Plain-language FINTRAC scoping, payments and PSP models, virtual currency, and control playbooks for Canadian MSBs, fintechs, and payment teams. Each article cites current guidance and legislation. Educational only — not legal advice.
Canadian AML obligations come in three layers: the PCMLTFA as the governing Act, the PCMLTFR as the source of most operational duties, and FINTRAC guidance as the regulator's stated expectations. This article explains how to rank the layers, why in-force dates matter as much as section numbers, and why archived policy interpretations like PI-7670 are context — never current authority.
MSB status in Canada turns on whether you actually perform one of the listed money services — foreign exchange, funds transfer, money orders, virtual currency dealing, and several newer categories — for clients, with a Canadian nexus. The product label never decides it: this guide walks through each service category, the "in the business of" indicators, the any-amount rule, and why your own marketing copy is part of the evidence.
Whether a payment processor must register as a money services business turns on what the business actually does with funds and payment instructions — who holds money, who controls settlement, who receives or forwards instructions — not on the "processor," "PSP," or "payfac" label. FINTRAC withdrew its old PI-7670 merchant-processing positions in April 2022, so the analysis now runs on the current MSB guidance and the statute itself.
Canadian AML obligations come in three layers: the PCMLTFA as the governing Act, the PCMLTFR as the source of most operational duties, and FINTRAC guidance as the regulator's stated expectations. This article explains how to rank the layers, why in-force dates matter as much as section numbers, and why archived policy interpretations like PI-7670 are context — never current authority.
A scoping memo is a short internal record of what your business does, which regulated services might apply, the facts and sources behind your conclusion, and when you will revisit it. Written before launch, it turns "are we in scope?" from a hallway opinion into something a reviewer, counsel, or a future hire can reopen and test.
Reporting-entity status is set by the class list in PCMLTFA s. 5 — sometimes written into the Act, sometimes activated by regulation — and that perimeter widened three times between October 2024 and October 2025. This article maps how coverage is drafted, what obligations follow (compliance program, documented risk assessment, directives and sanctions reporting), and how to read FINTRAC guidance against the provisions it cites.
MSB status in Canada turns on whether you actually perform one of the listed money services — foreign exchange, funds transfer, money orders, virtual currency dealing, and several newer categories — for clients, with a Canadian nexus. The product label never decides it: this guide walks through each service category, the "in the business of" indicators, the any-amount rule, and why your own marketing copy is part of the evidence.
Crowdfunding platform services are a prescribed money services business service in Canada, so a platform provided and maintained for others to raise funds or virtual currency can trigger FINTRAC registration and a full compliance program. The analysis turns on what the platform actually does with contributed value — not on whether it calls itself a platform, a marketplace, or a fundraising tool.
MSBs and foreign MSBs must be registered with FINTRAC before they begin operating, and the registration has to keep matching what the business actually does — new service lines, newly prescribed services, and provincial licences each raise their own question. This article covers the trigger, the update duty, and why a provincial licence never substitutes for federal registration.
A business with no place of business in Canada still comes under the PCMLTFA as a foreign MSB when it both directs MSB services at people in Canada and actually provides them to Canadian clients. This article works through the two-part test, the place-of-business facts that separate domestic from foreign status, the indicators of Canadian targeting, and what businesses typically document either way.
Under the PCMLTFA, an agent delivers a registered MSB's service on its instructions, while an independent MSB carries its own registration and compliance program — and the classification turns on control, branding and the customer relationship, not the contract label. A partner's FINTRAC registration never automatically covers introducers, resellers or platforms further down the chain.
Between July 2024 and October 2025, three business models were pulled into FINTRAC's MSB regime: transporting currency or negotiable instruments (in force July 1, 2024), cheque-cashing services (prescribed under PCMLTFR s. 29.1), and acquirer services for private ATMs (in force October 1, 2025). In each case the obligation follows a specific service — not the adjacent roles of hosting a machine, owning hardware, or handling your own receivables.
"Remitting or transmitting funds" is the MSB service definition that captures most payment models — invoice pay, payroll, rent, tuition, direct-debit bill pay — whenever a business receives funds from one party and moves them to another as a service. Scope turns on the funds flow, not the sector, the rail, or the "we're just a processor" label.
Whether a payments product is an MSB turns on what it actually does with funds — giving payment instructions, controlling settlement, moving money — not on whether the company describes itself as SaaS, orchestration, or a hardware vendor. This article walks through the functional test, the 2022 withdrawal of FINTRAC's older payment-processing positions, and what a defensible scope analysis documents.
In white-label and embedded-finance programs, MSB status follows the entity actually engaged in the business of providing the service — traced through contracts, funds custody and settlement instructions — while agents and reliance under PCMLTFR ss. 106–107 delegate the work, never the obligation. The article also covers why the program partner is itself a client from service-agreement signature (s. 4.1(d)), why group companies are scoped one entity at a time, and how to document a no-MSB conclusion without overstating it.
Whether a payment processor must register as a money services business turns on what the business actually does with funds and payment instructions — who holds money, who controls settlement, who receives or forwards instructions — not on the "processor," "PSP," or "payfac" label. FINTRAC withdrew its old PI-7670 merchant-processing positions in April 2022, so the analysis now runs on the current MSB guidance and the statute itself.
A funds-flow diagram mapping every party and settlement account — verified against the merchant, acquirer, processor, and bank contracts that actually assign control of funds — is the artifact an MSB scope review should be built on. The scope analysis under PCMLTFA s. 5(h)(ii) then reasons from what the diagram shows, not from how the product is described.
A merchant of record sells as principal and remits proceeds onward; a PSP moves money it never owned. Under the PCMLTFA that contractual difference — together with who actually controls settlement — drives the MSB scope analysis, and refund, chargeback and recurring-billing patterns then shape the monitoring work.
Payer consent clauses and payee agreements are facts to analyze, not conclusions: MSB scope under PCMLTFA s. 5(h)(ii) and s. 5(h.1)(ii) turns on who actually receives, forwards, or can change payment instructions and who controls the funds. Since FINTRAC withdrew its PI-7670 positions effective April 27, 2022, the documented funds-flow — not older interpretations or checkout language — carries the analysis.
FINTRAC withdrew PI-7670's positions on merchant servicing and payment processing effective April 27, 2022, so the old view that merchant servicing sat outside MSB scope carries no current weight. Payment companies now re-run that analysis against PCMLTFA s. 5(h) and the 2022 FINTRAC notices, and keep a dated record of what they concluded.
Three fact patterns can place a payment-adjacent business outside the MSB funds-transfer test: collecting payment only for your own goods or services, selling payment hardware without settlement or instruction services, and receiving funds to settle a debt without transmitting them onward. Each depends on specific facts, and each became harder to shortcut after FINTRAC withdrew its PI-7670 positions in April 2022.
Whether a payment platform is an MSB in Canada turns less on its label than on who controls settlement — timing, amounts, destinations, reversals, fees, and reserves — and who holds customer funds along the way. This article works through the four recurring fact patterns: settlement control, pass-through accounts, marketplace split payments, and wallet cash-out.
An OTC desk executing large, negotiated crypto trades is dealing in virtual currency under the PCMLTFA, which brings KYC/KYB, source-of-funds and source-of-virtual-currency checks, travel-rule information, recordkeeping, and reporting with it. Blockchain analytics supports those controls but cannot substitute for the documented program elements — policies, risk assessment, training, and human review of alerts — that the law prescribes.
Chain-hopping and mixer exposure are risk signals, not offences: their role is to feed the "reasonable grounds to suspect" test in PCMLTFA s. 7. This article explains both patterns in plain English and maps them to the filings an analyst actually makes — the STR (no threshold, attempted transactions count), the LVCTR (five working days, not 15) and the LPEPR where listed persons appear.
Wallet scope under the PCMLTFA turns on control points — who holds the keys, who executes transfers, and who receives instructions — not on the "custodial" or "non-custodial" label. A custodial wallet that moves client virtual currency on instruction looks like a virtual currency transfer service; a non-custodial wallet still needs a documented analysis before anyone concludes it is out of scope.
Under the PCMLTFA, "dealing in virtual currency" is its own MSB service covering both exchange (fiat-to-crypto and crypto-to-crypto) and transfer of virtual currency. Scope turns on what a platform actually does with custody, control, and conversion — not on whether it calls itself a wallet, a protocol, or an app.
Canadian AML law never names DeFi, staking or token listings — MSB scope under PCMLTFA s. 5(h) turns on what a product actually does with users' virtual currency, and once in scope the obligations arrive as concrete dollar triggers: $1,000 identity verification, $10,000 third-party determinations, $100,000 PEP screening. A token listing decision is a risk-assessment exercise: can you still monitor, value and identify for that asset, and can you show your work.
Receiving virtual currency worth CAD 10,000 or more — in one transaction or in smaller receipts aggregated over a 24-hour window — triggers a Large Virtual Currency Transaction Report, while transfer records attach at $1,000 per current FINTRAC guidance. This article walks through the threshold, the aggregation mechanics, the record set to capture, and how the travel rule fits alongside.
A peg to the dollar does not take a token out of Canada's AML framework: stablecoins generally meet the PCMLTFR definition of virtual currency, so exchanging, transferring, or holding them for clients triggers MSB registration, virtual-currency reporting, travel-rule, and record-keeping obligations. This article walks through the definitional test, the activities that put a stablecoin business in scope, and the scoping memo worth keeping on file.
PCMLTFR s. 124.1 requires prescribed originator and beneficiary information to travel with virtual currency transfers — a rule that lives half in product design and half in operations. This article covers what the provision requires, how to build transfer flows that carry the information, and how to detect, escalate, and document the cases where it arrives incomplete.
PCMLTFR s. 138 requires identifying every person who owns or controls, directly or indirectly, 25% or more of an entity's shares (or of the entity), understanding its ownership, control and structure, and taking reasonable measures to confirm that information both at onboarding and during ongoing monitoring. Where it cannot be obtained or confirmed, the entity's chief executive officer must be identified and the s. 157 high-risk special measures applied — and since October 1, 2025, material discrepancies with the Corporations Canada individuals-with-significant-control database must be reported for high-risk CBCA corporations within 30 days.
A business relationship usually forms the second time you are required to verify a client's identity (PCMLTFR s. 4.1) — and from that moment s. 123.1 requires periodic, risk-based monitoring with four named purposes. This article covers formation triggers, what each monitoring purpose demands in practice, beneficial ownership refresh, and why the expected-activity note you write at onboarding is the baseline the whole regime depends on.
MSBs must take reasonable measures to determine PEP/HIO status at the $100,000 transaction triggers in PCMLTFR s. 120, and a hit on a foreign PEP — or a high-risk domestic PEP or HIO — pulls in source-of-funds, source-of-wealth and senior-management review within 30 days under s. 122. This article walks through who the categories cover, when the check fires, and what to document.
Canadian AML rules give a business two distinct ways to let someone else handle identity verification: an agent or mandatary performing its s. 105(1) verification (PCMLTFR s. 106), or reliance on a verification another reporting entity already completed (s. 107). The 2025 in-force dates for five new sectors widened who sits in that reliance pool.
Third-party determination under PCMLTFR ss. 134–137 asks who a transaction is really for, while merchant and agent KYB verifies the business itself — its existence, directors and 25% beneficial owners — under ss. 109, 112 and 138. This article covers the exact triggers and records for each, why signing a merchant service agreement starts a business relationship for an MSB, and why a low-risk rating never switches off the fixed identification thresholds in s. 95.
PCMLTFR s. 105(1) gives five ways to verify a person's identity — government photo ID, government-source information, a Canadian credit file at least three years old, dual-process, and the affiliate or member method — with reliance and agent arrangements sitting separately in ss. 106–107. The binding 'authentic, valid and current' standard in s. 105(5) is what remote flows most often fail: an image of a document proves it exists, not that it is genuine.
Corporations are verified by referring to a record — a certificate of incorporation, an annual securities filing, or the most recent equivalent — that confirms existence, name, address and directors' names (PCMLTFR s. 109); partnerships, trusts and other entities use their constating record under s. 112. The record must be authentic, valid and current, and beneficial-ownership collection under s. 138 attaches to the same moment.
When you cannot obtain or confirm an entity's beneficial ownership, PCMLTFR s. 138(4) tells you exactly what happens next: verify the identity of the entity's chief executive officer and apply the high-risk special measures under s. 157. This article walks through that escalation path, the newer s. 138.1 discrepancy-reporting duty for CBCA corporations, and how the 25% test plays out for charities and other nonprofits that have no owners at all.
PCMLTFR s. 95(1) gives money services businesses exact identity-verification thresholds: $1,000 for EFTs, non-EFT funds transmission and virtual currency, $3,000 for foreign exchange, negotiable instruments and cheque cashing. Suspicious transactions and large cash or virtual currency receipts trigger verification with no dollar minimum at all.
An international EFT of CAD $10,000 or more is reportable at both ends: the business that initiates it and the business that finally receives it each file their own report within five working days. Missing travel-rule information is a monitoring signal — follow up, document the outcome, and assess whether the pattern supports a suspicious transaction report, which has no dollar threshold.
The STR deadline is not a day count: SOR/2001-317 s. 9(2) requires filing as soon as practicable after you complete the measures that establish reasonable grounds to suspect, which makes your own case timestamps the compliance evidence. This article covers that timing rule, how to write a narrative an analyst can actually use, what PCMLTFA s. 8 does and does not prohibit when clients ask questions mid-review, and how to structure the file/no-file decision.
An alert is not a report — it is a prompt to investigate. This article walks through the pipeline from monitoring rule to STR decision under PCMLTFA s. 7: the "reasonable grounds to suspect" threshold, the "as soon as practicable" clock in SOR/2001-317 s. 9(2), and the case notes, evidence and decision trail that let a no-file decision stand up later.
Most FINTRAC reporting failures are process failures: a deadline matrix that treats every report like an LCTR, 24-hour aggregation run under one lens instead of three, and no retained proof of what was actually filed. This article turns the verified deadlines and aggregation rules into a pre- and post-submission QA checklist, a correction record worth keeping, and a seeded-scenario script for testing monitoring controls.
Under PCMLTFA s. 7, a Suspicious Transaction Report is triggered by reasonable grounds to suspect — not proof — that a completed or attempted transaction is linked to money laundering, terrorist activity financing or, since August 19, 2024, sanctions evasion. There is no dollar threshold, and the report is due as soon as practicable after your review establishes those grounds.
Suspicious-transaction indicators are business-model translations of one statutory test — reasonable grounds to suspect under PCMLTFA s. 7 — and they look different at a cash-heavy MSB counter, a virtual currency platform, and a payments back office. This article walks through the recurring patterns for each model, the threshold and 24-hour-rule mechanics that structuring plays against, and how to train customer support teams to escalate without tipping anyone off.
The 24-hour rule deems two or more cash, international EFT, or virtual currency transactions totalling CAD $10,000 or more within 24 consecutive hours to be a single reportable transaction. FINTRAC requires you to run three separate groupings over the same transactions — same conductor, same third party, same beneficiary — and each grouping can generate its own report.
Receiving CAD $10,000 or more in cash triggers a Large Cash Transaction Report within 15 days; initiating or finally receiving an international electronic funds transfer of $10,000 or more triggers an EFT report within five working days. The 24-hour rule aggregates smaller amounts, and threshold reports are objective — they run on the amount, not on suspicion.
Geography is a prescribed factor in every PCMLTFA risk assessment, and three ministerial directives — covering North Korea, Iran and Russia — make every transaction to or from those countries high-risk regardless of amount. This article covers how corridor ratings drive the PCMLTFR s. 157 special measures, what each directive requires, and where sanctions obligations sit relative to the PCMLTFA reporting layer.
Rating a client high-risk under PCMLTFA s. 9.6 is not the end of the exercise — it triggers the mandatory PCMLTFR s. 157 special measures: enhanced identity verification, current beneficial-ownership information, and monitoring at a frequency matched to the risk. This article covers how to rate against the s. 156(1)(c) factors, what the three ministerial directives impose regardless of your model, and how PSPs review merchants and nested MSB clients.
The PCMLTFA never uses the words "inherent" or "residual," but s. 9.6(2) and PCMLTFR s. 156(1)(c) require ML/TF risk to be assessed and documented — and the two-step split is how practitioners keep that documentation honest. This article covers the prescribed factors, why a few defined bands beat decimal scores, how to record residual-risk acceptance, and the refresh triggers the regulation actually anchors.
PCMLTFR s. 156(2) requires a documented ML/TF risk assessment before a new product, delivery channel or technology goes live — a separate trigger from the ongoing s. 156(1)(c) factors it is often confused with. This article covers how to decompose product and channel risk, what a high-risk rating obliges you to do under s. 157, why a launch can change your reporting-entity status entirely, and where fraud risk ends and AML risk begins.
Canadian freeze and dealings-prohibition obligations come from the United Nations Act regulations, SEMA, the JVCFOA and the Criminal Code — the PCMLTFA then bolts on the FINTRAC layer: listed-property reporting under s. 7.1(1) and an STR under s. 7(c) for suspected sanctions evasion. This article maps where screening sits in a risk-based program, what the three ministerial directives require, and how the same rules reach virtual currency.
Source of funds traces the specific money in a transaction; source of wealth explains how the client built everything they own. Neither is a universal ask — the duty flows from the risk-based approach in PCMLTFA s. 9.6 and PCMLTFR ss. 156–157, and becomes non-negotiable for transactions touching North Korea, Iran or Russia under the ministerial directives.
Canada's risk-based approach is two documented assessments — one of the business against the prescribed PCMLTFR s. 156(1)(c) factors, one rating each client relationship — that must visibly drive controls, monitoring frequency and training. This article maps PCMLTFA s. 9.6 and PCMLTFR ss. 156–157, the pre-launch assessment for new technologies, and how ministerial directives hard-code part of the geographic rating.
An MSB's agent and employee evidence lives in three places: the agent listing on its FINTRAC registration, criminal-record documents under PCMLTFA s. 9.93 and PCMLTFR s. 37.1 (in force October 1, 2025), and training and review documentation under PCMLTFR s. 156. Contrary to a common assumption, no regulation prescribes a written agency agreement as a record — FINTRAC guidance instead expects the two-year effectiveness review to examine those agreements.
Identity verification and beneficial ownership work only counts at examination if a dated, attributed, producible record shows what was checked, against what source, and by whom. This article maps the KYC and ownership records to keep, the three five-year retention clocks in PCMLTFR s. 148, and the 30-day producibility rule in s. 149.
FINTRAC document requests run on a clock the regulation set before the letter arrived: records must be kept so they can be produced within 30 days of an examination request. This article covers the record inventory to build in advance, the compliance-program evidence pack, a working request tracker, and the remediation and minutes documentation that closes findings cleanly.
Canadian AML records must be kept for at least five years, but the clock starts on one of three different dates depending on the record type — and PCMLTFR s. 149 requires every record to be producible within 30 days of a FINTRAC examination request. This article maps the start dates, the record triggers that decide what you are holding, and the filing evidence that proves reports actually went in.
MSB recordkeeping runs on threshold tiers: $10,000 for large cash and large virtual currency records, $1,000 for the EFT, remittance and virtual currency transfer cluster, $3,000 for cheque cashing and money orders, and per-transaction exchange tickets with no threshold at all. This article maps each record type to its PCMLTFR provision and covers the retention and 30-day production rules that determine whether those records hold up in an examination.
An operating AML program's cost structure is set by PCMLTFR s. 156 — a named compliance officer, maintained policies, a documented risk assessment, a training cycle and a biennial auditor-led effectiveness review — scaled by transaction volumes at the $10,000 and $1,000 record thresholds. This article turns those elements into a metrics dashboard, a staffing model for early-stage MSBs and the recurring budget lines founders and boards should expect.
Canadian reporting entities must keep written, approved, risk-based policies and procedures as part of the compliance program required by PCMLTFA s. 9.6 and PCMLTFR ss. 156–157. This article separates policies (what and why) from procedures (how), then shows how version control and named control owners turn the documents into a program you can operate and evidence.
FINTRAC expects two distinct things: a training program (role-based content on what staff notice, escalate, and record) and a written training plan (who gets trained, how often, and how completion is tracked). This article explains what each element contains, how they differ, and which records businesses typically keep to show training actually happened.
A workable AML program names who decides each thing, by when, and with what recorded — because PCMLTFR s. 156 requires written, up-to-date policies and procedures, a documented training program, and a two-year effectiveness review, and a sentence like "we review transactions" satisfies none of that. This article shows how to write escalation paths and procedures a new hire could run on day one, and what to train each role on.
Canadian law lets a reporting entity hire out AML tasks — drafting policies, running the risk assessment, conducting the two-year effectiveness review — but PCMLTFA s. 9.6 keeps the compliance program obligation with the business itself. This playbook covers what is commonly delegated, what never leaves the entity, and the four questions (vendor scope, internal review, retained evidence, escalation) an outsourcing file should answer.
Canadian law requires a risk-based compliance program before a regulated product goes live — and that program has to keep pace as the product changes. This playbook walks through the pre-launch checklist (scope, registration, controls, vendors, training, reporting workflow, evidence) and the feature-level AML review that keeps the program true to the product afterward.
FINTRAC examiners test whether the five statutory program elements under PCMLTFA s. 9.6 and PCMLTFR ss. 156–157 actually operated; sponsor banks run commercial diligence on the business model, funds-flow, and MSB scope analysis before onboarding. A single maintained evidence pack — artifacts plus dated proof of operation — serves both, with the framing tailored to each reader.
A compliance calendar turns the PCMLTFR program elements into a monthly and quarterly rhythm with named owners and completion evidence, while a five-step change-management loop — notice, assess, assign, update, evidence — keeps that rhythm current as the law moves. Recent shifts such as armoured-car coverage in 2024 and private-ATM acquirer registration in 2025 show why neither control works without the other.
The PCMLTFA requires every reporting entity to have a compliance program, and the regulations spell out five elements: a compliance officer, written policies and procedures, a risk assessment, training, and a two-year effectiveness review. The harder question is what evidence shows each element genuinely operating rather than sitting in a binder.
Canadian reporting entities must test whether their compliance program actually works at least every two years, under PCMLTFA s. 9.6 and PCMLTFR ss. 156 and 157. The review only earns its keep if every finding becomes a tracked remediation item with an owner, a due date, evidence of completion, and a documented closure approval.
Cheque-cashing businesses became money services businesses under the PCMLTFA on April 1, 2025 — prescribed by PCMLTFR s. 29.1 — bringing FINTRAC registration, a documented compliance program, identity verification, recordkeeping and reporting duties. Here is what each obligation actually requires, and where the exact dollar thresholds live.
Five newly covered sectors — mortgage (October 11, 2024), factors, cheque-cashing and financing or leasing entities (April 1, 2025), and PABM acquirers and title insurers (October 1, 2025) — inherit the full PCMLTFA framework the day their regulations take effect. This guide maps what must exist on day one: correct classification, the s. 9.6 compliance program with a documented s. 156(1)(c) risk assessment, s. 157 special measures, ministerial-directive and sanctions-reporting procedures, and sector-specific records and training.
Since April 1, 2025, factoring companies and financing or leasing entities have been FINTRAC reporting entities in their own right under PCMLTFA s. 5(i) and s. 5(j) — not money services businesses — with a compliance program, documented risk assessment, identity verification and sector-specific reporting and records to build. This guide walks through the scope tests in PCMLTFR ss. 24.1 and 24.15 and how factoring and leasing businesses typically operationalize them, from debtor-side risk assessment to third-party determination.
Since October 1, 2025, providing acquirer services for private automated banking machines makes a business a money services business under PCMLTFA s. 5(h)(iv.1) — written into the Act itself, not the prescribed-services regulation. That status brings FINTRAC registration, a s. 9.6 compliance program with a documented PCMLTFR s. 156 risk assessment, sector record-keeping including s. 33(k), s. 157 special measures for high risk, and immediate coverage by the Iran, Russia and North Korea ministerial directives.
Between October 2024 and October 2025, six business types joined Canada's AML regime in three waves: mortgage administrators, brokers and lenders (October 11, 2024), then factors, cheque cashers and financing or leasing entities (April 1, 2025), then PABM acquirers and title insurers (October 1, 2025). This guide maps each sector to its statutory hook — MSB registration for some, standalone reporting-entity classes for others — and sets out what a newly covered business needs in place from its in-force date.
PCMLTFA s. 5 lists every FINTRAC reporting-entity class — financial entities, securities dealers, life insurance, casinos, real estate, accountants and dealers in precious metals and stones — and since October 2024 the roster has grown to include the mortgage sector, cheque-cashers, factors, financing or leasing entities, PABM acquirers and title insurers. This guide maps who is on the list, what typically triggers each sector's obligations, and the compliance-program core all of them share.
Mortgage administrators, brokers and lenders have had FINTRAC obligations since October 11, 2024, while title insurers came under the regime on October 1, 2025 — two different waves with different sector-specific PCMLTFR provisions. This guide walks through the compliance-program, risk-assessment, beneficial-ownership and directive obligations each sector inherits, and the dates practitioners most often get wrong.