Library
PublishedKYC & Due DiligenceLast reviewed 2026-07-09 · 6 min read

Business Relationships and Ongoing Monitoring

A business relationship usually forms the second time you are required to verify a client's identity (PCMLTFR s. 4.1) — and from that moment s. 123.1 requires periodic, risk-based monitoring with four named purposes. This article covers formation triggers, what each monitoring purpose demands in practice, beneficial ownership refresh, and why the expected-activity note you write at onboarding is the baseline the whole regime depends on.

Reader question

When does a business relationship begin, and what does ongoing monitoring actually require after onboarding?

A business relationship starts earlier than most founders expect

The trigger is not an account, a contract, or a certain dollar volume — it is repetition. Under PCMLTFR s. 4.1, a reporting entity enters a business relationship at the earliest of several events, and the one that catches most non-account businesses is s. 4.1(b): the second time the business is required to verify the client's identity under the Regulations. FINTRAC's business relationship guidance frames this as the second identity verification within a 5-year period — that 5-year window is guidance framing, not text you will find in s. 4.1 itself. A caution for anyone reading older material: 'business relationship' was once defined in PCMLTFR s. 1(2), but that definition was repealed by SOR/2019-240. Formation is now governed entirely by s. 4.1.

For a money services business, the second verification arrives quickly because the identification triggers in PCMLTFR s. 95(1) sit at low thresholds — for example, a request to initiate an electronic funds transfer of $1,000 or more (s. 95(1)(b)) or a foreign currency exchange of $3,000 or more (s. 95(1)(c)). A remittance customer who sends two $1,000-plus transfers a month apart has typically put the business into a business relationship on the second transfer. And where an MSB's client is an entity, s. 4.1(d) starts the relationship the moment a service agreement is entered for services under subparagraphs 5(h)(i)–(v) of the Act — no second transaction required (s. 4.1(e) is the parallel rule for foreign MSBs).

What ongoing monitoring actually requires under s. 123.1

Once the relationship exists, PCMLTFR s. 123.1 requires the business to periodically conduct ongoing monitoring of it, based on the risk assessment undertaken under PCMLTFA s. 9.6(2) in accordance with paragraph 156(1)(c). The section names four purposes, and each is a distinct workstream: (a) detecting transactions that must be reported; (b) keeping client identification information — and the beneficial ownership and other information referred to in ss. 138 and 145 — up to date; (c) reassessing the client's risk level; and (d) determining whether transactions or activities are consistent with the client information and the risk assessment.

Notice what the regulation does not say: it does not prescribe a review frequency. 'Periodically' is calibrated by your own risk assessment, which means the compliance program has to state the schedule — for example, more frequent reviews for higher-risk clients, less frequent for lower-risk — and the file has to show the reviews happened. For clients rated high risk, s. 157 layers on special measures, including enhanced ongoing monitoring (FINTRAC's guidance points to subparagraph 157(b)(ii)).

Keeping client information up to date: risk-based, documented

Purpose (b) is the one businesses most often under-build. Keeping information 'up to date' means periodically re-checking the identification details, and — for entity clients — the beneficial ownership picture. PCMLTFR s. 138(2) requires reasonable measures to confirm the accuracy of beneficial ownership information both when it is first obtained and in the course of ongoing monitoring; it is not a one-time onboarding artifact. If ownership information cannot be obtained or confirmed, s. 138(4) requires reasonable measures to verify the identity of the entity's chief executive officer (or whoever performs that function) and to apply the s. 157 special measures — FINTRAC's guidance describes this as treating the client as high risk. Since October 1, 2025, s. 138.1 adds a further step for CBCA corporations assessed as high risk: material discrepancies with the Corporations Canada individuals-with-significant-control database must be reported to the CBCA Director within 30 days.

In practice, businesses run tiered refresh cycles keyed to the risk rating and record three things for each review: what was checked, what changed, and what the new risk rating is. The regulation leaves the cycle length to you; for sector-specific expectations on frequency, check the current FINTRAC ongoing monitoring guidance.

Expected activity profiles: why onboarding notes carry the regime

Purpose (d) of s. 123.1 asks whether transactions are 'consistent with the information obtained about the client' — which only works if you recorded expectations in the first place. An onboarding note stating the client's stated purpose, expected transaction types, typical amounts, frequency, and destination corridors is the baseline every later review is measured against. Without it, a reviewer two years on has no way to say whether the activity drifted.

The profile also drives the other three purposes. When a client profiled as sending modest monthly family remittances starts moving much larger amounts to new jurisdictions, the deviation is the prompt to reassess the risk level (purpose (c)) and to consider whether anything crosses a reporting threshold (purpose (a)). Third-party signals belong in the same file: PCMLTFR ss. 134–137 require third-party determinations at specific record-keeping trigger points, and where a determination cannot be made but suspicion exists, the reasons must be recorded — records that must be kept at least 5 years under s. 148(1)(c).

When a business relationship ends

Ongoing monitoring attaches to the relationship, so its endpoint matters. FINTRAC's guidance states that a non-account business relationship ends when at least 5 years have passed since the last transaction that required identity verification. Until then, the periodic monitoring, information refresh, and risk reassessment obligations continue — which is why many businesses maintain a dated relationship register showing when each relationship formed, its current risk rating, its last review, and its computed end date. That single document answers most examiner questions about this obligation before they are asked.

At a glance

  • Under PCMLTFR s. 4.1(b), a business relationship forms at the earliest trigger — most commonly the second time you are required to verify a client's identity; FINTRAC guidance frames this as the second verification within a 5-year period.
  • For an MSB whose client is an entity, entering a service agreement for MSB services starts the business relationship immediately under s. 4.1(d)–(e) — no second transaction needed.
  • Ongoing monitoring under PCMLTFR s. 123.1 has four purposes: detect reportable transactions, keep client identification and beneficial ownership information up to date, reassess the client's risk level, and check activity against the client's profile.
  • Monitoring is 'periodic' and risk-based — the frequency comes from your risk assessment under PCMLTFA s. 9.6(2), not from a fixed calendar in the regulation, so your program must state and evidence the schedule.
  • Beneficial ownership accuracy must be re-confirmed in the course of ongoing monitoring (s. 138(2)); if it cannot be confirmed, verify the CEO's identity and apply the s. 157 high-risk special measures (s. 138(4)).
  • Per FINTRAC guidance, a non-account business relationship ends once at least 5 years have passed since the last transaction that required identity verification.

Common mistakes

  • Citing the old PCMLTFR s. 1(2) 'business relationship' definition — it was repealed by SOR/2019-240; formation is now governed by s. 4.1.
  • Treating the 5-year window for the 'second verification' as regulation text — it is FINTRAC guidance framing of s. 4.1(b), which itself sets no time limit.
  • Missing that an entity service agreement starts an MSB's business relationship on day one under s. 4.1(d), before any transaction occurs.
  • Reducing ongoing monitoring to transaction screening and ignoring the information-update and risk-reassessment purposes in s. 123.1(b)–(c).
  • Confirming beneficial ownership once at onboarding and never again — s. 138(2) requires reasonable measures to confirm accuracy in the course of ongoing monitoring as well.
  • Recording no expected-activity profile at onboarding, leaving the consistency check in s. 123.1(d) with no baseline to measure against.

Sources

Regulatory anchor: PCMLTFA s. 6.1; PCMLTFR ss. 4.1 (business relationship formation), 123.1 (ongoing monitoring), 138–138.1 (beneficial ownership and discrepancy reporting), 157 (high-risk special measures)

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.