
FINTRAC and its global counterparts have moved past the "check the box" era of compliance oversight. Many Canadian reporting entities still struggle with a basic question: what does a genuinely effective compliance program assessment actually look like, and how is it different from an audit or a live examination?
That confusion carries real cost. A compliance program assessment isn't a routine internal audit, and it isn't a FINTRAC examination either. It's a distinct, often legally mandated review with its own standards, methodology, and consequences for getting it wrong.
This guide breaks down what a compliance program assessment is, its core components, how to run one properly, and how to pick a partner whose findings support evidence-based decisions under regulatory scrutiny.
Key Takeaways
- FINTRAC requires a documented effectiveness review at least every two years (PCMLTFR subsection 156(3)).
- An assessment tests whether controls work in practice, not just whether policies exist on paper.
- Independence, evidence-based testing, and tracked remediation make a review defensible under scrutiny.
- Skipped or late reviews have drawn real FINTRAC financial penalties in recent enforcement actions.
What Is a Compliance Program Assessment and Why It's Required
A compliance program assessment is an independent, evidence-based evaluation of whether a compliance program is well-designed, current, and actually operating effectively. That last part matters most. Having a policy manual on file proves nothing if nobody follows it.
For Canadian reporting entities under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, this isn't optional. PCMLTFR subsection 156(3) requires the review and its results to be completed and documented every two years. FINTRAC's own guidance frames this as a "two-year effectiveness review," with the next review required to start no later than 24 months after the previous one began.
Who Can Conduct It
The regulation permits an internal or external auditor to perform the review, or the entity itself if it has no auditor. FINTRAC treats independence from day-to-day program operations as a best practice for impartiality rather than an absolute statutory rule. Regulators still notice when the reviewer and the reviewed are too close.
The Broader Regulatory Consensus
Canada isn't alone in expecting this. The U.S. Department of Justice's Evaluation of Corporate Compliance Programs guidance, updated in September 2024, asks three questions of any program:
- Is it well designed?
- Is it adequately resourced and empowered?
- Does it actually work in practice?
The Competition Bureau of Canada echoes this through seven program elements, from management commitment to ongoing program evaluation. Different regulators, same underlying demand: proof, not paperwork.
That demand carries a real enforcement cost. FINTRAC's published notice against a Canadian dealer in precious metals cited, among other findings, a failure to complete the biennial effectiveness review within the required timeframe, together with policy and risk-assessment deficiencies, and imposed a $51,562.50 administrative monetary penalty. (Commentary beyond the published findings and penalty amount is not restated here.) Entities whose review is approaching, due, or overdue should treat the statutory two-year window as non-negotiable.
Core Components of an Effective Compliance Program Assessment
A credible assessment under AlphaDelta's assessment framework (one practical assessment framework, not a FINTRAC taxonomy) covers six interconnected areas. The six-area structure is AlphaDelta methodology. Skipping an area can leave an untested portion of the program.
Governance, Oversight and Accountability
Senior governance needs meaningful reporting, not summary slides, at whatever level the entity's size and structure make appropriate. The compliance officer must hold real independence, authority, and resources. A title on the org chart is not enough.
Risk Assessment Methodology
The review should test whether the risk methodology, assumptions, and inherent-versus-residual ratings genuinely reflect the entity's:
- Products and services offered
- Customer base and relationships
- Delivery channels
- Geographic exposure
Policies, Procedures and Controls
Generic templates rarely match real operations when tested. Policies need to be tailored to the entity's actual risk profile, updated as regulations change, and applied consistently in day-to-day operations.
Training and Communication
Completion rates tell you almost nothing. A strong assessment checks whether role-based training actually reaches at-risk employees, refreshes on a defined schedule, and is measured for comprehension.
Monitoring, Testing and Reporting
This is where assessors evaluate transaction monitoring effectiveness, testing methodology, sample sizes, and the quality and timeliness of suspicious transaction reports. Testing that confirms a control exists without testing whether it operates, and samples too small to support a conclusion, are common weaknesses this area is designed to surface.
Documentation and Remediation Tracking
The program needs an evidence trail. Prior findings that were never tracked to closure are a frequent reason the same gap resurfaces in the next review cycle.
How to Conduct a Compliance Program Assessment: A Step-by-Step Approach
A defensible assessment follows a disciplined sequence. Rushing any step weakens the final report.
- Scope and plan the engagement. Define objectives, the regulatory obligations in scope, timeline, and resourcing, including whether the review needs to meet a formal independence standard.
- Review documents and controls. Examine policies, the risk assessment, prior audit or examination findings, and governance records to build a baseline understanding.
- Test and sample. Run control testing, transaction sampling, and process walkthroughs to confirm whether documented controls are actually operating as designed.
- Interview staff and assess culture. Talk to compliance personnel, front-line staff, and senior leadership to see whether stated policy matches lived practice.
- Analyze gaps and report findings. Rate each finding by severity, prioritize by regulatory and business risk, and deliver clear recommendations to senior management and the board.

This structure mirrors how AlphaDelta approaches Independent AML Effectiveness Reviews for Canadian reporting entities. Engagements start with a scoping discussion, move through document review and evidence-based testing (walkthroughs, interviews, file sampling, data analysis), and close with a findings debrief before the final written report.
Engagement length varies with organizational size, complexity, and scope - AlphaDelta does not publish a fixed universal timeline.
Common Pitfalls That Undermine Compliance Program Assessments
Even well-intentioned reviews can fail for common reasons.
- The "paper program" trap. Confirming policies exist is not the same as confirming controls work in practice.
- Compromised independence. When staff too close to daily operations run the review, credibility collapses the moment a regulator asks who performed it.
- Untracked remediation. Findings left open without a closure mechanism reappear in the next examination cycle—often beside new issues that make the pattern look worse.
Existence-only testing and weak remediation tracking are the two weaknesses most likely to undermine an otherwise sound assessment.
Best Practices for a Defensible AML Compliance Program Assessment
Three practices separate assessments that support evidence-based decisions under scrutiny from ones that don't.
- Anchor testing and documentation to FINTRAC guidance and comparable regulatory standards so findings can be explained and evidenced in an examination
- Escalate findings to the level of senior governance that fits the entity's size, structure and internal governance arrangements, so accountability for remediation sits with people who can authorise it
- Assign named owners, timelines, and closure verification to every recommendation — a static list marked "addressed" is not a remediation plan
Choosing the Right Partner for Your Compliance Program Assessment
Not every assessor brings the same depth. There's a meaningful difference between a generalist reviewer and someone who has actually built, defended, and examined AML programs from the inside.
AlphaDelta's Independent AML Effectiveness Reviews draw on senior AML practitioners with direct experience building, defending, and examining AML programs. Findings are framed so management can understand, explain, and evidence them if FINTRAC comes asking.
Before hiring a partner, ask them:
- What methodology do you use, and how are findings evidence-backed rather than assumption-driven?
- What independence safeguards separate your review team from any prior advisory work with our organization?
- Have you conducted regulatory examinations yourself, or only responded to them?
- Can you support us through an actual FINTRAC examination if one follows the review?
That last question is practical, not theoretical. Every engagement includes one optional findings clarification session within 90 days of the final report. If FINTRAC formally initiates a compliance examination within 12 months of the final report, AlphaDelta will provide up to 10 hours of review-related senior advisory support at no additional cost.
Frequently Asked Questions
What should be included in a compliance program review?
A thorough review covers governance and accountability, risk assessment methodology, policies and controls, training, monitoring and reporting, and remediation tracking. Scope should always reflect the organization's specific risk profile, not a generic checklist.
What are the 3 C's of compliance?
"Culture, Communication, and Controls" is a commonly referenced shorthand, though it isn't an official regulatory framework. FINTRAC and other regulators use their own structured program elements rather than this three-part mnemonic.
How often should a compliance program assessment be conducted?
For Canadian AML programs, FINTRAC requires the effectiveness review at least every two years under PCMLTFR subsection 156(3). Significant program or business changes may warrant an earlier review too.
Who should conduct an AML compliance program effectiveness review in Canada?
The review must be conducted by an internal or external auditor, or by the entity itself if it has no auditor. FINTRAC recommends someone not directly involved in day-to-day compliance activities as a best practice for impartiality.
What's the difference between a compliance audit and a compliance program assessment?
An audit typically tests controls against a fixed checklist. An assessment takes a broader view, evaluating program design, resourcing, and whether controls demonstrably work in real-world practice.
What happens if a compliance program assessment identifies significant gaps?
Findings should be risk-rated, reported directly to senior management and the board, and addressed through a remediation plan with named owners and closure verification. Skipping this step often means the same gap resurfaces at the next review or examination.


