Skip to main content
Skip to main content
General information only — not legal advice.

This guide is educational. It does not create a lawyer–client relationship and is not a substitute for advice from a qualified Canadian lawyer, accountant, or other professional familiar with your organization. If a regulator has contacted you, retain counsel promptly.

Response guide

If regulators contact you: what to do next, and who to involve

A calm, plain-language playbook for Canadian charities, non-profits, and corporations. Use it alongside — not instead of — advice from your own lawyer and accountant.

First 24 hours
  • Stay calm and read the letter carefully — don't reply substantively yet.
  • Preserve records — no destruction, no routine deletion.
  • Contact counsel before making any statement to the regulator.

Step-by-step: For-profit corporation

Work through these in order. Steps 1–3 should happen the same day the letter arrives.

  1. 1

    Read the letter carefully

    Identify the regulator (Corporations Canada, provincial registrar, CRA, OSC / provincial securities regulator, Competition Bureau, OPC, etc.), the statute cited, the deadline, and exactly what is requested — filings, records, interviews, or ISC register information.

  2. 2

    Log the contact

    Record date received, method, corporation number, reference number, named officer, and the reply-by date. Preserve delivery evidence.

  3. 3

    Preserve records — no destruction

    Hold minute book, share register, ISC register, board and shareholder resolutions, annual returns, tax filings, contracts, and related emails. Suspend routine deletion until counsel confirms scope.

  4. 4

    Notify the right internal people

    CEO, board chair, CFO, and general counsel (or external counsel) first. Add the privacy officer if personal data is involved. Keep the circle small; document who was told.

  5. 5

    Bring in the right external professionals

    Retain corporate counsel (regulatory or securities specialist where applicable). Involve your tax accountant, external auditor, and insurance broker (D&O and cyber where relevant).

  6. 6

    Draft a single-channel response plan

    One named contact — usually counsel. All communications in writing, reviewed before they go out. No ad-hoc calls with the regulator or investigators.

  7. 7

    Ask for a written extension if needed

    Regulators generally grant a first reasonable extension when asked promptly in writing. Never miss the original deadline without a granted extension on file.

Who to involve — and when

RoleWhen to loop in
Board chairImmediately — governance responsibility and director liability sit here.
Treasurer / CFOImmediately for anything touching financials, receipting, tax, or filings.
Executive Director / CEOImmediately — coordinates response and internal communications.
Privacy officerWhenever personal data, a suspected breach, or an OPC contact is involved.
External counselSame day — before any substantive reply to the regulator.
Auditor / accountantWhen records, financial statements, or tax positions are in scope.
Insurance broker (D&O / cyber)Early — many policies require prompt notice or coverage is jeopardized.
PR / communicationsOnly if the matter is likely to become public; coordinated with counsel.

Common types of regulator contact

Recognize what you've received so you can respond proportionately.

Reminder — this is not legal advice.

This page is general information published by Legal Risk Alert for educational purposes only. It is not legal advice, does not create a lawyer–client relationship, and does not replace advice from a qualified professional retained by your organization. Laws and regulator practices change; always verify current requirements with counsel.

Not sure where you stand today?

Take the free 8-minute compliance assessment to see which risks apply to your organization.

If a regulator has already contacted you, the Audit + Consult tier pairs the full audit with counsel-led response support.