National Anti-Fraud Strategy Discussion Paper
Issue
Budget 2025 announced the government's intention to develop a whole-of-government National Anti-Fraud Strategy (the Strategy), based on a multi-sector approach to protect Canadians from evolving and highly complex fraud schemes. The Strategy will seek to develop anti-fraud solutions across the financial and telecommunications sectors, as well as digital platforms. The Strategy will also seek to advance measures to support criminal enforcement of fraud and to address fraud targeting the Government of Canada.
This discussion paper seeks public feedback on three initial measures that could be taken to advance the Strategy:
- Establishing a comprehensive Multi-Sector Anti-Fraud Framework to protect Canadians that could introduce new (and enhance existing) market-conduct requirements for regulated organizations to take measures to prevent, detect and disrupt fraud perpetrated against Canadians and to respond when fraud occurs, ensuring that Canadians do not bear liability when regulated organizations fail to fulfill obligations. This could include:
- a general set of requirements applicable to all industries
- a sector-specific set of requirements
- Strengthening public awareness to position Canadians to better protect themselves against fraud, leading to reduced exposure to fraud and supporting improved outcomes.
- Supporting law enforcement's ability to combat fraud by establishing narrowly defined and minimally invasive rules for information sharing and strengthening national coordination of efforts to fighting cross-border fraud by police of jurisdiction at the federal, provincial and territorial and municipal levels.
Scope
The initial focus of the Strategy will be on fraud categories targeting individual Canadians, extending to small organizations where appropriate.
The following types of fraud, regardless of source, could be considered in scope:
An attempt, whether or not successful,
- to deceive or coerce an individual into authorizing a payment or transferring funds or sharing their personal or financial information in order to cause loss or harm to an individual
- to obtain, or to deceive an individual into sharing, personal or financial information in order to cause loss or harm to an individual
- to gain access to or use an individual's financial account in order to cause loss or harm to an individual, or
- to impersonate clients to access federal government accounts or to redirect payments
Financial Crimes Agency
Budget 2025 announced that government would establish a new Financial Crimes Agency (FCA) to investigate complex cases of money laundering, organized criminal activity and online financial scams, and to recover illicit proceeds of crime. While the Strategy will aim to support law enforcement's capacity to combat fraud, this paper is not seeking feedback on the establishment of the FCA.
Current state
Evolution of fraud
Fraud in Canada continues to grow in both scale and sophistication, with fraudsters increasingly using new technologies to target Canadians. As a result, financial losses have risen sharply. In 2025, Canadians reported losing more than $704 million to fraud, bringing total reported losses since 2022 to over $2.4 billion. With only an estimated 5 to 10 per cent of incidents reported, the true impact is likely far higher.
Fraudsters work across multiple sectors to defraud Canadians, engaging prospective victims through misleading and coercive emails, texts, phone calls and social media posts, and paid advertisements, either gaining access to consumers' bank accounts to directly transfer funds to themselves, or deceiving or coercing consumers into sending money.
Fraudsters are often not located in Canada, and are able to perpetrate fraud remotely, regardless of international and provincial and territorial borders. Fraudsters are increasingly leveraging technological advances, such as artificial intelligence (AI), to obfuscate their identity and convince victims to share information so that they can access victims' funds.
Fraudsters increasingly leverage government-issued identifiers, such as social insurance numbers, to compromise both government accounts and private sector financial accounts. Misuse of these identifiers can enable large-scale identity theft, the generation of synthetic identities, and cross-sector fraud.
The advance of sophisticated technology adds complexity to fraudulent acts while facilitating fraudsters' access to tactics and techniques, further contributing to this constantly evolving threat to Canadian individuals and the Canadian economy.
Existing regulatory obligations
Fraud is a criminal offence defined in the Criminal Code.
There are some marketplace rules in place that protect Canadians from fraud. But these rules have limitations and are typically industry-specific, with little-to-no cross-sector coordination (for example, between banks and telecommunications providers).
Broadly, Canada’s anti-spam legislation aims to protect consumers across sectors from electronic threats including identity theft, phishing and the spread of malicious software. However, businesses are not required to proactively detect, disrupt, prevent and respond to threats with respect to fraud.
Within the federal financial sector, consumers have limited liability for unauthorized transactions made from their debitFootnote 1 and creditFootnote 2 cards, provided they were not grossly negligent (or, in Quebec, demonstrated gross fault) in safeguarding their cards, their account information or their personal authentication information. However, these protections do not extend to other forms of account-based transactions (such as wire transfers). Bank account holder agreements typically elaborate on consumer conduct banks consider to be suggestive of payment authorization or gross negligence.
As a first step of the Strategy, the government has introduced proposed amendments to the Bank Act to strengthen fraud-related consumer protections. Bill C-15: An Act to implement certain provisions of the budget tabled in Parliament on November 4, 2025 proposed amendments which would require banks to:
- have policies and procedures to detect and prevent consumer-targeted fraud and to mitigate its impacts for consumers
- obtain the express consent of consumers before enabling prescribed account capabilities
- allow consumers to disable prescribed account capabilities
- allow consumers to adjust withdrawal and transaction limits associated with their accounts
- annually report prescribed fraud-related data to Financial Consumer Agency of Canada (FCAC)
The government is developing regulations to further specify fraud-related obligations for banks. FCAC would be responsible for supervising and enforcing compliance by banks with these consumer protection requirements once regulations are in force.
Telecommunications service providers (TSPs) are generally prohibited from interfering with communications traffic, including phone calls, text messages or email. However, the Canadian Radio-television and Telecommunications Commission (CRTC) has developed a number of requirements for TSPs to mitigate nuisance, illegitimate and fraudulent voice calls via blocking or flagging.
In addition to the above, certain TSPs have developed other methods of identifying suspected fraud communications and flagging the calls to recipients who may then answer or decline the call. This includes AI-powered tools to detect suspicious calls. Some TSPs have also received the CRTC's permission to block known spam calls, whereby the TSP terminates the incoming call before it gets to the intended recipients.
The unsolicited telecommunications rules that deal with practices such as cold calling can help reduce fraud. However, these rules are designed to enforce commercial best practices for businesses rather than to explicitly require them to proactively detect, disrupt, prevent and respond to threats with respect to fraud.
Digital platforms, including social media platforms, do not currently have legislated obligations respecting consumer-targeted fraud. In the absence of a legislative framework, social media platforms are not only not preventing, detecting and removing fraudulent posts and ads, but may be profiting from this activity by earning revenue from advertising fees paid by fraudsters to post fake ads.
A Multi-Sector Anti-Fraud Framework to protect Canadians
Bad actors are using services provided by key sectors and leveraging gaps between those sectors in order to perpetrate fraud. A key part of the Strategy could include the introduction of new and enhanced market-conduct obligations for federally regulated organizations in these sectors.
The following sectors could initially be in scope for the Multi-Sector Anti-Fraud Framework (the Framework):
- Federal financial sector – including banks and other federally-regulated financial institutions
- Telecommunications sector – including providers of telecommunications services (wire, cable, radio, optical or other electromagnetic system, or any similar technical system)
- Digital platforms – including social media services, instant messaging services, and search engines
The Framework could require regulated organizations to fulfill a set of general obligations applicable regardless of industry sector, reinforced by separate industry-specific obligations pertaining to market conduct unique to certain sectors.
These requirements could supplement, rather than duplicate, existing fraud-related consumer protection measures in place within each sector.
The requirements for regulated organizations could be in four key areas.
1. Prevention
The Framework could aim to introduce and enhance obligations for regulated organizations to design, operate and govern their services in ways that reduce the likelihood that fraud can occur, limit the ability of fraudsters to exploit gaps within and across sectors, and prevent their users from falling victim to fraud and the harms associated with fraud. This would require organizations to educate their customers as a complement to these system-level protections and safeguards to ensure that they are aware of fraud threats and that they know how to react, both before fraud occurs and if they suspect they have been victims of fraud, including by reporting fraud to service providers and initiating a complaint if they feel their service provider has not upheld its Framework obligations.
2. Detection
The Framework could introduce measures to require regulated organizations to ensure that fraud is effectively identified as it is occurring and investigated based on that information, ensuring that individuals impacted by active fraud activities are made aware that they may be or have been impacted. Organizations could be required to share fraud-related information with organizations in other sectors, while respecting users' privacy rights.
3. Disruption
The Framework could require regulated organizations to take actions to disrupt fraudulent activity from occurring and to prevent current and future losses resulting from that activity, once fraud or a high risk of fraud has been identified, including by removing fraudsters' access to their services and warning their users if they identify fraud risks tied to users' use of services.
4. Response
The Framework could require that individuals have access to avenues to report information about confirmed and attempted fraud, as well as access to clear and transparent internal dispute resolution processes, with the ability to escalate to an external complaints body for resolution. Regulated organizations that do not fulfill their obligations under the Framework could be required to reimburse users whose losses can be linked to organization(s') non-compliance with Framework obligations.
Consultation question
1. Are the three described sectors appropriate for the initial phase of a Framework? Should other sectors be considered?
Oversight of the Framework
The general Framework requirements would likely need to be overseen and enforced by a central regulator, responsible for monitoring and enforcing the compliance of all organizations within scope of the Framework. A central regulator, agnostic to any one of the three sectors implicated in the Framework, could be responsible for taking a holistic view of Framework compliance and be responsible for coordination of regulatory responses cutting across sectors.
Sector-specific rules could be overseen and enforced by industry regulators with knowledge and expertise of the sector (for example, the FCAC could oversee the financial sector obligations of federally regulated financial institutions, CRTC could oversee TSPs sector-specific rules).
Consultation questions
2. What role could a central regulator play in a Multi-Sector Anti-Fraud Framework?
3. What role could sector-specific regulators play in the Framework?
4. How can effective oversight of the Framework be achieved, without duplication of existing oversight of the three sectors?
Information sharing between regulators
Access to timely information can position regulators to better understand the evolving nature of fraud and inform anti-fraud oversight of their respective industries and public-facing anti-fraud messaging. For example, subject to confidentiality provisions, observations from the financial sector regulator drawn from its supervision of banks' compliance with the Framework, such as trends in the type of fraud schemes and execution methods that are impacting financial consumers, could be shared with the regulators in the telecommunications sector and digital platforms to inform their supervisions of fraud-related market conduct obligations applicable to those sectors.
The central regulator could be authorized to share pertinent and highly focused fraud-related information with sector-specific regulators, who could similarly be authorized to share fraud-related information with the central regulator and their counterparts responsible for other sectors captured by the Framework.
However, information-sharing authorities would need to be narrowly defined, respecting commercially sensitive information and Canadians' privacy rights.
Consultation questions
5. When should Framework regulators be permitted to share fraud-related information with each other to further the Strategy aims of preventing, detecting, disrupting and investigating fraud?
6. If so, what specific information should be shared, under what circumstances should it be shared and for what precise purpose should it be shared?
7. What privacy safeguards or oversight mechanisms should be in place for such information-sharing initiatives?
Reporting fraud-related information to law enforcement
Framework regulators' knowledge and awareness about fraud could potentially be useful to support law enforcement bodies' work to fight fraud. When timely and reliable, fraud-related insights from Framework regulators could inform how law enforcement could structure fraud investigations and target illegal activities.
Again, information-sharing authorities would need to be narrowly and precisely defined to ensure that safeguards under the Canadian Charter of Rights and Freedoms (Charter) and privacy rights are respected at all times.
Consultation questions
8. When should Framework regulators be permitted to share fraud-related information with law enforcement for the purposes of preventing, detecting, disrupting, and investigating fraud?
9. When should law enforcement be permitted to share fraud-related information with private sector organizations?
10. If so, what specific information should be shared, under what circumstances should it be shared and for what precise purpose should it be shared?
11. What privacy safeguards or oversight mechanisms should be in place for such information-sharing initiatives?
Aspects of a Framework
The general and sector-specific requirements of the Framework could be structured around the following principles:
1. Prevention
Organizations across the three regulated sectors could be required to proactively take measures to prevent their customers from being victimized by fraud. This could include robust anti-fraud governance, training programs for staff and relevant third parties, know-your-customer (KYC) requirements and consumer education. Prevention requirements could strike a balance, ensuring both effectiveness and minimal disruption to Canadians' legitimate use of banking, telecommunications and digital platforms.
General requirements
Governance
The success of a Framework would depend on regulated organizations implementing obligations and roles and responsibilities at the highest level. Regulated organizations across sectors could be required to embed responsibility for Framework obligations into their internal governance frameworks, including risk management and compliance functions.
Organizations could also be required to designate a senior official as responsible and accountable for the organization's compliance with the Framework, including the organization's policies and procedures for preventing, detecting, disrupting and responding to fraud, and the delivery of consumer education. They could also designate a committee of their board as responsible for reviewing the organization's compliance with Framework obligations.
Consultation question
12. How should organizations be required to embed compliance with the Framework into their governance models?
Training
The Framework would need to ensure that regulated organizations understand and carry out anti-fraud requirements. Organizations could be required to train staff and third-party service providers on the organization's fraud-related policies and procedures, including how they pertain to preventing, detecting and disrupting fraudulent activities, incident reporting and the organization's remediation policies. Training expectations could require that content be regularly updated to reflect emerging threats and best practices, explaining employees' roles in preventing, detecting, disrupting and responding to fraud.
Consultation question
13. How can organizations ensure that anti-fraud training is effective, and how should this be reflected in government policy or legislation?
KYC requirements
Canadians should have assurance that the services they receive from organizations are for their exclusive use and that other users they engage with are who they represent themselves to be. Organizations could be required to have processes in place to ensure that the users of their services are genuine individuals and to validate that individuals representing themselves as account holders are in fact the genuine holders of those accounts, in a manner that is designed to avoid unintended barriers or service disruptions.
Consultation question
14. When and how should organizations be required to validate the identity of users of their services?
Consumer education
When supported by strong protections and safeguards, Canadians are better positioned to prevent themselves from being victims of fraud. They can also respond effectively when fraud occurs when they understand how fraudsters operate and how they seek to engage victims, and what steps to take if they experience or suspect fraud.
Organizations could be required to develop, publish and prominently make available client-facing information concerning common fraudulent activities impacting their services, and the key indicators and warning signs of such activity. Organizations could also be required to outline steps they are taking to prevent fraud from impacting individuals using their services.
Organizations could be required to publish general information about the measures they are taking to prevent, detect, disrupt and respond to fraud, and to align that information with centralized and authoritative information about fraud produced by regulators or law enforcement.
Organizations could also be required to make information prominently available about how to report potential fraud to the organization and how to make a complaint respecting how an organization addressed an alleged fraud incident and the escalation process if the individual is unsatisfied with the resolution provided by the organization.
Consultation questions
15. What fraud-related information should organizations be required to make available to individuals using or who may use their services?
16. How should the effectiveness of organizations' fraud education be assessed to ensure that it meaningfully reduces harm?
Sector-specific requirements
In addition to the above general prevention requirements, organizations could be required to take fraud prevention measures specific to their industry.
Financial sector
Federally regulated financial institutions could be required to:
- provide specific warnings to individuals about the risk of fraud when individuals initiate large-scale transfer payments (for example, wire transfers, international money transfers)
- send real-time notifications to customers when a transfer payment is initiated or when a new recipient or payee is added
- put in place secure methods of multifactor authentication to validate the initiation of a payment or the addition of a new recipient or payee
Telecommunications sector
TSPs could be required to:
- implement a process to determine known fraudulent or highly suspicious phone numbers, and require TSPs to block or flag them, as well as mechanisms to correct false positives
- establish a "whitelist" of known legitimate aggregators with permission to send aggregated text messages
- block or flag calls "spoofing" legitimate enterprises, government institutions and law enforcement
Digital platforms
Digital platforms could be required to:
- limit advertising access on their platforms to verified users
- ensure that banned users cannot bypass the organization's account verification processes
- implement screening for fraudulent profiles and pages and blocking malicious links
Consultation question
17. What sector-specific fraud prevention rules should be in place?
2. Detection
Industry actors could be required to monitor and assess their services for fraud activity and investigate reports of potential fraud activity, including the nature of the fraud and the impact for its customers.
General requirements
Identifying and investigating fraudulent activity
Organizations can only effectively disrupt fraud if they take proactive steps to identify and investigate how fraudsters are targeting their customers.
Organizations could be required to take steps to identify potentially fraudulent activity targeting their customers and to track and detect confirmed incidents of fraud impacting their customers, including having appropriate resources and capabilities to detect fraud.
When organizations become aware of potentially fraudulent activity, either through their own internal processes or via a report or complaint from an individual, they could be required to investigate to confirm whether there is in fact fraudulent activity occurring using its services. Following investigation, organizations could be required to inform users impacted by the fraudulent activity where appropriate.
Consultation question
18. How could organizations be incentivized to effectively detect and investigate potentially fraudulent activity on their services?
Assessing fraud impacts
When fraud occurs, organizations can minimize future harms to their customers by taking steps to understand the severity of impacts. When an organization confirms that a fraudulent activity has occurred, it could be required to evaluate the harms, including financial harms, to individuals impacted by the fraudulent activity and assess the risk of future harms to the individual stemming from the fraudulent activity (for example, future financial loss, identify theft).
Organizations could be required to provide access to new accounts to ensure that fraudsters cannot continue to access a compromised account. Assessments of the degree of harm could ultimately inform determinations about how organizations respond to fraud.
Consultation questions
19. How should organizations be required to assess fraud-related harms to individuals using their services?
20. What actions should organizations be required to take to assess risk of future harm to individuals impacted by fraud?
Information sharing between organizations
Organizations may possess information that other organizations can use to prevent, detect and disrupt fraud. Separate from the information sharing between the Framework's regulators, and in addition to organizations' internal fraud detection tools, detection could be strengthened by the establishment of information sharing processes between organizations and across sectors. Information sharing between organizations can enable earlier and more effective identification of fraudulent activities and better position the organizations to detect and disrupt fraudulent activities before they impact individuals.
For example, based on information reported from consumers, a bank may note that many of its consumers are falling victim to false advertising about financial products and services hosted by a social media platform. In such a circumstance, the bank could notify the social media platform and request that the advertisement be taken down.
However, as discussed earlier, privacy rights must be always respected. This information sharing authority would need to be narrowly focused and mindful of Canadians' privacy rights.
Consultation questions
21. When should regulated private sector organizations be able to share fraud-related information with each other?
22. If so, what precise information should be shared, under what circumstances should it be shared and for what precise purposes should it be shared?
23. What privacy safeguards or oversight mechanisms should be in place for such information sharing initiatives?
Reporting fraud-related information to law enforcement
Regulated organizations' knowledge and perspectives could potentially be useful to support law enforcement bodies' work to fight fraud. When timely and reliable, this information could inform how law enforcement structure fraud investigations and target illegal activities.
As discussed, information sharing authorities would need to be narrowly and precisely defined to ensure that Charter and privacy rights are always respected.
Consultation questions
24. When should organizations be permitted to share fraud-related information with law enforcement for the purposes of preventing, detecting, disrupting and investigating fraud?
25. When should law enforcement be permitted to share fraud-related information with private sector organizations?
26. When should the government be permitted to share fraud-related information with law enforcement?
27. When should the government be permitted to share fraud-related information with private sector organizations?
28. If so, what specific information should be shared, under what circumstances should it be shared and for what precise purpose should it be shared?
29. What privacy safeguards or oversight mechanisms should be in place for such information sharing initiatives?
Sector-specific requirements
In addition to the above general prevention requirements, organizations could be required to take fraud-detection measures specific to their industry.
Financial sector
Federally regulated financial institutions could be required to:
- monitor account activity in real time, including transactions, for the purposes of identifying potential fraud incidents
- use behavioural analytics when monitoring accounts to identify instances of uncharacteristic user behaviour (for example, large wire transfers, multiple large cash withdrawals in a short window of time, addition of new payees or transfer contacts)
Telecommunications sector
TSPs could be required to:
- analyze phone call and text message traffic trends and conduct content analysis to detect suspicious activity and potential incidents of fraud, while respecting Canadians' privacy rights
- identify instances of subscribers responding to or engaging with known fraudulent phone calls or text messages and follow up as appropriate, consistent with relevant legal requirements
- monitor the volume of known fraudulent numbers using its telecommunications infrastructure and report to regulators, government, law enforcement and the public, as appropriate, on trends identified
- consider mechanisms to better authenticate legitimate communications
Digital platforms
Digital platforms could be required to:
- proactively identify accounts and content, including advertisements, potentially associated with fraudulent activities
- take steps to warn service users whose account may have been compromised
- monitor the volume of fraud using its digital platform and report to regulators and law enforcement
Consultation question
30. What sector-specific fraud detection rules should be in place?
3. Disruption
When organizations confirm fraud activity is occurring using their services, they could be required to halt the activity and to remove fraudulent users. In the event fraud is suspected, organizations could be required to take steps to suspend those activities while they are investigated by the organization.
General requirements
Removing known fraudulent actors
Fraudsters should not be able to access financial, telecommunications and digital platform infrastructure for the purposes of carrying out illegal activity. Organizations could be required to remove known fraudulent actors, disable applicable accounts and block future access to their services.
Consultation question
31. How can a balance be struck to limit use of industry infrastructure for fraudulent purposes, while ensuring that legitimate users are not unreasonably cut off from use of services?
Pausing potentially fraudulent activity
Organizations can use information gathered from fraud detection activities to disrupt potentially fraudulent activity. In the event an organization has a reasonable grounds to believe that a potential fraudulent activity has occurred, it could be required to suspend or block account activity until it has confirmed that the fraudulent activity is no longer a threat to anyone using the service. Organizations could be required to restore suspended services in such an event.
Consultation questions
32. In what situations should regulated entities be required to pause potentially fraudulent activity?
33. What measures, safeguards and recourse should be put in place to ensure that individuals' access is not improperly suspended or removed?
Warnings to users
Organizations can also position users of their services to make choices based on an informed understanding of the risk of being defrauded. When organizations become aware of potentially fraudulent activity or a threat of such activity, they could be obligated to warn implicated customers as soon as possible, to allow the customer to make informed decisions about the use of their services.
Consultation question
34. How can notifications of suspected fraudulent activity be effective?
Sector-specific requirements
In addition to the above general prevention requirements, organizations could be required to take the following fraud disruption measures specific to their sector.
Financial sector
Federally regulated financial institutions could be required to:
- close and block access to accounts known to be controlled by actors perpetrating fraud, retaining information that attributes these accounts to fraudsters
- allow account holders to freeze or disable accounts or certain capabilities of an account if they suspect their account has been compromised
Telecommunications sector
TSPs could be required to:
- intercept and block text messages and phone calls from known fraudulent or highly suspicious senders and identify suspicious SMS and phone calls as potential fraud
- close and block access to accounts known to be controlled by actors perpetrating fraud
Digital platforms
Digital platforms could be required to:
- immediately remove known fraudulent accounts and content, including fraudulent advertisements, and ban implicated users
- warn users when they are contacted by other users suspected of fraudulent activity and advise users who have engaged with known fraudulent content, regardless of whether the content remains active
- immediately suspend advertisements being investigated or flagged as potentially fraudulent
Consultation question
35. What sector-specific fraud disruption rules should be in place?
4. Response
Organizations could be required to have channels for their customers to report suspected fraud, as well as clear, transparent and easily accessible internal dispute resolution processes. Canadians should also have access to an external dispute process if an organization or organizations cannot resolve a complaint to their satisfaction.
General requirements
Receiving information about fraud activity
Organizations can act on fraud prevention, detection and disruption based on information they receive from their customers. Organizations could be required to have dedicated and distinct reporting channels in place to allow their customers and individuals engaging with their services to report alleged incidents of fraud. Organizations could also be required to prominently display information about these channels. These reporting channels could be required to inform individuals about the organization's process for internal dispute resolution.
Reporting to a regulated organization would not impact an individual's right to also report fraud to law enforcement.
Consultation question
36. How should organizations be required to make it easy for users to report fraud activity to them?
Internal dispute resolution
Victims of fraud who feel that their service providers have not fulfilled their anti-fraud obligations should have access to clear dispute resolution processes. Each organization could be required to have public-facing dispute resolution procedures in place to address individuals' complaints respecting compliance with Framework obligations – properly structured to allow organizations to make determinations about whether they fulfilled their general and sector-specific obligations.
Organizations in scope of the Framework could be required to adopt processes to ensure that cross-sectoral complaints (for example, an individual alleges a fraud loss as a result of their chequing account being compromised to a fraudster who obtained personal information from the individual through social media) have a single point of entry and not require individuals to navigate multiple internal dispute resolution processes (for example, opening separate complaints with a bank, a telecommunications company and a social media platform). This could require organizations to share information pertinent to fraud.
Organizations could have a set period to conclude their investigations. If an organization cannot close their investigation within that time frame, or the complaint is not resolved to the complainant's satisfaction, the complainant could be able to escalate their complaint to the Framework's external complaint body.
When resolving or otherwise closing a complaint, organizations could be required to provide complainants with a written summary of how they complied with their requirements under the Framework, particularly those at issue in the complaint. The summary could be required to include the remedy offered to complainants, or the reason why a remedy has not been offered.
Organizations could also be required to retain information about the complaints they receive and to provide that information to the Framework's external complaint body when a complainant escalates their complaint.
Consultation questions
37. How could organizations effectively investigate cross-sector complaints?
38. How long should organizations have to internally investigate complaints?
39. What information should organizations be required to include in a summary of complaint?
Liability in the event of non-compliance
In the event an organization's investigation of a complaint determines that it did not fulfill its Framework obligations, and that an individual suffered financial harm as a result, organizations could be required to make the individual whole, either solely by a single organization or, in the case where multiple organizations have not met their obligations, the individual could be made whole through an arrangement between organizations that apportions blame proportionate to the fault of the implicated organizations (for example, a text from a known fraudster leads to an individual making an electronic funds transfer payment to the fraudster).
Consultation questions
40. Should organizations be held liable when they do not fulfill their obligations under the Framework?
41. What standards should apply in determining whether an organization fulfilled its obligations?
42. How should liability be apportioned when multiple organizations have not fulfilled their obligations?
External dispute resolution
A single external dispute resolution body could be responsible for the review of escalated complaints within scope of the Framework. A single external dispute resolution process could ensure a consistent approach to complaint handling and interpretation of organizations' compliance with Framework obligations. Organizations within the Framework scope could be required to be members of the external dispute resolution process.
This body could be authorized to make findings and to make decisions with respect to organizations' compliance with their framework obligations. Organizations' summary of compliance could form the basis of the external complaint body's investigation; however, it could be authorized to request any information required to make a determination as to whether an organization complied with its general or sector-specific obligations.
In the event the external complaints body becomes aware of serious non-compliance with Framework obligations, it could be required to share this information with the general and/or sector-specific regulators.
Consultation questions
43. What should inform how an external complaint body is chosen?
44. Should decisions of the external complaint body be binding?
45. How long should the external complaints body have to investigate escalated complaints?
Empower Canadians to act against fraud
Another element of the Strategy could be to broaden and deepen Canadians' understanding of the constantly evolving threat posed by fraud, empowering them to make informed decisions about how they use financial, telecommunications and digital platform services, including how to respond effectively, through reporting fraud to their service providers and seeking resolution, if necessary.
The proposed scope of the Strategy accounts for several types of fraud, including situations where fraudsters gain direct access to an individuals' financial account and perpetrate fraud by transferring money directly to themselves or to a third-party account, as well as scenarios where an individual is deceived by a fraudster into making a payment after being misled about the use of the funds, or the nature of a product or service on offer (for example, romance or investment scams).
Public awareness efforts could also highlight the risks associated with misuse of government identifiers, including SIN compromise, and how such compromises may lead to both benefit fraud and financial account takeovers. Feedback is sought on how best to integrate awareness about government impersonation and identity-related fraud into national education efforts.
Industry, governments and regulators must all play a part to enhance Canadians' understanding of the nature and severity of the threat posed by fraud and to ensure that Canadians are well equipped to protect themselves against a range of fraud threats, including by:
- safeguarding their personal information and access to their accounts
- understanding and using the security features of the services they use
- scrutinizing offers and opportunities that may be "too good to be true"
- knowing how and where to report suspected fraud to their service providers, to regulators and to law enforcement
- understanding their rights, including available dispute resolution processes
Consultation questions
46. How can the government improve Canadians' awareness of the threat posed by fraud and better position them to protect themselves against fraud?
47. How can the government improve Canadians' awareness about the risk of misuse of government-issued identifiers, including social insurance numbers?
Support law enforcement's ability to combat fraud
In Canada, there are multiple federal, provincial and territorial and municipal law enforcement agencies involved in fraud enforcement, creating challenges in coordinating the identification and investigation of schemes that span Canadian and international jurisdictions.
As described in the Framework section, the Strategy could include measures to support law enforcement's ability to gather information about fraud and to inform investigations. Any measures advanced would need to be carefully considered with respect to the Charter safeguards and privacy rights.
The Canadian Anti-Fraud Centre
The CAFC is operated by the Royal Canadian Mounted Police (RCMP), in partnership with the Competition Bureau of Canada and the Ontario Provincial Police (OPP). The CAFC is a recognized National Police Service (NPS) that gathers intelligence and produces reports with regards to fraud and fraud-related offences for the benefit of other regulatory, domestic and international criminal law enforcement agencies. With the National Cybercrime Coordination Centre (NC3), the CAFC maintains the National Cybercrime and Fraud Reporting System, receiving, maintaining and actioning fraud reporting.
CAFC's efforts focus on prevention of fraud through education and awareness; disruption of key fraud enablers, in collaboration with implicated organizations in the financial and telecommunications sectors; recovery of fraud losses; and providing operational support to investigations by sharing fraud-related reports and intelligence with law enforcement and regulatory partners. However, the CAFC does not currently conduct investigations directly.
The Strategy could include measures to coordinate law enforcement efforts to fight fraud across Canadian jurisdictions. This could include measures to unify fraud response efforts at the federal, provincial and territorial and municipal levels.
Consultation questions
48. What can be done to support federal law enforcement's ability to investigate fraud and collect fraud-related intelligence?
49. What should be done to improve coordination between Canadian law enforcement across federal, provincial and territorial and municipal levels, and between those law enforcement bodies and international partners?
50. What role should the CAFC play in advancing the Strategy?
Appendix 1: Consultation questions
A Multi-Sector Anti-Fraud Framework
Oversight, Information Sharing and Reporting to Law Enforcement
- Are the three described sectors appropriate for the initial phase of a Framework? Should other sectors be considered?
- What role could a central regulator play in a Multi-Sector Anti-Fraud Framework?
- What role could sector-specific regulators play in the Framework?
- How can effective oversight of the Framework be achieved, without duplication of existing oversight of the three sectors?
- When should Framework regulators be permitted to share fraud-related information with each other for the purposes of further the Strategy aims of preventing, detecting, disrupting, and investigating fraud?
- If so, what specific information should be shared, under what circumstances should it be shared and for what precise purpose should it be shared?
- What privacy safeguards or oversight mechanisms should be in place for such information-sharing initiatives?
- When should Framework regulators be permitted to share fraud-related information with law enforcement for the purposes of preventing, detecting, disrupting, and investigating fraud?
- When should law enforcement be permitted to share fraud-related information with private sector organizations?
- If so, what specific information should be shared, under what circumstances should it be shared and for what precise purpose should it be shared?
- What privacy safeguards or oversight mechanisms should be in place for such information-sharing initiatives?
1. Prevention
- How should organizations be required to embed compliance with the Framework into their governance models?
- How can organizations ensure that anti-fraud training is effective and how should this be reflected in government policy or legislation?
- When, and how, should organizations be required to validate the identity of users of their services?
- What fraud-related information should organizations be required to make available to individuals using, or who may use, their services?
- How should the effectiveness of organizations' fraud education be assessed to ensure it meaningfully reduces harm?
- What sector-specific fraud-prevention rules should be in place?
2. Detection
- How could organizations be incentivized to effectively detect and investigate potentially fraudulent activity on their services?
- How should organizations be required to assess fraud-related harms to individuals using their services?
- What actions should organizations be required to take to assess risk of future harm to individuals impacted by fraud?
- When should regulated private sector organizations be able to share fraud-related information with each other?
- If so, what precise information should be shared, under what circumstances should it be shared and for what precise purposes should it be shared?
- What privacy safeguards or oversight mechanisms should be in place for such information sharing initiatives?
- When should organizations be permitted to share fraud-related information with law enforcement for the purposes of preventing, detecting, disrupting, and investigating fraud?
- When should law enforcement be permitted to share fraud-related information with private sector organizations?
- When should the government be permitted to share fraud-related information with law enforcement?
- When should the government be permitted to share fraud-related information with private sector organizations?
- If so, what specific information should be shared, under what circumstances should it be shared and for what precise purpose should it be shared?
- What privacy safeguards or oversight mechanisms should be in place for such information-sharing initiatives?
- What sector-specific fraud-detection rules should be in place?
3. Disruption
- How can a balance be struck to limit use of industry infrastructure for fraudulent purposes, while ensuring that legitimate users are not unreasonably cut off from use of services?
- In what situations should regulated entities be required to pause potentially fraudulent activity?
- What measures, safeguards and recourse should be put in place to ensure that individuals' access is not improperly suspended or removed?
- How can notifications of suspected fraudulent activity be effective?
- What sector-specific fraud-disruption rules should be in place?
4. Response
- How should organizations be required to facilitate users' reporting of fraud activity to organizations?
- How could organizations effectively investigate cross-sector complaints?
- How long should organizations have to internally investigate complaints?
- What information should organizations be required to include in a summary of complaint?
- Should organizations be held liable when they do not fulfill their obligations under the Framework?
- What standards should apply in determining whether an organization fulfilled its obligations?
- How should liability be apportioned when multiple organizations have not fulfilled their obligations?
- What should inform how an external complaint body is chosen?
- Should decisions of the external complaint body be binding?
- How long should the external complaints body have to investigate escalated complaints?
Empower Canadians to act against fraud
- How can the government improve Canadians' awareness of the threat posed by fraud and better position them to protect themselves against fraud?
- How can the government improve Canadians' awareness about the risk of misuse of government-issued identifiers, including social insurance numbers?
Support law enforcement's ability to combat fraud
- What can be done to support federal law enforcement's ability to investigate fraud and collect fraud-related intelligence?
- What should be done to improve coordination between Canadian law enforcement across federal, provincial and territorial and municipal levels, and between those law enforcement bodies and international partners?
- What role should the CAFC play in advancing the Strategy?