A Canadian payment processor onboards a new corporate client. Routine screening returns no direct list hits. Three weeks later, a beneficial-ownership review surfaces a controlling shareholder whose name appears on Canada's sanctions lists. Every transaction settled since onboarding now requires examination. Were any payments prohibited? Is the firm exposed to enforcement? These are not abstract questions – they are the operational reality of payment-processing controls under the Canadian sanctions regime.
Payment-processing controls under Canada rules are administered by Global Affairs Canada ("GAC") under the Special Economic Measures Act ("SEMA") and related statutes, which impose broad prohibitions on dealings with listed persons and designated entities. As of August 2026, the regime catches any transaction that directly or indirectly makes funds, financial services, or other economic value available to a designated person – including routing a payment on their behalf. The prohibition bites on the transaction, not just on the account.
This briefing sets out who administers the regime, what payment-related conduct is prohibited, how ownership and control tests apply to payment-service businesses, how Canada's rules compare with those of OFAC and OFSI, and what enforcement looks like in practice. It closes with the risk flags that most often surface in our cross-border compliance work.
Who administers Canada's payment-processing controls?
GAC administers Canada's autonomous sanctions regime, publishing and maintaining the consolidated lists of designated persons under SEMA and parallel statutes. The Financial Transactions and Reports Analysis Centre of Canada ("FINTRAC") has a distinct but complementary role: it receives suspicious-transaction reports from reporting entities – including payment-service providers – and shares intelligence with law-enforcement bodies. The Royal Canadian Mounted Police and the Public Prosecution Service of Canada are the principal enforcement arms for criminal violations.
Unlike OFAC in the United States, Canada does not maintain a single online screening tool managed by the sanctions authority itself. Practitioners must consult the Consolidated Canadian Autonomous Sanctions List published by GAC directly. Updates to that list can take effect on very short notice. In our experience, payment firms that rely on periodic bulk-list downloads rather than near-real-time feeds have repeatedly found themselves in a position where a newly designated person passed through their systems before their list was refreshed.
The practical implication is structural. A payment processor that relies solely on a third-party screening provider must verify the provider's update cadence against GAC's publication schedule. Any gap is a compliance gap. That gap is also one that GAC's enforcement posture has consistently treated as an aggravating factor.
What does Canada prohibit in relation to payment transactions?
SEMA and its thematic regulations prohibit any Canadian person, anywhere in the world, and any person in Canada from: dealing in the property of a designated person; providing financial or related services to or for the benefit of a designated person; making any goods, financial services, or funds available to a designated person; and acquiring any property held by or on behalf of a designated person.
For a payment-processing business, "dealing" encompasses origination, clearing, settlement, and correspondent-banking services. A single debit instruction routed through a Canadian-clearing infrastructure on behalf of a designated entity is a dealing in that entity's funds. The prohibition applies whether the firm acted as originating bank, intermediary, or beneficiary institution. The words "directly or indirectly" extend the prohibition to layered structures: a payment routed through an unlisted subsidiary of a designated person remains caught if the economic benefit flows to the designee.
What is the position on technical and ancillary services? SEMA-based regulations consistently treat the provision of processing infrastructure to a designated entity as a prohibited financial service. This includes gateway services, token-settlement pipelines, and card-network access. Payment-technology firms therefore face the same prohibitions as traditional financial institutions. The regime does not create a carve-out for firms that do not hold customer funds directly.
Canada also maintains a deemed-designation rule (sometimes described as an ownership-and-control test): an entity that is owned or controlled by a designated person is treated as though it were itself designated in certain thematic regulations. The precise formulation varies by regulation, and the threshold and definition of "control" are not uniform across all SEMA-based instruments. Practitioners must check the applicable thematic regulation, not assume a single standard.
How does Canada's ownership-and-control test compare with OFAC and OFSI?
The ownership-and-control analysis is where the three major regimes diverge most sharply – and that divergence matters directly to a payment firm settling cross-border transactions in multiple currencies.
Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is a bright-line mechanical test. Aggregate the ownership interests of all blocked persons. If the total reaches 50 percent or more, the entity is blocked regardless of whether any single blocked person holds a majority. Control is not the test; ownership is. The rule is set out in OFAC's published guidance and has been applied consistently.
OFSI in the United Kingdom applies an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person). "Control" here extends beyond percentage shareholding to encompass the ability to direct or influence the entity's activities through voting rights, contract, or other means. An entity may be caught under OFSI even where listed-person ownership falls below 50 percent, if the designated person exercises control in practice.
The EU applies an equivalent ownership-and-control approach under the relevant Council regulations. The EU position on "control" has been interpreted broadly by national competent authorities, particularly in the financial-services sector.
Canada's position under SEMA-based regulations is closer to the EU/OFSI approach than to OFAC's bright-line rule, but it is not uniform. Some thematic regulations specify a percentage threshold; others rely on a "control" concept without a fixed number. A payment firm with exposure to multiple regimes therefore cannot apply a single ownership test across its book. In our cross-border practice, we regularly advise firms to maintain a jurisdiction-specific matrix, running the OFAC 50 percent rule, the OFSI control test, and the applicable Canadian regulation in parallel rather than treating any single result as dispositive.
Does this create a practical problem for automated screening systems? It does. Most commercial screening platforms apply the OFAC 50 percent threshold universally because it is the most precisely codified. That approach may undercount exposure under Canadian and UK law where a designated person exercises control without holding a majority stake. Firms operating in Canada should ensure their screening logic reflects the Canadian regulatory standard, not a surrogate derived from a different regime.
The position above covers the standard case. Your facts – the counterparty's ownership structure, the currency of settlement, the route through which funds flow, and the specific Canadian regulation in force – change the analysis. For a jurisdictional review of your screening architecture, contact Calder & Vance at info@caldervance.com.
What reporting and record-keeping obligations apply to payment-service providers?
A Canadian payment-service provider that identifies property it believes to be owned or controlled by a designated person must freeze that property and report the freeze to GAC. The obligation to report arises on the firm's reasonable grounds to believe – it does not require certainty of designation. GAC's published guidance states that reports should be made as soon as practicable, and enforcement practice treats delay as an aggravating factor.
FINTRAC's obligations run in parallel. Firms that are "reporting entities" under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act must file suspicious-transaction reports where they have reasonable grounds to suspect a transaction is related to a money-laundering or terrorist-financing offence. A sanctions nexus frequently triggers the FINTRAC pathway as well as the GAC pathway. The two reporting regimes have different legal bases, different time limits, and different recipient authorities. Conflating them is a compliance error we see regularly in firms new to the Canadian market.
Record-keeping requirements under SEMA oblige firms to retain records related to frozen property and to any transaction that was blocked or reported. The standard retention period applicable across Canadian financial-sector record-keeping rules is five years, though the specific instrument should be consulted to confirm the applicable period for sanctions records. Firms should maintain a documented audit trail covering: the screening result, the list version consulted, the compliance officer's assessment, and the action taken.
If a transaction has already been flagged, or a report has been made and queried by GAC, an early review can preserve options that narrow with time. For a confidential review of a potential breach, contact Calder & Vance at info@caldervance.com.
How is Canada's payment-processing control regime enforced?
Canada's enforcement posture under SEMA has shifted materially in recent years. GAC and the Public Prosecution Service have both signalled that voluntary self-disclosure – VSD (voluntary self-disclosure to a regulator) – is considered an important mitigating factor, though no published settlement matrix exists. Criminal prosecution remains the primary enforcement route for serious violations: SEMA provides for imprisonment and substantial fines on conviction. Civil penalty mechanisms under SEMA are more limited than their OFAC equivalents, but administrative measures including disclosure orders and asset-freeze directives can be applied without a criminal charge.
For financial institutions regulated by the Office of the Superintendent of Financial Institutions ("OSFI"), sanctions compliance failures feed into OSFI's supervisory assessment. A payment-processor that is not itself a federally regulated financial institution may still face OSFI-related consequences if it relies on a federally regulated financial institution as a settlement partner – that partner faces regulatory scrutiny for its own management of third-party risk.
Secondary-sanctions exposure adds a further enforcement layer. A Canadian payment firm that processes a transaction on behalf of a party subject to US secondary-sanctions risk may face consequences under OFAC's rules even if the transaction is lawful under Canadian domestic law. OFAC's extraterritorial reach under certain programme regulations has been applied to non-US financial institutions, including Canadian firms with US-dollar clearing relationships. In our experience, this secondary-sanctions dimension is consistently underweighted in Canadian compliance programmes, particularly at mid-tier payment processors.
What triggers an enforcement referral? In practice, GAC and FINTRAC have prioritised wilful violations, systematic screening failures, and failures to file where there were clear grounds to do so. Isolated good-faith errors, promptly self-reported with a credible remediation plan, have generally been treated more leniently. The lesson for compliance teams is that the quality of documentation at the time of the incident – not reconstructed after the fact – determines the strength of any subsequent VSD narrative.
Risk flags specific to payment-processing businesses operating under Canada's regime
Payment-processing businesses face several risk patterns that do not present in the same way for other financial institutions. These are the flags we examine first in a compliance review.
- Nested payment relationships. A payment aggregator that settles on behalf of sub-merchants carries beneficial-ownership exposure for every merchant in its portfolio. If one sub-merchant is owned or controlled by a designated person, transactions routed through the aggregator are potentially prohibited. Many aggregators apply list-screening only at onboarding, not on each settlement cycle.
- Correspondent and intermediary roles. A Canadian firm acting as an intermediary institution in a correspondent chain may have limited visibility into the originator or beneficiary. The regime's "directly or indirectly" language means that limited visibility is not a defence. Straight-through-processing environments require enhanced due-diligence controls at points where ownership data is available.
- Virtual-asset service providers. VASP businesses operating under Canadian regulation face the same SEMA prohibitions as traditional payment firms. Blockchain-based transfers to wallets associated with designated persons are prohibited regardless of the settlement medium. FINTRAC's registration and reporting requirements for VASPs layer additional obligations on top of the SEMA prohibitions.
- Cross-border currency legs. A Canadian payment denominated in US dollars and cleared through a US correspondent bank is subject simultaneously to the Canadian sanctions regime and to OFAC's rules. Both sets of prohibitions apply independently. Compliance with one does not immunise the firm against liability under the other.
- Stale list versions. As noted above, GAC updates the Consolidated Canadian Autonomous Sanctions List on short notice. A firm that batches its list updates weekly – a common configuration in lower-tier payment technology firms – has a structural compliance gap for transactions processed in the days between refreshes.
A common misconception: "We only process payments – we do not hold funds"
A persistent misconception among payment-technology firms entering the Canadian market is that the prohibitions under SEMA apply only to firms that hold customer funds in segregated accounts. The argument runs: "We are a technical intermediary. The funds belong to the sender and receiver. We never own or control them."
This framing is incorrect as a matter of Canadian sanctions law. The prohibition on providing "financial services" to or for the benefit of a designated person is not limited to institutions that hold funds. Routing, clearing, or settling a payment is a financial service. Providing gateway access, processing card transactions, or operating a real-time-payments interface on behalf of a designated entity falls within the prohibition. The GAC and OSFI supervisory positions are consistent on this point.
In our practice, we have advised a number of payment-technology businesses – including API-based embedded-finance providers – that discovered their contractual characterisation as a "technical intermediary" offered no protection under the relevant Canadian regulations. The legal analysis turns on what the firm does, not on how its commercial agreements characterise it.
Does this mean every payment-technology firm needs a full financial-institution compliance programme? Not necessarily. The required controls scale to the firm's exposure. A firm processing low-value domestic transactions with limited cross-border connectivity carries a different risk profile from one settling multi-currency B2B transactions in markets with elevated sanctions risk. But the baseline obligation – to screen, to freeze on grounds, and to report – applies regardless of the firm's self-described role.
Related practices
- Sanctions compliance audit and testing – programme assessment and gap remediation across multiple regimes
- Payment-processing controls under EU sanctions – Council regulation obligations, ownership tests, and enforcement posture
- Payment-processing controls under OFAC – the 50 percent rule, blocking obligations, and VSD practice