into market adoption.

Related NCFA Intelligence

Open Banking in Canada Opportunity BriefCommercial opportunity layer connected to this regulatory guide Open the brief
Financial Innovation MapWhere consumer driven banking fits in the broader fintech innovation ecosystem View the map
Research LibrarySupporting reports, market evidence and policy research Research library
Fraud regulatory perspectiveTrust, fraud controls and consumer protection context for Canada’s open banking strategy Read the fraud perspective

From Regulation to Opportunity

Canada’s proposed Consumer Driven Banking Regulations create readiness questions across accreditation, consent, data scope, APIs, cybersecurity, reporting, liability, supervision, national security review and enforcement. NCFA tracks commercial opportunities separately in the Open Banking in Canada Opportunity Brief, where regulatory evidence connects to product opportunities, investment themes, implementation gaps and emerging market signals.

Open the Opportunity Brief


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights

NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter