PROCESSING...

Anti-Money Laundering
Consulting Services & Strategies

0 Items - Total: $0.00 CAD

Osgoode Certificate in Regulatory Compliance & Legal Risk Management for Financial Institutions

Join the module 5 discussion on Technology and Industry Disruptors as part of The Osgoode Certificate in Regulatory Compliance & Legal Risk Management for Financial Institutions, offered by Osgoode Professional Development at York University. Specifically, in Part B: Bitcoin/Blockchain and Case Studies, Outlier‘s Amber Scott will explore how blockchain technology and cryptocurrencies are reshaping the financial services landscape and challenging traditional regulatory frameworks.

Overall, the session will examine the opportunities, risks, and compliance implications associated with digital assets, decentralized technologies, and emerging business models.

For more information and to register, click here.

Infonex – Financial Services Regulation 2026 (Virtual)

Canada’s anti-money laundering landscape is undergoing its most significant transformation in years, and compliance professionals need to be ready.

Outlier’s Co-Founder & CEO, David Vijan, will join industry leaders at Infonex’s Financial Services Regulation 2026 conference to unpack the sweeping changes brought by Bill C-12 — the Strengthening Canada’s Immigration System and Borders Act — which received Royal Assent on March 26, 2026. The legislation dramatically raises the stakes for AML compliance, increasing administrative monetary penalties by up to 40 times current levels, expanding mandatory compliance agreements with FINTRAC, and broadening registration requirements to all reporting entities under the PCMLTFA.

David will also address the Government of Canada’s plans to establish a new Financial Crimes Agency — designed to serve as Canada’s lead enforcement authority on money laundering, organized crime, and online financial fraud — and what it means for financial institutions preparing for a new era of oversight.

Attendees will leave with a clearer picture of what these legislative and structural changes mean in practice, and how organizations can strengthen their AML programs to meet rising regulatory expectations.

For more information and to register, click here.

 

RPAA Annual Reporting – Reminder and Key Requirements

Background

Under the RPAA and the Retail Payment Activities Regulations (RPAR), Payment service providers (PSPs) must submit an annual report through the Bank of Canada’s (BoC) online portal using the prescribed reporting form. Reports must be filed annually by March 31 and must cover retail payment activities conducted during the prior calendar year.

Who Must Comply

All PSPs that are on the registration list with BoC must complete the annual report. For clarity, BoC has established the following deadlines:

  • PSPs registered before March 9, 2026, must submit their report by March 31, 2026.
  • PSPs registered between March 9 and March 30, 2026, have until April 28, 2026.

PSPs on the application list as of March 31, 2026, are not required to file a report for the 2025 year and will report in 2026.

The annual report is now available through PSP Connect. It includes mandatory sections and does not permit structural or formatting changes. It is set up similarly to what PSPs saw as part of registration. All required fields must be completed, and any omissions must be explained in accordance with BoC guidance.

What to Report

The following are the reporting elements of the annual report.

1. Operational Risk and Incident Management

In this section, PSPs must provide information on the governance, design, and effectiveness of their operational risk management and incident response frameworks. This includes confirming whether the framework, and any material updates to it, were approved during the reporting year by the senior officer.

In this section, PSPs must identify the operational risk categories monitored during the year and must outline what protective and detective measures were in place. Importantly, this action requires PSPs to provide quantitative staffing and resourcing information.

PSPs must also explain how operational risks arising from third-party service providers and agents or mandataries are managed. PSPs must also indicate whether agreements with third-party service providers were entered into, amended, extended, or renewed. Where agents or mandataries are used, PSPs are expected to confirm that responsibilities are clearly defined, operational risk criteria are established, and assessments are performed to evaluate whether those criteria are met.

Some key requirements for this section are:

  • Did the PSP classify assets and business processes by sensitivity and criticality?
  • Were sufficient human and financial resources available to implement and maintain the framework?
  • Did the framework set out operational reliability objectives, targets, and indicators?
  • Which measures were in place to mitigate technology risks and protect assets and processes?
  • Did the framework include incident response and recovery plans, including third-party incidents?
  • Which elements were included in the incident response plan?

2. Safeguarding of End-User Funds

In this section, PSPs that perform the payment function of holding funds on behalf of end-users must identify whether they safeguard funds through a trust account or through an account supported by insurance or a guarantee, and whether the safeguarding method changed during the reporting year.

PSPs must report whether end-user funds are placed into a safeguarding account upon receipt and, where processing constraints exist, whether funds are placed into the safeguarding account by the next business day. PSPs must identify whether safeguarding accounts are held with Canadian or foreign financial institutions and, where applicable, identify those institutions and their regulators.

PSPs must describe the liquidity approach used to ensure end-users have reliable access to their funds and outline the procedures in place for returning those funds in the event of the PSP’s insolvency.

Some key requirements for this section relate to shortfall reporting. PSPs must report instances during the reporting year where safeguarded funds were insufficient, including:

  • the date the shortfall occurred and the date it was resolved,
  • the maximum daily shortfall amount (in CAD),
  • the root cause (selected from prescribed categories), and
  • the measures taken to prevent recurrence.

3. Significant Changes and Incidents

In this section, PSPs must identify all significant changes that occurred during the reporting year. A change is considered significant where it could reasonably be expected to materially affect operational risk or the safeguarding of end-user funds. The annual report requires each change to be reported separately, including the month and year in which the change took effect.

Examples of reportable significant changes include new or amended outsourcing arrangements, changes to third-party service provider relationships, material technology changes, geographic expansions, new products or market segments, changes in participation in payment systems, and material changes to organizational structure or staffing levels.

It is important to note that the report must also include a complete inventory of incidents experienced during the year, including incidents that were not required to be reported to the Bank under the RPAA at the time they occurred.

PSPs must also identify any retail payment activities that the PSP began or ceased to perform during the reporting year.

4. Ubiquity and Interconnectedness Metrics

In this section, PSPs must provide quantitative metrics as it relates to end-user funds used by the Bank to assess a PSP’s footprint and interconnectedness within the Canadian payments ecosystem.

These metrics must capture transactions where the PSP performed a payment function directly or indirectly, and must be reported separately for all end-users and end-users in Canada, where applicable.

PSPs must also report the total number of distinct end-users served during the reporting year, including users receiving services directly and indirectly, and provide information on services performed for other registered PSPs.

Some key metrics that must be reported include:

Value of End-User Funds Held

  • The maximum Canadian Dollar (CAD) equivalent value of end-user funds held at any time during the year.
  • For each month, report the average daily value (in CAD) at month-end.
  • Both the total of all funds held, and a breakdown by currency held.

End-Users

  • Total number of distinct end-users, and
  • Number of users receiving direct vs. indirect services (via third-party PSPs).

Number and Value of Electronic Funds Transfers (EFTs)

  • Monthly Count and Total Value
    • Report the monthly count and total value of EFTs.
    • Values in CAD (as both a total of all currencies combined, and a breakdown by currency of the EFT).
  • Value by Payment Type
    • Report an estimate of the total value of EFTs by payment type as a share of total value.

PSP with a place of business in Canada must report values for end-users in Canada and end-users outside of Canada as separate amounts.

5. Financial Information

In this section, PSPs must report key financial information, including total revenue, operating expenses, and total equity. Financial information may be reported using the PSP’s fiscal year-end, whereas most other reporting elements must align with the calendar year.

6. Record-Keeping

In this section, PSPs must confirm whether they maintain records sufficient to demonstrate compliance with the RPAA and the Retail Payment Activities Regulations. PSPs must indicate whether record-keeping is complete, partially complete, or not in place, and should be prepared to support these responses if requested by the Bank.

Preparing for Report

The annual reporting form is available through PSP Connect as of February 2, 2026. We suggest that PSPs may begin gathering the needed information for submission at any time prior to the applicable deadline. To help make this a bit easier, Outlier has put together a spreadsheet that will help in compiling the needed information. Please note that this spreadsheet does not replace formal BoC guidance. The system does allow organizations to save and continue where you left off.

We’re Here To Help

If you would like assistance in understanding what has to be reported or if you need help with RPAA requirements in general, please get in touch.

DIACC Executive Plenary

Join Outlier’s David Vijan at the DIACC Executive Planery on November 6th, 2025.

The following topics will be explored during the panel discussion on “The Digital Trust Landscape: Open Banking & Client Identity Verification”:

  • Consumer-Directed Finance Framework in Canada
  • Regulatory landscape (FINTRAC, PIPEDA, provincial requirements)
  • Current state of identity verification in lending decisions

Panel Details:

  • November 6, 2025
  • 1:30PM-2:15pm ET

Industry Leaders Roundtable Session

This gathering provides a unique opportunity to discuss and network with executives and leaders in the AML industry, fostering meaningful dialogue in a confidential setting guided by the Chatham House Rule.

During the session, the new regulatory updates, key topics, and challenges faced by REs in the industry will be addressed. This discussion aims to bring together decision-makers and industry experts to foster collaboration, exchange insights, and explore solutions to pressing challenges.

Details & Registration: By invitation only; further details forthcoming

New Beneficial Ownership Discrepancy Reporting

Effective October 1, 2025, Canadian anti-money laundering (AML) reporting entities regulated by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) are required to report to Corporations Canada any material discrepancies identified between the beneficial ownership information that they have obtained and that is listed in Corporations Canada’s database.

Background

This requirement was introduced to enhance the reliability of beneficial ownership information available to authorities and the public, and to reduce the opportunities for misuse of Canadian corporate structures in money laundering, tax evasion, and sanctions avoidance schemes. Since the usefulness of the beneficial ownership information depends on the accuracy of the information, amendments under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) now will require reporting entities to flag material discrepancies between the information provided by a corporation incorporated under the Canada Business Corporations Act (CBCA) and what is recorded in the registry, thereby supporting Corporations Canada in maintaining an accurate database.

A “material discrepancy” exists where beneficial ownership information collected by a reporting entity substantively contradicts what is publicly disclosed. While the regulations give limited guidance, missing beneficial owners are considered material, while minor typographical errors are not. Currently, the definition of “material” remains imprecise, which may create some uncertainty for compliance teams.

Who Must Comply

The requirement applies to reporting entities who have the existing obligation to take reasonable measures to confirm the accuracy of beneficial ownership information when they first obtain it and in the course of conducting ongoing monitoring of their business relationships.

Discrepancy reporting applies only to CBCA corporations that are active on the Corporations Canada registry.

When to Report

Reporting entities are required to report a material discrepancy to Corporations Canada within 30 days after the day on which it is identified when the following criteria are met:

  • A client is an active CBCA corporation; and
  • The reporting entity determines that the corporation is high-risk for money laundering, terrorist financing, or sanctions evasion; and 
  • When there is a material discrepancy in beneficial ownership information that is not resolved within 30 days. Note there is no requirement to address the material discrepancy directly  with the customer. 

In these cases, reporting entities must check the Corporations Canada registry when a high-risk relationship is first identified and continue to check during ongoing monitoring of that high-risk business relationship.

If a previously reported discrepancy is identified again (i.e., during the course of ongoing monitoring) and it has not been resolved, it must be reported again. If there are other issues related to corporate status or registry info (not beneficial ownership information), this information can still be reported to Corporations Canada, but it must be done so separately. Voluntary reporting is permitted if the client is considered low-risk, but discrepancies are still found.

Reporting Steps

Reports are submitted through Corporations Canada’s online portal (accessed through the registry). The process is as follows:

  1. Ensure your reporting entity is registered for FINTRAC Web Reporting (FWR), and that the individual completing the reporting has an active My ISED account with Corporations Canada.
  2. Search the corporation on the Corporations Canada website to confirm it is an active CBCA corporation.
  3. While in Corporations Canada’s online portal, from the page connected to the corporation about which the discrepancy is being reported, select “Report an Issue” (currently a link at the bottom right of the page). This will prompt a My ISED login.
  4. Complete the discrepancy form with:
    • Reporting entity details (legal name, RE number, location, compliance contact/email). This information will auto-populate after the first report. 
    • Corporation details (name and incorporation number for the company you are reporting on).
    • Selecting the reason for reporting a discrepancy (reporting as required under PCMLTFA or voluntary).
    • Discrepancy details (nature of inconsistency, date identified).
  5. Review the information for accuracy and submit the report.
  6. A confirmation screen will appear, including a reference number 
  7. Corporations Canada will validate the report and issue an acknowledgment within 10 business days.
  8. Keep a copy of the acknowledgement as evidence of the completed discrepancy reporting.
  9. If the discrepancy has not been resolved by the next time you complete periodic monitoring for the entity, the process is repeated.

For more detailed steps on reporting, you may refer to the guidance on submitting a beneficial ownership discrepancy report or the following Corporations Canada demo video, which together provide a comprehensive overview.

 

Note that inaccurate or incomplete reporting entity information will result in an invalid Beneficial Ownership discrepancy report. Amendments to submitted reports are currently not possible, and a new report will have to be submitted. 

Reporting entities must retain the report acknowledgment and other supporting documentation as evidence of meeting obligations. 

We’re Here To Help

If you would like assistance in understanding what these changes mean to your business, or if you need help updating your compliance program and processes, please get in touch.

Stronger Together

Opening remarks from Outlier Compliance Group Co-Founder and Chairperson Amber D. Scott at TCAE 2025 Toronto Compliance & AML Conference

Many of us remember exactly where we were on this day 24 years ago. 

Imagine this scenario: I was a new compliance analyst at Manulife, having started my first role after university just a month before in the Waterloo head office. I had been at my desk since 7 am when a colleague, her face streaked with tears, came by to tell our team to assemble for instructions in one of the conference rooms. There was little information, but what was known was devastating; America was under attack, on home soil. 

Financial markets closed. Staff were sent home to await further instructions. When I went to my desk to pick up my handbag, my phone was ringing and I answered. It was a colleague in Toronto with mobility issues, who was not able to navigate the crowds at Union Station. So she had gone back to the office, which was now mostly empty, to wait, and she was terrified. We talked for two hours, until some of the crowds cleared.

While we were on the phone, my colleague and I would set our physical handset phones aside, and walk over to nearby meeting rooms to see if there were any updates on the news on the TVs there. It was 2001 – we couldn’t just Google it.

So much has changed since then. I think it’s fair to say that at the time, the idea of compliance was academically interesting, but if you asked me what I did – or why it mattered – neither money laundering, nor counter terrorism would have been top of mind. 

But some things strike me as being eerily similar – we talked to each other that day about what was happening and what it meant. In the days that followed, the most common question asked was what can we do to help? In the months and years that followed, how do we make sure that this doesn’t happen again? We refused to be paralyzed by fear, and sought to build more resilient systems, even if these were sometimes inconvenient.

Today, while I have many more sources of information at my fingertips, I am still very reliant on people in my network when I need to understand something at a deep level. While I don’t have to put down a handset and go to the meeting room next door to see what’s on the news, I am every bit as reliant on colleagues and contacts to parse information, understand implications, and find truth. 

Finding truth, in my estimation, is one of the greatest challenges of the modern era. The importance of truth cannot be overstated at a time when we are under continuous attack, pummeled with misinformation and disinformation, on a seemingly unending basis, from every possible direction, via every possible channel. On that score, I owe a huge debt to some of the folks in the room today, who have been unerring sources of insight, and of truth.

This is not an indictment of my own skills or abilities, but a call to the importance of communities, and knowledge sharing. Any one of us can be strong on our own, but no one can achieve a true level of badassery without community.

It is fitting then, that I am standing on this stage today with Souzan Ismaili, because no one builds community better than she does. Souzan is tireless in her quest to bring people together, to educate, and to create connections. 

I don’t think that the importance of this work can be understated – but this is not just Souzan’s work. This is a call to action to every person here today, to build community, to find your sources of truth, and to be that Northstar for your colleagues when you can. It won’t always be easy, in fact, sometimes it will be hard – but we will always be stronger together.

Outlier Compliance Group welcomes Maria Shamou!

The Outlier Compliance Group team is excited to welcome our newest member, Maria Shamou, as our administrative ninja.
Maria brings broad compliance knowledge complemented by over eight years of comprehensive customer service experience, paired with a strong foundation in administrative support and a strong interest in compliance along with a background in administrative support. She earned a Bachelor’s degree in Business Administration, and later completed a post-graduate program in Financial Services Compliance Administration at Seneca College. Through this program, she expanded her knowledge in anti-money laundering (AML) administration, risk management, privacy management, and financial services product knowledge. Her interest in financial services products led her to complete the Canadian Securities Course (CSC).

Maria is proud to support Outlier’s mission statement: “Good compliance is good business.”

 

Check Your FINTRAC MSB Registration

Divya BhakthaAre you a money services business (MSB) that serves clients in Canada? Have you checked your MSB registration lately? If not, there’s no time like the present, and you can do so here.

What’s Required?

There have been some changes to the process for updating registration information with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) that may not be immediately apparent, and further changes are forthcoming. As a reminder, when an MSBs’ information changes, including products, locations, key personnel such as the Compliance Officer, ownership, or agents, that information must be updated with FINTRAC within 30 days. MSB registration must also be renewed prior to the registration’s expiry date. 

MSB Registration Changes 

When your MSB registration information changes, the first step is to complete the change form on FINTRAC’s website and remember to submit it within 30 days of the change. This form has a number of checkboxes that must be selected, depending on the specific updates that are being requested, as well as a freeform field that can be used to provide additional information (but be brief, there is a 100-character limit). There is also an option to download and save a copy of the completed form, which should be kept as part of your AML records. 

Once FINTRAC has received the form, they will reach out, usually to the email address provided in the form, with next steps. The most common next step is currently for FINTRAC to send a PDF form using Canada Post Connect (a secure portal for messages and document sharing), which must be completed and returned within a specific timeframe. As with the online registration form, you should save a copy of your completed change form.

MSB Registration Renewals

Before your MSB registration expires, complete the renewal form on FINTRAC’s website. Remember, your MSB registration is valid for two years, and you need to renew it before it expires. This form is different from the change form, but does have a checkbox that must be selected if there are also changes to MSB registration information, as well as a freeform field that can be used to provide additional information (remember to be brief, as there is a 100-character limit). There is also an option to download and save a copy of the completed form, which should be kept as part of your AML records. You can also use the save a copy function to download a form in progress, which can be re-uploaded and completed later.

Once FINTRAC has received the form, they will reach out, usually to the email address provided in the form, with next steps. If there are changes to MSB registration information, the most common next step is currently for FINTRAC to send a PDF form using Canada Post Connect (a secure portal for messages and document sharing), which must be completed and returned within a specific timeframe. We recommend whitelisting @fintrac-canafe.gc.ca and @canadapost-postescanada.ca addresses, so that they don’t get caught in your spam filters.

In either of the above scenarios, we recommend that you always download and keep a copy of the registration details, which include the time and date when you submitted the document, so you have proof if required at a later date.

Does FINTRAC Send Notices to Expiring MSBs?

Prior to last year, MSBs received email reminders from FINTRAC when their registration was expiring, but it doesn’t seem that this is the case. You should not expect a notification from FINTRAC when your MSB registration is set to expire. We recommend setting a reminder in your calendar for 30 days before the registration expires, to make sure the form is submitted on time.

Need a hand?

Whether you need assistance with your FINTRAC registration or AML compliance in general, you can contact us here or by email at info@outliercanada.com.

We Turn 12!

Green foil balloons forming the number 12 with gold confetti on a light background, celebrating a 12-year anniversary.Today marks another milestone for us – 12 years since Outlier Compliance Group was founded.

What began as a bold and novel idea, building a consulting firm made up exclusively of seasoned compliance professionals with deep in-house experience, has grown into a thriving, trusted partner for clients navigating Canada’s ever-changing regulatory landscape.

Our name, inspired by Malcolm Gladwell’s “Outliers, the Story of Success” which espoused the notion that to be truly proficient in a skill, 10,000 hours of practice is required. That was the bar that was set, met, and most often exceeded by every compliance professional that joined our team over the years.

Over the years, we’ve grown, evolved, but have stayed true to our roots. We’ve learned that success comes from surrounding ourselves with exceptional people, from listening closely to our clients, and from being willing to adapt in the face of change. We’ve discovered the value of curiosity when navigating complexity, and the power of collaboration when tackling the most challenging problems.

Through it all, our mission has remained the same “good compliance is good business”. It’s the principle that guides our work, shapes our advice, and underpins every solution we deliver.

As the Canadian regulatory environment becomes increasingly complex, our mission and our learnings will play to our continued success and growth as we continue to provide top tier compliance and risk management services. 

To our amazing team, past, present and future, thank you for your passion, expertise and resilience. To our clients, partners and industry peers, thank you for your trust and collaboration. Lastly, but by no means least, a special thank you to our CEO, David Vijan, and our Chairperson, Amber D. Scott, for keeping us on our toes and steering the ship with vision and purpose. 

Here’s to 12 years of achievement and to the future.

Return to Blog Listing