A FINTRAC-registered MSB is only as strong as its compliance program. We build complete, examination-ready PCMLTFA programs around how your business actually works, never from a recycled template, and hand them over as editable documents your team can keep up to date.
Book a Free Consultation WhatsApp Us
Canadian law does not simply ask MSBs to “have policies”. The PCMLTFA and its regulations set out a specific program structure, and FINTRAC examines each element for effectiveness. A written document that nobody follows will not pass. The framework rests on five pillars.
A designated person with real authority and knowledge, responsible for the program day to day. See our fractional MLRO service.
Written, current, and specific to your products, channels and customer types, covering KYC, reporting, record keeping and sanctions.
A documented, risk-based analysis of your customers, geographies, products and delivery channels, driving the controls that follow.
A training program with a schedule, materials and attendance records, refreshed as the rules and your business change.
An independent review at least every two years testing whether the program actually works in practice, with findings tracked to closure.
You are registering an MSB or PSP and FINTRAC expects a complete program to exist from day one.
An examination flagged deficiencies and you need a credible rebuild with a remediation trail.
The program was bought at registration, never updated, and no longer describes what the business does.
New products, new corridors or crypto services have outgrown the controls you wrote two years ago.
We map your products, customers, corridors and volumes, because the program has to mirror the real business.
Risks are scored and documented first, so every control that follows has a reason to exist.
We draft the policies and procedures, then walk through them with your team and adjust them to how you actually operate.
We hand over the final documents with a briefing session, a training plan and a review schedule.
Canada's AML regime has tightened considerably, and the shift matters for how a compliance programme is written. FINTRAC no longer assesses whether documents exist. It assesses whether the programme works.
A policy manual that nobody in the business has read will not pass. Examiners now ask staff what they actually do and compare the answer to the document.
Controls that do not trace back to an identified risk look arbitrary. Controls that leave an identified risk untreated are a finding. The assessment has to come first and be revisited.
Administrative monetary penalties have risen sharply and are published. The reputational cost of a public penalty now often exceeds the financial one, particularly for businesses seeking banking relationships.
Virtual currency dealing, armoured car services and certain financing arrangements have been drawn into scope. Programmes written before these changes often no longer cover the whole business.
Payment service providers registered with the Bank of Canada under the RPAA also carry FINTRAC obligations. The two regimes overlap but are not identical, and a single programme has to satisfy both.
Correspondent banks increasingly ask to see the programme and the last effectiveness review before opening or keeping an account. A weak programme costs you banking, not just regulatory standing.
This is the document everything else rests on, and it is the one most often copied from a template. A real assessment examines four dimensions of your specific business and scores each.
| Dimension | What gets examined | Typical controls it drives |
|---|---|---|
| Customers | Retail or business, beneficial ownership complexity, PEP exposure, industries served | Enhanced due diligence triggers, ownership verification depth, approval levels |
| Products & services | Remittance, currency exchange, virtual currency, prepaid access, payment processing | Transaction limits, monitoring rules, record keeping requirements |
| Geography | Corridors served, sanctions exposure, jurisdictions with weak AML regimes | Country risk tiers, screening frequency, corridor-specific escalation |
| Delivery channels | Face to face, online onboarding, agents, third-party introducers | Identity verification methods, agent oversight, non-face-to-face controls |
Each dimension is scored, the residual risk is documented after controls are applied, and the result is signed off by senior management. That signature matters: it is the evidence that the business owns its risk position rather than outsourcing it to a consultant.
When FINTRAC announces an examination, the initial document request is fairly predictable. A programme built properly has all of this ready without a scramble.
Not every business needs a new programme. We start by telling you honestly which of these situations you are in.
The programme reflects your real business, the risk assessment is recent, and the gaps are specific. We gap-assess against current expectations and amend only what falls short.
The policies are broadly sound but the risk assessment is generic or the business has added products. We rebuild the assessment and rework the controls that depend on it.
The programme was bought at registration, never updated, and does not describe what you do. Rewriting is faster and safer than patching, and usually costs less than it sounds.
WhatsApp us
