Article
Background
The Canadian Bankers Association (CBA) is the voice of more than 60 domestic and foreign banks operating in Canada with over 280,000 employees that help drive Canada’s economic growth and prosperity. The CBA and its members (the CBA) advocate for public policies that contribute to a sound, thriving banking system to help ensure Canadians can succeed in their financial goals. Protecting Canadians from fraud remains a key priority for the banking sector.
The CBA looks forward to working with Finance on the development of the National Anti‑Fraud Strategy (the NAFS or Strategy). As announced in Budget 2025, the Government of Canada signalled its intent to strengthen and better coordinate the national response to fraud through the development of the Strategy, enhanced fraud reporting expectations, strengthened oversight, and improved cross sector collaboration to support more effective fraud prevention, detection, disruption, and enforcement efforts. The CBA supports a federal, cross sector strategy as a mechanism to strengthen consumer protection and reinforce trust in Canada’s digital economy and marketplace.
Recent data from the Canadian Anti‑Fraud Centre (CAFC) underscores the urgency of this work, with reported fraud losses to Canadians reaching approximately $7001 million in 2025, across 112,000 fraud reports. This combination of rising losses and persistent under‑reporting obscures the full scale of fraud, limits actionable intelligence, and constrains effective prevention and disruption measures. In addition, with the volume of fraud now originating through telecommunications, and digital platforms, financial sector only interventions are insufficient, reinforcing the need for a broadened, cross sector approach.
The CBA’s responses to the consultation questions are informed by the following strategic objectives developed through industry discussions. These objectives articulate the intended outcomes of the Strategy and provide a coherent Framework for coordinated action.
Proposed objectives for the Strategy:
- Protect consumers and reinforce public trust: Strengthen consumer protection, transparency, education, and safeguards to prevent fraud before harm occurs and to maintain confidence in Canada’s digital economy and marketplace. Prioritize reducing the volume of fraud reaching consumers, limiting victimization, and disrupting the flow of funds to organized criminal networks
- Strengthen cross‑sector fraud mitigation standards: Reduce the economic impact of fraud by establishing clear, proportionate, risk based, cross sector expectations and minimum capabilities to prevent, detect, and disrupt fraud across its lifecycle. Support these standards with effective government oversight and enforcement to drive consistent adoption, increase friction across criminal money in and money out pathways, and reduce any attractiveness of Canada as a target
- Clarify roles and responsibilities across the ecosystem: Define clear roles and responsibilities across sectors and sector‑specific regulators to support consistent fraud prevention, cooperation, coordinated incident response, and effective consumer protection throughout the fraud lifecycle
The CBA would welcome continued engagement with the Department of Finance as the Strategy is developed, including further dialogue on areas that warrant additional consideration. In this context, we are pleased to provide our response to the National Anti-Fraud Strategy Discussion Paper (Discussion Paper).
A Multi-Sector Anti-Fraud Framework to protect Canadians
1. Are the three described sectors appropriate for the initial phase of a Framework? Should other sectors be considered?
Response:
The three sectors identified in the Discussion Paper (financial services, telecommunications providers, and digital platforms) are appropriate for the initial phase of a Multi‑Sector Anti‑Fraud Framework (Framework). Together, these sectors intersect across the fraud lifecycle, from origination with consumer targeting, through transmission and deception, to payment execution for the benefit of fraudsters. Coordinated action across these sectors, alongside responsible consumer behavior, is therefore critical to meaningfully reducing fraud‑related harm to Canadians.
For the Framework to be effective, the scope of each sector should be clearly defined, with targeted extensions to additional sectors, where appropriate, as the fraud risk landscape evolves. The initial phase should include:
- Financial Services, including banks, credit unions, payment service providers, and other entities involved in money movement and transaction execution. This includes financial technology firms (i.e., PayPal, Stripe, Square), money services businesses (MSBs), crypto asset service providers (including firms that operate crypto and Bitcoin ATMs in Canada), and payment networks and operators2 (i.e., Interac, Payments Canada, Visa, Mastercard), which coordinate transaction routing and settlement across multiple entities
- Telecommunications Providers, given their role as a primary channel for fraud initiation through calls and messaging, and their ability to support upstream disruption of fraudulent activity before it reaches the payment stage
- Digital Platforms, including social media platforms, digital advertising, and messaging services, which are commonly used to originate, host, and scale fraudulent activity. This category should be extended to include:
- Online marketplaces that connect buyers and sellers to facilitate peer‑to‑peer transactions, which can be misused through fraudulent listings, impersonation, and payment‑related scams
- Online dating platforms, which are frequently exploited for impersonation, social engineering, and relationship based fraud schemes
- Internet infrastructure providers, such as domain registration and hosting services, which underpin online content and services and can be misused to enable or sustain fraud at scale
Oversight of the Framework
2. What role could a central regulator play in a Multi‑Sector Anti‑Fraud Framework?
Response:
The CBA believes a central regulator could play a useful coordination and oversight role within a Framework, helping promote consistent and proportionate implementation across sectors. A comparable approach has been adopted in Australia, where the Australian Competition and Consumer Commission acts as the general regulator and central coordinator of the Scams Prevention Framework, supporting cross‑sector collaboration, intelligence sharing, and coordinated enforcement across financial services, telecommunications, and digital platforms.
A central regulator would not replace existing sector‑specific authorities, which would continue to supervise and enforce rules within their mandates. Instead, a central regulator could provide a cross‑sector lens to support coherence, while preserving sectoral expertise.
In practice, this role could include supporting the development of baseline control expectations which would be developed in consultation with regulators and sector‑specific entities. These baseline expectations would be applicable across all in‑scope sectors, supplemented by sector‑specific codes and controls tailored to differing risk profiles, operating models, and services within each sector (see Figure 1). This approach would promote consistency across sectors while allowing proportionate, risk‑based implementation.
More specifically, a central regulator should:
- Work with sector‑specific regulators to support alignment on cross‑sector expectations and consistent interpretation of rules
- Support alignment of supervisory approaches and escalation principles across sectors to avoid uneven deterrence and potential gaps in coverage
- Promote a system wide view of fraud risk, helping to identify potential gaps, overlaps, and areas of displacement where fraud activity may migrate between sectors if rules are applied unevenly
- Provide oversight of external dispute resolution mechanisms for cross‑sector complaints
This coordination role is critical to avoid fragmentation. Without a unifying function, sector‑by‑sector oversight risks producing inconsistent deterrence and uneven implementation, which fraudsters could exploit by shifting activity to less constrained channels. A central regulator helps mitigate this risk by fostering predictability, shared accountability, and aligned incentives across the ecosystem. Figure 1 provides an illustrative overview of the central regulator’s role within the Framework.

Figure 1: Central Regulator Role
3. What role could sector‑specific regulators play in the Framework?
Response:
The CBA believes each sector should continue to be supervised by their existing regulators, with those regulators responsible for supervision, enforcement, and day‑to‑day, systemic oversight of compliance with sector‑specific rules under the Framework. Requirements should be applied within each sector using established supervisory tools and sector expertise.
Anchoring supervision and enforcement in existing regulators reflect their understanding of sector‑specific risks, technologies, and business models, supports proportionate, risk‑based, and operationally informed oversight while avoiding unnecessary duplication.
Within the Framework, sector specific regulators could be responsible for:
- Supervising compliance with sector‑specific rules and expectations within each regulator’s mandate
- Applying predictable, transparent, and proportionate enforcement for systemic non‑compliance, reinforcing clear incentives for ongoing investment in fraud mitigation and a linkage between non‑compliance and regulatory consequences
Sector‑specific regulators should operate within a coordinated oversight model, working with a central regulator to support alignment on cross‑sector expectations. This coordination can help reduce uneven application of requirements and limit the risk that fraud activity migrates to areas with weaker or inconsistent oversight.
Overall, sector‑specific regulators are well positioned to deliver effective supervision and enforcement under the Framework, supported by coordination across regulators to promote a coherent, system‑wide approach.
4. How can effective oversight of the Framework be achieved, without duplication of existing oversight of the three sectors?
Response:
Effective oversight of the Framework can be achieved by building on existing sector‑specific supervisory regimes, supplemented by a coordinated, multi‑sector oversight function, rather than by creating new or duplicative regulatory structures. Clear articulation of anti‑fraud expectations (e.g., rules / controls) for each sector will be essential to ensure consistent minimum standards and a clear delineation of oversight roles. Over time, government and regulators can refine coordination mechanisms and supervisory practices in response to evolving fraud risks and technologies.
The CBA supports a clear division of oversight responsibilities, where:
- Sector specific regulators retain responsibility for supervising compliance and enforcing rules within their respective sectors, using established supervisory tools and processes
- A central coordinating function provides cross sector alignment, consistency, and system level visibility, without duplicating institution level supervision
This model avoids duplication by leveraging existing regulatory mandates and expertise, while addressing potential gaps that arise where fraud activity spans multiple sectors and channels.
Information sharing between regulators
5. When should Framework regulators be permitted to share fraud‑related information with each other to further the Strategy aims of preventing, detecting, disrupting and investigating fraud?
6. If so, what specific information should be shared, under what circumstances should it be shared and for what precise purpose should it be shared?
7. What privacy safeguards or oversight mechanisms should be in place for such information‑sharing initiatives?
8. When should Framework regulators be permitted to share fraud‑related information with law enforcement for the purposes of preventing, detecting, disrupting, and investigating fraud? (Discussion Paper Section: Reporting Fraud‑Related Information to Law Enforcement)
Response:
The CBA believes that fraud prevention and disruption would be strengthened by enabling regulatory and enforcement bodies to share amongst themselves timely information on emerging risks, evolving fraud typologies, and systemic vulnerabilities. Fraud activity frequently spans multiple sectors and jurisdictions, exploiting regulatory gaps, misaligned supervision, delays in information sharing, and inconsistent responses. This underscores the need for greater coherence and coordination across regulatory and supervisory regimes.
In this context, information sharing among regulators, and between regulators and law enforcement, is critical in enabling a coordinated, system wide approach to reducing harm and protecting consumers. The CBA’s view is that regulators should be explicitly permitted to share fraud related intelligence with each other when necessary to drive cross sector supervisory consistency, prevent inconsistent regulatory guidance and enforcement outcomes, and minimize scenarios that enable criminal activity.
The CBA also supports permitting regulators to share fraud related information with law enforcement, based on reasonable judgment, to reduce harm, enable cross sector disruption, support enforcement prioritization, or protect victims. This sharing should be intelligence led and purpose driven, allowing law enforcement to better understand sector wide fraud patterns, prioritize resources, and coordinate responses across jurisdictions. Regulator to law enforcement information sharing should complement, rather than duplicate, private sector reporting and investigative processes, ensuring that insights gained through supervisory oversight contribute meaningfully to broader fraud disruption efforts.
Across both regulator to regulator and regulator to law enforcement information flows, the CBA advocates for privacy safeguards and oversight mechanisms that prioritize clarity, security, and confidence, while remaining grounded in a principle based Framework rather than prescriptive rules. Such safeguards should be supported by pragmatic oversight mechanisms, including common data standards and reporting frameworks, sharing agreements (such as data sharing charters or MOUs3 that clarify permissible use, safeguards, and accountability), and, where appropriate, centralized or federated data capabilities to support consistent access, transparency, and scalability. These mechanisms can reinforce secure by design privacy protection practices and clear accountability while preserving the flexibility needed to respond to evolving fraud threats and reducing interpretive uncertainty that can otherwise discourage timely cooperation.
Reporting fraud‑related information to law enforcement
9. When should law enforcement be permitted to share fraud‑related information with private sector organizations?
10. If so, what specific information should be shared, under what circumstances should it be shared and for what precise purpose should it be shared?
11. What privacy safeguards or oversight mechanisms should be in place for such information‑sharing initiatives?
Response:
The CBA recognizes that law enforcement’s fraud related expertise and situational awareness can play an important role in supporting the prevention, detection, disruption, and investigation of fraud. Timely and actionable intelligence from law enforcement enables private sector organizations to take immediate preventative action, strengthen controls, and prevent further victimization, while also informing their investigative prioritization and helping drive coordinated responses across sectors.
There are working examples of this approach in Canada. In certain cases, law enforcement has shared scam indicators and fraud intelligence with private sector organizations, enabling immediate transaction blocking and intervention, including protections for vulnerable customers such as elderly victims. These experiences demonstrate that law enforcement to private‑sector information sharing is most effective when designed to support disruption and harm prevention, rather than limited to post incident reporting or evidentiary processes.
In this context, the CBA supports permitting law enforcement to share fraud related information with private sector organizations as part of structured, proactive intelligence sharing arrangements, where such sharing clearly supports fraud prevention and disruption objectives and is conducted in a lawful, proportionate manner. Information sharing should be targeted and risk based and may include fraud‑related intelligence such as fraud typologies, methods of operation, emerging threat indicators, and systemic risk signals while prioritizing data desensitization where appropriate.
A critical condition for sustainable law enforcement to private‑sector information sharing is legal clarity and protection for recipient organizations. Private sector entities must be able possess and use the information provided by law enforcement and to be able to act on that information without fear of regulatory sanction or adverse consequence, where actions are taken in good faith and for legitimate fraud prevention or victim protection purposes. Clear expectations regarding downstream use, retention, and accountability will be essential to building confidence and ensuring that information sharing supports effective disruption outcomes, rather than creating unintended legal, privacy, or operational risks.
As reflected in responses to Questions 5—8, the CBA recognizes that effective privacy safeguards and oversight mechanisms are foundational to trusted and sustainable information sharing. A principle‑based approach, supported by common data standards, defined information‑sharing arrangements, and appropriate centralized or federated data capabilities, can reinforce accountability and transparency. It can also support consistent handling of fraud intelligence and enable timely, responsible use of information by private‑sector organizations.
1. Prevention
Governance
12. How should organizations be required to embed compliance with the Framework into their governance models?
Response:
Compliance with the Framework should be underpinned by clear accountability to help ensure it is applied consistently in practice. Framework rules should be integrated into existing risk management and compliance processes, rather than established as standalone constructs. This allows organizations to embed expectations into established governance and decision-making activities, without creating duplicative or overlapping regulatory and governance requirements.
Banks already operate with clearly defined accountabilities across the three lines of defense, risk frameworks, formal escalation and oversight structures, and embedded monitoring and assurance processes, which also support the structured adoption of new or evolving regulatory requirements. Leveraging these arrangements supports proportional and practical implementation, avoids unnecessary duplication or fragmentation, and enables efficient, scalable compliance as risks evolve. At the same time, other in scope sectors may be at different stages of process maturity and may initially require additional guidance, oversight, and enforcement, while still being brought within the Framework. The Framework should therefore set clear expectations for accountability and governance outcomes, while allowing flexibility in how organizations build or transition their programs over time, supporting consistent cross sector implementation and the sustainable evolution of the Framework.
Training
13. How can organizations ensure that anti‑fraud training is effective and how should this be reflected in government policy or legislation?
Response:
The effectiveness of anti‑fraud training (and public education) should be assessed using practical, outcome focused indicators. Effective training should support earlier awareness and prompt appropriate action, consistent with the roles organizations play in preventing, detecting, disrupting, and responding to fraud. For banks, anti‑fraud training is already embedded within broader governance, control, resilience, and regulatory programs.
From a policy perspective, the government should focus on principle-based expectations and avoid introducing prescriptive training requirements, particularly where sectors already demonstrate mature and effective programs. This approach supports consistency, sustainability, and alignment across sectors, while allowing training expectations to evolve alongside the threat landscape.
More broadly, the CBA recognizes that effective anti‑fraud training cannot be limited to organizations alone and must be complemented by strong public education. The government has an important role to play in improving fraud awareness among Canadians by providing clear warnings about fraud, consistent guidance on how to recognize fraud, how to respond when it occurs, and where to report suspected fraud. This includes driving national awareness campaigns and reinforcing messaging through trusted public service touchpoints, consistent with the approach outlined in response to Question 46.
Targeted government funding to strengthen and sustain national initiatives, such as cross‑sector awareness campaigns and the CAFC, could further amplify the impact without duplicating existing efforts. In addition, continued government investment in specialized fraud training across the public sector, including government departments, regulators, law enforcement, prosecutors, and the judiciary would help ensure that enforcement, prosecutorial, and judicial outcomes keep pace with evolving fraud typologies and support consistent application of the Framework across the justice system.
Government policy can support this by setting clear, high‑level expectations for anti‑fraud training and public awareness, while preserving flexibility in how training and education initiatives are designed and delivered across sectors. This outcome‑focused approach recognizes that organizations are at different stages of maturity and allows banks to continue embedding requirements within existing programs, while supporting other sectors as they build or enhance their own capabilities over time.
KYC requirements
14. When and how should organizations be required to validate the identity of users of their services?
Response:
Organizations should validate that users are genuine individuals or businesses and that they are who they claim to be. This includes confirming that the person accessing an account, placing an advertisement, or operating a webpage is authorized to do so. As banks have demonstrated through Know Your Customer (KYC) processes, when implemented appropriately in a manner that mitigates risk while avoiding unintended barriers to access, exclusionary outcomes, or unnecessary service disruption, identity controls can meaningfully contribute to fraud prevention and risk mitigation.
Identity verification at onboarding should be treated as a risk based entry control, applied in a manner proportionate to an organization’s fraud risk, to reduce access by bad actors. In addition, identity verification considerations should not be limited to onboarding alone. Ongoing authentication at the point of access and when executing specific actions (e.g., high‑risk account, security changes, etc.) could be applied where appropriate and where operationally feasible, including stepped‑up or multi‑factor authentication, to help prevent fraudulent activity.
It is also important to recognize that no single solution can fully address identity or authentication risk. Fraud tactics continue to evolve, including through social engineering and increasingly sophisticated impersonation methods. Controls that are effective today will require ongoing reassessment and enhancement over time. In particular, scams can undermine identity and authentication controls by coercing genuine customers into actions that appear legitimate. A layered approach across the broader ecosystem may therefore be appropriate, spanning both digital and non‑digital channels, accounting for dependencies on other services and credentials outside a single organization’s direct control, reinforced through consumer awareness and responsible use of intermediary platforms.
At a Framework level, the Strategy should position customer onboarding and authentication as baseline fraud‑prevention controls applicable across all sectors, establishing a common foundation for mitigating fraud risk. The specific requirements, design, and application of these controls should then be determined by the central regulator and sector‑specific supervisors and entities, while providing organizations with the flexibility to design and implement controls that are proportionate, risk‑based, operationally feasible, and aligned to the risks inherent in their sector, business model, and products and services offered.
Consumer education
15. What fraud‑related information should organizations be required to make available to individuals using or who may use their services?
Response:
The CBA agrees that organizations across all in‑scope sectors should provide clear, accessible, and relevant fraud‑related information to individuals using, or considering using, their services. This information should extend beyond cataloguing specific fraud typologies and focus on common behaviours and warning signs across fraud types, including when it is and is not appropriate to share sensitive information such as one‑time passwords. Individuals should be provided with practical, proactive steps they can take to protect themselves, including how to recognize and verify or test potentially fraudulent requests, along with clear education on available consumer facing tools and controls and how these measures work to reduce fraud risk. Information should be designed for education and prevention, and should not disclose institution specific controls, processes, or decision making thresholds that could be misused by malicious actors.
In addition, organizations should help ensure consumers have clear, accessible information on how to report suspected fraud, submit complaints, and escalate concerns where appropriate, including clearly identifying secure, trusted channels for doing so. Where appropriate, organizations across all sectors should complement these channels with targeted guidance or training (see response to Question 13) to reinforce safe practices and reduce the risk of repeated harm. Consistent with current practice, organizations should not be expected to disclose detailed investigation processes or internal assessments, even to impacted individuals, except through established legal or regulatory channels.
Fraud‑related information requirements should focus on clarity, consistency, and usability for consumers, rather than volume or complexity. Information should be presented in plain language and, where appropriate, aligned with authoritative sources produced by regulators or law enforcement to promote consistent messaging and reduce confusion. This could include reinforcing public education efforts through marketing and awareness campaigns across channels, such as digital, in‑branch, and other customer touchpoints. At the same time, policy should remain flexible in how organizations deliver this information, allowing it to be tailored to the nature of their services, customer base, and fraud risk profile, while supporting coherence across sectors.
16. How should the effectiveness of organizations' fraud education be assessed to ensure that it meaningfully reduces harm?
Response:
Similar to the industry’s response to Question 13, the effectiveness of organizations’ fraud education could be assessed on criteria such as whether the material available to consumers is clear, accessible, and applicable to the scenario(s) in question. Government policy can support this by setting clear, high‑level expectations for anti‑fraud training and public awareness, while preserving flexibility in how education and training initiatives are designed and delivered across sectors. At the same time, it is important to recognize that education driven outcomes may not be immediate; changes in behaviour, reporting patterns, or loss outcomes may lag education efforts and should be assessed over an appropriate time horizon, rather than expected to materialize instantly.
At an entity level, effectiveness can be reflected through high‑level characteristics rather than prescriptive requirements, for example, whether education content remains current and responsive to evolving fraud risks; whether fraud education is integrated into relevant customer journeys and reporting pathways; and whether it supports clear, timely guidance and escalation when indicators of fraud emerge.
At a broader, system level, effectiveness can be assessed through aggregate trends over time, such as increased and more consistent reporting of fraud, improved alignment in consumer messaging across sectors, and reductions in consumer exposure or losses at an ecosystem level.
This framing is intended to support outcomes focused assessment while preserving flexibility for organizations to design and deliver education in a manner proportionate to their sector context, risk profile, and existing governance arrangements.
Sector-specific requirements
17. What sector‑specific fraud prevention rules should be in place?
Response:
The CBA acknowledges the need for a cross-sector approach to fraud prevention. Banks presently implement a mature, layered set of risk‑based controls across the customer lifecycle. These include KYC and identity verification at onboarding, risk‑based authentication and step up measures, customer notifications and warnings, and customer‑controlled security features. Such features may include configurable transaction or account limits, real‑time alerts, and self‑serve options to temporarily restrict access or add additional verification for higher‑risk activity. Banks continue to enhance these controls in response to an evolving threat landscape. However, financial sector controls alone cannot materially reduce fraud volumes where risks originate upstream or outside the financial system.
This underscores the importance of a broader approach to fraud prevention that combines baseline controls (i.e. applicable across all sectors) with targeted, sector‑specific measures. Baseline controls provide a consistent foundation across the ecosystem, recognizing that fraud risks are dynamic, often span multiple, interconnected services, and take advantage of the path of least resistance. Sector‑specific measures, in turn, address distinct risk profiles, operating models, and points of vulnerability within particular sectors.
International experience demonstrates that effective fraud prevention increasingly relies on enforceable baseline and sector‑based rules distributed across the ecosystem. These approaches emphasize "anti‑fraud by design" principles, integrate controls into product and system design, and are implemented in a manner that remains non‑prescriptive, proportionate, and adaptable over time. The illustrative controls outlined below reflect practices emerging in other jurisdictions and are intended to support further dialogue between government, regulators, and sector‑specific entities to ensure the Framework remains risk‑based, feasible, and avoids unnecessary duplication.4
Baseline prevention controls (applicable across all sectors) observed in other jurisdictions:
- Apply risk‑based onboarding and identity validation measures to help reduce access by bad actors
- Implement risk‑based customer authentication controls, such as multi‑factor authentication, where available, and operationally feasible to help prevent unauthorized activity
Sector‑specific prevention controls observed in other jurisdictions:
Telecommunications Providers:
- Support sender ID and caller ID validation or registration measures to reduce spoofing and impersonation
Digital Platforms:
- Implement proportionate review and verification processes to detect and prevent fraudulent or deceptive advertisements and website
2. Detection
General requirements
18. How could organizations be incentivized to effectively detect and investigate potentially fraudulent activity on their services?
Response:
The CBA supports the expectation that all in‑scope cross‑sector entities take proactive steps to identify, detect, and investigate potentially fraudulent activity targeting users of their services. This includes maintaining appropriate resources, capabilities, and governance to detect suspected fraud, investigating potential incidents identified through internal processes or customer reports, and, where fraud is confirmed, taking steps as appropriate, such as informing impacted users and flagging or closing accounts. These activities are foundational to timely intervention, harm reduction, and improved fraud outcomes across sectors.
To incentivize effective detection and investigation, and similar to our response to other questions, the Framework should combine clear expectations, coordinated oversight, and proportionate enforcement. Clear and consistent baseline and sector‑specific rules help reduce uncertainty and support sustained investment in fraud‑management capabilities across sectors. Alignment in supervisory approaches further reinforces incentives by promoting a level playing field and reducing the risk that fraud activity exploits or migrates toward less‑regulated channels.
It is important to note that in practice, privacy is sometimes viewed as a barrier to certain fraud detection methods and information sharing. This reflects differing interpretations of principle‑based privacy law and regulatory guidance, evolving expectations of what is considered reasonable in detecting and preventing fraud, and differences in provincial requirements that may influence mitigation strategies. For example, due to biometric requirements in Quebec, organizations are required to obtain opt-in consent and offer alternatives to individuals for the collection and use of biometrics that may assist in fraud prevention and detection. This includes pending privacy reform that is expected to include the potential for fines and penalties for non‑compliance, which may disincentivize organizations from sharing information key to effective detection and investigation measures due to uncertainties.
Therefore, a risk‑based and balanced approach is necessary, so that privacy protections do not unnecessarily conflict with fraud prevention measures or create unintended consequences. As an example, where consent requirements are relevant, it should be recognized that opt‑in models may create potential gaps in protection due to poor uptake of enhanced safeguards, particularly in impersonation scenarios where bad actors are unlikely to consent to stronger safeguards. It should be made clear that sharing data across sectors may be treated as reasonable conditions of service with appropriate protection and governance in place.
Proportionate and transparent enforcement mechanisms can operate as a supporting measure to ongoing controls and supervision. Enforcement should function as a distinct supervisory function, clearly distinguishing between individual instances of fraud and broader deficiencies in an entity’s control environment.
Together, these measures can encourage continued investment in fraud‑management capabilities and reinforce shared accountability for reducing fraud‑related harm.
Assessing fraud impacts
19. How should organizations be required to assess fraud-related harms to individuals using their services?
Response:
Organizations across all in‑scope sectors should assess fraud‑related harms to individuals using a structured, risk‑based assessment once an organization has determined that fraud has occurred. Practically, this would involve, depending on the nature of the fraud, an initial assessment that is updated and refined as new information becomes available.
As part of this assessment, organizations should identify the nature and severity of harm experienced, which may include temporary or prolonged loss of access to accounts or essential services, compromise of credentials or personal information, and other material impacts relevant to the individual’s circumstances. To ensure a proportionate approach, the role of the consumer should be considered, including an assessment of whether control warnings were disregarded.
Assessing fraud‑related harm in this way enables organizations to calibrate their response proportionately. This includes determining appropriate remediation actions, safeguards to prevent further misuse (such as access controls or account changes), and the level of support required by the impacted individual. A structured harm assessment also supports consistency in responses, while remaining flexible enough to account for differences in services, customer contexts, and fraud scenarios.
20. What actions should organizations be required to take to assess risk of future harm to individuals impacted by fraud?
Following a confirmed fraud incident, organizations typically consider whether there is potential for further harm to affected individuals as part of their existing risk based fraud management practices. This may include assessing whether compromised accounts, credentials, or personal information could be reused, the likelihood of additional fraudulent activity, and whether the individual may face ongoing or related impacts beyond the initial incident, such as identity misuse.
These considerations are generally informed by available information, the fraud typology involved, indicators identified during investigation, and customer specific factors. Such considerations may vary based on the severity, complexity, and evolving nature of the incident. Where appropriate, organizations may apply proportionate protective measures within existing frameworks, such as enhanced monitoring, temporary safeguards or friction, and tailored education or warnings, in a manner that is principle based.
Where fraud activity spans multiple entities or sectors, reporting of confirmed fraud in accordance with an established fraud data‑sharing framework and existing standards (i.e., the Canadian Anti‑Scam Coalition (CASC) Scam Benchmarking and Reporting Framework), alongside appropriate information sharing with relevant parties, can help mitigate ongoing or future harm. This enables earlier preventive action and helps reduce repeat or cascading harm across the broader ecosystem.
Striking a balance requires a risk based and proportionate approach that introduces meaningful friction when fraud is suspected, while preserving continuity of service for users, using targeted controls that activate when defined risk thresholds are met and escalate where risk signals justify action.
Information sharing between organizations
21. When should regulated private sector organizations be able to share fraud‑related information with each other?
22. If so, what precise information should be shared, under what circumstances should it be shared and for what precise purposes should it be shared?
23. What privacy safeguards or oversight mechanisms should be in place for such information sharing initiatives?
Response:
Canada currently relies on a principle‑based framework for private‑to‑private information sharing related to fraud, permitting the voluntary sharing of personal information where certain immediacy, certainty, and consent conditions are met,5 and allowing unrestricted sharing of non‑personal information for fraud‑management purposes. This approach provides important flexibility, particularly given that fraud is constantly evolving and spans multiple sectors, channels, and typologies.
At the same time, this principle‑based approach has resulted in significant interpretive uncertainty, reducing the amount of data sharing done in practice. Differing views on legal and regulatory expectations, combined with concerns about potential non‑compliance or downstream liability, have led many organizations to adopt a narrow and cautious approach to information sharing.6 In practice, this has limited the scale and usefulness of shared intelligence, even where sharing could greatly support fraud prevention and disruption. The current prescriptive regime for voluntary sharing constrains the ability of organizations to adapt to emerging threats.
If the policy objective is to encourage more effective information sharing, the focus should be on reducing uncertainty and barriers, rather than introducing new prescriptive requirements. Greater clarity on what can reasonably and proportionately be shared (particularly with respect to thresholds such as "confirmed" versus "suspected" fraud, synthetic or enriched data, risk indicators, and victim or point‑of‑compromise information) would help align practices, reduce uncertainty, and increase confidence across entities. However, given the uncertainty that would still prevail under any principle‑based approach, we recommend there also be a mechanism to explicitly provide protection from non‑compliance‑related enforcement mechanism that may be introduced as part of federal privacy reform, when organizations operate in good faith to meet the Strategy’s policy objectives. This will best support an environment for information sharing at a scale and scope that will meaningfully address the evolving threat landscape.
The CBA supports private‑to‑private information sharing where it is necessary to prevent, detect, disrupt, or mitigate fraud, including at early stages based on credible risk indicators. Today, organizations often see only activity within their own environments, resulting in fragmented intelligence that is increasingly misaligned with the cross‑sector and distributed nature of fraud. More effective prevention requires timely, proportionate sharing and centralized retention of risk‑relevant information across entities. In practice, this means prioritizing the exchange of risk attributes, typologies, indicators, and detection insights, rather than relying solely on static lists or post‑incident reporting. Sharing should be purpose‑driven and aligned with clear objectives, such as identifying emerging threats, reducing repeat victimization, enabling timely intervention, and strengthening preventive controls across the ecosystem.
The CBA also recognizes that effective privacy safeguards and oversight mechanisms are foundational to trusted and sustainable information sharing. Information sharing should be supported by consistent, secure‑by‑design standards and robust governance, operating within a principle‑based Framework rather than prescribing specific mechanisms. This approach appropriately balances the need for strong privacy protection with the flexibility required to respond to evolving fraud tactics and use cases, while also reducing interpretive uncertainty that can inhibit participation. Importantly, the Personal Information Protection and Electronic Documents Act (PIPEDA) accountability principle already requires organizations to consider and implement appropriate privacy safeguards and oversight mechanisms. Any safeguards and governance mechanisms can be industry‑led, leveraging existing expertise and operating models. For example, within the banking sector, institutions have established the Bank Crime Prevention and Investigation Framework (BCPIF), a framework designed to address such requirements. Major telecommunications providers have implemented a similar sector‑specific framework.
Where more proactive or near‑real‑time intelligence sharing is needed to support prevention and disruption, this capability is best developed through industry‑led mechanisms, including existing industry or cross‑sector consortia. Such arrangements should complement, not replace, existing information‑sharing practices and remain focused on clearly defined and material risk scenarios.
Once the Strategy establishes clearer, ecosystem‑wide expectations and obligations for combating fraud, organizations will be better positioned to demonstrate to privacy regulators that fraud prevention and detection measures are reasonable and proportionate. This would support more consistent interpretation of fraud‑related information sharing, helping reduce uncertainty and other barriers to effective, responsible sharing.
Another potential government enabler for industry‑led models is safe testing rather than prescription. If uncertainty persists despite the measures outlined above, a regulatory sandbox could serve as an optional, confidence‑building tool, allowing entities to pilot real‑time intelligence‑sharing models in controlled environments and within defined regulatory boundaries before any broader scaling.
Reporting fraud‑related information to law enforcement
24. When should organizations be permitted to share fraud‑related information with law enforcement for the purposes of preventing, detecting, disrupting, and investigating fraud?
25. When should law enforcement be permitted to share fraud‑related information with private sector organizations?
Response:
The CBA recognizes that private sector organizations are often the first to detect fraud activity through customer interactions and internal controls. As a result, timely information sharing from the private sector to law enforcement can play a critical role in early disruption of fraud, protecting victims, and limiting the spread of organized and repeat cross sector schemes. The CBA believes the banking industry is willing and prepared to share relevant fraud intelligence, particularly where doing so can enable coordinated action and reduce harm.
Recent cross sector initiatives, such as the Maple Disruption7 and Project Nova8 exercise, demonstrate the value of this approach in practice. In that context, private sector entities shared confirmed fraud indicators, such as fraudulent domains, email addresses, IP addresses, and phone numbers, without disclosing victim personal information, resulting in measurable disruption over a short period. This experience illustrates that intelligence led sharing can be effective when focused on disruption and prevention, rather than solely on evidentiary standards required for prosecution.
Accordingly, the CBA supports permitting private sector organizations to share fraud related information with law enforcement not only on a reactive, case specific basis, but as part of more proactive, intelligence driven models where there are reasonable grounds to suspect criminal activity, significant consumer harm, or systemic risk. Information sharing should be guided by clear thresholds and objectives and, to enable timely sharing when needed, should not require private sector organizations to compile investigation ready or prosecution ready case files before sharing relevant information.
Despite demonstrated willingness to share, as well as proven use cases, information sharing from the private sector to law enforcement is often constrained by practical and systemic barriers. These include uncertainty arising from principle-based privacy interpretations, concerns about downstream use or misinterpretation of shared information, fragmented reporting channels, inconsistent expectations across jurisdictions, and the absence of common data standards. In addition, fear of regulatory, legal, or reputational consequences for good faith disclosures can discourage timely escalation or result in overly conservative, retrospective reporting. The CBA’s view is that government can play a constructive role in addressing these barriers by providing clearer guidance on permissible disclosures and escalation thresholds and reinforcing protections for organizations that share information in good faith for fraud prevention or disruption purposes, enabling more streamlined, consistent channels for engagement with law enforcement. Such actions would reduce uncertainty, encourage proactive participation, and help shift information sharing toward earlier, intelligence led intervention rather than delayed, case‑by‑case reporting.
The CBA also recognizes that effective privacy safeguards and oversight mechanisms are foundational to trusted and sustainable information sharing. Such safeguards should make an effort to prioritize clarity, security, and confidence, supported by secure‑by‑design standards and governance, operating within a principle‑based Framework rather than prescribing specific mechanisms. Complementary oversight mechanisms, such as common data standards, sharing agreements where needed (e.g., data sharing charters or MOUs), and centralized or federated data capabilities would further improve consistency, accountability, and scalability, while enabling secure, real‑time access to high‑value fraud intelligence and reducing duplication across entities.
The industry also emphasizes the importance of feedback loops, including outcome confirmation where feasible, to allow private sector organizations to refine controls, prevent repeat harm, and better understand the impact of shared intelligence, recognizing that current practices are inconsistent across jurisdictions.
26. When should the government be permitted to share fraud‑related information with law enforcement?
27. When should the government be permitted to share fraud‑related information with private sector organizations?
28. If so, what specific information should be shared, under what circumstances should it be shared and for what precise purpose should it be shared?
29. What privacy safeguards or oversight mechanisms should be in place for such information sharing initiatives?
Response:
The CBA supports permitting government to share relevant fraud insights with law enforcement and private sector organizations when doing so is necessary to reduce harm, support cross sector disruption strategies, inform enforcement prioritization, or protect consumers. Even where information is limited to aggregate indicators, typologies, and trend data, such insights can materially improve the understanding of sector wide and national threat dynamics and support more effective allocation of resources and coordinated responses across jurisdictions. Government information sharing should complement current reporting and investigative processes, ensuring that insights derived from supervisory oversight contribute meaningfully to broader fraud disruption efforts without creating parallel or overlapping reporting obligations.
Across both government to private sector and government to law enforcement information flows, the CBA welcomes continued engagement to better understand the types of fraud related data government entities hold, the level at which that data can be shared, and how it can most effectively support prevention and disruption objectives. While the specific scope and use of such data would benefit from ongoing dialogue, the CBA’s view is that at a high‑level, any sharing should be supported by privacy safeguards and oversight mechanisms that make an effort to prioritize clarity, security, and confidence, while remaining grounded in a principle‑based Framework rather than prescriptive rules.
Complementary governance arrangements could include pragmatic mechanisms such as common data standards and reporting frameworks for high level or aggregate information, clearly defined sharing arrangements (for example, data sharing charters or MOUs that clarify permissible use, safeguards, and accountability), and, where appropriate, centralized or federated data capabilities to support consistent access, transparency, and scalability. These mechanisms can reinforce secure by design practices and clear accountability while preserving the flexibility needed to respond to evolving fraud threats and reduce interpretive uncertainty.
Considering the Strategy’s goal to address fraud at large, one area where government‑to‑private sector information sharing could make substantive, near‑term progress relates to income fraud for mortgages. Income fraud for mortgages makes homes even less affordable for the average Canadian. While the United States and United Kingdom have had tax authority‑to‑financial institution income data sharing in place for over a decade, Canada remains a laggard. The Canada Revenue Agency (CRA) should implement a tool to digitally share, with taxpayer consent, its income data with financial institutions. Income verification between the CRA and financial institutions would prevent mortgage fraud and allow resources to be re‑deployed within financial institutions to target higher‑risk fraudsters.
Sector-specific requirements
30. What sector-specific fraud-detection rules should be in place?
Response:
The CBA acknowledges the need for a cross-sector approach to fraud prevention. Banks operate a mature, layered set of risk based controls, such as transaction monitoring (including real time monitoring where appropriate), alert triage, and investigation and escalation processes. Banks continue to enhance these controls in response to an evolving threat landscape. However, financial sector controls alone cannot materially reduce fraud volumes where risks originate upstream or outside the financial system.
Consistent with the response to Question 17, this underscores the importance of a broader approach to fraud detection that combines baseline rules and controls applicable across all sectors with targeted, sector specific measures. Baseline controls provide a consistent foundation across the ecosystem. Sector specific measures, in turn, address distinct risk profiles, operating models, and points of vulnerability within sectors, recognizing that not all sectors are positioned to detect the same risks at the same point in the fraud lifecycle.
International experience demonstrates that effective fraud detection increasingly relies on enforceable baseline and sector based rules and controls distributed across the ecosystem. These approaches emphasize "anti‑fraud by design" principle, integrate controls into product and system design, and are implemented in a manner that remains non prescriptive, proportionate, and adaptable over time. The illustrative controls outlined below reflect practices emerging in other jurisdictions and are intended to support further dialogue between government, regulators, and sector specific entities to ensure any Framework remains risk based, feasible, and avoids unnecessary duplication.9
Baseline detection controls (applicable across all sectors) observed in other jurisdictions:
- Engage in timely, privacy‑conscious, data and intelligence sharing of confirmed fraud and relevant risk indicators to improve visibility and support coordinated, intelligence‑led cross‑sector detection
- Coordinate with relevant federal and provincial authorities (including regulators) to support joint investigations and prosecution outcomes
- Enable appropriate customer reporting channels to support prompt reporting of suspicious activity
- Maintain and submit fraud‑related information in accordance with an established fraud data‑sharing and reporting framework and standards
Sector‑specific detection controls observed in other jurisdictions:
Financial Services:
- Monitor account activity, where appropriate and feasible, for the purposes of identifying potentially fraudulent activity
Telecommunications Providers:
- Implement monitoring capabilities to identify high‑risk SMS and call characteristics (e.g., spoofing indicators, malicious links, abnormal sending patterns)
- Detect high‑risk devices, SIMs, or traffic patterns (e.g., repeated fraud attempts, abnormal volumes, known malicious sources)
Digital Platforms:
- Implement monitoring capabilities to identify fraudulent content and accounts, including impersonation or spoofing of individuals, brands, websites, advertisements, or applications
3. Disruption
Removing known fraudulent actors
31. How can a balance be struck to limit use of industry infrastructure for fraudulent purposes, while ensuring that legitimate users are not unreasonably cut off from use of services?
Response:
Striking the right balance requires a risk‑based and proportionate approach that introduces meaningful friction where fraud is suspected while preserving continuity of service for legitimate users. Rather than relying on blanket suspensions or rigid rules, controls should be designed as graduated intervention mechanisms that escalate only where risk signals justify action.
In practice, this balance can be supported using time‑bound controls, where appropriate and feasible, that activate when defined risk thresholds are met, and that are intended to be calibrated to the severity and confidence of the fraud risk identified. This helps enable organizations to intervene early enough to help prevent or mitigate harm, while recognizing that false positives are an inherent risk of any fraud detection framework.
A layered approach across all in‑scope sectors further supports balance. Agreeing on a set of shared expectations across all sectors, with additional measures tailored to each sector, helps ensure that each industry contributes to reducing harm and protecting Canadians. Upstream measures within telecommunications networks can reduce the origination of fraudulent activity before it reaches consumers, while digital platforms can limit amplification by removing high‑risk content or accounts in a proportionate manner. Within financial services, transaction‑level friction and customer engagement at critical moments may help interrupt fraud without defaulting to full‑service termination.
Taken together, a model built on risk‑based thresholds, proportional escalation, and cross‑sector coordination helps restrict fraudsters’ access to infrastructure while maintaining fairness, usability, and trust for legitimate users.
Pausing potentially fraudulent activity
32. In what situations should regulated entities be required to pause potentially fraudulent activity?
Response:
Pausing of activity that may be fraudulent should be done within the contractual limits of the financial institution's arrangement with its customer and exercised using the financial institution’s commercially reasonable judgement. Activity may be paused where there is an indication of elevated fraud risk that presents as credible, and where a temporary pause enables further assessment or appropriate customer engagement. In doing so, entities should seek to balance fraud prevention with the risk of false positives, recognizing that there will be an impact on customers, while guarding against actions that would unreasonably disrupt legitimate customer activity or result in unnecessary denial of service. Clear and proactive communication of these practices can help manage customer expectations and mitigate frustration when temporary pauses occur.
In practice, pausing activity is most appropriate in situations where defined risk indicators or strong anomaly signals are present that have become recognized to financial institutions as indicators of fraud. This pausing of activity would be preventive rather than punitive, and creates the opportunity for validation, clarification, or intervention.
As part of the development of enforceable sector codes, requirements should therefore enable risk based intervention mechanisms that allow organizations across all in‑scope sectors to temporarily slow or suspend activity while assessments are undertaken, including:
- Financial Services: Apply temporary holds or delays on transactions or actions flagged as potentially suspicious, where appropriate, operationally feasible10 and aligned with existing frameworks
- Telecommunications Providers: Apply temporary blocks or restrictions of suspected high‑risk calls or messages (e.g., those exhibiting spoofing indicators, malicious links, or abnormal sending patterns), where appropriate and operationally feasible
- Digital Platforms: Apply temporary restrictions, suspensions, takedowns or review holds on suspected fraudulent content, accounts, links, or advertisements, where appropriate and operationally feasible
Importantly, expectations to pause activity should be clearly scoped and proportionate, with requirements refined through consultation to ensure interventions are operationally feasible and aligned with existing fraud management frameworks across sectors.
33. What measures, safeguards and recourse should be put in place to ensure that individuals' access is not improperly suspended or removed?
Response:
Safeguards should be built into fraud‑intervention processes to limit unintentional impacts to legitimate users. In current practices, financial service organizations typically apply established risk‑based assessments and intervention approaches designed to protect customers, while attempting to minimize unnecessary disruption.
Where activity is paused or access restricted, customer communication or outreach may be used to validate concerns and clarify intent where appropriate and feasible. This should be applied at the organization’s discretion in a manner that reflects the circumstances, the fraud risk, and security considerations (including where outreach itself could increase risk or enable further harm). Importantly, the Framework should also be developed to help ensure that organizations are not held liable or subject to regulator complaint for proportionate measures implemented in good faith, based on reasonable risk indicators, to prevent or mitigate suspected fraudulent activity, recognizing that false positives can occur despite appropriate controls.
Standard customer service and complaint channels should remain available to consumers and should operate in a way that does not weaken necessary protective controls or create pathways that fraudsters can exploit.
Warnings to users
34. How can notifications of suspected fraudulent activity be effective?
Response:
Notifications of suspected fraudulent activity may be limited in their effectiveness when issued by financial services alone, as fraud typically originates upstream within telecommunications providers and digital platforms before it reaches the financial services sector where fraud is monetized. Financial institutions can only act on the information available to them at the point of transaction; if notifications do not occur before or during the customer’s execution window, often lasting seconds or a few minutes, it is frequently too late to prevent harm. What is most effective is robust information and data sharing across sectors, enabling earlier identification of fraud patterns and coordinated intervention before fraudulent activity reaches consumers.
Notifications are most effective when delivered upstream, at the point where fraud originates. As such, notification expectations are best implemented through sector specific codes that reflect each sector's role and technical realities, where operationally reasonable. Used alongside other controls, targeted notifications can prompt protective actions (e.g., password resets) when an organization detects fraudulent activity or identifies users impacted by fraud.
Sector-specific requirements
35. What sector-specific fraud disruption rules should be in place?
Response:
The CBA acknowledges the need for a cross‑sector approach to fraud disruption. Financial institutions already implement risk‑based controls, including payment‑level friction and interventions where appropriate and operationally feasible. Institutions continue to enhance these controls in response to an evolving threat landscape. However, financial sector controls alone cannot materially reduce fraud volumes where risks originate upstream or outside the financial system.
Consistent with responses to Questions 17 and 30, this highlights the need for a broader, collective approach to fraud disruption that brings together baseline measures applicable across all sectors alongside targeted actions that reflect sector specific roles and points of influence. Baseline measures help promote timely and consistent intervention across the ecosystem, while sector specific disruption actions recognize differences in capabilities, authorities, and touchpoints within the fraud lifecycle.
Experience in other jurisdictions suggests that successful fraud disruption frameworks rely on coordinated, cross sector participation rather than prescriptive, one‑size‑fits‑all requirements. These approaches are grounded in "anti‑fraud by design" principles and implemented in a flexible, proportionate manner that can adapt over time. The illustrative measures outlined below are drawn from international practice and are intended to support continued engagement between government, regulators, and sector specific entities to ensure any approach remains risk‑based, practical, and avoids unnecessary duplication.11
Baseline disruption controls (applicable across all sectors) observed in other jurisdictions:
- Engage in timely, privacy‑conscious, data and intelligence sharing of confirmed fraud and relevant risk indicators to improve visibility and support coordinated, intelligence‑led cross‑sector disruption
- Coordinate with relevant federal and provincial authorities (including regulators) to support fraud reporting, joint investigations and prosecution outcomes
Sector‑specific disruption controls observed in other jurisdictions:
Financial Services:
- Apply intervention mechanisms (i.e., temporary holds/delays, step‑up review) where appropriate and operationally feasible
Telecommunications Providers:
- Disrupt or block high‑risk SMS and call activity before it reaches consumers by identifying indicators such as spoofing, malicious links, or abnormal traffic patterns
- Disrupt or block high‑risk devices, SIMs, or traffic patterns at the network‑level (e.g., repeated fraud attempts, abnormal volumes, known malicious sources)
Digital Platforms:
- Remove fraudulent content and accounts, including impersonation or spoofing of individuals, brands, websites, advertisements, or applications once identified
- Notify users, where appropriate, when content, accounts, or advertisements they have interacted with are removed or restricted due to fraudulent activity
- Provide a dedicated reporting channel for entities to flag platform‑hosted fraudulent activity
4. Response
Receiving information about fraud activity
36. How should organizations be required to make it easy for users to report fraud activity to them?
Response:
The CBA is supportive of the expectation that organizations make fraud reporting clear, accessible, and easy to use. Accessible customer reporting channels should be considered a baseline control applicable across all in‑scope sectors, given their foundational role in enabling timely detection, investigation, and disruption of fraud.
Clear and accessible reporting mechanisms allow individuals to promptly report suspected fraud and enable organizations to act on those signals before harm escalates. As such, customer reporting should be treated as a core component of the Framework, regardless of sector, rather than as a sector‑specific or optional measure.
Reporting channels can also be supported by consumer education and guidance, helping individuals understand when and how to report suspected fraud, while reinforcing that reporting to an organization does not limit or replace their ability to also report fraud to law enforcement.
Internal dispute resolution
37. How could organizations effectively investigate cross‑sector complaints?
38. How long should organizations have to internally investigate complaints?
39. What information should organizations be required to include in a summary of complaint?
Response:
The CBA recognizes that effective internal dispute resolution (IDR) processes are essential to maintaining trust, particularly where individuals believe a service provider has not met its anti‑fraud expectations. Most complaints can be addressed through existing IDR processes, which already promote efficiency, consistency, and procedural fairness.
Effective investigation within IDR depends on customers being able and willing to provide timely and accurate information to support fact‑finding, such as what happened, relevant dates, transaction details, and information about their own behaviour or devices. Where indicators suggest a cross‑sector scenario, targeted information sharing between implicated parties, supported by a police and CAFC report filed by the complainant, may be necessary to confirm scope, address potential information gaps, and support downstream processes. In practice, this will require appropriate customer consent, safeguards, and / or legislative permission; without these, cross‑sector complaints cannot be investigated effectively.
Complaint handling should balance transparency with proportionality and practicality, particularly where information may be shared beyond the organization. The focus should be on clearly communicating outcomes and next steps to customers, without requiring disclosure of internal controls or investigative methods.
Given the complexity of multi‑sector dispute resolution, it is imperative for the government to discuss implementation options with banks. Further work will be required in this area, and the CBA looks forward to continued engagement through the consultation process.
Liability in the event of non‑compliance
40. Should organizations be held liable when they do not fulfill their obligations under the Framework?
41. What standards should apply in determining whether an organization fulfilled its obligations?
42. How should liability be apportioned when multiple organizations have not fulfilled their obligations?
Response:
From the CBA’s perspective, liability, standards of care, and apportionment under the Framework are closely linked and depend on how rules and controls are defined across the ecosystem, including for regulated entities and the individuals they serve. The priority should be to establish clear and practical rules, controls, and standards as a foundation for consistent and workable liability or reimbursement outcomes.
Compliance should be assessed using a commercial reasonableness standard, focused on whether appropriate controls were maintained and whether compliance with defined rules can be demonstrated. Where an entity is required to reimburse consumers as a liability outcome, this should generally address the incident itself, with additional enforcement measures reserved for situations involving systemic issues or recurring patterns of non‑compliance.
In multisectoral scenarios, responsibility will need to be apportioned in a clearly defined manner across all in‑scope sectors involved, taking into account any contributory failure or negligence of the consumer defrauded. Reimbursement mechanisms should support accurate fact‑finding, recognizing that automatic or upfront reimbursement could reduce incentives for customer vigilance. Given these considerations, further work will be required in this area, and the CBA looks forward to continued engagement through the consultation process.
External dispute resolution
43. What should inform how an external complaint body is chosen?
44. Should decisions of the external complaint body be binding?
45. How long should the external complaints body have to investigate escalated complaints?
Response:
In considering how an external dispute resolution (EDR) body should be selected, the CBA views neutrality and cost‑effectiveness as central considerations. Consistency is best achieved through clearly defined standards, and governance arrangements, rather than reliance on broad discretion. The overall design should support a single, escalation pathway for cross‑party cases, while avoiding fragmentation or unnecessary duplication alongside existing dispute‑resolution mechanisms.
Where a complaint involves multiple parties, or where an IDR process does not resolve the matter, EDR can provide an independent forum. To operate effectively, the EDR body must have the ability to request and assess information across parties. In practice, this means that investigation timelines should be realistic and proportionate, reflecting the steps required to obtain and assess information, while acknowledging the complexity of multi‑sector scenarios. As fraud and anti‑fraud methods and systems evolve, dispute volumes and investigative demands are likely to grow; the EDR body should therefore be able to anticipate demand and scale capacity over time.
Across all aspects of the Framework, processes should protect confidentiality and avoid disclosures that could enable further fraud or expose sensitive operational details. Given these considerations, further work will be required in this area, and the CBA looks forward to continued engagement on potential options as the consultation progresses.
Empower Canadians to act against fraud
46. How can the government improve Canadians' awareness of the threat posed by fraud and better position them to protect themselves against fraud?
Response:
The government can improve Canadians’ awareness of fraud most effectively by amplifying credible, cross‑sector public education efforts at a national scale, reinforcing consistent messaging, and using trusted public service touchpoints to reach individuals before harm occurs. Public awareness and education are critical to an effective national anti‑fraud response, as informed individuals are better positioned to recognize, avoid, and report fraud early. As fraudsters increasingly use artificial intelligence to make scams more convincing and to operate at greater scale, it is essential that public awareness efforts remain aligned with an evolving threat landscape.
As fraudulent schemes continue to grow in both volume and sophistication, individuals are often exposed to risk before authorities or service providers can intervene. Strengthening public awareness supports earlier detection, informed decision‑making, and preventative action, while also reducing stigma, increasing reporting, and strengthening information‑sharing across communities.
International experience demonstrates the positive impact sustained public awareness campaigns can have on reducing fraud harm. In the United Kingdom, targeted public‑education campaigns, such as the Take Five initiative, have translated into measurable outcomes, with banks stopping £870 million in unauthorized fraud (a 20 per cent year‑over‑year increase in fraud prevented) and remote banking fraud losses declining by nearly a quarter.12 Similarly, Canada already has a strong foundation to build upon through cross‑sector initiatives such as the Canadian Anti‑Scam Coalition’s national Stand Against Scams campaign. To date, this campaign has operated under a coalition‑of‑the‑willing model, with significant industry commitment, including cash and in‑kind contributions. While this model demonstrates strong engagement, it faces limitations in achieving the scale required to consistently reach all Canadians.
There is a clear opportunity for government to play a more active amplifying role, extending reach, credibility, and consistency of messaging without assuming operational control of campaign design or delivery. In particular, government can reinforce awareness through existing federal channels and trusted service interactions, including the CRA, Service Canada, and programs related to the Canada Pension Plan and Old Age Security. Targeted government funding could further strengthen and sustain national initiatives, such as cross‑sector awareness campaigns and the CAFC, by leveraging existing infrastructure, supporting sustainable delivery, and enabling more tailored outreach to populations facing elevated risk or distinct vulnerabilities, including youth, seniors, and Indigenous communities. Collectively, this approach would expand national reach while strengthening awareness, preventative behaviours, and fraud‑reporting outcomes across Canada.
47. How can the government improve Canadians' awareness about the risk of misuse of government‑issued identifiers, including social insurance numbers?
Response:
The government can improve Canadians’ awareness of the risks associated with misuse of government‑issued identifiers by reinforcing clear, consistent, and practical public education on when such identifiers are legitimately required, how they are commonly misused in fraud and impersonation schemes, and the steps individuals should take if compromise is suspected. Messaging should encourage individuals to exercise caution and question unexpected or unsolicited requests, while also recognizing that government‑issued identifiers may be lawfully required or appropriately used by trusted institutions for legitimate purposes.
Awareness efforts should be carefully balanced. Overly broad guidance, such as encouraging individuals to never provide identifiers, could unintentionally discourage legitimate use (e.g., for KYC or credit risk assessment purposes), create confusion, or introduce unnecessary friction when accessing essential services. In some cases, sharing identifiers delivers clear benefits to individuals and supports safeguards that help prevent error and misuse.
From the CBA’s perspective, public awareness efforts would be effective if integrated into existing national fraud‑education initiatives and amplified through government service interactions, including those related to taxation, benefits, and identity‑related services. Targeted messaging that highlights common government‑impersonation tactics, the downstream risks of identifier compromise (such as account takeover or benefit fraud), and reporting pathways can help individuals better recognize and respond to these threats.
Finally, coordinated messaging across government, regulators, and ecosystem entities can strengthen credibility, reduce confusion, and reinforce consistent guidance, supporting earlier reporting and more effective prevention of identity‑related fraud.
Support law enforcement’s ability to combat fraud
The Canadian Anti-Fraud Centre
48. What can be done to support federal law enforcement's ability to investigate fraud and collect fraud‑related intelligence?
49. What should be done to improve coordination between Canadian law enforcement across federal, provincial and territorial and municipal levels, and between those law enforcement bodies and international partners?
50. What role should the CAFC play in advancing the Strategy?
Response:
The Strategy should reinforce Canada’s approach to financial‑crime prioritization, intelligence gathering, and coordination across investigative and enforcement functions, supported by sustained investment in specialized expertise and modern analytical and investigative tools. Strengthening investigative effectiveness will also require reducing reliance on slow, manual, and retrospective processes by improving data integration, AI usage, analytics, and secure information sharing so intelligence is timely, usable, and supports earlier operational action. Importantly, any new intelligence or reporting requirements should be designed to complement existing mechanisms or initiatives and avoid unnecessary duplication.
As implementation of the Strategy advances, it will be important that roles and mandates across the ecosystem, including federal, provincial/territorial, and municipal bodies, as well as newly established entities, are clearly articulated, and aligned. This should be supported by clear accountability and escalation pathways to avoid overlapping mandates, fragmented ownership, and inefficiencies that can dilute impact. In this context, the mandate of the proposed Financial Crimes Agency (FCA) will need to be clearly defined to ensure it operates as the federal authority responsible for leading and coordinating financial crime enforcement, without duplicating existing investigative, regulatory, or intelligence functions carried out by other organizations.
Improving coordination between Canadian law enforcement across federal, provincial/territorial, and municipal levels, and with international partners, will require a clearer, intelligence informed operating model supported by well defined roles, sustained resourcing, and stronger coordination mechanisms. This includes the ability to rapidly mobilize coordinated, time bound disruption efforts when organized fraud activity is identified, supported by adequate operational capacity, and moving beyond ad hoc, manual approaches that are difficult to scale. Equally important is strengthening law enforcement and prosecution capacity to ensure fraudsters are effectively investigated and brought to justice. Reports13 show that a significant proportion of fraud cases do not proceed due to limited resourcing and capacity, underscoring the need for targeted investment in investigative, prosecutorial, and analytical capabilities. Initiatives such as Operation Maple Disruption demonstrate how well‑resourced, intelligence‑led, and coordinated public‑private efforts can disrupt fraud activity more effectively and reduce harm when operationalized at speed.
Within this broader governance model, the CAFC should continue to serve as Canada’s primary fraud‑reporting and intelligence‑aggregation hub, rather than an investigative or enforcement body. The CAFC plays a critical role in consolidating reports, identifying trends, and generating system‑level insights that inform prevention and enforcement priorities. A centralized reporting function, supported by clear governance, common data standards, and proportionate reporting expectations, enables a consistent, national view of fraud activity without duplicating enforcement functions.
A coordinated, whole of government approach, supported by formal governance structures, shared priorities, amended regulatory environment and secure and risk certain information sharing mechanisms, can enable each organization to contribute within its area of authority and expertise. Clear articulation of how the FCA, CAFC, regulators, and other public sector bodies interact and support one another will be critical to ensuring coherence, reducing fragmentation, and maximizing the collective impact of Canada’s response to fraud.
Conclusion
A well‑designed Strategy is essential to strengthening Canada’s economic resilience and maintaining public confidence. By aligning clear definitions with a cross‑sector framework, baseline controls, improved fraud‑data sharing, and effective public education, the Strategy can meaningfully reduce fraud and harm at scale. Its success will depend on thoughtful implementation, effective oversight, and sustainable resourcing, supported by the ability to adapt as threats and technologies evolve.
As the Government of Canada advances this cross‑sector strategy, the CBA recognizes the importance of proceeding in a timely and deliberate manner. This includes clearly defining the legislative, regulatory, and operational enablers needed to support effective implementation, while strengthening prevention, disruption, investigation, intelligence‑informed decision‑making, and safety outcomes for Canadians.
The CBA appreciates the opportunity to provide its view, on behalf of its members, and looks forward to continued collaboration as the Strategy and Framework are refined and implemented. Ongoing engagement with the Department of Finance is welcomed, and the CBA will continue to share consolidated industry perspectives as this work progresses.
Anthony G. Ostler
President & Chief Executive Officer, Canadian Bankers Association
1 CAFC 2025 statistics available at: antifraudcentre-centreantifraude.ca/index-eng.htm
2 While payment networks and operators should not be subject to the same expectations given their role, they play a significant role within the NAFS by embedding system wide safeguards and cascading fraud prevention requirements across their participant networks.
3 Memoranda of understanding are commonly used in Canada as a formal mechanism to support coordinated information‑sharing between regulators, available at: Office of the Privacy Commissioner of Canada and Information and Privacy Commissioner of Ontario MOU, 2025
4 Jurisdictions studied to inform the list of baseline and sector-specific prevention controls includes the European Union, Australia, United Kingdom, Singapore, and New Zealand
5 Anchored by s. 7(3)(d.1) and (d.2) of the Personal Information Protection and Electronic Documents Act (PIPEDA)
6 For example, in their guidance on the application of PIPEDA s. 7(3)(d.1) and (d.2), the Office of the Privacy Commissioner advises such information sharing be considered on a case-by-case basis, which many interpret as limiting sharing at scale
7 Maple Disruption Initiative available at: antifraudcentre-centreantifraude.ca/features-vedette/2025/12/maple-disruption-operation-erable-eng.htm
8 Project Nova Initiative available at: rcmp.ca/en/news/2025/04/project-nova-canadian-law-enforcement-continues-disruption-criminal-labhost-users
9 Jurisdictions studied to inform the list of baseline and sector-specific prevention controls includes the European Union, Australia, United Kingdom, Singapore, and New Zealand
10 These interventions introduce friction that must be balanced against the government’s broader direction toward real‑time payments and open banking WRITE access, which prioritize speed and seamless execution
11 Jurisdictions studied to inform the list of baseline and sector-specific prevention controls includes the European Union, Australia, United Kingdom, Singapore, and New Zealand
12 Take Five to Stop Fraud – Over £600 million stolen by fraudsters in the first half of 2025 available at: takefive-stopfraud.org.uk/news/over-600-million-stolen-by-fraudsters-in-first-half-of-2025/
13 CBC report available at: cbc.ca/news/canada/toronto/majority-of-ontario-fraud-cases-tossed-since-2020-due-to-limited-resources-crowns-association-9.7004743