Compliance Risk Assessment In 2024-25, FINTRAC conducted more than 1,300 assessment activities and issued 23 Notices of Violation totalling more than $25 million - the largest number in FINTRAC's history (FINTRAC Annual Report 2024-25). These are dated annual-report figures, not a claim that FINTRAC "isn't easing up" or that any trajectory is permanent.

Behind many examinations sits the same question: is your risk assessment current, sound, and defensible?

A compliance risk assessment is the foundation regulators expect to find behind every AML program decision — from onboarding rules to transaction monitoring thresholds. Get it wrong, and everything built on top of it becomes questionable too.

This guide covers what a compliance risk assessment actually is, how to build one step by step, the common risk types worth tracking, and when it's time to bring in independent expert review.

Key Takeaways

  • A sound compliance risk assessment ranks legal and regulatory exposure so controls go where residual risk is highest
  • FINTRAC expects risk assessments to be current, methodologically sound, and backed by evidence
  • Organize the review around four illustrative risk categories (legal, financial, reputational, and operational) - a practical taxonomy, not FINTRAC-prescribed
  • Outdated or one-time risk assessments can raise examination risk
  • Independent challenge of your methodology can strengthen defensibility; remediation timing should follow governance and risk appetite, not a universal "immediate" rule

What Is a Compliance Risk Assessment?

A compliance risk assessment is a systematic process for evaluating the likelihood and impact of legal and regulatory risks tied to your products, customers, delivery channels and geography. It is an analytical exercise that maps where your organization is exposed and how severely.

In the Canadian AML context, this obligation isn't optional. Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), reporting entities must establish and implement a compliance program, including policies and procedures and a documented assessment of money-laundering and terrorist-financing risk (PCMLTFA s. 9.6; PCMLTFR s. 156). FINTRAC requires reporting entities to assess and document their ML/TF risks; it does not prescribe one assessment methodology.

Inherent Risk vs. Residual Risk

Inherent and residual risk are standard risk-management concepts used in AML risk assessments:

  • Inherent risk: the level of risk that exists before any controls or mitigation measures are applied
  • Residual risk: what remains after those controls are in place

You cannot eliminate inherent risk. The job is to bring residual risk within an acceptable tolerance and prove you did it.

Why regulators care so much: FINTRAC treats the risk assessment as the backbone of an "appropriately designed" AML program. Everything else (your policies, monitoring rules and training) should trace back to what the risk assessment identified. If the assessment is weak, the entire program is built on sand.

The stakes are real. FINTRAC's 2024-25 report shows 294 formal examinations and 32 disclosures to law enforcement, compared with 14 disclosures the year before. Treat those as dated facts, not a forecast.

How Do You Perform a Compliance Risk Assessment?

FINTRAC doesn't prescribe one formula, but its risk-based approach guidance outlines a consistent cycle you can work through in six steps.

6-step compliance risk assessment cycle process flow diagram

Step 1: Define Scope and Risk Universe

Identify every business line, product, customer type, delivery channel and geography that needs assessing. Miss a channel here, and you'll have a blind spot later.

Step 2: Map Risk Contact Points

Pinpoint exactly where your operations intersect with regulatory obligations:

  • Customer onboarding and identity verification
  • Transaction monitoring and alert review
  • High-risk customer types (politically exposed persons, cash-intensive businesses, non-resident clients)
  • Product launches and new delivery channels

Step 3: Assess Existing Controls

Evaluate whether your current controls actually prevent, detect and correct violations, not just whether they exist on paper. That test of inherent risk against your control environment is what produces residual risk.

Independent reviewers typically use a mix of:

  • Document review of policies and procedures
  • Interviews and process walkthroughs
  • File sampling
  • Data analysis
  • End-to-end testing across an entire process, not just isolated steps

Step 4: Score and Prioritize Risks

Score each risk by likelihood and impact, then plot findings onto a risk register or illustrative heat map. Generic heat maps and taxonomies are illustrative tools, not FINTRAC-prescribed formats or mandated "immediate remediation" instructions. Prioritize treatment, escalation, and documented action according to your governance, risk appetite, legal obligations, and approval authorities - not a universal top-right "Immediate Remediation Required" rule.

Step 5: Document, Report, and Remediate

Findings need owners, timelines and a reporting line to senior management or the board. In a regulator's eyes, undocumented findings are functionally unaddressed.

Step 6: Reassess Periodically

New products, new geographies, regulatory change, or examination findings should all trigger a reassessment. Don't wait for the calendar alone.

What Are Four Illustrative Types of Compliance Risk?

Organizing your findings into categories makes them easier to prioritize and report. Four practical categories used as an AlphaDelta organizing framework cover much of the ground:

  • Legal/regulatory risk: Non-conformance with AML statutes, regulations, FINTRAC directives, or prescribed practices
  • Financial risk: Fines, penalties, or loss exposure, including FINTRAC's $25 million-plus in 2024-25 penalties
  • Reputational risk: Trust damage after a breach or public enforcement action
  • Operational risk: Failures in internal processes, systems, or people that allow violations to occur

Four types of compliance risk legal financial reputational operational breakdown

OSFI Guideline E-13 frames regulatory compliance risk as potential non-conformance with laws, rules, and prescribed practices, and notes that reputational harm can invite closer regulatory intervention.

Use them as a practical lens for your risk register, not as a regulatory checklist.

What Should Be Included in an AML Compliance Program?

FINTRAC's compliance program guidance sets out five required elements, updated as recently as October 2024:

  1. A designated compliance officer responsible for implementing the program
  2. Written policies and procedures approved by a senior officer and reflecting your actual risk profile
  3. A documented risk assessment of money-laundering and terrorist-financing exposure
  4. An ongoing training program for employees, agents and authorized persons
  5. A documented effectiveness review, testing the program at least every two years

Five required elements of an AML compliance program checklist

The effectiveness-review clock is where many entities slip. The next review must begin no later than 24 months after the previous one started (FINTRAC compliance program requirements).

Findings from the risk assessment, training, and effectiveness review should feed executive and board decision-making. They should not sit unused until the next exam.

Example of a Compliance Risk Assessment

Consider a hypothetical Canadian money services business assessing risk across four dimensions:

Risk factor Inherent risk Control in place Residual risk
Customer type: non-resident wire clients High Basic KYC at onboarding High
Product: international wire transfers High Manual transaction review Medium-High
Delivery channel: online onboarding Medium Identity verification software Low
Geography: high-risk jurisdictions High Enhanced due diligence policy (undocumented in practice) High

The gap jumps out immediately. Manual review of high-volume international wire activity, paired with an enhanced due diligence policy that isn't consistently applied, leaves residual risk high where it should be mitigated. That combination (a documented policy without operational evidence it's followed) is exactly the kind of finding a FINTRAC examination would flag.

Remediation is straightforward:

  • Implement automated monitoring thresholds for wire activity above a defined value
  • Require documented evidence of enhanced due diligence for every high-risk jurisdiction transaction

When to Bring in Independent Senior AML Expertise

Self-assessed risk methodologies carry blind spots. That is structural: the people who build a risk assessment are rarely well-positioned to challenge their own assumptions. Those blind spots tend to surface at the worst possible time: during a FINTRAC examination.

FINTRAC's enforcement record includes a recent example. In a November 2025 penalty decision, FINTRAC found that one entity's risk-assessment procedures weren't tailored to Canadian legislation, and that its risk-rating methodology was only finalized after the examination period had already ended (FINTRAC AMP decision, 2025). The resulting penalty exceeded $536,000.

An independent challenge tests your methodology, assumptions and control framework before a regulator does. AlphaDelta's Senior AML Advisory (risk assessment and control challenge) examines whether your risk assessment, testing approach and control framework actually reflect your obligations, products, customers and operating environment, not just whether the paperwork exists.

This is especially worth prioritizing if:

  • Your two-year effectiveness review is approaching or overdue
  • You're preparing for, or currently responding to, a FINTRAC examination
  • You've made material changes to products, geography or business model since your last assessment
  • Previous findings from an audit or review haven't been fully remediated

Engagements can run as a retainer, a defined project, or hourly advisory support — whichever fits your timeline and level of ongoing need.

Frequently Asked Questions

How do you perform a compliance risk assessment?

Define scope, map operations to regulatory obligations, assess controls for residual risk, then score, prioritize, document and report. Reassess periodically — see the step-by-step section above for detail.

What are compliance risk assessments?

Compliance risk assessments are systematic evaluations of an organization's legal and regulatory exposure across products, customers, channels and geography. They are the foundation regulators expect behind AML program design.

What is regulatory compliance risk?

It's the risk of violating laws, rules or regulations specific to your sector. In the Canadian AML context, this centres on the PCMLTFA and FINTRAC's directives and guidance.

What are the 5 things a risk assessment should include?

Scope definition, risk identification, control assessment, prioritization and scoring, and ongoing monitoring with periodic reassessment. Skip any one of these and the assessment loses credibility.

Can you give me an example of a compliance risk?

Failing to file a suspicious transaction report as soon as practicable after establishing reasonable grounds to suspect a money-laundering connection. There is no dollar threshold; the obligation applies regardless of transaction size.

What are four illustrative types of compliance risk?

Legal/regulatory risk (violating statutes or directives), financial risk (fines and penalties), reputational risk (loss of trust), and operational risk (process or system failures that allow violations to happen). These are a practical AlphaDelta organizing framework for a risk register.