
Introduction
An AML effectiveness review (sometimes called independent testing, and less precisely "AML testing") is the mandatory, evidence-based check on whether your anti-money laundering compliance program actually functions, not just whether it exists on paper. The legal requirement is the effectiveness review - not a mandatory name of "independent AML effectiveness review."
It sounds like a straightforward checklist exercise. It is not. Two reviews of the same program can reach entirely different conclusions depending on scope, sample methodology, reviewer impartiality, and seniority.
A poorly executed review creates false comfort for management and the board - worse than no review at all. For Canadian reporting entities, that gap becomes visible when FINTRAC examines the program.
This article covers when an effectiveness review is required, the steps to run one, what must be in place beforehand, what makes results defensible and well evidenced, and the mistakes that trip up capable compliance teams.
Key Takeaways
- An AML effectiveness review is a Canadian regulatory requirement for reporting entities, completed as a documented review at least every two years (PCMLTFR s.156)
- Legal requirement: test whether the program is current, appropriately designed, and operating effectively
- AlphaDelta recommended methodology often includes outside-ops testing, severity ratings, senior-officer reporting, and follow-up testing - these practices support defensibility but are not each universal statutory mandates in that form
- Risk-based scoping, sample methodology, and reviewer competence determine review quality
- Outside-ops testing, board escalation, severity ratings, and formal action plans are recommended practices, not universally mandatory for every entity in every structure
How to Conduct an AML Effectiveness Review: A Step-by-Step Process
A defensible AML test follows a consistent, risk-based methodology regardless of institution size. It moves through five stages: scoping and planning, governance and policy testing, CDD and onboarding testing, transaction monitoring and screening testing, and findings and remediation. Skip a stage or rush it, and the whole review loses credibility.
Step 1: Scope and Plan the Review
Start with the entity's most recent enterprise-wide risk assessment. It tells you which products, customer types, and geographies carry the highest money laundering exposure, and that's where testing effort should concentrate.
Before fieldwork begins, document:
- The review period and specific objectives
- Focus areas: governance, CDD/KYC, transaction monitoring, sanctions/PEP screening, training, reporting
- Confirmation of who will conduct the review (internal auditor, external auditor, or the entity itself if no auditor exists) and how impartiality is preserved relative to day-to-day program development and maintenance
This documentation matters. A written plan with defined methods and sample sizes supports a defensible file; starting without a paper trail weakens the review.
Step 2: Test Governance, Policies, and the Risk Assessment
Check whether written policies actually reflect current PCMLTFA/PCMLTFR obligations and the entity's real business and risk profile, not last year's version with a new date stamped on it.
From there:
- Test whether the risk-rating methodology is applied consistently across customer files
- Confirm ratings are current, not left over from onboarding years ago
- Review evidence of senior management and board approval, oversight, and genuine challenge of the program
A risk assessment that hasn't been touched since a merger or new product launch is a red flag—catch it early.
Step 3: Test Customer Due Diligence and Onboarding Controls
Sample customer files across risk tiers. Verify identity verification, beneficial ownership, and source-of-funds documentation were completed properly, not just marked as done in a system field.
For high-risk and politically exposed persons:
- Confirm enhanced due diligence steps were actually performed, not merely triggered by a rule
- Check that source-of-wealth and source-of-funds documentation exists and is substantive
- Verify senior management reviewed and approved keeping the relationship open, where required
Finally, check whether periodic monitoring cycles for existing customers are being met on schedule, not slipping quietly behind.
Step 4: Test Transaction Monitoring, Sanctions, and PEP Screening
Validate that monitoring scenarios and thresholds reasonably cover the typologies relevant to this specific entity's risk profile, rather than a generic template borrowed from a peer institution.
Sample a set of generated alerts and ask:
- Were investigations thorough and properly documented?
- Were suspicious transactions escalated or reported when warranted?
- Is sanctions and PEP screening current, and does it catch near-matches and aliases, not just exact hits?
The stakes here are real. FINTRAC's 2024 penalty decision against a bank found the entity failed to file 5 STRs across 26 reviewed files and missed required ongoing monitoring in 8 of those 26 files. That is the kind of gap a properly scoped test is built to surface through evidence-based testing.
Step 5: Document Findings and Drive Remediation
A defensible methodology rates findings by severity and reports results in writing to a senior officer (PCMLTFR expects written reporting of effectiveness-review findings). Board escalation is good governance practice where applicable, not a universal FINTRAC prescription for every finding.
Recommended remediation practices include:
- A corrective action plan with a named owner
- A firm deadline
- Follow-up testing to confirm the fix actually worked
These steps support operating effectiveness; they are AlphaDelta-recommended methodology rather than a universal mandatory checklist for every entity.
When Should You Conduct an AML Effectiveness Review?
An AML effectiveness review is not purely an annual calendar event. Both regulatory minimums and risk-based triggers determine timing.
Under PCMLTFR section 156, reporting entities must complete a documented effectiveness review at least every two years. Findings must be reported in writing to a senior officer within 30 days of completion.
That cycle is the same whether you're a bank, an MSB, a life insurer, or a securities dealer. There's no separate timeline by sector.
That said, waiting for the two-year mark isn't always wise. Consider testing sooner when:
- Material changes to the AML program itself
- Expansion into new products, services, or geographies
- A merger or acquisition that changes the risk profile
- Prior audit or FINTRAC findings that warrant a targeted retest
If your review is approaching, overdue, or already flagged as a gap, a risk-based, evidence-based assessment is appropriate regulatory exposure management. Overdue reviews can surface as larger findings at the next examination. Timing and depth should reflect your risk profile and statutory cycle, not a generic "conduct testing now" imperative.

What You Need Before Conducting an AML Effectiveness Review
Preparation and the right expertise directly determine how well a test's conclusions are evidenced and documented.
Reviewer Options and Impartiality
FINTRAC permits an internal auditor, an external auditor, or the reporting entity itself if no auditor exists. Impartiality (a reviewer not directly involved in developing or maintaining the program) is best practice, not a universal legal rule that every reviewer must be independent from all day-to-day compliance activity in every structure.
When internal teams cannot provide structural separation or independent challenge, many Canadian reporting entities engage senior AML advisory firms such as AlphaDelta to lead or validate the effectiveness review. External delivery remains optional where internal options are available and properly separated.
Documentation and Data Readiness
Gather the following before fieldwork starts:
- Current policies and procedures
- The most recent risk assessment
- Training records
- Prior exam or audit findings
- Representative transaction and customer data
Missing any of these mid-review stalls testing and forces rework later.
Governance Sponsorship
Secure senior management and board sign-off on scope, budget, and full access to systems and staff before work begins. A review constrained halfway through because someone forgot to approve system access produces weaker conclusions and wastes everyone's time.
Key Factors That Determine AML Effectiveness Review Quality
Two reviews covering the "same" program can produce very different conclusions depending on how these variables are controlled.
| Factor | Why It Matters | Impact on Quality |
|---|---|---|
| Risk-based scoping depth | Scoping that ignores the actual risk assessment tests the wrong controls | Superficial scoping misses the highest-risk exposures a regulator would expect to be covered |
| Sample size and methodology | Judgmental vs. statistical sampling changes how far findings can defensibly extend | Undersized or non-representative samples produce findings that don't generalize to the full population |
| Tester seniority and impartiality | Junior or conflicted internal testers may lack the authority to challenge management's assumptions | Best practice is an impartial reviewer who understands the entity's obligations; weak separation often shows up as thin method and sample-size documentation |
| Technology and data access | Testers need real access to monitoring, screening, and case management systems, not just policy binders | Limited system access means automated controls get tested on paper, not in practice |
None of these factors work in isolation. Deep scoping with a tiny sample still misses things. Senior testers without system access still can't verify whether screening tools actually catch near-matches. Quality comes from getting all four right at once.
Common Mistakes in AML Effectiveness Reviews
Some mistakes show up so consistently across reviews that they're worth naming directly.
- Treating the review as a checkbox exercise. Confirming a policy exists is not the same as confirming it's followed.
- Using testers who lack real independence or seniority. A reviewer who can't push back on management's assumptions produces a rubber stamp, not a test.
- Scoping samples too narrowly. Emerging risk areas like trade-based laundering or virtual asset exposure get overlooked when sampling follows last year's template.
- Failing to track remediation to completion. A deficiency closed on paper resurfaces at the next review, or worse, at the next FINTRAC examination.
The cost of getting this wrong isn't hypothetical. FINTRAC's 2025 penalty against a virtual-currency MSB, $176,960,190 AMP (2025), under appeal to Federal Court where that status applies, found the entity failed to file 1,068 STRs tied to darknet markets and criminal wallets. Its risk assessment never accounted for its own products, channels, or client relationships.
The confirmed penalty reached $176,960,190 and is currently under appeal. Whatever the final figure, the case shows what happens when testing never reaches the risk areas that actually matter.
Frequently Asked Questions
What triggers AML checks?
AML checks and effectiveness testing are triggered by regulatory minimum timelines and by risk events—material program changes, new products or markets, mergers, or findings from a prior audit or examination.
What is anti-money laundering screening?
Screening means checking customers and transactions against sanctions, PEP, and watchlists in real time. It's one control validated within a broader AML test, not the test itself.
How much should an AML check cost?
Cost depends on entity size, risk profile, and scope. Fixed-fee independent reviews are common; the real cost risk is an inadequate review that fails under regulatory scrutiny.
How often is an AML effectiveness review required in Canada?
At least every two years under the PCMLTFR (Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations), with results reported to a senior officer within 30 days. Higher-risk firms should test more often.
Who can perform an AML effectiveness review?
An internal auditor, an external auditor, or the entity itself if it has no auditor. Impartiality relative to developing or maintaining the program is best practice. Many entities engage external specialists such as AlphaDelta when they want independent challenge.
What happens if an AML effectiveness review finds deficiencies?
Findings should be reported in writing to a senior officer. Severity ratings, board escalation, and formal action plans are possible governance practices - not universal statutory mandates for every structure. Address issues through a corrective action plan with named owners and deadlines where management so decides, and validate fixes with follow-up testing.


