What FINTRAC expects from the two-year effectiveness review
Every reporting entity under the PCMLTFA keeps a compliance program with five elements: a compliance officer, written policies and procedures, a risk assessment, an ongoing training program and plan, and a review of the program's effectiveness every two years.
The effectiveness review tests whether the program works in practice. FINTRAC expects it to cover:
- the policies and procedures, tested against real files and transactions;
- the risk assessment, including whether it still matches the products, customers, channels and countries the business has today;
- the training program and plan, and whether staff apply it.
The breadth of testing follows the size and risk of the business, transaction volumes and the findings of earlier reviews. The review is documented: the date, the period covered, who carried it out, the tests performed and the results, the conclusions, the deficiencies found, the recommendations and the action plan. An entity reports the findings, and any policy updates made during the period, in writing to a senior officer within 30 days after the review is completed.
Independent reviewer: who can do it
The regulations allow the review to be carried out by an internal or external auditor, or by the business itself when it has no auditor. A self-review is allowed; its limit is that the author of the program also grades it. An external reviewer brings sample testing, a fresh read of the risk assessment and a report that also works as evidence for banks and partners.
We carry out the review as an external reviewer for money services businesses and other reporting entities: scoping, sample testing of files and reports, a written report with findings and an action plan, and follow-up on fixes.
Related reading
- MSB registration in Canada: the compliance program from day one.
- Canada MSB banking: what banks check in an MSB's AML file.
- Outsourced compliance officer (MLRO) in Canada.
- All AML and compliance services in Canada.






