A Guide to Independent AML Effectiveness Reviews

Introduction

The 2025 Basel AML Index put the global average money-laundering risk score at 5.28 out of 10, barely moved from 5.30 the year before, according to the Basel Institute on Governance. Billions spent on compliance worldwide, and the needle hardly shifts.

A big part of the reason: audits that exist to check a box, not to test whether a program actually works.

For Canadian reporting entities, this plays out in a familiar way. The effectiveness review deadline creeps up, someone runs a quick internal checklist, and the file gets closed. Then FINTRAC shows up and asks harder questions than the internal review ever did.

This guide breaks down what an independent AML effectiveness review actually is, how often Canadian law requires one, and what triggers an unscheduled review. It also covers how to prepare so the exercise strengthens your program instead of generating paperwork.

Key Takeaways

  • An AML effectiveness review tests whether your compliance program works in practice, beyond policies on paper
  • Canadian reporting entities must complete an effectiveness review at least every two years under the PCMLTFR; "independent review" is common industry language, not a separate prescribed statutory term
  • The statutory cycle is the two-year schedule; a FINTRAC examination notice does not itself trigger that statutory review, though entities may choose additional testing when preparing for examination
  • FINTRAC identifies reviewer impartiality as a best practice; external delivery is one option, not a universal legal mandate

What Is an Independent AML Effectiveness Review?

Under Canadian regulation, the prescribed obligation is an AML effectiveness review (sometimes described informally as an AML audit). It is an evidence-based test of whether your AML/ATF compliance program is appropriately designed, current, and operating effectively. That's a very different exercise from confirming a policy manual exists somewhere on a shared drive. "Independent review" is useful industry language for how many entities deliver that obligation; it is not a separate prescribed statutory label.

Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations, the effectiveness review is one of the five prescribed compliance-program elements. FINTRAC lists all five in its compliance program guidance:

  1. A designated compliance officer, appointed and empowered to oversee the program
  2. Written policies and procedures that are current and applied consistently
  3. A documented risk assessment covering clients, products, delivery channels, and geography
  4. An ongoing, written training program for relevant staff
  5. A documented effectiveness-review plan, carried out at least every two years

Independent testing methods support that fifth element; they are not a separate mandatory "pillar" beyond the five elements of FINTRAC's compliance program requirements.

What a Review Actually Examines

What a Review Actually Examines A properly scoped effectiveness review tests, rather than simply describes, the following:

  • Risk assessment methodology and whether its assumptions still match your actual client base
  • Policies and procedures, checked for currency and consistency with obligations
  • Customer due diligence and KYC files, including beneficial ownership records
  • Transaction monitoring and sanctions/PEP screening effectiveness
  • Training records, content, and completion rates
  • The quality and timeliness of STR, LCTR, and other mandatory FINTRAC filings

This applies to every reporting entity under the PCMLTFA: banks, MSBs, securities dealers, casinos, real estate brokers, mortgage lenders, life insurers, and dealers in precious metals and stones. Beyond listing gaps, the review tests whether controls are designed and operating as intended, and sets out the weaknesses and remediation priorities that follow.

AML Effectiveness Review vs. Financial Audit vs. FINTRAC Examination

These three terms get used interchangeably, and that confusion causes real problems. A financial audit tests whether your financial statements are accurate. An AML effectiveness review tests whether your compliance program is designed and operating correctly. A FINTRAC examination assesses whether you meet your legislative obligations. All three differ in methodology, purpose, and consequence.

Dimension Financial Audit AML Effectiveness Review FINTRAC Examination
Who initiates it Entity or external auditor Reporting entity, self-directed or via independent reviewer FINTRAC, on a risk-based selection
Purpose Opine on financial statement accuracy Test program design and operating effectiveness Assess compliance with legislative obligations
Format Substantive and controls testing per audit standards Document review, interviews, sampling On-site or desk-based, per FINTRAC's examination guidance
Possible outcomes Audit opinion on the financial statements Internal findings report to senior management No action, follow-up, AMP recommendation, or Notice of Violation

A strong effectiveness review improves your position heading into a FINTRAC examination, because it identifies control weaknesses and remediation priorities on your own timeline.

The reviewer's background still matters. Someone who has built and defended AML programs and conducted examinations as a regulator can anticipate how findings may be interpreted. That is a different skill set than running through a generic checklist.

How Often Must You Conduct a Review, and What Triggers One?

How Often Must You Conduct a Review, and What Triggers One?

The Two-Year Minimum

Section 156(3) of the PCMLTFR is unambiguous: the review must be carried out and its results documented at least every two years. FINTRAC operationalizes this to mean your next review must start no later than 24 months after the previous one began, and the prior review needs to be finished before the new one starts.

That two-year cycle is a floor, not a target. Higher-risk products, customer segments, delivery channels, or jurisdictions often warrant more frequent or targeted testing between cycles.

Independence and Reviewer Options

FINTRAC identifies reviewer impartiality as a best practice. Depending on the reporting entity's circumstances, the effectiveness review may be conducted by an internal or external auditor, or through a documented self-assessment where no internal or external auditor is available. AlphaDelta provides an independent external review model, but external delivery is not universally required by the legislation.

What May Prompt Additional Testing Outside the Statutory Cycle

The statutory two-year effectiveness-review cycle is set by PCMLTFR s.156. A FINTRAC examination notice does not restart or legally trigger that two-year obligation. Entities may still choose additional testing or readiness work when:

  • An effectiveness-review deadline is approaching or overdue
  • A FINTRAC examination is anticipated or underway
  • Significant business or ownership change occurs, such as an acquisition
  • New products, delivery channels, or jurisdictions launch
  • Prior audit or quality-assurance findings need a remediation check
  • Internally flagged issues arise, including escalated complaints, leadership transitions, or ambiguous new regulatory guidance

The Cost of Skipping It

An accounting firm was hit with a $72,750 administrative monetary penalty in 2025 for failing to institute and document the required effectiveness review every two years, alongside deficient policies and a stale risk assessment.

An effectiveness review isn't a one-time deadline to clear. It belongs on your ongoing compliance calendar—and when independence or capacity is tight, an external reviewer can keep the cycle current without pulling your compliance officer off day-to-day work.

What Does an AML Effectiveness Review Cover? Key Steps and Scope

A properly run review follows a defined sequence rather than a loose set of questions:

  1. Planning and scoping — Define objectives, methodology, and the entity's risk profile against its specific PCMLTFA obligations before any fieldwork starts.
  2. Documentation review — Examine the compliance manual, policies and procedures, and the risk assessment's underlying methodology and assumptions.
  3. Testing and sampling — Pull transaction samples, review CDD and EDD files, and test sanctions and PEP screening for actual effectiveness, not just their presence.
  4. Interviews across the organization — Talk to the compliance officer, frontline staff, and senior management to check whether policy matches daily practice.
  5. Reporting obligations review — Assess the timeliness and quality of STRs, LCTRs, and other mandatory FINTRAC filings.
  6. Reporting and follow-up — Deliver a findings report to senior management and the board, with tracked remediation timelines.

FINTRAC expects this final step in writing: findings, related policy updates, and implementation status must reach a senior officer within 30 days of the review's completion.

Those middle steps—interviews, walkthroughs, and file sampling—often matter more than the manual. A policy can say all the right things about enhanced due diligence, but if frontline staff can't explain when EDD applies or how to escalate a flag, the written program isn't operating effectively. That gap between paper and practice is what a proper review is built to find.

Common Audit Findings and Consequences of Non-Compliance

Across Canadian reporting entities, certain deficiencies show up again and again:

  • Outdated risk assessments that no longer reflect the current client base, product mix, or delivery channels
  • Inconsistent application of enhanced due diligence, particularly for higher-risk clients
  • Incomplete or undocumented training records
  • Weak board-level governance, where AML reporting to senior leadership is thin or infrequent

Left unresolved, these gaps compound. A dealer in precious metals and stones received a $132,000 administrative monetary penalty in 2025.

FINTRAC found no properly developed policies and procedures, no documented risk assessment, no ongoing training program, and no effectiveness review. Four core pillars, all missing at once.

That's the pattern with enforcement cases: rarely one isolated gap, usually a cluster of foundational failures that a timely review would have caught early.

A well-timed audit catches these issues while they're still cheap to fix, before FINTRAC finds them for you.

How to Prepare for an AML Effectiveness Review and Choose the Right Reviewer

Get Your House in Order First

A few practical steps make any review faster and less painful:

  • Maintain a centralized register of AML policy documents, so nothing gets tracked down mid-review
  • Confirm key staff availability, including your compliance officer, frontline staff, and senior management, for interviews
  • Keep training records and CDD/EDD files current and easy to pull on short notice

Preparation only goes so far if the person reviewing your program cannot judge it the way a regulator will.

Why the Reviewer's Seniority Matters

A generic checklist review produces generic findings. A reviewer who has built, owned, and defended AML programs—and who has conducted examinations from the regulator's side of the table—knows what an examiner actually probes for and how findings get judged under real scrutiny.

For Canadian reporting entities whose two-year review is approaching, due, or already overdue, AlphaDelta's independent effectiveness reviews centre on document review, staff interviews, and evidence-based testing. The work is structured to produce documented, evidence-based findings suitable for senior-officer review.

Every engagement includes one optional findings clarification session within 90 days of the final report. If FINTRAC formally initiates a compliance examination within 12 months of the final report, AlphaDelta will provide up to 10 hours of review-related senior advisory support at no additional cost.

If your review is coming up, discuss scope and timing while you still have room to plan.

Frequently Asked Questions

What is an independent AML effectiveness review?

An independent AML effectiveness review is an independent test of whether your AML compliance program is properly designed and actually operating effectively. Unlike a financial audit, it does not opine on the accuracy of your financial statements. "AML audit" is informal secondary language, not the prescribed Canadian regulatory term.

How often is an AML effectiveness review required?

Canadian reporting entities must complete one at least every two years under the PCMLTFR. Higher-risk entities should test more frequently, on a risk basis, between those cycles.

What can trigger an AML effectiveness review?

Scheduled two-year cycles are the statutory baseline. Significant business changes, new products or jurisdictions, and internally identified issues may warrant additional testing. A FINTRAC examination notice does not itself trigger the statutory two-year effectiveness review, though entities often strengthen readiness work when an examination is expected.

Who can conduct an AML effectiveness review?

FINTRAC identifies reviewer impartiality as a best practice. Depending on the reporting entity's circumstances, the effectiveness review may be conducted by an internal or external auditor, or through a documented self-assessment where no internal or external auditor is available. AlphaDelta provides an independent external review model, but external delivery is not universally required by the legislation.

Is an AML effectiveness review the same as a FINTRAC examination?

No. An effectiveness review is self-initiated or independently commissioned by the reporting entity. A FINTRAC examination is regulator-led and can result in penalties or a Notice of Violation.

What happens if an AML effectiveness review finds deficiencies?

Findings should trigger a remediation plan with tracked deadlines and reporting to senior management or the board. Unresolved deficiencies increase the risk of adverse FINTRAC findings and financial penalties.