
Many compliance leaders find the Act's structure genuinely confusing. Between overlapping obligations, a frequently amended regulatory schedule, and a penalty regime that mixes administrative and criminal exposure, it's easy to lose the thread. Add in the 2024-2025 amendments expanding coverage to sectors like title insurers and white-label ATM (WLATM) acquirers, and even seasoned teams are re-checking whether their programs still fit.
This guide breaks down what the PCMLTFA actually requires: who it covers, what FINTRAC does, the core obligations reporting entities must meet, and what happens when things go wrong.
Key Takeaways
- The PCMLTFA is Canada's core AML/ATF statute, establishing FINTRAC and setting obligations for reporting entities
- Compliance programs must cover client identification, record keeping, and transaction reporting
- Non-compliance can trigger administrative monetary penalties under FINTRAC's current AMP framework, plus separate criminal penalties
- 2024-2025 amendments extended obligations to title insurers and WLATM acquirers, and strengthened MSB registration
What Is the Proceeds of Crime (Money Laundering) and Terrorist Financing Act?
The Act was originally enacted as the Proceeds of Crime (Money Laundering) Act. In December 2001, Parliament amended it to add terrorist financing provisions, folding counter-terrorist-financing obligations into what had been a money-laundering-focused statute.
As set out in Justice Canada’s consolidated text, the Act has four core objectives:
- Detect and deter money laundering and terrorist financing, while facilitating investigation and prosecution
- Support law enforcement through record-keeping, client-identification and reporting duties, while protecting the personal information collected
- Fulfill international commitments made by Canada in the fight against transnational financial crime
- Protect the integrity of Canada's financial system
The Act also establishes FINTRAC as the arm's-length agency responsible for receiving reports, analyzing them, and ensuring reporting entities comply with Parts 1 and 1.1 of the legislation.
Who Must Comply: Reporting Entities Under the Act
FINTRAC's current list of reporting entities is long and keeps growing. It includes:
- Banks, credit unions, and trust and loan companies
- Money services businesses (MSBs) and foreign MSBs
- Securities dealers, mortgage brokers, administrators and lenders
- Casinos and life insurance companies, brokers and agents
- Dealers in precious metals and stones
- Accountants, accounting firms, and BC public notaries
- Real estate brokers, sales representatives and developers
Notably, lawyers and law firms are not on FINTRAC's official reporting-entity list. They're a separate matter under provincial law society regimes, not the PCMLTFA.
The scope keeps expanding. Title insurers and white-label ATM (WLATM) acquirer services became reporting entities on October 1, 2025, joining cheque cashers, factors, and financing/leasing entities added earlier that year. If your business touches cash, property transfers, or payment processing, recheck whether you now fall inside the perimeter.
Understanding FINTRAC's Role and Authority
FINTRAC wears two hats: it's Canada's financial intelligence unit and its AML/ATF regulator. On the intelligence side, it receives and analyzes reports, then discloses actionable intelligence to law enforcement and national security agencies while operating independently from them.
On the regulatory side, FINTRAC:
- Conducts compliance examinations of reporting entities' programs and controls
- Issues guidance and interpretation notices that clarify obligations under the Regulations
- Imposes administrative monetary penalties (AMPs) when it finds non-compliance
One change worth flagging: from April 1, 2024, FINTRAC moved to an assessment of expenses model. Covered entities now help fund FINTRAC's compliance program directly through base, proportional, and interim-assessment components.
That model applies to:
- Banks and authorized foreign banks
- Life insurers
- Trust and loan companies
- Organizations filing 500+ specified reports annually
FINTRAC doesn't operate alone. It's one of 13 federal departments and agencies in Canada's AML/ATF regime, led by the Department of Finance, alongside partners like CSIS, the RCMP, CBSA, and OSFI.
Core Obligations Under the PCMLTFA and Its Regulations
Most compliance programs hinge on execution of five obligation categories.
Client Identification and KYC
Reporting entities must verify identity using prescribed methods. FINTRAC permits five approaches for individuals:
- Government-issued photo ID
- Credit file
- Dual-process
- Affiliate or member reliance
- Reliance on another reporting entity
Entities can be verified through confirmation of existence, reliance, or simplified identification, with exact triggers varying by sector and activity.
Record Keeping
Entities must retain records covering:
- Large cash transactions (LCTRs)
- Virtual currency transactions (LVCTRs)
- Client identification and beneficial ownership documentation
Report copies must be kept for at least five years.
Transaction Reporting
Core report types and thresholds (confirm live FINTRAC guidance for sector-specific detail):
| Report type | Threshold / trigger | Deadline (high level) |
|---|---|---|
| Suspicious Transaction Report (STR) | No dollar threshold; reasonable grounds to suspect ML, TF, or sanctions evasion where applicable | As soon as practicable after measures establishing reasonable grounds to suspect are complete |
| Large Cash Transaction Report (LCTR) | Cash of $10,000 or more (single or 24-hour aggregated under applicable conductor/beneficiary/third-party links) | Within 15 calendar days (per FINTRAC LCTR rules) |
| Large Virtual Currency Transaction Report (LVCTR) | Virtual currency of $10,000 or more (single or aggregated under applicable rules) | Per FINTRAC LVCTR timing |
| Electronic Funds Transfer Report (EFTR) | Outgoing/incoming EFTs at the prescribed $10,000 threshold (single or aggregated) | Per FINTRAC EFT reporting rules |
| Listed person or entity property report | Property owned or controlled by a listed person/entity; distinct from transaction reports - no transaction required | Immediately / without delay per listed-property rules |
Do not treat listed-property reporting as just another transaction threshold graphic. STR timing is as soon as practicable, not a fixed dollar clock.
Compliance Program Requirements
Every reporting entity needs:
- An appointed compliance officer with clear accountability
- Senior-approved, written policies and procedures
- A documented risk assessment
- Ongoing training, kept current
- An effectiveness review at least every two years
That biennial review isn't optional. FINTRAC expects it documented, evidence-based, and focused on whether controls work in practice, not only whether policies exist on paper.
This is where AlphaDelta's independent AML effectiveness reviews fit: testing governance, KYC, monitoring, and recordkeeping through document review, interviews, and file sampling, not a paper-only checklist.
The 24-Hour Rule
A common gap in transaction monitoring is aggregation under FINTRAC's 24-hour rule. Two or more transactions of the same reportable type (for example large cash) totaling $10,000 or more within a consecutive 24-hour window must be aggregated and reported as one when FINTRAC's aggregation links apply - typically the same conductor, third party, and/or beneficiary as set out in FINTRAC guidance.
Aggregation is type-specific (cash with cash, virtual currency with virtual currency, and so on). Systems that only monitor single transactions in isolation will miss linked activity that crosses the reporting threshold.
Penalties for Non-Compliance
FINTRAC's Administrative Monetary Penalties framework classifies violations as minor, serious, or very serious. Historical AMP ranges (commonly cited as up to $1,000 / $100,000 / $500,000 by tier) applied under the legacy schedule and must not be treated as current law for violations on or after March 26, 2026, when a revised, higher AMP framework took effect.
Confirm current classification criteria, methodology, and maximums in FINTRAC's live AMP materials. Do not rely on legacy tier tables in policies or training without labelling them as historical.
Beyond administrative exposure, the PCMLTFA and Criminal Code carry separate criminal penalties for actual money laundering or terrorist financing offences:
- Knowing contraventions under PCMLTFA section 74 can draw up to $5 million and five years' imprisonment on indictment
- Reporting contraventions under section 75 can reach $20 million and five years' imprisonment
- Laundering proceeds of crime under Criminal Code section 462.31 carries up to 10 years' imprisonment
Administrative penalties are civil and non-punitive by design. Criminal penalties are a different animal entirely, reserved for actual offences rather than program deficiencies.
The real risk often isn't the fine itself. A finding of non-compliance during a FINTRAC examination frequently triggers a chain reaction: a compliance order, a public notice of violation naming the entity, and the reputational fallout that follows once that notice is public.
Recent Regulatory Changes Reporting Entities Should Know
SOR/2024-266, registered in December 2024, rolled out several changes through 2025:
- Sanctioned property reporting: Extends beyond terrorist property to SEMA and Justice for Victims of Corrupt Foreign Officials Act sanctions (October 1, 2025)
- MSB registration: Criminal record checks now required for controlling persons and agents (October 1, 2025)
- White-label ATM (WLATM) acquirers: Must register and meet identification, recordkeeping, reporting, and program duties
- Title insurers: Added to the reporting-entity list on October 1, 2025
- Casino disbursements of $10,000+: Must identify the beneficiary, including ultimate beneficiaries when a third party is paid

The timing is deliberate. Canada's FATF mutual evaluation has moved past its on-site stage, which was listed for November 2025, and the FATF-APG evaluation of Canada was expected to be discussed at FATF Week in June 2026. Publication of the report remains pending until FATF posts it. Aligning domestic obligations with FATF standards ahead of that review is a clear driver of the expanded scope.
For compliance teams, the practical challenge is turning each amendment into program updates: revised risk assessments, policies, and staff training before the next effectiveness review or examination. AlphaDelta helps Canadian reporting entities interpret these rules, separate mandatory changes from optional enhancements, and design a practical implementation path. Clients retain ownership of execution and decisions.
Frequently Asked Questions
What are the penalties for breaching the PCMLTFA?
FINTRAC classifies violations as minor, serious, or very serious. Legacy per-violation AMP ceilings (including the former $500,000 entity cap for very serious violations) are historical for pre-March 26, 2026 conduct; a revised, higher AMP framework applies thereafter. Confirm current amounts in FINTRAC's live AMP materials. Separately, criminal penalties apply for actual money laundering or terrorist financing offences, including imprisonment.
What is the maximum penalty for money laundering in Canada?
Administrative monetary penalties under FINTRAC's current AMP framework should be confirmed in FINTRAC's live materials; legacy tier caps are historical only. Criminal sentencing is different: laundering proceeds of crime under the Criminal Code carries up to 10 years' imprisonment.
What is the PCMLTFA?
The PCMLTFA is Canada's core anti-money laundering and anti-terrorist financing statute, amended in December 2001 to add terrorist financing provisions. It establishes FINTRAC and sets client identification, recordkeeping, and reporting obligations for reporting entities.
What is FINTRAC and what does it do?
FINTRAC is Canada's financial intelligence unit and AML/ATF regulator. It receives and analyses reports from reporting entities, discloses actionable intelligence to law enforcement, and conducts compliance examinations.
What is the 24-hour rule in AML?
Reporting entities must aggregate two or more transactions of the same reportable type totaling $10,000 or more within a consecutive 24-hour window when linked by conductor, third-party, and/or beneficiary rules under FINTRAC guidance. Those transactions are reported as a single large cash (or other applicable) report.


