Library
PublishedControl PlaybooksLast reviewed 2026-07-08 · 5 min read

AML Training That Holds Up: Plan, Content, and Evidence

FINTRAC expects two distinct things: a training program (role-based content on what staff notice, escalate, and record) and a written training plan (who gets trained, how often, and how completion is tracked). This article explains what each element contains, how they differ, and which records businesses typically keep to show training actually happened.

Reader question

What should our AML training program and training plan include, and what evidence of training do we need to keep?

Training is a required program element, not a nice-to-have

Under PCMLTFA s. 9.6, reporting entities must establish a compliance program, and PCMLTFR ss. 156 and 157 set out its elements: an appointed compliance officer, written policies and procedures, a risk assessment, training, and a review of the program's effectiveness every two years. Training sits inside that structure — it is not an HR courtesy layered on top of the real program, it is one of the elements FINTRAC examines directly.

FINTRAC's compliance program guidance treats the training program and the training plan as related but separate elements. The program is the content staff learn; the plan is the written layer that says who learns it, when, how often, and how completion is tracked. A business can fail on either one independently, and in practice the plan is the piece more often missing.

The training program: what staff actually need to learn

Effective content is role-based. The person reviewing transactions, the engineer building the onboarding flow, and the support agent answering customer messages all touch money-laundering risk differently, and a single generic deck serves none of them well. For each role, the content should answer four questions: what should this person notice, when should they escalate, what records should they keep, and how does their work connect to the business's FINTRAC obligations.

Concrete beats abstract. A payroll platform that briefly holds employer funds might train its support team that a request to redirect a payout to a new beneficiary account is an escalation trigger, not a routine ticket — and train its engineers that identity-verification steps in onboarding exist because of specific record-keeping obligations, so they are not quietly optimized away. Training that names the actual products, the actual red flags seen in that business, and the actual escalation path is the kind that changes behaviour.

The training plan: who, when, and how completion is tracked

The training plan is the who/when/how-often document. It typically names the audiences (by role), the content each audience receives, the frequency (at hire, then on an ongoing cadence, plus when products or procedures change), and the method used to track completion. It does not need to be long — a page that maps roles to content, cadence, and a tracking mechanism covers the core of what FINTRAC's guidance describes.

The typical gap is having training materials but no plan: a folder of slides exists, sessions happened at some point, but nothing in writing shows who was supposed to be trained, on what schedule, or whether everyone actually completed it. When the plan is missing, even genuinely good training is hard to demonstrate after the fact.

Evidence: what to keep

Three categories of records do most of the work. First, attendance and completion: who took which training, on what date — a simple log or LMS export is enough. Second, the content itself: keep dated versions of the materials so you can show what a given cohort was actually taught at a given time. Third, testing: quiz results, sign-offs, or another assessment showing the material landed, not just that a session was scheduled.

The practical test is whether you could answer a specific question from records rather than memory — for example, showing that a support hire from last spring completed the escalation module before handling live customers. If the answer lives only in someone's recollection, the evidence element is not yet in place.

Keeping it alive: ongoing training and the effectiveness review

Training is an ongoing obligation, not a launch-day event. Businesses commonly pair onboarding training with a periodic refresher, and retrain when something material changes — a new product, an updated risk assessment, or a revised escalation procedure. The cadence should be written into the plan rather than left to whenever someone remembers.

The two-year effectiveness review required as a program element is also where training gets tested: a review that finds staff missing escalation triggers, or completion records with gaps, points directly at what the next training cycle should fix. Feeding review findings back into training content and the plan is how the element stays honest over time — check the current FINTRAC guidance for the full description of what the review covers.

At a glance

  • Training is one of the required compliance-program elements under PCMLTFA s. 9.6 and PCMLTFR ss. 156 and 157, alongside a compliance officer, policies and procedures, a risk assessment, and the two-year effectiveness review.
  • The training program is the content: role-based, ongoing material covering what each role should notice, when to escalate, what records to keep, and how the role connects to FINTRAC obligations.
  • The training plan is a separate element: a written who/when/how-often layer naming audiences, frequency, and how completion is tracked.
  • Keep three kinds of evidence: attendance/completion logs, dated versions of the content delivered, and testing or assessment results.
  • The most common gap is having materials but no written plan and no completion records — training that happened but cannot be demonstrated.

Common mistakes

  • Delivering one generic session instead of role-based content for operations, engineering, and support.
  • Treating training as a one-time onboarding event rather than an ongoing obligation with a written cadence.
  • Confusing the training program (content) with the training plan (audience, frequency, tracking) — FINTRAC's guidance treats them as separate elements.
  • Completing training without keeping attendance records, dated content versions, or testing evidence.
  • Not recording who completed training and when, so completion cannot be shown after the fact.
  • Failing to retrain when products, procedures, or the risk assessment change.

Sources

Regulatory anchor: PCMLTFA s. 9.6; PCMLTFR ss. 156 and 157.

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.