AML/CFT in Canada: Anti-Money Laundering and Countering the Financing of Terrorism Money laundering isn't a niche problem. The UNODC estimates that criminals launder somewhere between 2-5% of global GDP every year, roughly $800 billion to $2 trillion, though the agency is upfront that the clandestine nature of the crime makes an exact figure impossible to pin down. That's the global backdrop UNODC's overview of money laundering makes clear.

For Canadian reporting entities, though, AML/CFT isn't an abstract global statistic. It's an enforceable obligation under FINTRAC and the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), with real financial and reputational consequences when programs fall short.

This post covers what AML/CFT actually means, the prescribed program components every compliance program needs, the three classic stages of laundering, who has to comply in Canada, and how to know when your program needs a serious second look.

Key Takeaways

  • Money laundering may account for 2-5% of global GDP annually, per UNODC estimates
  • Canadian programs need five core pillars under FINTRAC's compliance program requirements, including a periodic effectiveness review
  • FINTRAC may issue administrative monetary penalties for non-compliance. Penalty amounts depend on the classification of the violation and the facts of the case. FINTRAC's 2024-25 annual report recorded 23 Notices of Violation totaling more than $25 million.
  • Effectiveness reviews are required at least every two years (PCMLTFR s.156); entities may also reassess after material business changes as sound practice, not as a universal early statutory trigger

What Is AML/CFT?

Anti-Money Laundering (AML) refers to the laws, regulations, and procedures designed to stop criminals from disguising illegally obtained funds as legitimate income. Combating the Financing of Terrorism (CFT) targets a related but distinct problem: funding terrorist activity, which doesn't always involve "dirty" money at all.

The difference matters. Laundering hides the origin of criminal proceeds. Terrorist financing can involve entirely legitimate funds redirected toward illegal ends. Despite that distinction, the two sit in one compliance framework because the detection tools overlap almost completely:

  • Customer due diligence and know-your-client (KYC) processes
  • Transaction monitoring and suspicious activity reporting
  • Recordkeeping and risk assessment

Canada's Regulatory Anchor

In Canada, the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) is the national AML/CFT regulator. The governing legislation is the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA).

Canada's framework is built to align with the Financial Action Task Force (FATF) Recommendations, the international standard-setting body to which more than 200 jurisdictions have committed.

Canada's most recent FATF follow-up rated the country compliant or largely compliant with most Recommendations, but still flagged gaps. "Aligned with FATF" does not mean perfect on every measure.

The Five Pillars of an AML/CFT Compliance Program

FINTRAC's compliance program requirements break down into five components. Miss one, and the whole structure is weaker than it looks on paper.

  1. Compliance officer — Someone with actual authority and resources to run the program, not just a title.
  2. Written policies and procedures — Reflecting the entity's specific risk profile, not a generic template.
  3. Documented risk assessment — Covering products, customers, delivery channels, and geography.
  4. Ongoing employee training — Tailored to each role's actual risk exposure.
  5. Effectiveness review — Conducted at least every two years to test whether the program works, not just whether it exists. The legal requirement is a periodic effectiveness review; using an independent or external reviewer is a common service model and best practice, not a universal statutory requirement that the reviewer must be external.

Where Programs Actually Fall Short

The effectiveness-review element is often where gaps appear. Writing policies is easy; proving with evidence that those policies operate as intended day to day is not.

An evidence-based effectiveness review that tests documents, interviews staff, and samples files closes the gap this element is meant to address. FINTRAC's best practice is an impartial reviewer who is not directly involved in developing or maintaining the program. Options include an internal auditor, an external auditor, or the reporting entity itself if no auditor is available. External delivery is one way to achieve impartial challenge, not a universal legal requirement.

AlphaDelta provides Independent AML Effectiveness Reviews and Senior AML Advisory for Canadian reporting entities whose review is approaching, overdue, or needs independent challenge.

The Three Stages of Money Laundering

AML programs still frame risk around three classic stages. Compliance teams use that model to place controls where intervention can still work.

  1. Placement: Introducing illicit cash into the financial system, often through deposits or structured transactions meant to stay under reporting thresholds.
  2. Layering: Moving funds across accounts, transactions, or jurisdictions to obscure origin.
  3. Integration: Returning "cleaned" funds to the legitimate economy through real estate, investments, or business ventures.

Three stages of money laundering placement layering integration process flow

FINTRAC guidance flags indicators at each stage—complex legal-entity structures that hide ownership, and transactions tied to jurisdictions of concern. Build detection around those points, not a generic "watch for large transactions" rule.

Who Must Comply with AML/CFT Obligations in Canada

FINTRAC's reporting-entity list is longer than most people expect. It includes:

  • Banks, credit unions, and caisses populaires
  • Money services businesses (MSBs), including foreign MSBs operating in Canada
  • Securities dealers
  • Casinos
  • Real estate brokers, sales representatives, and developers (for specified activities)
  • Life insurance companies, brokers, and agents
  • Mortgage administrators, brokers, and lenders
  • Virtual currency dealers
  • Dealers in precious metals and stones

Obligations scale with business type and risk, but core requirements (KYC, transaction reporting, and recordkeeping) apply across nearly every sector on that list. A FINTRAC examination or licence renewal review can force a closer look at whether the program still matches the entity's risk profile. Catching design and operating gaps earlier is usually less disruptive than remediating under examination pressure.

What Happens When AML/CFT Programs Fail

FINTRAC's public penalty notices tell a consistent story. Recent enforcement actions include:

Entity Penalty Year
A virtual-currency MSB (under appeal to Federal Court where that status applies) $176,960,190 2025
A Canadian bank $9,185,000 2024
An MSB $693,742.50 2026
A Canadian lottery/gaming reporting entity $212,025 2026

These notices are not limited to entities with no policy manual. Public penalty summaries often cite failures such as:

  • Deficient risk assessments
  • Missing suspicious transaction reports
  • Inadequate high-risk client measures
  • Gaps in ongoing monitoring

Those are exactly the issues an effectiveness review is meant to surface through evidence-based testing of design and operating effectiveness.

Beyond the fine itself, consequences can include:

  • Remediation obligations where FINTRAC requires or requests them
  • Loss of banking relationships or correspondent banking access
  • Increased regulatory scrutiny going forward
  • Executive and board-level accountability questions

Gaps more often involve programs that look compliant on paper but do not operate that way in practice, rather than the total absence of written policy.

When to Bring in Senior AML Expertise

Certain moments call for outside expertise rather than internal sign-off alone:

  • Your effectiveness review is due, overdue, or approaching the two-year mark
  • FINTRAC has signalled or begun a compliance examination
  • An internal audit or prior review turned up findings that need prioritizing
  • Your business model, products, or risk profile changed materially

Generic compliance consulting is not the same as guidance grounded in lived regulatory accountability. AlphaDelta's senior advisors have built AML programs, defended them under audit and examination, and conducted examinations from the regulator's side of the table. That perspective supports independent challenge and evidence-based prioritization; clients retain execution, ownership, decisions, and regulatory responsibility.

AlphaDelta is a senior AML advisory firm for Canadian reporting entities. Offerings are limited to Independent AML Effectiveness Reviews and Senior AML Advisory.

AlphaDelta provides senior advice and independent challenge; clients retain responsibility for their programs, operational execution, decisions, and regulatory outcomes.

Frequently Asked Questions

What is AML and CFT?

AML (Anti-Money Laundering) targets the disguising of criminal proceeds as legitimate funds. CFT (Combating the Financing of Terrorism) targets funding for terrorist activity, which may involve legitimate money. Both are handled within one compliance framework because the detection controls overlap.

What are the prescribed program components of the AML/CFT program?

A compliance officer, written policies and procedures, a documented risk assessment, ongoing employee training, and an effectiveness review conducted at least every two years (PCMLTFR s.156).

What are the AML three stages?

Placement (introducing illicit cash into the system), layering (moving it through accounts to hide its origin), and integration (reintroducing it as apparently legitimate funds).

Who enforces AML/CFT compliance in Canada?

FINTRAC is the national regulator, operating under the authority of the PCMLTFA. FINTRAC conducts examinations, issues guidance, and can impose administrative monetary penalties.

How often does a Canadian reporting entity need an AML effectiveness review?

At minimum, every two years under PCMLTFR s.156. Material business changes may warrant updating risk assessments and controls as sound practice; they do not universally trigger an early statutory effectiveness review outside the two-year cycle.

What are the consequences of failing an AML/CFT examination in Canada?

Consequences can include administrative monetary penalties. Amounts depend on the classification of the violation and the facts of the case. Remediation where required or requested, loss of banking relationships, and executive-level accountability for the gaps identified can also follow.