
15 July 2026 • 9 minute read
Canada proposes new anti-fraud regulations for banks under the Financial Consumer Protection Framework
On June 27, 2026, the Department of Finance published proposed amendments to the Financial Consumer Protection Framework Regulations under the Bank Act (Proposed Regulations), addressing consumer-targeted fraud in banking. The Proposed Regulations are designed to operationalize legislative changes introduced through the Budget Implementation Act, 2025, No. 1 (Bill C-15).
Comments on the Proposed Regulations must be submitted by July 27, 2026, and the regulations are scheduled to come into force on July 1, 2027.
The Proposed Regulations form part of the federal government's broader effort to develop a National Anti-Fraud Strategy, formally launched for public consultation on March 30, 2026, and which aims to establish a whole-of-government, multi-sector approach to combating fraud.
Background and policy context
Consumer-targeted fraud, encompassing both unauthorized transactions and transactions authorized as a result of coercion or deception, has escalated significantly in Canada. According to the Canadian Anti-Fraud Centre, reported losses reached $704 million in 2025, representing a nearly 300% increase over 2020 levels. These figures are widely understood to be substantially understated, as the Canadian Anti-Fraud Centre estimates that only five to ten percent of fraud is actually reported.
Artificial intelligence has exacerbated these risks by enabling fraudsters to deploy increasingly sophisticated techniques, such as deepfake videos and AI-generated voice calls. The potential for harm is compounded by the fact that personal deposit accounts often include high-value electronic transfer capabilities, such as wire transfers, international money transfers, and Interac e-Transfers that are enabled by default and may permit online banking transactions with values as high as $50,000. When fraudsters gain access to these accounts, the consequences for consumers can be severe.
Prior to the Bill C-15 amendments, the only federal legislative fraud-related consumer protection requirement for banks was a $50 liability cap on unauthorized credit card transactions, together with the understanding under the Canadian Code of Practice for Consumer Debit Card Services that consumers bear no liability for losses beyond their control.
Statutory framework established by Bill C-15
As discussed in our earlier bulletin, Changes under Bill C-15 affecting the Bank Act, the Bank Act amendments introduced by Bill C-15 establish a fraud risk management framework for banks and authorized foreign banks. The Proposed Regulations provide the operational specifics necessary to bring this framework into effect.
Key elements of the proposed regulations
Prescribed account capabilities and express consent
The Proposed Regulations define "prescribed account capabilities" as all capabilities permitting the transfer of funds by electronic means associated with personal deposit accounts. This includes wire transfers, global money transfers, and Interac e-Transfers. Notably, the following are excluded: transfers between accounts held by the same individual at the same institution, ATM withdrawals, payments made using payment card credentials (e.g., debit or prepaid cards), pre-authorized debits, and direct bill payments.
Before enabling any prescribed account capability, banks would need to obtain express consent from the account holder. The consent framework would require banks to:
- provide consumers with information regarding the nature and potential uses of each capability prior to activation;
- obtain consent separately for each capability, without bundling it with other consents; and
- implement procedures to verify the identity of the individual requesting activation.
The Proposed Regulations do not seek to prescribe a specific contact method through which banks must obtain this consent, leaving institutions with flexibility in how they design their consent processes. Importantly, banks would not be required to obtain retroactive consent for capabilities already enabled on existing accounts at the time the framework takes effect. Banks would also need to allow consumers to disable electronic funds transfer capabilities.
Account opening disclosure
The Proposed Regulations would amend the existing disclosure requirements applicable at account opening for personal deposit accounts. Banks would be required to inform consumers of:
- the account capabilities that cannot be activated without express consent;
- the account capabilities that can be deactivated; and
- the account capabilities for which the maximum withdrawal or transfer amount can be increased or decreased.
These disclosures are intended to ensure consumers are aware of the fraud protection measures available to them from the outset of the account relationship.
Additionally, banks would need to notify consumers by electronic means whenever an account capability is activated, deactivated, or a transaction or withdrawal limit is adjusted.
Transaction limit adjustments
Where a consumer requests a change to their transaction or withdrawal limit, banks would be obligated to implement that change: (a) without delay, if the bank has verified the account holder's identity; or (b) no later than the following business day, if the bank has not verified the account holder's identity. These timing requirements are designed to balance operational feasibility with fraud mitigation objectives.
Enhanced fraud policies and procedures
The Proposed Regulations supplement the statutory obligation to maintain fraud detection policies by requiring banks to include specific additional criteria in their policies and procedures, namely:
- criteria used to investigate transactions the bank has identified as suspicious; and
- criteria used to determine whether to notify a consumer that a suspicious request has been received to activate a prescribed account capability or increase a transaction limit.
Data collection and annual reporting to the FCAC
The Proposed Regulations would establish detailed requirements for the annual fraud reporting obligation. Banks would need to submit reports to the Financial Consumer Agency of Canada (FCAC) Commissioner within 135 days of the end of the calendar year, in a form satisfactory to the Commissioner. For each instance of consumer-targeted fraud, including attempted and alleged cases, banks would have to report:
- the date on which the institution became aware of the instance;
- whether the fraud was attempted or committed, and whether it was confirmed by the bank or alleged by the consumer;
- the type of fraud, tactic employed, communication medium, and transaction method;
- the amount lost by the consumer (for confirmed fraud) or sought by the fraudster (for attempted fraud);
- any amount reimbursed by the bank to the victim;
- whether the transaction was unauthorized or authorized as a result of coercion or deception;
- whether the bank delayed or stopped the transaction on suspicion of fraud; and
- limited demographic data, age range, gender, and first three digits of the victim's postal code.
In addition, banks would be obligated to report on their implementation of fraud-related policies and procedures, employee training activities, and any internal fraud reduction targets.
The FCAC Commissioner is required to compile a confidential consolidated report for the Minister of Finance by September 30 of each year.
A transitional provision would allow banks a six-month lead time after the regulations come into force to establish the data collection infrastructure. Specifically, the first reporting period will cover January 1, 2028, to December 31, 2028, with the initial report due to the FCAC by May 15, 2029.
Fraud response and victim determinations
The Proposed Regulations would require banks to establish and apply criteria to determine whether a consumer is a victim of fraud, assess whether a remedy is available, and communicate those determinations to affected consumers. Notably, the Proposed Regulations would not introduce new prescriptive liability allocation rules or mandatory reimbursement standards. The existing framework, under which consumers are generally protected for unauthorized card transactions but may bear losses for account-based transfers induced by deception, would remain largely unchanged. The proposed amendments are instead focused on formalizing and standardizing the processes banks use to evaluate and respond to fraud incidents.
Scope of application
The Proposed Regulations apply to all "institutions" as defined under Part XII.2 of the Bank Act, encompassing Schedule I and Schedule II banks as well as authorized foreign banks. As of December 31, 2025, this includes 35 Schedule I banks, 15 Schedule II banks, and 29 authorized foreign banks, for a total of 79 institutions.
Compliance, enforcement, and implementation
The FCAC would supervise and enforce compliance with the Proposed Regulations. For isolated or minor breaches, the FCAC may issue a letter and undertake enhanced monitoring; for more serious violations, it may require a bank to enter into a compliance agreement or may issue a Notice of Violation accompanied by an Administrative Monetary Penalty.
The July 1, 2027 coming-into-force date is intended to provide banks with sufficient time to update information technology systems, disclosure documents, internal policies and procedures, and other operational documentation. The consumer-targeted fraud provisions of the Bank Act (as amended by Bill C-15) are expected to come into force on the same date by Order in Council.
Implications for the banking sector
The Proposed Regulations would require banks to undertake operational and technological investments ahead of the July 1, 2027 deadline. Key areas of focus include redesigning consent workflows for electronic fund transfer capabilities, building systems to capture and report granular fraud data, enhancing account opening disclosure processes, and formalizing fraud investigation and victim determination criteria.
Banks should carefully review the Proposed Regulations and consider submitting comments during the 30-day consultation period, particularly with respect to: the scope of prescribed account capabilities; the timing and mechanics of the express consent regime; any operational challenges associated with the prescribed data collection and reporting requirements; and any ambiguities in the fraud determination and response framework.
Contact a member of our Financial Services or Compliance team if you have any questions or need further assistance regarding the Proposed Regulations.