Global fintech and funding innovation ecosystem

Category Archives: Fintech International

FINRA Cybersecurity Practices For Member Firms

August 19, 2026 | NCFA Resource | Cybersecurity And Fraud, Risk Compliance And Regtech, Capital Markets And Market Infrastructure

NCFA Resource – FINRA Cybersecurity Practices For Member Firms

12 Controls For Cyber Risk, Vendors, Access And Recovery

In August 2026, the Financial Industry Regulatory Authority published Cybersecurity Effective Practices, a 12-part framework for FINRA member firms reviewing cybersecurity programs, controls and operating procedures. A firm can use the resource as a structured checklist for who owns cybersecurity, which systems and vendors create risk, who can access sensitive data, how threats are detected, and whether the business can recover when systems fail. FINRA designed the practices to scale with firm size, business model, technology complexity and risk profile.

What It Does In Practice

FINRA organizes the resource around 12 areas:

  1. governance
  2. risk management
  3. third party risk management
  4. asset management
  5. access control and identity management
  6. data protection
  7. security awareness and training
  8. vulnerability and patch management
  9. security monitoring
  10. threat intelligence and information sharing
  11. incident response and reporting
  12. resilience and recovery

The framework starts with accountability and risk ownership. FINRA recommends a designated cybersecurity lead, regular reporting to senior decision makers, documented policies and periodic reviews, while also making cyber risk part of decisions about new technology, systems and operating changes. From there, firms are expected to identify the information, systems and business functions they depend on, assess threats such as ransomware, insider activity and vendor exposure, test important systems for weaknesses and revisit those risks when technology or operations change.

Third party risk receives detailed treatment. FINRA treats vendors with access to customer information or critical systems as part of the firm’s security perimeter. Firms should know which vendors have access, understand important fourth party relationships and identify which providers support critical operations. Contracts can address audit rights, data handling, breach notification and visibility into subcontractors, while ongoing oversight should include access monitoring and a documented process for removing access and handling customer information when a relationship ends.

That concern extends beyond US broker dealers. Weak access control governance can expose sensitive information when a partner or service provider retains permissions that are unnecessary or poorly monitored. FINRA’s guidance connects vendor governance with the practical question of who can access systems and data, for how long, and under what controls.

Asset management and access control fit naturally together. FINRA recommends keeping a current inventory of hardware, software, cloud services and data flows, assigning owners to important assets and identifying systems that no longer receive security updates. Once firms know what they have, they can control who gets access through unique credentials, role based permissions, multifactor authentication, periodic entitlement reviews, segregation of duties and least privilege. Access should also be changed or removed promptly when employees change roles or leave.

Data protection, training and patching cover another part of the operating picture. Firms are encouraged to classify sensitive data, encrypt it at rest and in transit where feasible, control retention and protect backups, including with immutable or air gapped storage. FINRA also recommends ongoing employee training, role specific instruction for staff with sensitive access and phishing simulations backed by records of participation. Vulnerability management should include regular scanning, risk based patch priorities and verification that remediation work was completed rather than assumed.

Who Gets Value

The primary users are FINRA member broker dealers, including compliance teams, cybersecurity leaders, technology teams, operations executives and senior management. Smaller firms can use the 12 areas to identify where basic controls are missing without trying to copy the cybersecurity program of a much larger institution, while larger firms can use the same structure to review whether responsibilities, documentation and technical controls are working together.

Technology providers, managed security firms, consultants and RegTech companies serving broker dealers can also use the resource to understand what clients may expect around access, logging, vendor controls, data handling, patching, incident response and recovery. Boards and senior executives can use it as a governance checklist because FINRA makes cybersecurity ownership, management reporting, resource decisions and documented risk acceptance part of the program rather than leaving cyber risk entirely with the technology team.

Strengths And Limits

The main strength is that FINRA connects governance directly to operating controls. A firm can follow the framework from senior accountability through asset inventories, identity controls, encryption, training, monitoring and recovery testing, which makes the document more useful than a high level cyber policy statement.

Third party risk is also handled with more depth than a basic checklist. Firms are expected to understand vendor dependencies, monitor privileged access, address fourth parties and plan how systems and data will be handled when a provider relationship ends. Security monitoring extends that discipline to unusual access, suspicious data transfers, system changes and privileged accounts, with logs retained long enough to support operations, investigations, forensic work and applicable recordkeeping requirements.

The framework also includes threat intelligence, incident response and recovery. FINRA recommends using relevant threat feeds, updating defenses as attack methods change and participating in trusted information sharing networks. Incident response focuses on how a firm detects, escalates and contains an event, while recovery planning deals with how critical systems and data return to service afterward. Tested backups, tabletop exercises, offline procedures and defined Recovery Point Objectives and Recovery Time Objectives all help firms decide how much data loss and downtime different systems can tolerate.

The main limitation is jurisdiction. FINRA developed the resource for US member firms and connects several practices to US requirements, including SEC Regulations S-P and S-ID, FINRA Rules 3110 and 4370, and Exchange Act recordkeeping rules. The document also doesn't create new legal or regulatory requirements or reinterpret existing ones. For Canadian financial technology and service firms, its best use is as a practical comparison and control review, not as a statement of Canadian regulatory obligations.

Key Resources

FINRA Cybersecurity Effective Practices (12-part cybersecurity control framework)

Cybersecurity Effective Practices PDF (downloadable nine page resource)

Small Firm Cybersecurity Checklist (small firm program checklist last reviewed February 2024)

Core Cybersecurity Threats And Controls (small firm threats and control questions)

FINRA Cybersecurity Resources (cybersecurity tools, guidance and related material)

2026 Cybersecurity And Cyber Enabled Fraud (current threats and effective practices)

Proposed Class Action Targets Equifax Access Controls (access governance and third party permissions)


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: [www.ncfacanada.org](http://www.ncfacanada.org)

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

AWS AgentCore Payments Brings Spending Controls To AI Agents

```html
August 18, 2026 | NCFA Insight | Artificial Intelligence And Data, Payments Infrastructure And Money Movement, Digital Assets

AI Image – AI agent payments with delegated wallet spending controls and secure machine transactions

Wallet Delegation, Spending Limits And Machine Payments

On August 18, 2026, Amazon Web Services made AgentCore Payments generally available, taking the capability from its May preview into production. AI agents can now encounter paid APIs, services accessed through Model Context Protocol (MCP), or other digital resources during a workflow and initiate payment through infrastructure that connects spending controls with external wallets.

AWS can enforce how much an agent is allowed to spend and for how long, manage access to wallet providers and coordinate the payment from inside the same infrastructure used to run the agent. Coinbase or Stripe's Privy provides the wallet, while external providers and blockchain networks handle signing, verification and settlement.

AWS isn't taking custody of customer money. It is taking a position earlier in the transaction, where software determines whether it has permission to buy something and which payment connection to use. That puts payment authority closer to the AI execution layer.

GA Adds More Ways For Agents To Pay During A Task

AgentCore Payments already supported Coinbase and Privy wallets, spending controls and x402 payments during preview. General availability adds the Machine Payments Protocol (MPP), easier Coinbase wallet setup, improved discovery of paid x402 services and an x402 pricing option called upto.

The upto model is designed for services whose final cost isn't known before use. An agent can approve a maximum amount, while the provider charges for what was actually consumed. AWS points to model inference, compute and other usage-based APIs where a flat price per request may not reflect the real cost.

That fits how autonomous software may buy digital services. Instead of establishing a subscription with every provider in advance, an agent can encounter a paid resource during a task, check whether the price fits its delegated budget, pay for it and continue.

See: Should Fintechs Design For People Or AI Agents?

MPP adds another payment protocol. Developed by Stripe and Tempo, it lets software exchange payment requirements during an online transaction and can support different payment models, including microtransactions and recurring payments.

x402 takes a somewhat different approach. It lets an online service respond to an agent's request by saying payment is required before the resource is released. The agent can then authorize the payment through its connected wallet and retry the request.

Stripe says MPP can support stablecoins as well as conventional payment methods, but AgentCore Payments currently documents an embedded crypto wallet as its supported payment instrument.

AWS Controls The Spending Rules, Not The Money

The architecture adds useful boundaries around the word autonomous. A user or business first provides the wallet and grants authority. AWS then applies rules around how the agent can use that authority during a payment session. NCFA's Financial Innovation Map tracks this convergence of AI agents, financial permissions and programmable infrastructure.

Those controls can include an expiry and a maximum amount the agent is permitted to spend. Before a transaction proceeds, AgentCore checks whether the request fits within that budget. A payment that exceeds the limit is rejected at the infrastructure level rather than left to the agent's judgement.

AWS also keeps the wallet-provider credentials away from the agent itself. Coinbase or Privy provides the wallet infrastructure, while AWS uses controlled access to request operations such as signing a transaction.

The result is delegated spending rather than independent control of money. The person or business sets the authority, AWS enforces part of the operating boundary and the connected wallet provider controls the financial instrument.

AWS also records payment activity through its monitoring tools, giving developers logs and transaction information they can use to review what agents attempted and what payments succeeded. That adds an audit layer around activity that would otherwise be difficult to supervise once agents begin buying resources during longer workflows.

This is where AWS gains a potentially valuable position. It doesn't need to become a bank or payment processor to influence whether an agent-side transaction can proceed.

Coinbase And Privy Supply The Wallet Layer

Coinbase is one supported provider, not an exclusive requirement. Its developer infrastructure provides embedded wallets and supports x402 payments, while Coinbase's Bazaar service helps agents discover online services that accept the protocol.

Coinbase documents payments in the USDC stablecoin on Base and Solana for its AgentCore implementation. That makes digital assets a substantive part of the current product architecture rather than a side effect of Coinbase's involvement. It also connects directly to NCFA's Programmable Stablecoin Payments opportunity brief, which examines programmable money movement and payment infrastructure.

Privy provides another embedded-wallet option. The company is now part of Stripe, but its role in AgentCore is still wallet infrastructure rather than ordinary card processing through Stripe's full payments stack.

AgentCore Payments doesn't require every payment protocol to use cryptocurrency, and MPP itself can support other payment methods. But AWS's currently documented AgentCore payment instrument is still a crypto wallet.

Payment companies therefore remain important underneath the agent platform. They provide the wallet, credentials and financial infrastructure needed to execute transactions, while AWS controls more of the environment where an agent decides when to call them.

This isn't the only infrastructure model emerging. Circle's USDC infrastructure for AI agents combines policy-controlled wallets, service discovery and programmable payments under predefined guardrails.

Travala Shows How Delegated Agent Payments Work

Travala provides a useful production example because its implementation shows where the customer's authority remains. Its current Travel MCP lets an AI agent search and book hotels, with payment settled in the USDC stablecoin on Base from a Coinbase wallet connected through AgentCore.

The customer still has to authorize the spending relationship. Travala says the permission is revocable and time-limited, the company never receives the private key and the customer must explicitly confirm the hotel purchase before payment is made.

Once that permission is in place, the agent can complete the payment within the delegated limits and continue the booking workflow. That is more precise than saying an AI agent independently controls money.

AWS also names Anchor Browser, SpreadX's Incarna, Elsa AI and Heurist AI among customers or integrations using AgentCore Payments. AWS does not provide transaction volumes for those implementations, so there isn't yet enough evidence to describe agent-led payments as broadly adopted at scale.

The Travala example is still important. It shows a live consumer transaction where conversational software can search, obtain approval and complete payment without sending the customer into a separate checkout flow.

Payment Distribution Could Move Into The AI Stack

Traditional electronic payments divide responsibility among merchants, gateways, processors, acquirers, networks, issuers and customer interfaces. Agent commerce adds another decision point before many of those functions because software has to decide whether a paid service is useful, whether the price is acceptable and whether the purchase falls within the user's authority.

AWS now controls part of that decision environment. It doesn't set the merchant's price, supply the customer's money or settle the transaction. It can, however, determine whether the agent's payment request fits its permitted spending session and coordinate access to the wallet needed to proceed.

That creates a new distribution question for payment companies. A wallet provider may still own the financial relationship underneath the transaction, while the cloud or AI platform controls the environment where an agent discovers a service and decides which payment connection to use.

See: OpenAI Pulls Back From Checkout As Agentic Commerce Expands

AgentCore Payments still has important limits. AWS isn't providing general merchant acquiring, and its documentation doesn't establish native chargebacks, universal merchant controls or a standalone fraud-screening service inside AgentCore Payments. Those functions may remain with the merchant, application, wallet provider or other payment infrastructure.

Control of the agent execution environment can still become valuable payment real estate even when the platform never holds the money. If agents increasingly choose services and initiate purchases on behalf of users, the infrastructure governing those decisions becomes another point where payment providers compete for access.

AgentCore Payments Is Not Yet Available In Canada

AgentCore Payments is currently available in 12 AWS regions across the United States, Europe, Singapore and Australia. AWS does not currently offer the capability from its Canadian region, even though several other AgentCore services are available there.

That creates a practical constraint for Canadian developers that want to keep this part of the stack in an AWS Canadian region. They can deploy AgentCore Payments elsewhere, but there is no Canadian region for the capability today.

The longer-term issue for Canadian fintechs and financial institutions is less about one AWS region and more about where financial authority is being placed. Agent payments combine AI governance, delegated spending, wallets and payment infrastructure inside one operating workflow.

Firms will need to decide which controls remain inside their own applications and which can be delegated to cloud, wallet and protocol providers. That becomes more important as agents gain permission to buy services during a task rather than simply recommend what a person should buy.

Talking Point

If AI and cloud platforms control the environment where agents receive spending authority and decide whether a transaction can proceed, while payment companies provide wallets and settlement underneath them, which layer will ultimately control distribution in agent-led commerce?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

```

SEC Regulation Crypto Assets and US$75M Fundraising Rules

August 18, 2026 | NCFA Feature | Regulation And Policy, Digital Assets, Capital Markets And Market Infrastructure

AI Image – SEC Regulation Crypto Assets crypto fundraising and compliance framework

New Offering Rules, Crypto Resales And Investment Contract Exit

On August 18, 2026, the U.S. Securities and Exchange Commission proposed Regulation Crypto Assets (download 402 page PDF Proposed Regulation Crypto Assets document), a tailored securities framework for certain investment contracts involving crypto assets. The 402-page proposal would create a startup exemption of up to US$5 million over four years, a larger fundraising exemption with US$20 million and US$75 million tiers, crypto-specific disclosures, new SEC forms, secondary-market provisions, state-law preemption and a process for determining when an investment contract has ended.

The scope is narrower than the name might suggest. Regulation Crypto Assets would apply to what the SEC calls a covered investment contract. A crypto asset must be subject to the investment contract, the crypto asset itself must not be a security and no other asset can be subject to that contract.

That builds on the SEC's March 2026 crypto interpretation. The March action addressed when transactions involving a non-security crypto asset can create an investment contract and when that relationship can end. Regulation Crypto Assets would add an operating framework around that lifecycle.

The proposal is significant because it goes beyond creating two new fundraising limits. The SEC is designing rules for how certain crypto investment contracts could be offered, disclosed, distributed and resold, and how the underlying crypto asset could eventually separate from the investment contract.

What Regulation Crypto Assets Does And Does Not Cover

The proposed Regulation Crypto Assets isn't a comprehensive U.S. crypto rulebook. It doesn't create the general regulatory regime for payment stablecoins, programmable payments, crypto custody, crypto lending, mining or conventional securities that happen to be tokenized. Those activities may fall under other federal or state laws, other regulators or separate SEC work.

Payment stablecoins are a good example. Regulation Crypto Assets says permitted payment stablecoins could be accepted as consideration in a covered offering and would count toward its offering limit. It does not establish the rules for issuing payment stablecoins.

That work is proceeding separately under the federal GENIUS Act. On August 17, one day before the SEC proposal, the U.S. Treasury issued a proposed payment stablecoin rule covering implementation of the separate federal framework for their issuance, offering and sale.

Other crypto activities can intersect with Regulation Crypto Assets without becoming generally regulated by it. The proposed Startup Exemption contemplates certain distributions connected with development and use of a crypto network, including circumstances involving airdrops, staking, governance, gas fees and testing. The legal question remains whether the particular transaction involves a covered investment contract.

The proposal also doesn't create a new legal category for tokenized stocks or bonds. Tokenized conventional securities remain securities. Regulation Crypto Assets instead addresses a narrower case where the crypto asset itself isn't a security but is subject to an investment contract.

It's important for founders, investors, lawyers and trading platforms to know that a crypto asset, an investment contract involving that asset and a tokenized security, can look technologically similar while carrying very different securities-law consequences.

The US$5M Startup Route Removes Several Reg CF Frictions

The proposed Startup Exemption could be used for no more than four years after an issuer's initial Form NOR filing. The issuer and its affiliates could conduct covered transactions up to an aggregate US$5 million during that period and couldn't simply restart the four-year clock for the same or a substantially similar crypto asset.

The issuer definition is unusually flexible. The proposal would allow an entity, an individual or a group of individuals or entities to qualify, subject to the other conditions. That accommodates crypto projects that may begin with a development team before they resemble a conventional corporate securities issuer.

The fundraising mechanics are also important. The proposed startup route would permit general solicitation, impose no individual investment limit on retail purchasers and require neither financial statements nor use of a registered intermediary. Covered investment contracts sold through the exemption would not be restricted securities under federal law and would not carry a separate rule-based holding period.

Disclosure doesn't disappear. Before conducting covered transactions, the issuer would file Form NOR on EDGAR and make the disclosures required by Rule 103 publicly available free of charge.

Those disclosures are designed around the investment contract and crypto network. They include offering terms, management and conflicts, the crypto asset, development plans, network or application security, source code where applicable, token economics and allocations, governance, the related crypto ecosystem and material risks. The information must remain publicly available, with material changes addressed under the proposal's update requirements.

Bad-actor disqualifications would apply as well, and issuers would remain subject to federal antifraud and antimanipulation rules. This is a different compliance model, not an absence of securities regulation.

The most revealing comparison is Regulation Crowdfunding. Reg CF also permits up to US$5 million, but over a 12-month period. It requires a registered broker-dealer or funding portal, financial disclosure and investment limits for non-accredited investors, while securities generally face a one-year resale restriction.

The SEC makes that comparison itself. Its economic analysis estimates average Reg CF intermediary fees at approximately 6.6%, with a 6% median, and identifies the absence of mandatory financial statements and an intermediary as potential cost savings under the crypto Startup Exemption.

There is little evidence that current Reg CF rules have produced a large crypto financing market. SEC data identify 42 crypto-related Reg CF offerings by 41 issuers between 2016 and 2024. Reported proceeds totalled approximately US$13.6 million, with an average of US$545,300 among offerings for which proceeds were reported. The SEC cautions that the proceeds total is incomplete and likely represents a lower bound.

The proposal is therefore testing more than a higher ceiling. It asks whether removing particular intermediary, financial reporting, investor and resale frictions would make a public capital route more workable for qualifying crypto projects.

Tier 1 Fundraising Exemption US$20M With Ongoing Reporting

Larger projects could instead use the proposed Fundraising Exemption. Tier 1 would permit up to US$20 million in 12 months. The issuer would have to file Form 1-CRYPTO and couldn't sell covered investment contracts until the SEC qualified the offering statement.

The offering circular would combine the crypto-specific Rule 103 disclosures with financial information about the issuer. Tier 1 financial statements generally wouldn't require an audit, but the issuer would still enter an ongoing reporting regime using annual Form 1-KC, semiannual Form 1-SC and Form 1-UC for specified current events.

Retail investors would also face a restriction that doesn't apply under the Startup Exemption. A non-accredited investor generally couldn't purchase more than 10% of the greater of annual income or net worth. For a non-natural person, the test would use revenue or net assets.

Tier 2 Fundraising Exemption US$75M With Audited Financials

Tier 2 would permit up to US$75 million in 12 months. Like Tier 1, it would require Form 1-CRYPTO, SEC qualification before sales, ongoing reporting and the 10% non-accredited investor limit. The key additional financial requirement is that Tier 2 statements would have to be audited by an independent accountant under the proposed standards.

The larger Fundraising Exemption also comes with a strong U.S. nexus. The issuer would have to be an entity organized under U.S. law, a majority of its executive officers or directors would need to be U.S. citizens or residents, more than half of its assets would need to be in the United States and its business would have to be administered principally there.

Canada appears explicitly in the SEC's request for comment. Question 86 asks whether Canadian issuers, or other foreign issuers, should be permitted to rely on the Fundraising Exemption.

That is more than a passing jurisdictional detail. Regulation A already allows qualifying Canadian issuers, while the proposed Regulation Crypto Assets fundraising route currently does not. Whether the SEC changes that provision could affect how useful the US$20 million and US$75 million routes become for Canadian crypto companies.

Resale And State Rules Could Expand Crypto Distribution

The proposal's treatment of secondary transfers may prove almost as important as its fundraising limits. The SEC says existing exemptions can impede the network effects of crypto assets when they restrict who can participate or how quickly securities can be resold.

Both proposed exemptions would therefore allow issuers to sell covered investment contracts that are not restricted securities under federal law. Investors wouldn't face the federal holding periods associated with restricted securities, although contractual restrictions and other applicable laws could still affect a transfer.

That differs from common Regulation D offerings and from Reg CF's first-year resale limits. The SEC's rationale is specific to crypto networks. Wider ownership and use can contribute to how a network operates and how the crypto asset derives value, so distribution restrictions can affect more than investor liquidity.

See: Canada's Stablecoin Regulatory Framework

Rule 500 would address another obstacle by proposing federal preemption of certain state registration and qualification requirements. It would treat purchasers in qualifying Regulation Crypto Assets transactions as qualified purchasers for that purpose and extend the treatment to specified secondary-market transactions.

The preemption isn't unlimited. Secondary-market treatment would depend on the issuer remaining current with the disclosure, filing or reporting requirements attached to the applicable exemption. States would also retain antifraud authority, powers over unlawful broker or dealer conduct, notice filing requirements and applicable fees.

For trading platforms and intermediaries, the proposal introduces an additional status question. They may need to distinguish between the underlying non-security crypto asset, an outstanding covered investment contract involving it and an asset for which that investment-contract relationship has ended.

The Safe Harbor Creates An Investment Contract Exit

Rule 400 addresses one of the most distinctive features of the proposal. The SEC's existing securities rules generally deal with financial instruments whose fundamental legal character doesn't change over time. A crypto asset can present a different problem because an investment contract surrounding it may end while the crypto asset continues to exist and circulate.

The proposed safe harbor would apply when the issuer has completed or permanently ceased all essential managerial efforts that it represented or promised under the covered investment contract. The issuer also couldn't be making, or intending to make, new promises to perform those essential managerial efforts.

An issuer seeking to use the safe harbor would file Form TR. The filing would include a certification and an analysis supporting the conclusion that the required managerial efforts have ended.

Meeting those conditions would mean the crypto asset is deemed no longer subject to that investment contract for the relevant definitions of a security under the Securities Act and Exchange Act. That doesn't mean Form TR can convert a security into a non-security simply because an issuer files it. The substantive conditions still have to be satisfied, and the SEC can challenge an issuer's analysis.

Nor does the proposal replace Howey or the March interpretation. The safe harbor creates one defined route for dealing with the end of an investment contract. The SEC acknowledges that a covered investment contract could also cease to exist outside the safe harbor under the applicable securities-law analysis.

That lifecycle helps explain why the proposal is more consequential than a new exemption schedule.

The SEC is contemplating a regulatory sequence in which a project can finance development through an investment contract, distribute the associated crypto asset widely and potentially reach a point where the investment contract itself no longer exists.

Canada Could Face A Wider Crypto And Funding Gap

Canada has dealt with token offerings for years. Canadian securities regulators issued guidance on cryptocurrency offerings in 2017 and followed with more detailed token offering guidance in 2018. The CSA has made clear that coins or tokens can involve investment contracts and distributions of securities depending on their economic substance and how they are offered.

There have also been Canadian security-token initiatives and exempt-market token offerings. The difference isn't that Canada has avoided token issuance. Canada has generally applied its existing securities laws, prospectus exemptions and registration framework rather than creating a dedicated crypto lifecycle regime comparable to Regulation Crypto Assets. That difference also fits Canada's wider capital formation gap.

Capital formation makes that difference more important. Canada's NI 45-110 startup crowdfunding exemption currently permits an eligible issuer to raise up to C$1.5 million over 12 months. An investor generally can invest up to C$2,500 in an offering, or C$10,000 when a registered dealer determines that the investment is suitable, and the offering must take place through a funding portal.

The Canadian market is also much smaller. FrontFundr reports that it processed C$4.79 million from 4,320 investors under NI 45-110 in 2025 and accounted for 93% of activity under the exemption. Because that 93% figure comes from FrontFundr rather than an official national regulatory dataset, it should be treated as a platform estimate rather than an official Canadian market total.

There is stronger evidence that the C$1.5 million ceiling is becoming binding for some issuers. Edison Motors raised C$1.491 million under NI 45-110 in 2025, roughly 99% of the limit. Blossom Social raised C$1.450 million, approximately 97%.

See: Reg CF At 10 Shows Equity Crowdfunding Works

The more direct U.S. comparison is Regulation Crowdfunding. Reg CF already allows eligible companies to raise up to US$5 million in 12 months, but requires an SEC-registered intermediary, limits investments by non-accredited investors and generally restricts resale for one year. The proposed US$5 million crypto Startup Exemption would use the same headline ceiling with a different compliance model.

The larger crypto Fundraising Exemption is more directly comparable with Regulation A. Existing Reg A already uses US$20 million Tier 1 and US$75 million Tier 2 limits, with additional audit, investor-protection and ongoing-reporting requirements at Tier 2.

Canada is a different comparison. NI 45-110 isn't a crypto-specific equivalent to Regulation Crypto Assets, but it is Canada's nationally harmonized startup crowdfunding route. It remains capped at C$1.5 million over 12 months, with a funding-portal requirement and investor limits of C$2,500 per offering or C$10,000 with suitability advice from a registered dealer.

NCFA has been advocating for a C$5 million or higher issuer cap for years, arguing that the C$1.5 million ceiling can limit the usefulness of the exemption for growing companies. That concern is now easier to test against actual market activity, with some Canadian crowdfunding campaigns reaching close to the current ceiling.

The relevant policy question is therefore wider than whether Canada has an identical crypto exemption. The U.S. already offers Reg CF and Regulation A for different stages of capital raising and is now proposing a separate crypto-specific framework built around fundraising, token distribution, resale and the eventual end of an investment contract.

That matters because Canada's capital formation system already has funding gaps, while some Canadian crowdfunding campaigns are reaching the NI 45-110 ceiling. Regulation Crypto Assets could add another financing and regulatory option to the U.S. market without a directly comparable Canadian crypto-specific route.

The proposed US$75 million Tier 2 also raises a separate competitiveness issue. The SEC is asking whether Canadian issuers should eventually be eligible for the Fundraising Exemption. If they are included, qualifying Canadian crypto companies could gain access to a much larger U.S. pathway. If they remain excluded, access to U.S. capital could become another factor projects consider when deciding where to organize and raise funds.

None of this means Canadian regulators should copy the SEC. It does strengthen the case for examining Canada's startup financing limits, token-offering rules and capital-market pathways together rather than as separate policy files.

For Canada, the challenge is whether existing rules can protect investors while giving legitimate companies enough financing capacity and regulatory flexibility to build here. If the U.S. adds specialized crypto fundraising routes on top of Reg CF and Regulation A, that competitive comparison becomes more difficult to ignore.

Talking Point

If the U.S. adds a dedicated crypto capital-formation and investment-contract lifecycle regime on top of Reg CF and Regulation A, while Canada still relies on existing exemptions and a C$1.5 million startup crowdfunding cap, how long can Canada treat crypto regulation and capital-formation reform as separate policy questions?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Why Traders Watch Nasdaq 100 Moves

Aug 18, 2026

AI Image – Trader monitoring Nasdaq 100 market moves on multiple screens in a modern office

Markets have a few gauges that traders keep open even when they are not planning to trade them. The Nasdaq 100 is one of those gauges. It tends to get attention before the US session, during earnings weeks, and on days when rates or technology shares move hard.

Part of that comes from the companies inside the index. The Nasdaq 100 includes many of the names people already know from software, chips, cloud services, online retail, and consumer devices. When traders change their view on those companies, the index often shows it quickly. That is why the index can be useful even for people who are not trading it that day.

Why Traders Watch the Nasdaq 100

The Nasdaq 100 tracks 100 large non-financial companies listed on the Nasdaq exchange. Because the index leans toward technology and other growth businesses, it can move differently from broader benchmarks that include more banks, utilities, and industrial stocks. A broad index may look calm while the Nasdaq 100 is already showing stress in growth shares.

That mix gives the index a sharper edge. It may rally when traders feel more confident about growth and future earnings. It may also sell off quickly when rate expectations rise or when a large company warns that demand is slowing. The same feature that makes the index interesting can also make it uncomfortable to hold through rough sessions.

For active traders, those swings can create setups. For people watching the wider market, they can also show how much risk investors are willing to take. A strong Nasdaq 100 session can point to renewed appetite for growth stocks. A sudden drop can signal a more cautious mood, especially around inflation data, central bank comments, or major earnings results.

What Can Move the Index

Price movement in the Nasdaq 100 rarely comes from one headline. Traders usually look at company news, macro data, and the general tone of US equities before deciding whether a move has staying power. A rally based only on one strong stock may fade faster than a move supported by several sectors inside the index.

  • A big earnings miss from a major technology company can pull the index lower, especially if guidance changes.
  • Rate expectations matter because growth stocks are sensitive to the cost of capital.
  • Broad market mood matters too. When traders cut risk, they often reduce exposure to fast-moving growth names first.

Those drivers can overlap. A company may report strong revenue but still fall if margins disappoint or if traders think interest rates will stay high. Another stock may rise on weaker numbers because expectations were already low. That is why Nasdaq 100 moves often need context rather than a quick headline reading.

For many traders, the index is a shorthand for how the market is treating large growth companies against the current economic backdrop. It is not a perfect economic signal, but it can show whether investors are leaning toward risk or stepping back from it.

How Platform Tools Fit In

Trading platforms make that monitoring easier than it used to be. A trader can keep charts, watchlists, alerts, price data, and instrument details in one place instead of jumping between separate screens. That convenience matters when the market is moving and a slow check can lead to a late decision.

This is useful when the market starts moving quickly. One earnings report, one change in rate expectations, or one sharp move in US equity futures can change the tone of the session. Traders following the Nasdaq 100 usually want to see price levels, spreads, recent volatility, and related news before they place an order.

Someone comparing index products can use Vantage's nas100 page to check instrument details, pricing context, and platform access before deciding whether the market fits their plan. That page is not a trading signal. It is a reference point for understanding the product before putting money at risk.

Good platform habits are usually boring, but they matter. Traders may set alerts near levels they care about, check the daily range before deciding position size, and compare current spreads with what they normally see. None of that predicts the next move. It simply reduces the chance of entering a trade without knowing the basic conditions.

Before Placing an Order

A chart helps, but it is only part of the job. Traders also need to know how the instrument behaves on the platform they use. That includes the typical spread, order types, margin requirements, and how quickly prices can change during busy sessions.

Risk controls deserve the same attention as the setup. Stop-loss orders, position sizing, alerts, and account limits can keep a market view from turning into oversized exposure. That matters even more with index-based products, where leverage can magnify losses as well as gains.

Execution is another practical issue. In quieter sessions, prices may move in a fairly orderly way. During data releases or earnings headlines, the same market can become much harder to read. Watching how a platform handles those moments can be as useful as watching the chart.

A simple pre-trade routine can help. Check why the index is moving, decide where the idea is wrong, and know the maximum loss before entering. Traders do not need a complicated checklist, but they do need a repeatable one. Without that, a fast market can turn a reasonable idea into a rushed reaction.

Keep the Chart in Context

The Nasdaq 100 is easy to follow because many of its companies are familiar. That familiarity can be misleading. Knowing the names in the index does not protect a trader from sudden gaps, sharp reversals, or bad timing. A familiar company can still move in a way that surprises even experienced traders.

Past moves do not guarantee the next one. A pattern that worked during one earnings season can fail in the next. A level that held last month can break when macro conditions change. The index is liquid and closely watched, but that does not make it predictable.

See:  When Does A Smart Prediction Become Insider Trading?

Used carefully, Nasdaq 100 price action can help traders understand the mood around growth stocks and wider equity risk. It works best alongside product research and a clear risk plan. Preparation matters more than prediction, especially in a market where speed can make confidence look better than it really is.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

National Bank Modernizes Fund Accounting With Multifonds

August 17, 2026 | NCFA Market Activity | Capital Markets And Market Infrastructure, Wealth Investing And Trading, Competition And Market Structure

AI Image – Fund accounting and ETF administration operations centre

Fund And ETF Accounting Infrastructure Modernization

National Bank is modernizing its fund and ETF accounting infrastructure with Multifonds, bringing work handled across separate systems onto one platform.

On August 11, 2026, Multifonds announced that National Bank of Canada had selected Multifonds for fund and ETF accounting after an evaluation and proof of concept.

The project gives National Bank one accounting environment for more of the valuation, NAV and ETF administration work it performs for firms that offer investment funds and ETFs.

National Bank Brings Fund And ETF Accounting Onto One Platform

National Bank provides fund and ETF administration services that include fund accounting, transfer agency, ETF basket creation, financial statements and tax support.

Multifonds Global Accounting brings fund and ETF accounting into one environment. It processes data in real time and uses exception based workflows so operations teams can focus on records that need review.

The platform includes more than 350 configurable controls across NAV, valuation and distribution work. Multifonds says it supports more than 40,000 funds across 35+ jurisdictions.

National Bank plans to replace siloed systems with the platform. Multifonds expects the change to reduce manual steps, improve oversight and support faster product onboarding.

While those are the expected benefits, the results will depend on how the platform performs once National Bank moves more accounting work into production.

ETF Administration Adds More Operational Work

ETF administration involves more than calculating a fund's value. National Bank also supports transfer agency, market makers and the creation of ETF baskets.

Those processes depend on accounting records and outside data staying aligned. Multifonds connects ETF accounting with more automated data exchange, giving National Bank a common system for more of that work.

Canada's ETF market has grown sharply. Canadian ETFs attracted a record C$122 billion in net inflows in 2025, up 62% from the previous record, and Canadian ETF assets reached about C$790.5 billion by the end of March 2026.

Canada's ETF market has grown sharply. Canadian ETFs attracted a record C$122 billion in net inflows in 2025, while industry assets approached C$800 billion in early 2026.

The market is also under closer regulatory review. The CSA consultation on Canadian ETF rules examines areas including unit creation and redemption, ETF trading, NAV alignment and basket practices.

That growth means more products, valuations, baskets, records and exceptions for administrators to process. Automation can reduce repetitive work, but controls still have to catch problems before incorrect data reaches fund managers, trading partners or investors.

The same operating challenge appears in tokenized fund operations. New ways to issue or transfer fund interests still depend on reliable pricing, accounting, investor records and administration.

CIBC Mellon And RBC Are Automating Asset Servicing

National Bank is investing in a part of the market where other large Canadian asset servicers are also spending on technology.

In April, CIBC Mellon expanded its Appian automation program. Planned improvements include a more digital ETF service and fund administration workflows designed to reduce manual work and improve data visibility. CIBC Mellon reported more than C$3.4 trillion in assets under administration as of March 31, 2026.

RBC Investor Services reported C$3.1 trillion in assets under administration in the second quarter. Its asset servicing technology investments include ETF modernization, automated reconciliations and predictive reporting.

These investments highlight competitive pressure. Fund administrators need to support more products and data without adding manual work at the same rate.

Technology can influence how quickly an administrator launches products, handles exceptions and gives clients access to accurate information.

National Bank is also using specialist technology in other operating areas. Its Sardine fraud controls deployment focuses on fraud and financial crime rather than fund administration, but both projects use specialist technology for high-volume financial operations.

Moving more fund and ETF accounting onto one platform can simplify operations, but it also increases dependence on that platform.

National Bank will need strong data quality, integrations, controls and recovery processes as the implementation expands. If a shared accounting system fails, the  adverse impacts can amplify and reach more funds and ETF workflows at once.

Talking Point

As Canadian asset servicers automate more fund and ETF administration, will technology become a bigger factor in which providers win new business?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

How fintech companies can use public web data without regulatory risk

Aug 17, 2026

AI Image – Public web data fintech regulatory compliance

A mid-size alternative lender in Vilnius pulls company registry filings, marketplace pricing and sanctions lists into its underwriting model every night. None of it is illegal to read. Most of it becomes a liability the moment it is copied, stored and combined with something else. That gap between "publicly visible" and "lawfully processed" is where fintech compliance teams keep losing arguments with their own data science departments.

Public web data – company filings, marketplace listings, court dockets, sanctions databases, social media bios – has become a standard input for credit scoring, fraud detection, KYB and competitive pricing in financial services. In Meta Platforms v. Bright Data, a federal district court held that Bright Data had not breached Meta's terms of service by collecting data from logged-out pages, which was the specific conduct at issue. The ruling turned on Bright Data's particular conduct and its contractual relationship with Meta rather than establishing a general rule for scraping public websites. For a regulated entity, that distinction is not academic. A bank's third-party risk team, an EU DORA auditor or a state attorney general does not care whether the data was "technically public" if the collection method itself created exposure.

What "public" actually means under US and EU law

hiQ Labs v. LinkedIn is still the reference case for US practitioners, and it is more nuanced than the headlines from 2019 suggest. The Ninth Circuit held twice, first in 2019 and again on remand in 2022, that scraping data from pages open to any visitor does not amount to accessing a computer "without authorization" under the Computer Fraud and Abuse Act. That took the CFAA off the table as a criminal exposure for reading public pages. It did not end the case. hiQ and LinkedIn settled the remaining contract claims in 2022, and hiQ agreed to destroy the data it had already collected and pay damages, because its scraping still violated LinkedIn's user agreement. The lesson for a fintech legal team is specific: CFAA risk and contract risk are two separate questions, and winning on one does not close the other.

On the EU side, the CFAA question barely matters, because GDPR does not distinguish between public and private personal data. Article 4 defines personal data by whether it relates to an identifiable natural person, not by where it was found. A LinkedIn bio, a court filing with a defendant's name, or a marketplace seller profile with a real name attached all fall inside GDPR's scope the moment they are collected, and Article 6 still requires a lawful basis – legitimate interest is workable for adverse-media or fraud screening, but it requires a documented balancing test, not just a note in a Confluence page.

Where fintechs actually use this data

Four use cases account for most of the public-data traffic coming out of fintech data engineering teams. Alternative underwriting pulls e-commerce store metrics, invoice marketplaces and gig-platform ratings to score borrowers who lack conventional credit files – Kabbage and, later, Amex built entire product lines on this. AML and sanctions screening cross-references OFAC, EU and UN lists against onboarding data, refreshed daily because list updates are unscheduled. Competitive pricing intelligence in embedded finance and BNPL tracks merchant-facing rates across marketplaces to benchmark interchange and fee structures. Fraud and adverse-media screening checks court records, press mentions and social profiles as a secondary signal alongside device fingerprinting.

Not all four carry the same regulatory weight. The table below is the one compliance teams actually need before greenlighting a collection project, not a generic "data source" taxonomy.

Data sourceTypical fintech useRegulatory sensitivityMain legal basis to check
Company registries (Companies House, EDGAR, EU BRIS)KYB, beneficial ownership checksLow to mediumPublic register rules and applicable data protection law; filings may contain personal data of directors, officers, beneficial owners and other natural persons
Sanctions and PEP lists (OFAC, EU, UN)AML/KYC screeningLowGovernment-published, but update frequency and source authenticity matter
E-commerce and marketplace pricingCompetitive intelligence, embedded-finance pricing modelsLow to mediumTerms of service and contract law; CFAA exposure may be lower for pages accessible without login (per hiQ v. LinkedIn)
Public social media profilesAlternative credit signals, fraud indicatorsMedium to highGDPR/CCPA personal-data rules apply even if the profile is public
Court records and litigation databasesAdverse media, fraud investigationHighJurisdiction-specific rules on re-use of judicial data (varies widely, e.g. France's Article 33)

The technical side: building a collection pipeline that survives an audit

The engineering choices matter as much as the legal analysis, because a regulator or a bank's third-party risk assessor will ask for logs, not intentions. A defensible pipeline has five properties, and they map to concrete infrastructure decisions rather than policy statements.

Collection controls and evidence each leaves behind

Figure 1

Figure 1. Each control maps to an artifact a third-party risk assessor can actually inspect. The first four are described below; request logging is the fifth, and the one the practical takeaway returns to.

Rate limiting that respects the source, not just your own throughput budget

Reading a site's robots.txt crawl-delay directive and setting concurrency accordingly is a five-minute engineering task that changes the legal character of the whole program. A crawler hitting a company registry at 200 requests per second looks like a denial-of-service test to the target's security team, regardless of what the data is used for afterward. Most production fintech scrapers we've reviewed cap at 1 request per 2-4 seconds per domain, which keeps CPU load on the target negligible and avoids the WAF triggers that generate abuse complaints in the first place.

IP rotation for reliability, not for evasion

This is the point where proxy infrastructure choice stops being a procurement decision and starts being a compliance decision. Rotating through residential or datacenter IPs to maintain a stable success rate against rate limits is standard engineering practice. Rotating IPs specifically to re-access a source after being blocked for a terms-of-service violation is the fact pattern that turned hiQ's win on CFAA into a loss on contract claims. The distinction sounds semantic until an opposing counsel reconstructs your request logs during discovery.

Data minimization at ingestion, not at export

Filtering personal identifiers (names, emails, phone numbers, biometric-adjacent fields) before the data lands in a warehouse is materially cheaper than filtering it after ten analysts have already queried the raw table. A regex-and-NER pass at the collection layer, logged with a timestamp and a rule version, is the artifact a DPO can actually show an auditor.

Retention limits tied to the original purpose

GDPR's storage limitation principle (Article 5(1)(e)) and most US state privacy laws expect a defined retention period. "We keep everything indefinitely for model retraining" is the single most common finding in the DPIAs we've read for alt-data underwriting programs, and it is usually fixable with a 90-180 day rolling window plus a documented exception process for flagged accounts.

Infrastructure and vendor selection

Proxy and scraping infrastructure choice affects three things a compliance file will ask about: whether the vendor itself runs KYC on IP sourcing, whether the billing model matches your actual usage pattern (per-IP monthly vs. per-GB bandwidth), and whether the vendor's own terms indicate the network is ethically sourced rather than built from compromised devices.

ProviderBilling modelEntry priceWhere it fits a fintech workload
Proxys.ioPer dedicated IP / monthFrom $1.40/mo (individual IPv4), $0.13/mo (IPv6)Steady, low-volume monitoring jobs (registry checks, sanctions list refresh) where a fixed, auditable IP per data feed is easier to log than rotating bandwidth pools
Decodo (formerly Smartproxy)Per GB, tiered$2.00-$3.75/GB depending on volumeMid-volume scraping across many source domains where bandwidth, not IP count, is the cost driver
OxylabsPer GB, sales-assistedRoughly $8/GB at entry tier, KYC required before provisioningEnterprises that want a vendor-side KYC record as part of their own third-party risk file
Bright DataPer GB (PAYG or committed)$8.40/GB PAYG residential, down to ~$3/GB committed; datacenter from ~$0.90/GBLarge, multi-region collection programs where volume discounts offset the higher entry rate

The billing model split matters more than the headline price. A sanctions-list refresh job that hits the same twelve government sources every night at a predictable, low volume is a poor fit for per-GB bandwidth pricing – you're paying for a metric (data transferred) that has almost nothing to do with your actual constraint, which is IP reputation and consistency of access over time. Vendors like Proxys.io bill per dedicated IP per month, which lines up better with that access pattern and makes cost forecasting for a fixed set of monitored sources straightforward. A marketplace-pricing crawl that touches thousands of product pages across dozens of domains is the opposite case: bandwidth is the real cost driver, and a per-GB model from Decodo, Oxylabs or Bright Data scales more predictably with that workload. Enterprises already running Oxylabs' or Bright Data's own KYC process may lean on that as one input to their own vendor risk assessment, though it doesn't substitute for one.

Billing model against workload shape

Figure 2

Figure 2. The two variables that move cost are how many domains a run touches and how much data it moves, not the headline price per unit. Per-IP and per-GB rates are quoted in different units and cannot be compared directly.

See: AI Governance for Canadian Financial Advisors

None of these vendors, including the ones with published ethics or KYC pages, remove the fintech's own obligation to define a lawful basis, log what was collected, and honor retention limits. The proxy layer solves an availability and reliability problem – consistent access to public pages without disproportionate load on the source – not a data protection problem.

When the current setup stops being fit for purpose

Three signals usually mean a proxy or scraping setup needs to change, independent of price. First, a rising block rate on sources with unchanged rate limits – that's an IP-reputation problem the vendor's pool has accumulated, not something a compliance policy fixes. Second, the compliance team asking for source-level access logs the engineering stack can't currently produce – that's a signal the collection layer needs structured logging before it needs a new vendor. Third, a shift in workload shape, for example moving from a handful of steady, low-volume registry checks to broad multi-domain marketplace crawling, which usually means the per-IP pricing that worked for the first case stops making sense for the second.

Practical takeaway

A fintech data program built on public web sources holds up under regulatory review when three things are documented before the first request is ever sent: the lawful basis for each data category (not a blanket justification), the technical controls that keep collection proportionate to the source (rate limits, minimization, retention), and a request log detailed enough to reconstruct what was collected and why if a regulator or a counterparty's third-party risk team asks. The infrastructure vendor is a smaller decision than most procurement processes treat it as – it changes reliability and cost, not the underlying legal analysis.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

NCFA Weekly Fintech Intelligence Aug 8-14, 2026

Aug 8, 2026 | NCFA Fintech Whisperer | Digital Banking And BaaS, Regulation And Policy, SME Finance And Business Banking, Digital Assets Blockchain And Tokenization, Payments Infrastructure And Money Movement, Capital Markets Infrastructure And Funding, Artificial Intelligence And Data, Wealthtech Investing And Trading, Embedded Finance, Risk Compliance And Regtech, Lending Consumer Credit And BNPL, Cybersecurity Fraud And Financial Crime

Image Freepik, Data visualization signals

Image: Freepik

This live weekly NCFA intelligence page tracks financial technology developments that significantly affect how fintechs build, sell, raise capital, and operate under scrutiny. Coverage prioritizes Canada and includes global events that directly influence competitive conditions, market access, and execution realities across fintech sectors.  This page will be updated throughout the week with market movers in a live format and then each week we'll close the prior week's contents in prep for the upcoming week, and continue on a rolling basis.  (Missed prior week's Fintech Whisperer?  (December 6-12, 2025, December 13-19, 2025, January 1-9, 2026, January 10-16, 2026, January 17-23, 2026, January 24-30, 2026, January 31-February 6, 2026, February 7-13, 2026, February 14-20, 2026, February 21-27, 2026, February 28-March 6, 2026, March 7-13, 2026, March 14-20, 2026, March 21-27, 2026, March 28-April 3, 2026, April 4-10, 2026, April 11-17, 2026, April 18-24, 2026, April 25-May 1, 2026, May 2-8, 2026, May 9-15, 2026, May 16-22, 2026, May 23-29, 2026, May 30-June 5, 2026, June 6-12, 2026, June 13-19, 2026, June 20-26, 2026, June 27-July 3, 2026, July 4-July 10, 2026, July 11-July 17, 2026, July 18-24, 2026, July 25-July 31 2026, August 1-August 7, 2026).

Weekly Fintech Market Intelligence Aug 8 - 14, 2026

Wealthtech Investing And Trading

Gate Expands Into U.S. Stocks And Tokenized Equities Through Alpaca

August 13, 2026, Global
  • Gate, which Alpaca says serves more than 58 million users, launched access to more than 10,000 U.S. listed stocks and ETFs, eligible IPO allocations and tokenized stocks using Alpaca infrastructure.
  • Alpaca provides the brokerage infrastructure behind the offering and supports custody and settlement of the underlying shares associated with Gate's gStocks tokenized stock product.
  • One day earlier, Crypto.com launched Tokenized Stocks through Alpaca for a platform serving more than 150 million customers, offering economic exposure to 1,500 U.S. stocks and ETFs from US$1, with selected products available around the clock.
  • Crypto.com's products are derivative financial instruments that provide economic exposure rather than ownership of the underlying shares or associated shareholder rights.

Large crypto platforms are starting to look more like multi asset investment distributors, but the infrastructure underneath them is still regulated brokerage, custody and settlement. Alpaca has been building specifically for this role, which NCFA recently examined in its global brokerage platform expansion. The competitive question is who controls that regulated layer as crypto, traditional securities and tokenized products converge inside the same customer interface.

BlackRock Canada Embeds Bitcoin In Diversified ETF

August 10, 2026, Canada
  • BlackRock Canada launched the iShares Equity + Bitcoin ETF Portfolio, or IBQT, on the Toronto Stock Exchange with a strategic allocation of approximately 97% global equities and 3% bitcoin.
  • The fund carries a 0.22% management fee and packages Canadian, U.S., international and emerging market equities with bitcoin exposure inside one portfolio.
  • IBQT currently gets its bitcoin exposure through BlackRock’s Canadian IBIT fund, extending that product from a standalone bitcoin investment into a component of a diversified portfolio.

IBQT changes where the crypto allocation decision happens. Investors choosing the fund are buying a diversified equity portfolio with bitcoin already assigned a modest strategic weight, rather than adding crypto separately. That puts bitcoin closer to conventional portfolio construction and gives Canadian advisers and investors a simple way to combine traditional markets and digital assets in one listed product.

Payments Infrastructure And Money Movement

Flywire And Trustly Bring Pay By Bank To Canada

August 12, 2026, Canada / United States
  • Flywire expanded its Trustly partnership into Canada and the United States, letting payers authorize large domestic and cross border payments directly from their bank accounts.
  • In Canada, the payment itself runs through Pre Authorized Debit. Trustly adds bank authentication and account connectivity around that existing rail rather than using Canada’s future regulated payment initiation framework.
  • The service removes manual account entry during checkout and adds payment verification and risk controls around higher value bank transfers.

Pay by Bank is reaching Canadian customers before regulated payment initiation does. Foreign providers are improving the experience around an existing Canadian bank rail instead of waiting for new infrastructure. That makes the commercial timing important for Canada’s open banking opportunity: future regulated access will enter a market where some of the customer experience is already being built.

Dream Payments Launches Programmable U.S. Payout Network

August 11, 2026, Canada / United States
  • Toronto based Dream Payments launched Dream Payouts for eligible U.S. businesses in collaboration with J.P. Morgan Payments, supporting payments to suppliers, partners and individuals.
  • Eligible payments can arrive through the RTP network in under 30 seconds, including nights, weekends and holidays, with ACH and wire available when instant delivery is unavailable or not selected.
  • Software platforms can embed payout capabilities, while Dream provides recipient onboarding, identity checks, banking verification, approval controls and transaction tracking from initiation through settlement.
  • Dream says the infrastructure can support software and AI agents that initiate, approve and reconcile payments within defined business controls.

Dream is taking infrastructure built by a Canadian fintech into U.S. business payment workflows where the payment can start inside the software that created the obligation. That also gives agent payment infrastructure a more concrete operating model: software can participate in the workflow, but identity, authority, approval and settlement controls still determine whether money moves.

Francisco Partners To Acquire Moneris For C$2 Billion

August 10, 2026, Canada
  • Francisco Partners agreed to acquire Moneris from RBC and BMO for approximately C$2.0 billion in cash, with each bank receiving half of the proceeds. The transaction remains subject to regulatory approvals and other closing conditions.
  • RBC and BMO will keep exclusive referral relationships with Moneris even as ownership of the payments company transfers to Francisco Partners.
  • Moneris says it has nearly 2,000 employees in Canada and will retain its Canadian headquarters and technology infrastructure after the transaction closes.

Last year’s Moneris sale discussion has become a signed change of control. RBC and BMO are giving up ownership while preserving customer distribution, leaving Francisco Partners to decide how aggressively Moneris invests across merchant acquiring, commerce software and payments technology. The separation between infrastructure ownership and bank distribution is the more consequential part of the deal.

Capital Markets Infrastructure And Funding

Canada Starts Trial Of Government Securities Fail Fee Framework

August 13, 2026, Canada
  • CIMPA and CDS will begin the first stage of Canada's fail fee framework for Government of Canada bond and T-bill transactions on September 8, 2026.
  • The trial will run for at least 18 months. Settlement fails and indicative fees will be calculated, statistics will be published and CDS participants will receive reports and indicative invoices.
  • No fail fees will be charged or paid during this first stage. The Canadian Fixed-Income Forum will decide whether payments are activated later.

Canada is putting a settlement discipline framework into live measurement before imposing a financial penalty. That gives dealers, custodians and market infrastructure providers time to see where fails occur, what the operational burden looks like and whether the fee design changes settlement behaviour. The evidence from the trial will determine whether a reporting framework eventually becomes an economic incentive.

Canada Starts Standardized Government Collateral Trading On CCMS

August 12, 2026, Canada
  • CIMPA, TMX Group and Clearstream have started repo trading using a standardized Government of Canada General Collateral basket on the Canadian Collateral Management Service.
  • CCMS automates repo collateral management and supports unlimited real time collateral substitution, giving participants another way to manage liquidity and collateral throughout a transaction.
  • The first GoC basket is expected to be followed by standardized baskets covering provincial securities, Canada Mortgage Bonds, NHA mortgage backed securities, public sector securities and corporate collateral.

Canada's repo market now has a standardized collateral workflow running on infrastructure that the Bank of Canada also plans to use for its domestic repo operations. Wider adoption would make collateral easier to allocate and substitute across financing activity while reducing manual processing. The next evidence is usage: how much repo activity migrates onto CCMS and whether the additional baskets deepen participation beyond Government of Canada securities.

PointsKash Expands Capital Commitment To Support National Kiosk Rollout

August 12, 2026, United States
  • PointsKash announced an expanded strategic capital commitment of up to US$100 million from Hawk Capital Advisors to support commercialization and national deployment of its financial services platform.
  • The first phase provides for up to US$35 million through October 30, 2026 for priorities including refurbishment and deployment of approximately 2,100 company owned KashPoint kiosks, technology integration, merchant activation, PK Pay development and working capital.
  • A second phase could provide up to another US$65 million between February and April 2027, subject to operating and deployment milestones, customary closing conditions and financing availability.

The financing connects capital directly to deployment of a physical and digital financial services network rather than funding an undefined expansion plan. PointsKash acquired more than 2,100 cryptocurrency kiosks earlier in August and now has a staged capital structure intended to refurbish and redeploy that hardware while building payments, merchant and mobile services around it. The conditional structure also keeps a clear line between near term funding and the larger amount that depends on execution.

CIRO Short Sale Settlement Rule Takes Effect

August 11, 2026, Canada
  • CIRO now requires a Participant or Access Person to have a reasonable expectation that a short sale can settle on the intended settlement date before entering the order.
  • The rule adds a positive control before execution instead of relying only on action after a trade fails to settle.
  • CIRO provides defined exceptions, including certain sales involving securities a person is deemed to own, subject to prescribed delivery conditions.

The rule changes where settlement risk has to be dealt with. Firms must support the expectation of settlement before a short sale reaches the market, putting more responsibility on trading controls, securities availability and supervision. Difficult to borrow securities and repeated settlement failures will show how demanding the requirement becomes in practice.

Artificial Intelligence And Data

RBI Sets Concrete AI Governance Expectations For Banks

August 11, 2026, India
  • Reserve Bank of India Governor Sanjay Malhotra told banks to maintain inventories of material AI systems and establish governance that assigns clear responsibility for their use and risks.
  • He called for contracts with AI providers to preserve audit, explanation and exit rights, while material systems should be stress tested and tested against adversarial behaviour before deployment and periodically afterward.
  • Banks should retain meaningful human oversight where an AI error could materially harm a customer or financial stability, including lending, fraud and other consequential decisions.

RBI is pushing AI governance into the same operating disciplines banks already use for material risk. That aligns with Canadian work on regulated AI, where model oversight, vendor access, fallback plans and proof of control are becoming practical requirements. The advantage will come from deploying useful AI while being able to show who owns the risk and how the system is controlled.

Cross Border Payments And FX

Brazil Explores Linking Pix To Foreign Payment Systems

August 10, 2026, Brazil
  • Brazil’s central bank is assessing bilateral connections between Pix and foreign instant-payment systems, as well as participation in multilateral payment hubs, to support lower-cost and faster cross-border transfers.
  • The work goes beyond earlier discussion of possible international expansion. Banco Central do Brasil had already placed Pix Internacional on its 2027+ development agenda in March, and the August update points to more concrete interoperability options.
  • Pix processed nearly 80 billion transactions worth more than R$35 trillion in 2025, giving any international connection potential scale well beyond a niche cross-border payment product.

Pix is starting to test whether a national instant-payment rail can connect directly into foreign payment infrastructure rather than relying only on traditional correspondent channels. NCFA’s cross border payments benchmark shows why that distinction matters: strong domestic rails don’t automatically solve international cost, speed or interoperability. The practical questions are which systems Brazil connects to first, how FX, compliance and settlement are handled across jurisdictions, and whether this becomes a repeatable model for other domestic real time rails.

Digital Assets Blockchain And Tokenization

OCC Conditionally Approves World Liberty National Trust Bank

August 14, 2026, United States
  • The OCC granted preliminary conditional approval for World Liberty Trust Company, National Association, the proposed national trust bank of Trump family backed World Liberty Financial.
  • The approved business plan covers USD1 issuance and redemption, maintenance of USD1 reserve assets, fiduciary digital asset custody and limited conversion services for custody customers.
  • The approval is not authority to begin operations. The proposed bank is limited to trust company activities, does not plan to become an FDIC insured depository institution and must satisfy remaining OCC conditions before commencing business.

USD1 could move from a stablecoin structure supported by external service providers into a federally supervised trust bank that combines issuance, redemption, reserves and custody. That would bring more of the operating stack behind a payment stablecoin inside one regulated entity, while concentrating responsibility for reserve management, safeguarding and compliance.

Deribit Gets Dubai Broker Dealer Licence And Coinbase Liquidity

August 13, 2026, United Arab Emirates
  • Deribit FZE received a Broker Dealer Licence from Dubai's Virtual Assets Regulatory Authority, expanding the permissions behind its existing regulated spot trading operation.
  • Spot buy, sell and trade orders placed on Deribit can now be routed to Coinbase Exchange for execution, giving clients access to deeper liquidity and hundreds of additional assets.
  • The upgraded spot service is rolling out to retail, qualified and institutional investors. Assets acquired through it can also be used as collateral for Deribit derivatives trading, subject to regulatory approval.

The Coinbase acquisition is moving from ownership into shared market infrastructure. Deribit can keep its derivatives interface while drawing on Coinbase's spot liquidity and execution stack, extending the Deribit acquisition strategy into day to day trading. That brings spot execution, collateral and derivatives closer together inside one regulated operating structure.

Perpetual Markets Extends Regulated European Venue Into Crypto

August 13, 2026, Cyprus / European Union
  • PM MTF Ltd received CySEC authorization under MiCA for crypto asset services alongside its existing regulated European trading venue.
  • The authorized activities include operating a crypto asset trading platform, custody and administration, execution of orders, reception and transmission of orders, and crypto asset transfers.
  • The authorization provides a regulated route for Perpetual Markets to extend crypto services across the EEA, including infrastructure that can support institutional and white label distribution.

The significance is the combination of existing regulated market infrastructure with newly authorized crypto services. Rather than building a separate crypto venue, Perpetual Markets can extend an established MTF operating model into digital assets, giving brokers and institutions another route to offer crypto products under a European regulatory framework. The announcement authorizes expansion, but does not establish that every permitted crypto service is already live at scale.

Anchorpoint Starts Institutional Rollout Of Regulated HKD Stablecoin

August 12, 2026, Hong Kong
  • Hong Kong licensed issuer Anchorpoint began phase one of HKD At Par, or HKDAP, through Beta Access for institutional distributors and professional investors.
  • Authorized distributors can provide conversion between HKDAP and fiat currency for institutions, corporate users and professional investors while integrating the stablecoin into commercial and financial applications.
  • Anchorpoint is initially targeting cross border payments and settlement and distribution of tokenized real world assets. Broader retail access could begin as early as the end of 2026, depending on market conditions.

Hong Kong's stablecoin regime has crossed from licensing into controlled distribution and commercial use. That builds on the tokenized finance strategy NCFA has been tracking through Standard Chartered and Hong Kong's regulators. HKDAP now has to prove that regulated tokenized money can attract repeat transaction flow across payments, asset settlement and institutional distribution rather than remain a licensed product with limited circulation.

Coinbase Gets Abu Dhabi Permission For Tokenized Securities Hub

August 11, 2026, United Arab Emirates
  • Coinbase received Financial Services Permission from the Financial Services Regulatory Authority of ADGM to arrange investment deals and provide custody in support of tokenized securities.
  • Coinbase says securities issued through the structure will be backed by underlying shares, with verified token holders receiving shareholder rights including dividends and voting.
  • Transfers will be subject to ongoing sanctions screening, with wallet level freeze and seizure capabilities where required.

The important distinction is the legal and operating structure behind the token. Coinbase is combining regulated custody, underlying shares, investor rights and blockchain transferability rather than offering price exposure alone. That puts the model inside the infrastructure test NCFA is tracking for regulated tokenized assets: whether ownership rights, custody, compliance and transfer can work together at market scale.

Robinhood Uses Bitstamp To Bring Crypto Into Its UK App

August 10, 2026, United Kingdom
  • Robinhood has begun rolling crypto trading out to eligible UK customers, adding more than 50 digital assets directly inside its main investing app alongside equities, ISAs, options and futures.
  • Crypto trading is provided through Bitstamp UK Ltd, bringing the regulated UK infrastructure Robinhood acquired with Bitstamp into Robinhood’s retail distribution channel. Robinhood completed the acquisition in June 2025 to accelerate its crypto expansion outside the U.S.
  • The rollout is a material follow-on to Robinhood’s July 1 announcement, when the company said UK crypto trading was coming soon but had not yet launched it. Robinhood’s own disclosure at the time still said its UK entity did not offer crypto trading or custody.
  • The launch also adds Cortex Digests for Crypto, using generative AI to combine news, market data, technical indicators and Robinhood information into asset-level market summaries.

Bitstamp is becoming more than an acquired exchange for Robinhood. Its UK crypto infrastructure now lets Robinhood add digital assets to the same interface where customers already invest across traditional markets. The next test is whether that combination deepens customer activity and gives Robinhood a repeatable way to extend its wider investment platform into regulated crypto markets.

Lending Consumer Credit And BNPL

Shakepay Launches Bitcoin Backed Line Of Credit In Canada

August 13, 2026, Canada
  • Shakepay launched BLOC, a revolving line of credit that lets eligible Canadian customers borrow against bitcoin held with Shakepay without selling it.
  • Customers can borrow up to C$50,000 starting at 9.5% APR and track their balance, payments, collateral and loan to value ratio inside the Shakepay app.
  • BLOC is offered by Shakepay Credit Inc. under exemptive relief. If collateral values fall, borrowers may need to add bitcoin, repay part of the balance or face liquidation under the product terms.

Crypto backed lending is becoming part of the product stack offered by Canadian trading platforms. Shakepay is integrating the credit relationship directly into its own account experience, while embedded crypto lending at Netcoins uses APX to supply the lending operation behind the interface. The two models create different economics and different responsibility for underwriting, collateral controls and servicing.

Mortgage Automator Brings Construction Draw Management Into The Loan File

August 10, 2026, Canada
  • Toronto based Mortgage Automator launched Draw Management, bringing construction budgets, draw schedules and approvals directly into the active loan file for private lenders.
  • The feature automatically flags budget variances and applies Project Health scoring so lenders can monitor construction progress and draw risk without relying on separate spreadsheets or disconnected workflows.
  • The launch follows Mortgage Automator's August 4 acquisition of Lendr, extending its expansion into construction and private lending infrastructure across North America.

Construction lending is operationally intensive because capital is released in stages and each draw depends on current budget, progress and compliance information. Moving those controls into the loan system can reduce reconciliation work and make exceptions visible earlier, while giving private lenders a more integrated way to manage construction credit as portfolios scale.

Digital Banking And BaaS

TD Adds In-App Payroll Deposit Switching With Atomic

August 10, 2026, Canada
  • TD launched an in-app payroll direct-deposit switching experience that lets customers redirect payroll deposits to a TD account in about one minute with most employers.
  • The capability is powered by Atomic and sits inside the TD app, removing the need for customers to separately obtain banking details and update payroll information through their employer.
  • TD says it is the first Canadian financial institution to offer a fully integrated in-app payroll switching experience and has exclusive Canadian rights to Atomic’s capability through the end of 2026.

Opening a new bank account is easier than making it the primary account. Payroll switching reduces the work required to redirect recurring income and adds an operational layer to open banking and financial portability. Competition improves when customers can act on a better banking option, not only compare one. The next measure is whether easier switching translates into more primary-account relationships and deposits.

Revolut Receives Full French Banking Licence

August 10, 2026, France / Western Europe
  • Revolut Bank S.A. received a full French banking licence following a joint assessment by France’s ACPR and the European Central Bank, with the decision formally adopted by the ECB Governing Council.
  • The new French bank will begin serving customers in France before progressively expanding across Germany, Ireland, Italy, Portugal and Spain. Revolut Bank UAB in Lithuania remains the group’s other European banking hub.
  • Revolut says Western Europe now accounts for about 30 million customers. It has committed more than €1 billion to the region and is hiring more than 600 people across its Western European markets.

The licence turns Revolut’s banking expansion into a two-hub European structure with a new regulated entity serving its largest regional customer base. The execution test is how quickly customers and products migrate to the French bank, and whether local licences give Revolut more room to deepen lending, business banking and other regulated services across Western Europe.

Regulation And Policy

CFTC Uses Emergency Authority To Keep Kalshi Operating

August 11, 2026, United States
  • The CFTC exercised emergency authority after Kalshi notified the Commission of a market emergency tied to litigation brought by New York Attorney General Letitia James.
  • The Commission ordered Kalshi to continue operating in accordance with the Commodity Exchange Act Core Principles. New York is seeking to stop Kalshi from offering event contracts nationwide and is pursuing more than US$36 billion in damages.
  • The CFTC says federal law requires a uniform national derivatives market and has challenged state efforts to apply gambling laws to federally regulated designated contract markets in several jurisdictions.

The dispute is becoming a direct test of who controls access to event contracts in the United States. The CFTC is treating Kalshi as national derivatives infrastructure while states continue to challenge parts of the market through gaming law. NCFA’s regulated event contract infrastructure brief tracks the same boundary between exchange regulation, market integrity and product access.

FCA Adds Five Fintechs To Scale-Up Regulatory Unit

August 10, 2026, United Kingdom
  • ClearScore, Modulr, Teya, Urban Jungle and Zilch became the first firms regulated solely by the FCA to join its Scale-up Unit.
  • The unit gives fast-growing regulated firms a dedicated regulatory contact for product launches, permission changes, policy developments and other issues that arise as they expand.
  • The FCA also published findings from a 15-firm high-growth pilot, including weaknesses where governance, board oversight, risk management and controls had not kept pace with business growth.

The FCA is making regulatory engagement part of the scale up process rather than waiting for rapid growth to create supervisory problems. NCFA’s closer look at the five firms shows how that support intersects with payments, credit, insurance and European expansion. For fintechs, the tradeoff is clearer: faster access to regulatory guidance comes with closer attention to whether governance, controls and customer protections are developing at the same rate as products, customers and market expansion.

Senate Sets September Procedural Vote On CLARITY Act

August 8, 2026, United States
  • Senate leadership filed cloture on the motion to proceed to H.R. 3633, the Digital Asset Market Clarity Act, after the chamber left for its August recess without voting on the bill.
  • The Senate schedule says the cloture motion will ripen on September 15 at 2:15 p.m., creating a formal procedural route toward floor consideration when senators return.
  • The bill still faces a 60-vote threshold and unresolved negotiations, including bank concerns over stablecoin rewards and proposed ethics provisions.

The CLARITY Act has moved from an uncertain post-recess commitment to a scheduled Senate procedure. The September vote will test whether negotiators can assemble enough support to advance a federal market-structure framework and narrow the remaining disagreements over banking, stablecoins and digital-asset oversight.

SME Finance And Business Banking

Mercury Lets Businesses Issue Dedicated Cards To AI Agents

August 11, 2026, United States
  • Mercury launched Mercury Spend with budgets, expense policies and company cards managed through one spending system.
  • Businesses can issue dedicated cards to AI agents for approved transactions and monitor their spending separately from employee activity.
  • Budgets and expense policies provide the control layer around those cards, while Mercury can automatically categorize transactions and lock cards when required tasks remain overdue.

The important change is that an AI agent can now receive its own controlled payment credential rather than only prepare a transaction for someone else. That makes permission design part of the payment product. NCFA has already tracked how AI agents use card rails; Mercury brings the same question inside company spending, where budgets and policy controls define how much authority software actually receives.

SIDBI Takes Invoice Fraud Controls Into Live MSME Lending

August 10, 2026, India
  • SIDBI and MonetaGo confirmed that Secure Financing is live on SIDBI’s GST-Sahay invoice-based financing platform following a pilot and three months of production use.
  • The system validates invoices financed through India’s TReDS infrastructure and checks invoices across participating factoring platforms and lenders, including SBI Global Factors and India Factoring.
  • The production milestone follows the November 2025 SIDBI-MonetaGo partnership. The system is designed to identify duplicate financing and strengthen invoice validation before credit is advanced to MSMEs.

Invoice financing fraud controls are becoming shared lending infrastructure rather than checks performed inside one lender at a time. MonetaGo has been working on shared trade finance fraud controls for years; the SIDBI deployment brings that model into live MSME lending. The test is whether interoperable validation reduces duplicate financing and exceptions at scale while making cash flow credit faster and safer across multiple lenders and factoring platforms.

Embedded Finance

Mews Gains EEA Electronic Money Institution Licence

August 11, 2026, European Economic Area
  • De Nederlandsche Bank granted Mews Financial Services B.V. an Electronic Money Institution licence, giving the hospitality software company regulated financial standing across the EEA.
  • Mews plans to bring payment services, financial workflows and hotel operating data into the same platform, alongside safeguarding, fraud monitoring, sanctions screening and anti money laundering controls.
  • The company processed US$19.7 billion in hotel transaction value in 2025. Regulated capabilities are expected to begin with a Netherlands pilot in late 2026 before expanding across the EEA.

Mews is taking embedded finance beyond connecting hotels to outside financial providers. Its own regulated entity can now sit inside the software where hotel revenue, operations and payments already meet. That changes the regulatory boundary for embedded finance: vertical software can become part of the licensed financial infrastructure instead of remaining only the distribution layer.

Risk Compliance And Regtech

TransFi Puts AI Into Cross Border Compliance Workflows

August 14, 2026, Global
  • TransFi launched JARVIS, a proprietary compliance intelligence platform that combines KYC and sanctions screening, internet profiling, behavioural and biometric signals, and fiat and blockchain transaction monitoring.
  • JARVIS builds risk profiles, uses heuristics and AI research to recommend actions on high confidence matches, and escalates complex or ambiguous cases for human review.
  • Final KYC, KYB, transaction monitoring and screening decisions remain with TransFi's compliance team under MLRO oversight.

AI is entering compliance as an investigation and decision support layer rather than replacing accountable human approval. That model fits the emerging market for AI powered compliance workflows where evidence, escalation, auditability and human control determine whether automation can be trusted. TransFi's operating test is whether JARVIS reduces review effort across multiple jurisdictions without weakening decision quality.

Cybersecurity Fraud And Financial Crime

Trezor Customer Data Exposed In Shipping Provider Breach

August 13, 2026, Global
  • Trezor disclosed that a breach at shipping provider ShipMonk exposed customer information including names, email addresses, phone numbers and shipping addresses.
  • Approximately 11,742 customers had full contact and shipping information exposed, while another 1,947 had partial exposure, bringing the affected total to about 13,689 customers.
  • Trezor says its own systems, devices and services were not compromised. The company warns that the exposed information could instead be used for more sophisticated phishing and impersonation attempts.

The breach shows how self custody can inherit risk from suppliers that never touch a private key. Fulfilment providers still hold enough identity and location data to expose hardware wallet owners to targeted attacks, making vendor controls and data retention part of hardware wallet security rather than a separate privacy issue.

Weekly Close

Financial infrastructure is becoming easier to enter and harder to operate well. Bank switching is getting simpler, payments are becoming programmable, AI agents are gaining spending authority and software platforms are taking on regulated financial roles. At the same time, regulators are putting more weight on governance, settlement discipline, market access and accountability. The competitive advantage is moving toward firms that can combine better distribution with stronger control of the infrastructure underneath it.

NCFA offers various curated resources to help founders and investors stay current on developments that impact fintech markets. Get the weekly Whisperer and related market intelligence through NCFA's newsletter, view the latest fintech insights, industry research, or launch into emerging financial innovation opportunities.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter