Bank of Canada headquarters in Ottawa winter light — symbolic of governance above the Canadian tokenisation rail
    Flagship · Canada · June 2026

    Tokenised Assets in Canada

    Two parallel obligations — banking-supervisory law for deposit-grade instruments, securities law for asset-grade instruments. One control plane above both.

    9 min read · Cabier Intelligence

    Contents
    1. 01Executive summary
    2. 02The Canadian landscape
    3. 03Cohort B — tokenised deposits (Canada)
    4. 04Cohort A — tokenised securities (Canada)
    5. 05Six obligations the rail cannot discharge
    6. 06Cabier capabilities — Canadian mapping
    7. 07What this is not
    8. 08Frequently asked questions
    9. 09Glossary

    Executive summary

    Canadian tokenisation is not a single track. Federally regulated banks issue deposit liabilities and underwrite securities at scale; both flows are tokenising in parallel. The banking-supervisory perimeter — OSFI B-10, E-23, the Bank Act, CDIC, Lynx and the Real-Time Rail — governs one. The securities perimeter — CSA staff notices 21-329, 21-330, 51-364, and 81-336, and IIROC / CIRO conduct obligations — governs the other.

    Both perimeters carry an L5 governance obligation that no rail operator and no consortium can discharge on the institution's behalf. Cabier's OSFI engine is already in production; the tokenisation extension reuses that substrate rather than building in parallel. The CSA staff- notice tracker layers above as a securities-cohort overlay on the same evidence vault.

    This brief states the Canadian landscape, the two cohorts side by side, the six obligations the rail cannot discharge, and the Cabier capability mapping. The companion briefs cover Cohort A globally at /insights/governance-above-the-rail-2026 and Cohort B globally at /insights/tokenised-deposits-2027-governance-vacancy.

    The Canadian landscape

    OSFI supervises the federally regulated institutions that will issue and custody the bulk of Canadian tokenised activity. B-10 governs material outsourced arrangements — a tokenisation rail used at scale is exactly that. E-23 governs the models embedded in pricing, surveillance, screening and liquidity workflows over tokenised assets.

    The Bank of Canada operates Lynx high-value and oversees the Real-Time Rail through Payments Canada. Where bank-issued deposit tokens settle alongside either, the reconciliation, exception handling and FMI-grade operational resilience are the institution's obligation. Project Jasper and Project Agorá carry forward as the wholesale CBDC and cross-border settlement substrate.

    The Canadian Securities Administrators harmonise the securities perimeter through staff notices. Provincial commissions — the OSC in Ontario, the AMF in Québec, the BCSC, and the ASC — carry the local conduct authority. IIROC / CIRO carries the dealer-conduct layer. FINTRAC carries the AML reporting layer under PCMLTFA. Each is the institution's own.

    Cohort B — tokenised deposits (Canada)

    A tokenised deposit is a liability of a Canadian-chartered bank, represented as a token on a shared ledger so that interbank value transfers settle 24/7 inside the regulated banking system. The Bank Act s.413 characterisation does not change because the representation does; the deposit is still a deposit. CDIC coverage carries through to the standard limits where the characterisation holds.

    OSFI's prudential treatment — capital, liquidity, large-exposure — applies on the bank's balance sheet as it does for any other deposit liability. B-10 applies to the rail as a material outsourced arrangement. E-23 applies to any model embedded in surveillance, screening, pricing or liquidity decisions over the rail. The institution carries the resolution-planning obligation; the rail does not.

    Reconciliation cadence is the operational delta. A 24/7 shared rail cannot be reconciled against a deposit ledger on a batch cycle. Continuous Control Monitoring runs at the rail's cadence; mint and burn events reconcile against Lynx or the RTR in near-real time, with discrepancies routed into the institution's exception workflows with evidence attached.

    Cohort A — tokenised securities (Canada)

    CSA staff notice 21-329 frames the application of securities law to crypto-asset trading platforms. 21-330 addresses crypto-assets that are securities or derivatives. 51-364 covers custody and operational expectations. 81-336 addresses value-referenced crypto-assets. Each applies the provincial securities acts to tokenised instruments without waiting for new statute.

    IIROC / CIRO carries the dealer-side conduct obligations — registration, suitability, surveillance, recordkeeping. Where a federally regulated bank operates an investment-dealer subsidiary that participates in tokenised-securities flow, both the prudential and dealer perimeters apply concurrently. Cabier instruments both on one substrate.

    Provincial nuance matters. Ontario, Québec, British Columbia and Alberta diverge on registration relief, value-referenced crypto-asset treatment, and crypto-asset trading-platform terms-and-conditions. The Canadian overlay exposes those nuances explicitly rather than flattening them into a national line.

    Six obligations the rail cannot discharge

    These are the questions an OSFI, CSA, IIROC / CIRO, or FINTRAC supervisor will put to the participating institution — not to the rail operator. Each resolves to evidence the institution must produce.

    OSFI B-10 third-party risk

    Third-party material risk identification, due diligence, ongoing monitoring, and exit planning where the tokenisation rail is a material outsourced arrangement to a federally regulated financial institution.

    OSFI E-23 model risk

    Model identification, validation, ongoing monitoring, and governance for any model embedded in tokenised-asset workflows — pricing, surveillance, screening, liquidity.

    Bank Act s.413 deposit characterisation

    Where a token represents a deposit liability of a Canadian-chartered bank, the deposit-taking characterisation, CDIC coverage attestation, and prudential treatment remain the bank's own.

    CSA staff-notice perimeter

    Provincial securities-act application via CSA staff notices 21-329, 21-330, 51-364, and 81-336 — registration, prospectus, custody, and crypto-asset trading-platform obligations.

    PCMLTFA / FINTRAC Travel Rule

    Originator and beneficiary data for value transfers, sanctions screening, and STR/LCTR reporting — institution-side regulated activity, not dischargeable by the rail.

    Payments Canada Lynx / RTR reconciliation

    Where bank-issued deposit tokens settle alongside Lynx high-value or the Real-Time Rail, reconciliation, exception handling, and FMI-grade operational resilience are the institution's obligation.

    Cabier capabilities — Canadian mapping

    The substrate above the Canadian rail. Each capability is pre-existing infrastructure, instrumented against the obligations above and reusable across both cohorts.

    OSFI-OSOSFI Compliance Engine

    B-10 and E-23 in production. Tokenised-asset extension reuses the existing third-party register, model registry, and continuous-monitoring substrate without parallel build.

    TCOSTokenization Control OS — Canadian profile

    Three-lines-of-defence evidence engine reweighted for Canadian banking-supervisory and securities law. Effectiveness grading replaces pass/fail attestation.

    PROTOCOLCabier Protocol — CTRE-CA

    FATF Recommendation 16 / IVMS101 envelope adapted to PCMLTFA reporting and FINTRAC submission patterns. Carries originator and beneficiary across Canadian and cross-border flows.

    AI-RFOSAI Assurance OS

    E-23 model risk management over any AI embedded in surveillance, screening, liquidity, or pricing on Canadian tokenised-asset workflows. SR 11-7 mapping retained for cross-border institutions.

    ORSOperational Resilience Score — Canadian weighting

    Nine-dimension composite recalibrated for Canadian supervisory expectations. ICT resilience and third-party concentration carry distinct weights for FRFIs.

    LRELiquidity Resilience Engine — Lynx/RTR overlay

    Basel III LCR and NSFR machinery instrumented for Canadian liquidity reporting, with intraday telemetry where bank-issued deposit tokens settle on 24/7 rails.

    What this is not

    • Not a deposit-taker. Cabier does not hold deposits.
    • Not a dealer. Cabier carries no IIROC / CIRO registration.
    • Not a payments service provider. Cabier does not move value; Lynx and the RTR do.
    • Not a custodian. Cabier does not hold tokenised assets.
    • Not a public price. Every Canadian engagement is custom-quoted under signed terms.
    • Not a model vendor. Cabier does not train foundation models; the AI Assurance OS wraps any model in scope under E-23.

    Frequently asked questions

    Is Cabier OSFI-ready today?

    The OSFI Compliance Engine is in production today against B-10 and E-23. The tokenised-asset extension reuses that substrate; it is not a parallel build.

    How does Canada treat tokenised deposits?

    A token that represents a deposit liability of a Canadian-chartered bank remains a deposit under the Bank Act. The bank carries the OSFI prudential treatment, the CDIC coverage attestation, and the resolution-planning obligations. Cabier carries the evidence.

    How does Canada treat tokenised securities?

    CSA staff notices 21-329, 21-330, 51-364, and 81-336 apply the provincial securities acts to tokenised securities, crypto-asset trading platforms, and value-referenced crypto-assets. IIROC / CIRO conduct obligations apply at the dealer layer. Cabier instruments the institutional controls above the rail.

    Why is balanced cohort treatment important in Canada?

    Because Canadian institutional balance sheets carry both at scale — the big six issue deposit liabilities and underwrite tokenised securities. A single-cohort approach would leave half the perimeter unmeasured.

    Does Cabier reconcile against Lynx or the Real-Time Rail?

    Where bank-issued deposit tokens settle alongside Lynx high-value or the RTR, Cabier reconciles mint and burn events against settlement records in near-real time and routes discrepancies into the institution's exception workflows.

    What about FINTRAC and the Travel Rule?

    The CTRE-CA envelope carries PCMLTFA-compliant originator and beneficiary data across Canadian and cross-border flows, mapped to FATF Recommendation 16 and IVMS101. Reporting remains the institution's submission.

    Does CDIC coverage carry through to a deposit token?

    Where the token is characterised as a deposit, the underlying liability is insured to the standard CDIC limits. Look-through characterisation, segregation evidence, and resolution-planning artefacts are the bank's obligation; Cabier carries the evidence.

    How does this interact with the Bank of Canada's wholesale CBDC work?

    Project Jasper and Project Agorá learnings are carried forward into the Cabier substrate. Where wholesale CBDC primitives become settlement components, the reconciliation pattern is the same.

    Does this work for federally regulated insurers and federally regulated trusts?

    Yes. The OSFI substrate covers all FRFIs in scope. Provincially regulated entities are supported via the CSA overlay and provincial securities-commission patterns.

    Is there a public Canadian price list?

    No. Every Canadian engagement is custom-quoted under signed terms. Public price cards distort institutional procurement and we refuse to publish them.

    How is provincial divergence handled?

    Ontario, Québec, British Columbia, and Alberta carry distinct securities and consumer-protection patterns. The Cabier overlay exposes provincial nuances explicitly where they diverge from the CSA harmonised text.

    Does Cabier hold any Canadian licence?

    No. Cabier is not a deposit-taker, not a dealer, not a custodian, not a payments service provider. The licensed activity remains the institution's; Cabier provides the L5 substrate.

    Is data residency a problem?

    No. Sovereign Canadian deployment and on-shore data residency are supported. There is no mandatory US data storage in the platform.

    How does this map to OSFI's Integrity and Security Guideline?

    Integrity and security obligations are instrumented at the platform layer — access controls, audit trail, model-event logging — and surfaced into the institution's OSFI reporting.

    Can OSFI access the platform directly?

    A supervisor-facing window can be provisioned on request. It exposes ORS lineage, control effectiveness grades, reconciliation evidence, and incident reports at the depth OSFI specifies, scoped to the supervised entity.

    What is withheld from this article?

    ORS weights, the effectiveness-grade rubric, Trust Gate definitions, the dependency-graph internals, and the Canadian institutional control library specifics. The category map is published; the operating disclosure is released only under signed terms.

    How does Cabier interact with IIROC / CIRO?

    Where the institution carries IIROC / CIRO conduct obligations on tokenised securities, the dealer-side controls and surveillance evidence are instrumented alongside the OSFI prudential layer.

    Where is the named competitor comparison?

    Under non-disclosure at /insights/tokenization-named-comparison. The matrix carries a Canadian column alongside the global cohorts.

    Glossary

    OSFI
    Office of the Superintendent of Financial Institutions — federal prudential regulator for Canadian banks, insurers, and pensions.
    OSFI B-10
    Third-Party Risk Management Guideline — governs material outsourced arrangements at federally regulated financial institutions.
    OSFI E-23
    Model Risk Management Guideline — covers identification, validation, monitoring and governance of models, including those embedded in tokenised workflows.
    Bank Act s.413
    Section of the Bank Act (Canada) addressing the receipt of deposits by Canadian-chartered banks; controls the characterisation of bank-issued deposit tokens.
    CDIC
    Canada Deposit Insurance Corporation — federal deposit insurer; coverage carries through to tokenised deposit liabilities of member institutions.
    CSA staff notices
    Canadian Securities Administrators harmonised staff notices — 21-329 (crypto-asset trading platforms), 21-330 (crypto-asset securities), 51-364 (custody and operational), 81-336 (value-referenced crypto-assets).
    IIROC / CIRO
    Canadian Investment Regulatory Organization — successor self-regulatory body for investment dealers; carries conduct obligations on tokenised-securities activity.
    PCMLTFA
    Proceeds of Crime (Money Laundering) and Terrorist Financing Act — Canadian AML statute administered by FINTRAC.
    FINTRAC
    Financial Transactions and Reports Analysis Centre of Canada — Canadian financial intelligence unit.
    Lynx
    Canada's high-value payment system, operated by Payments Canada.
    Real-Time Rail (RTR)
    Canada's real-time payment system, operated by Payments Canada.
    Project Jasper
    Bank of Canada distributed-ledger settlement research initiative; learnings carried into wholesale CBDC and tokenised-deposit reconciliation.
    Project Agorá
    BIS-coordinated cross-border wholesale tokenisation project in which the Bank of Canada participates.
    FRFI
    Federally Regulated Financial Institution — under OSFI prudential supervision.
    Cohort A
    Tokenised securities track — governed by securities law and CSA staff notices in Canada.
    Cohort B
    Tokenised deposits track — bank-issued money on 24/7 rails, governed by banking-supervisory law in Canada.
    L5 — Governance, Control & Assurance
    The institutional governance layer above the tokenisation stack; cannot be discharged by the rail operator.
    TCOS
    Tokenization Control OS — the three-lines-of-defence evidence engine over the institution's tokenised activity.
    Cabier Protocol
    Open standards: CDS data model, CEF cryptographic evidence, COM ORS methodology, CTRE cross-chain Travel Rule envelope.
    CTRE-CA
    Canadian profile of the Cross-chain Travel Rule Envelope — mapped to PCMLTFA reporting and FINTRAC submission patterns.
    ORS
    Operational Resilience Score — nine-dimension composite, regulator-traceable, recalculated continuously.
    AI Assurance OS
    Model risk governance over any AI embedded in tokenised workflows; OSFI E-23 and SR 11-7 mapped.
    Evidence vault
    Single immutable substrate behind every report, attestation, supervisory question, and audit walkthrough.
    Custom quote
    Cabier's standing policy: no engagement is publicly priced; every scope is sized and quoted under signed terms.
    FATF Recommendation 16
    Travel Rule — originator and beneficiary data for value transfers; carried via IVMS101.

    Continue reading

    Companion briefs cover the global Cohort A and Cohort B perimeters in depth.

    References and citations

    Primary sources. Positions change; verify at source before relying on any figure or determination.

    1. 1Canadian Securities Administrators, Staff Notice 21-333 and related crypto trading platform guidanceCanadian platform registration and custody expectations.Source
    2. 2Office of the Superintendent of Financial Institutions, Guideline B-10 — Third-Party Risk ManagementDependency and outsourcing expectations for tokenised infrastructure.Source
    3. 3Bank of Canada, research on retail and wholesale digital currencyCentral bank position on tokenised settlement.Source
    4. 4Basel Committee on Banking Supervision, SCO60 — Prudential treatment of cryptoasset exposuresCapital treatment applied by Canadian banks.Source