PROCESSING...

Anti-Money Laundering
Consulting Services & Strategies

0 Items - Total: $0.00 CAD

Your Real Estate Business Can’t Afford ‘Just-in-Time Compliance’

Written with Heidi Unrau

 

In the past two years, 13 real estate brokerages faced a total of $1,041,936 in administrative monetary penalties (AMP) from FINTRAC, the federal agency that regulates anti-financial crime compliance and analyzes financial intelligence in Canada. That works out to an average fine of $80,148 per brokerage, with the single largest AMP reaching approximately $150,000. 

Real estate brokers, sales representatives, and developers have legal responsibilities under Canada’s anti-money laundering rules prescribed by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). These rules are designed to prevent, detect and deter real estate transactions from being used to hide proceeds of crime, to fund terrorist activity, or evade sanctions. 

Yet too many brokerages still treat anti-money laundering (AML) compliance as a cost centre instead of a core risk management function. And what we’re seeing is a lot of “just-in-time compliance” behaviour, resulting in major deficiencies with up to six-figure penalties.

Compliance within the real estate industry has never been as important as it is right now. Not only is the regulator penalizing companies for compliance failures, but the monetary penalties are now 40 times higher than they were before. That emphasizes the level of effort that needs to be paid to your compliance program before FINTRAC calls.

Why is FINTRAC Cracking Down on Real Estate?

Real estate is an attractive target for money laundering because one deal can move a significant amount of illicit funds. Real estate transactions are especially vulnerable because they are used at the integration stage of money laundering, after the funds have already moved through accounts, businesses, third parties, family members, or international transfers to obscure the origin. 

By the time those funds reach real estate, the warning signs are much harder to identify, but the compliance expectations do not change. Given the size, complexity, and risk profile of real estate transactions, you need to apply greater scrutiny to the people, funds, and circumstances behind each deal. 

Weak controls around identification, record keeping, training, and suspicious transaction reporting expose your business to unnecessary financial and reputational risk.

The Problem With ‘Just-in-Time Compliance’

Just-in-time compliance happens when you ignore your AML compliance obligations throughout the year, or worse, a longer period of time, then scramble to fix everything after FINTRAC makes contact. By then, it’s too late. 

Once FINTRAC calls, the exam has already started. Everything done after that point becomes last-minute compliance. It’s better than doing nothing, but it doesn’t prove you had those controls in place during the period FINTRAC is reviewing. 

The regulator is looking at whether you had a functioning program in place during the period under review. If your procedures, training, records, and review processes were missing or outdated during that period, fixing them after FINTRAC contacts you will not undo the deficiency.

A FINTRAC examination can disrupt regular business operations if you’re scrambling to track down missing records, update stale policies, complete overdue training, or fix program gaps while still trying to serve clients and close deals. 

FINTRAC publishes all administrative monetary penalties on its website. A public enforcement action can damage trust with clients, lenders, referral partners and other stakeholders, causing serious reputational harm that can negatively affect your bottom line. 

That’s exactly why AML compliance has to be treated as an ongoing business function. You already understand this concept in other areas of your business. You do not wait until tax season to create a full year of bookkeeping from scratch. You do not wait until a lawsuit to decide if your contracts were properly drafted. AML compliance works the same way. The work needs to be done before the regulator asks for proof. 

Start With Your Baseline AML Obligations

Trying to build a perfect AML program right out of the gate can be overwhelming. In reality, you should start by meeting the baseline requirements. That means ensuring your real estate business has the fundamentals in place, such as written policies and procedures, a designated Compliance Officer, training, risk assessment, record keeping, suspicious transaction escalation and reporting processes, and the required two-year compliance effectiveness review. 

Beyond these baseline requirements, FINTRAC states you must implement a compliance program that can effectively verify the identity of the persons and entities involved in transactions, conduct ongoing monitoring when a business relationship is formed, obtain and take reasonable measures to confirm beneficial ownership information for entities, make third-party determinations when required, and take reasonable measures to determine whether clients are politically exposed persons or heads of international organizations.

Your policies and procedures should clearly explain what your business is supposed to do. Risk assessments identify where your business is most exposed. Your training ensures staff and agents understand their obligations. Your records prove what happened. And your suspicious transactions process shows how concerns are escalated, reviewed, documented, and reported. 

Why The Two-Year Effectiveness Review Is Critical

The two-year effectiveness review is especially important because it reveals where your program is working and where it’s weak. We recommend starting here because it provides a look at your AML compliance program as a whole, identifies the biggest problem areas, and prioritizes the highest risk gaps. It is very important that the person completing your review has adequate experience and understands the industry, as well as your business. This should not be a “check the box” compliance exercise. 

If you have not yet completed an effectiveness review, that should be the top priority. 

Where Real Estate Entities Commonly Fail 

Many real estate compliance failures are basic program deficiencies that are entirely preventable. The most serious gaps usually fall into three main areas: not having an AML program at all, failing to complete the required two-year effectiveness review, and unreported suspicious transactions. The regulator can, and does, penalize failures in the compliance process itself, including missed reporting, poor documentation, and weak program controls.

It is complex, but it is not impossible. If your written program does not reflect how your brokerage actually operates, fix it. If your training is outdated, that needs attention. If your team is unsure what to collect, when to escalate concerns, or when a report may be required, those deficiencies should be fixed before FINTRAC identifies them for you.

No AML Program At All

The most common failure is having nothing in place. That means no written policies and procedures, no designated compliance officer, no training, and no clear internal process for meeting AML obligations. 

These are the foundation of a compliance program. Without them, your business has no consistent way to identify risk, collect required information, train agents, escalate concerns, keep records, or prove to the regulator that the business is taking its obligations seriously. 

The Two-Year Effectiveness Review Not Done

Another major gap is the two-year effectiveness review. It’s often skipped entirely, even though it is one of the most important tools you have to determine if your compliance program is actually working. Without it, you may not know where your business is exposed until FINTRAC identifies the problem first. 

Missed Suspicious Transaction Reporting

A single unreported suspicious transaction can result in a financial penalty well over $100,000. Yet, this remains one of the most common compliance failures. 

FINTRAC has given reporting entities a laundry list of suspicious indicators. And that laundry list is what they’re using to assess your transactions. If a transaction presents red flags, it needs to move through a clear internal process so you can show the regulator what the final decision was. Specifically, that there were reasonable grounds to suspect (RGS) the transaction was related to financial crime and reported as a suspicious transaction to FINTRAC, or there was not RGS and the rationale is clearly documented.  

‘Suspicious’ Does Not Automatically Mean a Dead Deal

A common point of confusion is the distinction between a high-risk transaction, a suspicious transaction, and a transaction you cannot legally participate in. 

A transaction can be high risk without being illegal. A client might have foreign funds, a complex ownership structure, have a holding company involved, or have a third party helping with the purchase. Those details can have legitimate explanations. They also require more questions, documentation, and scrutiny. 

A transaction is suspicious when you have reasonable grounds to suspect, which is a lower threshold than to believe, that it is linked to criminal activity. You do not need proof, but you do need to explain why you feel it is suspicious based on facts, context, indicators, what you know about the client, and the nature of the transaction. 

You can still proceed with high risk and suspicious transactions. Your obligation is to assess the concern, document what happened, escalate internally, and report to FINTRAC when required. 

However, if a client is asking you to help them break the law or evade sanctions, then you absolutely cannot proceed with the transaction. 

Next Steps

For real estate brokerages, compliance is no longer something to address only when an exam is looming, the biggest risk is waiting too long.

If your real estate business does not have an AML compliance program, you need to implement one as soon as possible. Get support from a qualified compliance provider that can help create policies and procedures customized to the specific type of real estate business you conduct. Generic compliance templates are no longer effective because they are not tailored to align with your specific day-to-day operations. 

If you have an AML compliance program, but have not yet completed your two-year effectiveness review, start there. It will tell you where your program is working and where it’s not. Then use that information to prioritize what needs to be fixed first. 

Need an effectiveness review or support building, reviewing, or updating your AML compliance program? Contact Outlier to get clear, practical guidance on your obligations and next steps.

Outlier Team Update: Promoting Maria Shamou

We’re excited to announce the promotion of Maria Shamou to AML Project Coordinator!

Since joining Outlier, Maria has been an integral part of our team, providing exceptional support to both our clients and consultants. In her expanded role, she will continue her administrative responsibilities while also coordinating our AML projects, helping ensure seamless project delivery and a better, more seamless client experience.

This promotion reflects Maria’s hard work, dedication, and commitment to excellence. Please join us in congratulating her. We’re excited to see her continue to grow with the Outlier team!

 

 

Osgoode Certificate in Regulatory Compliance & Legal Risk Management for Financial Institutions

Join the module 5 discussion on Technology and Industry Disruptors as part of The Osgoode Certificate in Regulatory Compliance & Legal Risk Management for Financial Institutions, offered by Osgoode Professional Development at York University. Specifically, in Part B: Bitcoin/Blockchain and Case Studies, Outlier‘s Amber Scott will explore how blockchain technology and cryptocurrencies are reshaping the financial services landscape and challenging traditional regulatory frameworks.

Overall, the session will examine the opportunities, risks, and compliance implications associated with digital assets, decentralized technologies, and emerging business models.

For more information and to register, click here.

Outlier Compliance Group welcomes Jasbir Dhillon and Wioletta Traynor!

 

The Outlier Compliance Group team is thrilled to welcome two of our newest members, Jasbir Dhillon and Wioletta Traynor.

Jasbir brings deep money services business (MSB) and real estate experience to the team, and Wioletta brings deep jewelry sector expertise and is a CPA.

Jasbir’s Bio

Jasbir is a compliance and financial crime professional with over 15 years of experience in regulatory oversight, anti-money laundering (AML), and risk management across the banking, money services business, and consulting sectors. She has extensive experience supporting organizations in meeting their obligations under Canadian regulatory frameworks, including FINTRAC requirements, the PCMLTFA, and PIPEDA.

Her work focuses on regulatory audits, AML/ATF investigations, risk assessments, and the development of robust compliance programs that help organizations navigate complex regulatory environments while maintaining strong operational integrity.

 

 

 

Wioletta’s Bio

Wioletta Traynor, CPA, CGA brings more than 13 years of leadership experience in the precious metals, e-commerce industry, with a background in AML/ATF compliance, risk and finance management, and private accounting.

Prior to joining Outlier Solutions Inc., Wioletta has served in a senior leadership role, including Chief Deputy Compliance Officer, Financial Controller, and CFO, helping businesses with compliance and accounting frameworks, internal controls, and internal compliance systems and investigations. Her experience includes AML/ATF Compliance Effectiveness Reviews, GAP Analysis, policy development, AML/ATF risk assessments, internal investigations, fraud prevention, and general compliance.

Over the years, she has contributed to multiple fraud related investigations involving suspicious transactions and financial misconduct, including the widely publicized Project Bridle Path mortgage fraud case.

Wioletta is passionate about helping organizations go beyond the “tick box” AML/ATF checklist and building effective programs to protect businesses from financial and reputational risk.

Please join us in welcoming Jasbir and Wioletta!

As with all our consultants, both Jasbir and Wioletta have deep subject matter expertise of more than 10,000 hours and support Outlier’s mission statement “good compliance can enable good business”.

 

Looking for Outlier AI? You’ve Reached the Wrong Company

If you searched for “Outlier AI” and ended up here, you’re not alone – but you are in the wrong place.

Outlier Solutions Inc. (operating as Outlier Compliance Group) is a Canadian compliance consulting firm based in Canada. We help reporting entities navigate their regulatory obligations under Canadian financial compliance frameworks. We are not affiliated with, related to, or connected to Outlier AI in any way.

So What is Outlier AI?

Outlier AI is a separate company. Any inquiries meant for them should be directed through their own website. Contacting us will not reach them – we have no way to forward messages or act on their behalf.

Why the Confusion?

The similarity in our names has led to a growing number of misdirected inquiries, particularly as AI companies have expanded rapidly in recent years. If you’re looking for Outlier AI specifically, please visit their website directly.

Now, if You’re in the Right Place…

If you’re a reporting entity looking for compliance support — whether that’s AML, regulatory risk, or compliance program development — we’re here to help. Please get in touch.

AML 101 for Jewellers Webinar

Have you completed your annual AML Training? Jewellers are required to conduct Anti-Money Laundering (AML) Compliance training for staff annually.

Join Outlier Compliance Group‘s CEO and AML Expert, David Vijan, for CJA‘s annual “AML 101 For Jewellers” webinar. This webinar focuses on AML basics and can be used as part of your mandatory annual training, in addition to advising your staff on your own specific procedures. Case studies and key updates shared during the webinar will assist attendees with their compliance obligations.

Register here.

Date & Time: April 27, 2026 – 1:00 pm – 2:00 pm (ET)

RPAA Annual Reporting – Reminder and Key Requirements

Background

Under the RPAA and the Retail Payment Activities Regulations (RPAR), Payment service providers (PSPs) must submit an annual report through the Bank of Canada’s (BoC) online portal using the prescribed reporting form. Reports must be filed annually by March 31 and must cover retail payment activities conducted during the prior calendar year.

Who Must Comply

All PSPs that are on the registration list with BoC must complete the annual report. For clarity, BoC has established the following deadlines:

  • PSPs registered before March 9, 2026, must submit their report by March 31, 2026.
  • PSPs registered between March 9 and March 30, 2026, have until April 28, 2026.

PSPs on the application list as of March 31, 2026, are not required to file a report for the 2025 year and will report in 2026.

The annual report is now available through PSP Connect. It includes mandatory sections and does not permit structural or formatting changes. It is set up similarly to what PSPs saw as part of registration. All required fields must be completed, and any omissions must be explained in accordance with BoC guidance.

What to Report

The following are the reporting elements of the annual report.

1. Operational Risk and Incident Management

In this section, PSPs must provide information on the governance, design, and effectiveness of their operational risk management and incident response frameworks. This includes confirming whether the framework, and any material updates to it, were approved during the reporting year by the senior officer.

In this section, PSPs must identify the operational risk categories monitored during the year and must outline what protective and detective measures were in place. Importantly, this action requires PSPs to provide quantitative staffing and resourcing information.

PSPs must also explain how operational risks arising from third-party service providers and agents or mandataries are managed. PSPs must also indicate whether agreements with third-party service providers were entered into, amended, extended, or renewed. Where agents or mandataries are used, PSPs are expected to confirm that responsibilities are clearly defined, operational risk criteria are established, and assessments are performed to evaluate whether those criteria are met.

Some key requirements for this section are:

  • Did the PSP classify assets and business processes by sensitivity and criticality?
  • Were sufficient human and financial resources available to implement and maintain the framework?
  • Did the framework set out operational reliability objectives, targets, and indicators?
  • Which measures were in place to mitigate technology risks and protect assets and processes?
  • Did the framework include incident response and recovery plans, including third-party incidents?
  • Which elements were included in the incident response plan?

2. Safeguarding of End-User Funds

In this section, PSPs that perform the payment function of holding funds on behalf of end-users must identify whether they safeguard funds through a trust account or through an account supported by insurance or a guarantee, and whether the safeguarding method changed during the reporting year.

PSPs must report whether end-user funds are placed into a safeguarding account upon receipt and, where processing constraints exist, whether funds are placed into the safeguarding account by the next business day. PSPs must identify whether safeguarding accounts are held with Canadian or foreign financial institutions and, where applicable, identify those institutions and their regulators.

PSPs must describe the liquidity approach used to ensure end-users have reliable access to their funds and outline the procedures in place for returning those funds in the event of the PSP’s insolvency.

Some key requirements for this section relate to shortfall reporting. PSPs must report instances during the reporting year where safeguarded funds were insufficient, including:

  • the date the shortfall occurred and the date it was resolved,
  • the maximum daily shortfall amount (in CAD),
  • the root cause (selected from prescribed categories), and
  • the measures taken to prevent recurrence.

3. Significant Changes and Incidents

In this section, PSPs must identify all significant changes that occurred during the reporting year. A change is considered significant where it could reasonably be expected to materially affect operational risk or the safeguarding of end-user funds. The annual report requires each change to be reported separately, including the month and year in which the change took effect.

Examples of reportable significant changes include new or amended outsourcing arrangements, changes to third-party service provider relationships, material technology changes, geographic expansions, new products or market segments, changes in participation in payment systems, and material changes to organizational structure or staffing levels.

It is important to note that the report must also include a complete inventory of incidents experienced during the year, including incidents that were not required to be reported to the Bank under the RPAA at the time they occurred.

PSPs must also identify any retail payment activities that the PSP began or ceased to perform during the reporting year.

4. Ubiquity and Interconnectedness Metrics

In this section, PSPs must provide quantitative metrics as it relates to end-user funds used by the Bank to assess a PSP’s footprint and interconnectedness within the Canadian payments ecosystem.

These metrics must capture transactions where the PSP performed a payment function directly or indirectly, and must be reported separately for all end-users and end-users in Canada, where applicable.

PSPs must also report the total number of distinct end-users served during the reporting year, including users receiving services directly and indirectly, and provide information on services performed for other registered PSPs.

Some key metrics that must be reported include:

Value of End-User Funds Held

  • The maximum Canadian Dollar (CAD) equivalent value of end-user funds held at any time during the year.
  • For each month, report the average daily value (in CAD) at month-end.
  • Both the total of all funds held, and a breakdown by currency held.

End-Users

  • Total number of distinct end-users, and
  • Number of users receiving direct vs. indirect services (via third-party PSPs).

Number and Value of Electronic Funds Transfers (EFTs)

  • Monthly Count and Total Value
    • Report the monthly count and total value of EFTs.
    • Values in CAD (as both a total of all currencies combined, and a breakdown by currency of the EFT).
  • Value by Payment Type
    • Report an estimate of the total value of EFTs by payment type as a share of total value.

PSP with a place of business in Canada must report values for end-users in Canada and end-users outside of Canada as separate amounts.

5. Financial Information

In this section, PSPs must report key financial information, including total revenue, operating expenses, and total equity. Financial information may be reported using the PSP’s fiscal year-end, whereas most other reporting elements must align with the calendar year.

6. Record-Keeping

In this section, PSPs must confirm whether they maintain records sufficient to demonstrate compliance with the RPAA and the Retail Payment Activities Regulations. PSPs must indicate whether record-keeping is complete, partially complete, or not in place, and should be prepared to support these responses if requested by the Bank.

Preparing for Report

The annual reporting form is available through PSP Connect as of February 2, 2026. We suggest that PSPs may begin gathering the needed information for submission at any time prior to the applicable deadline. To help make this a bit easier, Outlier has put together a spreadsheet that will help in compiling the needed information. Please note that this spreadsheet does not replace formal BoC guidance. The system does allow organizations to save and continue where you left off.

We’re Here To Help

If you would like assistance in understanding what has to be reported or if you need help with RPAA requirements in general, please get in touch.

VACI’s 2026 “Life Cycle of Dirty Money” Webinar Series

From January 8 to February 12, 2026, the Vancouver Anti-Corruption Institute (VACI) will host a six-part webinar series connecting leading voices on anti-money laundering investigations and enforcement.

Join Outlier‘s Amber Scott in Session 2’s discussion: Preventing Money Laundering.

Date and Time: January 15, 2026 | 9:00-10:00 AM

Canada & Australia Financial Crime Webinar Series

We’re proud to participate in a five-part webinar series on Financial Crime Investigations and Enforcement in Canada and Australia. The series brings together leading voices from Canada and Australia to explore today’s most pressing financial crime challenges.

Join Outlier’s Amber Scott in moderating the 4th session of the Canada & Australia Financial Crime Webinar Series on Due Diligence (Canada) on November 24.

4PM-5PM ET Online

Learn more and register here.

Industry Leaders Roundtable Session

This gathering provides a unique opportunity to discuss and network with executives and leaders in the AML industry, fostering meaningful dialogue in a confidential setting guided by the Chatham House Rule.

During the session, the new regulatory updates, key topics, and challenges faced by REs in the industry will be addressed. This discussion aims to bring together decision-makers and industry experts to foster collaboration, exchange insights, and explore solutions to pressing challenges.

Details & Registration: By invitation only; further details forthcoming

Return to Blog Listing