Queue item eight, and the seventh article this session. Item seven, video game and interactive digital media credits, gates at 4 against the film production article and was skipped rather than written thinly. This one gates clear and is the most genuinely current thing in the queue: the obligations came into force eleven months before we wrote and one of the consequences was still unresolved.

Key Takeaway

A payment service provider holding end-user funds must hold them in trust in a trust account, or in an account subject to insurance or a guarantee, segregated from all other funds in an account used for nothing else. Both comply. The trust route created an Income Tax Act problem the Bank of Canada flagged on the commencement date itself, and the Department of Finance's answer as at December 2025 was an intent to amend.

The Verdict, Stated First

Five claims, in descending order of confidence.

One. Since 8 September 2025 payment service providers must have established risk management and funds safeguarding frameworks. This is the Bank of Canada's own statement of its own supervisory regime.

Two. Safeguarding permits two methods and requires segregation under both. End-user funds must be held in trust in a trust account, or in an account where the funds are subject to insurance or a guarantee, and in either case segregated from all other funds in an account not used for any other purpose.

Three. The Bank flagged an Income Tax Act problem with the trust method on the commencement date. Its letter to industry of 8 September 2025 states that for PSPs retaining interest income on end-user funds held in trust there may be unintended tax consequences or administrative burden under the Income Tax Act, including issuance of tax slips to end-users.

Four. As at December 2025 the resolution was an intention. The Bank's follow-up letter records that the Department of Finance wrote stating its intent to amend the Income Tax Act to address the unintended consequences.

Five. On our own arithmetic interest on end-user float can be more than half of a PSP's operating profit. On an invented provider holding $40 million of average float at four percent, interest is $1,600,000 against $3,000,000 of operating profit, which is 53.3 percent of it. Least confident of the five because both the float and the fee base are our assumptions.

Our Grades For These Claims

We grade our own sourcing before anyone else has to.

Claims one, three and four come from the Bank of Canada directly, being its retail payments supervision pages and two letters to industry, one dated 8 September 2025 and one dated December 2025. For a question about what a supervisor requires and what it has said about a problem, the supervisor's own letters are the right source.

Claim two is sourced from law firm bulletins describing the Act, the Regulations and the Bank's final Safeguarding End-User Funds Guideline of 12 December 2024. We did NOT obtain the Act, the Regulations or the Guideline. Four independent firm descriptions agree on the substance, which is worth something and is not the same as reading it.

Claim five is arithmetic on invented figures. The $40 million of float, the four percent rate, the $6.8 million of fees and the $5.4 million of operating cost are ours.

The balance sheet argument in the middle of this article is ours and is reasoning. No source we found compares the two safeguarding methods in balance sheet terms. We think the comparison is obvious once both are described and we flag that as exactly the kind of thought that needs a warning label.

We did not obtain any accounting guidance. Not on trust arrangements, not on derecognition, not on the treatment of funds held for others [6]. We raise the question and deliberately do not answer it, for the same reason as in previous articles this session.

A Note On Method

What we obtained: the Bank of Canada's retail payments supervision pages; its letter to industry on the trust tax issue dated 8 September 2025; its follow-up letter of December 2025 recording the Department of Finance's response; and bulletins from four Canadian law firms describing the registration timeline, the two safeguarding methods, the segregation requirement, the written framework, senior officer obligations and the annual report.

What we did NOT obtain:

  • The Retail Payment Activities Act. Everything about what the statute requires reaches us through the Bank's description or a firm's.
  • The Retail Payment Activities Regulations.
  • The Bank's final Safeguarding End-User Funds Guideline of 12 December 2024, which is the operative document for what compliance actually looks like [5].
  • The Department of Finance letter stating its intent to amend. We have the Bank's account of it.
  • Any accounting guidance, and any real PSP's float, fee base, cost structure or safeguarding arrangement.
  • Any subsequent development. The December 2025 position was an intent to amend. Whether that amendment has since been made is something a reader must check and we could not.

That last gap is the important one. This article describes a problem whose resolution was pending at the date of the most recent source we found. It is entirely possible the Income Tax Act has since been amended and the difficulty we describe has been fixed.

A New Supervisor Arrived

Payment service providers in Canada were, until recently, largely unsupervised as such. They were subject to anti-money-laundering obligations, to consumer protection law, to card network rules and to contracts with their banking partners, but there was no prudential supervisor whose job was the payments activity itself.

The Retail Payment Activities Act changed that, and the Bank of Canada is the supervisor.

The obligations fall into three groups. Registration with the Bank, which is what brings a provider into the regime and onto a public registry. Operational risk management and incident response, which is a framework obligation with reporting attached. And safeguarding of end-user funds, which applies to providers that hold funds and is the subject of this article.

The Bank's own summary is that individuals and entities subject to the Act are required to register, must manage operational risks, respond to incidents, and protect end-user funds, and that as of 8 September 2025 providers must have established risk management and funds safeguarding frameworks and are required to submit an annual report [1].

For a business that has been holding customer money for years as a matter of commercial arrangement, the third obligation is the one that reaches the balance sheet.

The Dates

The sequence matters because it determines which financial year each obligation lands in and how long providers had to make an irreversible choice.

1 to 15 November 2024. The window for applications for registration. Not a period, a window: applications were to be made between those two dates.

12 December 2024. The Bank publishes its final Safeguarding End-User Funds Guideline, replacing a draft published in February 2024 [4].

1 November 2024 to 7 September 2025. The transition period, during which the Bank reviewed applications.

8 September 2025. The Bank's registration and registry obligations come into force, along with the remaining provisions on operational risk and end-user funds safeguarding. Providers must by this date have established both frameworks.

8 September 2025. The same day, the Bank writes to industry about the trust tax problem.

31 March 2026. The first annual report is due, relating to fiscal 2025.

December 2025. The Bank writes again to record that the Department of Finance intends to amend the Income Tax Act.

Note the compression. A provider had to decide how it would safeguard funds in order to complete a registration application in a fifteen-day window in November 2024, before the final Guideline existed, and the tax consequence of one of the two available methods was publicly raised by the supervisor on the day the obligation commenced.

Bound Before You Are Approved

One feature of the commencement is easy to miss and it caught a population nobody talks about.

The professional descriptions are specific about who the ongoing obligations bind. They apply to registered payment service providers and to parties that have applied for registration whose applications are in process [4].

So a provider that filed in the fifteen-day window in November 2024 and was still waiting for a decision on 8 September 2025 was nonetheless required, from that date, to have established a safeguarding framework and a risk management framework, and to have arranged its end-user funds in one of the two permitted ways.

That is a coherent design. A regime that only bit on approval would create an obvious incentive to keep an application pending. But it produces an unusual position for the business in it.

Ours. A pending applicant carries the full cost of compliance without the benefit of the registration. It cannot point to a registry entry when a banking partner asks. It does not know whether it will be registered. And if it is refused, it has restructured how it holds customer money, established frameworks, appointed a senior officer and incurred whatever guarantee cost it chose, in order to comply with a regime it turns out not to be in.

For an adviser the practical consequence is that the question is not whether the client is registered. It is whether the client is registered or has an application in process, because the obligations are identical either way and only the first produces a public record.

Two Ways To Comply

The Act gives a provider holding end-user funds two routes, and the descriptions are consistent across every source we read [4].

Method one: in trust in a trust account. The funds are held in trust, which on the Bank's own account requires the provider to establish an arrangement that forms a valid express trust.

Method two: in an account where the funds are subject to insurance or a guarantee. The protection comes from a third party standing behind the account rather than from the legal character of the holding.

Under both, the funds must be segregated from all other funds the provider holds.

The purpose is stated plainly in the professional commentary and is worth keeping in view throughout: the framework exists to protect end-user funds from receipt until withdrawal or transfer, to protect end-users from loss if the provider becomes insolvent, and to ensure end-users continue to have reliable and timely access to their funds.

So the objective is identical under both methods. An end-user is meant to be equally protected either way. What differs is not the protection. It is the legal character of the holding, and everything that follows from that.

The Account That Does Nothing Else

The segregation requirement deserves separating out because it is more demanding than it sounds and it constrains ordinary operations.

The requirement, on the descriptions we read, is that end-user funds be segregated from all other funds by using a safeguarding account not used for any other purpose.

Professional commentary makes the operational consequence explicit: to preserve the integrity of a trust arrangement, providers must avoid paying non-trust-related expenses from the trust account.

That is easy to state and awkward to run. A payments business moves money constantly, and the temptation to settle a fee, a chargeback, a network assessment or a partner payment out of the account where the money already sits is enormous, because that is where the money is.

Ours. Every improper payment out of a safeguarding account is a potential challenge to the arrangement's integrity, and the risk is not proportionate to the amount. A small operational convenience taken repeatedly is a better argument against the existence of a valid trust than a single large error would be, because it evidences a practice rather than a mistake.

This is the same structural point we found in the trust reconciliation article earlier in this programme, arriving from a completely different direction. A segregation rule is only as good as the discipline of the people with access to the account, and the failure mode is not theft. It is convenience.

What The Float Is Worth

Before the tax problem, it is worth establishing why anyone cares who owns the interest.

A provider holding end-user funds holds a float. Money sits between receipt and disbursement, and in aggregate the balance is persistent even though every individual dollar moves quickly. That float earns interest.

Ours, on an invented provider. Assume $40,000,000 of average end-user float.

  • At three percent: $1,200,000 a year
  • At four percent: $1,600,000
  • At five percent: $2,000,000

Now put it in context. Assume the same provider earns $6,800,000 in fees and has $5,400,000 of operating cost.

  • Total revenue including interest at four percent: $8,400,000
  • Operating profit: $3,000,000
  • Interest as a share of revenue: 19.0 percent
  • Interest as a share of operating profit: 53.3 percent
  • Operating profit without the interest: $1,400,000

More than half the profit comes from holding other people's money.

That is not a criticism. It is a description of how a great deal of the payments industry works, and it has always worked that way. What is new is that a federal statute now dictates the legal form in which that money must be held, and the legal form turns out to bear on who the interest belongs to.

The Problem The Bank Announced On The Day

On 8 September 2025, the date its supervisory mandate came into effect, the Bank of Canada published a letter to industry.

Its substance is this. The Bank and the Department of Finance had been made aware of possible unintended tax consequences for providers seeking to comply with the safeguarding requirements using the in-trust-in-a-trust-account method. To hold end-user funds in trust, a provider must establish an arrangement that forms a valid express trust. For providers retaining interest income on the end-user funds they hold, there may be unintended tax consequences or administrative burden under the Income Tax Act, including the issuance of tax slips to end-users [2].

Read the sequence again, because the timing is the story.

The obligation to safeguard came into force on 8 September 2025. Providers had chosen their method in order to complete registration applications in a fifteen-day window ten months earlier. And on the day the obligation commenced, the supervisor published a letter saying that one of the two available methods might have tax consequences nobody intended.

This is not a criticism of the Bank, which appears to have flagged the issue as soon as it was identified and to have engaged Finance about it. It is an observation about what it is like to be regulated by a new regime: the operational choice had to be made before the consequences of the choice were fully known, and there was no version of the timeline in which a provider could have waited.

What The Tax Problem Actually Is

The Bank's letter is short and does not set out the mechanism. What follows is our reading of what the difficulty must be, and it is reasoning rather than reporting.

If end-user funds are held in a valid express trust, then in law the beneficial ownership of those funds sits with the end-users. The provider holds them as trustee.

Income earned on trust property is, in the ordinary case, income of the trust rather than of the trustee. If the provider then retains that interest for itself, there is a question about what has happened: whether the income was the trust's and has been distributed to the trustee, whether it was the trust's and has been paid to someone not entitled, or whether the trust terms allocate it to the provider in the first place.

Each of those has a different tax answer, and at least one of them produces exactly the consequence the Bank names, which is the issuance of tax slips to end-users in respect of income allocated to them.

We want to be clear about the limits of that. We have not read the Income Tax Act provisions, we have not read the Act or the Guideline, and we did not obtain the Department of Finance letter. This is an inference about the shape of a problem from the regulator's one-paragraph description of it. A provider with money at stake needs a tax opinion, not a paragraph in an article.

What is not in doubt, because the Bank says it, is that the difficulty arises specifically for providers retaining interest income on funds held in trust. A provider that passes the interest to end-users does not have the problem. A provider that keeps it does.

The Fix That Is An Intention

In December 2025 the Bank published a follow-up. It records that, further to the September letter, the Department of Finance issued a letter to the Bank stating its intent to amend the Income Tax Act to address the unintended tax consequences for providers [3].

That is a helpful signal and it is not a change in the law.

A stated intent to amend tells a provider that the government agrees there is a problem and means to fix it. It does not tell the provider what the amendment will say, when it will be made, whether it will be retroactive to 8 September 2025, or what to do about the period in between.

Ours, and the practical point of this section. A provider that adopted the trust method has, on this record, an unresolved tax position for at least the period from September 2025 forward. Whether that produces an exposure, a filing obligation, an administrative burden or nothing at all depends on an amendment that had not been made as at the most recent source we could find.

We could not establish what has happened since December 2025 and a reader must check. It is entirely possible the amendment has been made and this section is historical. It is also possible it has not, in which case the position at the time of reading is the position we describe.

Either way the lesson for a fiscal year straddling this is the same. A tax position that depends on a promised amendment is a disclosure question at minimum, and treating it as resolved because the government said it would fix it is not the same as it being fixed.

Two Methods, Two Balance Sheets

Now the part we think has not been written down, and it is entirely our reasoning.

The two safeguarding methods are described as alternatives that achieve the same protective objective. In protection terms that appears to be true. In accounting terms they do not look like alternatives at all.

Under the trust method, the funds are trust property. The provider is trustee. There is a serious argument that trust property held for beneficiaries is not an asset of the trustee at all, and that neither the funds nor a corresponding liability belong on the provider's balance sheet.

Under the insurance or guarantee method, the funds sit in a segregated account, but the legal character of the holding is not a trust. It is an account, in the provider's name, with a third party standing behind it. That looks much more like an asset of the provider with a matching obligation to end-users.

If that is right, then two providers with identical businesses, identical float, identical end-users and identical protection can report balance sheets that differ by the entire amount of the float. On our invented provider that is $40,000,000.

Every ratio with total assets in it moves. Return on assets, leverage, any covenant measured against the balance sheet. The business is the same. The money is equally protected. The statements are unrecognisably different.

We did not obtain any accounting guidance and we are not answering this. Whether trust property is derecognised, and on what basis, is a question for the standards and for an auditor looking at the actual arrangement. We are raising it because the two methods are presented everywhere as equivalent compliance options, and on this dimension they may not be equivalent at all.

The Slips

The administrative burden the Bank names deserves a number, because administrative burden is easy to nod at and hard to picture.

If interest on trust funds is allocated to end-users, tax slips follow. Ours, on the same invented provider, across three plausible customer bases:

  • 5,000 end-users: 5,000 slips
  • 25,000 end-users: 25,000 slips
  • 120,000 end-users: 120,000 slips

Now consider what a slip requires that a payments platform may not hold. A name matched to a tax identity. A current mailing address or a consented electronic delivery channel. An allocation of interest to each end-user for the period their funds were held, which for a payments float means computing a daily balance per user across a year.

That last one is the real difficulty. A payments provider knows every transaction, but it may never have needed to compute a per-user average daily balance, because nothing in its business depended on one. The data exists in the sense that the transactions exist. It does not exist in the sense of being a field somebody can query.

Ours. The interest amounts per user would in most cases be trivial. On $1,600,000 across 120,000 users the average is about $13. The cost of computing, producing and delivering a slip is not proportionate to $13, which is precisely why the Bank described this as an unintended consequence rather than a policy outcome. Nobody designed a regime intended to send 120,000 people a slip for thirteen dollars.

What The Other Route Costs

If the trust route carries a tax problem, the obvious response is the other route. That has a price and it is worth putting a range on it.

The insurance or guarantee method requires a third party to stand behind the account. Third parties charge for that.

Ours, on $40,000,000 of float, at rates we have assumed rather than sourced:

  • 10 basis points: $40,000 a year, being 1.3 percent of our invented provider's operating profit
  • 25 basis points: $100,000, being 3.3 percent
  • 50 basis points: $200,000, being 6.7 percent

We did not source a single guarantee rate and the range above is our guess at a plausible band. A provider pricing this needs a quote, not our arithmetic. What the arithmetic does show is the order of magnitude: a few percent of operating profit, not a few tens of percent.

Set that against the alternative. The trust route costs nothing in premium and carries an unresolved tax position plus, on the worst reading, an obligation to allocate interest and issue slips. The guarantee route costs a measurable annual amount and, on our reading, leaves the funds looking like the provider's asset with a matching liability, which changes the balance sheet but raises no obvious income tax question about who owns the interest.

So the choice, framed commercially, is between a known annual cost and an unresolved tax position. Reasonable providers will answer that differently, and a provider that chose the trust route in 2024 because it was free made a decision on facts that were incomplete through no fault of its own.

What This Is Actually For

It is worth stepping back from the mechanics to what the requirement is protecting, because that is the test every arrangement should be read against.

The purpose of the safeguarding framework, on the professional descriptions we read, is to protect end-user funds from the moment they are received until they are withdrawn or transferred, to protect end-users from financial loss if the provider becomes insolvent, and to ensure end-users continue to have reliable and timely access to their funds [4].

Note that there are two distinct protections in that sentence and they are not the same.

Protection from loss. If the provider fails, the money is not available to the provider's general creditors.

Continued timely access. If the provider fails, end-users can still get at their money, promptly.

The second is harder than the first and is the one an arrangement is most likely to fail on. Money can be perfectly protected in law and completely inaccessible in practice, because the people who knew how to operate the account are gone, the reconciliation that identifies whose money is whose lived in a system nobody is paying for, and the institution holding the account has frozen it pending instructions from someone with authority.

Ours. A safeguarding framework that establishes the legal character of the holding and does not establish who computes the per-user entitlement, from what records, on whose authority, after the provider has failed, has done the easier half of the job. The per-user allocation problem that makes tax slips difficult is the same problem that makes an insolvency payout difficult, and it has the same solution.

The Registry Is A Commercial Document

Among the provisions that came into force on 8 September 2025 was the Bank's requirement to register providers and publish a registry of them [4].

A public registry is usually treated as a supervisory housekeeping matter. In this industry it is not, and the reason is who reads it.

Payment service providers do not exist in isolation. They depend on banking partners for accounts, on card networks and acquirers for access, on platform customers who embed them, and on enterprise clients whose own procurement functions ask questions. Every one of those relationships involves a counterparty assessing whether the provider is a legitimate, supervised business.

Before the registry, that assessment was made from whatever the provider chose to disclose. After it, there is a list, published by the Bank of Canada, and a provider is on it or is not.

Ours, and stated as commercial reasoning rather than as anything the Act says. Three consequences follow.

Absence becomes evidence. A provider not on the registry now has to explain why, and the explanations divide into being out of scope, having an application in process, or having been refused. Only the first two are comfortable.

It is a procurement filter. Any counterparty can check in seconds, which means the check will be added to onboarding questionnaires whether or not anyone thought hard about it.

It changes what registration is worth. A compliance obligation that produces a public credential is not purely a cost. For a provider competing against unregistered or offshore alternatives, the registry entry is the only third-party verification of legitimacy it has ever been able to point at.

None of that appears in a compliance budget, and on our reading it is the one part of this regime that a provider might reasonably describe as an asset rather than an expense.

The Framework, And Who Signs For It

Two further obligations are worth recording because they attach responsibility to named people.

The written framework. A provider holding end-user funds must establish, implement and maintain a framework describing the systems, policies, processes, procedures, controls and other means by which it meets the objective of protecting those funds. There is a parallel obligation for operational risk and incident response, with requirements to internally review and test the framework, establish roles and responsibilities, and identify risks in annual reports.

The senior officer. Senior officers are responsible for overseeing the provider's practices and ensuring they comply. Professional commentary records the Bank's view that a senior officer need not be a direct employee of the provider, nor located in Canada, so long as they meet the regulatory definition, which extends to officers who are not direct employees but report directly to the board, the chief executive or the chief operating officer.

That flexibility is practically useful for foreign-owned providers and it has a consequence worth naming. If the person responsible for oversight is not an employee and is not in Canada, the arrangement that makes them responsible is a contract and a reporting line, and both need to be real. A title conferred to satisfy a definition does not produce oversight.

For an auditor or an adviser the practical question is short: who is the senior officer, what do they actually see, and how often. If the answer to the second question is a quarterly summary prepared by the people being overseen, the framework has a gap that no document will close.

The First Annual Report

The reporting obligation completes the regime and the first one has already fallen due.

Providers are required to submit an annual report. On the professional descriptions, the first report relates to fiscal year 2025 and was due by 31 March 2026, and it must include information about the provider's accounts, insurance and guarantees, its holding of end-user funds, and its risk management and incident response framework, together with descriptions of changes made during the year, the human and financial resources available for implementing and maintaining the framework, and the provider's operational position.

Two observations, ours.

The report asks about resources. A requirement to describe the human and financial resources available for maintaining a framework is a requirement to state, in writing, to a supervisor, how much a provider is actually spending on compliance. That is a different kind of disclosure from describing a policy, and it is harder to answer well while spending very little.

The first report covers a year in which the rules changed mid-stream. Fiscal 2025 contains a period before 8 September when the obligations were not in force and a period after when they were. Any description of the year has to handle that, and any comparative next year will be against a part-year.

For an adviser the useful question is whether the client's fiscal 2025 report was prepared from records that existed at the time or reconstructed afterwards. The second is common in a first year of any regime and it is worth knowing which it was before relying on the report as evidence of anything.

If You Run A Payment Service Provider

Five things, in the order we would look at them.

Establish which safeguarding method you actually use, and whether the documentation supports it. If you hold in trust, there must be a valid express trust. A ledger labelled trust is not a trust.

Find out whether you retain the interest. On the Bank's own description the tax difficulty arises specifically for providers retaining interest income on funds held in trust. If you pass it through, this is not your problem. If you keep it, it is.

Check whether the promised Income Tax Act amendment has been made. As at December 2025 it was an intention. That may have changed and you should not rely on our account of a moving position.

Audit what comes out of the safeguarding account. Non-trust expenses paid from a trust account are the most likely challenge to the integrity of the arrangement, and the risk is behavioural rather than financial.

Work out whether you could compute a per-user entitlement tomorrow. You need it for tax slips on one reading, and you need it in an insolvency on every reading. If the answer is that it would take weeks, that is the finding.

If You Advise One

Four checks we would run on any payment service provider engagement.

How the float appears in the financial statements, and on what basis. If funds are on balance sheet, why. If they are off, why. The answer should reference the actual legal arrangement rather than what the previous year did.

What proportion of profit is interest on end-user funds. On our invented provider it is 53.3 percent. If it is a large share for your client, then the safeguarding method is not a compliance topic, it is the business model.

Whether there is a tax position or a disclosure for the trust issue. A provider using the trust method and retaining interest has, on the record we found, an unresolved position from September 2025.

Whether the fiscal 2025 annual report was built from contemporaneous records. First-year reports under new regimes are frequently reconstructed, and a reconstructed report is weaker evidence than it looks.

And one thing to resist. Do not treat the two safeguarding methods as interchangeable because the regulator presents them as alternatives. They are alternatives for the protective purpose. On our reading they may not be alternatives for the balance sheet or for tax, and nobody has written that down.

What To Do

If you take one thing from this article, take the divergence. Two lawful ways to safeguard the same money, offering the end-user the same protection, and on our reading producing different balance sheets and different tax. That is not how compliance alternatives are usually described and it is worth checking which one you are on.

If you take two, take the timing. The obligation commenced on 8 September 2025 and the supervisor raised a tax problem with one of the methods on the same day. As at December 2025 the answer was an intention to amend. A provider that chose in November 2024 chose without that information.

If you are advising a payment service provider this quarter, the highest-value single question is whether the provider retains interest on end-user funds and holds them in trust. If both are true, there is an unresolved position that needs looking at rather than assuming.

The Limits Of This Analysis

Long and specific, because a limits section that is short is decoration.

We did not read the Act, the Regulations, or the Guideline. Everything about what the regime requires reaches us through the Bank's summaries and four law firm bulletins. Four independent descriptions agreeing is real corroboration and it is not the same as reading the instrument.

The position is moving and our most recent source is December 2025. The Income Tax Act amendment was an intention at that date. It may have been made since. The whole of our trust tax discussion could be historical by the time it is read.

The tax mechanism is our inference. The Bank's letter names the consequence and not the mechanism. Our account of why trust income might be allocated to end-users is reasoning from general principles, and we did not read the relevant Income Tax Act provisions.

The balance sheet argument is entirely ours and is unsupported. No source we found compares the two methods in accounting terms, and we obtained no accounting guidance. It may be that both methods produce the same treatment for reasons we have not considered.

Every number about the provider is invented. The $40 million float, the four percent rate, the $6.8 million of fees, the $5.4 million of operating cost and the customer counts. The striking figure, interest at 53.3 percent of operating profit, is a direct consequence of choosing those inputs.

The guarantee cost range is a guess. We sourced no rate at all. The 10 to 50 basis point band is our assumption of what is plausible and should not be used for anything.

We do not know how common each method is. Our framing assumes meaningful numbers of providers chose the trust route, which is why the Bank wrote about it, but we found no data on the split.

Scope of the regime is still not addressed. Who is and is not a payment service provider under the Act is a substantial question with exclusions and edge cases, and we have written as though a reader already knows they are in scope. We added a section on pending applicants, which is about when the obligations bite rather than on whom, and does not close this gap.

The registry section is commercial reasoning, not law. That absence from a public registry functions as a procurement signal is our inference about how counterparties will behave. We have no evidence that any bank, network or platform has in fact added the check.

Nothing here is tax advice or legal advice, and the one thing we would most want a reader to take away is that a provider with money at stake needs an opinion rather than an article.

Frequently Asked Questions

When did the RPAA safeguarding obligations come into force?
8 September 2025. On the Bank of Canada's own statement, as of that date payment service providers must have established risk management and funds safeguarding frameworks and are required to submit an annual report. Registration applications had been due between 1 and 15 November 2024.
What are the two ways to safeguard end-user funds?
Holding them in trust in a trust account, or holding them in an account where the funds are subject to insurance or a guarantee. Under both, the funds must be segregated from all other funds in a safeguarding account not used for any other purpose.
What is the trust tax problem?
The Bank of Canada wrote to industry on 8 September 2025 saying that for providers retaining interest income on end-user funds held in trust there may be unintended tax consequences or administrative burden under the Income Tax Act, including issuing tax slips to end-users. Holding in trust requires a valid express trust arrangement.
Has the tax problem been fixed?
As at the Bank's December 2025 letter, the Department of Finance had stated its intent to amend the Income Tax Act. An intent to amend is not an amendment, and we could not establish what has happened since. A reader should check the current position rather than rely on ours.
Does the choice of method affect the financial statements?
On our own reading, potentially by the entire amount of the float, because trust property held for beneficiaries and a segregated account in the provider's own name are different things. No source we found makes this comparison and we obtained no accounting guidance, so treat it as a question to raise rather than an answer.
How much is the float actually worth?
On an invented provider holding $40 million of average end-user float at four percent, interest is $1,600,000 a year, which is 19.0 percent of revenue and 53.3 percent of operating profit. For many providers the safeguarding method is not a compliance topic, it is the business model.
Who is responsible for compliance inside the business?
Senior officers oversee the provider's practices and ensure compliance. Professional commentary records the Bank's view that a senior officer need not be a direct employee or be located in Canada, provided they meet the regulatory definition, which extends to officers reporting directly to the board, chief executive or chief operating officer.

References

  1. Bank of Canada, retail payments supervision pages. Source of the statement that individuals and entities subject to the Retail Payment Activities Act are required to register with the Bank and must manage operational risks, respond to incidents and protect end-user funds, and that as of 8 September 2025 payment service providers must have established risk management and funds safeguarding frameworks and are required to submit an annual report. Note: the supervisor describing its own regime, which is the right source for what is required and is not the statute. Bank of Canada
  2. Bank of Canada, letter to industry on the trust tax issue, 8 September 2025. Source of the statements that the Bank's mandate to supervise payment service providers under the RPAA is in effect as of that date including obligations related to operational risk and end-user funds safeguarding; that the Bank and the Department of Finance had been made aware of possible unintended tax consequences for providers seeking to comply using the in-trust-in-a-trust-account method; that holding end-user funds in trust requires establishing an arrangement that forms a valid express trust; and that for providers retaining interest income on end-user funds there may be unintended tax consequences or administrative burden under the Income Tax Act, such as issuance of tax slips to end-users. Note: primary, from the regulator, dated the same day the obligation commenced. The load-bearing source for this article. Bank of Canada
  3. Bank of Canada, letter to industry updating on the trust tax issue, December 2025. Source of the statement that further to the September letter, the Department of Finance issued a letter to the Bank stating its intent to amend the Income Tax Act to address the unintended tax consequences for providers. Note: primary as to the fact that Finance stated an intent. We did NOT obtain the Finance letter itself, and this is the most recent source we found on a position that was still open at that date. Bank of Canada
  4. Bulletins from four Canadian law firms on the Retail Payment Activities Act and Regulations, used for the registration window of 1 to 15 November 2024, the transition period to 7 September 2025, publication of the final Safeguarding End-User Funds Guideline on 12 December 2024 replacing a February 2024 draft, the two safeguarding methods, the requirement to segregate end-user funds in a safeguarding account not used for any other purpose, the requirement for a written safeguarding framework and a risk management and incident response framework, the stated purpose of protecting funds from receipt to withdrawal and protecting end-users on insolvency while preserving timely access, the caution against paying non-trust-related expenses from a trust account, the senior officer definition and the Bank's view that a senior officer need not be an employee or be in Canada, and the annual report obligation with the first report relating to fiscal 2025 and due 31 March 2026. Note: secondary, but four independent firms describing the same regime and agreeing on substance. Used because we did not obtain the primary instruments.
  5. The Retail Payment Activities Act, the Retail Payment Activities Regulations, and the Bank of Canada's final Safeguarding End-User Funds Guideline of 12 December 2024 were NOT obtained for this article. Note: recorded as a reference deliberately, so the absence appears on the list rather than being buried. The Guideline in particular is the operative document for what compliance actually looks like, and every statement we make about the requirements should be checked against it by someone who has it open.
  6. No accounting guidance was consulted for this article, on trust arrangements, derecognition, or the treatment of funds held on behalf of others. Note: recorded as an absence for the same reason. The balance sheet comparison in this article is our own reasoning and rests on no standard.