
Many brokerages are still catching up. Compliance programs get built reactively, often without a dedicated AML background on staff, leaving gaps that surface when FINTRAC examines the program.
This article covers who's affected, the five program elements FINTRAC expects, the red flags specific to mortgage transactions, the penalties for getting it wrong, and how to move from a policy binder to a program that works in practice under examination.
Key Takeaways
- Mortgage administrators, brokers, and lenders became FINTRAC reporting entities on October 11, 2024, with full PCMLTFA obligations
- Five program elements are mandatory: compliance officer, written policies, risk assessment, staff training, and a biennial review
- Non-compliance risks administrative monetary penalties and, in serious cases, criminal charges
- Written policies alone won't pass an examination; FINTRAC wants proof the program works
Who Must Comply: Mortgage Brokers, Administrators and Lenders Under FINTRAC
The amended regulations define three regulated categories, and the distinctions matter because they determine which obligations apply:
- Mortgage administrators — businesses that service mortgage or hypothec agreements on behalf of lenders
- Mortgage brokers — provincially authorized intermediaries connecting lenders and borrowers
- Mortgage lenders — non-financial-entity businesses that issue loans secured by real property or immovables
Financial entities already regulated elsewhere under the PCMLTFA (banks, credit unions) are excluded from these specific definitions, since they're covered under their own reporting-entity category.
Size doesn't matter here. A two-person brokerage carries the same federal obligations as a national lending shop.
These requirements also sit on top of provincial licensing rules, not instead of them. Think BCFSA's Mortgage Brokers Act requirements or FSRA's oversight in Ontario. If you're unsure whether your business qualifies, FINTRAC's Mortgage Sector Self-Assessment Tool is the fastest way to confirm.
Provincial regulators have reinforced the message. BCFSA and FSRA have both issued advisories aligning with FINTRAC's expectations, so brokers now face scrutiny from two directions at once: provincial and federal.
The Five Pillars of a FINTRAC-Compliant AML Program
FINTRAC doesn't assess a single policy document. It assesses a full program, and each of the following five elements gets tested independently during an examination.
The prescribed program components FINTRAC tests are:
- Compliance officer and governance with real authority and clear escalation paths
- Written policies and procedures tailored to your actual operations
- Ongoing risk assessment across products, clients, channels, and geography
- Role-specific, ongoing training tied to day-to-day red flags and reporting
- A two-year effectiveness review that tests whether the program actually works

Compliance Officer and Governance
Every reporting entity needs a compliance officer with real authority — not a title tacked onto someone's existing job with no budget or access to leadership. Examiners look closely at reporting lines and escalation paths. If your compliance officer can't reach senior management quickly when something suspicious surfaces, that's a governance gap FINTRAC will flag.
Written Policies and Procedures
Generic templates don't cut it. Policies must reflect your brokerage's actual operations, client base, and risk tolerance — not a boilerplate document purchased online. A one-hour webinar certificate filed away in a drawer doesn't demonstrate customization either. FINTRAC expects procedures tailored to how your business actually runs.
Risk Assessment
Your risk assessment needs to weigh products, clients, delivery channels, and geography — and it can't be a one-time exercise. As your client base shifts or you add new lending products, the assessment needs updating to match.
Training Program
Onboarding training once and calling it done won't satisfy FINTRAC. Training has to be role-specific and ongoing, covering how to spot red flags and when reporting obligations kick in for the people actually handling client files day to day.
Two-Year Effectiveness Review
Every 24 months, the program must be tested for whether it's current and actually functioning. FINTRAC has stated that mortgage entities brought under the regime in October 2024 should complete their first review before October 11, 2026. An independent or external reviewer is a best practice and a common service model; it is not a universal statutory requirement that every effectiveness review must be external. Internal self-assessment can still miss design flaws and operating gaps that surface under evidence-based testing—the core of a FINTRAC biennial effectiveness review.
Customer Due Diligence and Red Flags in Mortgage Transactions
Identity Verification Methods (Prescribed Triggers)
Client identification is not an every-client, every-measure obligation. FINTRAC's prescribed ID requirements apply when statutory triggers are met (for example, large cash or virtual currency transactions, certain business relationships, and other activity-based thresholds). When a trigger applies, FINTRAC accepts several verification methods; three are most relevant for mortgage transactions:
| Method | What's required |
|---|---|
| Government-issued photo ID | Valid, current document with name, photo, and unique number; record document type, number, and expiry |
| Credit file | Canadian credit bureau file at least three years old, matching name, address, and birth date |
| Dual process | Two independent, reliable sources confirming name plus address, birth date, or a financial account |
Each method comes with its own documentation standard, and skipping the paper trail is one of the fastest ways to fail a file review. Separate business-relationship (BR) rules also apply once a BR is established; those are distinct from one-off transaction ID.
Politically Exposed Persons and High-Risk Clients
Identity verification alone is not enough when PEP/HIO rules are triggered. Brokers must distinguish account-based and non-account PEP/HIO determination rules, and apply enhanced measures on a risk-based basis rather than treating every client as high risk by default. Receiving $100,000 or more in cash or virtual currency triggers a mandatory PEP/HIO determination regardless of prior screening.
Where a foreign PEP or related party is involved in a transaction of that size, you'll need to establish source of funds and source of wealth within 30 days, plus obtain senior-management sign-off. Domestic PEPs and HIOs trigger the same enhanced measures once the relationship is assessed as high risk. Ongoing monitoring and enhanced due diligence scale to risk; they are not a universal checklist applied identically to every file.
Red Flags Unique to Mortgage and Real Estate Transactions
Beyond formal PEP determinations, day-to-day deal patterns often surface the risk first. Transaction-based red flags include:
- Property purchased significantly above or below fair market value
- Rapid refinancing shortly after the initial purchase
- Large, unexplained mortgage pre-payments
- Down payments structured in amounts just under the $10,000 reporting threshold
Behavioural and profile-based red flags include:
- Reluctance to meet in person or provide standard documentation
- A financial profile inconsistent with stated income or occupation
- Down payments funded by unrelated third parties
- Source of funds that can't be clearly explained

None of these confirm wrongdoing on their own. What they should trigger is a closer look, escalation to your compliance officer, and, where warranted, a suspicious transaction report.
Ignoring a pattern of red flags because a deal is profitable is precisely the scenario examiners probe for.
Reporting Obligations, Recordkeeping and Penalties for Non-Compliance
Mortgage entities must file with FINTRAC using one of several report types:
- Suspicious Transaction Reports (STRs) — no dollar threshold; filed as soon as practicable once suspicion arises
- Large Cash Transaction Reports (LCTRs) — cash of $10,000 or more, filed within 15 calendar days
- Large Virtual Currency Transaction Reports (LVCTRs) — virtual currency equivalent of $10,000 or more
- Listed Person or Entity Property Reports — replacing the former Terrorist Property Report as of October 2025
Submissions go through FINTRAC's Web Reporting System for lower-volume filers, or its API for high-volume reporters.
On the recordkeeping side, client identification records, transaction records, and receipt-of-funds documentation must be retained for a minimum of five years from creation. STR copies follow the same five-year rule, measured from submission date.
Non-compliance carries material consequences:
- Administrative penalties: For violations committed on or after 26 March 2026, AMP amounts are set under the Proceeds of Crime (Money Laundering) and Terrorist Financing Administrative Monetary Penalties Regulations (SOR/2007-292, s. 5), and s. 73.1 of the Act caps a prescribed violation at $4,000,000 for a person and $20,000,000 for an entity. Legacy amounts continue to apply to violations committed entirely before 26 March 2026.
- Criminal sanctions: Knowingly contravening the Act can mean fines up to $5 million and imprisonment up to five years on indictment, per section 74 of the PCMLTFA.
- Business impact: Damage with lenders, insurers, and referral partners pushes the true cost well past any fine.
Beyond the Checklist: Building an AML Program That Works in Practice
Plenty of newly regulated mortgage entities have produced a document that looks compliant. Far fewer have tested whether it actually functions when someone outside the business starts asking questions. That gap between paper compliance and operational effectiveness is exactly what the mandatory two-year review is designed to expose. Treat it as an opportunity, not just a box to tick.
Internal self-review has a blind spot: the people who built the program are rarely the best judges of where it breaks down. An independent, evidence-based review surfaces design and operating gaps that self-assessment misses. Effective reviews typically include:
- Document analysis of policies, procedures, and records
- Staff interviews across compliance and front-line roles
- File sampling and walkthroughs of actual transactions
Examination readiness is its own discipline, separate from the review itself. Before FINTRAC contacts you, you need:
- A clear regulatory posture
- A communication plan for regulator engagement
- A response strategy that is not built under deadline pressure
Reactive scrambling during a live examination rarely goes well.
Risk assessments deserve the same independent challenge. A methodology built years ago, or borrowed from a template, may no longer reflect the brokerage's actual products, clients, and delivery channels.
AlphaDelta works with Canadian reporting entities, including mortgage administrators, brokers, and lenders, on these gaps. Independent AML Effectiveness Reviews use document review, interviews, and evidence-based testing to determine whether a program is genuinely operating as designed. Engagements also include:
- Every engagement includes one optional findings clarification session within 90 days of the final report. If FINTRAC formally initiates a compliance examination within 12 months of the final report, AlphaDelta will provide up to 10 hours of review-related senior advisory support at no additional cost.
For brokerages preparing for or navigating an active examination, Senior AML Advisory is available as a retainer, defined engagement, or hourly support. The work draws on practical Canadian regulatory and program experience, giving mortgage clients a practical view of how findings actually get formed.
Frequently Asked Questions
What is the AML policy for mortgage brokers?
A firm-specific written compliance program covering client identification, risk assessment, recordkeeping, reporting, and staff training as required under the PCMLTFA. It must reflect the brokerage's actual operations, not a generic template.
Do mortgage lenders do AML checks?
Yes. Since October 2024, mortgage lenders must apply prescribed client identification when statutory triggers apply, screen for PEPs/HIOs under the applicable account or non-account rules, and monitor for suspicious activity on a risk-based basis, the same as brokers and administrators.
When did FINTRAC's AML requirements for mortgage brokers take effect?
October 11, 2024, under the amended PCMLTFA regulations (SOR/2023-194). This marked the first time mortgage administrators, brokers, and lenders became formal FINTRAC reporting entities.
What happens if a mortgage broker fails a FINTRAC examination?
Outcomes can include administrative monetary penalties, mandatory remediation timelines, and reputational damage with lenders and referral partners. Serious or knowing violations can escalate to criminal charges under section 74 of the Act.
How often must mortgage brokers review their AML compliance program?
Every two years, at minimum. Mortgage businesses that became subject to the Act on 11 October 2024 were expected to complete their first two-year effectiveness review before 11 October 2026. Independent or external delivery is best practice, not a universal statutory requirement.
What are common money laundering red flags in mortgage transactions?
Common red flags include:
- Properties bought well above or below market value
- Rapid refinancing shortly after purchase
- Down payments structured just under the $10,000 reporting threshold


