
The problem? Many reporting entities treat their RBA as a document they wrote once and filed away. That is not how FINTRAC sees it. An RBA is supposed to be a living framework, tested and updated regularly. When examiners find a static, checkbox version instead, published FINTRAC examination and penalty notices often describe the same pattern.
This article breaks down what a risk-based approach actually is, its core components, and how it applies specifically to KYC under Canadian regulation.
Key Takeaways
- Scale ML/TF controls to risk severity instead of applying uniform measures across every client
- FINTRAC requires every reporting entity to document a risk assessment covering clients and business relationships, products, services and delivery channels, geography, and new developments or technologies (PCMLTFR s.156(1)(c) and s.156(2)), plus the sector risks in the latest National Risk Assessment; affiliate risk applies only to financial entities, life insurance companies and securities dealers
- Apply enhanced due diligence to higher-risk clients; lower-risk clients still receive prescribed identification and due diligence - simplified treatment must not cut prescribed duties
- A poorly designed or undocumented RBA can drive FINTRAC penalties and adverse examination findings
What Is a Risk-Based Approach?
FATF Recommendation 1 sets the international standard: countries and financial institutions must identify, assess and understand their money laundering and terrorist financing risks, then apply mitigation measures proportionate to what they find. Not every client, product or jurisdiction carries equal risk, so your controls shouldn't treat them as if they do.
FINTRAC builds on this with two working concepts:
- Inherent risk: the risk level before any controls are applied
- Residual risk: what's left after mitigation measures are in place
FINTRAC's assessments focus primarily on inherent risk, since that's what reveals whether you actually understand your exposure before you start layering on controls.
A Statutory Obligation Under PCMLTFA
Under PCMLTFA s.9.6 and the associated Regulations (s.156), every reporting entity listed in s.5 must establish a compliance program that includes a documented risk assessment. That obligation is statutory, not optional guidance.
Regulators favour this model over rigid, rules-based checklists because it shows genuine risk understanding. A checklist can be followed without real comprehension of where the danger sits. Misapplying an RBA, or documenting one that doesn't reflect reality, invites the scrutiny reporting entities want to avoid.
FINTRAC doesn't prescribe one methodology. Your risk assessment needs to fit your size, sector and client base: a mortgage lender's risk profile looks nothing like a casino's.
The Three Steps of a Risk-Based Approach
FINTRAC's official guidance describes a six-step cycle, but in practice it collapses into three core components.
1. Identify and assess inherent risk factors
This means evaluating risk across five prescribed categories:
- Products, services and delivery channels
- Client geography
- New developments and technology
- Clients and business relationships
- Applicable affiliates

2. Apply risk-tolerance-based mitigation
Once risk is identified, controls need to match it:
- Enhanced due diligence for higher-risk relationships
- Transaction monitoring calibrated to risk level
- Sanctions and PEP screening
- Special measures for high-risk clients, including senior management approval where required
3. Monitor and reassess when material factors change
Risk does not stay static. Client behaviour changes, new products launch, and jurisdictions shift on watchlists. The risk assessment itself is an ongoing obligation when material factors change - it is not a two-year risk-assessment cycle.
Separately, FINTRAC requires a mandatory effectiveness review at least every two years (PCMLTFR s.156). The next effectiveness review must start within 24 months of the previous review's start date, and only after that prior review is fully complete. Do not conflate the two-year effectiveness-review clock with a two-year RA refresh mandate.
An independent check tests whether the RBA still holds in practice. AlphaDelta's AML effectiveness reviews use document review, interviews, walkthroughs, file sampling and end-to-end testing. That work confirms whether a reporting entity's RBA methodology and controls are designed properly and operating as intended, before FINTRAC asks the same questions.
The Risk-Based Approach to KYC
Applying RBA to KYC means matching the depth of identification and due diligence to each client's assessed risk level. Uniform questionnaires and the same document pack for every relationship fail that test.
Building the Relationship-Based Risk Assessment
Each client relationship gets evaluated against:
- Products, services and delivery channels used
- Client geography, including any exposure to high-risk jurisdictions
- Technology exposure (digital onboarding, crypto rails, etc.)
- Client characteristics and observed patterns of activity
When Enhanced Due Diligence Kicks In
EDD becomes necessary when specific triggers appear:
- PEP status — foreign PEPs trigger prescribed measures automatically; domestic PEPs and heads of international organizations trigger them when assessed as high risk
- Complex beneficial ownership structures — especially when you can't confirm who owns or controls 25% or more of an entity
- High-risk jurisdictions tied to FATF statements or ministerial directives
- Unusual transaction patterns inconsistent with the client's stated profile
When beneficial ownership can't be verified, FINTRAC requires you to treat the entity as high-risk by default and apply enhanced ongoing monitoring, even if nothing else looks suspicious.

Proportionate Treatment Without Cutting Prescribed Duties
Lower-risk clients do not need the same intensity of enhanced measures. Applying EDD universally is inefficient: it dilutes resources and can suggest you are not differentiating risk at all. Proportionate treatment still requires meeting prescribed identification, record-keeping, and other statutory duties - simplified intensity is not a licence to drop obligations FINTRAC still requires.
Documentation matters as much as the rating. A defensible risk-based KYC program needs a written rationale explaining why a client received their risk rating, not only a score in the file.
Red Flags During KYC Verification
FINTRAC publishes indicator categories that reporting entities should watch for:
- Unknown or unexplained source of funds
- Unexplained complexity in ownership structures
- Unusual transaction speed, volume or frequency
- Client information inconsistent with observed activity or stated occupation
- Unexplained third-party involvement in transactions
A single red flag doesn't automatically make a client high-risk. FINTRAC treats these as contextual indicators assessed alongside other factors, not as standalone proof.
What drives examination findings is failing to escalate red flags once identified. If front-line staff spot something unusual and it never gets investigated or documented, that gap shows up quickly in a FINTRAC review.
The FATF's Risk-Based Approach to Supervision
FATF Recommendation 1 applies to supervisors as well as reporting entities. FATF's guidance on risk-based supervision directs regulators to apply proportionate oversight: more intensive scrutiny for higher-risk sectors and entities, lighter touch where risk is genuinely lower.
FINTRAC mirrors this proportionality in its own examination selection. Higher-risk sectors such as MSBs, casinos, and certain real estate businesses tend to see more frequent and deeper examinations than lower-risk sectors. That pattern reflects the same proportional logic FATF asks of national regulators.
Why This Matters for Canadian Reporting Entities
The enforcement record makes the stakes concrete. FINTRAC's own penalty notices cite risk-assessment failures directly:
- A virtual-currency MSB was penalized $176,960,190 in October 2025 (under appeal to Federal Court where that status applies), in part for failing to assess and document risk across required factors
- a real estate brokerage faced a $107,250 penalty for a risk assessment that didn't adequately document business-specific risks
- A bank was penalized for eight separate failures to conduct ongoing monitoring tied to its own s.9.6(2) risk assessment

FINTRAC doesn't just check whether a risk assessment exists. Examiners test whether controls are actually applied consistently and whether that consistency can be demonstrated with evidence during an examination. A binder full of policies means nothing if front-line practice doesn't match it.
An independent challenge before an examination is where that gap shows up. AlphaDelta's senior advisory work — structured as retainer, defined engagement, or hourly support — gives reporting entities an outside view of their risk assessment methodology and control framework.
That view is shaped by practical Canadian regulatory and program experience. Knowing how an examiner tests assumptions beats guessing at what they might look for.
Frequently Asked Questions
What is a risk-based approach?
A risk-based approach means identifying, prioritizing and mitigating risk in proportion to its severity, rather than treating all risk factors equally. It allocates the most scrutiny to the areas of greatest ML/TF exposure.
Why is a risk-based approach used in AML compliance?
It allows reporting entities to direct resources toward the highest actual risks instead of spreading effort evenly across all clients. It's also a legal requirement under both FINTRAC's guidance and FATF's international standards.
What are the three steps for a risk-based approach?
The core steps are: identify and assess risk, apply proportionate mitigation controls, and monitor and periodically review the residual risk. FINTRAC's full guidance breaks this into six steps, but they collapse into these three phases.
What are the three components of a risk-based approach to AML compliance?
They are risk identification, control implementation, and ongoing monitoring and review. Under FINTRAC, these sit inside your compliance program obligations; the framework is consistent even when product- or sector-specific rules differ.
What is the risk-based approach to KYC?
It means calibrating how intensive your identification and due diligence process is based on the client's assessed risk level. High-risk clients get enhanced due diligence; lower-risk clients get standard measures applied proportionately, without dropping prescribed duties.
What is a red flag during KYC verification?
Common examples include an unexplained source of funds, unusually complex ownership structures, and transaction activity inconsistent with a client's stated profile. FINTRAC treats these as contextual indicators, not standalone proof of wrongdoing.


