Compliance Reviews and Audits Many compliance officers use "compliance review" and "audit" interchangeably. That's a mistake with real consequences.

Canadian reporting entities face a mandatory AML effectiveness review at least every two years, alongside the possibility of a FINTRAC examination at any time. Confusing the two leads to poor preparation, thin documentation and findings that catch senior management off guard.

The stakes are real. In fiscal 2023-24 alone, FINTRAC issued 12 Notices of Violation totalling more than $26 million and conducted 123 formal examinations, according to FINTRAC's 2023-24 Annual Report. Undetected program gaps don't stay hidden forever.

This guide breaks down the difference between reviews and audits, what triggers each, and how to prepare with the rigour a regulator expects.

Key Takeaways

  • A compliance review (effectiveness review) is entity-led and proactive; a FINTRAC examination is regulator-led, formal and consequential - they are not the same thing
  • Scope, independence, frequency and reporting lines drive how you prepare, who owns the work and what gets reported
  • Effectiveness-review triggers centre on the statutory two-year cycle; FINTRAC examinations use risk-based selection, not a universal fixed examination schedule
  • Strong documentation and evidence-based testing support a defensible program posture
  • Practitioner-level guidance helps programs work in practice, not just on paper

Compliance Review vs. Compliance Audit: Key Distinctions

A compliance review, in the Canadian AML context, is the legislated "effectiveness review": a self-assessment of whether your policies, procedures and controls are current and actually working.

It is required under Regulation 156(1)(f). Regulation 156(3) requires it to be documented at least every two years and conducted by an internal or external reviewer, or by the entity itself if it has none, according to the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations.

What many teams call a compliance audit is often confused with a FINTRAC examination. A FINTRAC examination is regulator-led, scoped using FINTRAC's own risk analysis, and can include document requests, staff interviews, transaction sample testing, and a formal findings letter. A compliance review is not usually a FINTRAC examination; the two remain distinct processes.

Comparing the Two

Factor Compliance Review FINTRAC Examination
Who conducts it Internal/independent reviewer FINTRAC examiners
Control Entity-controlled scope Regulator-controlled scope
Frequency At least every 2 years Risk-based selection, any time
Reporting line Senior officer Senior officer, board, regulator
Consequence Internal action items Findings letter, possible AMP

Compliance review versus FINTRAC examination comparison chart differences

Entities conflate the two because both test controls against the same underlying obligations. Independence and consequence still differ sharply. A review is an internal exercise you control; an examination is a regulatory process with statutory consequences.

That difference matters. A Canadian bank's December 2023 penalty of $7,475,000 followed a compliance examination that found missed suspicious transaction reports and outdated written policies, according to FINTRAC's enforcement release. A program that passes an internal review on paper can still fail under regulator scrutiny if operating effectiveness was never truly tested.

What Triggers a Compliance Review or Audit?

Keep three distinct clocks separate:

Statutory effectiveness review cadence

  • The legislated two-year effectiveness review cycle (PCMLTFR s.156) is non-negotiable: the clock resets from when the previous review started, not when it finished
  • This is not a universal FINTRAC examination cycle, and it is not a "scheduled cyclical FINTRAC examination" requirement

Internal or voluntary reviews

  • Leadership transitions, program redesign, new technology, M&A due diligence, or material changes to products, customers, or delivery channels may warrant an internal or voluntary review outside the statutory effectiveness-review clock

Risk-based FINTRAC examinations

  • FINTRAC uses internal risk analysis and public information to select entities for examination; there is no universal fixed examination schedule for every reporting entity
  • Thematic or sweep reviews may target areas such as virtual currency, new payment methods, and sanctions evasion
  • FINTRAC's own bulletin flags cryptocurrency exposure as a key emerging risk in sanctions evasion cases
  • For-cause selection can follow prior deficiencies, whistleblower reports, unusual patterns, or public scrutiny

Its 2024-25 Annual Report cites over 1,300 assessment activities and 294 formal examinations, with attention noted on fentanyl trafficking, professional money laundering, and sanctions evasion. These are dated annual-report figures.

If your entity touches elevated risk areas, a proactive internal review can still make sense without treating FINTRAC exams as a routine periodic statutory duty.

How to Conduct an Effective AML Compliance Review

Step 1: Define the Applicable Standards and Scope

Start by identifying which obligations actually apply to you. Your reporting entity type, products, customers and delivery channels determine the scope. A mortgage broker and a securities dealer face different testing priorities under the same underlying framework.

Document the rationale, review period, methods and sample sizes before fieldwork begins. That record is what makes your conclusions defensible when someone later asks how you scoped the work.

Step 2: Assess the Risk-Based Approach and Controls

Don't just confirm the risk assessment exists. Test whether its methodology and assumptions actually reflect your current business and regulatory environment.

Products change. Customer bases shift. Delivery channels evolve. A risk assessment written three years ago for a different product mix isn't protecting anyone.

Step 3: Test Design and Operating Effectiveness

These are two separate questions:

  1. Design — does a policy exist, and is it appropriately built for your risks?
  2. Operating effectiveness — do staff actually follow it, day to day, in practice?

Testing operating effectiveness means interviews, walkthroughs, file sampling and end-to-end transaction testing, not just reading the policy manual. AlphaDelta's review engagements, for example, separate these two questions explicitly: document review establishes design, while sampling and walkthroughs confirm what actually happens on the ground.

Step 4: Document Findings and Build a Remediation Plan

Every finding needs:

  • Supporting evidence
  • A risk-prioritized ranking
  • A realistic corrective action timeline

Vague findings lead to vague remediation. Findings tied to clear evidence give teams action plans they can execute.

Step 5: Brief Senior Management and the Board

Findings need translation into governance-ready language for the senior officer who must receive written reporting. A poorly communicated finding, buried in technical jargon or minimized in a slide deck, can draw deeper examination scrutiny later. Clear senior-officer communication at this stage is part of managing regulatory risk; universal board approval of review scope or findings is not a FINTRAC requirement.

Five-step AML compliance review process from scope to board briefing

Addressing Findings from a Review, Audit or Examination

When FINTRAC identifies significant deficiencies, it may request a formal action plan in certain examination cases. When an action plan is requested, it is generally due within 30 calendar days of the findings letter, unless FINTRAC states otherwise.

To respond effectively:

  • Assign clear ownership for each corrective action, with named individuals, not departments
  • Track implementation against deadlines with documented evidence of completion
  • Distinguish root causes from symptoms: a superficial fix (like updating a policy without retraining staff) tends to resurface in the next cycle

FINTRAC may follow up with an on-site or desk examination, or simply monitor your action plan's progress. Either way, the goal is addressing the cause of a deficiency within a reasonable time, not just checking a box.

Why Senior AML Expertise Matters When Facing a Review or Examination

Most AML programs don't fail because policies are missing. They fail because nobody tested those policies against real operating conditions — with the eyes of someone who has sat on both sides of the regulatory table.

AlphaDelta was built around that gap. Its practitioners have:

  • Built and owned AML programs inside institutions
  • Defended those programs during audits and regulatory examinations
  • Conducted examinations as a regulator

That third perspective is rare, and it changes how you anticipate findings. Understanding how examiners interpret obligations, test controls and form conclusions means preparing for scrutiny before it arrives, not scrambling after a findings letter lands.

AlphaDelta's Independent AML Effectiveness Review engagements reflect this:

  • Tailored, risk-based testing of design and operating effectiveness
  • Evidence-backed findings
  • Every engagement includes one optional findings clarification session within 90 days of the final report. If FINTRAC formally initiates a compliance examination within 12 months of the final report, AlphaDelta will provide up to 10 hours of review-related senior advisory support at no additional cost.

This same depth of experience supports compliance leaders navigating role transitions, program redesigns or high-stakes decisions: situations where guidance grounded in lived accountability matters more than theoretical knowledge.

Frequently Asked Questions

What triggers a compliance review?

Triggers include the statutory two-year effectiveness review cycle, FINTRAC's risk-based examination selection, complaints, or significant internal program changes like new products or leadership transitions.

What does good AML compliance look like in practice?

A reporting entity that consistently completes and documents risk-based KYC and transaction monitoring in line with its own written policies, with evidence available for testing.

How often must Canadian reporting entities undergo an AML effectiveness review?

At least every two years, per Regulation 156(3). Don't wait until it's overdue. Start assessing readiness well before the deadline approaches.

What is the difference between a FINTRAC examination and an internal compliance review?

A review is entity-controlled, proactive and internal. An examination is regulator-led and formal, and can result in a Notice of Violation or administrative monetary penalty.

What happens if significant deficiencies are found?

In certain cases FINTRAC may request a written action plan. When requested, it is generally due within 30 days unless otherwise stated, and FINTRAC may follow up with further examination or ongoing monitoring until deficiencies are resolved.

Who should conduct an AML effectiveness review?

Under PCMLTFR s.156(3) the review may be carried out by an internal auditor, an external auditor, or by the entity itself if it has no auditor. FINTRAC treats impartiality as a best practice rather than a universal legal rule. In practice, a reviewer who understands how programs are built, defended and examined adds more than one who only checks how policies are worded on paper.