- Home
- »
- Services
- »
- PSP Registration
- »
- PSP Risk Assessment
PSP Operational Risk Assessment and Framework
Every registered PSP must maintain a written operational risk and incident response framework. We build yours around your actual systems, third parties, and failure points, then keep it ready for Bank of Canada scrutiny.
Operational Risk Under the RPAA Framework
Since September 2025, every registered PSP must document how it identifies, escalates, reports, and remediates operational risk. The Bank of Canada expects your framework to address cybersecurity, fraud, and third-party dependencies, alongside the reliability targets that your systems and your service are genuinely held to.
Different From Your AML Assessment
These are two separate obligations. FINTRAC requires a money laundering and terrorist financing risk assessment, while the Bank of Canada requires an operational risk framework covering system failures, incidents, and service outages. Most PSPs need both, and confusing them leaves a gap that examiners find quickly. We build each one properly.
Risk Framework
We write your operational risk framework to Bank of Canada guideline expectations.
Incident Response
We build escalation and remediation procedures that meet the forty-eight hour notification rule.
Third-Party Risk
We assess your outsourcing arrangements and the dependencies that could disrupt your service.
Framework Testing
We test your controls and reliability targets so the framework holds under real scrutiny.
Ready to Simplify Your Compliance?
PSPs We Help Assess
We support payment processors, digital wallets, remittance operators, gateways, and foreign PSPs registered in Canada. Every framework reflects the systems you run, the partners you depend on, and the incidents you could realistically face.
We support banks with program design, oversight, & regulatory examination readiness.
We help credit unions meet obligations proportionate to their membership and scale.
We handle registration, renewals, reporting, & controls FINTRAC expects from you.
We cover Bank of Canada registration alongside your anti money laundering obligations.
We establish what your wallet activity triggers, then build only what applies.
We build compliance around what your product does, before volumes and questions arrive.
We register virtual currency dealers and build the reporting their activity demands.
We support financial institutions across registration, program build, and reporting duties.
Why PSPs Trust Our Risk Work
Both Regimes
We build your operational risk framework and your AML risk assessment together, so neither regulator finds a gap.
Evidenced Resources
The Bank asks what people and budget you commit to risk, so we document those resources rather than implying them.
Report Ready
Your annual report demands detail on framework efficacy, and we build the evidence trail as we go, not afterwards.
Serving PSPs Across Canada
We support payment service providers nationwide, from Toronto and Montreal to Vancouver and Calgary, and we also assist foreign PSPs meeting Bank of Canada risk expectations wherever they happen to operate.
Let's Talk About Your Compliance Needs
Schedule a Free Consultation
Whether you’re starting a new MSB or need ongoing AML support, our team responds within one business day.














PSP Risk Assessment Questions
Clear answers to the questions payment service providers ask most about operational risk frameworks, incident response, and risk obligations under the RPAA.
What must the risk framework cover?
How you identify, escalate, report, and remediate operational risk, including cybersecurity, fraud, third-party dependencies, and your reliability targets for system availability.
Is this the same as AML risk?
No. Operational risk is a Bank of Canada requirement about system failures. AML risk assessment is a separate FINTRAC obligation about money laundering exposure.
How quickly must incidents be reported?
Initial notice must be given without delay, and no later than forty-eight hours after you determine an incident has a material impact.
Can we use our parent framework?
Yes, provided it meets the expectations set out in the RPAA, the regulations, and the Bank of Canada operational risk guideline.
Does the framework need testing?
Yes. The Bank expects evidence your framework works, and your annual report must disclose its efficacy, oversight, and the resources committed to it.











