
Many Canadian businesses — real estate brokerages, money services businesses (MSBs), financial entities — under-build these programs. They buy a template, fill in the blanks, and assume that's compliance. It isn't. FINTRAC examiners test whether a program actually functions, not whether it exists on paper.
This guide breaks down the prescribed program components FINTRAC requires, who has to comply, and what separates a program that can be explained with evidence under scrutiny from one that cannot.
Key Takeaways
- Every PCMLTFA reporting entity needs a five-element compliance program scaled to its size and risk
- For violations on or after 26 March 2026 the PCMLTFA sets maximum AMPs of $4 million for a person and $20 million for an entity, subject to a cumulative cap of 3% of global gross revenue, with criminal charges also possible
- A documented effectiveness review must be carried out and the results documented every two years. The risk assessment must also be kept current, including assessing new developments or technologies before they are introduced where required (PCMLTFR s.156(2))
- Generic templates don't satisfy FINTRAC: programs must reflect your actual business
Who Must Comply with FINTRAC's Compliance Program Requirements
FINTRAC's rules apply to "reporting entities": a broad category covering most businesses involved in moving money in Canada. Current guidance lists 17 sector categories, including:
- Financial entities (banks, credit unions, trust companies)
- Money services businesses (MSBs) and foreign MSBs, cheque cashers, and private-ATM acquirers
- Securities dealers and life insurance companies/brokers
- Real estate brokers, sales representatives, and developers
- Casinos and dealers in precious metals and stones
- Mortgage administrators, brokers, and lenders
- Accountants and accounting firms (when conducting specified activities)
Size doesn't create an exemption. A one-person real estate brokerage and a national bank are both reporting entities under the Act. What changes is the depth and complexity of the program required, not whether one is required at all.
There's one narrow carve-out worth knowing: a sole proprietor with no employees or agents acting on their behalf isn't required to maintain a training program or training plan for themselves. That's it. Every other element (compliance officer, policies, risk assessment, and effectiveness review) still applies.
The Five Elements of a FINTRAC Compliance Program
FINTRAC's compliance program guidance structures every AML program around five connected requirements. Skip one, and the whole structure weakens. The five elements, in logical order:
1. Compliance Officer
Appointing someone to the role isn't enough. FINTRAC expects the compliance officer to have genuine authority: budget access, escalation rights, and direct communication with senior management or the board.
The officer must actively implement every program element, not just hold the title while someone else does the work. Examiners look for real ownership of the program, not a name on an org chart.
2. Written Policies and Procedures
Policies must be written, current, accessible, and approved by a senior officer. At minimum, they should cover:
- Know-your-client (KYC) procedures
- Business relationship and ongoing monitoring rules
- Record-keeping requirements
- Transaction reporting workflows
- Third-party determination and, as applicable to the entity's activities, travel rule requirements
Generic industry templates are a red flag. FINTRAC's own enforcement history shows entities penalized for policies that weren't updated or approved by senior officers. In one published case against a Canadian dealer in precious metals, outdated, unapproved policies were one of three cited failures.
3. Risk Assessment
Your risk assessment needs to cover:
- Clients and business relationships
- Products and delivery channels
- Geography
- Sector-specific risks
- Sanctions-evasion exposure
FINTRAC expects entities to use Canada's National Risk Assessment as foundational input, layered with entity-specific analysis.
When a client, product, or geography is assessed as high risk, enhanced measures are mandatory, not discretionary. A stale risk assessment that hasn't been updated for new products or client bases is one of the more common gaps examiners find.
4. Training Program
Training must be ongoing and documented, not a one-time onboarding session. A defensible plan specifies:
- Who receives training (role-based, not one-size-fits-all)
- What topics are covered (legal duties, ML/TF methods, internal controls, reporting obligations)
- How it's delivered
- How often it recurs
The sole-proprietor exception noted earlier applies here specifically, and only when there's genuinely no staff or agents to train.
5. Two-Year Effectiveness Review
This is where programs most often fail. FINTRAC requires a test of policies, risk assessment, and training at least every two years, with the next review starting no later than 24 months after the previous one began.
Findings must go to a senior officer in writing within 30 days of the review's completion, documenting the review period, methodology, deficiencies found, and an action plan.
An internal or external auditor can conduct it, or the entity itself if no auditor is available. FINTRAC still treats independence from anyone directly involved in the program as a best practice worth following; independence is not a separate sixth prescribed element.
Consequences of Non-Compliance
The financial exposure for non-compliance has grown substantially. For violations committed on or after 26 March 2026, the PCMLTFA sets the maximum administrative monetary penalty for a prescribed violation at $4,000,000 for a person and $20,000,000 for an entity, subject to a cumulative cap of 3% of global gross revenue. FINTRAC's updated AMP policy, including how amounts are set within those maxima, is still being developed; the regulatory framework sits in the Administrative Monetary Penalties Regulations. Legacy amounts continue to apply to violations committed entirely before 26 March 2026.
Criminal penalties under the PCMLTFA run even higher for knowing contraventions and reporting offences: up to $20 million and five years' imprisonment on indictment for certain reporting violations.
These aren't hypothetical numbers. FINTRAC's 2024–25 Annual Report documented 23 Notices of Violation worth more than $25 million, alongside 294 formal examinations, concentrated heavily in MSBs, precious-metals dealers, and credit unions.
In one recent case, a foreign MSB received a $536,853.35 penalty for four violations tied to program deficiencies.
FINTRAC publishes every penalty publicly. The reputational cost often outlasts the financial one: clients, partners, and regulators all see the notice.
Building, Testing, and Defending a Program That Works in Practice
A compliance program that exists only on paper collapses the moment an examiner asks for evidence. FINTRAC doesn't just review your policy manual. It tests whether staff actually follow it, whether files reflect the risk assessment, and whether the effectiveness review produced real findings and follow-through.
Common reasons programs fail under examination:
- Risk assessments that haven't been updated for years, missing new products or client segments
- Policies copied from a generic template, never tailored or re-approved
- A compliance officer without budget, authority, or a real seat at the table
- An effectiveness review completed late, superficially, or by someone too close to the program
Closing those gaps takes experience on both sides of the regulatory relationship. AlphaDelta founder Andrew Morris has served as an IIROC/CIRO examiner, a Chief Compliance Officer, and an enterprise AML program owner. That includes building Canada's first national AML/ATF program for the armoured-car sector from the ground up.
AlphaDelta's Independent AML Effectiveness Reviews are scoped to test the prescribed program elements — policies and procedures, risk assessment, and training — through document review, interviews, walkthroughs, and file sampling. Under PCMLTFR s.156(3) the reporting entity remains responsible for carrying out and documenting the statutory review; a scoped external review can be used as that review.
Every review also includes:
- Every engagement includes one optional findings clarification session within 90 days of the final report.
- If FINTRAC formally initiates a compliance examination within 12 months of the final report, AlphaDelta will provide up to 10 hours of review-related senior advisory support at no additional cost.
For entities facing an active examination, addressing findings, or rebuilding governance, Senior AML Advisory engagements (retainer, defined-scope, or hourly) offer direct access to that same practitioner-level experience.
Frequently Asked Questions
Who must report to FINTRAC?
Financial entities, MSBs, securities dealers, life insurance companies, real estate brokers and developers, casinos, precious metals dealers, mortgage brokers, and several other sectors listed under the PCMLTFA. See the "Who Must Comply" section above for the full breakdown.
Who is required to have an AML program?
Every reporting entity, regardless of size. The only narrow exception is the training plan requirement for sole proprietors with no employees or agents — every other pillar still applies.
What transactions are reported to FINTRAC?
Suspicious transaction reports (STRs, no dollar threshold), large cash transaction reports ($10,000+), large virtual currency transaction reports ($10,000+), international electronic funds transfers ($10,000+), and listed person or entity property reports.
What are the requirements for an AML/CTF program?
Five elements: a compliance officer with real authority, written and approved policies, a documented risk assessment, an ongoing training program, and a two-year effectiveness review. See the core section above for details on each.
What happens if I don't comply with FINTRAC?
For violations on or after 26 March 2026, the PCMLTFA sets maximum penalties of $4,000,000 for a person and $20,000,000 for an entity, subject to a cumulative cap of 3% of global gross revenue, with criminal penalties possible for knowing contraventions. FINTRAC also publishes penalties publicly, adding reputational risk.
What is an AML compliance review?
It's the mandatory biennial test of your policies, risk assessment, and training program, with findings reported in writing to a senior officer within 30 days. It's designed to catch gaps before FINTRAC does.


