Written with Heidi Unrau
In the past two years, 13 real estate brokerages faced a total of $1,041,936 in administrative monetary penalties (AMP) from FINTRAC, the federal agency that regulates anti-financial crime compliance and analyzes financial intelligence in Canada. That works out to an average fine of $80,148 per brokerage, with the single largest AMP reaching approximately $150,000.
Real estate brokers, sales representatives, and developers have legal responsibilities under Canada’s anti-money laundering rules prescribed by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). These rules are designed to prevent, detect and deter real estate transactions from being used to hide proceeds of crime, to fund terrorist activity, or evade sanctions.
Yet too many brokerages still treat anti-money laundering (AML) compliance as a cost centre instead of a core risk management function. And what we’re seeing is a lot of “just-in-time compliance” behaviour, resulting in major deficiencies with up to six-figure penalties.
Compliance within the real estate industry has never been as important as it is right now. Not only is the regulator penalizing companies for compliance failures, but the monetary penalties are now 40 times higher than they were before. That emphasizes the level of effort that needs to be paid to your compliance program before FINTRAC calls.
Why is FINTRAC Cracking Down on Real Estate?
Real estate is an attractive target for money laundering because one deal can move a significant amount of illicit funds. Real estate transactions are especially vulnerable because they are used at the integration stage of money laundering, after the funds have already moved through accounts, businesses, third parties, family members, or international transfers to obscure the origin.
By the time those funds reach real estate, the warning signs are much harder to identify, but the compliance expectations do not change. Given the size, complexity, and risk profile of real estate transactions, you need to apply greater scrutiny to the people, funds, and circumstances behind each deal.
Weak controls around identification, record keeping, training, and suspicious transaction reporting expose your business to unnecessary financial and reputational risk.
The Problem With ‘Just-in-Time Compliance’
Just-in-time compliance happens when you ignore your AML compliance obligations throughout the year, or worse, a longer period of time, then scramble to fix everything after FINTRAC makes contact. By then, it’s too late.
Once FINTRAC calls, the exam has already started. Everything done after that point becomes last-minute compliance. It’s better than doing nothing, but it doesn’t prove you had those controls in place during the period FINTRAC is reviewing.
The regulator is looking at whether you had a functioning program in place during the period under review. If your procedures, training, records, and review processes were missing or outdated during that period, fixing them after FINTRAC contacts you will not undo the deficiency.
A FINTRAC examination can disrupt regular business operations if you’re scrambling to track down missing records, update stale policies, complete overdue training, or fix program gaps while still trying to serve clients and close deals.
FINTRAC publishes all administrative monetary penalties on its website. A public enforcement action can damage trust with clients, lenders, referral partners and other stakeholders, causing serious reputational harm that can negatively affect your bottom line.
That’s exactly why AML compliance has to be treated as an ongoing business function. You already understand this concept in other areas of your business. You do not wait until tax season to create a full year of bookkeeping from scratch. You do not wait until a lawsuit to decide if your contracts were properly drafted. AML compliance works the same way. The work needs to be done before the regulator asks for proof.
Start With Your Baseline AML Obligations
Trying to build a perfect AML program right out of the gate can be overwhelming. In reality, you should start by meeting the baseline requirements. That means ensuring your real estate business has the fundamentals in place, such as written policies and procedures, a designated Compliance Officer, training, risk assessment, record keeping, suspicious transaction escalation and reporting processes, and the required two-year compliance effectiveness review.
Beyond these baseline requirements, FINTRAC states you must implement a compliance program that can effectively verify the identity of the persons and entities involved in transactions, conduct ongoing monitoring when a business relationship is formed, obtain and take reasonable measures to confirm beneficial ownership information for entities, make third-party determinations when required, and take reasonable measures to determine whether clients are politically exposed persons or heads of international organizations.
Your policies and procedures should clearly explain what your business is supposed to do. Risk assessments identify where your business is most exposed. Your training ensures staff and agents understand their obligations. Your records prove what happened. And your suspicious transactions process shows how concerns are escalated, reviewed, documented, and reported.
Why The Two-Year Effectiveness Review Is Critical
The two-year effectiveness review is especially important because it reveals where your program is working and where it’s weak. We recommend starting here because it provides a look at your AML compliance program as a whole, identifies the biggest problem areas, and prioritizes the highest risk gaps. It is very important that the person completing your review has adequate experience and understands the industry, as well as your business. This should not be a “check the box” compliance exercise.
If you have not yet completed an effectiveness review, that should be the top priority.
Where Real Estate Entities Commonly Fail
Many real estate compliance failures are basic program deficiencies that are entirely preventable. The most serious gaps usually fall into three main areas: not having an AML program at all, failing to complete the required two-year effectiveness review, and unreported suspicious transactions. The regulator can, and does, penalize failures in the compliance process itself, including missed reporting, poor documentation, and weak program controls.
It is complex, but it is not impossible. If your written program does not reflect how your brokerage actually operates, fix it. If your training is outdated, that needs attention. If your team is unsure what to collect, when to escalate concerns, or when a report may be required, those deficiencies should be fixed before FINTRAC identifies them for you.
No AML Program At All
The most common failure is having nothing in place. That means no written policies and procedures, no designated compliance officer, no training, and no clear internal process for meeting AML obligations.
These are the foundation of a compliance program. Without them, your business has no consistent way to identify risk, collect required information, train agents, escalate concerns, keep records, or prove to the regulator that the business is taking its obligations seriously.
The Two-Year Effectiveness Review Not Done
Another major gap is the two-year effectiveness review. It’s often skipped entirely, even though it is one of the most important tools you have to determine if your compliance program is actually working. Without it, you may not know where your business is exposed until FINTRAC identifies the problem first.
Missed Suspicious Transaction Reporting
A single unreported suspicious transaction can result in a financial penalty well over $100,000. Yet, this remains one of the most common compliance failures.
FINTRAC has given reporting entities a laundry list of suspicious indicators. And that laundry list is what they’re using to assess your transactions. If a transaction presents red flags, it needs to move through a clear internal process so you can show the regulator what the final decision was. Specifically, that there were reasonable grounds to suspect (RGS) the transaction was related to financial crime and reported as a suspicious transaction to FINTRAC, or there was not RGS and the rationale is clearly documented.
‘Suspicious’ Does Not Automatically Mean a Dead Deal
A common point of confusion is the distinction between a high-risk transaction, a suspicious transaction, and a transaction you cannot legally participate in.
A transaction can be high risk without being illegal. A client might have foreign funds, a complex ownership structure, have a holding company involved, or have a third party helping with the purchase. Those details can have legitimate explanations. They also require more questions, documentation, and scrutiny.
A transaction is suspicious when you have reasonable grounds to suspect, which is a lower threshold than to believe, that it is linked to criminal activity. You do not need proof, but you do need to explain why you feel it is suspicious based on facts, context, indicators, what you know about the client, and the nature of the transaction.
You can still proceed with high risk and suspicious transactions. Your obligation is to assess the concern, document what happened, escalate internally, and report to FINTRAC when required.
However, if a client is asking you to help them break the law or evade sanctions, then you absolutely cannot proceed with the transaction.
Next Steps
For real estate brokerages, compliance is no longer something to address only when an exam is looming, the biggest risk is waiting too long.
If your real estate business does not have an AML compliance program, you need to implement one as soon as possible. Get support from a qualified compliance provider that can help create policies and procedures customized to the specific type of real estate business you conduct. Generic compliance templates are no longer effective because they are not tailored to align with your specific day-to-day operations.
If you have an AML compliance program, but have not yet completed your two-year effectiveness review, start there. It will tell you where your program is working and where it’s not. Then use that information to prioritize what needs to be fixed first.
Need an effectiveness review or support building, reviewing, or updating your AML compliance program? Contact Outlier to get clear, practical guidance on your obligations and next steps.







