
That mismatch is a common source of residual risk that FINTRAC examinations and independent reviews can surface.
Many compliance teams use "control gap analysis," "risk assessment," and "audit" interchangeably. They're not the same thing, and confusing them leads to wasted effort and missed exposure. This post defines control gap analysis precisely for Canadian reporting entities, covers the types of gaps you'll encounter, walks through a defensible four-step process, and explains when your organization actually needs one.
Key Takeaways
- Control gap analysis compares what your AML program should do against what it actually does in practice
- Four gap categories (performance, design, knowledge, resource) are an AlphaDelta analytical framework; each needs different remediation
- Structured four-step processes produce defensible, evidence-based results
- Gap analysis informs risk assessments and effectiveness reviews but does not replace either
- Independent, senior-level challenge can surface gaps internal teams miss; clients retain ownership of remediation and management decisions
What Is Control Gap Analysis in an AML Context?
A control gap analysis compares the controls your risk-based approach and written policies say should exist with what is actually operating, evidenced, and effective on the ground.
This is different from a compliance checklist. A checklist confirms a document exists. A gap analysis tests whether the control functions as intended against your current risk exposure. You can have a perfectly written enhanced due diligence procedure and still have a serious gap if front-line staff aren't applying it.
It also differs from two related exercises:
- Risk assessment: identifies inherent and residual ML/TF risk across your products, clients, and channels
- Effectiveness review: the broader, FINTRAC-mandated periodic assessment of your entire program
Control gap analysis usually feeds into both. It's the mechanism that tells you whether the controls your risk assessment relies on are actually there.
Where Undetected Gaps Come From
Certain conditions consistently produce gaps that internal teams miss:
- Manual controls that depend on individual diligence rather than systematic enforcement
- Recent changes in compliance leadership or program ownership
- Newly added products, jurisdictions, or delivery channels that haven't been fully absorbed into the control framework
FINTRAC's own guidance is direct: risk is not static, and new products, services, technologies, or business-model changes should trigger a fresh look at whether your controls still fit (FINTRAC risk assessment guidance).
Gaps can remain undetected until an examination or independent review tests operating effectiveness. That is why proactive analysis matters more than reactive fixes.
Common Types of Control Gaps
The four categories below are AlphaDelta's analytical framework for classifying control gaps. They are not a FINTRAC-prescribed taxonomy. Not all gaps are the same problem wearing different clothes. Misclassifying one leads directly to the wrong fix.
Performance gaps happen when a control is documented, assigned an owner, and looks fine on paper — but isn't operating as intended. A transaction monitoring rule exists, has an owner, and still isn't catching what it should.
Design/opportunity gaps occur when your control framework hasn't kept pace with the business. You added a new delivery channel or entered a new jurisdiction, but the controls weren't redesigned to match.
Knowledge gaps arise when staff lack the training or expertise to execute a control correctly. This is common after a new compliance officer joins or leadership transitions, and the institutional knowledge behind a control walks out the door.
Resource gaps show up when the control design is sound but under-resourced. Staffing, technology, or time constraints mean the control can't operate consistently at scale. It works for 20 files a week, not 200.
| Gap Type | Root Issue | Typical Fix |
|---|---|---|
| Performance | Control exists but isn't executed correctly | Retraining, supervision, process redesign |
| Design/Opportunity | Framework hasn't adapted to new risk | Rebuild control to match current exposure |
| Knowledge | Staff lack expertise | Structured training, mentoring |
| Resource | Under-resourced for scale | Staffing, automation, reprioritization |

The Four-Step Process for Conducting a Control Gap Analysis
Step 1: Define Current and Desired States
Map your existing controls against three references: regulatory obligations, internal policy, and your entity's risk-based approach. This baseline tells you what "should" be happening before you test what "is" happening.
Skip this step and you'll end up testing controls against assumptions instead of documented requirements. That is a weak position if FINTRAC asks how you arrived at your conclusions.
Step 2: Identify and Classify the Gap
Once you spot a discrepancy, classify it. The category drives the fix:
- Performance: supervision and process discipline
- Design: control logic, thresholds, or workflow redesign
- Knowledge: training, guidance, or escalation criteria
- Resource: staffing, capacity, or technology investment
Treat a resource gap like a performance gap (retrain people instead of adding capacity) and it will resurface within a quarter.
Step 3: Investigate Root Cause
Don't accept the first explanation offered. Use root cause interviews and control-ownership tracing to get past surface-level answers like "we were busy" or "the system flagged it late."
Ask why the control failed, who owned it, what changed, and whether earlier warning signs were ignored. When root causes stay unaddressed, the same deficiency can reappear in later reviews or examinations.
Step 4: Build and Validate an Action Plan
A remediation plan needs three things to hold up under scrutiny:
- Clear ownership — a named individual accountable for the fix, not a department
- Realistic timelines — dated milestones, not vague commitments
- Evidence of testing — proof the fix actually works, not just that it was implemented
A plan without documented validation is only a promise. It will not hold up under an Independent AML Effectiveness Review or a FINTRAC examination.

A Worked Example
Your enhanced due diligence (EDD) control exists on paper. Policy requires high-risk files to escalate within 48 hours, yet some sit a week before review.
- Step 1: Required state is 48-hour escalation; current average is 6 days.
- Step 2: Performance gap — design is sound, execution is failing.
- Step 3: Staff lack clear escalation triggers, and no automated reminder flags the deadline.
- Step 4: Publish a trigger list, add a 24-hour system reminder, name a supervisor as owner. Retest shows average escalation at 36 hours within six weeks.
Why Control Gap Analysis Matters for Risk and Regulatory Exposure
Unaddressed control gaps carry real consequences: examination findings, remediation orders, reputational damage, and in serious cases, financial penalties.
In its 2024-25 fiscal year, FINTRAC conducted 294 formal examinations and issued 23 Notices of Violation totaling more than $25 million, the largest annual number in FINTRAC's history (FINTRAC 2024-25 Annual Report). The agency also recorded 32 non-compliance disclosures that year, compared with 14 the year before. These are dated annual-report figures, not a claim about future enforcement intensity.
This isn't abstract. In 2024, FINTRAC imposed a $9.185 million AMP against a Canadian bank for interconnected failures spanning risk assessment, high-risk client measures, ongoing monitoring, and suspicious transaction reporting (FINTRAC notice). Gaps in one control area tend to weaken others downstream.
Gaps widen fastest during periods of change:
- Leadership transitions
- Rapid business growth
- New product or service launches
- Organizational restructuring
Each of these moments deserves a fresh gap analysis, not just a note for the next scheduled review. Control gap analysis works best as a continuous input into your risk-based approach, not a box you check once every two years.
When Should Your Organization Conduct One — and Who Should Lead It
Certain triggers should prompt a control gap analysis without waiting for the calendar:
- An effectiveness review is due, overdue, or approaching (FINTRAC requires an effectiveness review at least every two years under PCMLTFR s.156; that cadence is not a standalone gap-analysis mandate)
- You're preparing for, or responding to findings from, a FINTRAC examination
- Significant program or personnel change has occurred
- A new product, service, or delivery channel is launching
Why Independent Review Catches What Internal Teams Miss
Internal teams live inside the program every day. That proximity is valuable for operational knowledge, but it's also a blind spot. Assumptions baked into a risk assessment years ago often go unquestioned simply because no one steps back far enough to challenge them.
An independent, senior-level perspective often surfaces gaps in risk assessment methodology and control design assumptions that internal teams may not challenge.
Who leads the work matters as much as when you run it. A senior AML advisor can challenge the analysis so internal assumptions get tested, not reinforced. Client management retains ownership of the analysis conclusions, remediation decisions, and regulatory outcomes.
AlphaDelta provides Canadian reporting entities with Senior AML Advisory and Independent AML Effectiveness Reviews grounded in direct regulatory and institutional experience. That vantage point supports independent challenge of risk assessments, control frameworks, and testing approaches.
Frequently Asked Questions
What are the four types of gap analysis?
AlphaDelta groups control gaps into four diagnostic types (not a FINTRAC taxonomy):
- Performance gaps — control exists but isn't executed properly
- Opportunity/design gaps — framework hasn't kept pace with business change
- Knowledge gaps — staff lack training or expertise
- Resource gaps — control is well-designed but under-resourced
What is an example of a gap analysis?
A common example involves an enhanced due diligence control that exists on paper, but front-line staff aren't consistently escalating high-risk files within the required timeframe. Root cause investigation typically reveals unclear triggers or missing system reminders.
What are the four steps of gap analysis?
The four steps are:
- Define current and desired states
- Identify and classify the gap
- Investigate root cause
- Build and validate an action plan with ownership, timelines, and testing evidence
How is a control gap analysis different from a risk assessment?
A risk assessment identifies and prioritizes your inherent and residual ML/TF risk exposure. A control gap analysis tests whether the controls you've put in place are actually closing that exposure in practice.
How often should a Canadian reporting entity perform a control gap analysis?
There is no universal FINTRAC rule that every reporting entity must run a standalone control gap analysis every 24 months. The statutory two-year cycle applies to the AML effectiveness review (PCMLTFR s.156). Gap analysis is a practical tool entities may use on a risk-based schedule, and often alongside material program, personnel, or business change.
Can a control gap analysis help during a FINTRAC examination?
Yes. Proactively identifying and remediating gaps strengthens your regulatory posture and demonstrates that your program is actively managed, not just documented, before an examiner arrives.


