PROCESSING...

Anti-Money Laundering
Consulting Services & Strategies

0 Items - Total: $0.00 CAD

Your Real Estate Business Can’t Afford ‘Just-in-Time Compliance’

Written with Heidi Unrau

 

In the past two years, 13 real estate brokerages faced a total of $1,041,936 in administrative monetary penalties (AMP) from FINTRAC, the federal agency that regulates anti-financial crime compliance and analyzes financial intelligence in Canada. That works out to an average fine of $80,148 per brokerage, with the single largest AMP reaching approximately $150,000. 

Real estate brokers, sales representatives, and developers have legal responsibilities under Canada’s anti-money laundering rules prescribed by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). These rules are designed to prevent, detect and deter real estate transactions from being used to hide proceeds of crime, to fund terrorist activity, or evade sanctions. 

Yet too many brokerages still treat anti-money laundering (AML) compliance as a cost centre instead of a core risk management function. And what we’re seeing is a lot of “just-in-time compliance” behaviour, resulting in major deficiencies with up to six-figure penalties.

Compliance within the real estate industry has never been as important as it is right now. Not only is the regulator penalizing companies for compliance failures, but the monetary penalties are now 40 times higher than they were before. That emphasizes the level of effort that needs to be paid to your compliance program before FINTRAC calls.

Why is FINTRAC Cracking Down on Real Estate?

Real estate is an attractive target for money laundering because one deal can move a significant amount of illicit funds. Real estate transactions are especially vulnerable because they are used at the integration stage of money laundering, after the funds have already moved through accounts, businesses, third parties, family members, or international transfers to obscure the origin. 

By the time those funds reach real estate, the warning signs are much harder to identify, but the compliance expectations do not change. Given the size, complexity, and risk profile of real estate transactions, you need to apply greater scrutiny to the people, funds, and circumstances behind each deal. 

Weak controls around identification, record keeping, training, and suspicious transaction reporting expose your business to unnecessary financial and reputational risk.

The Problem With ‘Just-in-Time Compliance’

Just-in-time compliance happens when you ignore your AML compliance obligations throughout the year, or worse, a longer period of time, then scramble to fix everything after FINTRAC makes contact. By then, it’s too late. 

Once FINTRAC calls, the exam has already started. Everything done after that point becomes last-minute compliance. It’s better than doing nothing, but it doesn’t prove you had those controls in place during the period FINTRAC is reviewing. 

The regulator is looking at whether you had a functioning program in place during the period under review. If your procedures, training, records, and review processes were missing or outdated during that period, fixing them after FINTRAC contacts you will not undo the deficiency.

A FINTRAC examination can disrupt regular business operations if you’re scrambling to track down missing records, update stale policies, complete overdue training, or fix program gaps while still trying to serve clients and close deals. 

FINTRAC publishes all administrative monetary penalties on its website. A public enforcement action can damage trust with clients, lenders, referral partners and other stakeholders, causing serious reputational harm that can negatively affect your bottom line. 

That’s exactly why AML compliance has to be treated as an ongoing business function. You already understand this concept in other areas of your business. You do not wait until tax season to create a full year of bookkeeping from scratch. You do not wait until a lawsuit to decide if your contracts were properly drafted. AML compliance works the same way. The work needs to be done before the regulator asks for proof. 

Start With Your Baseline AML Obligations

Trying to build a perfect AML program right out of the gate can be overwhelming. In reality, you should start by meeting the baseline requirements. That means ensuring your real estate business has the fundamentals in place, such as written policies and procedures, a designated Compliance Officer, training, risk assessment, record keeping, suspicious transaction escalation and reporting processes, and the required two-year compliance effectiveness review. 

Beyond these baseline requirements, FINTRAC states you must implement a compliance program that can effectively verify the identity of the persons and entities involved in transactions, conduct ongoing monitoring when a business relationship is formed, obtain and take reasonable measures to confirm beneficial ownership information for entities, make third-party determinations when required, and take reasonable measures to determine whether clients are politically exposed persons or heads of international organizations.

Your policies and procedures should clearly explain what your business is supposed to do. Risk assessments identify where your business is most exposed. Your training ensures staff and agents understand their obligations. Your records prove what happened. And your suspicious transactions process shows how concerns are escalated, reviewed, documented, and reported. 

Why The Two-Year Effectiveness Review Is Critical

The two-year effectiveness review is especially important because it reveals where your program is working and where it’s weak. We recommend starting here because it provides a look at your AML compliance program as a whole, identifies the biggest problem areas, and prioritizes the highest risk gaps. It is very important that the person completing your review has adequate experience and understands the industry, as well as your business. This should not be a “check the box” compliance exercise. 

If you have not yet completed an effectiveness review, that should be the top priority. 

Where Real Estate Entities Commonly Fail 

Many real estate compliance failures are basic program deficiencies that are entirely preventable. The most serious gaps usually fall into three main areas: not having an AML program at all, failing to complete the required two-year effectiveness review, and unreported suspicious transactions. The regulator can, and does, penalize failures in the compliance process itself, including missed reporting, poor documentation, and weak program controls.

It is complex, but it is not impossible. If your written program does not reflect how your brokerage actually operates, fix it. If your training is outdated, that needs attention. If your team is unsure what to collect, when to escalate concerns, or when a report may be required, those deficiencies should be fixed before FINTRAC identifies them for you.

No AML Program At All

The most common failure is having nothing in place. That means no written policies and procedures, no designated compliance officer, no training, and no clear internal process for meeting AML obligations. 

These are the foundation of a compliance program. Without them, your business has no consistent way to identify risk, collect required information, train agents, escalate concerns, keep records, or prove to the regulator that the business is taking its obligations seriously. 

The Two-Year Effectiveness Review Not Done

Another major gap is the two-year effectiveness review. It’s often skipped entirely, even though it is one of the most important tools you have to determine if your compliance program is actually working. Without it, you may not know where your business is exposed until FINTRAC identifies the problem first. 

Missed Suspicious Transaction Reporting

A single unreported suspicious transaction can result in a financial penalty well over $100,000. Yet, this remains one of the most common compliance failures. 

FINTRAC has given reporting entities a laundry list of suspicious indicators. And that laundry list is what they’re using to assess your transactions. If a transaction presents red flags, it needs to move through a clear internal process so you can show the regulator what the final decision was. Specifically, that there were reasonable grounds to suspect (RGS) the transaction was related to financial crime and reported as a suspicious transaction to FINTRAC, or there was not RGS and the rationale is clearly documented.  

‘Suspicious’ Does Not Automatically Mean a Dead Deal

A common point of confusion is the distinction between a high-risk transaction, a suspicious transaction, and a transaction you cannot legally participate in. 

A transaction can be high risk without being illegal. A client might have foreign funds, a complex ownership structure, have a holding company involved, or have a third party helping with the purchase. Those details can have legitimate explanations. They also require more questions, documentation, and scrutiny. 

A transaction is suspicious when you have reasonable grounds to suspect, which is a lower threshold than to believe, that it is linked to criminal activity. You do not need proof, but you do need to explain why you feel it is suspicious based on facts, context, indicators, what you know about the client, and the nature of the transaction. 

You can still proceed with high risk and suspicious transactions. Your obligation is to assess the concern, document what happened, escalate internally, and report to FINTRAC when required. 

However, if a client is asking you to help them break the law or evade sanctions, then you absolutely cannot proceed with the transaction. 

Next Steps

For real estate brokerages, compliance is no longer something to address only when an exam is looming, the biggest risk is waiting too long.

If your real estate business does not have an AML compliance program, you need to implement one as soon as possible. Get support from a qualified compliance provider that can help create policies and procedures customized to the specific type of real estate business you conduct. Generic compliance templates are no longer effective because they are not tailored to align with your specific day-to-day operations. 

If you have an AML compliance program, but have not yet completed your two-year effectiveness review, start there. It will tell you where your program is working and where it’s not. Then use that information to prioritize what needs to be fixed first. 

Need an effectiveness review or support building, reviewing, or updating your AML compliance program? Contact Outlier to get clear, practical guidance on your obligations and next steps.

Canadian MSB Association: 2026 Spring Conference

Explore the latest developments shaping the compliance landscape at CMSBA 2026. This year’s program features expert-led sessions covering key regulatory updates, emerging risks, and practical strategies for MSBs and financial professionals.

Topics will include recent amendments to the PCMLTFA and evolving FINTRAC reporting expectations, as well as guidance on RPAA and it’s associated regulations, and preparing for initial supervisory reviews. Furthermore, attendees will gain insights into reporting best practices, including STRs, LPEPRs, AMPs highlights, and common pitfalls to avoid.

The agenda will also dive into emerging fraud typologies, crypto-related misuse, scams, and cybercrime trends impacting the industry. Sessions on AI and automation in AML will showcase real-world applications across KYC, KYB, transaction monitoring, and remediation.

Join Amber Scott as a panelist at CMSBA 2026, exploring best practices for hiring a qualified Chief Anti-Money Laundering Officer (CAMLO). Also, don’t miss Divya Bhaktha in the discussion of compliance programs aimed at preventing issues leading to recent AMPs.

Register here.

New Beneficial Ownership Discrepancy Reporting

Effective October 1, 2025, Canadian anti-money laundering (AML) reporting entities regulated by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) are required to report to Corporations Canada any material discrepancies identified between the beneficial ownership information that they have obtained and that is listed in Corporations Canada’s database.

Background

This requirement was introduced to enhance the reliability of beneficial ownership information available to authorities and the public, and to reduce the opportunities for misuse of Canadian corporate structures in money laundering, tax evasion, and sanctions avoidance schemes. Since the usefulness of the beneficial ownership information depends on the accuracy of the information, amendments under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) now will require reporting entities to flag material discrepancies between the information provided by a corporation incorporated under the Canada Business Corporations Act (CBCA) and what is recorded in the registry, thereby supporting Corporations Canada in maintaining an accurate database.

A “material discrepancy” exists where beneficial ownership information collected by a reporting entity substantively contradicts what is publicly disclosed. While the regulations give limited guidance, missing beneficial owners are considered material, while minor typographical errors are not. Currently, the definition of “material” remains imprecise, which may create some uncertainty for compliance teams.

Who Must Comply

The requirement applies to reporting entities who have the existing obligation to take reasonable measures to confirm the accuracy of beneficial ownership information when they first obtain it and in the course of conducting ongoing monitoring of their business relationships.

Discrepancy reporting applies only to CBCA corporations that are active on the Corporations Canada registry.

When to Report

Reporting entities are required to report a material discrepancy to Corporations Canada within 30 days after the day on which it is identified when the following criteria are met:

  • A client is an active CBCA corporation; and
  • The reporting entity determines that the corporation is high-risk for money laundering, terrorist financing, or sanctions evasion; and 
  • When there is a material discrepancy in beneficial ownership information that is not resolved within 30 days. Note there is no requirement to address the material discrepancy directly  with the customer. 

In these cases, reporting entities must check the Corporations Canada registry when a high-risk relationship is first identified and continue to check during ongoing monitoring of that high-risk business relationship.

If a previously reported discrepancy is identified again (i.e., during the course of ongoing monitoring) and it has not been resolved, it must be reported again. If there are other issues related to corporate status or registry info (not beneficial ownership information), this information can still be reported to Corporations Canada, but it must be done so separately. Voluntary reporting is permitted if the client is considered low-risk, but discrepancies are still found.

Reporting Steps

Reports are submitted through Corporations Canada’s online portal (accessed through the registry). The process is as follows:

  1. Ensure your reporting entity is registered for FINTRAC Web Reporting (FWR), and that the individual completing the reporting has an active My ISED account with Corporations Canada.
  2. Search the corporation on the Corporations Canada website to confirm it is an active CBCA corporation.
  3. While in Corporations Canada’s online portal, from the page connected to the corporation about which the discrepancy is being reported, select “Report an Issue” (currently a link at the bottom right of the page). This will prompt a My ISED login.
  4. Complete the discrepancy form with:
    • Reporting entity details (legal name, RE number, location, compliance contact/email). This information will auto-populate after the first report. 
    • Corporation details (name and incorporation number for the company you are reporting on).
    • Selecting the reason for reporting a discrepancy (reporting as required under PCMLTFA or voluntary).
    • Discrepancy details (nature of inconsistency, date identified).
  5. Review the information for accuracy and submit the report.
  6. A confirmation screen will appear, including a reference number 
  7. Corporations Canada will validate the report and issue an acknowledgment within 10 business days.
  8. Keep a copy of the acknowledgement as evidence of the completed discrepancy reporting.
  9. If the discrepancy has not been resolved by the next time you complete periodic monitoring for the entity, the process is repeated.

For more detailed steps on reporting, you may refer to the guidance on submitting a beneficial ownership discrepancy report or the following Corporations Canada demo video, which together provide a comprehensive overview.

 

Note that inaccurate or incomplete reporting entity information will result in an invalid Beneficial Ownership discrepancy report. Amendments to submitted reports are currently not possible, and a new report will have to be submitted. 

Reporting entities must retain the report acknowledgment and other supporting documentation as evidence of meeting obligations. 

We’re Here To Help

If you would like assistance in understanding what these changes mean to your business, or if you need help updating your compliance program and processes, please get in touch.

CMSBA 2025 Fall Conference

The Canadian MSB Association 2025 Fall Conference brings together industry professionals from MSBs, payment service providers, fintech, armoured car services, regtech and more. Over two days, attendees will engage in sessions exploring:

  • Implementation of the March 2025 PCMLTFA amendments
  • RPAA supervision go-live and lessons learned so far
  • New reporting expectations for STRs, EFTRs, sanctions, and beneficial ownership
  • Operational risk frameworks and incident response under RPAA/R
  • Approaches to safeguarding end-user funds via trust, insurance, or guarantees
  • Challenges around financial access, de‑risking, and bank onboarding in the evolving landscape

Attendees can expect a mix of insights, best practices, and peer networking across both in-person and virtual formats. Join over 200+ professionals from across MSBs, fintech, regtech, armoured car services, and more.

Registration/More Info: Buy your ticket here

Identification Triggers for Factoring Companies

Background

We recently sought clarification from FINTRAC as it relates to identification requirements that Factoring Companies (Factors) must comply with.

Factors supply liquidity to a customer in exchange for the cash value of a certain amount of the customer’s accounts receivable (i.e. invoices) to be collected later by the factoring company. A factor is defined as a person or entity that is engaged in the business of factoring, with or without recourse against the assignor.

If you missed it, Factors became reporting entities under the PCMLTFA effective April 1, 2025. As a reporting entity, Factors must have in place a compliance program and comply with various requirements, including identification requirements.  Please refer to our previous blog post on Factors that outlines full requirements that factors must comply with.

Identification Requirements

Factors must confirm identification using prescribed methods for individuals and entities where they are required to keep a record as defined under section 24.14 of the

Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations.

Section 24.14 states a factor shall keep the following records in respect of every factoring agreement that it enters into:

(a) an information record in respect of the person or entity with whom it enters into the agreement;

 (b) if the information record is in respect of an entity, a record of the name, address and date of birth of every person who enters into the agreement on behalf of the entity and the nature of the person’s principal business or their occupation;

 (c) if the information record is in respect of a corporation, a copy of the part of official corporate records that contains any provision relating to the power to bind the corporation in respect of transactions with the factor;

 (d) a record of the financial capacity of the person or entity with which it enters into the agreement and the terms of the agreement;

 (e) for any payment it makes; and

 (f) a receipt of funds record in respect of every amount of $3,000 or more that it receives, unless the amount is received from a financial entity or public body or from a person who is acting on behalf of a client that is a financial entity or public body.

As it relates to the last record, funds may come from a party other than the factoring client (a third party) and in such instances it is not sufficient to rely on identification that would have been completed for the factoring client, but rather the third party would have to be identified.

Below is a response from FINTRAC:

Under the PCMLTFA, specifically section 24.14(f), a receipt of funds record must be kept for every amount of $3,000 or more, unless the funds are received from a financial entity, public body, or a person acting on behalf of such an entity.

In response to your question:
If funds are received from a party other than the identified factoring client, identification requirements may still apply depending on who that third party is.

If the third party is not:

    • a financial entity,
    • a public body, or
    • acting on behalf of one,

then yes, identification and a receipt of funds record would be required, even if the factoring client has already been identified. This is because the receipt of funds record pertains to who the funds are actually received from, not just who the factoring agreement is with.

Identification of the factoring client alone is not sufficient if funds are received from another party who does not fall under the exemptions in s. 24.14(f). The source of funds must be identified and recorded accordingly.

The factoring company must take reasonable measures to identify the sender, document those efforts, and keep a receipt of funds record.

While this may prove to be challenging in some instances, demonstrating that reasonable measures were taken becomes critical.

We’re Here To Help

If you would like assistance in understanding what this mean to your business, or if you need help in creating or updating your compliance program and processes, please get in touch.

Securities Dealers See Rising FINTRAC Penalties

We’re seeing FINTRAC ramp up Administrative Monetary Penalties against all sectors, however, for securities dealers we’re starting to see some heavy hits, something we haven’t seen before, signaling a graduated approach to compliance assessments by FINTRAC.

On July 3, 2025, FINTRAC announced an Administrative Monetary Penalty of $544,500 against an investment dealer headquartered in Vancouver, British Columbia. Additionally, on February 13, 2025, FINTRAC announced an Administrative Monetary Penalty of $66,000 against, a Wealth Management Securities Dealer in Ontario.

Securities dealers must fulfill specific obligations as required by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated Regulations, to help combat money laundering and terrorist activity financing in Canada. As defined under the PCMLTFA, a securities dealer means a person or entity authorized under provincial legislation to engage in the business of dealing in securities or any other financial instruments or to provide portfolio management or investment advising services.

FINTRAC has the legislative authority to issue administrative monetary penalties (AMPs) to reporting entities that are found to be non-compliant with the PCMLTFA and associated Regulations. For more information, see Penalties for non-compliance.

Between the two notices, it was found that following compliance examinations, the following failures were found, which resulted in the AMPs:

  • Failure to develop and apply written compliance policies and procedures that are kept up to date; and, in the case of an entity, are approved by a senior officer. Specifically, the firm did not sufficiently develop and document its compliance policies and procedures in relation to know your client and record keeping requirements.
  • Failure to assess and document the risk of a money laundering or terrorist financing offence, taking into consideration prescribed factors. Specifically, the firm’s risk assessment was incomplete, as it did not clearly outline the risks associated with its clients and did not contain assessment of all the required categories. In addition, the risk assessment did not document an adequate methodology for the assessment of its money laundering and terrorist financing risks.
  • Failure to institute and document the prescribed review of its policies and procedures, risk assessment and training program. Specifically, the scope of a review did not cover the firm’s risk assessment. Additionally, the review did not specify how the organization ensured that its compliance program was tested for effectiveness.
  • Failure to submit suspicious transaction reports where there were reasonable grounds to suspect that transactions or attempted transactions were related to a money laundering or terrorist activity financing offence.
  • Failure to take the prescribed special measures for high risk.

Of all the findings, the ones that netted the highest AMP were related specifically to:

  • Failure to submit suspicious transaction reports where there were reasonable grounds to suspect that transactions or attempted transactions were related to a money laundering or terrorist activity financing offence.
  • Failure to take the prescribed special measures for high risk.

Failures in suspicious transaction reporting continue to be a big focus for FINTRAC and a trend with the larger value AMPs that we’ve been seeing.

Securities dealers are responsible for the following requirements under the PCMLTFA and associated Regulations:

  1. Compliance program:
    1. Appoint a compliance officer who is responsible for implementing the program. The Compliance Officer must always have access to management and the authority to carry out their duties.
    2. Develop and apply written compliance policies and procedures that are kept up to date and, in the case of an entity, are approved by a senior officer. Policies and procedures must be detailed and reflect the reporting entities business model.
    3. Conduct a risk assessment of your business to assess and document the risk of a money laundering or terrorist activity financing offence occurring in the course of your activities. The categories that must be assessed are outlined in guidance.
    4. Develop and maintain a written, ongoing compliance training program for your employees, agents or mandataries, or other authorized persons.
    5. Institute and document a plan for the ongoing compliance training program and deliver the training (training plan).
    6. Institute and document a plan for a review of the compliance program for the purpose of testing its effectiveness, and carry out this review every two years at a minimum (two-year effectiveness review). The review must test all parts of your compliance program as well as operations.
  2. Know your client:
    1. verifying client identity,
    2. politically exposed persons, heads of international organizations, their family members and close associates, beneficial ownership, and
    3. third party determination.
  3. Transaction reporting:
    1. Suspicious Transaction reporting
    2. Listed Person or Entity Property Reports
    3. Large Cash Transactions reporting
    4. Large Virtual Currency Transaction reporting; and
    5. Reporting suspected sanctions evasion.
  4. Record keeping;
  5. Foreign branches, foreign subsidiaries and affiliates; and
  6. Ministerial directives

We’re Here To Help

If you need help in creating or updating your compliance program and processes, are due for a Compliance Effectiveness Review, or have general questions on your compliance obligations,  please get in touch.

What to Expect When FINTRAC Comes Knocking

Written with Heidi Unrau

FINTRAC’s New Assessment Approach – It’s Not Just Exams Anymore

Every request, meeting, form, or call with the Financial Transaction and Reports Analysis Centre of Canada (FINTRAC), Canada’s anti-money laundering (AML) regulator and financial intelligence unit (FIU), is a potential assessment activity. If your business is subject to the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), the regulator could contact you at any time. In 2025, FINTRAC significantly expanded and diversified its compliance assessment toolkit.

FINTRAC’s assessment activities are not limited to full-blown compliance examinations, and the regulator is increasingly using other assessment tools. These include a wider range of formal and informal touchpoints, each of which can carry consequences and should be taken seriously. Here’s what you need to know to prepare, respond, and stay one step ahead when FINTRAC contacts you.

Yes, These Are All Assessment Activities

Many organizations are surprised to learn that not every FINTRAC interaction is labelled as an “examination,” although a range of activities are used to assess FINTRAC reporting entities. While some of these activities may be more informal than examinations, they are not unimportant.

In 2025, common FINTRAC assessment activities include, but are not limited to:

A woman peeking out from behind a stack of folders on a desk.

Data Hide and Seek

  • Information Requests
  • Supervisory Risk Assessment Questionnaires (SRAQs)
  • Compliance Self-Attestations
  • Monitoring Meetings
  • Action Plans
  • Examinations

Each of these activities serves as an opportunity for FINTRAC to understand and evaluate how well your organization is meeting its AML compliance obligations. Responding late, incorrectly, or incompletely can impact your risk score, trigger follow-up activities including examinations, or even result in penalties.

Information Requests

FINTRAC can request a wide range of information from reporting entities related to AML compliance. Where no personal information (PI) is being requested, these requests may be delivered by email rather than by more secure channels such as Canada Post’s secure messaging system.

However, reporting entities that prefer to respond via a secure channel can request this, and FINTRAC will generally accommodate their request. If an information request is unclear or if the timeframes are not feasible for your business, it is important to contact FINTRAC as soon as possible to resolve the issue.

Supervisory Risk Assessment Questionnaires (SRAQs)

SRAQs are Excel forms sent through Canada Post’s secure platform, often after a call or meeting with FINTRAC to explain the process. They include detailed questions about your business structure, risk levels, and electronic funds transfers.

Some fields may be pre-filled by FINTRAC, but must be reviewed. The SRAQ will generally have questions about your risk assessment, and you may be asked whether your risk assessment aligns with Canada’s National Risk Assessment (NRA).

Compliance Self-Attestations

These detailed PDF forms are also delivered securely, either with a SRAQ or on their own, and may follow a call or meeting with FINTRAC to explain the process. The self-attestation form asks about your Compliance Officer, AML policies and procedures, risk assessment, training, and compliance effectiveness reviews (audits). The responses must be specific (tailored to your business, documentation, and processes), and questions often overlap with the SRAQ.

The self-attestation questionnaire commonly asks who approved your policies, and whether compliance effectiveness reviews (audits) led to action plans. The final section of the attestation form requires sign-off from the person completing it, attesting to the accuracy and completeness of the information provided.

Monitoring Meetings

Monitoring meetings are common for larger or higher-risk businesses and are used to follow up on issues like reporting errors, self-declared non-compliance, or action plan progress. Be ready to explain past issues and decisions, particularly where FINTRAC is actively monitoring the remediation of an issue, including deficiencies observed by FINTRAC through examinations or other assessment activities. Detailed records help keep these meetings focused and efficient.

Action Plans

FINTRAC may request an action plan to correct deficiencies observed in the course of its assessment activities, or subsequent to a voluntary self-declaration of non-compliance. An action plan describes the deficiencies, the steps that are being taken to address and correct the issues, and the expected timelines. In some cases, FINTRAC may request updates to action plans in conjunction with monitoring meetings.

Examinations

FINTRAC selects businesses for examinations based on factors like risk score, past findings, or industry trends. Examinations may be in-person or remote, and full-scope (covering a broad range of AML compliance requirements) or targeted (covering only a narrow scope, such as high-risk customers and enhanced due diligence activities).

The examination process generally begins with a notification call, followed by a formal letter, document review, interviews, and concludes with a findings report. As PI and other sensitive information is exchanged with FINTRAC in this process, written communication is usually through Canada Post’s secure online portal. If serious deficiencies are discovered, FINTRAC may issue a Notice of Violation, which accompanies an administrative monetary penalty (AMP).

Take Every Request Seriously, The Consequences Are Real

A single poorly handled request can escalate to a formal examination or enforcement action, up to and including an AMP. For example:

  • Information Requests might ask for detailed operational data, like wallet addresses, transaction volumes, geographic reach, etc., that must be provided within specific timeframes.
  • SRAQs and Self-Attestations often probe the strength and scope of your compliance program, training, policies, and controls.
  • Monitoring Meetings may seem routine, but they serve as real-time evaluations of progress or issues.

Even if you think your compliance program is strong, you can’t rest on your laurels. Giving too much, too little, or the wrong kind of information can still cause problems.

Timing & Scope Matter, So Speak Up Early

One of the most preventable mistakes? Not raising concerns early. If you receive a request that:

  • Requires more time than you realistically have
  • Involves an impractical volume of data
  • Touches on sensitive or operationally risky areas (like sending wallet addresses via unencrypted email, for example)
  • Is unclear or difficult to fulfill, or
  • Seems misaligned with your actual business structure…

Reach out to FINTRAC right away! They may allow accommodations like a secure file upload option or deadline extensions. FINTRAC  will also be able to clarify or refine the scope of their request, but you have to ask early. Proactive communication helps avoid mistakes and shows a good-faith effort to comply.

Documentation is Protection

Formal or informal? It doesn’t matter. If you interact with FINTRAC, document everything:

  • The requests received and your interpretations,
  • Deadlines and communication
  • What data you provided and how
  • Who internally approved or reviewed the responses

Keep a central record, like a shared folder or internal compliance log, to track all relevant information. Where there is something unusual about your business or processes, consider whether or not it makes sense to include explanations either in writing or during a meeting with FINTRAC.

Common Errors to Avoid

These are the biggest issues that trip up even experienced teams:

  • Not answering the question asked: Too much or too little detail can both be problematic, and providing information that doesn’t address the question makes you seem disorganized at best.
  • Assuming foreign compliance standards apply: FINTRAC’s mandate is to ensure compliance with Canadian requirements, and straying from this focus can imply that you’re not well-versed when it comes to the Canadian AML framework.
  • Underestimating the data lift: Raw data is often messier and harder to extract than expected. Plan accordingly and start pulling data and organizing your response early.
  • Auditor independence: If your auditor is also your AML program creator, expect scrutiny for lack of independence.

Make an Action Plan, Even if You’re Not Asked

There is some variance in terms of whether or not action plans are requested after FINTRAC examinations. Today, they’re becoming an unspoken expectation, though you may not be asked for your action plan until the next time that you’re faced with an assessment activity. Best practice? Develop an internal action plan, even if  FINTRAC doesn’t ask for one. Examiners, auditors, and your leadership team will expect to see how you’ve addressed gaps. Your action plan should:

  • Outline findings and fixes
  • Assign owners and timelines
  • Track milestones and updates

If you’ve already had an examination or audit and didn’t document an action plan, it’s not too late. Your plan can include work already completed to address any deficiencies.

Is This Really From FINTRAC? How to Tell

Some recent FINTRAC requests look different from what businesses are used to, which has caused confusion. And to make matters worse, there have been documented cases of scammers impersonating FINTRAC and other regulators. Here’s how to tell if the request is legitimate:

  • Check the Sender: Legit emails come from @fintrac-canafe.gc.ca or @fintrac-canafe.canada.ca.
  • Look for legal references: Real requests often cite the PCMLTFA (for example, section 63.1(2) of the PCMLTFA).
  • Expect formal language: Clear instructions, deadlines, and specific data requests are standard.
  • Templates included: FINTRAC may attach Excel or PDF forms to complete. These will not be in a “zipped” format or other format that cannot be scanned for malicious elements.
  • No contact name? Still valid: Some are signed by the team or department without a specific person named.
  • Delivery method: Sensitive items may come through Canada Post’s secure epost system, but where this is the case, reporting entities will generally receive a phone call first.

If you’re unsure, don’t ignore it. Verify through FINTRAC’s official contact channels, not by replying to a suspicious email.

Final Reminder: Treat Every Touchpoint as an Evaluation

A call. An email. A simple questionnaire or data request. It’s all part of a broader assessment process. These activities carry weight, can impact your risk profile, and may lead to further scrutiny if not handled correctly.

Treat every request seriously and respond with care. If something is unclear, the scope seems off, or if you need more time, speak up early! Proactive communication prevents misunderstandings and protects your organization from costly consequences.

Need a Hand?

If you’re unsure how to interpret a request, need help crafting a response, or want to strengthen your overall compliance approach, Outlier Compliance Group is here to help. Please get in touch.

New Reporting Entity: Factoring Companies

Background

On March 26, 2025 final amendments to the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations were officially published in the Canada Gazette (SOR/2025-68). This round of anticipated changes introduces three company types that will become reporting entities. Below, we summarize the requirements that Factoring Companies will have to comply with as of April 1, 2025.

Factoring Companies (Factors)

Factors supply liquidity to a customer in exchange for the cash value of a certain amount of the customer’s accounts receivable (i.e. invoices) to be collected later by the factoring company. A factor is defined as a person or entity that is engaged in the business of factoring, with or without recourse against the assignor.

Requirements

All reporting entities (including Factoring Companies, as of April 1, 2025) must have in place a compliance program as defined under the PCMLTFA and associated regulations. The following is a summary of the requirements, as well as links to FINTRAC guidance (some of which will need to be updated).

Program Elements

  • Appoint a compliance officer who is responsible for implementing the compliance program and have oversight. The Compliance Officer must always have access to management and have the authority to carry out their duties.
  • Develop and apply written compliance policies and procedures that describe what is required under law and how these obligations will be met. These must be kept up to date and approved by a senior officer.
  • Conduct and document a risk assessment of your business. This assessment should include all activities that could make an entity vulnerable to money laundering or terrorist financing, as well as the mitigating controls that are put into place to prevent such risks.
  • Develop and maintain an ongoing compliance training program for your staff and agents. Everyone that deals with customers, customer funds, or transactions must receive AML and ATF training at least annually.
  • Conducting compliance effectiveness reviews. This is an audit that tests a company’s AML and ATF program and its effectiveness. These reviews must be completed at least once every two years.

Operational Elements

  • Reporting certain transactions. Where there are reasonable grounds to suspect that a particular financial transaction is related to the commission of a money laundering or terrorist activity financing offence, a Suspicious Transaction Report must be summitted to FINTRAC. This includes Large Cash and Large Virtual Currency reporting.
  • Follow ministerial directives and perform watchlist screening. Where a company may be in possession of funds or property that belong to a terrorist (either an individual or an organization) or a listed person, a Listed Person or Entity Report must be submitted to FINTRAC.
  • Identifying customers. Upon entering into a factoring agreement or when an information record is created, Factoring Companies will need to verify the identity of a customer using prescribed methods for individuals and entities.
  • Conducting transaction monitoring.
  • Conducting enhanced due diligence and enhanced transaction monitoring for high-risk customers.
  • Keeping certain records. In addition to keeping records related to the requirements above, Factoring Companies are required to keep the following records:
    • an information record in respect of the person or entity with whom it enters into the agreement;
    • if the information record is in respect of an entity, a record of the name, address, and date of birth of every person who enters into the agreement on behalf of the entity and the nature of the person’s principal business or their occupation;
    • if the information record is in respect of a corporation, a copy of the part of official corporate records that contains any provision relating to the power to bind the corporation in respect of transactions with the factor;
    • a record of the financial capacity of the person or entity with which it enters into the agreement and the terms of the agreement;
    • for any payment it makes, a record of:
      • the date of the payment,
      • if the payment is in funds, the type and amount of each type of funds involved,
      • if the payment is not in funds, the type of payment and its value,
      • the method by which the payment is made,
      • the name of every person or entity involved in the payment, and
      • every account number or other equivalent reference number connected to the payment; and
    • a receipt of funds record in respect of every amount of $3,000 or more that it receives, unless the amount is received from a financial entity or public body or from a person who is acting on behalf of a client that is a financial entity or public body.

What Next?

Factoring Companies should start working on developing their compliance program immediately if they have not done so already. FINTRAC has updated their sector-specific guidance page with relevant information for this new reporting entity and should be read.

We’re Here To Help

If you would like assistance in understanding what these changes mean to your business, or if you need help in creating or updating your compliance program and processes, please get in touch.

New Reporting Entity: Financing and Leasing Entities

Background

On March 26, 2025 final amendments to the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations were officially published in the Canada Gazette (SOR/2025-68). This round of anticipated changes introduces three company types that will become reporting entities. Below, we summarize the requirements that Financing and Leasing Entities will have to comply with as of April 1, 2025.

Financing and Leasing Entities

A financing or leasing entity is defined as a person or entity that is engaged in the business of financing or leasing of:

  • property, other than real property or immovables, for business purposes;
  • passenger vehicles in Canada; or
  • property, other than real property or immovables, that is valued at $100,000 or more.

Requirements

All reporting entities (including Financing and Leasing Entities, as of April 1, 2025) must have in place a compliance program as defined under the PCMLTFA and associated regulations. The following is a summary of the requirements, as well as links to FINTRAC guidance (some of which will need to be updated).

Program Elements

  • Appoint a compliance officer who is responsible for implementing the compliance program and have oversight. The Compliance Officer must always have access to management and have the authority to carry out their duties.
  • Develop and apply written compliance policies and procedures that describe what is required under law and how these obligations will be met. These must be kept up to date and approved by a senior officer.
  • Conduct and document a risk assessment of your business. This assessment should include all activities that could make an entity vulnerable to money laundering or terrorist financing, as well as the mitigating controls that are put into place to prevent such risks.
  • Develop and maintain an ongoing compliance training program for your staff and agents. Everyone that deals with customers, customer funds, or transactions must receive AML and ATF training at least annually.
  • Conducting compliance effectiveness reviews. This is an audit that tests a company’s AML and ATF program and its effectiveness. These reviews must be completed at least once every two years.

Operational Elements

  • Reporting certain transactions. Where there are reasonable grounds to suspect that a particular financial transaction is related to the commission of a money laundering or terrorist activity financing offence, a Suspicious Transaction Report must be submitted to FINTRAC. This includes Large Cash and Large Virtual Currency reporting.
  • Follow ministerial directives and perform watchlist screening. Where a company may be in possession of funds or property that belong to a terrorist (either an individual or an organization) or a listed person, a Listed Person or Entity Report must be submitted to FINTRAC.
  • Identifying customers. Upon entering into an agreement for the listed activities under the definition above, Financing and Leasing Entities will need to verify the identity of a customer using prescribed methods for individuals and entities.
  • Conducting transaction monitoring.
  • Conducting enhanced due diligence and enhanced transaction monitoring for high-risk customers.
  • Keeping certain records. In addition to keeping records related to the requirements above, Financing and Leasing Entities are required to keep the following records:
    • an information record in respect of the person or entity with which it enters into the arrangement;
    • if the information record is in respect of an entity, a record of the name, address and date of birth of every person who enters into the arrangement on behalf of the entity and the nature of the person’s principal business or their occupation;
    • if the information record is in respect of a corporation, a copy of the part of official corporate records that contains any provision relating to the power to bind the corporation in respect of transactions with the financial leasing entity;
    • a record of the financial capacity of the person or entity with which it enters into the arrangement and the terms of the arrangement; and
    • in respect of every payment that it receives under the arrangement, other than a payment received from a financial entity or public body or from a person who is acting on behalf of a client that is a financial entity or public body, a record of
      • the date of the payment,
      • the name of the person or entity that makes the payment,
      • the amount of the payment and of any part of it that is made in cash, and
      • the method by which the payment is made.

What Next?

Financing and Leasing Entities should start working on developing their compliance program immediately if they have not done so already. FINTRAC has updated their sector-specific guidance page with relevant information for this new reporting entity and should be read.

We’re Here To Help

If you would like assistance in understanding what these changes mean to your business, or if you need help in creating or updating your compliance program and processes, please get in touch.

New Reporting Entity: Cheque Cashing

Background

On March 26, 2025 final amendments to the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations were officially published in the Canada Gazette (SOR/2025-68). This round of anticipated changes introduces three company types that will become reporting entities. Below, we summarize the requirements that cheque cashing businesses, who will be classified as either domestic or foreign money services businesses (MSBs), will have to comply with as of April 1, 2025.

Requirements

MSBs (including cheque cashing businesses) must register with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) and have in place a compliance program as defined under the PCMLTFA and associated regulations. The following is a summary of the requirements that MSBs must comply with, as well as links to FINTRAC guidance.

Program Elements

  • Appoint a compliance officer who is responsible for implementing the compliance program and have oversight. The Compliance Officer must always have access to management and have the authority to carry out their duties.
  • Develop and apply written compliance policies and procedures that describe what is required under law and how these obligations will be met. These must be kept up to date and approved by a senior officer.
  • Conduct and document a risk assessment of your business. This assessment should include all activities that could make an entity vulnerable to money laundering or terrorist financing, as well as the mitigating controls that are put into place to prevent such risks.
  • Develop and maintain an ongoing compliance training program for your staff and agents. Everyone that deals with customers, customer funds, or transactions must receive AML and ATF training at least annually.
  • Conducting compliance effectiveness reviews. This is an audit that tests a company’s AML and ATF program and its effectiveness. These reviews must be completed at least once every two years.

Operational Elements

  • Register with FINTRAC before conducting prescribed transactions. The registration information must be kept up to date and renewed every two years;
  • Reporting certain transactions. Where there are reasonable grounds to suspect that a particular financial transaction is related to the commission of a money laundering or terrorist activity financing offence, a Suspicious Transaction Report must be summitted to FINTRAC. This includes Large Cash, Large Virtual Currency and Electronic Funds Transfer reporting;
  • Follow ministerial directives and perform watchlist screening. Where a company may be in possession of funds or property that belong to a terrorist (either an individual or an organization) or a listed person, a Listed Person or Entity Report must be submitted to FINTRAC;
  • Identifying customers. As it relates to cheque cashing services, MSBs will need to verify the identity of a customer using prescribed methods for individuals and entities where there is a request to cash one or more cheques that total $3,000 or more;
  • Conducting ongoing transaction monitoring for customers that have formed a business relationship;
  • Conducting enhanced due diligence and enhanced transaction monitoring for high-risk customers; and
  • Keeping certain records. MSBs must keep specific records. As it relates to cheque cashing activities (over $3,000) the following records must be retained:
    • the date when each cheque is cashed;
    • the person’s or entity’s name and address, the nature of their principal business or their occupation and, in the case of a person, their date of birth;
    • the total amount of the cheque or cheques;
    • the name of the issuer of each cheque;
    • the number of every account that is affected by the cashing of the cheque or cheques, the type of account and the name of each account holder;
    • every reference number that is connected to the cashing of the cheque or cheques and that has a function equivalent to that of an account number; and
    • if the cashing of the cheque or cheques involves virtual currency, every transaction identifier, including the sending and receiving addresses.

What Next?

Companies that perform cheque cashing activities should start working on developing their compliance program immediately if they have not done so already. FINTRAC has updated their sector-specific guidance page with relevant information for this new reporting entity and should be read.

We’re Here To Help

If you would like assistance in understanding what these changes mean to your business, or if you need help in creating or updating your compliance program and processes, please get in touch.

Return to Blog Listing