Karsten Wenzlaff, Advisor
August 26th, 2025
August 19, 2026 | NCFA Resource | Cybersecurity And Fraud, Risk Compliance And Regtech, Capital Markets And Market Infrastructure

In August 2026, the Financial Industry Regulatory Authority published Cybersecurity Effective Practices, a 12-part framework for FINRA member firms reviewing cybersecurity programs, controls and operating procedures. A firm can use the resource as a structured checklist for who owns cybersecurity, which systems and vendors create risk, who can access sensitive data, how threats are detected, and whether the business can recover when systems fail. FINRA designed the practices to scale with firm size, business model, technology complexity and risk profile.
FINRA organizes the resource around 12 areas:
The framework starts with accountability and risk ownership. FINRA recommends a designated cybersecurity lead, regular reporting to senior decision makers, documented policies and periodic reviews, while also making cyber risk part of decisions about new technology, systems and operating changes. From there, firms are expected to identify the information, systems and business functions they depend on, assess threats such as ransomware, insider activity and vendor exposure, test important systems for weaknesses and revisit those risks when technology or operations change.
Third party risk receives detailed treatment. FINRA treats vendors with access to customer information or critical systems as part of the firm’s security perimeter. Firms should know which vendors have access, understand important fourth party relationships and identify which providers support critical operations. Contracts can address audit rights, data handling, breach notification and visibility into subcontractors, while ongoing oversight should include access monitoring and a documented process for removing access and handling customer information when a relationship ends.
That concern extends beyond US broker dealers. Weak access control governance can expose sensitive information when a partner or service provider retains permissions that are unnecessary or poorly monitored. FINRA’s guidance connects vendor governance with the practical question of who can access systems and data, for how long, and under what controls.
Asset management and access control fit naturally together. FINRA recommends keeping a current inventory of hardware, software, cloud services and data flows, assigning owners to important assets and identifying systems that no longer receive security updates. Once firms know what they have, they can control who gets access through unique credentials, role based permissions, multifactor authentication, periodic entitlement reviews, segregation of duties and least privilege. Access should also be changed or removed promptly when employees change roles or leave.
Data protection, training and patching cover another part of the operating picture. Firms are encouraged to classify sensitive data, encrypt it at rest and in transit where feasible, control retention and protect backups, including with immutable or air gapped storage. FINRA also recommends ongoing employee training, role specific instruction for staff with sensitive access and phishing simulations backed by records of participation. Vulnerability management should include regular scanning, risk based patch priorities and verification that remediation work was completed rather than assumed.
The primary users are FINRA member broker dealers, including compliance teams, cybersecurity leaders, technology teams, operations executives and senior management. Smaller firms can use the 12 areas to identify where basic controls are missing without trying to copy the cybersecurity program of a much larger institution, while larger firms can use the same structure to review whether responsibilities, documentation and technical controls are working together.
Technology providers, managed security firms, consultants and RegTech companies serving broker dealers can also use the resource to understand what clients may expect around access, logging, vendor controls, data handling, patching, incident response and recovery. Boards and senior executives can use it as a governance checklist because FINRA makes cybersecurity ownership, management reporting, resource decisions and documented risk acceptance part of the program rather than leaving cyber risk entirely with the technology team.
The main strength is that FINRA connects governance directly to operating controls. A firm can follow the framework from senior accountability through asset inventories, identity controls, encryption, training, monitoring and recovery testing, which makes the document more useful than a high level cyber policy statement.
Third party risk is also handled with more depth than a basic checklist. Firms are expected to understand vendor dependencies, monitor privileged access, address fourth parties and plan how systems and data will be handled when a provider relationship ends. Security monitoring extends that discipline to unusual access, suspicious data transfers, system changes and privileged accounts, with logs retained long enough to support operations, investigations, forensic work and applicable recordkeeping requirements.
The framework also includes threat intelligence, incident response and recovery. FINRA recommends using relevant threat feeds, updating defenses as attack methods change and participating in trusted information sharing networks. Incident response focuses on how a firm detects, escalates and contains an event, while recovery planning deals with how critical systems and data return to service afterward. Tested backups, tabletop exercises, offline procedures and defined Recovery Point Objectives and Recovery Time Objectives all help firms decide how much data loss and downtime different systems can tolerate.
The main limitation is jurisdiction. FINRA developed the resource for US member firms and connects several practices to US requirements, including SEC Regulations S-P and S-ID, FINRA Rules 3110 and 4370, and Exchange Act recordkeeping rules. The document also doesn't create new legal or regulatory requirements or reinterpret existing ones. For Canadian financial technology and service firms, its best use is as a practical comparison and control review, not as a statement of Canadian regulatory obligations.
FINRA Cybersecurity Effective Practices (12-part cybersecurity control framework)
Cybersecurity Effective Practices PDF (downloadable nine page resource)
Small Firm Cybersecurity Checklist (small firm program checklist last reviewed February 2024)
Core Cybersecurity Threats And Controls (small firm threats and control questions)
FINRA Cybersecurity Resources (cybersecurity tools, guidance and related material)
2026 Cybersecurity And Cyber Enabled Fraud (current threats and effective practices)
Proposed Class Action Targets Equifax Access Controls (access governance and third party permissions)
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: [www.ncfacanada.org](http://www.ncfacanada.org)
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Aug 8, 2026 | NCFA Fintech Whisperer | Digital Banking And BaaS, Regulation And Policy, SME Finance And Business Banking, Digital Assets Blockchain And Tokenization, Payments Infrastructure And Money Movement, Capital Markets Infrastructure And Funding, Artificial Intelligence And Data, Wealthtech Investing And Trading, Embedded Finance, Risk Compliance And Regtech, Lending Consumer Credit And BNPL, Cybersecurity Fraud And Financial Crime

Image: Freepik
This live weekly NCFA intelligence page tracks financial technology developments that significantly affect how fintechs build, sell, raise capital, and operate under scrutiny. Coverage prioritizes Canada and includes global events that directly influence competitive conditions, market access, and execution realities across fintech sectors. This page will be updated throughout the week with market movers in a live format and then each week we'll close the prior week's contents in prep for the upcoming week, and continue on a rolling basis. (Missed prior week's Fintech Whisperer? (December 6-12, 2025, December 13-19, 2025, January 1-9, 2026, January 10-16, 2026, January 17-23, 2026, January 24-30, 2026, January 31-February 6, 2026, February 7-13, 2026, February 14-20, 2026, February 21-27, 2026, February 28-March 6, 2026, March 7-13, 2026, March 14-20, 2026, March 21-27, 2026, March 28-April 3, 2026, April 4-10, 2026, April 11-17, 2026, April 18-24, 2026, April 25-May 1, 2026, May 2-8, 2026, May 9-15, 2026, May 16-22, 2026, May 23-29, 2026, May 30-June 5, 2026, June 6-12, 2026, June 13-19, 2026, June 20-26, 2026, June 27-July 3, 2026, July 4-July 10, 2026, July 11-July 17, 2026, July 18-24, 2026, July 25-July 31 2026, August 1-August 7, 2026).
Large crypto platforms are starting to look more like multi asset investment distributors, but the infrastructure underneath them is still regulated brokerage, custody and settlement. Alpaca has been building specifically for this role, which NCFA recently examined in its global brokerage platform expansion. The competitive question is who controls that regulated layer as crypto, traditional securities and tokenized products converge inside the same customer interface.
IBQT changes where the crypto allocation decision happens. Investors choosing the fund are buying a diversified equity portfolio with bitcoin already assigned a modest strategic weight, rather than adding crypto separately. That puts bitcoin closer to conventional portfolio construction and gives Canadian advisers and investors a simple way to combine traditional markets and digital assets in one listed product.
Pay by Bank is reaching Canadian customers before regulated payment initiation does. Foreign providers are improving the experience around an existing Canadian bank rail instead of waiting for new infrastructure. That makes the commercial timing important for Canada’s open banking opportunity: future regulated access will enter a market where some of the customer experience is already being built.
Dream is taking infrastructure built by a Canadian fintech into U.S. business payment workflows where the payment can start inside the software that created the obligation. That also gives agent payment infrastructure a more concrete operating model: software can participate in the workflow, but identity, authority, approval and settlement controls still determine whether money moves.
Last year’s Moneris sale discussion has become a signed change of control. RBC and BMO are giving up ownership while preserving customer distribution, leaving Francisco Partners to decide how aggressively Moneris invests across merchant acquiring, commerce software and payments technology. The separation between infrastructure ownership and bank distribution is the more consequential part of the deal.
Canada is putting a settlement discipline framework into live measurement before imposing a financial penalty. That gives dealers, custodians and market infrastructure providers time to see where fails occur, what the operational burden looks like and whether the fee design changes settlement behaviour. The evidence from the trial will determine whether a reporting framework eventually becomes an economic incentive.
Canada's repo market now has a standardized collateral workflow running on infrastructure that the Bank of Canada also plans to use for its domestic repo operations. Wider adoption would make collateral easier to allocate and substitute across financing activity while reducing manual processing. The next evidence is usage: how much repo activity migrates onto CCMS and whether the additional baskets deepen participation beyond Government of Canada securities.
The financing connects capital directly to deployment of a physical and digital financial services network rather than funding an undefined expansion plan. PointsKash acquired more than 2,100 cryptocurrency kiosks earlier in August and now has a staged capital structure intended to refurbish and redeploy that hardware while building payments, merchant and mobile services around it. The conditional structure also keeps a clear line between near term funding and the larger amount that depends on execution.
The rule changes where settlement risk has to be dealt with. Firms must support the expectation of settlement before a short sale reaches the market, putting more responsibility on trading controls, securities availability and supervision. Difficult to borrow securities and repeated settlement failures will show how demanding the requirement becomes in practice.
RBI is pushing AI governance into the same operating disciplines banks already use for material risk. That aligns with Canadian work on regulated AI, where model oversight, vendor access, fallback plans and proof of control are becoming practical requirements. The advantage will come from deploying useful AI while being able to show who owns the risk and how the system is controlled.
Pix is starting to test whether a national instant-payment rail can connect directly into foreign payment infrastructure rather than relying only on traditional correspondent channels. NCFA’s cross border payments benchmark shows why that distinction matters: strong domestic rails don’t automatically solve international cost, speed or interoperability. The practical questions are which systems Brazil connects to first, how FX, compliance and settlement are handled across jurisdictions, and whether this becomes a repeatable model for other domestic real time rails.
USD1 could move from a stablecoin structure supported by external service providers into a federally supervised trust bank that combines issuance, redemption, reserves and custody. That would bring more of the operating stack behind a payment stablecoin inside one regulated entity, while concentrating responsibility for reserve management, safeguarding and compliance.
The Coinbase acquisition is moving from ownership into shared market infrastructure. Deribit can keep its derivatives interface while drawing on Coinbase's spot liquidity and execution stack, extending the Deribit acquisition strategy into day to day trading. That brings spot execution, collateral and derivatives closer together inside one regulated operating structure.
The significance is the combination of existing regulated market infrastructure with newly authorized crypto services. Rather than building a separate crypto venue, Perpetual Markets can extend an established MTF operating model into digital assets, giving brokers and institutions another route to offer crypto products under a European regulatory framework. The announcement authorizes expansion, but does not establish that every permitted crypto service is already live at scale.
Hong Kong's stablecoin regime has crossed from licensing into controlled distribution and commercial use. That builds on the tokenized finance strategy NCFA has been tracking through Standard Chartered and Hong Kong's regulators. HKDAP now has to prove that regulated tokenized money can attract repeat transaction flow across payments, asset settlement and institutional distribution rather than remain a licensed product with limited circulation.
The important distinction is the legal and operating structure behind the token. Coinbase is combining regulated custody, underlying shares, investor rights and blockchain transferability rather than offering price exposure alone. That puts the model inside the infrastructure test NCFA is tracking for regulated tokenized assets: whether ownership rights, custody, compliance and transfer can work together at market scale.
Bitstamp is becoming more than an acquired exchange for Robinhood. Its UK crypto infrastructure now lets Robinhood add digital assets to the same interface where customers already invest across traditional markets. The next test is whether that combination deepens customer activity and gives Robinhood a repeatable way to extend its wider investment platform into regulated crypto markets.
Crypto backed lending is becoming part of the product stack offered by Canadian trading platforms. Shakepay is integrating the credit relationship directly into its own account experience, while embedded crypto lending at Netcoins uses APX to supply the lending operation behind the interface. The two models create different economics and different responsibility for underwriting, collateral controls and servicing.
Construction lending is operationally intensive because capital is released in stages and each draw depends on current budget, progress and compliance information. Moving those controls into the loan system can reduce reconciliation work and make exceptions visible earlier, while giving private lenders a more integrated way to manage construction credit as portfolios scale.
Opening a new bank account is easier than making it the primary account. Payroll switching reduces the work required to redirect recurring income and adds an operational layer to open banking and financial portability. Competition improves when customers can act on a better banking option, not only compare one. The next measure is whether easier switching translates into more primary-account relationships and deposits.
The licence turns Revolut’s banking expansion into a two-hub European structure with a new regulated entity serving its largest regional customer base. The execution test is how quickly customers and products migrate to the French bank, and whether local licences give Revolut more room to deepen lending, business banking and other regulated services across Western Europe.
The dispute is becoming a direct test of who controls access to event contracts in the United States. The CFTC is treating Kalshi as national derivatives infrastructure while states continue to challenge parts of the market through gaming law. NCFA’s regulated event contract infrastructure brief tracks the same boundary between exchange regulation, market integrity and product access.
The FCA is making regulatory engagement part of the scale up process rather than waiting for rapid growth to create supervisory problems. NCFA’s closer look at the five firms shows how that support intersects with payments, credit, insurance and European expansion. For fintechs, the tradeoff is clearer: faster access to regulatory guidance comes with closer attention to whether governance, controls and customer protections are developing at the same rate as products, customers and market expansion.
The CLARITY Act has moved from an uncertain post-recess commitment to a scheduled Senate procedure. The September vote will test whether negotiators can assemble enough support to advance a federal market-structure framework and narrow the remaining disagreements over banking, stablecoins and digital-asset oversight.
The important change is that an AI agent can now receive its own controlled payment credential rather than only prepare a transaction for someone else. That makes permission design part of the payment product. NCFA has already tracked how AI agents use card rails; Mercury brings the same question inside company spending, where budgets and policy controls define how much authority software actually receives.
Invoice financing fraud controls are becoming shared lending infrastructure rather than checks performed inside one lender at a time. MonetaGo has been working on shared trade finance fraud controls for years; the SIDBI deployment brings that model into live MSME lending. The test is whether interoperable validation reduces duplicate financing and exceptions at scale while making cash flow credit faster and safer across multiple lenders and factoring platforms.
Mews is taking embedded finance beyond connecting hotels to outside financial providers. Its own regulated entity can now sit inside the software where hotel revenue, operations and payments already meet. That changes the regulatory boundary for embedded finance: vertical software can become part of the licensed financial infrastructure instead of remaining only the distribution layer.
AI is entering compliance as an investigation and decision support layer rather than replacing accountable human approval. That model fits the emerging market for AI powered compliance workflows where evidence, escalation, auditability and human control determine whether automation can be trusted. TransFi's operating test is whether JARVIS reduces review effort across multiple jurisdictions without weakening decision quality.
The breach shows how self custody can inherit risk from suppliers that never touch a private key. Fulfilment providers still hold enough identity and location data to expose hardware wallet owners to targeted attacks, making vendor controls and data retention part of hardware wallet security rather than a separate privacy issue.
Financial infrastructure is becoming easier to enter and harder to operate well. Bank switching is getting simpler, payments are becoming programmable, AI agents are gaining spending authority and software platforms are taking on regulated financial roles. At the same time, regulators are putting more weight on governance, settlement discipline, market access and accountability. The competitive advantage is moving toward firms that can combine better distribution with stronger control of the infrastructure underneath it.
NCFA offers various curated resources to help founders and investors stay current on developments that impact fintech markets. Get the weekly Whisperer and related market intelligence through NCFA's newsletter, view the latest fintech insights, industry research, or launch into emerging financial innovation opportunities.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Aug 1, 2026 | NCFA Fintech Whisperer | Digital Assets Blockchain And Tokenization, Treasury Liquidity, Embedded Finance, Artificial Intelligence And Data, Cybersecurity Fraud And Financial Crime, SME Finance And Business Banking, Payments Infrastructure And Money Movement, Capital Markets Infrastructure And Funding, Regulation And Policy, Risk Compliance And Regtech

Image: Freepik
This live weekly NCFA intelligence page tracks financial technology developments that significantly affect how fintechs build, sell, raise capital, and operate under scrutiny. Coverage prioritizes Canada and includes global events that directly influence competitive conditions, market access, and execution realities across fintech sectors. This page will be updated throughout the week with market movers in a live format and then each week we'll close the prior week's contents in prep for the upcoming week, and continue on a rolling basis. (Missed prior week's Fintech Whisperer? (December 6-12, 2025, December 13-19, 2025, January 1-9, 2026, January 10-16, 2026, January 17-23, 2026, January 24-30, 2026, January 31-February 6, 2026, February 7-13, 2026, February 14-20, 2026, February 21-27, 2026, February 28-March 6, 2026, March 7-13, 2026, March 14-20, 2026, March 21-27, 2026, March 28-April 3, 2026, April 4-10, 2026, April 11-17, 2026, April 18-24, 2026, April 25-May 1, 2026, May 2-8, 2026, May 9-15, 2026, May 16-22, 2026, May 23-29, 2026, May 30-June 5, 2026, June 6-12, 2026, June 13-19, 2026, June 20-26, 2026, June 27-July 3, 2026, July 4-July 10, 2026, July 11-July 17, 2026, July 18-24, 2026, July 25-July 31 2026).
The acquisition puts Canadian inference technology inside AMD as competition for AI compute intensifies. NCFA’s deeper look at the Taalas acquisition examines the Canadian tradeoff more closely: engineering can remain here while ownership, capital allocation and the commercial direction of the technology move inside a global semiconductor company.
Scotiabank is progressing from general AI assistance to governed financial workflows built around approved information sources and defined employee tasks. The next measures are repeat usage, time saved, answer quality and whether the agents can support more complex work without weakening human review, data controls or accountability.
The acquisition puts differentiated Canadian AI infrastructure inside AMD as competition for inference performance intensifies. It also adds another example to the question of who owns Canadian AI infrastructure as domestic companies scale. Taalas keeps its engineering base in Canada, but its technology, capital requirements and commercial reach will now sit inside AMD’s global platform.
Europe has turned AI-content provenance into an operating compliance requirement. Banks, fintechs, insurers, publishers and AI providers now need controls that preserve machine-readable markings across creation, editing, distribution and resharing while documenting when human editorial oversight creates an exception.
Circle is placing banks, asset managers, market infrastructure providers and payment networks inside the operation of its blockchain rather than treating them only as users. The next test is whether Arc launches on schedule with live institutional integrations, meaningful transaction activity and connections to assets and liquidity outside Circle’s own ecosystem.
South Africa is bringing offshore platforms and self-custodied wallets inside its capital flow controls without treating every domestic crypto transaction as cross-border. The framework could improve regulatory visibility, but its operating impact will depend on authorization capacity, reporting costs and whether users continue using regulated channels when transferring assets internationally.
Property completion gives programmable finance a demanding test because payment release depends on a verified event outside the payment system. Banks and infrastructure providers will need clear rules for defining completion conditions, confirming title status, cancelling reserved funds, handling failed transactions and assigning liability across the payment and property networks.
Wells Fargo is bringing programmable commercial bank money into corporate treasury while banks compete with stablecoins for always-on settlement. The next test is whether clients can move funds beyond Wells Fargo’s customer and network boundaries without losing the speed, control and regulatory treatment that make tokenized deposits attractive.
FIS now has bank-issued digital money infrastructure and a commercial-banking platform spanning payments, treasury and trade finance. The immediate test is whether one shared platform can handle local payment rails, regulatory requirements and corporate workflows while reducing the cost and complexity of entering additional markets.
Nuvei is moving payment acceptance and reconciliation into the enterprise receivables stack instead of leaving payment as a separate process. The operating test is whether live deployments reduce unmatched receivables and improve collection visibility across complex international operations.
The acquisition connects merchant services and consumer loyalty inside one bank-controlled platform. The next test is whether financial institutions use the combined infrastructure to strengthen SME relationships, increase customer activity and compete with standalone payment and commerce platforms.
Chime is using employers as a distribution channel for several consumer financial products rather than offering earned-wage access as a standalone benefit. The operating measures are how many eligible employees enroll, whether they use multiple products and whether the early savings behaviour continues across a workforce of this size.
The FCA is making regulation easier for software to consume, not just easier for people to read. That creates a direct data layer between the regulator and the systems firms use to track obligations and compliance changes. It also strengthens the case for AI powered regulatory intelligence, where reliable source data is one of the constraints on using AI safely in regulated workflows.
MVB is changing more than the software used by its compliance team. It is buying completed AML and KYC work through an AI assisted managed service while keeping responsibility for the underlying risk program. That puts the AI compliance burden into a new operating model where banks have to prove that automation, human review and outsourced execution still produce controlled and defensible decisions.
Visa is assembling transaction, behavioural and device intelligence inside its global security portfolio. The competitive test is whether BioCatch helps financial institutions identify compromised customers, manipulation and mule accounts before suspicious activity reaches the payment authorization stage.
Tokenization is being added to the regulated ownership and transfer records of a conventional investment fund, rather than operating as a separate digital wrapper. The next test is whether institutions use the shares for collateral, treasury and liquidity workflows, and whether onchain transfers reduce processing time without weakening investor controls, recordkeeping or legal certainty.
The ruling goes beyond financial penalties and reaches how a major digital platform is designed and governed. Fintechs and AI platforms should watch whether courts increasingly use product controls, age assurance, monitoring and reporting requirements to address consumer harm before legislators or regulators create wider rules.
South Africa is bringing cross-border crypto transfers inside its capital-flow controls rather than treating them only as domestic virtual-asset activity. Providers will need to connect wallet and transaction infrastructure with customer records, regulatory reporting and exchange-control permissions. The final rules will determine which transfers can proceed routinely and which require additional authorization.
AI agents need clear authority. Payments need verified conditions before money is released. Tokenized funds still need trusted records. Cross border crypto still has to fit inside regulatory controls. The technology can act faster, but firms still need to know who can act, what they can approve and which record settles the outcome.
NCFA offers various curated resources to help founders and investors stay current on developments that impact fintech markets. Get the weekly Whisperer and related market intelligence through NCFA's newsletter, view the latest fintech insights, industry research, or launch into emerging financial innovation opportunities.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Aug 6, 2026 | NCFA Insight | Artificial Intelligence And Data, Risk Compliance And Regtech, Capital Markets And Market Infrastructure

On July 29, 2026, a shareholder filed a Rackspace securities complaint alleging that the cloud company failed to explain how its AI plans were affecting capacity, spending and revenue. The complaint says Rackspace reaffirmed its 2026 guidance in May, then cut expected annual revenue by US$150 million in July. It also alleges that resources moved away from the more profitable Private Cloud business while margins absorbed restructuring and AI investment.
Those claims haven't been proven, and the court hasn't decided whether Rackspace or its directors did anything wrong. The filing still raises a useful question. Once an AI plan changes how a company spends, allocates computing capacity or describes future results, the board needs a clear view of the economics behind it. Investors may need that view too.
Rackspace isn't an isolated case. Recent complaints against Oracle, Microsoft, ZoomInfo and Upstart use different facts, but each asks whether the company story kept pace with what was happening inside the business.
An Oracle shareholder complaint alleges that the company understated the financing pressure created by its AI infrastructure build. Oracle later projected US$50 billion of capital spending for fiscal 2026, US$15 billion above its September 2025 projection, while reporting more than US$10 billion of negative free cash flow. The complaint focuses on whether investors received enough information about the scale, financing and cash impact.
A Microsoft securities complaint focuses on a different pressure point. The plaintiffs allege that Microsoft overstated Copilot adoption and didn't adequately explain that AI products were competing with Azure customers for computing capacity. Microsoft reported US$72.4 billion of capital spending in the first half of its fiscal year, almost as much as it spent in the prior full year. The unresolved issue is whether product demand, available capacity and investor disclosure remained aligned as the build accelerated.
ZoomInfo adds the risk of AI weakening the business that funds the transition. Its June 2026 complaint alleges that customers were using internal AI tools and moving away from seat-based subscriptions toward consumption pricing. The plaintiffs argue that management failed to explain how AI was changing demand for the existing model.
None of these cases proves misconduct. Shareholder complaints present company events through the plaintiff's theory, and a falling share price does not establish that earlier disclosure was misleading. The filings are interesting because they show where disputes are forming. Investors are asking what was spent, what reached customers, what revenue followed and what the rest of the business gave up.
A board cannot judge an AI strategy from product demos or spending totals alone. It needs to know what the money produced, such as more computing capacity, products in market, paying users, lower costs, higher revenue or better service.
Usage numbers can hide as much as they reveal. An enabled account may never use the product. An active user may not pay. Even paid adoption says little about retention, margins or the cost of serving that customer.
Savings claims need the same scrutiny. AI may reduce work in one team while increasing cloud costs, review time or customer complaints elsewhere. Early pilots do not need to make money immediately, but management should know what would justify further investment and what would cause it to pull back.
Boards also need to see what the AI plan is displacing. Computing capacity assigned to one product cannot serve another workload. Engineers moved to a new platform are no longer maintaining something else. A sales team promoting an AI add-on may spend less time selling the core product. Those choices may be reasonable, but the trade-offs should be clear before a profitable business starts carrying an open-ended investment.
Directors do not need to become model engineers but they do need enough operating information to test whether the plan is working. That includes supplier commitments, capacity constraints, effects on established products and a clear explanation when results fall short.
The SEC Investor Advisory Committee's AI disclosure recommendation follows the same logic. It calls on issuers to define what they mean by AI, explain how the board oversees it and disclose material effects on operations and customers. It also argues that companies can provide much of this information through existing disclosure requirements. The recommendation comes from an SEC advisory committee. It is not an SEC rule.
For banks and fintechs, weak AI performance can reach customers before it appears in an earnings release. A model may change who receives credit, how a transaction is flagged or what recommendation reaches an investor. It can also create more manual review, complaints and losses when performance moves in the wrong direction.
The Upstart securities complaint brings that issue into automated lending. Plaintiffs allege that a model update reacted too strongly to negative economic signals, reducing loan approvals and conversions while affecting revenue and guidance. The filing shows why boards need model performance connected to approval rates, customer outcomes and financial forecasts.
That connection becomes harder when a firm depends on an outside cloud, model or data provider. A vendor change can alter cost or performance. An outage can interrupt a regulated process. Concentration can leave the company without a workable alternative. NCFA's analysis of feedback loops behind AI failures shows how model output, human responses and operating data can reinforce an error before the full effect is visible.
The Financial Stability Board's 2026 consultation proposes 12 practices covering governance, the AI lifecycle, cyber risk and outside providers. It is not a binding international standard. In Canada, OSFI's Guideline E-23 on model risk takes effect on May 1, 2027 for federally regulated financial institutions. It expects clear ownership, model inventories, monitoring and communication to senior management and boards.
AI is already moving into governed financial workflows. Board reporting has to keep pace. Spending and adoption belong beside model exceptions, overrides, complaints and losses. Otherwise, financial results may arrive after the operating warning signs.
Canadian boards do not need an AI-specific statute before asking these questions. Under the Canada Business Corporations Act, directors of federal corporations must act honestly and in good faith and exercise the care, diligence and skill of a reasonably prudent person.
Canadian continuous-disclosure requirements separately require reporting issuers to publish financial statements, management's discussion and analysis, material-change reports and other prescribed information. The exact obligation depends on the issuer and the facts.
AI is already appearing in Canadian filings. The Ontario Securities Commission reviewed 225 companies in the S&P/TSX Composite and found that 72 issuers mentioned AI in 2024 annual management discussion and analysis. That is 32% of the sample. The OSC described the work as a proof of concept and did not assess whether any issuer's disclosure was adequate.
Simply mentioning AI more often will not make disclosure more useful. Investors need to know how much the company is spending, what is already in use, how customers are responding and what has changed since the last report. When AI affects capacity, margins, revenue or a regulated customer decision, a generic risk paragraph is not enough.
Canada may get more immediate value from clearer reporting on AI costs, live deployment, board oversight and business results. A separate AI disclosure rule is not the only option. Existing board duties and continuous-disclosure requirements already give companies a reason to make sure their public statements match what management is seeing inside the business.
Poor AI performance is not automatically a governance failure or securities violation. A board can approve a reasonable investment that does not work. Litigation can also overstate what directors could have known at the time. The difficult question is whether the company’s internal numbers had changed while its public story stayed the same.
When an AI plan changes spending, capacity or revenue, what should the board see before investors hear the same growth story again?
Continue through the operating controls, supervisory questions and financial risks most closely connected to material AI deployment.
CAPITAL MARKETS OVERSIGHT
The governance, model risk and accountability questions supervisors can bring into reviews of AI used by market firms.
CANADIAN FINANCE
Canadian operating constraints around AI governance, outside providers, customer outcomes and financial stability.
AI spending becomes a board issue when it is material to strategy, capital commitments, margins, capacity, customer outcomes or regulated operations.
No. The complaints contain allegations that have not been proven, and courts have not decided the merits. They identify the spending, adoption, capacity and business-model questions investors are asking.
The board should see enough financial, operating, customer and model-performance information to challenge the investment and recognize when results depart from the approved plan.
Canada does not have a single AI-specific securities disclosure rule for public issuers. Existing corporate duties and securities requirements can still apply when AI costs, risks or operating effects become material.
An AI model can affect credit, fraud controls, suitability, customer service and complaints before its full financial effect appears in company results.
This article is provided for informational purposes and does not constitute investment, financial or legal advice. Lawsuits discussed contain allegations that have not been proven in court. Recommendations, consultations and regulatory requirements may change.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: [www.ncfacanada.org](http://www.ncfacanada.org)
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 25, 2026 | NCFA Fintech Whisperer | Payments And Money Movement, Embedded Finance, Capital Markets Infrastructure And Funding, Digital Assets Blockchain And Tokenization, Wealthtech Investing And Trading, Cross Border Payments And FX, Cybersecurity Fraud And Financial Crime, Lending Consumer Credit And BNPL, Artificial Intelligence And Data, Open Banking Open Finance And Data Sharing, Competition And Market Structure, Financial Inclusion, Insurance And Insurtech, Banking And Credit, Sustainable Finance And ESG

Image: Freepik
This live weekly NCFA intelligence page tracks financial technology developments that significantly affect how fintechs build, sell, raise capital, and operate under scrutiny. Coverage prioritizes Canada and includes global events that directly influence competitive conditions, market access, and execution realities across fintech sectors. This page will be updated throughout the week with market movers in a live format and then each week we'll close the prior week's contents in prep for the upcoming week, and continue on a rolling basis. (Missed prior week's Fintech Whisperer? (December 6-12, 2025, December 13-19, 2025, January 1-9, 2026, January 10-16, 2026, January 17-23, 2026, January 24-30, 2026, January 31-February 6, 2026, February 7-13, 2026, February 14-20, 2026, February 21-27, 2026, February 28-March 6, 2026, March 7-13, 2026, March 14-20, 2026, March 21-27, 2026, March 28-April 3, 2026, April 4-10, 2026, April 11-17, 2026, April 18-24, 2026, April 25-May 1, 2026, May 2-8, 2026, May 9-15, 2026, May 16-22, 2026, May 23-29, 2026, May 30-June 5, 2026, June 6-12, 2026, June 13-19, 2026, June 20-26, 2026, June 27-July 3, 2026, July 4-July 10, 2026, July 11-July 17, 2026, July 18-24, 2026).
Visa is reducing staff in the teams building and maintaining payment products while stablecoins, account-to-account payments and agentic commerce increase competitive pressure. The next evidence should show which capabilities lose capacity, where investment increases and whether product delivery improves following the restructuring.
Lianlian is progressing from one controlled transaction to connecting the same procurement model with a second global payment network. That makes this operating evidence rather than another agentic-commerce concept. The human approval, verified-agent and spending-control design also gives practical form to the consent and liability questions examined in AI Payments Challenge Consent Rules And Liability.
Together, the approvals create two routes into regulated stored value: a global acquirer connecting merchant acceptance with issuing, and a local spend platform seeking direct control over customer funds. The competitive test begins after final licensing, operating launches and evidence that merchants or small businesses use the new account, card funding and wallet capabilities.
Canada is setting a retirement date for a paper clearing method while updating the operating rules around membership and account changes. Banks, payment service providers and businesses that still originate paper PAD items now have a conversion deadline covering processing, exceptions and reconciliation. The change concerns the existing batch system and complements, rather than replaces, the modernization tracked in NCFA's Real-Time Rail guide.
The UK provides a working volume benchmark for open banking commercialization in Canada. The next measures are payment share, merchant adoption, fraud outcomes, service reliability and whether variable recurring payments can compete with card-on-file and direct debit services.
Singapore is pairing disclosure requirements with assurance skills, training support and phased implementation. The practical test is whether this approach produces comparable climate information without allowing voluntary reporting outside SFRS S2 to become a lasting information gap.
The ECB is turning climate-transition exposure into a direct input when valuing collateral used for central-bank liquidity. The next test is whether the 5% ceiling materially affects collateral selection, corporate lending data and the financing conditions faced by transition-exposed businesses.
Chime connects a measurable increase in AI-assisted development with a material change in workforce structure. Following Block’s larger AI-led operating reset, the development strengthens the evidence that fintechs are applying AI to organizational design as well as customer products. The next test is whether smaller teams produce faster releases, stronger growth and better margins without weakening product quality, compliance or customer support.
The renewal links research access, specialist recruitment and applied development to RBC’s enterprise AI program. The measures that count through 2032 are production deployments, control performance, reusable intellectual property and retention of Canadian AI talent. NCFA’s governed financial workflows analysis identifies the permissions, approved tools, human review and audit evidence required as agentic AI reaches regulated banking work.
HSBC is placing treasury, payments and wealth workflows inside one global AI capability plan. The proof points will arrive after launch through production deployments, measurable customer and operating outcomes, control performance and evidence that systems can meet different data, governance and conduct requirements across jurisdictions.
Verity Prepare is a production example of governed financial workflows entering accounting operations. The useful measures are close time, exception accuracy, audit adjustments, human overrides and whether finance teams can trace every source and decision used to prepare a reconciliation.
The launch places a deposit account, card and peer-to-peer payment relationship inside a social platform that already owns communication and audience distribution. Cross River provides the regulated banking layer while X controls the customer interface. The commercial test is whether subscribers use X for recurring deposits and payments, and whether the partners can manage fraud, support and compliance at social platform scale.
The transaction would place a larger share of fixed income data, execution and compliance workflow inside ICE. Market participants and regulators should examine how the combination affects platform access, data pricing, execution choice and competition across electronic bond markets.
The mandate is driving a market infrastructure conversion measured in trillions of dollars per day. The implementation test now concerns client capacity, onboarding completion, collateral and margin demands, clearing costs and whether remaining participants can connect without concentrating access among a small group of dealers.
The authorization converts the European consolidated tape from regulatory design into supervised market infrastructure. A common view of prices and trading activity could improve price discovery while reducing the information advantage created by fragmented venue data. Canadian exchanges, dealers and regulators should compare EuroCTP on data cost, latency, venue coverage, retail access and commercial use once operations begin.
RVII would package private company exposure inside an exchange listed fund, extending public access from IPO allocation toward venture portfolios. The structure provides a US comparator for retail IPO access in Canada while placing private company valuation, liquidity, fees and portfolio concentration inside a public investment product.
Canadian pension capital is providing repeat issuance capacity instead of purchasing one completed security. The structure gives Ontario Teachers direct exposure to CLO equity and platform economics while helping M&G expand its European corporate credit securitization business. It also belongs beside the Bank of Canada’s warning about private credit transparency and non bank leverage. Credit quality, leverage, issuance volumes and performance through weaker credit cycles will determine the value and risk of the model.
The structure connects a long-term commodity buyer, project financing and domestic processing optionality inside one capital formation strategy. It provides a Canadian example of how offtake commitments can help finance critical mineral infrastructure without giving up the option to capture more value through domestic conversion. The financing should be treated as conditional until definitive terms are executed and funds become available.
The results increase the commercial pressure behind Coinbase’s Everything Exchange strategy. Its Deribit acquisition and wider product expansion now need to produce enough repeat revenue to reduce the company’s dependence on spot crypto trading cycles.
The mandate places a Canadian digital asset manager inside a sovereign-linked reserve program and a planned international financial centre. The next measures are mandate size, custody, investment limits, governance, public reporting and whether the partnership converts Bitcoin reserves into durable financial capacity. It also extends the institutional strategy NCFA examined when Coincheck agreed to acquire 3iQ.
Canada now has a much larger crypto-owning population, but product knowledge and investor protection understanding have not kept pace. Compared with the OSC 2023 survey, platform registration checks are improving while ownership has increased sharply. Regulators and platforms should track whether greater participation produces stronger product knowledge, greater use of registered venues and better complaint outcomes.
The acquisition gives Circle strategic control over intellectual property that reaches beyond stablecoins into banking, cloud infrastructure and enterprise financial systems. Canadian institutions evaluating USDC and Circle infrastructure should examine how the larger patent position affects licensing, interoperability, supplier dependence and competitive access. NCFA previously tracked Circle compliance with Canadian VRCA requirements.
Payward is bringing scaled embedded wallet infrastructure into the same operating stack as trading, custody and other financial services. The acquisition follows its xStocks expansion into global equity markets and adds another product layer to its shared infrastructure strategy. For Canada, Payward also operates Kraken through a national restricted dealer registration. Newton Labs is concentrating separately on transaction authorization, compliance and risk controls before settlement.
HashKey is testing whether a digital asset group can offer one customer interface across several regulatory systems without combining the underlying legal entities, licences or product permissions. The same country by country constraint appears in RedotPay’s regulated market expansion. Account portability, data boundaries, regulatory accountability and consistency between regional services will determine whether HashKey’s architecture can scale.
BitMart’s notice followed BitMEX by three days and AscendEX within the same month. The companies disclosed different circumstances, so the timing alone does not establish a shared cause. The sequence still warrants review of exchange liquidity, customer migration, operating costs, regulatory access and competition from onchain venues. Users and counterparties should track withdrawal processing, asset segregation, proof of reserves, financial disclosure and the controls used to settle positions during the wind down.
The penalties establish a high cost benchmark for advertising interest free finance without clearly presenting the continuing credit account and fees behind it. Retailers and lenders share exposure when they jointly design and distribute the offer. The decision also provides an enforcement comparator for the UK BNPL regulatory framework, where product presentation and consumer understanding remain central.
Cowbell is attaching AI to measurable underwriting and product-development outcomes while keeping final authority with underwriters. Independent performance evidence on pricing accuracy, loss ratios, claims, regulatory outcomes and business retained after renewal will provide a stronger test of the operating model.
The acquisition combines global embedded-insurance distribution with local banking integrations and regulatory infrastructure. The commercial measures are new bank deployments, policy conversion, non-interest revenue for participating institutions and whether the combined platform can expand beyond the German-speaking market without adding heavy implementation work.
Robinhood’s wider product mix is absorbing weaker crypto revenue more effectively than a platform that depends heavily on digital asset trading. The results extend the household finance strategy examined in Robinhood’s product expansion. The next measures are retention, revenue concentration and whether event contracts and subscriptions remain durable through weaker trading cycles.
Webull is making individually managed bond portfolios economical at account sizes previously served mainly through funds and ETFs. Canadian platforms are pursuing a related ownership model through products such as Wealthsimple’s direct indexing and fractional gold services. Brokers and digital advisers still need to address suitability, liquidity, credit risk, tax reporting and whether customers understand what they directly own.
The integration embeds custody onboarding inside the advisor’s existing platform at significant operating scale. Account-opening time, rejection rates, correction work, client completion and the number of participating custodians will determine whether the architecture materially improves advisor and client workflows.
The planned service takes an institutional blockchain payment network into the operating workflow of importers and exporters. RBC and TD are already participating in Swift’s blockchain ledger prototype, giving Canada a direct institutional comparator. Banks should compare settlement times, foreign exchange costs, liquidity requirements and exception handling with conventional correspondent banking once the KB Kookmin service launches.
The regulatory focus is advancing from recognizing frontier AI as a systemic cyber threat to changing how financial firms defend against it. The gap between finding a vulnerability and exploiting it is getting shorter, which puts more weight on continuous controls, faster response and technology supplier oversight. NCFA’s AI and financial crime intelligence tracks the same convergence between AI capability, cyber resilience and financial infrastructure.
Bank of America is choosing direct ownership of specialist cyber expertise as financial institutions face faster vulnerability discovery, AI-enabled attacks and growing operational resilience requirements. The operating test is whether the acquired team improves vulnerability testing, threat detection and response across the bank without losing the external perspective that made the consultancy valuable.
Attack automation is reducing the cost and time required to exploit weaknesses while delayed remediation continues to produce multimillion-dollar losses. Financial institutions should test controls for agent identities, APIs, cloud configuration, vulnerability remediation and cryptographic inventories. NCFA has already explained why fintech cannot wait for quantum computing, and the IBM findings strengthen the financial case for beginning that work now.
The incident provides a direct operating test of customer asset segregation during a digital asset security breach. The control appears to have limited the exposure to company treasury assets, although the cause, total loss, wallet control failures and recovery prospects remain undisclosed. Canadian safeguarding rules for payment service providers similarly require customer funds to be protected through dedicated accounts, trust arrangements, insurance or guarantees. Stablecoin payment providers still need strong treasury wallet governance even when customer funds are separately safeguarded.
The incident separates core-system resilience from identity and data exposure. A bank can keep its transaction engine operating while one compromised mailbox still creates privacy, fraud and customer risks. The forensic findings need to establish what data was accessible, whether credentials were exposed and how far the attacker travelled beyond the email account.
The index turns quantum risk into a measurable banking-sector readiness program. It adds a concrete adoption baseline to why fintech can’t wait for quantum computing: awareness is spreading, but formal planning and practical migration remain well behind the regulator’s 2030 objective.
The acquisition combines Leatherback’s cross-border payment technology with Zedcrest’s capital, governance and financial-services operations. Canada becomes directly relevant if the planned North American hub opens. Licensing, banking partners, supported corridors, staffing and Canadian customer activity will determine whether that plan develops into a meaningful market entry.
The pilot treats transaction history as financial infrastructure for farmers who may have limited conventional credit records. The operating test is whether digital records lead to active accounts, lower payment friction, useful savings behaviour and responsible access to financing rather than simply creating more profiles.
Lloyds is connecting acquired wallet technology, AI and its existing banking distribution inside one operating strategy. Canadian banks should watch wallet adoption, mortgage processing time, customer activity and whether the investment creates new revenue or mainly lowers operating costs.
Fintech value is concentrating at the control points between customer access and regulated execution. Distribution can now be embedded almost anywhere, but deposits, payments, market data, clearing and governed AI still depend on infrastructure that’s difficult to replace. That creates a sharper strategic choice: own the customer relationship, own a critical operating layer, or risk becoming a feature inside someone else’s stack. NCFA offers various curated resources to help founders and investors stay current on developments that impact fintech markets. Get the weekly Whisperer and related market intelligence through NCFA's newsletter, view the latest fintech insights, industry research, or launch into emerging financial innovation opportunities.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |

We're opening up more and more APIs to partners, fintech services, and client applications. The only question is whether we're confident these same APIs aren't opening up new paths for attackers.
Just a few years ago, a bank mostly dealt with its own systems. A customer would log into the app, check their balance, make a transfer. The whole journey stayed inside the perimeter of a single organization.
Today, one customer might simultaneously use a mobile banking app, a budgeting service, an accounting platform, a payment provider, and an AI assistant that analyzes their spending. All of these services exchange data through APIs - interfaces that let different systems talk to each other according to a set of established rules.
Open Banking isn't just a regulatory requirement or a new integration channel - it's a shift in the trust model itself. A bank used to be responsible for security within its own infrastructure. Now it hands off part of its data to dozens of external services, and those services, in turn, rely on the bank. The more participants in the ecosystem, the more points there are where trust is either reaffirmed or cracked, every single day.
Attackers are less and less interested in finding a weak spot inside any one bank. Today, hackers target the interaction between systems itself. The longer the chain - bank, fintech, payment hub, partner app - the more places there are for something to go wrong.
Common examples include:
An API can perform flawlessly on the functional side - fast, stable, no errors in the logs - and still carry a critical vulnerability. Functional correctness and cybersecurity don't always go together.
Banks and fintech companies generally don't neglect API security. They go through certifications, run automated scans, do code reviews and QA. But none of these tools answer the one question that matters most: can this specific API's logic be bypassed in a way its developer never anticipated? Scanning catches known vulnerability patterns; code review and QA confirm the code does what it was built to do. Neither one thinks like an attacker who isn't hunting for a bug in the code, but for a logical gap in how the API interacts with other systems.
That's why most attacks on financial APIs today aren't about technical mistakes - they're about logic: the sequence of actions, the boundaries of authority, the trust placed in data coming from the client. It's also why modern Cybersecurity Solutions for Fintech increasingly go beyond formal compliance with standards, testing real-world abuse scenarios at the points where multiple systems meet.

Here's a short checklist for reviewing every external API in your ecosystem:
If you don't have a confident answer to any of these, that's reason enough to look closer.
It's worth telling apart three things that often get lumped together. Vulnerability scanning looks for known vulnerabilities by signature, catching familiar vulnerability classes, common misconfigurations, and known dangerous patterns. Automated testing checks whether the code performs its intended functions correctly. Separate from both is API Penetration Testing (https://datami.ee/services/pentest/api-penetration-testing/) - manual testing in which a specialist plays the role of a real attacker: combining requests, tweaking parameters, hunting for unusual sequences of actions that a scanner, in most cases, won't flag as anomalous, because each individual request looks legitimate on its own.
It's also best if this kind of testing is handled by an external team. In-house specialists tend to know their own API inside and out - and that's precisely what makes it hard for them to spot an unconventional abuse scenario, since day-to-day work with a system's logic doesn't train you to look at it through the eyes of someone deliberately trying to break it. External specialists bring experience from other architectures and payment integrations, so they're more likely to catch the gaps a team had written off as unimportant.
A bank can offer the most convenient digital service and the best partner API on the market. But if even one partner or customer stops trusting the security of the data exchange, the benefits of Open Banking vanish almost instantly. Trust here isn't a bonus feature - it's the baseline condition, and without it the whole structure loses its meaning.
That's why investing in API protection in the financial sector isn't just about regulatory compliance - it's about sustaining trust across the whole ecosystem: between bank and fintech, fintech and customer, and customer and every new service they let into their data.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
July 18, 2026 | NCFA Fintech Whisperer | Capital Markets Infrastructure And Funding, Wealthtech Investing And Trading, Payments Infrastructure And Money Movement, Artificial Intelligence And Data, Banking And Credit, Insurance And Insurtech, Policy Regulation And Governance, Open Banking Open Finance And Data Sharing, Digital Assets Blockchain And Tokenization, Cybersecurity And Fraud, Cross Border Payments And FX, Sustainable Finance And ESG, Competition And Market Structure, Risk Compliance And Regtech, Identity Privacy And Data Governance

Image: Freepik
This live weekly NCFA intelligence page tracks financial technology developments that significantly affect how fintechs build, sell, raise capital, and operate under scrutiny. Coverage prioritizes Canada and includes global events that directly influence competitive conditions, market access, and execution realities across fintech sectors. This page will be updated throughout the week with market movers in a live format and then each week we'll close the prior week's contents in prep for the upcoming week, and continue on a rolling basis. (Missed prior week's Fintech Whisperer? (December 6-12, 2025, December 13-19, 2025, January 1-9, 2026, January 10-16, 2026, January 17-23, 2026, January 24-30, 2026, January 31-February 6, 2026, February 7-13, 2026, February 14-20, 2026, February 21-27, 2026, February 28-March 6, 2026, March 7-13, 2026, March 14-20, 2026, March 21-27, 2026, March 28-April 3, 2026, April 4-10, 2026, April 11-17, 2026, April 18-24, 2026, April 25-May 1, 2026, May 2-8, 2026, May 9-15, 2026, May 16-22, 2026, May 23-29, 2026, May 30-June 5, 2026, June 6-12, 2026, June 13-19, 2026, June 20-26, 2026, June 27-July 3, 2026, July 4-July 10, 2026, July 11-July 17, 2026).
Insurance is becoming part of the financing structure for AI infrastructure. Larger coordinated capacity can make complex data centre projects more bankable, but underwriting models must keep pace with construction, energy, cyber, climate and technology dependencies that can affect the same project simultaneously.
The notice gives Canadian insurers a clearer route for transferring flood, wildfire, earthquake and severe storm risk into capital markets. It could expand catastrophe risk capacity beyond conventional reinsurance while creating opportunities for structuring, modelling, collateral management and institutional investment.
The consortium converts long term cryptographic concern into funded development and a custody implementation timetable. It extends the operating case in Why Fintech Can’t Wait For Quantum Computing. The key measures are how much funding reaches developers, which cryptographic approaches advance and whether exchanges, custodians and wallet providers can coordinate upgrades without disrupting access to assets.
The demonstration tests whether a virtual-machine boundary survives guest-root compromise. Financial institutions should require independent vendor testing, scoped and preferably read-only file mounts, deny-by-default network access, monitoring inside the sandbox and rapid credential revocation. Exposure across current Cowork deployments remains unconfirmed until Anthropic responds or an independent team reproduces the chain.
This was a real containment failure during an evaluation; it does not establish malicious intent. For financial institutions, OSFI’s frontier-AI guidance makes the control response concrete: separate evaluation and production systems, scope agent identities and credentials, restrict network egress, monitor technical boundaries and preserve rapid revocation and shutdown. NCFA’s coverage of governed AI workflows provides the operating context.
Poland now has an operating framework for protected public-sector data access and supervised data intermediation. It provides Canada with a comparator for trusted data intermediaries extending beyond banking and complements NCFA’s coverage of open-banking governance. Registration quality, access times, pricing and the first approved services will determine whether the framework produces usable data capacity for fintech, research and public-interest applications.
The $771.3 billion headline represents institutional assets rather than capital invested directly into community projects, with credit unions accounting for nearly all of the total. The $7.3 billion excluding credit unions provides a clearer baseline for the specialized community finance market, although SVX notes that institution level asset data remain incomplete for some organization types. Private debt dominates by product count while housing and real estate dominate investment objectives, adding national context to Canadian examples such as CSI's community bond campaign.
The fine converts platform-risk governance into a material operating and financial consequence. Fintech marketplaces and embedded finance providers should examine whether merchant onboarding, monitoring, staffing and remediation controls can withstand similar scrutiny. Payment, credit and insurance partners also face exposure when their products are distributed through platforms with weak merchant and product controls.
The financing puts a measurable cost on Galaxy’s expansion from digital assets into AI data centres. It also adds company level evidence to the concentration of capital in AI computing capacity. Investors need to watch the construction timetable, 9.875% borrowing cost, tenant concentration and the point at which contracted capacity produces recurring revenue.
The temporary 2025 financing relief produced a measurable increase in how Canadian listed issuers raise capital, and the CSA is now considering whether to embed that access in the national rule. Issuers, investors and financing platforms should examine the proposed liquidity test, dilution limit, successor issuer access, convertible securities and disclosure requirements before the comment deadline.
This regulated tokenized securities platform connects issuance, transfer agency, distribution, trading and settlement inside one corporate group. Issuers and financial firms now need to compare the model with tracker certificates, custodial entitlements and traditional brokerage structures. The key tests will be asset availability, investor rights, liquidity, custody and interoperability with existing accounts.
The exchange is giving its technology partner ownership in the infrastructure expected to carry existing market activity. Members, liquidity providers, bullion dealers, and settlement firms need the implementation timetable, migration requirements, operating rules, risk controls, and links to Hong Kong’s separate gold clearing initiatives before they can assess how access and execution will change.
Prediction markets are acquiring the execution, block trading, data and downstream distribution infrastructure used by professional markets. That makes prediction market integrity more important as these products reach institutions and brokerage platforms. The next test is whether liquidity, surveillance, contract governance and disclosure can mature quickly enough to support that distribution.
The xStocks expansion takes tokenized equities from U.S. stock replicas into international market access supported by traditional custody and record keeping. Existing scale provides operating evidence, but licensing, disclosure and investor protection will still need to be addressed market by market.
Tokenized equities are being forced to confront the gap between economic exposure and legal ownership. Bringing proxy and disclosure workflows into the distribution layer does not resolve every rights question, but it makes governance a core part of tokenized market infrastructure rather than an afterthought.
This is a severe example of the concentration risk created when an economy depends on a small number of foreign correspondent banks. The planned cutoffs extend the long running decline in correspondent banking relationships into essential national payment access. If the relationships end, more activity could enter cash based and unregulated channels while banks lose the electronic balances required to settle trade.
Questrade has placed agentic finance inside a live Canadian brokerage workflow. The control questions now concern permission scope, retained data, order review, erroneous instructions, recordkeeping and responsibility when an external agent influences an investment decision. NCFA’s analysis of AI agents entering governed financial workflows explains why access, approvals and audit evidence become essential once agents can act on financial accounts.
This gives AI assistants controlled access to current portfolio and compliance data inside established advisor workflows. The d1g1t company profile shows how MCP extends a wealth platform serving more than 90 firms and representing over C$200 billion in assets. Wealth firms still need traceable actions, review gates and clear limits on what an agent can retrieve, recommend or execute.
Chime is extending from payments, savings and credit into retail investment distribution without becoming the adviser or broker. The next measures are funded-account adoption, average balances, managed-versus-self-directed use and whether frequent financial-app engagement translates into sustained investing.
This direct network participation gives a crypto platform greater control over one of Canada’s most widely used payment services. Shakepay can rely less on intermediary arrangements and build payment functions closer to the network. Other regulated fintechs will need to compare the operating control, settlement requirements, technical obligations and customer economics of becoming participants rather than remaining downstream users.
The scale turns a card acceptance partnership into connected national payment infrastructure. Bir is combining banking, ecommerce, terminals and a wallet with an international network, giving merchants one operating ecosystem for domestic commerce, tourism and cross border customer access.
South Korea is testing a two tier model in which the central bank supplies the settlement base and commercial banks own distribution. The test could provide a practical comparator for how tokenized deposits, public money and regulated bank services can operate inside one payment system.
If implemented at the reported scale, this would provide one of the clearest tests of stablecoins as operating payment infrastructure rather than a crypto trading product. The real measure will be whether suppliers adopt it, convert it easily and receive a meaningful cash flow benefit.
The deployment turns open finance from account aggregation into operating intelligence for SMEs and their banks. It provides a practical comparator for Canada’s open banking development, where permissioned financial data could improve cash visibility, risk monitoring, credit decisions and relationship banking.
Institutional data providers are bringing governed financial information into the AI interfaces analysts already use. Credit teams need to test permissions, source traceability, update timing, confidential data boundaries, model outputs, and review requirements before connector generated work enters investment decisions. Adoption data will determine whether this becomes core research infrastructure or remains an optional interface.
Manulife is putting AI governance into the operating architecture of a major Canadian financial institution. Together with Canada’s shared AI control infrastructure, the deployment provides a direct test of whether central agent registries, monitoring and security controls can support enterprise AI without fragmenting accountability across business units and jurisdictions.
AI agents do not fit conventional per seat data licences. Bigdata.com is testing whether attribution, licensing and payment can be embedded directly into retrieval, creating a potential commercial layer for financial research and other data intensive AI workflows.
The rejection shows that federal payment access depends on both settlement policy and compliance readiness. Wise’s planned GENIUS Act application adds a major global payments company to the US trust charter debate. The next test is whether Wise can design a viable application without changing how its existing customers hold and transfer money.
A national bank charter would give Upstart direct access to deposit funding and place its lending activities within a federal prudential framework. It could reduce funding and regulatory complexity while adding bank level capital, liquidity, governance, compliance and supervisory obligations. Partner institutions and investors should watch the remaining approvals, preopening requirements and how Upstart allocates originations between its own bank and external funding partners.
A global fintech can now combine deposits, payments and credit under one Australian prudential licence. Canada has a clear comparator for foreign fintech bank entry, deposit protection and the competitive impact of giving a large digital platform its own regulated balance sheet.
Augustus is targeting the correspondent banking layer with programmable dollar accounts, payment rails and an owned core. If its charter becomes operational, international fintechs could gain direct dollar infrastructure without relying on several sponsor and intermediary relationships. That is highly relevant to Canadian firms requiring dependable US accounts, liquidity and payment access.
The implementation will test whether one configurable core can support conventional and Shariah compliant products across a national banking network. Canadian banks and credit unions face the same challenge of replacing legacy infrastructure while preserving existing products, controls and customer access.
The priorities establish policy direction ahead of binding rules and connect AI development with consumer protection, personal data, automated public decisions and employment. Canadian institutions should watch how Australia assigns responsibility when AI agents influence prices, purchases and regulated decisions.
The decisions directly affect how fintech applications are discovered and how developers direct customers to alternative payment channels. Fairer search treatment could reduce dependence on a gatekeeper’s commerce products, while fewer steering restrictions could give fintechs greater control over pricing, billing and customer relationships. Canadian firms serving European users may need distinct distribution and payment strategies for DMA-compliant channels.
Stablecoin payment providers are beginning to place counterparty verification and authorization before settlement rather than treating compliance as a review after funds arrive. Banks, payment firms, exchanges, and custodians need to decide where approval occurs, which party controls it, what information travels with the payment, and how rejected or restricted transactions are handled across wallets and jurisdictions.
BitMEX helped establish perpetual swaps as a core crypto trading product, yet creating a market did not preserve its liquidity position. Kaiko data cited by Reuters placed daily trading volume near US$400,000 and market share below 0.01% when the closure was announced. The exit raises a market-structure question about whether smaller centralized venues can retain enough traders, market makers and revenue as activity concentrates among major exchanges and onchain platforms.
The Senate draft now connects market structure, intermediary registration, asset classification and political ethics in one legislative package. Digital asset firms should examine which activities would fall under SEC or CFTC supervision, how certification and custody requirements would work, and whether negotiations materially change the ethics, enforcement or implementation provisions before the bill advances.
Coinbase is preparing to compete for more than Canadian crypto trades. Derivatives provide the immediate entry point, while stocks, ETFs and prediction markets could eventually place it against Canadian brokerages and multi product investment platforms. Permitted client limits, dealer registration, product approvals, custody, disclosures and market surveillance will determine how much of the strategy reaches Canadian customers.
The strongest thread this week is control. Fintechs are gaining more direct access to payment networks, regulated markets, financial data and AI infrastructure. That access creates commercial opportunity, but it also places greater responsibility on firms to protect customer rights, govern automated decisions and keep critical systems resilient. For Canadian founders and investors, your advantage will come from owning a useful part of this infrastructure before access rules, operating economics and market positions harden. Follow the next developments through NCFA’s newsletter, explore connected opportunities in the Financial Innovation Map, or review the latest fintech insights.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
August 26th, 2025
January 4th, 2024
June 1st, 2021
September 9th, 2020
July 9th, 2018
January 3rd, 2018
September 25th, 2017
June 20th, 2017
May 10th, 2017
December 14th, 2016

NCFA Canada
Craig Asano
CEO and Executive Director
casano@ncfacanada.org
ncfacanada.org










