MSB Compliance Services in Canada

AML Compliance Program for Canadian MSBs

A FINTRAC-registered MSB is only as strong as its compliance program. We build complete, examination-ready PCMLTFA programs around how your business actually works, never from a recycled template, and hand them over as editable documents your team can keep up to date.

Book a Free Consultation WhatsApp Us
Modern financial tower at golden hour representing AML compliance for Canadian MSBs

What a PCMLTFA compliance program must contain

Canadian law does not simply ask MSBs to “have policies”. The PCMLTFA and its regulations set out a specific program structure, and FINTRAC examines each element for effectiveness. A written document that nobody follows will not pass. The framework rests on five pillars.

The five pillars of FINTRAC compliance

1

Compliance officer

A designated person with real authority and knowledge, responsible for the program day to day. See our fractional MLRO service.

2

Policies & procedures

Written, current, and specific to your products, channels and customer types, covering KYC, reporting, record keeping and sanctions.

3

Risk assessment

A documented, risk-based analysis of your customers, geographies, products and delivery channels, driving the controls that follow.

4

Ongoing training

A training program with a schedule, materials and attendance records, refreshed as the rules and your business change.

5

Effectiveness review

An independent review at least every two years testing whether the program actually works in practice, with findings tracked to closure.

When you need a program build

New registration

You are registering an MSB or PSP and FINTRAC expects a complete program to exist from day one.

Exam findings

An examination flagged deficiencies and you need a credible rebuild with a remediation trail.

Stale template

The program was bought at registration, never updated, and no longer describes what the business does.

Model change

New products, new corridors or crypto services have outgrown the controls you wrote two years ago.

What we deliver

  • Documented business-wide risk assessment
  • Full AML/ATF policy and procedure manual
  • KYC / KYB onboarding and ongoing monitoring procedures
  • STR, LCTR, EFT and terrorist property reporting procedures
  • Sanctions and PEP screening procedures
  • Training program with materials and records templates
  • Effectiveness review framework and schedule
  • Editable source documents, not locked PDFs

Our build process

1

Discovery

We map your products, customers, corridors and volumes, because the program has to mirror the real business.

2

Risk assessment

Risks are scored and documented first, so every control that follows has a reason to exist.

3

Drafting & calibration

We draft the policies and procedures, then walk through them with your team and adjust them to how you actually operate.

4

Delivery & briefing

We hand over the final documents with a briefing session, a training plan and a review schedule.

What changed after Bill C-12

Canada's AML regime has tightened considerably, and the shift matters for how a compliance programme is written. FINTRAC no longer assesses whether documents exist. It assesses whether the programme works.

Effectiveness over paperwork

A policy manual that nobody in the business has read will not pass. Examiners now ask staff what they actually do and compare the answer to the document.

Risk assessment drives everything

Controls that do not trace back to an identified risk look arbitrary. Controls that leave an identified risk untreated are a finding. The assessment has to come first and be revisited.

Higher penalties

Administrative monetary penalties have risen sharply and are published. The reputational cost of a public penalty now often exceeds the financial one, particularly for businesses seeking banking relationships.

More reportable activity

Virtual currency dealing, armoured car services and certain financing arrangements have been drawn into scope. Programmes written before these changes often no longer cover the whole business.

PSPs under two regimes

Payment service providers registered with the Bank of Canada under the RPAA also carry FINTRAC obligations. The two regimes overlap but are not identical, and a single programme has to satisfy both.

Banking partners look too

Correspondent banks increasingly ask to see the programme and the last effectiveness review before opening or keeping an account. A weak programme costs you banking, not just regulatory standing.

Inside the risk assessment

This is the document everything else rests on, and it is the one most often copied from a template. A real assessment examines four dimensions of your specific business and scores each.

DimensionWhat gets examinedTypical controls it drives
CustomersRetail or business, beneficial ownership complexity, PEP exposure, industries servedEnhanced due diligence triggers, ownership verification depth, approval levels
Products & servicesRemittance, currency exchange, virtual currency, prepaid access, payment processingTransaction limits, monitoring rules, record keeping requirements
GeographyCorridors served, sanctions exposure, jurisdictions with weak AML regimesCountry risk tiers, screening frequency, corridor-specific escalation
Delivery channelsFace to face, online onboarding, agents, third-party introducersIdentity verification methods, agent oversight, non-face-to-face controls

Each dimension is scored, the residual risk is documented after controls are applied, and the result is signed off by senior management. That signature matters: it is the evidence that the business owns its risk position rather than outsourcing it to a consultant.

What examiners ask for first

When FINTRAC announces an examination, the initial document request is fairly predictable. A programme built properly has all of this ready without a scramble.

  • The current compliance policies and procedures, with version history
  • The most recent risk assessment and evidence it was approved
  • The compliance officer's appointment record and reporting line
  • Training materials, the training schedule and attendance records
  • The last independent effectiveness review and the remediation log
  • A sample of customer files showing identification and verification
  • Reporting records for STRs, LCTRs, EFTs and terrorist property
  • Transaction monitoring rules and a sample of alerts with outcomes

Update or rebuild?

Not every business needs a new programme. We start by telling you honestly which of these situations you are in.

Update is enough

The programme reflects your real business, the risk assessment is recent, and the gaps are specific. We gap-assess against current expectations and amend only what falls short.

Partial rebuild

The policies are broadly sound but the risk assessment is generic or the business has added products. We rebuild the assessment and rework the controls that depend on it.

Full rebuild

The programme was bought at registration, never updated, and does not describe what you do. Rewriting is faster and safer than patching, and usually costs less than it sounds.

Frequently asked questions

How long does a program build take?
Most builds are finished within two to four weeks, depending on how complex the business is and how quickly you can get us the discovery information.
Can you update an existing program instead of rebuilding?
Yes. If the foundations are sound, we gap-assess against current FINTRAC expectations and update only what falls short. That is usually the faster and cheaper route.
Does the program cover crypto (virtual currency) activity?
Yes. Virtual currency exchange and transfer services are reportable MSB activities in Canada, and the risk assessment and procedures cover them explicitly.
Who runs the program after delivery?
Your designated compliance officer does. If you do not have one, our fractional MLRO service can take the role and run the program we build.

Talk to a compliance specialist