Library
PublishedControl PlaybooksLast reviewed 2026-07-09 · 7 min read

AML Metrics, Staffing and Budget for Founders

An operating AML program's cost structure is set by PCMLTFR s. 156 — a named compliance officer, maintained policies, a documented risk assessment, a training cycle and a biennial auditor-led effectiveness review — scaled by transaction volumes at the $10,000 and $1,000 record thresholds. This article turns those elements into a metrics dashboard, a staffing model for early-stage MSBs and the recurring budget lines founders and boards should expect.

Reader question

What should founders and boards track, staff, and budget for an AML program that actually operates?

Start with the six program elements the regulation requires

Founders usually ask what an AML program should cost before asking what it must contain. PCMLTFR s. 156(1) answers the second question directly. A reporting entity must: (a) appoint a compliance officer; (b) keep written compliance policies and procedures up to date; (c) document a risk assessment; (d) maintain a written ongoing training program for employees, agents or mandataries and anyone else authorized to act on its behalf; (e) institute and document a training plan and actually deliver the training; and (f) institute and document a plan for a compliance-program effectiveness review. Under s. 156(3), that review must be carried out every two years by an internal or external auditor and its results documented.

Read as a budget, that list is: one named role with real hours attached, a document set someone maintains, a training cycle someone runs and records, and a review someone independent performs on a fixed clock. Everything else — case-management tooling, analysts, outside counsel — scales with volume. These six elements do not go away at any size, so they are the floor of the plan, not a stretch goal.

A dashboard that answers one question: are the obligations operating?

The useful metrics fall straight out of the record triggers. For an MSB: large cash records for $10,000 or more received in a single transaction (PCMLTFR s. 31) and large virtual currency records at the same threshold (s. 32); EFT records at $1,000 or more for transfers the business initiates, sends as an intermediary, or finally receives (s. 36(d)–(f)); records at $1,000 or more for non-EFT remittance and transmission (s. 36(c.1)–(c.2)) and for virtual currency transfers (s. 36(g)–(h)); and an exchange ticket for every foreign currency or virtual currency exchange transaction regardless of amount (s. 36(i)–(j)) — the $3,000 figure many teams remember is not the trigger, it only adds requester details to the FX ticket.

For each trigger, track three numbers monthly: how many records were created, how many are missing required fields, and the age of the oldest unresolved item in any review queue. Add training completion against the documented plan, the date policies were last updated, and a sampled time-to-produce test: s. 149 requires every record to be kept so it can be provided within 30 days of an examination request under s. 62 of the Act. A board that sees trigger counts, exception rates, queue ages and a producibility result can tell whether the program operates. Raw transaction volume alone tells it nothing.

Staffing an early-stage MSB

The only role the regulation names is the compliance officer (s. 156(1)(a)). At an early-stage MSB this is commonly a founder or senior operator, and that is workable — what matters is a documented appointment, genuine authority, and enough recurring hours that the trigger work above actually happens. A practical test: the officer's calendar should visibly contain record QA, queue review, training delivery and policy maintenance, not just the title.

Two forces push headcount past one. The first is volume at the record thresholds — each product line (cash, EFTs, virtual currency, exchange) brings its own trigger set. The second is agents. Every agent, mandatary and branch must appear on the FINTRAC registration with its name, address, services and relationship, and changes to that information must be notified (PCMLTF Registration Regulations, SOR/2007-121, s. 4 and Schedule 1, Part C). Since October 1, 2025, an MSB must also obtain and review criminal-record documents for each agent — for entity agents, the CEO, president, directors and 20%-plus owners — before engaging them and again within 30 days after the second anniversary of the most recent review; the documents must have been issued no more than six months before the review and be retained for five years (PCMLTFA s. 9.93; PCMLTFR s. 37.1). An agent network of any size justifies dedicated hours for this cycle alone.

One structural rule shapes the org chart: the two-year effectiveness review must be conducted by an internal or external auditor (s. 156(3)). The person who wrote the policies should not be grading them, and on a small team that almost always means buying the review externally. FINTRAC's compliance-program guidance also indicates the review should include a look at agreements with agents or mandataries, where applicable — a guidance expectation rather than a prescribed record, but worth scoping into the engagement.

Budget lines that recur

A realistic AML budget has very few one-time items. The recurring lines: the effectiveness review every two years; the training cycle — writing, delivering and documenting it under s. 156(1)(d)–(e), covering agents as well as staff; record storage sized for five-year retention under s. 148, remembering the clock runs from account closure, the last transaction, or record creation depending on the record type, with electronic storage acceptable if a paper copy can readily be produced (s. 147); and the agent criminal-record re-check cycle every two years.

Businesses that only recently became reporting entities should date the budget from their in-force date, not the next fiscal year: cheque-cashing businesses, factors and financing or leasing entities came under the regime on April 1, 2025, and acquirers of private automated banking machines and title insurers on October 1, 2025. For program-content expectations beyond the s. 156 elements, check the current FINTRAC compliance-program guidance rather than working from memory.

What the board pack looks like

One quarterly page is enough if it carries the right numbers: trigger counts by record type against prior quarters; missing-field and exception rates; the oldest unresolved item in each queue; training completion; the dates of the last policy update and last documented risk-assessment refresh (s. 156(1)(b)–(c)); registration currency, including whether agent and branch changes were notified; the latest producibility sample against the 30-day standard; and remediation status for findings from the last effectiveness review. Boards that minute their discussion of this pack are building exactly the documentation trail the next two-year review will examine — the review asks whether the program operated, and the pack is the evidence.

At a glance

  • PCMLTFR s. 156(1) fixes the program skeleton — an appointed compliance officer, current written policies and procedures, a documented risk assessment, written ongoing training covering employees and agents, and a documented plan for the effectiveness review — so staff and budget against those six elements first.
  • Build the metrics dashboard on obligation triggers: records at $10,000 or more (cash and virtual currency received) and $1,000 or more (EFTs, non-EFT remittance and virtual currency transfers), exchange tickets on every FX or VC exchange, plus exception rates, queue ages and training completion.
  • Track producibility as a metric: every record must be retrievable within 30 days of an examination request (PCMLTFR s. 149) and kept for at least five years (s. 148) — sample-test it and report the result.
  • The two-year effectiveness review must be carried out by an internal or external auditor with documented results (s. 156(3)); for early-stage teams that is a recurring external budget line, not a self-assessment.
  • Agents are a distinct cost centre: FINTRAC registration listing and change notifications, plus — since October 1, 2025 — criminal-record checks before engagement and again within 30 days after the second anniversary, using documents issued no more than six months before the review and retained five years (PCMLTFA s. 9.93; PCMLTFR s. 37.1).
  • A one-page quarterly board pack (trigger counts, exceptions, queue ages, training, registration currency, review findings) is both the oversight tool and the evidence the next effectiveness review will examine.

Common mistakes

  • Treating the compliance officer appointment as a paper title — s. 156(1)(a) is an operating role; budget recurring hours for record QA, queues and training, and document the appointment.
  • Building a dashboard of growth metrics (volume, revenue, users) with nothing that shows obligations operating — track exception rates, queue ages and time-to-produce against the 30-day standard instead.
  • Letting the person who built the program conduct the two-year effectiveness review — s. 156(3) requires an internal or external auditor, which on a small team usually means an external engagement.
  • Budgeting for setup and forgetting the recurring items: the biennial review, the training cycle, five-year record storage, and (since October 1, 2025) agent criminal-record re-checks within 30 days after the second anniversary of the last review.
  • Assuming exchange tickets start at $3,000 — a foreign currency exchange transaction ticket is required for every FX transaction; $3,000 only adds requester details to the ticket.
  • Letting the FINTRAC registration go stale as the agent network grows — each agent, mandatary and branch must be listed with services and relationship, and changes must be notified.

Sources

Regulatory anchor: PCMLTFR s. 156(1)(a)–(f) and s. 156(3) (compliance program elements; two-year effectiveness review); PCMLTFR ss. 31, 32, 36, 148, 149 (record triggers, five-year retention, 30-day production); PCMLTFA s. 9.93 with PCMLTFR s. 37.1 (agent due diligence); SOR/2007-121 s. 4 and Sch. 1, Part C (registration of agents and branches).

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.