Global fintech and funding innovation ecosystem

Category Archives: Digital, NEO, Open Banking, Open Finance

UK Cryptoasset Regulations And FCA Final Rules

NCFA Regulatory Intelligence - UK FCA Final Cryptoasset Rules
NCFA Canada | Regulatory Intelligence | Digital Assets, Cryptoassets and Blockchain | Last updated July 19, 2026 | Status final FCA rules
NCFA Regulatory Intelligence
This guide explains UK cryptoasset regulations and the FCA final rules for authorisation, market access, implementation, compliance and opportunity analysis. Sources include FCA policy statements PS26/9 to PS26/13, finalised guidance FG26/5 to FG26/7 and the aggregate cost benefit analysis.
FCA Cryptoasset Regime Final rules for UK regulated cryptoasset activities

UK Cryptoasset Regulations And FCA Final Rules

The FCA published its final cryptoasset rules and guidance on 30 June 2026. The application period runs from 30 September 2026 to 28 February 2027, and the new regime starts on 25 October 2027. Use this guide to understand what the final rules require, what firms need to build, how the consultation outcome changed the design and where regulation creates market opportunities. Coverage includes admissions, disclosures, market abuse, stablecoin issuance, trading platforms, intermediaries, lending, borrowing, staking, safeguarding and custody, prudential requirements, Consumer Duty, governance, operational resilience, financial crime, reporting, redress, international firms and DeFi.

What Are The UK Cryptoasset Regulations?

The UK cryptoasset regulations bring specified cryptoasset activities into Financial Conduct Authority supervision under the Financial Services and Markets Act. The FCA final rules cover authorisation, trading platforms, intermediaries, stablecoin issuance, custody, lending, staking, disclosures, market abuse, prudential requirements, Consumer Duty, governance and operational resilience. The regime starts on 25 October 2027.

Final Rules Published30 June 2026
Applications Open30 September 2026
Application Deadline28 February 2027
Regime Starts25 October 2027
RegulatorFinancial Conduct Authority
Existing RegistrationMLR registration does not automatically convert to FSMA authorisation

UK Cryptoasset Regulation Journey

The UK has completed perimeter design, consultation and final FCA rulemaking. Firms now have an implementation period to prepare authorisation, governance, capital, custody, trading, stablecoin, market abuse and conduct systems before the regime starts.
Policy and consultation
Final rules and buildout
Implementation and supervision
Perimeter2023 to 2024 Cryptoasset activities brought into scope
Consultations2025 to 2026 CP25 and CP26 industry feedback
Final Rules30 June 2026 PS26/9 to PS26/13
Applications And Buildout30 Sep 2026 to 28 Feb 2027 Authorisation and systems preparation
Regime Starts25 October 2027 Handbook instruments commence
Supervision2027 onward Market conduct and resilience

Impact Analysis

Selected figures from the FCA aggregate cost benefit analysis and policy statements.
8%UK adults with cryptoasset holdings in 2025
£2,250Estimated average UK consumer crypto holding
£1.315BEstimated quantified firm costs over 10 years
£735MEstimated value of improved regulatory protections
£25MExample trading platform 10 year PV costs
£10MExample FSMA custodian entering crypto custody
£8MExample stablecoin issuer 10 year PV costs
£285MEstimated prudential requirement PV costs

What Firms Should Do Now

Firms that carry out or plan to carry out regulated cryptoasset activities should prepare their authorisation and implementation evidence before the application deadline.

  1. Map every UK activity against the regulated activity perimeter and identify any exclusions or special treatment.
  2. Determine whether the firm needs a new FCA authorisation or a variation of permission.
  3. Prepare a complete application for the period from 30 September 2026 to 28 February 2027 and apply as early as practical.
  4. Assign accountable owners across CRYPTO, CASS, CRYPTOPRU, Consumer Duty, SYSC, SM&CR, financial crime and reporting.
  5. Build evidence for governance, financial resources, custody, resilience, outsourcing, consumer outcomes and operational controls.
  6. Test systems and remediation plans before the regime starts on 25 October 2027.

Regulatory Intelligence Explorer

Navigate the FCA final cryptoasset regime by rule area. Each section separates requirements, implementation work, consultation outcome and NCFA’s strategic perspective.

Overview

Requirements The FCA package creates a full UK cryptoasset regime rather than a single rule. It combines designated activity rules for admissions and market abuse, regulated activity rules for trading platforms, intermediaries, lending, borrowing, staking and safeguarding, stablecoin issuance rules, prudential requirements and cross cutting FCA Handbook standards. The Handbook instruments commence on 25 October 2027.
  • The regime covers UK qualifying cryptoasset trading platforms, cryptoasset intermediaries, qualifying stablecoin issuers, custodians, lending and borrowing services, staking services and firms carrying on regulated cryptoasset activities in or into the UK
  • The final package includes CRYPTO sourcebook rules, CASS 16 for stablecoin backing assets, CASS 17 for safeguarding qualifying cryptoassets, CRYPTOPRU and COREPRU prudential rules, Consumer Duty, COBS, SYSC, SM&CR, DISP, FOS access, reporting and operational resilience requirements
  • The commencement sequence includes stablecoins, admissions, market abuse, intermediaries, trading platforms, lending, borrowing and staking, safeguarding, client asset consequentials, conduct and firm standards, and prudential instruments
  • The FCA kept the broad policy architecture but made targeted changes for proportionality, including stablecoin backing asset simplification, best execution clarification, removal of principal dealers from pre trade transparency, and operational resilience guidance
Implementation Firms should build a regime map by activity, not by document title. A single firm may need authorisation, admissions controls, disclosures, surveillance, custody arrangements, CASS controls, prudential calculations, Consumer Duty evidence, financial crime controls, operational resilience testing and regulatory reporting. The implementation plan should assign accountable owners for each CRYPTO, CASS, SYSC, COBS, SM&CR, DISP and CRYPTOPRU dependency.
Consultation Outcome
  • The FCA moved from consultation to final rules while preserving the regime design
  • Respondents generally supported a comprehensive regime, but pushed for proportionality, international competitiveness and operational clarity
  • The FCA responded with targeted refinements rather than a lighter perimeter
  • Remaining open items include further guidance on DeFi decentralisation and separate DLT operational resilience guidance
NCFA Perspective This is a regulatory market structure event. The UK is setting a supervised operating model for crypto as financial infrastructure. The strategic question is which firms can turn authorisation, custody, stablecoin operations, market surveillance, prudential analytics and conduct evidence into repeatable operating capability before the regime goes live.

Scope and Authorisation

Requirements The regime applies to regulated cryptoasset activities brought into scope by the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 and implemented through FCA Handbook instruments. Activities include operating a qualifying cryptoasset trading platform, dealing, arranging, qualifying cryptoasset lending and borrowing, staking, safeguarding and qualifying stablecoin issuance. Firms conducting those activities will need FCA authorisation unless an exclusion or specific treatment applies.
  • UK QCATP operators require authorisation where they operate in the UK or serve UK consumers from overseas
  • International firms are assessed against threshold conditions including location of offices, effective supervision, appropriate resources, suitability and business model
  • Dual regulated firms may operate in the UK through a branch where the PRA is satisfied threshold conditions and ongoing requirements are met
  • The FCA expects an authorisation gateway before the regime goes live, with firms preparing systems, controls and evidence in advance
  • Existing cryptoasset MLR registration does not replace FSMA authorisation for regulated cryptoasset activities
Implementation Firms should map every UK facing activity to the regulated activity perimeter and authorisation pathway. The implementation file should include corporate structure, UK presence, branch or subsidiary analysis, overseas service model, governance, financial resources, systems and controls, operational resilience, outsourcing, financial crime and Consumer Duty evidence.
Consultation Outcome
  • The FCA clarified its approach to international firms and branches following feedback
  • The final approach remains cautious about cross border firms serving UK consumers without clear UK accountability
  • The FCA did not create a broad equivalence shortcut in the final package
  • The authorisation runway becomes a key commercial dependency for firms seeking UK market access
NCFA Perspective Scope is the competitive gate. The UK is giving global crypto firms a route into a regulated market, but the route depends on authorisation evidence, supervision, governance and operational substance. That is different from simply allowing offshore activity to reach UK users.

Admissions and Disclosures

Requirements The admissions and disclosure framework governs admission of qualifying cryptoassets to trading on UK QCATPs and offers to the public of qualifying cryptoassets admitted to trading. It uses qualifying cryptoasset disclosure documents, admission criteria, due diligence, responsibility allocation and disclosure obligations to create a baseline for market entry.
  • UK QCATP operators must establish admission criteria and assess whether a qualifying cryptoasset should be admitted to trading
  • Offerors and relevant issuers must produce qualifying cryptoasset disclosure documents where required
  • Disclosure documents must support informed decisions and include material information about the cryptoasset, rights, risks, technology, governance and project context
  • Trading platforms need procedures for disclosure review, admission decisions, record keeping and ongoing monitoring
  • Relevant issuers and offerors face responsibility for statements and omissions in disclosure documents
  • Protected forward looking statements have specific treatment under the regime
  • Firms must manage the link between admissions, disclosures, market abuse controls and post admission monitoring
Implementation Implementation requires an admissions committee or equivalent control function, written admission criteria, due diligence checklists, disclosure templates, issuer and offeror attestations, legal review, technology risk review, conflict checks, decision records and post admission triggers. Platforms should prepare a repository for disclosure documents, versions, approvals, rejection reasons and ongoing updates.
Consultation Outcome
  • The FCA retained the admissions and disclosure framework after consultation
  • The final rules are designed to support market integrity without importing traditional securities listing rules wholesale
  • Firms will need to show how disclosures are complete, fair and understandable for the relevant market
  • The burden falls heavily on platforms because admission decisions become a regulated control point
NCFA Perspective Admissions are where market access becomes a regulated quality filter. The practical opportunity is not only listing more tokens. It is building repeatable disclosure, due diligence, legal review and issuer data infrastructure that can support credible cryptoasset markets.

Market Abuse

Requirements The market abuse regime addresses insider dealing, unlawful disclosure of inside information and market manipulation in qualifying cryptoassets and related instruments. The FCA rules and guidance set out concepts, prohibited behaviours and systems requirements for UK QCATP operators and cryptoasset intermediaries.
  • CRYPTO 4 provides guidance on inside information, insider dealing, unlawful disclosure and market manipulation
  • UK QCATP operators and cryptoasset intermediaries must prevent, detect and disrupt cryptoasset market abuse
  • Operators need systems and procedures for monitoring orders, transactions, communications, suspicious behaviour and abusive patterns
  • Firms must receive and store notifications securely with completeness, integrity and confidentiality
  • Market abuse arrangements must address crypto specific risks such as cross venue trading, on chain activity, token issuance events, concentrated holdings and information asymmetry
  • Outsourcing or delegation does not remove responsibility for compliance
  • Firms need records that can support investigation, escalation and regulator engagement
Implementation Firms should build surveillance scenarios for insider dealing, pump and dump activity, spoofing, wash trading, manipulation around token admissions, misuse of issuer information, coordinated social activity and suspicious on chain transfers. Platforms should integrate order book data, trade data, wallet data where available, issuer announcements, disclosure documents and escalation logs.
Consultation Outcome
  • The final package applies a market abuse model tailored to cryptoasset markets while drawing on familiar FCA concepts
  • The FCA expects trading venues and intermediaries to operate proactive controls rather than relying only on post event enforcement
  • Secure notification and evidence handling are explicit operational requirements
  • The regime creates a compliance technology need across surveillance, data integrity and case management
NCFA Perspective Market abuse is the credibility test for regulated crypto trading. The UK framework will only support institutional adoption if market surveillance, disclosure timing and manipulation controls are strong enough to distinguish regulated markets from speculative venues.

Stablecoin Issuance

Requirements PS26/10 sets final rules for non systemic UK issued qualifying stablecoins, covering issuance, backing assets, redemption, safeguarding and disclosures. CASS 16 governs management and safeguarding of backing asset pools. The FCA’s approach treats stablecoins as money like instruments where trust depends on backing, segregation, redemption, reconciliation and clear disclosures.
  • Issuers must maintain a backing asset pool for each qualifying stablecoin product and segregate it from the firm’s own assets and from other backing pools
  • Backing pools must be held in backing funds accounts or backing assets accounts meeting CASS conditions
  • Issuers using expanded backing assets must calculate the backing asset composition requirement every redemption day
  • The core backing asset requirement is the higher of 5% and the highest redemption percentage over the previous 180 redemption days or shorter operating history
  • Issuers must promptly notify the FCA if they cease to comply with specified backing asset requirements, with a limited exception for rebalancing after a daily calculation
  • Backing assets are held on statutory trust for holders of the qualifying stablecoin
  • Backing asset pools for different stablecoin products must be separate, distinct, independently managed and held in different accounts
  • Stablecoin funds must be promptly paid into a backing funds account or invested in assets held in a backing assets account
  • Issuers must conduct internal and external safeguarding reconciliations, identify and resolve discrepancies and maintain records
  • Redemption requirements include T+1 expectations, with KYC checks completed before the redemption period begins
  • Issuers must provide disclosures and make holders aware of withdrawal rights
  • The FCA allows limited intragroup custody subject to safeguards and allows a 5% excess in the backing asset pool
Implementation Stablecoin issuers need a dedicated operating model for backing assets, liquidity, reconciliation, redemption, disclosures, trust accounting, custodian oversight and holder communications. Implementation should include product level backing pool ledgers, daily BACR calculations where expanded assets are used, reconciliation workflows, FCA notification triggers, redemption queue logic, KYC timing controls, disclosure history and governance over tokenized versions of backing assets.
Consultation Outcome
  • The FCA simplified the backing asset composition requirement after feedback that forward looking redemption estimates were complex and burdensome
  • The FCA kept the range of permissible backing assets and rejected broader LVNAV and non UK UCITS MMF expansion because of stability concerns
  • Tokenized versions of permissible backing assets are not prohibited if they comply with CASS 16 and custody requirements
  • Redemption timelines were adjusted so KYC checks are completed before the redemption period begins
  • The FCA confirmed statutory trust arrangements and made refinements to third party and intragroup custody treatment
NCFA Perspective Stablecoin issuance is where compliance becomes product architecture. The winners will not be the firms that simply issue tokens. They will be the firms that can evidence backing, redemption, liquidity, disclosure and custody controls well enough for consumers, institutions and regulators to treat stablecoins as usable financial infrastructure.

Trading Platforms

Requirements PS26/11 sets rules for UK qualifying cryptoasset trading platforms. The framework covers location and authorisation, platform access, operating rules, conflicts, settlement arrangements, transparency, record keeping and reporting. The FCA expects platforms serving UK consumers to operate through an authorised UK model or an acceptable international firm structure.
  • UK QCATP operators require FCA authorisation if operating in the UK or serving UK consumers from overseas
  • Platforms must have operating rules, admission processes, access standards and controls for orderly trading
  • Retail customer focused requirements apply where platforms serve retail clients
  • Platforms must manage conflicts of interest, including risks around affiliated activities, proprietary activity, token admissions and market data
  • Settlement arrangements must be clear, reliable and consistent with safeguarding and operational resilience requirements
  • Transparency, record keeping and reporting obligations apply to orders, transactions and platform operation
  • Best execution expectations interact with authorised execution venues and periodic post trade analysis
  • Principal dealers were removed from pre trade transparency requirements in the final approach
  • Platforms need market abuse prevention, detection and disruption arrangements under PS26/9
Implementation Platform implementation should include authorisation planning, operating rulebook, access policy, admission governance, conflicts register, surveillance tooling, settlement design, order and trade records, client reporting, market data controls, resilience mapping and incident response. Firms should evidence why venue access, matching, settlement, custody and conflict controls protect consumers and market integrity.
Consultation Outcome
  • The FCA clarified location, incorporation and international firm expectations after feedback
  • Principal dealers were removed from pre trade transparency requirements
  • Best execution was clarified so firms should check prices from at least three reliable UK authorised execution venues where possible but do not need mechanical transaction by transaction checks or execution on those venues
  • The FCA retained the broader platform framework and added guidance rather than reducing the venue perimeter
NCFA Perspective Trading platforms are the centre of the regulated market. The commercial question is whether UK authorised venues can offer credible liquidity, transparent execution and institutional controls without losing users to offshore platforms that do not meet the same standard.

Intermediaries

Requirements The intermediary rules cover firms dealing in qualifying cryptoassets as principal, arranging deals and providing related intermediation services. They connect execution quality, client communication, conflicts, payments for order flow, authorised venue interaction, conduct obligations and prudential requirements.
  • Intermediaries must understand which regulated activity they perform and whether they deal, arrange, route, introduce or support client execution
  • Execution arrangements must be effective and supported by periodic post trade analysis
  • Firms should check prices from at least three reliable UK authorised execution venues where possible
  • The FCA clarified that firms are not required to execute on those venues or perform mechanical transaction by transaction checks if effective arrangements are in place
  • Conflicts, remuneration, inducements and payments for order flow require controls
  • Client communications and conduct obligations apply through COBS and Consumer Duty where relevant
  • Intermediaries may be subject to prudential requirements, financial crime controls, operational resilience and reporting
Implementation Intermediaries should build an execution policy, venue assessment framework, periodic price review, conflicts assessment, client disclosure process, order routing records, remuneration review and evidence that client outcomes are monitored. Firms with global routing models need controls showing how UK clients receive fair treatment under the UK regime.
Consultation Outcome
  • The FCA responded to feedback by clarifying best execution rather than imposing venue execution mandates
  • The final rules seek to balance execution quality with the reality of fragmented global crypto liquidity
  • Concerns about the arranging perimeter and international firms were addressed through guidance and refinements
  • Intermediaries remain a high implementation burden because conduct, execution, financial crime and prudential requirements overlap
NCFA Perspective Intermediation is where user experience meets regulatory discipline. Firms that can route orders well, evidence execution quality and manage conflicts may turn compliance into trust. Firms that treat execution as a black box will struggle under the new model.

Lending and Borrowing

Requirements The lending and borrowing chapter applies to authorised cryptoasset firms providing qualifying cryptoasset lending or borrowing services to retail clients who are not overseas retail clients, with certain requirements also applying to clients who are not overseas clients. Firms remain responsible where they comply through third parties such as custodians or service providers.
  • Firms must provide retail clients with information about the firm and the qualifying cryptoasset lending or borrowing service before the client is bound or before service provision
  • Information must be provided in a durable medium or through a qualifying website, mobile application or digital medium
  • Where clients give express prior consent for yield to be used in further lending, firms may not need to repeat the information requirement for that yield use
  • Retail protections apply to lending and borrowing service design, client information and risk communication
  • Firms remain responsible for compliance when using third party custodians or service providers
  • Rules and controls must address collateral, yield, client reporting, service risk, counterparty risk and return of assets
  • Lending and borrowing firms will also need prudential, safeguarding, operational resilience, financial crime and Consumer Duty evidence
Implementation Implementation should include client information templates, durable medium controls, express consent capture, yield treatment logic, collateral policy, counterparty due diligence, risk disclosures, client reporting, third party contracts, custody links, withdrawal and return processes, and complaint handling. Firms should stress test whether clients understand rehypothecation, loss, yield, liquidity and counterparty risk.
Consultation Outcome
  • The FCA confirmed retail protections for lending and borrowing as part of the final PS26/11 package
  • The rules preserve firm accountability even where service delivery uses third parties
  • Final refinements address collateral and service design issues but keep lending and borrowing inside a regulated conduct baseline
  • This is one of the areas where Consumer Duty evidence will matter because product risk can be hard for retail clients to understand
NCFA Perspective Crypto lending is no longer being treated as a purely private yield product. The UK regime pushes it toward regulated product governance, clear client information and controlled service design. That could reduce high risk models but may also create room for safer institutional and collateral services.

Staking

Requirements The staking framework in PS26/11 confirms retail protections and targeted refinements to staking rules, including treatment of auto staking. Staking services create operational, validator, custody, disclosure and client outcome risks that connect to safeguarding, operational resilience and Consumer Duty.
  • Firms providing staking services must identify whether the service is within the regulated perimeter and which client protections apply
  • Client information should explain staking arrangements, validator risk, lockups, slashing, rewards, fees, liquidity, tax or reporting context where relevant and operational dependencies
  • Auto staking treatment was refined in the final rules
  • Where staking uses validators, node operators, custodians or other service providers, the authorised firm remains accountable for regulated obligations
  • Operational resilience guidance identifies validator risk and validator outages as crypto specific risks
  • Firms need records showing staking instructions, rewards, fees, losses, slashing events, service disruptions and client communications
Implementation Implementation should include validator due diligence, staking policy, client consent flows, reward calculation controls, fee disclosure, slashing incident workflow, exit queue process, asset segregation, outsourcing or third party arrangements and resilience testing for validator outages. Firms should connect staking risk to Consumer Duty outcomes and complaint handling.
Consultation Outcome
  • The FCA retained staking inside the final activity framework while making targeted refinements
  • Operational resilience guidance specifically highlights validator risks and outages
  • The final approach does not remove staking risk but requires firms to evidence controls and client understanding
  • Further market practice will likely shape supervisory expectations after go live
NCFA Perspective Staking is a good example of regulation translating crypto native activity into financial services controls. The opportunity is not simply offering yield. It is making staking understandable, monitored, resilient and institutionally acceptable.

Safeguarding and Custody

Requirements The FCA applies safeguarding requirements through CASS 17 for qualifying cryptoassets and related CASS amendments. Custody and safeguarding are central to the regime because many cryptoasset failures come from weak asset control, poor segregation, private key compromise, unclear client ownership or inadequate third party oversight.
  • Firms safeguarding qualifying cryptoassets must comply with CASS 17 requirements tailored to cryptoasset custody
  • Safeguarding requirements interact with CASS 16 where tokenized stablecoin backing assets or qualifying stablecoin custody is involved
  • Firms need arrangements for holding, recording, reconciling and protecting client cryptoassets
  • Private key management, wallet infrastructure, access controls, signing authority and recovery procedures are core operational controls
  • Third party custody or infrastructure arrangements require due diligence, contractual protections and ongoing oversight
  • Client reporting must ensure clients can access information, including where information is available on chain
  • Custody controls link to operational resilience, financial crime, Consumer Duty, dispute resolution, complaints and prudential requirements
Implementation Custodians and firms using custodians should document wallet architecture, key ceremony, MPC or HSM controls, cold and warm wallet policies, access roles, transaction approval, reconciliation, incident response, third party oversight, bankruptcy analysis, client asset records, insurance or financial resources and client reporting. Firms should test private key loss, unauthorized signing, chain outage, custodian failure and reconciliation breaks.
Consultation Outcome
  • The FCA confirmed application of safeguarding requirements under CASS 17 with cryptoasset specific adjustments
  • The FCA did not create a separate SM&CR prescribed responsibility for digital asset custody because existing custody PRs cover custody of a broad range of assets
  • Limited intragroup custody is permitted for stablecoin backing arrangements subject to safeguards
  • The final regime gives custody a central role in institutional trust and consumer protection
NCFA Perspective Custody is likely to be the most important infrastructure layer in the regime. Regulated crypto markets cannot scale without credible asset control, private key governance, reconciliation and failure recovery. This is where specialist infrastructure providers may gain durable advantage.

Prudential Requirements

Requirements PS26/12 creates a prudential framework for regulated cryptoasset firms covering capital, own funds, concentration risk, liquid assets, overall risk assessment and public disclosure. It uses CRYPTOPRU and COREPRU amendments to establish a baseline that reflects cryptoasset risks without simply importing bank prudential rules.
  • Firms must meet own funds definition and composition requirements
  • Own funds requirements include fixed overhead and K factor based components where applicable
  • The operational risk K factor for stablecoin issuance was reduced from 2% to 1% in the final rules
  • The revised market risk framework applies a single 40% net cryptoasset position requirement for K NCP where assets can be prudently valued and are admitted to a UK QCATP
  • Cryptoassets that do not meet the conditions are deducted from regulatory capital and subject to a 100% volatility adjustment for K CCD
  • Concentration risk and liquid asset requirements apply to support resilience
  • Firms must conduct overall risk assessments and maintain adequate financial resources
  • Public disclosure obligations are included with proportionality refinements
  • Prudential obligations apply alongside activity specific conduct, custody, stablecoin and Handbook requirements
Implementation Firms should build prudential models by activity and balance sheet exposure. Required work includes own funds classification, K factor calculation, stablecoin issuance exposure, custody and platform activity mapping, cryptoasset valuation policy, capital deduction logic, liquid asset monitoring, concentration risk limits, stress testing, management information, public disclosure process and board sign off.
Consultation Outcome
  • The FCA largely maintained the prudential architecture but recalibrated key areas for proportionality
  • Stablecoin operational risk capital was reduced from 2% to 1%
  • The market risk framework was simplified to a 40% treatment for qualifying prudently valued assets admitted to a UK QCATP and deduction or 100% volatility adjustment for others
  • The public disclosure regime was made more proportionate
  • Respondents supported prudential clarity but raised concerns about calibration, competitiveness and operational burden
NCFA Perspective Prudential rules turn crypto firms into regulated financial businesses with capital and liquidity discipline. The effect may be fewer casual entrants, but stronger survivors. The commercial opportunity is prudential analytics, treasury management, disclosure tooling and capital efficient operating models.

Consumer Duty and Conduct

Requirements PS26/13 applies key FCA Handbook standards to regulated cryptoasset activities, including Consumer Duty, COBS, conduct rules, dispute resolution, compensation treatment and reporting. Most firms carrying on regulated cryptoasset activities will be subject to these cross cutting obligations, with specific exceptions for certain professional client platform activity and platform member transactions.
  • Consumer Duty applies to relevant cryptoasset activity subject to defined scope and exclusions
  • Principles 6 and 9 and Consumer Duty do not apply when operating a qualifying CATP for professional clients
  • Certain Principles and Consumer Duty do not apply to transactions concluded between members or participants under the rules of a qualifying cryptoasset trading platform
  • The FCA clarified Consumer Duty guidance on territorial scope, fair value, consumer support, consumer understanding and manufacturer or distributor roles
  • COBS standards apply to relevant cryptoasset conduct and communications
  • Firms need evidence that products, services, support and communications deliver appropriate outcomes
  • DISP and Financial Ombudsman Service access apply to relevant complaints
  • Compensation and redress rules are part of the broader Handbook application
Implementation Implementation should include Consumer Duty outcome mapping by activity, customer journey review, product governance, fair value assessment, communication testing, support standards, vulnerability considerations, complaints data, MI dashboards and board reporting. Crypto firms should prove that customers understand custody, stablecoin, staking, lending, execution and volatility risks before and after purchase.
Consultation Outcome
  • The FCA made clarifications rather than retreating from applying Consumer Duty and conduct standards
  • UK issued qualifying stablecoins were excluded from the definition of restricted mass market investments
  • Consumer Duty guidance was clarified across fair value, support, understanding and supply chain roles
  • The final approach signals that crypto conduct standards should converge with regulated financial services expectations
NCFA Perspective This is one of the strongest differences between regulated crypto and offshore crypto. The UK model requires firms to evidence consumer outcomes, not only publish risk warnings. Firms that can make complex products understandable may have a material trust advantage.

Governance and SM&CR

Requirements The FCA applies Senior Management Arrangements, Systems and Controls and the Senior Managers and Certification Regime to cryptoasset firms. Governance requirements cover risk management, controls, accountability, prescribed responsibilities, operational resilience, financial crime, custody and board oversight.
  • SYSC 4 to SYSC 10 apply to qualifying cryptoasset firms according to firm type and common platform status
  • SM&CR applies to relevant cryptoasset firms with proportionality and threshold treatment
  • The enhanced SM&CR threshold for qualifying UK stablecoin issuers is set at £20 billion, intended to capture the most significant stablecoins over time
  • Smaller and medium sized stablecoin issuers are not expected to fall into enhanced SM&CR at commencement
  • Existing prescribed responsibilities are used for custody rather than creating separate digital asset custody PRs
  • Senior management responsibilities include financial crime, operational resilience, compliance, safeguarding, prudential risk and conduct outcomes where relevant
  • Governance must support FCA supervision, authorisation evidence and ongoing compliance
Implementation Firms should build a management responsibilities map, committee structure, board reporting pack, policy owner register, control owners, prescribed responsibility allocation, SMF evidence, certification population, conduct training, breach escalation and decision records. Stablecoin issuers should monitor whether scale could bring enhanced SM&CR into scope over time.
Consultation Outcome
  • The FCA adjusted the enhanced threshold for qualifying UK stablecoin issuers in light of Bank of England proposals
  • The FCA expects the £20 billion threshold to capture 1% or less of the firm population and likely no firms at commencement
  • The FCA declined to create separate prescribed responsibilities for cryptoasset custody
  • Governance requirements were largely maintained with targeted proportionality refinements
NCFA Perspective Governance is where regulatory permission becomes accountable execution. The UK is not just authorising products. It is assigning responsibility to named leaders, boards and control functions. That will shape who can credibly scale.

Operational Resilience

Requirements The FCA extends SYSC 15A operational resilience to cryptoasset firms and provides FG26/6 to explain cryptoasset specific risks. Firms must identify important business services, set impact tolerances, map dependencies and conduct scenario testing. SYSC 4, SYSC 7 and SYSC 8 complement the framework through risk management, controls and outsourcing requirements.
  • Firms must have sound, effective and comprehensive strategies, processes and systems proportionate to their nature, scale and complexity
  • Important business services must be identified and mapped across people, processes, technology, facilities and information
  • Impact tolerances must be set and tested through severe but plausible scenarios
  • Crypto specific risks include smart contract vulnerabilities, private key security risks, validator risks, service disruptions, cyber risks, DLT dependencies and emerging technologies such as AI and quantum computing
  • FG26/6 highlights cyber and technology resilience, cryptographic key and infrastructure safeguarding, continuity and disruption planning
  • Outsourcing expectations cover custody infrastructure, MPC and HSM providers, validator services, cloud providers and security critical transaction signing infrastructure
  • Permissionless DLT use should not be treated as outsourcing under SYSC 8.1.1R, but firms remain responsible for operational resilience controls
  • Firms should conduct targeted vulnerability scans, penetration tests and maintain monitoring and logging evidence
Implementation Implementation should produce a live resilience map for every important business service. Firms need dependency mapping, wallet and key infrastructure controls, validator due diligence, smart contract testing, cyber controls, incident playbooks, impact tolerance testing, penetration testing, cloud and third party oversight, logging, operational dashboards and board reporting. Scenario tests should include private key compromise, smart contract failure, validator outage, chain disruption, trading outage, stablecoin reconciliation failure and custodian failure.
Consultation Outcome
  • 91% of respondents supported extending SYSC 15A to cryptoasset firms and 88% supported the guidance approach
  • 98% supported the view that permissionless DLTs should not be treated as outsourcing
  • The FCA kept the extension of operational resilience while adding crypto specific guidance
  • Further non Handbook guidance on DLT operational resilience is expected later
NCFA Perspective Operational resilience is where the FCA regime becomes more than conduct regulation. Crypto firms are technology firms with financial risk. The UK framework makes uptime, key security, third party dependency and recovery capability part of the regulatory value proposition.

Financial Crime

Requirements PS26/13 applies the financial crime elements of SYSC 6, the Financial Crime Guide and Financial Crime Thematic Reviews to firms conducting regulated cryptoasset activities. These obligations sit alongside the Money Laundering Regulations and Travel Rule obligations already applicable to UK cryptoasset exchange providers and custodian wallet providers.
  • Cryptoasset firms conducting regulated activities must follow the same financial crime framework as other FSMA authorised firms where applicable
  • Relevant Handbook references include SYSC 6.1.1R adequate policies and procedures, SYSC 6.3.1R systems and controls, SYSC 6.3.3R financial crime risk assessments, SYSC 6.3.8R senior manager responsibility and SYSC 6.3.9R MLRO
  • Firms must comply with MLRs and the Travel Rule alongside FSMA obligations
  • Policies and procedures must be comprehensive and proportionate to the nature, scale and complexity of activities
  • Controls should identify, assess, monitor and manage money laundering, sanctions, fraud, terrorist financing, bribery, corruption and market abuse related risk
  • Financial crime evidence must connect to onboarding, transaction monitoring, wallet screening, custody, stablecoin issuance, trading, lending and staking
Implementation Implementation should include risk assessment, customer due diligence, wallet and blockchain analytics, sanctions screening, Travel Rule workflow, suspicious activity reporting, transaction monitoring, fraud controls, stablecoin redemption screening, market abuse escalation, MLRO governance, senior manager accountability, periodic control testing and audit trails.
Consultation Outcome
  • The FCA retained the proposal to apply financial crime rules and guidance to cryptoasset firms
  • The FCA views the same financial crime baseline as proportionate for cryptoasset firms despite sector specific risks
  • The regime operates alongside MLR registration and Travel Rule obligations, so firms face overlapping compliance layers
  • Financial crime controls become part of authorisation readiness and ongoing supervision
NCFA Perspective Financial crime is central to regulatory legitimacy. The UK regime will reward firms that can combine on chain analytics with traditional financial crime governance. This is also a clear opportunity for regtech, wallet intelligence and compliance automation.

Reporting and Redress

Requirements PS26/13 applies reporting, dispute resolution and redress architecture to regulated cryptoasset activities. Firms need to report to the FCA, maintain records, handle complaints, provide access to the Financial Ombudsman Service where relevant and preserve evidence across product, custody, execution, conduct and prudential areas.
  • Regulatory reporting applies to cryptoasset firms under the Handbook application package
  • Firms need data on activities, clients, complaints, prudential position, operational resilience, financial crime controls and other supervisory metrics
  • DISP and access to the Financial Ombudsman Service apply where relevant
  • Complaint handling must connect to Consumer Duty, client reporting, custody, execution, lending, staking and stablecoin redemption issues
  • Record keeping requirements apply across admissions, market abuse, client orders, transactions, lending, borrowing, staking, safeguarding and reporting
  • Public disclosure obligations apply in the prudential regime with proportionality refinements
  • Firms need evidence retention policies that allow supervisory reconstruction of decisions and client outcomes
Implementation Firms should build a reporting data model before go live. Required work includes regulatory returns ownership, data lineage, complaints taxonomy, FOS workflow, prudential reporting data, custody records, client statements, execution data, surveillance cases, operational incidents, financial crime alerts and board MI. Manual reporting will be risky given the breadth of the regime.
Consultation Outcome
  • The FCA made focused amendments to reporting requirements in PS26/13
  • The prudential disclosure regime was made more proportionate
  • The overall approach keeps crypto inside existing FCA supervisory and redress architecture
  • Reporting and redress obligations will expose weak data governance quickly after authorisation
NCFA Perspective Reporting is the regime’s memory. Firms that cannot reconstruct decisions, client outcomes, custody records or prudential positions will struggle to defend their operating model. Good reporting infrastructure becomes a strategic asset, not only a compliance cost.

International Firms

Requirements The FCA’s approach to international cryptoasset firms sets expectations for firms seeking UK authorisation while serving UK consumers. It focuses on threshold conditions, location of offices, effective supervision, appropriate resources, suitability and business model. The final guidance clarifies branch treatment for dual regulated firms where PRA conditions are satisfied.
  • International firms requiring FCA authorisation must meet minimum standards at application and on an ongoing basis
  • The FCA considers location of offices, effective supervision, appropriate resources, suitability and business model
  • The FCA identifies higher consumer and market harm risk where international firms serve UK customers through branches rather than UK legal entities
  • Dual regulated firms may operate through a UK branch where the PRA is satisfied threshold conditions and ongoing requirements are met
  • International models must demonstrate accountability, supervision, client protection, operational resilience and financial crime controls
  • Cross border liquidity access may be relevant, but does not remove UK authorisation and governance expectations
Implementation International firms should prepare a UK market access file covering branch or subsidiary choice, governance, UK senior managers, service model, outsourcing, group support, capital, liquidity, client disclosures, data location, custody, financial crime, operational resilience and how UK customers are protected if overseas operations fail.
Consultation Outcome
  • The FCA clarified the international firm approach after feedback in CP26/4
  • The final guidance acknowledges branches for dual regulated firms where PRA expectations are met
  • The FCA did not make overseas access easy simply because liquidity is global
  • The approach tries to balance global liquidity with UK accountability and effective supervision
NCFA Perspective This is where the UK tries to attract global crypto firms without importing offshore risk. The strongest firms will treat UK authorisation as a credible market badge, not a light touch registration.

DeFi

Requirements The FCA’s current approach to decentralised finance is to apply rules where there is an identifiable controlling entity, with separate guidance to follow on how decentralisation will be assessed in practice. DeFi is treated as a range of financial services marketed with a high degree of automation rather than as a blanket exemption from regulation.
  • Rules apply where there is an identifiable controlling entity
  • Separate guidance is expected on how decentralisation will be assessed
  • DeFi interfaces, arrangements and controlling entities may fall within regulated activity analysis
  • Automation does not by itself remove regulatory obligations
  • Firms must assess governance, control, user interface, protocol dependency, custody, financial promotion, market abuse, lending, staking and consumer risk
  • DeFi related activity may also raise operational resilience, financial crime, Consumer Duty and international firm issues
Implementation Firms should document who controls the interface, protocol parameters, governance keys, admin rights, fee flows, custody, upgrade authority, user onboarding, compliance controls and consumer communications. A DeFi implementation file should show whether the business is genuinely decentralised or whether an identifiable entity directs regulated activity.
Consultation Outcome
  • The FCA retained the principle that identifiable controlling entities bring DeFi activity within regulatory reach
  • The FCA acknowledged the need for separate guidance on decentralisation assessment
  • The final approach avoids treating DeFi labels as determinative
  • This remains a watch area because future guidance will likely affect interface operators, protocol sponsors and infrastructure providers
NCFA Perspective DeFi is the frontier test for the regime. The key issue is control. If a business can control access, fees, governance, listings or user experience, regulators are unlikely to treat it as outside the market structure simply because the protocol uses smart contracts.

UK Cryptoasset Regulations FAQ

When do the UK cryptoasset regulations start?

The new FCA cryptoasset regime starts on 25 October 2027.

When can firms apply for FCA cryptoasset authorisation?

The scheduled application period runs from 30 September 2026 to 28 February 2027. Firms seeking to rely on saving and transitional provisions should apply within that period.

Does an existing MLR registration become FCA authorisation?

No. Existing registrations and permissions do not automatically convert. A firm carrying on an in scope regulated cryptoasset activity will need the relevant FSMA permission.

Which cryptoasset activities are covered?

The regime covers activities including operating qualifying cryptoasset trading platforms, dealing, arranging, stablecoin issuance, custody, lending, borrowing and staking. Admissions, disclosures and market abuse rules also apply.

Which FCA rulebooks apply to cryptoasset firms?

The package includes the CRYPTO sourcebook, CASS 16 and CASS 17, CRYPTOPRU and COREPRU, plus relevant Consumer Duty, COBS, SYSC, SM&CR, DISP, reporting and operational resilience requirements.

What should firms prioritise before applying?

Firms should confirm scope, prepare governance and financial resource evidence, document custody and resilience controls, assess Consumer Duty outcomes and build a complete authorisation file for their business model.

Continue Exploring

How Tokenization Became a Business Investors Can MeasureConnects the FCA regime to the shift from crypto speculation toward measurable, investable tokenized infrastructureRead the story
How Is Crypto Custody Regulation Changing?Useful for custody, safeguarding, CASS 17, institutional trust and operational control questionsRead the question
UK FCA Plans Full Crypto Licensing Regime by 2026Background on the UK path from policy design and consultation toward a full cryptoasset regimeReview the buildout
FCA Chair on Crypto, Stablecoins and Digital Asset RegulationPolicy signal connecting crypto regulation, stablecoins, consumer risk, scams and the FCA's long running supervisory directionRead the speech context
Stablecoin Data Shows Payments Reality GapMarket evidence on why stablecoin payments need trust, liquidity, distribution and operating infrastructureRead the analysis
Tokenized Infrastructure Is Changing How Markets OperateMarket infrastructure context for tokenized cash, settlement, collateral, custody and regulated railsRead the insight

From Regulation to Opportunity

The FCA regime creates demand for regulated infrastructure across stablecoins, custody, market surveillance, disclosure, trading systems, prudential analytics, operational resilience, Consumer Duty evidence, reporting and compliance automation. The closest NCFA opportunity layer is the Programmable Stablecoin Payments brief, which examines where compliant stablecoin infrastructure can create practical payment and settlement use cases.

Open the Stablecoin Payments Opportunity Brief


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights

NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Canada’s Open Banking Regulatory Intelligence Guide

Jun 29, 2026 | NCFA Resource | Open Banking Open Finance, Regulation And Policy

Last updated: September 11, 2026

Canada open banking and Consumer Driven Banking regulatory intelligence guide

Canada Open Banking Rules For Readiness And Consultation

NCFA has published a new Regulatory Intelligence guide to Canada Open Banking and Consumer Driven Banking Rules. The interactive resource organizes the proposed regulations, implementation requirements, consultation questions and strategic issues shaping Canada’s regulated open banking framework.

For a broader view of Open Banking and Consumer-Driven Finance, including the Canadian market map, 146 learning modules, company intelligence, global benchmarks and interactive discussions, explore NCFA Open Banking & Consumer-Driven Finance Interactive Intelligence.

The guide tracks accreditation, data scope, consent, authentication, security, technical standards, liability, reporting, complaints, national security review, fees and administrative monetary penalties. It also explains why consumer trust, fraud prevention and clear accountability are central to implementation. For further analysis, see Canada's Open Banking Strategy Starts With Trust.

What It Does In Practice

The resource gives readers a structured way to understand what the proposed Consumer Driven Banking Regulations would require before final rules are published.

Instead of treating the regulations as one long legal document, the guide breaks them into operating topics. Each section separates regulatory requirements, implementation work, consultation considerations and NCFA’s strategic perspective.

Canada’s open banking framework is progressing from policy design into regulatory implementation. Firms need to understand more than API access. They need to prepare evidence for accreditation, consumer consent flows, registry checks, authentication records, security safeguards, breach response, complaint procedures, service standards, reporting obligations and board level accountability.

The 60-day Canada Gazette consultation closed on August 26, 2026. The proposed regulations remain subject to finalization, while firms continue preparing for accreditation, supervision, data-sharing, consent, security and operational requirements.

Who Gets Value

This resource is useful for fintech founders, open banking platforms, financial institutions, credit unions, payment service providers, data aggregators, regtech providers, compliance teams, investors, policymakers and industry associations.

It is especially useful for organizations assessing accreditation, product design, consent architecture, data sharing duties, technical standards, cybersecurity, consumer protection and implementation costs.

Strengths And Limits

The strength of this resource is its focus on regulatory readiness. It converts the proposed Consumer Driven Banking Regulations into a practical intelligence layer that can support planning, consultation, product design and ecosystem coordination.

The guide connects the proposed regulations to Canada’s policy objectives, including stronger consumer protection, fraud mitigation, secure financial data sharing, competition and confidence in the open banking framework.

It also connects regulation to commercial opportunity. The guide identifies where read access, data portability, identity and income verification, cash flow analysis, embedded workflows, write access and open finance may create future product and infrastructure demand.

The regulations remain proposed and may change following consultation. Readers should use the guide for ecosystem intelligence and planning, not as legal, financial, investment, compliance or professional advice.

Key Resources

Canada Open Banking and Consumer Driven Banking Rules (primary NCFA Regulatory Intelligence guide)

NCFA Open Banking & Consumer-Driven Finance Interactive Intelligence (market map, 146 learning modules, company intelligence, discussions and global benchmarks)

Canada's Open Banking Strategy Starts With Trust (consumer protection and fraud readiness)

Open Banking In Canada Opportunity Brief (commercial opportunity layer)

NCFA Financial Innovation Map (ecosystem context)

Proposed Consumer-Driven Banking Regulations (official Canada Gazette source)


National Crowdfunding and Fintech Association of CanadaThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Canada Open Banking and Consumer Driven Banking Rules

NCFA Regulatory Intelligence - Canada Open Banking And Consumer Driven Banking Rules
NCFA Canada | Regulatory Intelligence | Open Banking and Consumer Driven Banking | Last updated September 11, 2026 | Status proposed regulations, consultation closed
NCFA Regulatory Intelligence
This guide explains Canada’s open banking framework through the proposed Consumer Driven Banking Regulations, including accreditation, consent, data sharing, security, liability, supervision and implementation. Sources include the Canada Gazette, the Regulatory Impact Analysis Statement, the Consumer Driven Banking Act, Finance Canada, Bank of Canada materials and the Office of the Privacy Commissioner of Canada’s August 26 submission.
Canada Open Banking

Proposed Consumer Driven Banking Regulations

Canada Open Banking and Consumer Driven Banking Rules

Canada’s proposed Consumer Driven Banking Regulations establish the operating framework for open banking. They address accreditation, consumer consent, data sharing, security, technical standards, liability, complaints, reporting, national security review and enforcement.

Use this guide to understand the proposed requirements, the implementation work they create and the post-consultation issues that may affect banks, credit unions, payment service providers, fintechs, consumers and small businesses.

The 60-day consultation closed August 26, 2026. The regulations remain proposed while Finance Canada considers feedback and prepares the next regulatory steps. Firms can use the published draft for planning, but final requirements and implementation timing may still change.

For a broader view of Open Banking and Consumer-Driven Finance beyond the regulatory framework, explore NCFA Open Banking & Consumer-Driven Finance Interactive Intelligence, including the Canadian Market Map, 146 learning modules, company intelligence, discussions, innovation themes and global benchmarks.

Canada’s Open Banking and Consumer Driven Banking Journey

Canada has advanced from open banking policy development into proposed Consumer Driven Banking Regulations under Bank of Canada oversight. The consultation closed on August 26, 2026. The current stage is regulatory finalization and supervisory preparation.
Launch read access and data mobility
Next write access
Consultation2018 to 2022 open banking policy review
Framework2023 to 2024 Consumer Driven Banking design
2026 Currentconsultation closed, final rules pending Bank of Canada supervision framework and implementation preparation
Read Accesslaunch phase secure data sharing and data mobility
Data Productsnear term verification, cash flow and embedded workflows
Write Accessnext phase payment initiation and account actions
Open Financelonger term broader financial product scope

Impact Analysis

Key figures from the Regulatory Impact Analysis Statement and proposed regulations.
$13.2BEstimated 10 year benefits
$457.7MEstimated 10 year costs
9MCanadians using data sharing services
680Affected businesses in central scenario
578Small businesses affected
$89,133Average annualized small business cost estimate
99.5%Monthly endpoint availability
$10MMaximum entity or ATPSP penalty

Regulatory Intelligence Explorer

Navigate the proposed regulations by topic. Each section separates requirements, implementation work, post-consultation issues to watch and NCFA’s strategic perspective.

Overview

Requirements The proposed regulations support implementation of the Consumer Driven Banking Act and create the operating layer for Canada’s open banking framework. They prescribe the data covered by the Act, accreditation information and requirements, accreditation fees, review timelines, revocation notices, accredited third party service provider requirements, national security information requirements, Ministerial review timelines, data sharing duties, exceptions to sharing, service standards, security safeguards, breach reports, responsible officer information, authentication steps, consumer signs, change notices, annual reporting, record keeping, liability related consumer notices, complaint procedures, technical standards body reporting, evidentiary privilege, assessments, administrative monetary penalties and coming into force rules.
  • Definition of Act and prescribed covered data
  • Accreditation applications for federal or provincial financial institutions, RPAA registered payment service providers, other entities and accredited third party service providers
  • Bank of Canada electronic application system, accreditation fee, refusal review and revocation processes
  • National security information package, Ministerial decision period, review period, extensions and review rights
  • Registry based verification before sharing data and exceptions where sharing can be withheld
  • Service standards for response times, endpoint availability, planned outages and traffic management
  • Security safeguards, breach reporting and responsible officer reporting
  • Authentication, acknowledgement and consent connected to secure data sharing
  • Notices, annual reporting, record keeping, liability, complaints, technical standards body reporting, assessments and violations
Implementation Organizations should build a regulatory inventory that maps each requirement to a system, policy owner, evidence file and supervisory reporting obligation. The Bank of Canada says its supervisory framework will cover participating entities, governance, risk management, operational resilience and monitoring of trends and issues. The first implementation work is not only API build. It includes accreditation evidence, national security information, data classification, registry checks, consent design, authentication records, breach playbooks, service monitoring, complaint intake, record retention, change notices, fee modelling, ATPSP contracts and board level accountability.
Post-Consultation Watch
  • Whether the framework gives enough implementation runway between final regulations, Bank of Canada guidance and coming into force
  • Whether proportionality is strong enough for small firms and RPAA registered payment service providers without reducing consumer trust
  • Whether guidance should clarify connections between fraud, consent, complaints, liability, security events and record keeping
  • Whether the technical standards body, conformance testing and service performance rules should be clearer before launch
  • Whether the cost and reporting model supports competition or favours organizations with existing compliance infrastructure
  • Whether consumers and SMEs will be able to understand which entities are accredited, which data is covered and how complaints or deletion requests work
August 26 Privacy Commissioner Submission The Office of the Privacy Commissioner of Canada supports the aims of consumer-driven banking and several privacy protections in the proposed regulations, but recommends changes before finalization.
  • Specify the individual data elements covered by the framework more clearly so consumers can understand what may be shared
  • Strengthen accreditation evidence in several pathways, including safeguards, complaints, authentication, dashboards, technical-standard evidence and selected insurance or integrity requirements
  • Narrow the consent exception for publicly available data so it does not capture information where a consumer has a reasonable expectation of privacy
  • Add an overarching requirement for safeguards appropriate to the sensitivity of the data as technology and threats change
  • Clarify coordination between the Privacy Commissioner and the Bank of Canada where privacy and supervisory responsibilities intersect
NCFA Perspective This is a trust and market structure test. Canada is defining the participation standard for a regulated financial data market. The strongest framework will not be the one with the most rules. It will be the one that makes safe participation practical, keeps consumer control understandable and lets credible new entrants compete without pushing the ecosystem into a narrow, incumbent led implementation path.

Application and Data

Requirements The regulations define the Act and prescribe the data to which the consumer driven banking framework applies. Covered data includes data relating to consumers of the covered products or services, account and product identifiers, the terms under which products and services are provided, balances or amounts owing, completed, pending and pre authorized transactions, and information about products or services available or offered to consumers. The data scope is tied to the products and services referred to in the Act and must be shared only through the regulated framework once the relevant duties apply.
  • Identity related data for consumers of covered products or services
  • Account numbers, branch numbers, transit numbers and other product or service identifiers
  • Product and service terms, including fees, interest rates and authorizations
  • Current and past balances or amounts owing
  • Completed, pending and pre authorized transaction data
  • Information about products or services available or offered to consumers, including terms
  • Historical limits apply in the data sharing rules for balances, transactions and available or offered products and services older than 24 months
  • Covered data must be tied to a valid data sharing request, participant verification, consumer authentication and consent
Implementation Participants need a data inventory that maps each covered category to source systems, product owners, API fields, consent screens, retention rules, deletion workflows, complaints, liability records and service monitoring. Data providers should identify where product terms, balances, transaction history and account identifiers are stored, how far history is available, what data is excluded, and how data quality issues will be handled when another participant relies on the information.
Post-Consultation Watch
  • Whether Finance Canada adopts the Privacy Commissioner’s recommendation to specify the individual data elements within each covered category more clearly
  • Whether the treatment of derived, inferred or enriched data needs clearer boundaries
  • Whether the 24 month historical limit is sufficient for SME finance, lending, accounting and cash flow use cases
  • Whether business accounts, joint accounts, delegated authority and multi user permissions need more detailed guidance
  • Whether future open finance expansion should be signalled earlier to reduce later redesign
  • Whether data quality, correction and dispute processes need a clearer connection to complaints and liability
NCFA Perspective Data scope is the first market boundary. A narrow read access model can still support verification, underwriting, cash flow analysis, switching, accounting and embedded workflows. The larger Canadian opportunity depends on whether this foundation can expand cleanly into write access, payment initiation and broader open finance without rebuilding the trust layer from scratch.

Accreditation

Requirements The accreditation rules prescribe different application pathways for federal or provincial financial institutions, RPAA registered payment service providers, other entities and accredited third party service providers. Applications must be submitted through the Bank of Canada electronic system. Common information includes legal and trade names, formation details, civic and mailing addresses, contact information, website, application contact, organizational and governance structure, regulatory or supervisory oversight, foreign open banking registration or accreditation status, designated officer or employee details, consumer complaint contact information, technical standard evidence and national security information. RPAA registered PSPs and other entities must also provide Canadian place of business declarations, whether they operate from a dwelling house, independent third party confirmation of security safeguards, insurance or guarantee evidence, and integrity and good character policies for individuals with significant responsibility. Other entities must additionally describe how they will meet specified Act requirements, complaint procedures, external complaints body membership status and estimated consumer numbers.
  • Federal or provincial financial institution applications include security compliance declaration, designated officer details, complaint contact, technical standard evidence and national security information
  • RPAA registered PSP applications include Canadian place of business, dwelling house declaration, independent security confirmation, technical standard evidence, insurance or guarantee and integrity policy or good character information
  • Other entity applications include similar information plus descriptions of how they will meet specified duties, complaint procedures, external complaints body membership and estimated consumer numbers
  • RPAA registered PSPs and other entities must maintain place of business, insurance or guarantee and integrity or good character requirements after accreditation
  • The accreditation fee is $2,500 in the first year and then indexed to September CPI, rounded to the nearest $100, with no decrease from the previous year
  • An applicant has 30 days to request Governor review of an accreditation refusal, and the Governor has 120 days after giving an opportunity to make representations to accredit or confirm refusal
  • Participating entities requesting voluntary revocation must provide consumers with name and contact, planned request date, impact assessment, deletion notice and complaint resolution information
  • A participating entity has 30 days to request Governor review of a notice of intent to revoke accreditation, and the Governor has 60 days after giving an opportunity to make representations to revoke or withdraw the notice
  • Former participating entities must notify consumers of revocation date, reasons, impact, deletion request requirement and complaint process
  • Accredited third party service provider applications include legal information, activity description, participating entity relationships, Canadian place of business, independent security confirmation, technical standard evidence, contract and policy information and national security information
Implementation Applicants should build a complete accreditation evidence file before applying. That file should include corporate and governance documents, regulatory status, technical standard evidence, security confirmation, insurance or guarantee evidence, complaint process, designated officer details, integrity policy, national security information, contracts with participants where relevant and consumer impact notices for potential exit. RPAA registered PSPs should map which information can be reused from RPAA registration and which requirements are new under CDB.
Post-Consultation Watch
  • Whether final accreditation rules adopt the Privacy Commissioner’s recommendations for stronger evidence in selected pathways, including safeguards, complaints, authentication, dashboards, technical-standard compliance, insurance or guarantees and integrity checks
  • Whether the independent third party confirmation of security safeguards should have defined qualifications or assurance standards
  • Whether insurance or guarantee sufficiency needs guidance so applicants can price participation
  • Whether the dwelling house declaration could create unnecessary ambiguity for remote first firms
  • Whether refusal, revocation and review timelines are workable for firms planning launch and funding milestones
  • Whether ATPSP accreditation requirements are clear enough for infrastructure providers that will support multiple participating entities
NCFA Perspective Accreditation sets the practical threshold for market participation. If evidence requirements are too light, the framework risks weak trust. If they are too heavy, innovation may concentrate among large institutions and compliance funded platforms. The policy challenge is not choosing between safety and competition. It is designing entry rules that reward credible operators without making participation uneconomic for the firms most likely to create new consumer and SME products.

Authentication and Consent

Requirements The proposed rules connect data sharing to verification, consumer authentication and consent. A participant receiving a request must verify the requesting entity and confirm through the registry that it is an accredited participating entity and not suspended in a way that prevents receiving data. A participant requesting data must verify the provider and confirm through the registry that the provider is accredited and not suspended in a way that prevents providing data. Authentication requires confirmation of the consumer’s authentication information using multi factor authentication. The consumer must acknowledge the requesting participant’s name, the nature of the request and the accounts from which the requested data will be provided before the data is shared and the consumer is redirected.
  • Requester and provider verification against the registry before sharing
  • Confirmation that accreditation has not been suspended or restricted by Bank conditions
  • Multi factor authentication of the consumer’s authentication information
  • Consumer acknowledgement of the requesting entity, nature of the request and relevant accounts
  • Data sharing only after verification, authentication and acknowledgement requirements are met
  • Renewal may be required after circumstances where data sharing was not required or consent has not yet been renewed
  • Consent evidence must connect to records, deletion requests, liability, complaints and annual reporting
Implementation Participants need registry lookup, accreditation status checks, suspension condition logic, MFA, acknowledgement capture, consent evidence, renewal workflows, revocation and deletion links, exception handling and audit trails. Authentication and consent should not be built as a user interface layer only. They need to produce evidence that can support annual reporting, complaint resolution, breach response, liability allocation and supervisory review.
Post-Consultation Watch
  • Whether the registry verification workflow is operationally clear for real time data sharing
  • Whether MFA requirements align with existing bank and fintech authentication journeys
  • Whether consent and acknowledgement guidance makes the sharing scope sufficiently specific for consumers to understand what information is captured
  • Whether consent renewal triggers and failed renewal situations need clearer examples
  • Whether consumer dashboards, consent receipts and cross provider visibility should be addressed in guidance
  • Whether consent evidence is sufficient to resolve liability, complaint and deletion disputes
NCFA Perspective Consent is one of the highest trust points in the framework. The market will not fail because consent screens are hard to build. It will fail if consumers cannot understand them, if participants cannot prove what was authorized, or if revocation and deletion are too hard to execute. This is where compliance design and product design become the same problem.

Security

Requirements The regulations prescribe detailed security safeguards for participating entities. Safeguards include vulnerability identification and remediation, regular updates, secure default configuration, security software, robust authentication, access management policies, unique accounts, data encryption and backup, network security controls, external storage policy, bans on unauthorized devices and applications, network traffic monitoring, suspicious content controls, inventory of systems and devices, third party service provider contract protections, employee cyber threat training and an incident response plan with log auditing and periodic exercises based on extreme but plausible scenarios. Safeguards must be proportionate to data sensitivity and network segmentation is permitted. Federal and provincial financial institutions are presumed to have implemented safeguards unless OSFI or the relevant provincial authority has identified deficiencies and directed remediation.
  • Vulnerability management and regular updates
  • Secure configuration by default
  • Security software on relevant systems and devices
  • Robust authentication methods
  • Role based access management policies
  • Unique accounts and minimized shared accounts
  • Encryption and regular backup of stored data
  • Network security controls for data in transit
  • External storage policy
  • Prohibition on unauthorized devices and applications
  • Monitoring and control of network traffic
  • Suspicious content identification, quarantine or blocking
  • Inventory of systems and devices used for sharing and storing covered data
  • Contract terms requiring third party service provider protection of data
  • Employee cyber threat training and ongoing updates
  • Incident response plan with detection, response, recovery, log auditing and scenario exercises
  • Responsible officer or employee details must be provided to the Bank without delay after designation
  • Breach reports to the Bank must include circumstances, known cause, date or period, affected data, number of consumers, potential impacts, mitigation and contact information
Implementation Participants should treat security as an accreditation and operating evidence file. Required work includes asset inventory, vulnerability program, configuration standards, endpoint and system security, identity and access controls, encryption, backup, network monitoring, third party contract review, cloud and vendor risk, cyber training, incident response testing, breach reporting templates and escalation paths to the Bank. Security records should be aligned with annual reporting, complaint records and liability evidence.
Post-Consultation Watch
  • Whether final rules add the Privacy Commissioner’s recommended overarching requirement for safeguards appropriate to data sensitivity as technology and threats change
  • Whether independent third party confirmation should follow a defined assurance framework
  • Whether breach reporting timing, consumer notification thresholds and report updates need more prescriptive examples
  • Whether third party and cloud contract requirements should include subcontractor and data location obligations
  • Whether small entrants can meet the same security evidence burden without shared infrastructure
  • Whether fraud, identity, authentication and cyber controls should be addressed together in Bank guidance
NCFA Perspective Security is the trust anchor. Consumer driven banking exists partly to replace unsafe credential sharing with supervised data access. That only works if security is operationally real, not a paper control. The framework must be strong enough to protect consumers and flexible enough that security compliance does not become the reason only the largest organizations can participate.

Technical Standards

Requirements The technical standard provisions operate through the Act and the regulations. Applicants must provide evidence of compliance with the technical standard referred to in the Act. Participating entities must declare technical standard compliance in annual reports. Data sharing systems must meet response time expectations consistent with generally accepted international standards, maintain 99.5 percent monthly availability excluding planned outages, and use traffic management only for technical stability or security in a proportionate, non discriminatory way. The technical standards body must submit an annual report to the Bank within seven days after each anniversary of its designation order. That report must describe vulnerabilities in the technical standard or standards body that had or could have had an impact on the security of data sharing, non technical descriptions of changes to data fields, features, functionality or other security relevant aspects of the technical standard, rationale and decision process for those changes, and changes relevant to the body’s designation.
  • Applicants must provide technical standard compliance evidence
  • Participating entities must report annual technical standard compliance
  • API or electronic system response times must align with generally accepted international standards
  • Data sharing systems must meet 99.5 percent monthly availability, excluding planned outages
  • Rate limiting, throttling and preferencing are restricted to stability and security purposes
  • Traffic management must be proportionate, non discriminatory and must not degrade consumer outcomes
  • Technical standards body annual report is due within seven days after each designation anniversary
  • Technical standards body must report vulnerabilities, causes, impacts, mitigation and contact person
  • Technical standards body must describe changes to data fields, features, functionality or security relevant aspects, plus rationale and decision process
  • Technical standards body must describe changes relevant to its designation factors
Implementation Technical teams need API inventory, conformance evidence, performance monitoring, availability measurement, outage notification, traffic management governance, test environment planning, error handling, historical data readiness, change management and documentation that can support Bank supervision. Firms should prepare for technical standard versioning and for annual evidence that systems remained compliant through the reporting year.
Post-Consultation Watch
  • Whether the technical standards body should be identified or its governance clarified before final implementation planning
  • Whether conformance testing should be mandatory before production access
  • Whether response time expectations should be converted into measurable standards
  • Whether 99.5 percent availability is sufficient for higher value financial workflows
  • Whether public reporting of availability, outages and API performance would strengthen trust
  • Whether technical standard changes should have notice periods, backwards compatibility expectations and migration timelines
NCFA Perspective Technical standards are where the framework becomes real infrastructure. Canada’s competitive position will depend less on whether APIs exist and more on whether standards, testing, versioning and change management let participants build once and scale. Ambiguity here can turn regulatory permission into integration drag.

Liability

Requirements The liability provisions clarify consumer responsibility and the allocation of responsibility between participating entities. Every participating entity must inform consumers of the consequences of gross negligence or, in Quebec, gross fault in safeguarding authentication information. It must advise consumers of reasonable measures they can take to safeguard authentication information. It must not intentionally mislead consumers about the extent of their liability or adopt policies that presume consumer liability contrary to the Act. Where a consumer is not liable for a financial loss arising from loss, unauthorized access or unauthorized use of data shared under the Act, liability between participating entities is determined by where the loss, access or use occurred. The requester is liable to the extent it occurs in relation to the requester securely receiving or managing the data. The provider is liable to the extent it occurs in relation to provider authentication or secure provision of the data.
  • Consumers must be informed about gross negligence or gross fault consequences for authentication information
  • Consumers must be advised of reasonable safeguarding measures
  • Participants must not mislead consumers about liability
  • Participants must not adopt policies presuming consumer liability contrary to the Act
  • Requester liability follows failures connected to receiving or managing data
  • Provider liability follows failures connected to authenticating the consumer or securely providing data
  • Liability evidence depends on consent, authentication, registry checks, transmission logs, receipt records, complaint files and incident records
Implementation Participants should prepare consumer notices on authentication information, avoid default liability language, align customer support scripts with the Act, and preserve records that show where an event occurred. Liability operations require authentication logs, consent evidence, registry verification, data transmission records, receipt confirmations, access logs, incident investigations, complaint handling and remediation decisions.
Post-Consultation Watch
  • Whether gross negligence or gross fault communications will be understandable for consumers
  • Whether liability allocation is clear enough for multi party flows involving ATPSPs
  • Whether examples should clarify direct financial loss, unauthorized access, data loss and failed revocation
  • Whether consumer support and complaint processes need stronger alignment with liability rules
  • Whether records required to prove liability should be specified more explicitly
  • Whether fraud and scam scenarios are sufficiently covered by the liability architecture
NCFA Perspective Liability will be tested in edge cases, not in clean diagrams. The strategic issue is whether the framework can resolve consumer harm quickly without turning every incident into a multi party blame exercise. Clear evidence rules can build trust. Unclear responsibility can undermine adoption even if the technology works.

Reporting Requirements

Requirements The proposed regulations require change notices, annual reports and records sufficient to demonstrate compliance. Changes that must be reported include names or contact information, organizational structure, RPAA registration status for entities accredited under the RPAA pathway, Canadian regulatory oversight, foreign open banking registration or accreditation, designated officer contact, complaint contact, external complaints body membership, significant responsibility individuals and integrity status, insurance or guarantee sufficiency, technical standard compliance and national security information. Some changes must be reported within 30 days after they occur, some as soon as feasible after awareness, some at least 30 days before taking effect and some at least 60 days before taking effect. Annual reports must provide monthly metrics on non sharing events, express consents, consent renewals, withdrawals, deletion requests, system availability, data sharing counterparties, successful data provisions and average response time. They must also include changes, policy and procedure updates, breach summaries, planned and unplanned outages, technical standard declaration, financial metrics, supervisory deficiency declarations for financial institutions and security safeguard implementation descriptions for certain accredited entities. Records must be sufficient to demonstrate compliance, kept electronically in a format intelligible to the Bank, retained for five years after they cease to demonstrate current compliance unless otherwise specified, and protected against loss, destruction, falsification, inaccuracy and unauthorized access or use.
  • Notice of change categories cover identity, structure, registration, oversight, foreign accreditation, officers, complaints, EBC membership, significant responsibility individuals, insurance or guarantee, technical standard compliance and national security information
  • Notice timing includes 30 days after occurrence, as soon as feasible, at least 30 days before certain changes and at least 60 days before certain data storage or processing country changes
  • Annual report metrics include monthly non sharing counts and reasons
  • Annual report metrics include express consents, renewals, withdrawals and deletion requests
  • Annual report metrics include uptime, data sharing counterparties, delivery counts and average response time
  • Annual report must include changes, policy updates, breach summary, outages, technical compliance declaration and financial metrics
  • Records must demonstrate compliance with the Act and regulations
  • Records must be electronic and intelligible to the Bank
  • Records must generally be kept for five years after they cease to demonstrate current compliance
  • Records must be protected from loss, destruction, falsification, inaccuracies and unauthorized access or use
  • ATPSPs must keep compliance records, contracts with participants and policies or procedures relating to services they perform for participants, with the same electronic form and protection rules
  • Certain supervisory information, Bank directions, compliance agreements and supervisory correspondence are privileged for civil evidence purposes, with specified exceptions for use by the Minister, Governor, Bank, Attorney General of Canada, participants or ATPSPs in certain proceedings
Implementation Participants need a compliance data model that captures events as they happen. Manual annual reporting will be fragile. Systems should collect consent events, renewal events, withdrawal events, deletion requests, non sharing reasons, uptime, response time, outage data, breaches, policy changes, material changes, complaint records and financial metrics. Record retention and protection should be built into the architecture before production data flows begin.
Post-Consultation Watch
  • Whether the notice timing categories are clear enough for operational teams to apply consistently
  • Whether annual reporting should align with RPAA and other Bank of Canada reporting regimes where possible
  • Whether public transparency reporting on uptime, outages, complaints and non sharing events would strengthen trust
  • Whether smaller firms need proportional reporting without weakening supervisory visibility
  • Whether five year record retention is practical across all evidence categories
  • Whether privileged supervisory information rules strike the right balance between supervision, litigation risk and transparency
NCFA Perspective Reporting and records are the hidden operating system of regulated open banking. They may matter more than any single product feature because they determine whether trust can be audited, problems can be reconstructed and smaller firms can participate without building a bank sized compliance department.

Complaints

Requirements The regulations require complaint handling information at accreditation and connect complaints to revocation notices, consumer contact information, external complaints body membership and records. Other entity applicants must describe intended complaint procedures, the officers or employees to be designated for complaint responsibilities, and the contact information consumers will use. A participating entity requesting revocation or a former participating entity whose accreditation has been revoked must provide consumers with information about the process for resolving outstanding complaints. Annual reporting must describe changes to complaint related procedures. Record keeping must support compliance and complaint evidence. ATPSPs must keep contracts and related policies or procedures where they perform activities for participating entities.
  • Complaint contact information is required in accreditation applications
  • Other entity applications must describe complaint procedures and designated complaint roles
  • External complaints body membership status is required for certain applicants
  • Revocation and former participant notices must include complaint resolution information
  • Complaint processes connect to annual reporting and record keeping
  • Complaint evidence should align with consent, authentication, data sharing, security, breach and liability records
Implementation Participants should design complaint intake, triage, escalation, evidence review, consumer communication, external complaints body routing, remediation, root cause analysis and reporting. Complaint workflows should identify whether the issue relates to access, failed sharing, revoked consent, deletion, fraud, data quality, breach, liability or service availability.
Post-Consultation Watch
  • Whether complaint timelines and escalation expectations should be more explicit
  • Whether consumers will know whether to contact the provider, requester, ATPSP, bank or external complaints body
  • Whether SMEs need distinct complaint pathways for business account use cases
  • Whether complaint data should feed into supervisory or public transparency reporting
  • Whether complaints involving data quality, failed sharing, deletion or fraud require specific treatment
NCFA Perspective Complaint handling will be a public trust signal. Consumers rarely judge infrastructure by how it works on a perfect day. They judge it by what happens when something breaks, money is lost, access fails or nobody knows who is responsible.

National Security Review

Requirements The regulations prescribe extensive information for national security review and timelines for Ministerial decisions. Applicants must provide information about legal name, trade names, jurisdictions, addresses, contact information, business activities, financial services, affiliates, ownership and control, individuals or entities with significant voting or ownership interests, board members, highly compensated senior officers, major creditors, state owned enterprise ownership or appointment powers, categories of personal or financial information gathered or planned to be gathered, countries where the applicant or third party service providers store or process that information, and individuals or entities outside employees or agents that may receive access to that information. The Minister has 60 days after receiving the application copy to decide whether to review, with extensions in 60 day periods. If a review proceeds, the Minister has 180 days, with 180 day extensions. Applicants have 30 days to request review of a directive to refuse accreditation. Applicants must provide requested additional information within 30 days. For suspension and revocation, participants or ATPSPs have 30 days to request review of a notice of the Minister’s intent to direct revocation. Former participants and former ATPSPs must provide specified information to consumers or participating entities. Additional information requested by the Bank must be provided within 15 days.
  • Ownership, control, affiliates, significant influence and voting or ownership interest information
  • Countries of residence, citizenship, incorporation or formation for relevant individuals and entities
  • Board member and five most highly compensated senior officer information
  • Five largest creditors and credit agreement terms
  • State owned enterprise ownership, voting interest or appointment powers
  • Categories of personal and financial information gathered or planned, including identifying information, financial data, private communications and geolocation data
  • Countries where applicant or third party service providers store or process information
  • Non employee or non agent individuals or entities that may access the information
  • 60 day Ministerial decision window to review, extendable by 60 day periods
  • 180 day national security review period, extendable by 180 day periods
  • 30 day applicant review request period for refusal directive
  • 30 day period to provide additional requested information under subsection 54(2)
  • 30 day review request period for notice of intent to direct revocation
  • 15 day period to provide additional information requested by the Bank under subsection 71(2)
Implementation Applicants should prepare a national security file before applying, not after questions arrive. That file should include ownership charts, control analysis, citizenship and residency information, affiliates, creditors, SOE exposure, data categories, data storage and processing locations, cloud and vendor access, third party access, board and senior officer information, and change monitoring. Deal teams should assess how fundraising, acquisitions, data residency, vendor changes and cross border processing could affect review risk.
Post-Consultation Watch
  • Whether the national security information package is proportionate for lower risk applicants
  • Whether significant influence, creditor exposure and third party access require clearer guidance
  • Whether data residency and cross border processing expectations should be clarified before applications begin
  • Whether the 60 day and 180 day review timelines could materially affect investment, partnership and launch planning
  • Whether applicants should have a pre filing process or informal guidance pathway for complex ownership structures
  • Whether national security review should be harmonized with broader financial infrastructure, digital identity and cloud risk policy
NCFA Perspective This connects open banking to financial infrastructure security. It is not a side process. National security review can affect who enters the market, which investors participate, where data is processed, which vendors are acceptable and how exits are structured. If handled clearly, it can strengthen trust. If handled opaquely, it can slow capital and partnership formation.

Assessments and Fees

Requirements The regulations set an indexed accreditation fee and annual assessments. The accreditation fee is $2,500 in the year the section comes into force. In later years it is calculated as $2,500 multiplied by the ratio of the September all items CPI for Canada in the year before application to the September CPI in the year the section comes into force, rounded to the nearest $100, with no decrease from the previous year. Participating entity assessments are calculated as base assessment plus variable assessment minus interim assessments. Base assessments depend on total asset value. Entities with at least $1 trillion in assets pay a $150,000 base amount; $100 billion to under $1 trillion pay $100,000; $10 billion to under $100 billion pay $50,000; $1 billion to under $10 billion pay $20,000; and under $1 billion pay $10,000. Variable assessment shares allocate remaining Bank costs after deductions by asset tier using 0.4, 0.3, 0.2 and 0.1 factors for the larger asset tiers, while the under $1 billion category has no variable amount. Subsidiary assets are excluded where the subsidiary is itself a participating entity. ATPSPs are assessed $10,000 per year less interim assessments. The external complaints body is assessed $50,000 per year less interim assessments, reduced proportionally for a partial year. Information requested about assets must be provided by March 31 following the relevant calendar year when requested by December 31, or within 15 days for other requests. If asset information is not provided on time, the entity is treated as being in the highest asset category for assessment purposes.
  • $2,500 first year accreditation fee
  • CPI indexed accreditation fee after first year, rounded to nearest $100 and not allowed to decrease
  • Participating entity assessment equals base assessment plus variable assessment minus interim assessment
  • Base assessment tiers of $150,000, $100,000, $50,000, $20,000 and $10,000 based on total assets
  • Variable assessment shares of 0.4, 0.3, 0.2 and 0.1 for larger asset tiers
  • No variable assessment for entities with less than $1 billion in assets
  • ATPSP annual assessment of $10,000 less interim assessments
  • External complaints body annual assessment of $50,000 less interim assessments, prorated for partial year designation
  • Asset information deadline of March 31 in specified cases and 15 days in other cases
  • Failure to provide asset information can result in assessment as if the entity were in the highest asset category
Implementation Participants should model accreditation fees, annual assessment tier, possible variable assessment, interim assessments, ATPSP fees, external complaints body implications, insurance or guarantee costs, technical build, security assurance, reporting systems and compliance staffing. Smaller firms should assess whether direct participation, ATPSP services, partnership or staged entry creates a viable cost structure.
Post-Consultation Watch
  • Whether the base assessment tiers are proportionate for mid sized and smaller participants
  • Whether the zero variable assessment for under $1 billion firms is enough to support competition
  • Whether ATPSP fixed fees support shared infrastructure economics
  • Whether asset based assessment is the right proxy for supervisory cost or market impact
  • Whether fee predictability is sufficient for early entrants and investors
  • Whether the highest tier default for missing asset information is too punitive or necessary for compliance discipline
NCFA Perspective The fee schedule is only one part of participation cost. The strategic issue is total regulatory operating cost. If cost scales poorly, Canada could see a market where participation is open in law but concentrated in practice. Shared infrastructure, clear guidance and proportionate reporting may determine whether smaller innovators can enter.

Administrative Monetary Penalties

Requirements The regulations designate violations for contraventions of a long list of Act provisions, specified regulation provisions, non compliance with compliance agreements and non compliance with Bank directions. The designated Act provisions include obligations related to accreditation, suspension conditions, former entity notices, ATPSP activities, prescribed information, data sharing, use of registry, privacy, security, designated officer, breach reporting, authentication, consent, deletion, notices, liability, complaints, records, technical standards, reporting, Bank information requests and other framework duties. The designated regulation provisions include failure to notify another participating entity of non sharing reasons, data sharing service standards, responsible officer information, specified reporting and notice provisions, record keeping provisions and ATPSP record keeping provisions. The Act provides maximum penalties of up to $1 million for individuals and up to $10 million for participating entities or ATPSPs.
  • Contraventions of numerous Act provisions are designated as violations
  • Contraventions of selected regulation provisions are designated as violations
  • Non compliance with compliance agreements is designated as a violation
  • Non compliance with specified Bank directions is designated as a violation
  • Regulation violations include non sharing notice failures, service standard failures, officer reporting failures, notice failures, annual reporting failures and record keeping failures
  • Maximum penalty of $1 million for individuals
  • Maximum penalty of $10 million for participating entities or ATPSPs
  • Penalty exposure connects to accreditation, data sharing, registry use, privacy, security, breach reporting, authentication, consent, deletion, liability, complaints, technical standards, reporting, records and Bank information requests
  • Coming into force is staged by Act sections, with most regulations coming into force when section 44 of the Act comes into force, data sharing and many operational obligations when section 76 comes into force, and assessment provisions when section 140 comes into force
Implementation Participants should map every designated violation to an internal control, evidence record and accountable owner. Enforcement readiness should cover consent, registry checks, non sharing notices, uptime, breach reporting, annual reporting, records, complaints, officer information, Bank information requests, compliance agreements and directions. Boards and senior leaders should understand which failures create individual or organizational exposure.
Post-Consultation Watch
  • Whether violation categories are clear enough for participants to map controls before launch
  • Whether penalty exposure is proportionate across firms of different size and role
  • Whether remediation and self reporting should affect penalty treatment
  • Whether public enforcement disclosure will be used to strengthen market discipline
  • Whether staged coming into force gives firms enough time to build controls before penalties apply
  • Whether individual exposure could affect senior officer recruitment and governance design
NCFA Perspective Penalty risk is less about the headline maximum and more about whether an organization can prove it had controls, records and remediation processes in place before something went wrong. Enforcement should strengthen trust without chilling responsible innovation. That balance will matter as Canada tries to turn regulatory credibility into market adoption.

Related NCFA Intelligence

Open Banking in Canada Opportunity BriefCommercial opportunity layer connected to this regulatory guide Open the brief
Financial Innovation MapWhere consumer driven banking fits in the broader fintech innovation ecosystem View the map
Research LibrarySupporting reports, market evidence and policy research Research library
Fraud regulatory perspectiveTrust, fraud controls and consumer protection context for Canada’s open banking strategy Read the fraud perspective

From Regulation to Opportunity

Canada’s proposed Consumer Driven Banking Regulations create readiness questions across accreditation, consent, data scope, APIs, cybersecurity, reporting, liability, supervision, national security review and enforcement. NCFA tracks commercial opportunities separately in the Open Banking in Canada Opportunity Brief, where regulatory evidence connects to product opportunities, investment themes, implementation gaps and emerging market signals.

Open the Opportunity Brief


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights

NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Canada’s Open Banking Strategy Starts With Trust

June 29, 2026 | NCFA Feature | Open Banking And Open Finance, Digital Identity And Trust, Cybersecurity And Fraud, Risk Compliance And Regtech, Fintech And Innovation

AI Image – Canada’s Consumer Driven Banking framework showing a secure digital trust layer

Fraud, Consent And Liability Before Open Finance Scale

On June 26, 2026, the Government of Canada published Consumer Driven Banking regulations together with new fraud prevention regulations, the most significant progress in Canada's open banking implementation since legislation received Royal Assent earlier this year.

At first glance, the two regulatory packages appear separate. One establishes the operating rules for consumer driven banking. The other requires federally regulated banks to strengthen fraud prevention for electronic funds transfers.

Together, however, they reveal something much bigger.

Canada isn't simply launching open banking. It's building the trust infrastructure needed before open finance can scale.

The problem is that millions of Canadians already share their financial information through screen scraping, a practice tracked as a core open banking risk in Bank Of Canada Signals Open Banking Timing Risk. Finance Canada estimates roughly nine million Canadians currently use screen scraping despite the security, liability, and consumer protection concerns it creates. The new framework is designed to replace that model with accredited participants, standardized APIs, consumer controlled consent, and clear accountability.

The Regulations Explain Canada's Strategy

Much of the early discussion around open banking has focused on data portability. The regulations suggest Finance Canada sees the challenge differently.

Data sharing is only one part of the system.

  • Consumers must know who can access their information
  • Financial institutions must know who they are sharing data with
  • Accredited participants must meet common operational and security requirements
  • Liability must be clear when something goes wrong
  • Fraud must be monitored
  • Technical standards must allow systems to communicate securely
  • Consumers need complaint mechanisms and regulatory oversight

Only after these pieces exist does secure data sharing become practical.

The Regulatory Impact Analysis estimates the framework will generate approximately $13.2 billion in net benefits over ten years, compared with implementation costs of about $457.7 million, largely through greater competition, improved consumer choice, reduced friction, and innovation.

Those numbers reinforce that Consumer Driven Banking is being treated as national financial infrastructure rather than another fintech initiative.

Why Fraud Rules Arrived At The Same Time

Some viewed the fraud regulations as a separate announcement, but the timing suggests otherwise.

As consumers gain greater control over financial data and eventually broader payment functionality, fraud risks also change. Criminals increasingly exploit social engineering, account takeover, impersonation, and authorized push payment scams rather than technical weaknesses alone.

Finance Canada's fraud framework responds by requiring federally regulated banks to establish policies and procedures to detect, prevent, and mitigate consumer targeted fraud involving electronic funds transfers.

The regulations also introduce stronger expectations around consumer controls, including the ability to manage transaction capabilities and limits, express consent before enabling electronic funds transfer functionality, and fraud reporting to the Financial Consumer Agency of Canada.

Greater consumer control must be matched by stronger consumer protection.  The inherent message is that the federal government wants to make fraud prevention part of the architecture rather than an afterthought.

Canada Is Turning Trust Into Rules

Reading the regulations together shows that trust is no longer treated as a policy objective. It's becoming operational and the framework combines:

  • consumer controlled consent
  • accreditation of participating organizations
  • secure API based data exchange
  • authentication requirements
  • defined liability arrangements
  • technical standards
  • record keeping obligations
  • ongoing supervision
  • consumer complaint processes
  • fraud monitoring and reporting

None of those capabilities creates value on its own, but collectively they create an environment where consumers, banks, fintechs, and regulators can exchange financial information with greater confidence than today's screen scraping model.

The regulations therefore answer an important implementation question that has existed since Canada's open banking discussions began several years ago.

Trust is not assumed. It's engineered.

Every Regulatory Requirement Creates A Product Opportunity

The regulations also strengthen several areas already appearing across NCFA's Financial Innovation Map.

Consumer consent requirements create opportunities for consent orchestration platforms that help consumers understand, grant, renew, and withdraw permissions across multiple financial relationships.

Accreditation requirements create opportunities for compliance operations platforms that help fintech companies prepare for accreditation, maintain operational controls, manage evidence, and demonstrate ongoing compliance.

Fraud obligations strengthen demand for behavioural fraud analytics, scam detection, mule account monitoring, transaction risk scoring, and real time payment controls.

Authentication requirements reinforce opportunities for digital identity, credential management, and secure customer authentication.

Technical standards create demand for API testing, interoperability tools, certification services, and developer infrastructure.

Liability and complaint provisions strengthen opportunities for workflow automation covering dispute management, evidence collection, case handling, and regulatory reporting.

None of these businesses exists because regulators explicitly created them, but they will emerge because every operational requirement creates work that financial institutions and technology providers must perform efficiently.  And that's often where durable fintech companies are built.

Canada Is Building Beyond Read Only Banking

The initial Consumer Driven Banking framework focuses on secure consumer permissioned data sharing. It's an intentional starting point.

Once accreditation, liability, consent management, authentication, and technical standards mature, the same infrastructure can support broader open finance capabilities, including additional financial products and, potentially, future write access.

The regulations therefore describe more than the first phase of open banking. They establish the operating foundation for future financial data ecosystems.

The opportunity is not limited to data sharing. It extends into the systems that make data sharing safe, usable, auditable, and commercially scalable.

That includes trust infrastructure, fraud infrastructure, consent systems, API reliability, compliance operations, data governance, and consumer protection workflows.

See: Canada Open Banking Commercialization Roadmap

The next phase of Canada's open banking market will depend on whether these operating layers mature quickly enough for banks, fintechs, consumers, and businesses to use the framework with confidence.

That makes today's implementation decisions highly important because many of tomorrow's fintech products will inherit the rules established now.

For Canada's fintech ecosystem, this strengthens the opportunity case outlined in NCFA's Open Banking Opportunity Brief.  The next iteration of value will come from tools that make consent, risk, identity, fraud controls, interoperability, and compliance easier to operate at scale.

Talking Point

If trust, consent, fraud controls, liability, and interoperability become core infrastructure for open banking, which product category will create the greatest competitive advantage for Canadian fintech companies over the next five years?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Open Banking in Canada

NCFA Opportunity - Open Banking in Canada, Consumer Driven Banking Framework
Innovation Map → Open Finance → Open Banking In Canada → Opportunity
Last Updated Sep 11, 2026
FINANCIAL INNOVATION OPPORTUNITY BRIEF This page tracks evidence, commercialization pathways, policy signals and venture opportunities as Canada implements open banking through its official Consumer Driven Banking framework and prepares for broader open finance.
Innovation OpportunityOpen Banking, Consumer Driven Banking And Open Finance

Open Banking in Canada

Open Banking in Canada, officially called Consumer Driven Banking, is Canada’s regulated framework for secure financial data sharing. The opportunity is not only safer account access. It is the product layer that can turn trusted financial data into better consumer choice, stronger competition, SME finance, embedded software, future payments and broader open finance markets.

Is Consumer Driven Banking the same as open banking in Canada? Yes. Consumer Driven Banking is the official Canadian framework commonly referred to as open banking.

Regulatory update: the 60 day consultation on the proposed Consumer Driven Banking regulations closed August 26, 2026. The draft rules remain the current planning reference while Finance Canada considers feedback and the Bank of Canada develops the supervisory framework.

For a broader view of Open Banking and Consumer-Driven Finance, explore NCFA Open Banking & Consumer-Driven Finance Interactive Intelligence, including the Canadian Market Map, 146 learning modules, company intelligence, discussions, innovation themes and global benchmarks.

28 Evidence5 Product Paths5 Questions14 Resources

Canada’s Open Banking And Consumer Driven Banking Journey

Canada has progressed from open banking policy consultation into implementation of the official Consumer Driven Banking framework under the Bank of Canada. The consultation on the proposed regulations closed August 26, 2026. The draft rules remain proposed while Finance Canada considers feedback and the Bank of Canada develops its supervisory framework. Secure read access and data mobility follow in the launch phase, with write access, payment initiation and broader open finance planned for later stages.

Launch: Read Access And Data MobilityNext: Write Access
Consultation2018 to 2022open banking policy review
Framework2023 to 2024Consumer Driven Banking design
2026 Currentconsultation closed, final rules pendingBank of Canada supervision framework and implementation preparation
Read Accesslaunch phasesecure data sharing and data mobility
Data Productsnear termverification, cash flow and embedded workflows
Write Accessnext phasepayment initiation and account actions
Open Financelonger termbroader financial product scope

Opportunity Intelligence

Market Potential

9MCanadians already share dataGovernment estimate of users relying on credential based screen scraping today
$13.2BEstimated benefitsPresent value over 10 years from proposed regulations, using conservative use case estimates
$457.7MEstimated costsPresent value over 10 years for implementation, compliance, oversight and operation
293KSMEs in scope signalEstimated SME participants that could benefit from streamlined account administration

The market case is now supported by regulatory impact data, not only broad fintech demand. The first commercial window is replacing unsafe credential sharing with regulated API access in workflows that already have budget: verification, onboarding, cash flow analysis, SME credit, accounting, payroll, fraud checks and treasury operations. The larger window opens when read access connects to write access, payment initiation, account switching and broader open finance products.

Why Investors And Builders Should Care

Open banking is not a narrow compliance project. It can become a product layer for better underwriting, faster onboarding, cleaner SME workflows, lower switching friction and new account to account payment models. The most attractive opportunities sit where regulated data reduces real operating cost or helps users make better financial decisions.

Top Opportunity

The strongest current opportunity is open banking intelligence and embedded workflow infrastructure. Read access can support income verification, affordability, categorization, cash flow insight, fraud signals, onboarding and SME finance before payment initiation is available. The next competitive test is decision intelligence: whether permissioned data improves credit, fraud detection, financial guidance and workflow decisions in ways customers and businesses can measure.

Consumer And Competition Benefit

The public benefit is stronger when data portability helps consumers and small businesses compare, switch, qualify, verify, budget, borrow and manage money with less friction. The commercial test is whether approved participants can turn secure access into products that improve choice instead of simply recreating today’s screen scraping market.

What To Watch

Final regulations, Bank of Canada supervisory expectations, the Privacy Commissioner’s recommendations on data scope and safeguards, accreditation details, liability allocation, technical standards, consent experience, SME support, RPAA alignment, Real Time Rail progress and evidence that Canadian software platforms embed regulated financial data into daily workflows.

Product Opportunities

Leading commercial opportunity today: Open Banking Intelligence Platforms

Evidence supports five product paths inside the parent opportunity. Each path is a focused problem and solution area that founders, innovators, investors and partners can explore from the Innovation Map.

1. Open Banking Intelligence Platforms

Financial data transformed into verification, insight, risk and decision products

read access
strongest path
software led

Raw account data becomes valuable when it is categorized, enriched and used in decisions. This path supports income verification, affordability, cash flow insight, fraud detection, SME credit, financial health, onboarding and advice.

Problem

Lenders, platforms and advisors need fresher, permissioned financial data that improves decisions without manual document collection.

Sample market players

Canada: Flinks and Canadian lender or SME finance platforms. Global: Plaid, MX, Mastercard Open Banking, Envestnet Yodlee and Validis.

BuyerLenders, banks, platforms
ReadinessVery High
Canada GapReusable intelligence
EvidenceStrong
What to validate first

Which Canadian buyers adopt permissioned cash flow and verification products first, and whether regulated API data improves approval, fraud or onboarding outcomes.

What could break this thesis

If data quality, coverage, categorization or consent conversion is weak, intelligence products may not outperform existing aggregation and document collection.

2. Consent And Trust Infrastructure

Trusted participation, consent records, identity assurance and operating controls

read access
high readiness
policy dependent

Consumer Driven Banking needs an operating layer that lets approved participants request, manage, revoke and audit access. This creates opportunities in consent management, certification, participant directories, authorization, compliance workflows and liability support.

Problem

Consumers and small businesses need safer data sharing. Participants need trusted access without rebuilding every control themselves.

Sample market players

Canada: Bank of Canada, Interac, Financial Data Exchange Canada and identity verification providers. Global: OpenID Foundation FAPI, Raidiam and Ozone API.

BuyerBanks, fintechs, PSPs
ReadinessHigh
Canada GapOperating detail
EvidenceStrong
What to validate first

Whether accreditation, liability, consent dashboards and participant monitoring become clear enough for non bank entrants to plan products.

What could break this thesis

Slow rules, weak trust UX or unclear liability could keep the market dependent on bilateral integrations and screen scraping workarounds.

3. Embedded Open Banking Data Products

Open banking inside accounting, payroll, treasury, tax and business software

read access
workflow led
SME relevant

The most useful open banking products may not look like banking products. They may appear inside tools businesses already use to reconcile accounts, verify income, forecast cash flow, automate expenses, compare financing and prepare tax records.

Problem

SMEs and operators lose time moving financial records between banks, accounting systems, lenders and payroll tools.

Sample market players

Canada: Float, accountants, credit unions and SME finance platforms. Global: QuickBooks, Xero, Stripe, NetSuite, Rippling and vertical software providers.

BuyerSMEs and software firms
ReadinessHigh
Canada GapSME workflow focus
EvidenceStrong
What to validate first

Whether accounting, payroll, lending and treasury platforms treat open banking as a core workflow layer rather than a narrow bank feed feature.

What could break this thesis

If implementation focuses only on consumer account access, the SME workflow opportunity may arrive late or move to imported software platforms.

4. Programmable Bank Payments

Payment initiation, pay by bank, recurring payments and payouts

Future phase
payments led
RTR dependent

Payment initiation is a later phase opportunity. International models show how open banking can support pay by bank, recurring payments, merchant acceptance, bill payment, payouts and treasury movement once write access and modern payment rails are available.

Problem

Merchants, platforms and treasury teams need lower friction account to account payments that are trusted, data rich and easier to reconcile.

Sample market players

Canada: Payments Canada, Bank of Canada, RPAA supervised PSPs and payments firms. Global: Open Banking Limited, TrueLayer, Tink and Adyen Pay by Bank.

BuyerMerchants, PSPs, platforms
ReadinessMedium
Canada GapWrite access timing
EvidenceStrong global
What to validate first

Whether Real Time Rail, RPAA supervision and future write access converge into practical payment initiation rules and merchant grade products.

What could break this thesis

If RTR timelines slip, write access is narrow or banks control initiation too tightly, the pay by bank market may remain mostly theoretical in Canada.

5. Financial Data Portability And Switching

Comparison, onboarding, product transfer and broader open finance

Future phase
competition led
open finance

The competition value of open banking depends on whether consumers and businesses can act on better options. Portability and switching can support product matching, onboarding automation, account comparison, credit portability and future open finance services.

Problem

Consumers and SMEs can see better options but still face friction when changing providers or reusing financial history across products.

Sample market players

Canada: comparison platforms, brokers, credit unions, banks and financial marketplaces. Global: Australia CDR, UK Smart Data, CFPB data rights and account aggregation markets.

BuyerMarketplaces, brokers, banks
ReadinessMedium
Canada GapSwitching friction
EvidenceModerate Strong
What to validate first

Whether data rights reduce actual onboarding and switching friction, not only provide better dashboards and comparisons.

What could break this thesis

If portability stops at read only visibility, consumers may get better information without enough power to switch, negotiate or transfer relationships.

Competitive And Global Benchmark

Canada is later than leading open banking markets, but the comparison is useful for founders and investors. It shows which product layers are proven elsewhere and which Canadian gaps still need local execution.

Jurisdiction
Read access
Payment initiation
Switching
Open finance
United Kingdom
Australia
Brazil
Europe
Canada
LeadingIn progressEarly

NCFA assessment based on public implementation evidence, regulatory direction and observable market capability.

What this means competitively

Canada can import proven consent, standards, data intelligence and payment initiation patterns, but the local opportunity depends on regulated execution, payment rail timing and whether Canadian software platforms turn data access into daily workflow value.

See NCFA’s infrastructure story for the backstory on why open banking, payment modernization and regulated finance infrastructure are now converging.

Evidence Trail

28 verified evidence items

Filter by signal type to review source backed policy, standards, infrastructure and adoption evidence. Rows are dated to a publication, announcement or implementation milestone. Homepages and general provider pages are kept in Resources or Sample market players, not counted as evidence.

2026-08-06
Analysis
Open Banking’s Next Battle Is Decision Intelligence
Commercial value above data access in credit, fraud, financial guidance and workflow decisions
Adoption
2026-08-26
Primary
Privacy Commissioner Submission On Consumer-Driven Banking Regulations
Recommendations on data scope, accreditation evidence, publicly available data, safeguards and Bank of Canada coordination
Regulatory
2026-06-27
Primary
Consumer Driven Banking Regulations
Proposed rules for data scope, accreditation, liability, technical standards, fees and violations
Regulatory
2026-06-27
Impact
Regulatory Impact Analysis Statement
$13.2B estimated benefits and $457.7M estimated costs over 10 years, with use cases across lending, SME administration, savings, switching and subscriptions
Regulatory
2026-06-26
Analysis
Canada Open Banking Commercialization Roadmap
Commercialization timing, product paths and implementation risks
Regulatory
2026-06-25
Analysis
Bank Of Canada Signals Open Banking Timing Risk
Implementation timing and execution risk
Regulatory
2026-06-24
Analysis
Bill C-15 Gives Canada A Digital Finance Framework
Consumer Driven Banking and digital finance framework signal
Regulatory
2026-06-20
Analysis
How Canada Started Opening Its Financial Infrastructure
Open banking, payment rails and infrastructure context
Adoption
2026-06-05
Primary
Consumer Driven Banking Act
Framework for consumers, including businesses, to direct data sharing among participating entities
Regulatory
2025-10-02
Market Data
Payments Canada Payment Market Data
22.5B Canadian payment transactions worth $12.2T in 2024
Infrastructure
2025-09-08
Oversight
Retail Payment Activities Act Supervision
PSP supervision relevant to future payment products
Regulatory
2025-06-16
Primary
Payments Canada Real Time Rail
Payment rail dependency for future account to account use cases
Infrastructure
2025-04-01
Oversight
Bank Of Canada Consumer Driven Banking
Administration and oversight role
Regulatory
2025-02-22
Standards
OpenID FAPI 2.0 Security Profile
Final financial grade API security profile for high security use cases
Standards
2024-12-01
Primary
Australia Consumer Data Standards
Economy wide data sharing standards model
Standards
2024-10-22
Policy
Personal Financial Data Rights Rule
US consumer financial data rights benchmark
Regulatory
2024-06-07
Market Report
Open Finance Brasil Annual Report
Large scale open finance adoption, active consents and participating institutions
Adoption
2024-04-16
Policy
Canada’s Framework For Consumer Driven Banking
Federal framework for regulated financial data sharing
Regulatory
2024-03-06
Market Report
UK Open Banking Impact Report
UK user outcomes, adoption evidence and ecosystem development
Adoption
2024-03-01
Policy
UK Smart Data Roadmap
Cross sector data portability policy direction
Regulatory
2024-02-01
Payment Model
Variable Recurring Payments
Payment initiation and recurring payment model
Infrastructure
2023-12-14
Market Activity
TD And Plaid Data Access Agreement
API based data sharing agreement for Canadian and US customers
Adoption
2023-11-21
Policy
Open Banking Implementation
Federal implementation work and policy background
Regulatory
2023-08-01
Standards
Consumer Data Right Rollout
Phased expansion beyond banking
Standards
2023-06-28
Policy
EU Financial Data Access Framework Proposal
Rights and obligations for customer data sharing beyond payment accounts
Standards
2023-06-06
Provider
Mastercard Open Banking Account Verification
Open banking powered account owner verification and onboarding signal
Infrastructure
2022-01-01
Analysis
Small Step Forward As Feds Publish Straw Man Open Banking Framework
Early Canadian framework design and consultation signal
Standards
2020-07-29
Primary
Financial Data Exchange Launches In Canada
FDX Canada launch with Canadian firms adopting technical standards for secure financial data sharing
Standards

Participate In This Opportunity

Share your perspective, research, case study or video response. You can also express interest in future discussions, collaboration opportunities and innovation activities related to this topic.

Learn how NCFA identifies, validates and tracks innovation opportunities →
Participate

About NCFA Opportunity Intelligence

NCFA Opportunity Intelligence tracks emerging venture opportunities using evidence, market developments and validation signals. Opportunity briefs are updated as new information, evidence and stakeholder perspectives become available. This content is provided for information purposes only and does not constitute legal, investment, financial, tax or professional advice.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights

NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

NCFA Weekly Fintech Intelligence Jun 20-26, 2026

June 26, 2026 | NCFA Fintech Whisperer | Digital Assets Blockchain And Tokenization, Capital Markets And Market Infrastructure, Artificial Intelligence And Data, Lending Consumer Credit And BNPL, Risk Compliance And Regtech, Payments And Market Infrastructure, Regulation And Policy, Treasury Liquidity And Cash Management

Image Freepik, Data visualization signals

Image: Freepik

This live weekly NCFA intelligence page tracks financial technology developments that significantly affect how fintechs build, sell, raise capital, and operate under scrutiny. Coverage prioritizes Canada and includes global events that directly influence competitive conditions, market access, and execution realities across fintech sectors.  This page will be updated throughout the week with market movers in a live format and then each week we'll close the prior week's contents in prep for the upcoming week, and continue on a rolling basis.  (Missed prior week's Fintech Whisperer?  (December 6-12, 2025, December 13-19, 2025, January 1-9, 2026, January 10-16, 2026, January 17-23, 2026, January 24-30, 2026, January 31-February 6, 2026, February 7-13, 2026, February 14-20, 2026, February 21-27, 2026, February 28-March 6, 2026, March 7-13, 2026, March 14-20, 2026, March 21-27, 2026, March 28-April 3, 2026, April 4-10, 2026, April 11-17, 2026, April 18-24, 2026, April 25-May 1, 2026, May 2-8, 2026, May 9-15, 2026, May 16-22, 2026, May 23-29, 2026, May 30-Jun 5, 2026, Jun 6-12, 2026, Jun 13-19, 2026).

Weekly Fintech Market Intelligence Jun 20 - Jun 26, 2026

Digital Assets Blockchain And Tokenization

Credit Unions Launch Stablecoin And Digital Asset Programme

June 24, 2026, United States
  • Stablecore, Circuit and Curql launched an early access stablecoin and digital asset programme for credit unions, with initial participation from RBFCU, Stanford FCU, La Capitol FCU and other institutions representing approximately $25 billion in combined assets.
  • The programme allows participating credit unions to evaluate stablecoin payments, tokenized deposits, Bitcoin on and off ramps, digital asset accounts, staking, compliance support and member education before broader deployment.
  • The initiative gives credit unions a coordinated path to test digital asset services instead of running isolated vendor experiments.

Credit unions now have a clearer way to test stablecoins, tokenized deposits and digital asset accounts inside member owned financial institutions. Banks, core providers, payments firms, fintechs and regulators should watch whether these early programmes become production deployments for real time settlement, deposit tokens and broader member access to digital assets.

FinCEN Proposes CIP Rules For Stablecoin Issuers

June 22, 2026, United States
  • FinCEN and the federal banking agencies proposed customer identification program requirements for permitted payment stablecoin issuers under the GENIUS Act.
  • The proposal would treat permitted payment stablecoin issuers as financial institutions under the Bank Secrecy Act and require them to maintain effective CIPs.
  • The Federal Register notice opened a public comment period ending Aug. 21, 2026.

Stablecoin issuer regulation is becoming an AML and identity control issue, not only a reserve or redemption issue. Issuers, banks, custodians, wallets, exchanges and compliance teams should prepare for customer identification, verification, recordkeeping and risk controls as payment stablecoin frameworks mature.

Bank Of England Advances Systemic Stablecoin Rules

June 22, 2026, United Kingdom
  • The Bank of England published a policy statement and draft rules for systemic sterling stablecoin issuers.
  • The framework covers reserve assets, safeguarding, redemption, issuer resilience, disclosure, supervision, and the role of stablecoins in payments.
  • The rules are aimed at firms whose stablecoins may become systemically important for UK payments and financial stability.

Stablecoin regulation is moving from policy design into operating rules for payment infrastructure. Issuers, banks, custodians, payment firms, exchanges, and fintechs should watch how reserve design, redemption rights, safeguarding, and systemic supervision shape market access for regulated digital money.

Capital Markets And Market Infrastructure

Securitize Sets NYSE Listing Path For Tokenization Platform

June 26, 2026, United States / Global
  • Securitize and Cantor Equity Partners II said their business combination is expected to raise approximately $400 million in gross proceeds.
  • The combined company is expected to trade on the New York Stock Exchange under the ticker SECZ after closing, subject to shareholder approval and closing conditions.
  • Securitize said it has more than $4 billion in tokenized real world assets under management and operates regulated digital securities infrastructure in the United States and Europe.

Tokenization platforms are entering public capital markets. Asset managers, broker dealers, transfer agents, custodians, exchanges and investors should watch how public company access, regulated ATS infrastructure and cross border digital securities permissions shape the next phase of tokenized fund and real world asset distribution.

US Senators Target Sports Prediction Market Contracts

June 26, 2026, United States
  • Senators John Curtis and Adam Schiff introduced the Prediction Markets Are Gambling Act to prohibit CFTC registered entities from listing prediction contracts that resemble sports bets or casino style games.
  • The bill would clarify that the Commodity Exchange Act does not permit sports gambling through federally regulated prediction market contracts.
  • The senators said sports prediction contracts are being offered across all 50 states, including states with sports betting restrictions or prohibitions.

Event contract markets are facing a sharper boundary test. Exchanges, brokers, prediction market platforms, sports leagues, tribal gaming authorities and regulators should watch whether Congress narrows the line between federally regulated event contracts and state regulated gambling.

FRC Clarifies Auditor Independence Rules For PISCES Companies

June 25, 2026, United Kingdom
  • The Financial Reporting Council issued staff guidance on auditor independence requirements for companies traded on the UK Private Intermittent Securities and Capital Exchange System.
  • The guidance says PISCES traded companies should not currently be treated as listed entities under the FRC Ethical Standard for auditor independence purposes.
  • The FRC said it will give at least one year’s notice before any future change to this position.

Private market trading infrastructure needs audit rules that firms can apply before transactions scale. Companies, auditors, advisers, venues and investors should watch how PISCES treatment affects independence checks, audit committee planning, transaction readiness and the operating model for periodic private share trading.

CSA Finalizes Access Model For Issuer Disclosure

June 25, 2026, Canada
  • The Canadian Securities Administrators announced final amendments to implement an access model for annual financial statements, interim financial reports, and related MD&A for reporting issuers other than investment funds.
  • The model lets issuers provide electronic access to eligible disclosure documents instead of sending paper copies, while investors can still request paper or electronic delivery.
  • The amendments are expected to take effect on Sept. 22, 2026 and include new SEDAR+ functionality to notify investors when eligible documents are filed.

Canadian issuer disclosure is becoming more digital by default. Public companies, transfer agents, investor relations teams, legal advisers and compliance staff need to adjust delivery controls, SEDAR+ workflows, investor notices and request handling before the new access model takes effect.

CSA And CIRO Delay Access Fee And Tick Size Rule Changes

June 22, 2026, Canada
  • CSA and CIRO delayed implementation of final amendments to Canadian access fee and tick size rules.
  • The amendments had been scheduled to come into force on Nov. 2, 2026.
  • The delay follows the SEC’s postponement of related US tick size and access fee reforms, affecting harmonization for interlisted securities.

Canadian equity market structure remains tied to US implementation timelines. Trading venues, brokers, market makers, and technology teams need more time to adjust routing logic, fee models, tick increments, compliance controls, and systems that support trading in interlisted securities.

ICE And OKX Form Joint Venture For Tokenized Markets

June 22, 2026, United States / Global
  • Intercontinental Exchange and OKX announced a 50-50 joint venture, subject to regulatory approvals, to connect traditional and digital asset markets.
  • The venture is expected to operate as a US registered broker dealer and futures commission merchant.
  • The companies say the platform will give OKX customers access to ICE futures markets and NYSE tokenized equities markets.

Tokenization is moving closer to regulated market infrastructure. Exchanges, brokers, clearing firms, custodians, digital asset platforms, and regulators should watch how traditional market operators and crypto venues build permissioned pathways for tokenized securities, futures access, custody, execution, and compliance. Similar infrastructure questions are also emerging in event contract markets as new regulated venues, distribution channels, and contract frameworks develop.

Artificial Intelligence And Data

Santander Scales AI Access Across 185,000 Employees

June 22, 2026, Spain / Global Bank
  • Santander extended AI access to all 185,000 employees as part of its AI first operating strategy.
  • The bank reported €35 million in AI generated value in Q1 2026, with a target above €200 million in 2026 and more than €1 billion from 2026 to 2028.
  • Santander says it has deployed 280 process automation agents and is applying AI across fraud, KYC, operations, software development, customer service, and internal productivity.

Bank AI adoption is moving from pilots to operating metrics. Financial institutions, fintech vendors, compliance teams, investors, and regulators should watch how large banks measure AI value, scale employee access, govern automation agents, and connect AI deployment to fraud control, onboarding, productivity, risk operations, and compute infrastructure markets.

Payments And Market Infrastructure

Skydo Establishes Regulated Canada Payments Presence

June 23, 2026, Canada / India
  • Skydo co founder Movin Jain said Skydo Payments Inc. is registered as a FINTRAC approved money services business and authorized under Canada’s Retail Payment Activities Act.
  • The post described the Canadian authorization as Skydo’s first regulatory step outside India.
  • Finextra reported that the Canadian entry supports local collections, local payouts and two way payment flows between India and Canada.

Cross border payments are becoming a regulated corridor strategy. Exporters, payment firms, banks, compliance teams and fintechs should watch how RPAA registration, money services business obligations, local payout capability and bank account connectivity affect competition in Canada India payment flows.

European Parliament Committee Backs Digital Euro Position

June 23, 2026, European Union
  • The European Parliament’s Economic and Monetary Affairs Committee adopted its position on the establishment of the digital euro by 43 votes to 14, with one abstention.
  • The proposal would create an electronic form of ECB money that works online and offline, with privacy safeguards, holding limits, fee rules, and a distribution role for banks, e-money providers, post offices, and regulated crypto-asset providers.
  • The committee also backed related files on digital euro services by PSPs in non-euro member states and the legal tender status of euro cash.

Digital euro policy is becoming payment infrastructure design. The next test is how offline use, privacy controls, holding limits, fees, PSP distribution, and cash protection fit into a system that has to work across public money, private payment providers, and existing rails.

Lending Consumer Credit And BNPL

B.C. Tightens Mortgage Services Rules Under New Act

June 22, 2026, Canada
  • B.C.’s Mortgage Services Act comes into force Oct. 13, 2026, replacing the Mortgage Brokers Act.
  • BCFSA says the new framework modernizes licensing, supervision, rulemaking, investigation, discipline, and consumer protection for mortgage services.
  • Discipline penalties for serious contraventions can reach $250,000 for individuals and $500,000 for mortgage brokerages, while administrative penalties can range from $1,000 to $100,000.

Mortgage distribution is becoming a stronger fraud, licensing, and consumer protection issue. Brokers, lenders, fintech mortgage platforms, compliance teams, and investors should watch how higher penalties, clearer licensing rules, and stronger supervision reshape risk controls in mortgage services.

Risk Compliance And Regtech

FINTRAC Enables Information Sharing To Detect Financial Crime

June 25, 2026, Canada
  • FINTRAC confirmed that reporting entities can now exchange designated information with one another to detect and deter money laundering, terrorist activity financing and sanctions evasion under Canada's amended anti money laundering framework.
  • The changes allow regulated entities to strengthen financial crime detection while remaining subject to legislative requirements governing the collection, use and disclosure of personal information.
  • The new information sharing framework forms part of broader amendments to Canada's anti money laundering and anti terrorist financing regime.

Financial crime detection no longer depends only on what individual institutions can see. Banks, credit unions, payment service providers, securities dealers, fintechs and other reporting entities can now strengthen risk detection by sharing designated information, creating new opportunities for collaborative fraud controls, network analysis and anti money laundering investigations.

Bank Of England Signals Shift In Enforcement Engagement

June 24, 2026, United Kingdom
  • Bank of England Head of Enforcement and Litigation David Chaplin said PRA and Bank enforcement cases are showing earlier engagement, candour and remediation by investigation subjects.
  • The speech highlighted the Early Account Scheme, which can support faster investigations and enhanced penalty discounts where firms provide accurate accounts and make early admissions.
  • The Bank said the change is already visible across live cases, with firms making admissions earlier than would previously have been typical.

Regulatory enforcement is becoming more incentive driven. Banks, insurers, investment firms, credit unions and compliance teams should review how early investigation strategy, breach assessment, remediation evidence and senior accountability affect enforcement outcomes.

FRC Updates UK Auditing Standards

June 24, 2026, United Kingdom
  • The Financial Reporting Council revised ISA (UK) 700, ISA (UK) 701 and ISA (UK) 720 to shorten auditor reports and improve investor usefulness.
  • The standards add auditor reporting requirements linked to UK Corporate Governance Code Provision 29 controls statements for companies that follow the code.
  • The FRC withdrew two older audit bulletins and said the revised standards take effect from Dec. 15, 2026.

Audit reporting is becoming more focused on useful disclosure, controls evidence and investor readability. Companies, audit committees, auditors, governance advisers and compliance teams should prepare for updated report content, Provision 29 controls statements and revised audit workflows before the December effective date.

White House Orders Transition To Post Quantum Cryptography

June 22, 2026, United States
  • The White House issued an Executive Order directing federal agencies to accelerate migration to post quantum cryptography to address future quantum computing threats to encryption.
  • Federal agencies must designate post quantum cryptography migration leads within 30 days, while OMB is required to issue implementation guidance within 90 days.
  • The order establishes transition targets requiring high value assets and high impact systems to adopt post quantum cryptography for key establishment by Dec. 31, 2030 and digital signatures by Dec. 31, 2031.

Firms need to know where encryption is used, which vendors are exposed, which systems protect high value data, and how long migration will take. Crypto inventory, procurement language, vendor assurance, and roadmap planning should start before compliance dates become delivery pressure.

Treasury Liquidity And Cash Management

SCRYPT Moves Internal Treasury Into Franklin Templeton’s BENJI Fund

June 25, 2026, Switzerland / Global
  • SCRYPT integrated BENJI, the tokenized share of the Franklin OnChain U.S. Government Money Fund, into its internal treasury operations.
  • The deployment gives SCRYPT 24/7 onchain access to a yield-bearing money market fund for managing idle liquidity.
  • SCRYPT is using the fund through the same Swiss-licensed trading, settlement and custody infrastructure that supports its institutional digital asset operations.

A regulated operating company is using a tokenized money market fund for its own liquidity rather than presenting it as a future client product. That moves tokenization into daily treasury operations, where continuous access, settlement speed, custody controls and balance-sheet utility can be tested against conventional cash-management infrastructure.

Regulation And Policy

OSFI Launches Streamlined Approvals Framework

June 25, 2026, Canada
  • OSFI launched its Streamlined Approvals Framework to provide eligible new entrants with a quicker, clearer and more predictable approvals process for federally regulated financial institutions.
  • The framework introduces a three phase approvals process with defined service standards, greater transparency and a public dashboard showing the status of applications.
  • The initiative applies to eligible incorporations, continuances, business expansions and other approval requests, using a risk based approach to streamline lower risk applications.

Approval processes are becoming more transparent and predictable for eligible applicants entering or expanding within Canada's federally regulated financial sector. Banks, fintechs, federal credit union applicants and regulated financial institutions should watch how the framework affects application timelines, market entry, organizational changes and future supervisory expectations. For background, see NCFA's earlier coverage of the Streamlined Approvals Framework proposal.

Manitoba Enacts Public Sector AI And Cybersecurity Governance Law

June 1, 2026, Canada
  • Manitoba gave Royal Assent to the Public Sector Artificial Intelligence and Cybersecurity Governance Act, creating a legal framework for AI and cybersecurity controls across prescribed public sector organizations.
  • The Act allows requirements covering AI accountability, monitoring, documentation, risk assessment, bias testing, human oversight and prescribed technical standards.
  • It also provides for cybersecurity programs, incident reporting, procurement requirements and ministerial cybersecurity directives.
  • Most practical obligations still depend on proclamation and future regulations, which will determine who is covered and how the requirements operate.

Manitoba has put AI governance and cybersecurity inside the same statutory control structure for the public sector. The next test is implementation. Regulations will determine how far the province goes on human oversight, technical standards, incident reporting and vendor procurement, and whether those requirements become a practical benchmark for other Canadian governments.

Conclusion

Every week brings hundreds of announcements. Only a small number signal meaningful change. This week's developments point to new opportunities across payments, digital assets, AI, capital markets and regulation that could influence where innovation accelerates, investment flows and new business models emerge next.

NCFA offers various curated resources to help founders and investors stay current on developments that impact fintech markets, subscribe to NCFA weekly newsletter updates, view the latest fintech insights, industry research, or launch into emerging financial innovation opportunities.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Float Raises $85M To Build AI Business Finance Stack

June 25, 2026 | NCFA Fintech Market Activity | Capital Markets And Funding, SME Finance And Business Banking, Artificial Intelligence And Data, Fintech And Innovation

AI Image – AI powered business finance dashboard supporting payments, cash management, and finance workflows for Canadian businesses

AI Finance Workflows Move Deeper Into Canadian Business Banking

On June 24, 2026, Float Financial announced a CAD $85 million all equity Series C led by Inovia Capital, with continued participation from Goldman Sachs Alternatives and Garage Capital, and new investment from BDC Capital and Northleaf. Float says the round raises its valuation by 70% and brings total capital raised since inception to CAD $300 million, including debt and equity financing.

The financing gives Float more capital to expand its AI finance workflow layer, grow across Western Canada and Quebec, and hire across product, R&D, sales, and marketing. The company now serves more than 7,500 Canadian businesses and says revenue has grown more than 120% since its Series B.

Float’s own growth data shows how quickly Canadian business finance is moving from point solutions into connected operating platforms. Business account balances are up more than 4.5x, volumes across five products are up more than 100%, and nearly one third of customers now use more than one Float product which suggests Float is expanding inside existing finance teams rather than only adding new accounts.

Float Wants More Of The Finance Workflow

Float gives Canadian businesses tools for corporate cards, expense management, bill pay, reimbursements, foreign exchange, business accounts, reporting, and working capital credit. The Series C adds more fuel to Float Intelligence, the company’s AI layer for automating finance workflows.

Rob Khazzam, CEO and co-founder of Float, framed the round around infrastructure:

“We are not building a single feature. We are building the infrastructure that powers how Canada does business - and proving that the best financial tools for Canadian businesses don't have to come from somewhere else.”

Canadian businesses want fewer disconnected finance tools. They need better control over spending, faster approvals, clean reporting, cash visibility, cross border payments, and finance workflows that don't depend on manual work.

Float says its platform is trusted by companies including Cohere, Knix, Neo, Jane, and Rebel. The Jane customer quote in the release points to the same theme: Canadian companies want AP, expense, and finance tools built for the Canadian market, not adapted from U.S. systems.

If Float keeps expanding across cards, accounts, payments, credit, and AI finance workflows, Canadian businesses may get a stronger local alternative to the tools many finance teams stitch together today.

Canadian SME Finance Signals

Float secured $100 million in debt financing to expand SME finance in Canada before this Series C.

EQ Bank launched a Business Card, adding spending, cashback, interest, and cash flow tools to its SME banking stack.

Relay secured $50 million to grow its SMB finance platform.

Payments Canada admitted new payment service providers, including Float, as access to payment infrastructure opens to more fintech operators.

Canadian SMB banking research highlights high fees, credit friction, and outdated financial systems as ongoing barriers for business owners.

Talking Point

If Canadian businesses adopt one platform for spending, payments, cash, credit, and AI finance workflows, which institution owns the primary operating relationship: the bank, the fintech, or the software layer?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter