Canada Gazette, Part I, Volume 160, Number 26: Regulations Amending the Financial Consumer Protection Framework Regulations

June 27, 2026

Statutory authority
Bank Act

Sponsoring department
Department of Finance

REGULATORY IMPACT ANALYSIS STATEMENT

(This statement is not part of the Regulations.)

Executive summary

Issues: Consumer-targeted fraud is increasing rapidly in Canada, with estimated losses totalling $704 million in 2025; however this is an under-representation, as it is likely to only represent 5 to 10 per cent of actual fraud losses. Bank-offered personal deposit accounts often have default features, such as wire and international money transfer, which permit online banking transactions with values as high as $50,000. If an account is accessed in an unauthorized manner, the consequences can be severe for a consumer. Additionally, without accurate data, it is difficult for policy-makers to estimate the true magnitude of fraud losses and to implement effective measures to protect consumers. The proposed Regulations are necessary to operationalize legislative amendments to the Bank Act introduced through the Budget Implementation Act, 2025, No. 1.

Description: The proposed Regulations Amending the Financial Consumer Protection Framework Regulations (proposed Regulations) would require banks to

  • obtain express consent from consumers before enabling electronic funds transfer capability associated with their personal deposit accounts — including wire transfers, global money transfers, and Interac e-Transfers — only after informing them of the nature and potential uses of those capabilities;
  • allow consumers to disable those same electronic funds transfers;
  • implement requests to increase a transaction limit without delay, if they have validated the consumer’s identity, or the following business day, if they have not verified the consumer’s identity;
  • have policies and procedures for how it would investigate suspicious transactions and for notifying consumers of suspicious requests to enable capabilities or increase transaction limits;
  • collect and report certain data points on fraud instances, including the scheme type and transaction method used to defraud the consumer, and report that data to the Financial Consumer Agency of Canada (FCAC), which will compile the information and provide a report to the Minister of Finance; and
  • disclose to consumers, upon account opening, that certain account capabilities require express consent to enable and can be disabled, and that transaction limits may be adjusted.

Rationale: The proposed Regulations would mitigate harms caused by consumer-targeted fraud by requiring banks to allow consumers to disable account capabilities that they do not use and obtain express consent from consumers before enabling certain account capabilities. These capabilities can be used by fraudsters to steal consumers’ funds when they succeed in gaining illicit access to personal deposit accounts. The proposed Regulations would provide protections to consumers in the event that their account is compromised, by making it harder for fraudsters to initiate certain high-value transactions. Additionally, to ensure the Department of Finance has access to timely, relevant data on consumer-targeted fraud for the purposes of policy development, the proposed Regulations would prescribe the specific fraud-related data points banks would be required to report to the Financial Consumer Agency of Canada. This will enable the government to better understand how fraud is impacting consumers, including prevalent fraud scheme types, execution methods, contact methods, as well as how fraudulent payments are made, and ultimately inform future policy development.

Issues

Consumer-targeted fraud, where a consumer has been defrauded through a transaction that they have not authorized or have authorized as a result of coercion or deception, has been rising rapidly in Canada since 2018. This problem has been exacerbated by advances in artificial intelligence (AI), which make it easier for fraudsters to use sophisticated techniques, such as deepfake videos or AI-generated phone calls, to defraud Canadians. In some cases, a consumer may not know they have been defrauded until it is too late.

Consumer-targeted fraud is a foreseeable risk associated with bank-enabled payment features, including Interac e-Transfers, wire transfers and global money transfers. To address the growing rate of fraud, stronger and more consistent institutional safeguards are required.

There are currently limited mechanisms in place to protect consumers from fraud. While there are limited consumer liability rules in place with respect to unauthorized transactions made using debit and credit cards, consumers are generally offered little control over the payment features associated with their deposit accounts (e.g. Interac e-Transfers, wire transfers, global money transfers, etc.), nor can they adjust the transaction limits on these features to protect themselves in the event a fraudster gains access to their accounts. These features are often enabled by default on bank-offered personal deposit accounts, and because many consumers do not have a need to use these features and, therefore, may not be fully aware that these transaction methods are available to them and could be used to defraud them.

While fraud is rising, the true cost of fraud losses is unclear, as consumers are often reluctant to report fraud to law enforcement and banks are not required to report on their behalf. Fraud reporting by banks is currently only narrowly captured by the requirement to report complaint data to the FCAC. This reporting would only capture fraud cases where the consumer made and escalated a complaint against their financial institution. Some consumers may choose to report instances of fraud to law enforcement; however, this data is either not collected or not available to policy-makers.

While the Financial Consumer Agency of Canada (FCAC) has authority to request information from banks for the purposes of furthering its mandate and for the purposes of monitoring compliance with market conduct obligations, there is no current market conduct requirement for banks to report this information to the FCAC. Generally, any data reported to law enforcement is confidential and not available to policy-makers. While the Canadian Anti-Fraud Centre (CAFC), a national police service operated by the RCMP, receives fraud reporting from the public, conducts analysis and issues public reports, it estimates that only 5 to 10 per cent of fraud is reported. The absence of reliable and comprehensive data reported directly by banks has presented challenges for informed policy making.

As a result, the government cannot accurately estimate the true magnitude of fraud in Canada, nor can it compare year-over-year data to examine how fraud trends are evolving. Without accurate fraud data, it is difficult for policy-makers to develop and implement effective measures to protect consumers from fraud.

These proposed Regulations are required to operationalize legislative amendments announced in Budget 2025 and passed through the Budget Implementation Act, 2025, No. 1. The legislative amendments are not yet in force but will impose requirements on banks to address consumer-targeted fraud.

Background

In 2025, Canadians reported losses totalling $704 million to the CAFC, a nearly 300 per cent increase over reported losses in 2020. These values likely represent a significant underestimation of total losses to fraud, given victims’ reluctance to report the crime. The CAFC estimates that only 5 to 10 per cent of fraud is reported.

Multi-sectoral nature of fraud

The nature and scale of consumer-targeted fraud are rapidly evolving, with fraudsters able to easily leverage technological advances to deceive consumers into compromising their personal financial information in new and increasingly complex ways. Fraudsters employ telecommunications and other digital infrastructure to identify and contact potential victims through scam texts, calls, emails and social media content. Low-cost barriers to accessing advanced generative artificial intelligence technology permit fraudsters to create increasingly convincing and compelling scams, through false representations about the true identities of the parties seeking to defraud consumers or the nature of services on offer, including false investment offers. Exacerbating the problem, broad availability of advanced account-based large-value transaction methods, such as wire transfers and international money transfers, permits fraudulent payments to be made quickly when fraudsters gain access to personal deposit accounts.

Current framework

Under the current financial sector legislative framework, the sole fraud-related consumer protection requirement for banks is related to unauthorized credit card transactions. In the event a consumer’s credit card or credit card credentials are used in an unauthorized manner, the consumer’s liability is limited to $50, unless the consumer has been grossly negligent in protecting their card, their account information or their personal authentication information. In practice, however, all major credit card issuers offer cardholders zero liability for unauthorized transactions. This means that consumers are not held liable for transactions made using their credit cards that they did not authorize. This would include instances where a consumer’s credit card or credentials are stolen and used to make payments.

Similarly, most banks have signed on to the voluntary Canadian Code of Practice for Consumer Debit Card Services, which requires that consumers not be held liable for losses resulting from circumstances beyond their control, such as if they are a victim of fraud or theft, or have been coerced by trickery, force, or intimidation into making a debit card payment.

Banks may hold consumers fully liable for all other fraudulent transactions made from their account, including unauthorized Interac e-Transfers, wire transfers, and global money transfers made by a fraudster who has gained access to their account. Consumers are also held liable for fraudulent transactions that have been authorized by the consumer as a result of coercion or deception such as

To address the multi-sectoral nature of fraud, the government announced in Budget 2025 that it will develop a National Anti-Fraud Strategy to bring together financial institutions, technology, and telecommunications companies to develop a cross-sectoral approach to combat fraud.

Legislative amendments

The Budget Implementation Act, 2025, No. 1 introduced amendments to the Bank Act to combat consumer-targeted fraud. Once the relevant provisions are in force, these amendments will require banks to have policies and procedures to address consumer-targeted fraud, allow consumers to adjust maximum transaction amounts, obtain express consent to enable certain prescribed account capabilities, allow consumers to disable certain account features, and require banks to collect and report prescribed fraud data to the Commissioner of the FCAC.

These regulations would provide more specificity to support these legislative amendments, such as prescribing additional policies and procedures banks would need to have, the account capabilities that banks must allow consumers to enable and disable, how banks must obtain express consent before enabling these capabilities, when banks must enable transaction limit increases requested by consumers, and the specific data points banks will need to collect and report to the FCAC with respect to consumer-targeted fraud. The intention is for the consumer-targeted fraud legislative amendments to come into force on the same day as the proposed Regulations.

Objective

The objective is to ensure banks’ systems manage consumer access to personal deposit account features in a manner that permits consumers to make informed decisions when choosing the capabilities available to them and allowing consumers to adjust these features to protect themselves from fraud. Additionally, the regulations would ensure the government has access to timely, accurate data about consumer-targeted fraud in Canada, better positioning the government to make informed policy decisions.

Description

The proposed Regulations would be made subsequent to legislative amendments to the Bank Act which introduce a definition of “consumer-targeted fraud.” The proposed Regulations would apply to all institutions as defined as “banks and authorized foreign banks” under the Bank Act.

Account capabilities

The proposed Regulations would require banks to obtain express consent from consumers before enabling any capability that allows for the electronic transfer of funds, including wire transfers, global money transfers, and Interac e-Transfers. Transfers between two accounts with the same institution that are owned by the same individual, automatic teller machine withdrawals, any payments made using payment card credentials (e.g. a debit card or prepaid card), pre-authorized debits, and direct bill payments would be exempt from this requirement.

The proposed Regulations would specify that banks must provide the individual with information about the nature and potential uses of the capabilities, and must implement measures to validate the identity of the account holder before enabling these capabilities. The proposed Regulations would not specify the contact method through which banks must obtain express consent.

The proposed Regulations would also require banks to allow consumers to disable these same account capabilities and to disclose, upon account opening, the fact that consumers have these options available to them.

Banks would not be required to obtain express consent for capabilities that are already enabled for existing accounts at the time the proposed Regulations come into force.

Withdrawal and transfer limit implementation periods

The proposed Regulations set out the periods over which banks must enable requests to increase transaction limits. Banks would have to enable the increased limit without delay, if the bank has verified that the person making a request to increase a limit is the genuine account holder. This would ensure that legitimate requests made by the account holder are not needlessly delayed, allowing consumers to easily adjust their transaction limits if they need to make a transaction that exceeds their limit.

In the event the bank has not verified the requester’s identity, the limit increase would take effect the following business day. This would ensure that banks do not instantly enable a transaction limit increase if it cannot verify that the account holder is making the request. In the event a fraudster gains access to a consumer’s account and attempts to increase a transaction limit, this requirement would frustrate their ability to immediately maximize theft of the consumer’s funds. The Bank Act requires banks to notify consumers if their limits are adjusted, which would permit consumers to notify their bank if a limit is adjusted that they did not request.

Policies and procedures

The proposed Regulations would require banks to include in their policies and procedures criteria they use to investigate transactions they had deemed to be suspicious and the criteria they use to determine whether to notify an account holder of a suspicious request to increase a transaction limit or enable an account capability. The proposed Regulations would also require banks to review their policies and procedures at least annually.

These requirements would supplement other Bank Act requirements with respect to banks’ policies and procedures for detecting and preventing consumer-targeted fraud and mitigating its impacts.

Data collection and reporting

The proposed Regulations would require banks to report to FCAC data on the fraud instances that impact their customers, whether confirmed by the bank or merely alleged by the consumer. For each instance of fraud, banks would be required to report the following information:

The proposed Regulations would require banks to report this information annually to the Commissioner of the FCAC, in a form satisfactory to the Commissioner, along with information regarding the steps they have taken to implement and adhere to the policies and procedures referred to in the Bank Act and any training provided to employees related to consumer-targeted fraud. Banks would also need to report information regarding their internal fraud reduction targets, if any exist. To ensure the report is in a form satisfactory to the Commissioner, banks would need to align with the Commissioner’s expectations on how the data is reported (e.g. through FCAC’s information portal), and the drop-down menus associated with each data point.

The report would cover data from the entire calendar year, from January 1 to December 31, and need to be submitted to the Commissioner within 135 days of the end of the calendar year. This aligns with the timeline to make the complaints handling report available to the public, as required by the Bank Act.

The proposed Regulations would also require FCAC to submit a confidential annual report to the Minister of Finance compiling information received in the fraud reports FCAC received from banks. The report prepared by the FCAC would have to be submitted by September 30 of the year immediately following the year covered by the banks’ reports. Requiring the Commissioner to submit this report to the Minister by September 30 would ensure the FCAC has sufficient time following receiving the annual reports from the banks to compile its annual report.

While there would be a delay between data being collected by banks and it being reported to the Minister of Finance, this would represent a significant improvement in access to data by policymakers. Currently, there is limited reliable and comprehensive data available on fraud incidents and much of this data relies on voluntary reporting to the CAFC, which CAFC estimates represents only 5 to 10% of all fraud cases. By collecting data directly from banks, the government would be better able to understand the magnitude of fraud in Canada. Banks will need a reasonable period of time to compile the various required data points following the end of the calendar year. Likewise, the FCAC will require time to compile and analyze the data it receives from banks before submitting its report to the Minister.

Account opening disclosure

The proposed Regulations would amend the existing section of the Financial Consumer Protection Framework Regulations that prescribes information that banks must disclose to consumers upon account opening. The proposed Regulations would require banks to disclose to consumers the account capabilities that require express consent to enable, the account capabilities that can be disabled, and the account capabilities for which the transaction or withdrawal limit may be increased or decreased. This would ensure that consumers are aware of the fraud protection measures available to them when they open a personal deposit account.

Regulatory development

Consultation

The Department conducted three rounds of public consultations in association with the legislative review of the financial sector statutes.

The initial consultation (which ran from October 5 to December 4, 2023) solicited stakeholder feedback on potential additional protections to ensure Canadians receive high-quality, low-cost banking services, and easy access to banking services, including cost barriers. The feedback received informed the development of a subsequent consultation, which ran between August 12 and September 11, 2024.

The second consultation sought stakeholder feedback on specific measures to address fraud, including requiring banks to

The Department received feedback from 22 organizations representing consumer groups, industry members, and other provincial and federal government organizations.

Feedback to this consultation was mixed. Consumer groups were highly supportive of all proposed measures. Industry groups representing banks and other financial institutions, however, were not supportive of the proposed measures and instead urged the government to consider a voluntary approach to addressing fraud that would allow banks to decide which anti-fraud measures to implement within their own institution. These industry groups also pointed to the newly formed Canadian Anti-Scam Coalition (CASC), a multi-sectoral working group which at that point was led by the Canadian Bankers Association (CBA), which aimed to combat fraud against Canadians, as an example of the industry’s voluntary work to address fraud. While the voluntary work conducted by the CASC is a positive development, it was determined that voluntary measures would not be adequate to protect consumers from fraud.

Following the consultation, the Department held follow-up meetings with nine organizations, including consumer groups and trade associations representing banks and financial institutions, to discuss their comments.

Separately, following the Budget 2025 announcement of the legislative amendments that would introduce new requirements to combat fraud, the Department held informal and targeted engagement with consumer and industry stakeholders that had previously provided comments throughout the legislative review consultations.

This consultation sought feedback on the proposed Regulations, including which account features should banks be required to obtain express consent before enabling and allow consumers to disable, how banks should be required to obtain the express consent of account holders before enabling capabilities, if any additional adjustable transaction limits should be prescribed, the time period for banks to enable any account holder-requested adjustments to withdrawal or transfer limits, whether any additional criteria should be prescribed for inclusion in banks’ policies and procedures for detecting and preventing consumer-targeted fraud, the fraud-related data points banks will be required to report to FCAC, and information banks would have to disclose to consumers opening a personal deposit account about the fraud-related features associated with their accounts.

The Department received feedback from 10 organizations during this consultation period, including consumer advisory groups, industry trade associations, and government regulators. Consumer groups are generally supportive of the proposed regulations, especially those requiring banks to allow consumers to adjust certain account capabilities and disclose to consumers upon account opening that certain account capabilities may be adjusted. Consumer groups are also supportive of the Department’s proposed list of account capabilities that would be subject to these requirements.

Industry association groups representing banks and financial institutions were not supportive of additional requirements to be prescribed in regulations, as they were of the view that the legislative amendments, along with practices banks already employ, would be sufficient to prevent fraud. While banks do take steps to prevent fraud, such as implementing two-factor authentication for certain transactions and engaging in consumer awareness, these measures do not go far enough to prevent fraud, as evidenced by rising fraud losses.

The Department did not agree that the legislative amendments would provide sufficient protection against consumer-targeted fraud and as such, is proceeding with developing these proposed Regulations to prescribe additional requirements. However, these industry groups were supportive of updating account opening disclosure requirements to align with the new requirements introduced in the legislation and proposed regulations. Industry groups also expressed their desire for any time periods to be expressed in business days rather than hours.

Indigenous engagement, consultation and modern treaty obligations

Following the completion of the assessment of modern treaty implications, no adverse impacts on potential or established Indigenous or treaty rights, which are recognized and affirmed in section 35 of the Constitution Act, 1982, were identified.

Indigenous peoples or representative groups were not specifically consulted as part of the proposed Regulations, given that promoting competition in the financial sector and improving the process of transferring investment accounts apply to all Canadians.

Instrument choice

The proposed Regulations are required to minimize the risk of consumer-targeted fraud against Canadians. The objective of the proposed Regulations could not be accomplished through other instruments, as specific regulatory requirements are required to enable enforcement action by the FCAC.

As part of the regulatory development process, other options were considered to protect consumers from fraud. One option considered was relying on banks’ voluntary efforts through the CASC to reduce fraud against Canadians. This work includes developing consumer awareness campaigns to raise awareness of the nature of consumer-targeted fraud and consideration of how institutions across multiple sectors, including banks, telecommunications companies and social media platforms, may share data related to fraud with one another. The voluntary approach does not include specific requirements that would allow consumers to adjust account capabilities or require banks to develop policies and procedures to address fraud.

The government determined that a prescriptive regulatory approach to addressing fraud, rather than a principles-based voluntary code, would provide stronger protections for consumers through imposing specific requirements on banks to prevent, detect and mitigate fraud, ensure consistency in the level of consumer protection across banks, and ensure the FCAC can take appropriate actions to supervise and enforce the requirements, including by imposing monetary penalties in the event of non-compliance. While some banks may have voluntarily implemented some of the requirements in the proposed Regulations, these practices are likely inconsistent across banks. The proposed Regulations are therefore necessary to ensure consistent treatment of consumers regardless of their financial institution.

Additionally, prescribing the reporting of fraud data would ensure a consistent approach across all banks while also ensuring the Department of Finance and the FCAC have access to fraud-related data collected by the banks. Absent the proposed Regulations, the government would continue to not have access to reliable fraud data and therefore knowledge gaps would continue to create challenges from a policy development perspective. These regulatory requirements will supplement other legislated requirements in the Bank Act for banks to prevent and detect consumer-targeted fraud and mitigate its impacts, which will be supervised and enforced by FCAC.

To further protect consumers from fraud, the Department is working with other government departments to develop a National Anti-Fraud Strategy that will propose a multi-sectoral approach to combat fraud. This Strategy will bring together financial institutions, telecommunications, and technology companies to better protect consumers from fraud.

Regulatory analysis

Benefits and costs

Overview

The cost-benefit analysis examines the potential incremental costs and benefits associated with the proposed Regulations. Overall, this analysis finds that the proposed Regulations would provide discounted benefits totalling $2.9 billion and discounted costs totalling $611 million over the 10-year period following the registration of the proposed Regulations (discounted to year 2027 at a 7% discount rate and expressed in 2026 dollars). This would represent a net benefit of $2.3 billion over the 10-year period following the registration of the proposed Regulations. All the monetized benefits would be borne by consumers, while the monetized costs would be shared between consumers, banks, and the government.

The analysis highlights the following monetized benefit associated with the proposed Regulations:

  1. Reduction in total fraud losses, borne by consumers, as a result of being able to deactivate account capabilities that they may not use, but fraudsters may use to make unauthorized payments if they gain access to consumers’ accounts.

The analysis also highlights the following four monetized costs associated with the proposed Regulations:

  1. Implementation costs, borne by banks, associated with implementing the proposed Regulations. This would include costs to update policies and procedures to reflect the proposed requirements and to update information technology (IT) systems to allow consumers to adjust account capabilities.
  2. Administrative costs, borne by banks, including to collect data associated with consumer-targeted fraud, associated with the proposed requirement for banks to report data annually to the FCAC.
  3. Government supervision costs, borne by the FCAC, associated with resources required to oversee and enforce the new consumer provisions introduced by the proposed Regulations.
  4. Consumer costs associated with new frictions introduced through the proposed Regulations such as enabling account capabilities that would have otherwise been enabled and verifying identity when attempting to increase a transaction limit.

Additionally, there are the following qualitative benefits associated with this proposal:

  1. Reduction in non-financial harms associated with fraud losses, including poor mental health impacts, resulting from both the reduction in the frequency and total value of fraud losses.
  2. Reduction in time spent by law enforcement and financial institutions investigating fraud losses.
  3. Consumers will benefit from the requirement for banks to implement requests to change a withdrawal or transaction limit without delay if the bank verifies the consumer’s identity.
  4. Enhanced consumer trust in the federal financial sector as a result of fewer fraud losses.
  5. Access to reliable, timely, and accurate data to inform future fraud prevention policies, including the National Anti-Fraud Strategy.
Profile of affected stakeholders
Consumers

The proposed Regulations would provide monetized benefits to Canadian consumers that disable (or for new accounts, do not enable) account capabilities that would otherwise have been used to defraud them. That is, consumers that disable electronic funds transfers would benefit from a reduction in fraud losses in the event that their personal deposit account is accessed by a fraudster.

The CAFC finds that, based on 2024 data, individuals under 50 years of age are more likely to be defrauded. However, those over 50 lose more money on average when they are defrauded. In 2024, CAFC received 109 000 reports of fraud. However, CAFC notes that only 5 to 10% of fraud in Canada is reported,footnote 1 meaning that the true number of fraud instances in Canada could be between 1.1 and 2.2 million in 2024.

FCAC survey evidence indicates that consumer-targeted fraud affects Canadians across demographic groups, but reported victimization varies across sub-populations. In FCAC’s Monthly Financial Well-Being Monitor, 13% of Canadians reported being a victim of fraud in 2024, with higher reported victimization among younger adults aged 18–34 (16%) and lower among those aged 65+ (9%).

Between 2023 and 2025, total fraud losses reported to CAFC rose by approximately 10% each year. The year-over-year increase in fraud losses declined following the COVID-19 pandemic, when fraud losses rose by 130% in 2021 and 40% in 2022. CAFC has not published data earlier than 2020.

Consumers would also be impacted by additional frictions that would be introduced by the proposed Regulations. This would include the requirement for banks to obtain express consent before enabling certain account capabilities and needing either to validate their identity to have a transaction limit increased without delay, or wait one business day if the bank has not validated their identity. This may cause frustration for consumers that are attempting to make legitimate transactions, particularly if they are time sensitive.

Financial institutions

The proposed Regulations would only apply to “institutions” as defined under part XII.2 of the Bank Act. This definition includes banks listed under Schedule I and Schedule II as well as authorized foreign banks. As of December 31, 2025, there were 35 Schedule I banks and 15 Schedule II banks operating in Canada. As per the Office of the Superintendent of Financial Institutions (OSFI), there are 29 authorized foreign banks. In total, 79 institutions would be impacted by the proposed Regulations.

Model and assumptions
Reduction in fraud losses (monetized)

To proxy fraud levels in Canada, which go mostly unreported, it will be assumed that the number and value of fraud incidents reported by CAFC represents 7.5% of the true value of fraud in Canada. As mentioned in the background, this assumption is based on CAFC estimate that only 5 to 10% of fraud is reported, meaning 90 to 95% of fraud remains unreported. In 2024, CAFC reported fraud losses totalling $645 million associated with 109 000 reports of fraud. However, not every report corresponds to a loss due to fraud, as some consumers report attempted fraud to CAFC. In 2024, consumers’ reported losses to wire transfers totalled $154 million and losses to Interac e-Transfers totalled $36.7 million. If these values represent 7.5% of the true value of fraud losses, this would mean Canadians lost $2.1 billion to wire transfer fraud and $489 million to Interac e-Transfer fraud in 2024.

Based on the value of fraud losses reported by CAFC between 2022 and 2025, it is assumed that fraud losses will continue to rise by 10% each year. For the purposes of this analysis, it is also assumed that the number of fraud victims will rise by 10% each year.

To estimate the benefits of the proposed Regulations, it is assumed that consumers who have not used a wire transfer, global money transfer, or an Interac e-Transfer would not enable these functions and, therefore, would not incur losses via these transaction methods should a fraudster gain access to their account. Interac reports that 88% of Canadians have used Interac e-Transfer.footnote 2 Given that some portion of those that have not used Interac e-Transfer would likely still enable the capability, it is assumed that 10% of account holders would turn off Interac e-Transfer if given the option.

Since CAFC does not distinguish between wire transfers and global money transfers in its annual report, it is assumed that losses associated with global money transfers are a subset of losses associated with wire transfers. As per Payments Canada,footnote 3 20% of Canadians had sent an international payment in the 12 months prior to March 2024. While these individuals may not have used the global money transfer capability, this is used as a proxy to estimate the number of consumers that would disable global money transfers. Given that there is likely some portion of the population that has not used a global money transfer but does not wish to disable it, it is assumed that 25% of Canadians would enable global money transfers, and thus 75% would have this function disabled.

Due to the lack of data on how many Canadians use wire transfers, it is assumed that an additional 50% of Canadians would enable wire transfers. While wire transfers are not a common method for day-to-day transactions, they are useful for large-value transactions such as mortgage down payments or vehicle purchases. Combined with the estimates for global money transfers, it is assumed that 25% of the population would disable wire transfers, including global money transfers.

For the purposes of monetized benefits reported in this analysis, it is assumed that only unauthorized fraudulent transactions would be prevented as a result of these proposed Regulations. While it is possible that these proposed Regulations may prevent some instances of authorized transaction fraud if, for example, a consumer opts to not send a fraudulent payment due to the friction associated with re-enabling an account capability, this would likely represent a significantly small portion of fraud losses and the effectiveness of the regulations in preventing such fraud is much more uncertain. Therefore, these benefits will not be monetized as part of this analysis. As per Payments Canada,footnote 4 unauthorized transactions represented 38% of fraud experienced by Canadians during a six-month period in 2024. Therefore, it is assumed that 38% of the estimated fraud losses are due to unauthorized fraud and that these losses would be prevented if the proposed Regulations were in force.

To estimate the reduction in fraud losses, the estimated value of fraud losses associated with each transaction method in 2027 ($651 million for Interac e-Transfer; $2.7 billion for wire transfer) is multiplied by the estimated percentage of the population that would turn the feature off (10% and 25%, respectively) and by the percentage of the total losses associated with unauthorized transaction fraud (38%).

Industry implementation costs (monetized)

To estimate the costs to banks incurred in the first year following registration of the proposed Regulations, the following assumptions are made:

Industry annual costs (monetized)

To estimate the ongoing annual cost associated with reviewing the policies and procedures annually, the following assumptions are made:

To estimate the costs associated with collecting fraud data from consumers, it is assumed that all consumers would report fraud instances to their banks. To estimate the number of fraud instances in a given year, it is assumed that the number of fraud instances reported to the CAFC represents 7.5% of the total number of fraud instances in Canada. This aligns with the CAFC’s estimate that only 5 to 10% of fraud instances are reported. It is assumed that each report would take 12 minutes to complete, meaning a bank employee could complete five reports in one hour. Therefore, 5 381 hours would be required to collect all fraud data at each of the 79 implicated banks in 2028. It is assumed that each of these employees is at the senior analyst or management level and earns $59.48 per hour (NOC 10010).

These costs would be incurred beginning in year two following registration of the proposed Regulations.

Finally, to estimate the annual cost associated with reporting fraud data to the FCAC, the following assumptions are made:

Costs associated with reporting fraud data to the FCAC would be incurred beginning in year three following registration of the proposed Regulations.

Government supervision costs (monetized)

FCAC would administer, supervise and enforce compliance by banks and authorized foreign banks with the proposed Regulations, undertake targeted updates to or create new consumer information resources, and support annual reporting to the Minister once required data have been submitted in accordance with the proposed Regulations.

FCAC’s activities to oversee the proposed Regulations would evolve over time, beginning with implementation activities during the transition period and progressing toward ongoing risk-based supervisory oversight and enforcement.

In the first year following the registration of the proposed Regulations, FCAC would undertake a series of implementation activities to facilitate timely and consistent compliance by regulated entities. This includes adapting and expanding FCAC’s existing data intake and validation systems, and engagement with banks to communicate regulatory expectations, including the development of internal supervisory guidance, operational procedures, and interpretive frameworks. During this time, the FCAC would also prepare outward-facing communications products — such as website updates, consumer information pages, and questions and answers.

In the first year, the FCAC estimates that it would require five full-time equivalents (FTEs) to prepare for data reporting, five FTEs to prepare for supervision of account capability requirements, and eight FTEs to prepare for the supervision of consumer-targeted fraud policies and procedures. In total, FCAC would require 18 FTEs in the first year following the registration of the proposed Regulations.

In each subsequent year, after the regulations come into force, FCAC estimates that it would require nine FTEs to support monitoring of the data reporting requirements, 11 FTEs to monitor the requirements related to policies and procedures, and five FTEs to monitor the requirements related to account capabilities. In total, FCAC estimates that it would require 25 FTEs annually beginning in year two following the registration of the proposed Regulations.

Consumer friction costs (monetized)

Consumers would incur costs associated with enabling account capabilities and validating their identity to increase a transaction limit. It is assumed that, of the population of Canadians that have bank accounts, 95% would wish to enable some account capability, whether that is a wire transfer, a global money transfer, an Interac e-Transfer, or some combination of the three, and that enabling these capabilities would take approximately five minutes, regardless of the number of account capabilities enabled. Banks would not be required to obtain express consent for capabilities that would have already been enabled upon coming into force of the proposed Regulations. Therefore, consumers that open an account before the proposed Regulations come into force would not incur costs associated with enabling a capability, unless they choose to disable a capability first.

To estimate the number of accounts that will be opened in a given year, it is assumed that 99% of the growth in the adult population in Canada would open a bank account. This assumption is based on data from the Canadian Bankers Association that estimates that 99% of adult Canadians have a bank account.footnote 7 This would mean that 28 000 Canadians would open a bank account in 2027. In addition to the portion of Canadians that will open their first bank account, it is assumed that 24% of the adult population would open a second bank account or switch banks in any given year.footnote 8 This aligns with data from Environics Research that found 24% of Canadians reported switching bank accounts in 2024. In 2027, this would correspond to 8.1 million Canadians.

Additionally, it is assumed that, of the population of adult Canadians that have bank accounts, 25% would wish to increase a transaction limit at some point during the year and that validating their identity would take approximately five minutes. Given that 99% of Canadian adults have a bank account, it is assumed that 8.4 million Canadians would wish to increase a transaction limit in the second year following registration of the proposed Regulations.

To estimate these costs to consumers, the opportunity cost of providing express consent and identity validation is assumed to be equal to the average wage in Canada. As per Statistics Canada, the average wage for all employees was $36.40 in 2025.

Cost-benefit statement
Table 1: Monetized benefits (x $1,000,000)
Impacted stakeholder Description of benefit Base year (2027) Other relevant years (2028) Final year (2036) Total (present value) Annualized value
Consumers Reduction in fraud losses $142 $313 $671 $2,887 $411
All stakeholders Total benefit $142 $313 $671 $2,887 $411
Table 2: Monetized cost (x $1,000,000)
Impacted stakeholder Description of cost Base year (2027) Other relevant years (2028) Final year (2036) Total (present value) Annualized value
Industry   Implementation costs $3 $0 $0 $3 $0
Annual costs $0 $26 $55 $227 $32
Government Supervision costs $4 $7 $6 $39 $6
Consumers Payment friction costs $25 $51 $54 $342 $49
All stakeholders Total costs $32 $84 $115 $611 $87
Table 3: Summary of monetized costs and benefits (x $1,000,000)
Impacts Base year (2027) Other relevant years (2028) Final year (2036) Total (present value) Annualized value
Total benefits $142 $313 $671 $2,887 $411
Total costs $32 $84 $115 $611 $87
Net impact $110 $229 $555 $2,276 $324
Sensitivity analysis

In the cost-benefit analysis, it is assumed that CAFC’s reported fraud losses represent 7.5% of total fraud losses in Canada (1.9 million cases of fraud per year). While CAFC estimates that its report represents 5 to 10% of total fraud losses in Canada, the true value is unknown. The sensitivity analysis examines the impact of the proposed Regulations if CAFC’s reports represent 5% (high scenario — 2.9 million fraud cases a year) and 10% (low scenario — 1.4 million cases of fraud per year) of fraud losses in Canada.

As shown in the table below, if the actual number of fraud incidents and value of fraud losses is lower than what is assumed in the central scenario, the associated costs and benefits will also be lower. Conversely, if the true number and value of fraud incidents is higher than initially assumed, the costs and benefits would be higher. If all other assumptions remained the same in the analysis as long as the number of fraud cases exceeds 145 200 per year (75.9% of fraud cases reported), the regulations would result in a positive net benefit.

Table 4: Results of sensitivity analysis on the impacts of the proposed Regulations (x 1,000,000)
  Low Scenario Central Scenario High Scenario
Total number of fraud incidents (2027) 1.4 1.9 2.9
Total value of fraud losses (2027) $2,538.2 $3,384.3 $5,076.4
Total benefits (PV) $2,164.9 $2,886.6 $4,329.9
Total costs (PV) $484.9 $610.9 $595.2
Net benefit $1,680.0 $2,275.6 $3,734.7
Annualized net benefit $239.2 $324.0 $531.7
Distributional analysis

As per the CAFC, fraud affects all demographics generally evenly. While seniors are more likely to be defrauded through “conventional” methods such as direct telephone calls, rather than cyber-enabled fraud, younger age groups are increasingly being victimized by nuanced and age-specific forms of fraud, such as deepfake videos on social media. Similarly, men and women generally experience fraud at the same rates.

These benefits would likely be distributed across provinces based on fraud rates, meaning that provinces that experience greater fraud losses would receive greater benefits. As per the CAFC’s 2024 Annual Report, Ontario experienced the greatest value of losses due to fraud and as such, would be expected to receive greater benefits. Conversely, as the territories reported the lowest value of fraud losses, they are expected to receive the smallest share of benefits.

Small business lens

Analysis under the small business lens concluded that the Regulations will not impact small businesses. As such, no further analysis was conducted on the impact on small businesses or measures taken to reduce that impact. This analysis assumes that no small businesses use personal deposit accounts to conduct their business. If this is not the case, these small businesses may face minor friction costs, but would also benefit from the fraud prevention protections provided by the proposed Regulations.

One-for-one rule

The one-for-one rule would apply, as the proposed Regulations would impose new administrative costs on businesses. Banks would experience a new administrative burden as a result of the proposed requirement for banks to submit data on fraud instances to the FCAC.

Using assumptions and data presented above and the methodology developed in the Red Tape Reduction Regulations, it is estimated that the regulated community will assume total administrative costs of $117,093 (2012 Canadian dollars, 7% discount rate, base year of discounting in 2012) for all banks.

Regulatory cooperation and alignment

The Department conducted a jurisdictional scan to examine how other jurisdictions address fraud. This scan included examining anti-fraud requirements in other OECD countries, including Australia, New Zealand, the United Kingdom, Singapore, and the European Union. These jurisdictions were selected due to recent updates to their fraud prevention measures.

Australia recently introduced its Scams Prevention Framework, a multi-sectoral framework aimed at reducing fraud. The Framework will require institutions in the financial and telecommunications sectors, as well as digital platforms, to take action to prevent, detect, report, disrupt and respond to fraud against their users. The Framework includes overarching requirements applicable to all industries as well as sector-specific guidelines.

New Zealand has also recently announced its intention to develop a national anti-scam strategy. Similar to Australia’s model, this cross-sector initiative will include measures to strengthen user protections across the financial and telecommunications sectors, and for digital platforms.

The United Kingdom has taken a different approach, where it assigns liability for fraudulent transactions to the institutions that completed the transaction. In cases where a fraudulent transaction is sent between institutions (i.e. not between two accounts held at the same institution), both the sending and the receiving institution must accept liability for 50% of the funds lost by the victim.

Similarly, Singapore has implemented a limited liability model whereby financial institutions and telecommunications providers may be held liable for fraudulent transactions if they did not meet their respective obligations to prevent fraud.

As part of the broader work to advance the National Anti-Fraud Strategy, the government has consulted on proposals to introduce new fraud-related market-conduct requirements across the financial sector, the telecommunications sector and for digital platforms, with potential requirements for consumer redress in the event of non-compliance with those responsibilities leading to fraud losses. Significant policy work is required to determine how to best advance the Strategy.

Additionally, the European Union recently introduced regulations that require payment service providers to accept liability for fraudulent transactions if they fail to implement appropriate fraud prevention measures.

It was found that other jurisdictions, such as Australia, will require financial institutions to report instances of fraud to the relevant regulator. This aligns with the proposed requirement for banks to collect and report annual fraud data to the Commissioner of the Financial Consumer Agency of Canada (FCAC) and the requirement for banks to have policies and procedures to determine when to report an instance of fraud to the relevant regulator.

Requirements to allow consumers to adjust certain account capabilities do not appear to exist in other jurisdictions. This may be due to financial institutions in other jurisdictions providing these capabilities voluntarily.

Effects on the environment

In accordance with the Cabinet Directive on the Environmental Assessment of Policy, Plan and Program Proposals, a preliminary scan concluded that a strategic environmental assessment is not required.

Gender-based analysis plus

The proposed Regulations would benefit all Canadians that are victims of fraud. Data from the Canadian Anti-Fraud Centre (CAFC) suggests that while Canadians of all ages are at risk of being defrauded, those ages 50 and above report the highest dollar losses to fraud, according to CAFC’s 2021 and 2022 Annual Reports. As such, those over 50 would likely benefit the most from these proposed Regulations.

According to CAFC, seniors are more likely to be defrauded through “conventional” methods such as direct telephone calls, rather than cyber-enabled fraud. However, those under 50 are increasingly being victimized by nuanced and age-specific forms of fraud. For example, the CAFC reports that those under 19 are more likely to experience fraud related to dating app usage.

Data from the CAFC does not suggest fraud is a gendered issue — all genders experience fraud at relatively similar rates and would therefore be equally impacted by the proposed Regulations. While CAFC does not collect data on income, education level, and newcomer status, these factors may impact whether an individual is more likely to be a victim of fraud. Data from Interacfootnote 9 suggests that newcomers to Canada feel as though they are at a heightened risk of being defrauded.

FCAC’s Canadian Financial Capability Survey (CFCS) 2024 shows that fraud affects Canadians broadly, but patterns differ by fraud type across demographic groups. By gender, men are more likely to report investment fraud (10%) than women (8%), while women are more likely to report unauthorized use of bank or credit card numbers (39%) than men (33%). By age, Canadians aged 55+ are more likely to report phishing (16%) than younger Canadians (11%).

Implementation, compliance and enforcement, and service standards

Implementation

The proposed Regulations would come into force on July 1, 2027. The coming-into-force period would give banks sufficient time to make changes to their information technology systems, disclosure documents, policies and procedure documents, and other internal documentation in order to achieve compliance with these measures. The FCAC would be able to enforce the proposed Regulations by the proposed coming-into-force date.

The regulations include a transitional provision that would provide that banks’ first annual consumer-targeted fraud report must be submitted to the FCAC by May 15, 2029, and would cover data for the period beginning January 1, 2028, and ending on December 31, 2028. This would mean that banks would not be required to begin collecting consumer-targeted fraud data until six months after the proposed Regulations would come into force. This will give banks and the FCAC additional time to build the necessary IT systems to allow for the collection and reporting of fraud data.

The consumer-targeted fraud legislative amendments would come into force on the same date as the proposed Regulations, July 1, 2027. This date would be fixed by an Order in Council.

The Department would work with the FCAC to prepare communications materials and update existing consumer education materials, as required, to be available at the registration of these proposed Regulations.

Compliance and enforcement

The FCAC promotes, monitors and enforces the compliance of banks and other federally regulated financial entities with consumer protection measures. The FCAC monitors compliance with provisions under the Bank Act and the Financial Consumer Protection Framework Regulations, including monitoring market trends and the activities of banks to ensure compliance.

The FCAC operates on a cost-recovery basis and is funded mainly through assessments from the regulated entities it supervises. FCAC publishes a Business Plan on an annual basis, which outlines its planned activities in accordance with its mandate, and the resources that will support those activities. Costs associated with the new requirements will be recovered through existing cost recovery processes and reflected in FCAC’s Business Plan. Compliance with the provisions of the proposed Regulations would be achieved through a variety of approaches along a compliance continuum. For example, for isolated or minor breaches, the FCAC many issue a letter to the bank and undertake enhanced monitoring. For more serious breaches, the FCAC may request that a bank enter into a compliance agreement or may issue a Notice of Violation and an Administrative Monetary Penalty (AMP).

Contact

The contact person for public enquiries is Mark Radley, Director of Consumer Affairs, who can be contacted at consumer.consommateur@fin.gc.ca.

PROPOSED REGULATORY TEXT

Notice is given that the Governor in Council proposes to make the annexed Regulations Amending the Financial Consumer Protection Framework Regulations under paragraphs 627.998(a)footnote a, (p)footnote b, (q)footnote b and (s) to (v)footnote b of the Bank Act footnote c.

Interested persons may make representations concerning the proposed Regulations within 30 days after the date of publication of this notice. They are strongly encouraged to use the online commenting feature that is available on the Canada Gazette website but if they use email, mail or any other means, the representations should cite the Canada Gazette, Part I, and the date of publication of this notice, and be sent to Mark Radley, Director of Consumer Affairs, Financial Servies Division, Financial Sector Policy Branch, Department of Finance, 90 Elgin Street, Ottawa, Ontario K1A 0G5 (email: consumer.consommateur@fin.gc.ca).

Ottawa, June 19, 2026

Janna Rinaldi
Assistant Clerk of the Privy Council

Regulations Amending the Financial Consumer Protection Framework Regulations

Amendments

1 The Financial Consumer Protection Framework Regulations footnote 10 are amended by adding the following after section 8:

Consumer-Targeted Fraud

Prescribed account capabilities

8.1 (1) For the purposes of subsection 627.131(1) of the Act, all account capabilities that permit the transfer of funds by electronic means are prescribed account capabilities.

Exclusion

(2) Despite subsection (1), electronic funds transfers between accounts held by the same natural person within the same financial institution, automatic teller machine withdrawals, any form of payment using payment card credentials, pre-authorized debits and direct bill payments are not prescribed account capabilities.

Express consent — manner

8.2 (1) For the purposes of subsection 627.131(1) of the Act, to obtain the express consent of the natural person who requested the opening of the personal deposit account or in whose name it is kept, the institution must

Independent consent

(2) The institution must obtain express consent for each activation of a prescribed account capability, independent of any other express consent obtained by the institution for the purposes of opening the account or activating any other prescribed account capability.

Prescribed periods

8.3 For the purposes of subsection 627.132(3) of the Act, the increase to the maximum amount of a withdrawal or transfer of funds that can be made from personal deposit account must take effect

Fraud — policies and procedures

8.4 (1) For the purposes of paragraph 627.134(2)(g) of the Act, the following are prescribed criteria:

Review

(2) An institution must, at least once a year, conduct a review of the effectiveness of policies and procedures it has established to detect and prevent consumer targeted fraud and to mitigate its impacts.

Annual report — Commissioner

8.5 The institution must submit the annual report prepared under subsection 627.134(4) to the Commissioner, in a form satisfactory to the Commissioner, within 135 days after the end of the calendar year for which it was prepared and must contain

Annual Report — Minister

8.6 The Commissioner must submit the annual report, prepared under subsection 627.135(1) of the Act, to the Minister by September 30 of the calendar year following the calendar year for which the report was prepared.

2 Section 22 of the Regulations is amended by striking out “and” at the end of paragraph (b), by adding “and” at the end of paragraph (c) and by adding the following after paragraph (c):

Transitional Provision

3 For the purposes of section 8.5 of the Financial Consumer Protection Framework Regulations, the first annual report prepared under subsection 627.134(4) of the Bank Act must be submitted to the Commissioner, as defined in section 2 of that Act, by May 15, 2029 and must include the information referred to in paragraphs 8.5(a) to (d) of these Regulations for the period that starts on January 1, 2028 and ends on December 31, 2028.

Coming into Force

4 These Regulations come into force on July 1, 2027.

Terms of use and Privacy notice

Terms of use

It is your responsibility to ensure that the comments you provide do not:

  • contain personal information
  • contain protected or classified information of the Government of Canada
  • express or incite discrimination on the basis of race, sex, religion, sexual orientation or against any other group protected under the Canadian Human Rights Act or the Canadian Charter of Rights and Freedoms
  • contain hateful, defamatory, or obscene language
  • contain threatening, violent, intimidating or harassing language
  • contain language contrary to any federal, provincial or territorial laws of Canada
  • constitute impersonation, advertising or spam
  • encourage or incite any criminal activity
  • contain external links
  • contain a language other than English or French
  • otherwise violate this notice

The federal institution managing the proposed regulatory change retains the right to review and remove personal information, hate speech, or other information deemed inappropriate for public posting as listed above.

Confidential Business Information should only be posted in the specific Confidential Business Information text box. In general, Confidential Business Information includes information that (i) is not publicly available, (ii) is treated in a confidential manner by the person to whose business the information relates, and (iii) has actual or potential economic value to the person or their competitors because it is not publicly available and whose disclosure would result in financial loss to the person or a material gain to their competitors. Comments that you provide in the Confidential Business Information section that satisfy this description will not be made publicly available. The federal institution managing the proposed regulatory change retains the right to post the comment publicly if it is not deemed to be Confidential Business Information.

Your comments will be posted on the Canada Gazette website for public review. However, you have the right to submit your comments anonymously. If you choose to remain anonymous, your comments will be made public and attributed to an anonymous individual. No other information about you will be made publicly available.

Comments will remain posted on the Canada Gazette website for at least 10 years.

Please note that communication by email is not secure, if the attachment you wish to send contains sensitive information, please contact the departmental email to discuss ways in which you can transmit sensitive information.

Privacy notice

The information you provide is collected under the authority of the Financial Administration Act, the Department of Public Works and Government Services Act, the Canada–United States–Mexico Agreement Implementation Act,and applicable regulators’ enabling statutes for the purpose of collecting comments related to the proposed regulatory changes. Your comments and documents are collected for the purpose of increasing transparency in the regulatory process and making Government more accessible to Canadians.

Personal information submitted is collected, used, disclosed, retained, and protected from unauthorized persons and/or agencies pursuant to the provisions of the Privacy Act and the Privacy Regulations. Individual names that are submitted will not be posted online but will be kept for contact if needed. The names of organizations that submit comments will be posted online.

Submitted information, including personal information, will be accessible to Public Services and Procurement Canada, who is responsible for the Canada Gazette webpage, and the federal institution managing the proposed regulatory change.

You have the right of access to and correction of your personal information. To seek access or correction of your personal information, contact the Access to Information and Privacy (ATIP) Office of the federal institution managing the proposed regulatory change.

You have the right to file a complaint to the Privacy Commission of Canada regarding any federal institution’s handling of your personal information.

The personal information provided is included in Personal Information Bank PSU 938 Outreach Activities. Individuals requesting access to their personal information under the Privacy Act should submit their request to the appropriate regulator with sufficient information for that federal institution to retrieve their personal information. For individuals who choose to submit comments anonymously, requests for their information may not be reasonably retrievable by the government institution.