How to Prepare for a FINTRAC Examination FINTRAC selects entities for examination on a risk basis. Not every reporting entity faces examination on a fixed schedule, and not every examination covers every requirement area. The practical question is how ready you will be if selected.

Too many organizations treat a FINTRAC exam like a generic audit: gather some documents, answer some questions, hope for the best. That approach misreads what's actually happening. FINTRAC's methodology is risk-based and evidence-driven, built to test whether your compliance program actually functions — not just whether it exists on paper. Entities that skip this distinction end up with avoidable deficiencies.

This article covers what FINTRAC actually examines, how to prepare long before notification arrives, what happens during the process itself, and how to respond once findings are issued.

Key Takeaways

  • The exam clock starts at the notification call, not the on-site visit: fixes after that date don't erase prior gaps
  • When a program element is in scope, weakness in that element can affect how related elements are viewed; examinations are risk-based in scope and not every exam covers every requirement
  • Preparation done months before notice arrives matters more than how you perform during the exam itself
  • Documentation, cooperation, and a calm, organized response support a clearer examination posture

Understanding FINTRAC Examinations: What Triggers Them and What Gets Assessed

FINTRAC's authority to examine reporting entities comes from the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). Selection isn't random.

According to FINTRAC's Assessment Manual, selection weighs:

  • Business size, complexity, and risk profile
  • Compliance history and prior findings
  • Self-declarations
  • Reports submitted (or not submitted) over time

Higher perceived risk raises your odds of selection. It also widens the sample size, examination period, and interview list once an exam is underway.

FINTRAC indicates reporting entities are usually contacted approximately 30 to 45 days before an examination; timing may vary and is not a guaranteed minimum or universal rule. Notice is typically delivered first by phone and confirmed in writing shortly after. Larger or more complex businesses sometimes get more lead time.

Here's the part that catches people off guard: the examination period begins on the date of that notification call, not the date officers walk through your door.

On-Site vs. Desk Examinations

The format depends on your risk profile and business type:

  • On-site examinations — FINTRAC officers visit your premises, conduct in-person interviews, and walk through your systems and files directly
  • Desk examinations — Officers work remotely through document submission, virtual interviews, and file review from a FINTRAC office

Neither format is inherently easier. Desk exams simply shift the burden toward producing clean, well-organized digital records on demand.

On-site versus desk FINTRAC examination format comparison infographic

What FINTRAC Actually Reviews

FINTRAC examinations are risk-based in scope. Officers may focus on selected areas rather than assessing every requirement in every exam. Common focus areas can include:

  • Implementation of your compliance program
  • Required transaction reporting
  • Client identification procedures
  • Record-keeping practices
  • Third-party determinations

Officers pull compliance documents, client and transaction records, and submitted reports, then interview staff to see whether practice matches policy. If a sample raises questions, they expand it.

The Five Pillars of an AML Compliance Program FINTRAC Will Test

FINTRAC's assessment framework centres on five mandatory program elements set out in section 156 of the PCMLTF Regulations (PCMLTFR, not the PCMLTFA itself). Examiners may weight these elements holistically when in scope. A weak effectiveness review, for instance, can cast doubt on related program areas.

Compliance Officer Appointment and Authority

FINTRAC verifies more than a job title. Examiners check:

  • Formal, documented appointment of the compliance officer
  • Direct access to senior management, not filtered through layers
  • Sufficient knowledge, authority, and resources to act independently

Written Policies and Procedures

Policies must be tailored to your actual business, not a generic template, and approved by senior management. Examiners look for:

  • Documented procedures that match how you really operate
  • Senior management approval on record
  • Staff who follow the written process in live transaction handling

Risk Assessment

Your risk assessment must cover:

  • Products and services offered
  • Client types and business relationships
  • Geographic exposure
  • Delivery channels
  • New technologies and developments

Each category needs documented rationale and matching mitigation measures. A risk assessment that lists categories without explaining why they're rated a certain way won't hold up.

Ongoing Training Program

Examiners review training frequency, whether content reflects your actual risk exposure, and attendance records. Then they test understanding directly through interviews. A well-designed program means little if staff can't explain it in their own words.

Two-Year Effectiveness Review

Section 156(3) of the PCMLTFR sets the two-year cadence for the effectiveness review. Section 156(4) requires an entity to report the findings in writing to a senior officer within 30 days of completion, together with any policy updates made in the period and their implementation status. Independence of the reviewer (structural separation from day-to-day operation) is expected; external delivery is a common model, not a universal legal requirement that the reviewer must be external. This is a common weak spot.

A McCarthy Tétrault summary of FINTRAC's 2026 Industry Day flagged recurring issues, including:

  • Reviews that checked whether a control existed rather than whether it worked
  • Incomplete end-to-end testing
  • Remediation that never closed the loop

Prescribed program components of a FINTRAC AML compliance program

Preparing Before the Notification Call Arrives

By the time your phone rings, your preparation window has already closed on anything retroactive. What you put in place before that call is what shapes the examination outcome.

Run a self-assessment against the prescribed program components. Test your program the way FINTRAC would: document review, interviews, and sample testing, before an examiner does it for you. This surfaces gaps while you still have time to fix them properly.

Organize records for fast retrieval. FINTRAC expects records produced within its required timeframes. Build folders or cover sheets mapped to the document requests you're likely to receive, so nothing gets lost hunting through shared drives under time pressure.

Understand the notification-date nuance. Any reporting gap or policy update made after the call is logged doesn't erase non-compliance that existed before it. Ongoing readiness beats last-minute scrambling; there's no clean slate once the clock starts.

Brief staff with substance, not scripts. Give employees factual, business-specific context ahead of interviews rather than rehearsed answers examiners will see through immediately. Designate one point of contact to manage the examiner relationship and keep communication consistent.

Bring in an outside perspective before the exam, not after. Internal teams often assume their program is solid because it's familiar, not because it's been stress-tested. An independent review closes that gap with the same methods an examiner uses: document review, staff interviews, and evidence-based testing (walkthroughs, file sampling, end-to-end testing).

AlphaDelta's Independent AML Effectiveness Reviews are built for this purpose. Every engagement includes one optional findings clarification session within 90 days of the final report. If FINTRAC formally initiates a compliance examination within 12 months of the final report, AlphaDelta will provide up to 10 hours of review-related senior advisory support at no additional cost.

Navigating the Examination Itself

FINTRAC works through three phases:

  1. Planning and scoping — Examiners set the examination period, sample sizes, and areas of focus based on your risk profile
  2. Examination and assessment — Documents are reviewed, staff interviewed, and samples expanded where questions arise
  3. Developing conclusions — Findings are finalized and prepared for the exit meeting and formal letter

Know your legal obligations. Under section 62 of the PCMLTFA, authorized officers can enter non-dwelling premises at a reasonable time, examine and copy records, and access computer systems where relevant information is kept.

You must grant that access, produce requested records within the prescribed timeframe, and provide reasonable assistance. That duty is a legal requirement under the Act.

During interviews, stay factual. Refer to documented policy when a question calls for it. If a request is unclear, ask for clarification rather than guessing. A wrong guess creates more problems than an honest question.

The exit meeting matters. This is where FINTRAC presents preliminary findings, called deficiencies. You'll typically get a chance to add context before anything is finalized. Use that window: unexplained findings are harder to correct once the formal letter is issued.

Duration varies widely by size and complexity. A small or mid-sized business might wrap up in under a week; a large institution can run several weeks. Plan staff availability up front. Slow responses that stretch the exam reflect poorly, even when the underlying program is sound.

After the Exam: Findings, Deficiencies, and Remediation

A findings letter leads to one of four outcomes:

  • No further compliance or enforcement action: FINTRAC does not identify an additional compliance or enforcement step in the findings letter for the examined scope
  • Follow-up compliance action: minor issues requiring correction, tracked but not escalated
  • Enforcement recommendation: more serious concerns referred internally
  • Notice of Violation: a formal penalty, with the amount specified

Four possible FINTRAC examination outcomes from no action to violation

In fiscal 2024–25, FINTRAC completed 294 formal examinations, issued 23 Notices of Violation totalling more than $25 million, and made 32 non-compliance disclosures to law enforcement, according to FINTRAC's 2024–25 Annual Report. Enforcement is a routine part of the examination cycle, not an edge case.

When FINTRAC requests an action plan in certain examination cases, it is often due within 30 days unless otherwise stated. A plan that patches symptoms without addressing root causes often leaves the same issues for the next review cycle.

FINTRAC's own AMP policy weighs an entity's compliance history when setting penalty amounts. Its public enforcement record includes cases where deficiencies from one examination stayed substantially unaddressed for years, then triggered a much larger penalty at the next review. Repeat findings compound. They don't reset.

That pattern is why governance-level change often becomes necessary: not only fixing a policy document, but rethinking accountability structures, reporting lines, and how controls are actually tested.

AlphaDelta's Senior AML Advisory work in this space focuses on separating what is mandatory from what is merely nice-to-have, sequencing remediation in a defensible order, and helping leadership reach decisions that can be explained with evidence if scrutiny continues.

Frequently Asked Questions

What are FINTRAC's screening requirements?

Reporting entities must screen clients at onboarding and monitor high-risk relationships on an ongoing basis. Specific obligations apply to politically exposed persons, heads of international organizations, and any sanctioned or listed individuals or entities.

What are FINTRAC's risk assessment requirements?

Your risk assessment must cover products and services, clients, geography, delivery channels, and new technologies. Each factor needs documented rationale and mitigation measures scaled to your business's size and complexity.

What triggers a FINTRAC examination?

FINTRAC uses a risk-based selection process weighing compliance history, sector risk, prior examination findings, and reporting irregularities. There's no single published trigger — it's a combination of factors specific to your business profile.

What is FINTRAC compliance?

FINTRAC compliance means maintaining all five mandatory program elements under the PCMLTFR (s.156): a designated compliance officer, written policies and procedures, a documented risk assessment, ongoing staff training, and a biennial effectiveness review.

How much advance notice does FINTRAC give before an examination?

FINTRAC indicates reporting entities are usually contacted approximately 30 to 45 days before an examination; timing may vary and is not a guaranteed minimum or universal rule. Notice is typically delivered by phone and confirmed in a formal letter. Larger or more complex businesses sometimes receive additional lead time.

What happens if FINTRAC identifies deficiencies during an examination?

You'll receive a findings letter outlining outcomes ranging from no further action to a formal Notice of Violation. If deficiencies are found, FINTRAC may request a documented action plan in certain cases; when requested, it is often due within 30 days of the letter unless otherwise stated.