RPAA Internal Framework Review: Highlights & Requirements for PSPs

A purple and orange gradient graphic with the words Ask Us Anything Key Highlights and The AML Shop Logo.

In case you missed our Ask Us Anything Webinar last week all about Internal RPAA Framework review, here are a couple of key highlights PSPs might find useful from the session.

When am I required to conduct an Annual RPAA Framework Internal review? 

An Internal RPAA Framework Review must occur:

  1. At least once per year

and

  1. Before any material change to operations, systems, policies, procedures or controls occur.

What is the Criteria for an annual internal review?

You must evaluate your RPAA program broadly and specifically.  This includes:

  1. The framework’s compliance with the requirements of the RPAA/RPAR,

  2. Evaluating your ability to meet integrity, confidentiality and availability objectives,

  3. The adequacy and performance in your framework’s ability to  detect, protect, respond to and recover from risks and incidents,)

  4. Sufficiency of the allocated roles and responsibilities and the adequacy of human and financial resources to implement the program, and

  5. The arrangements for assessing and mitigating risk from the use of third party service providers, agents and mandataries.

Remember, scope and methodology can be subjective to your specific business type and operations. For example: Do you or do you not have safeguarding obligations? If so, then you must review your safeguarding framework and obligations as well. 


What’s the difference between the internal annual review and the expected independent review every 3-years?

First, a 3-year independent review must be completed by a sufficiently skilled individual who possesses the appropriate knowledge and has no role in the implementation, establishment or the maintenance of the risk management and incident response framework and if applicable, the safeguarding framework for the PSP. This party should be independent and segregated from the program. For example, a compliance company like The AML Shop.

For the Annual Framework Internal Review, you may assign either an internal or external party, and this could include someone who has or had direct involvement with the risk management and incident response or safeguarding programs. 

There were so many other great questions and we thank you all for attending!

If you need any further RPAA assistance, contact our experts to learn how we can help reduce friction with regulators and help you keep The Bank of Canada Happy.