PROCESSING...

Anti-Money Laundering
Consulting Services & Strategies

0 Items - Total: $0.00 CAD

Outlier Compliance Group welcomes Jasbir Dhillon and Wioletta Traynor!

 

The Outlier Compliance Group team is thrilled to welcome two of our newest members, Jasbir Dhillon and Wioletta Traynor.

Jasbir brings deep money services business (MSB) and real estate experience to the team, and Wioletta brings deep jewelry sector expertise and is a CPA.

Jasbir’s Bio

Jasbir is a compliance and financial crime professional with over 15 years of experience in regulatory oversight, anti-money laundering (AML), and risk management across the banking, money services business, and consulting sectors. She has extensive experience supporting organizations in meeting their obligations under Canadian regulatory frameworks, including FINTRAC requirements, the PCMLTFA, and PIPEDA.

Her work focuses on regulatory audits, AML/ATF investigations, risk assessments, and the development of robust compliance programs that help organizations navigate complex regulatory environments while maintaining strong operational integrity.

 

 

 

Wioletta’s Bio

Wioletta Traynor, CPA, CGA brings more than 13 years of leadership experience in the precious metals, e-commerce industry, with a background in AML/ATF compliance, risk and finance management, and private accounting.

Prior to joining Outlier Solutions Inc., Wioletta has served in a senior leadership role, including Chief Deputy Compliance Officer, Financial Controller, and CFO, helping businesses with compliance and accounting frameworks, internal controls, and internal compliance systems and investigations. Her experience includes AML/ATF Compliance Effectiveness Reviews, GAP Analysis, policy development, AML/ATF risk assessments, internal investigations, fraud prevention, and general compliance.

Over the years, she has contributed to multiple fraud related investigations involving suspicious transactions and financial misconduct, including the widely publicized Project Bridle Path mortgage fraud case.

Wioletta is passionate about helping organizations go beyond the “tick box” AML/ATF checklist and building effective programs to protect businesses from financial and reputational risk.

Please join us in welcoming Jasbir and Wioletta!

As with all our consultants, both Jasbir and Wioletta have deep subject matter expertise of more than 10,000 hours and support Outlier’s mission statement “good compliance can enable good business”.

 

Looking for Outlier AI? You’ve Reached the Wrong Company

If you searched for “Outlier AI” and ended up here, you’re not alone – but you are in the wrong place.

Outlier Solutions Inc. (operating as Outlier Compliance Group) is a Canadian compliance consulting firm based in Canada. We help reporting entities navigate their regulatory obligations under Canadian financial compliance frameworks. We are not affiliated with, related to, or connected to Outlier AI in any way.

So What is Outlier AI?

Outlier AI is a separate company. Any inquiries meant for them should be directed through their own website. Contacting us will not reach them – we have no way to forward messages or act on their behalf.

Why the Confusion?

The similarity in our names has led to a growing number of misdirected inquiries, particularly as AI companies have expanded rapidly in recent years. If you’re looking for Outlier AI specifically, please visit their website directly.

Now, if You’re in the Right Place…

If you’re a reporting entity looking for compliance support — whether that’s AML, regulatory risk, or compliance program development — we’re here to help. Please get in touch.

RPAA Annual Reporting – Reminder and Key Requirements

Background

Under the RPAA and the Retail Payment Activities Regulations (RPAR), Payment service providers (PSPs) must submit an annual report through the Bank of Canada’s (BoC) online portal using the prescribed reporting form. Reports must be filed annually by March 31 and must cover retail payment activities conducted during the prior calendar year.

Who Must Comply

All PSPs that are on the registration list with BoC must complete the annual report. For clarity, BoC has established the following deadlines:

  • PSPs registered before March 9, 2026, must submit their report by March 31, 2026.
  • PSPs registered between March 9 and March 30, 2026, have until April 28, 2026.

PSPs on the application list as of March 31, 2026, are not required to file a report for the 2025 year and will report in 2026.

The annual report is now available through PSP Connect. It includes mandatory sections and does not permit structural or formatting changes. It is set up similarly to what PSPs saw as part of registration. All required fields must be completed, and any omissions must be explained in accordance with BoC guidance.

What to Report

The following are the reporting elements of the annual report.

1. Operational Risk and Incident Management

In this section, PSPs must provide information on the governance, design, and effectiveness of their operational risk management and incident response frameworks. This includes confirming whether the framework, and any material updates to it, were approved during the reporting year by the senior officer.

In this section, PSPs must identify the operational risk categories monitored during the year and must outline what protective and detective measures were in place. Importantly, this action requires PSPs to provide quantitative staffing and resourcing information.

PSPs must also explain how operational risks arising from third-party service providers and agents or mandataries are managed. PSPs must also indicate whether agreements with third-party service providers were entered into, amended, extended, or renewed. Where agents or mandataries are used, PSPs are expected to confirm that responsibilities are clearly defined, operational risk criteria are established, and assessments are performed to evaluate whether those criteria are met.

Some key requirements for this section are:

  • Did the PSP classify assets and business processes by sensitivity and criticality?
  • Were sufficient human and financial resources available to implement and maintain the framework?
  • Did the framework set out operational reliability objectives, targets, and indicators?
  • Which measures were in place to mitigate technology risks and protect assets and processes?
  • Did the framework include incident response and recovery plans, including third-party incidents?
  • Which elements were included in the incident response plan?

2. Safeguarding of End-User Funds

In this section, PSPs that perform the payment function of holding funds on behalf of end-users must identify whether they safeguard funds through a trust account or through an account supported by insurance or a guarantee, and whether the safeguarding method changed during the reporting year.

PSPs must report whether end-user funds are placed into a safeguarding account upon receipt and, where processing constraints exist, whether funds are placed into the safeguarding account by the next business day. PSPs must identify whether safeguarding accounts are held with Canadian or foreign financial institutions and, where applicable, identify those institutions and their regulators.

PSPs must describe the liquidity approach used to ensure end-users have reliable access to their funds and outline the procedures in place for returning those funds in the event of the PSP’s insolvency.

Some key requirements for this section relate to shortfall reporting. PSPs must report instances during the reporting year where safeguarded funds were insufficient, including:

  • the date the shortfall occurred and the date it was resolved,
  • the maximum daily shortfall amount (in CAD),
  • the root cause (selected from prescribed categories), and
  • the measures taken to prevent recurrence.

3. Significant Changes and Incidents

In this section, PSPs must identify all significant changes that occurred during the reporting year. A change is considered significant where it could reasonably be expected to materially affect operational risk or the safeguarding of end-user funds. The annual report requires each change to be reported separately, including the month and year in which the change took effect.

Examples of reportable significant changes include new or amended outsourcing arrangements, changes to third-party service provider relationships, material technology changes, geographic expansions, new products or market segments, changes in participation in payment systems, and material changes to organizational structure or staffing levels.

It is important to note that the report must also include a complete inventory of incidents experienced during the year, including incidents that were not required to be reported to the Bank under the RPAA at the time they occurred.

PSPs must also identify any retail payment activities that the PSP began or ceased to perform during the reporting year.

4. Ubiquity and Interconnectedness Metrics

In this section, PSPs must provide quantitative metrics as it relates to end-user funds used by the Bank to assess a PSP’s footprint and interconnectedness within the Canadian payments ecosystem.

These metrics must capture transactions where the PSP performed a payment function directly or indirectly, and must be reported separately for all end-users and end-users in Canada, where applicable.

PSPs must also report the total number of distinct end-users served during the reporting year, including users receiving services directly and indirectly, and provide information on services performed for other registered PSPs.

Some key metrics that must be reported include:

Value of End-User Funds Held

  • The maximum Canadian Dollar (CAD) equivalent value of end-user funds held at any time during the year.
  • For each month, report the average daily value (in CAD) at month-end.
  • Both the total of all funds held, and a breakdown by currency held.

End-Users

  • Total number of distinct end-users, and
  • Number of users receiving direct vs. indirect services (via third-party PSPs).

Number and Value of Electronic Funds Transfers (EFTs)

  • Monthly Count and Total Value
    • Report the monthly count and total value of EFTs.
    • Values in CAD (as both a total of all currencies combined, and a breakdown by currency of the EFT).
  • Value by Payment Type
    • Report an estimate of the total value of EFTs by payment type as a share of total value.

PSP with a place of business in Canada must report values for end-users in Canada and end-users outside of Canada as separate amounts.

5. Financial Information

In this section, PSPs must report key financial information, including total revenue, operating expenses, and total equity. Financial information may be reported using the PSP’s fiscal year-end, whereas most other reporting elements must align with the calendar year.

6. Record-Keeping

In this section, PSPs must confirm whether they maintain records sufficient to demonstrate compliance with the RPAA and the Retail Payment Activities Regulations. PSPs must indicate whether record-keeping is complete, partially complete, or not in place, and should be prepared to support these responses if requested by the Bank.

Preparing for Report

The annual reporting form is available through PSP Connect as of February 2, 2026. We suggest that PSPs may begin gathering the needed information for submission at any time prior to the applicable deadline. To help make this a bit easier, Outlier has put together a spreadsheet that will help in compiling the needed information. Please note that this spreadsheet does not replace formal BoC guidance. The system does allow organizations to save and continue where you left off.

We’re Here To Help

If you would like assistance in understanding what has to be reported or if you need help with RPAA requirements in general, please get in touch.

Canada & Australia Financial Crime Webinar Series

We’re proud to participate in a five-part webinar series on Financial Crime Investigations and Enforcement in Canada and Australia. The series brings together leading voices from Canada and Australia to explore today’s most pressing financial crime challenges.

Join Outlier’s Amber Scott in moderating the 4th session of the Canada & Australia Financial Crime Webinar Series on Due Diligence (Canada) on November 24.

4PM-5PM ET Online

Learn more and register here.

DIACC Executive Plenary

Join Outlier’s David Vijan at the DIACC Executive Planery on November 6th, 2025.

The following topics will be explored during the panel discussion on “The Digital Trust Landscape: Open Banking & Client Identity Verification”:

  • Consumer-Directed Finance Framework in Canada
  • Regulatory landscape (FINTRAC, PIPEDA, provincial requirements)
  • Current state of identity verification in lending decisions

Panel Details:

  • November 6, 2025
  • 1:30PM-2:15pm ET

Industry Leaders Roundtable Session

This gathering provides a unique opportunity to discuss and network with executives and leaders in the AML industry, fostering meaningful dialogue in a confidential setting guided by the Chatham House Rule.

During the session, the new regulatory updates, key topics, and challenges faced by REs in the industry will be addressed. This discussion aims to bring together decision-makers and industry experts to foster collaboration, exchange insights, and explore solutions to pressing challenges.

Details & Registration: By invitation only; further details forthcoming

New Beneficial Ownership Discrepancy Reporting

Effective October 1, 2025, Canadian anti-money laundering (AML) reporting entities regulated by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) are required to report to Corporations Canada any material discrepancies identified between the beneficial ownership information that they have obtained and that is listed in Corporations Canada’s database.

Background

This requirement was introduced to enhance the reliability of beneficial ownership information available to authorities and the public, and to reduce the opportunities for misuse of Canadian corporate structures in money laundering, tax evasion, and sanctions avoidance schemes. Since the usefulness of the beneficial ownership information depends on the accuracy of the information, amendments under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) now will require reporting entities to flag material discrepancies between the information provided by a corporation incorporated under the Canada Business Corporations Act (CBCA) and what is recorded in the registry, thereby supporting Corporations Canada in maintaining an accurate database.

A “material discrepancy” exists where beneficial ownership information collected by a reporting entity substantively contradicts what is publicly disclosed. While the regulations give limited guidance, missing beneficial owners are considered material, while minor typographical errors are not. Currently, the definition of “material” remains imprecise, which may create some uncertainty for compliance teams.

Who Must Comply

The requirement applies to reporting entities who have the existing obligation to take reasonable measures to confirm the accuracy of beneficial ownership information when they first obtain it and in the course of conducting ongoing monitoring of their business relationships.

Discrepancy reporting applies only to CBCA corporations that are active on the Corporations Canada registry.

When to Report

Reporting entities are required to report a material discrepancy to Corporations Canada within 30 days after the day on which it is identified when the following criteria are met:

  • A client is an active CBCA corporation; and
  • The reporting entity determines that the corporation is high-risk for money laundering, terrorist financing, or sanctions evasion; and 
  • When there is a material discrepancy in beneficial ownership information that is not resolved within 30 days. Note there is no requirement to address the material discrepancy directly  with the customer. 

In these cases, reporting entities must check the Corporations Canada registry when a high-risk relationship is first identified and continue to check during ongoing monitoring of that high-risk business relationship.

If a previously reported discrepancy is identified again (i.e., during the course of ongoing monitoring) and it has not been resolved, it must be reported again. If there are other issues related to corporate status or registry info (not beneficial ownership information), this information can still be reported to Corporations Canada, but it must be done so separately. Voluntary reporting is permitted if the client is considered low-risk, but discrepancies are still found.

Reporting Steps

Reports are submitted through Corporations Canada’s online portal (accessed through the registry). The process is as follows:

  1. Ensure your reporting entity is registered for FINTRAC Web Reporting (FWR), and that the individual completing the reporting has an active My ISED account with Corporations Canada.
  2. Search the corporation on the Corporations Canada website to confirm it is an active CBCA corporation.
  3. While in Corporations Canada’s online portal, from the page connected to the corporation about which the discrepancy is being reported, select “Report an Issue” (currently a link at the bottom right of the page). This will prompt a My ISED login.
  4. Complete the discrepancy form with:
    • Reporting entity details (legal name, RE number, location, compliance contact/email). This information will auto-populate after the first report. 
    • Corporation details (name and incorporation number for the company you are reporting on).
    • Selecting the reason for reporting a discrepancy (reporting as required under PCMLTFA or voluntary).
    • Discrepancy details (nature of inconsistency, date identified).
  5. Review the information for accuracy and submit the report.
  6. A confirmation screen will appear, including a reference number 
  7. Corporations Canada will validate the report and issue an acknowledgment within 10 business days.
  8. Keep a copy of the acknowledgement as evidence of the completed discrepancy reporting.
  9. If the discrepancy has not been resolved by the next time you complete periodic monitoring for the entity, the process is repeated.

For more detailed steps on reporting, you may refer to the guidance on submitting a beneficial ownership discrepancy report or the following Corporations Canada demo video, which together provide a comprehensive overview.

 

Note that inaccurate or incomplete reporting entity information will result in an invalid Beneficial Ownership discrepancy report. Amendments to submitted reports are currently not possible, and a new report will have to be submitted. 

Reporting entities must retain the report acknowledgment and other supporting documentation as evidence of meeting obligations. 

We’re Here To Help

If you would like assistance in understanding what these changes mean to your business, or if you need help updating your compliance program and processes, please get in touch.

Check Your FINTRAC MSB Registration

Divya BhakthaAre you a money services business (MSB) that serves clients in Canada? Have you checked your MSB registration lately? If not, there’s no time like the present, and you can do so here.

What’s Required?

There have been some changes to the process for updating registration information with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) that may not be immediately apparent, and further changes are forthcoming. As a reminder, when an MSBs’ information changes, including products, locations, key personnel such as the Compliance Officer, ownership, or agents, that information must be updated with FINTRAC within 30 days. MSB registration must also be renewed prior to the registration’s expiry date. 

MSB Registration Changes 

When your MSB registration information changes, the first step is to complete the change form on FINTRAC’s website and remember to submit it within 30 days of the change. This form has a number of checkboxes that must be selected, depending on the specific updates that are being requested, as well as a freeform field that can be used to provide additional information (but be brief, there is a 100-character limit). There is also an option to download and save a copy of the completed form, which should be kept as part of your AML records. 

Once FINTRAC has received the form, they will reach out, usually to the email address provided in the form, with next steps. The most common next step is currently for FINTRAC to send a PDF form using Canada Post Connect (a secure portal for messages and document sharing), which must be completed and returned within a specific timeframe. As with the online registration form, you should save a copy of your completed change form.

MSB Registration Renewals

Before your MSB registration expires, complete the renewal form on FINTRAC’s website. Remember, your MSB registration is valid for two years, and you need to renew it before it expires. This form is different from the change form, but does have a checkbox that must be selected if there are also changes to MSB registration information, as well as a freeform field that can be used to provide additional information (remember to be brief, as there is a 100-character limit). There is also an option to download and save a copy of the completed form, which should be kept as part of your AML records. You can also use the save a copy function to download a form in progress, which can be re-uploaded and completed later.

Once FINTRAC has received the form, they will reach out, usually to the email address provided in the form, with next steps. If there are changes to MSB registration information, the most common next step is currently for FINTRAC to send a PDF form using Canada Post Connect (a secure portal for messages and document sharing), which must be completed and returned within a specific timeframe. We recommend whitelisting @fintrac-canafe.gc.ca and @canadapost-postescanada.ca addresses, so that they don’t get caught in your spam filters.

In either of the above scenarios, we recommend that you always download and keep a copy of the registration details, which include the time and date when you submitted the document, so you have proof if required at a later date.

Does FINTRAC Send Notices to Expiring MSBs?

Prior to last year, MSBs received email reminders from FINTRAC when their registration was expiring, but it doesn’t seem that this is the case. You should not expect a notification from FINTRAC when your MSB registration is set to expire. We recommend setting a reminder in your calendar for 30 days before the registration expires, to make sure the form is submitted on time.

Need a hand?

Whether you need assistance with your FINTRAC registration or AML compliance in general, you can contact us here or by email at info@outliercanada.com.

We Turn 12!

Green foil balloons forming the number 12 with gold confetti on a light background, celebrating a 12-year anniversary.Today marks another milestone for us – 12 years since Outlier Compliance Group was founded.

What began as a bold and novel idea, building a consulting firm made up exclusively of seasoned compliance professionals with deep in-house experience, has grown into a thriving, trusted partner for clients navigating Canada’s ever-changing regulatory landscape.

Our name, inspired by Malcolm Gladwell’s “Outliers, the Story of Success” which espoused the notion that to be truly proficient in a skill, 10,000 hours of practice is required. That was the bar that was set, met, and most often exceeded by every compliance professional that joined our team over the years.

Over the years, we’ve grown, evolved, but have stayed true to our roots. We’ve learned that success comes from surrounding ourselves with exceptional people, from listening closely to our clients, and from being willing to adapt in the face of change. We’ve discovered the value of curiosity when navigating complexity, and the power of collaboration when tackling the most challenging problems.

Through it all, our mission has remained the same “good compliance is good business”. It’s the principle that guides our work, shapes our advice, and underpins every solution we deliver.

As the Canadian regulatory environment becomes increasingly complex, our mission and our learnings will play to our continued success and growth as we continue to provide top tier compliance and risk management services. 

To our amazing team, past, present and future, thank you for your passion, expertise and resilience. To our clients, partners and industry peers, thank you for your trust and collaboration. Lastly, but by no means least, a special thank you to our CEO, David Vijan, and our Chairperson, Amber D. Scott, for keeping us on our toes and steering the ship with vision and purpose. 

Here’s to 12 years of achievement and to the future.

Identification Triggers for Factoring Companies

Background

We recently sought clarification from FINTRAC as it relates to identification requirements that Factoring Companies (Factors) must comply with.

Factors supply liquidity to a customer in exchange for the cash value of a certain amount of the customer’s accounts receivable (i.e. invoices) to be collected later by the factoring company. A factor is defined as a person or entity that is engaged in the business of factoring, with or without recourse against the assignor.

If you missed it, Factors became reporting entities under the PCMLTFA effective April 1, 2025. As a reporting entity, Factors must have in place a compliance program and comply with various requirements, including identification requirements.  Please refer to our previous blog post on Factors that outlines full requirements that factors must comply with.

Identification Requirements

Factors must confirm identification using prescribed methods for individuals and entities where they are required to keep a record as defined under section 24.14 of the

Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations.

Section 24.14 states a factor shall keep the following records in respect of every factoring agreement that it enters into:

(a) an information record in respect of the person or entity with whom it enters into the agreement;

 (b) if the information record is in respect of an entity, a record of the name, address and date of birth of every person who enters into the agreement on behalf of the entity and the nature of the person’s principal business or their occupation;

 (c) if the information record is in respect of a corporation, a copy of the part of official corporate records that contains any provision relating to the power to bind the corporation in respect of transactions with the factor;

 (d) a record of the financial capacity of the person or entity with which it enters into the agreement and the terms of the agreement;

 (e) for any payment it makes; and

 (f) a receipt of funds record in respect of every amount of $3,000 or more that it receives, unless the amount is received from a financial entity or public body or from a person who is acting on behalf of a client that is a financial entity or public body.

As it relates to the last record, funds may come from a party other than the factoring client (a third party) and in such instances it is not sufficient to rely on identification that would have been completed for the factoring client, but rather the third party would have to be identified.

Below is a response from FINTRAC:

Under the PCMLTFA, specifically section 24.14(f), a receipt of funds record must be kept for every amount of $3,000 or more, unless the funds are received from a financial entity, public body, or a person acting on behalf of such an entity.

In response to your question:
If funds are received from a party other than the identified factoring client, identification requirements may still apply depending on who that third party is.

If the third party is not:

    • a financial entity,
    • a public body, or
    • acting on behalf of one,

then yes, identification and a receipt of funds record would be required, even if the factoring client has already been identified. This is because the receipt of funds record pertains to who the funds are actually received from, not just who the factoring agreement is with.

Identification of the factoring client alone is not sufficient if funds are received from another party who does not fall under the exemptions in s. 24.14(f). The source of funds must be identified and recorded accordingly.

The factoring company must take reasonable measures to identify the sender, document those efforts, and keep a receipt of funds record.

While this may prove to be challenging in some instances, demonstrating that reasonable measures were taken becomes critical.

We’re Here To Help

If you would like assistance in understanding what this mean to your business, or if you need help in creating or updating your compliance program and processes, please get in touch.

Return to Blog Listing