Library
PublishedSector GuidesLast reviewed 2026-07-09 · 8 min read

Day-One Compliance for Newly Covered Sectors

Five newly covered sectors — mortgage (October 11, 2024), factors, cheque-cashing and financing or leasing entities (April 1, 2025), and PABM acquirers and title insurers (October 1, 2025) — inherit the full PCMLTFA framework the day their regulations take effect. This guide maps what must exist on day one: correct classification, the s. 9.6 compliance program with a documented s. 156(1)(c) risk assessment, s. 157 special measures, ministerial-directive and sanctions-reporting procedures, and sector-specific records and training.

Reader question

You just became a FINTRAC reporting entity — what has to exist on day one?

Which sectors came in, and on what dates

Canada's reporting-entity perimeter expanded in three waves. Obligations for the mortgage sector — mortgage administrators, mortgage brokers and mortgage lenders — came into force on October 11, 2024 (a date that now lives on FINTRAC's mortgage sector page, not its 'changes' page, which trips up people hunting for it). On April 1, 2025, obligations came into force for factors, cheque-cashing businesses, and financing or leasing entities under SOR/2025-68. On October 1, 2025, the remaining regulations brought in acquirers of private automated banking machines (PABMs) and title insurers.

The in-force date is when the obligations start — so a business that only recently realized it is caught should treat the gap between that date and today as a documented remediation item, not something to quietly backfill.

Confirm which class you fall into — it changes what day one looks like

Cheque-cashing services are a prescribed money services business (MSB) service: PCMLTFR s. 29.1 designates them (alongside crowdfunding platform services) for PCMLTFA s. 5(h)(v) and (h.1)(v). A business providing cheque-cashing services is therefore an MSB or foreign MSB and must register with FINTRAC.

Factors and financing or leasing entities are frequently mislabeled as MSBs — they are not. A factor is its own reporting-entity class under PCMLTFR s. 24.1 and PCMLTFA s. 5(i), with sector obligations in PCMLTFR ss. 24.11–24.14 and identity verification in s. 93.1. A financing or leasing entity is covered under PCMLTFR s. 24.15 and PCMLTFA s. 5(j) when it finances or leases property (other than real property or immovables) for business purposes, passenger vehicles in Canada, or property valued at $100,000 or more; its obligations sit in PCMLTFR ss. 24.16–24.2 and s. 93.2.

PABM acquirer services are written directly into the Act's MSB definition at PCMLTFA s. 5(h)(iv.1) and (h.1)(iv.1), with 'private automated banking machine' defined in s. 2(1). Title insurers received their own provisions via SOR/2024-267 (PCMLTFR ss. 64.7–64.8 and 102.2), and the mortgage sector's sit at PCMLTFR ss. 64.1–64.6.

The compliance program and risk assessment that must exist on day one

PCMLTFA s. 9.6(1) requires every person or entity referred to in s. 5 to establish and implement a compliance program, and s. 9.6(2) requires that program to include policies and procedures to assess money laundering and terrorist financing risk in the course of the business's activities. PCMLTFR s. 156(1)(c) makes that assessment a written artifact: you must assess and document the risk.

The prescribed factor categories are: clients, business relationships and correspondent banking relationships; products, services and delivery channels; the geographic location of activities; affiliate risk (only for financial entities under PCMLTFA s. 5(a)–(g)); and any other relevant factor. Note that 'new technologies' is not on that list — new developments and new technologies are handled by a separate pre-implementation assessment under PCMLTFR s. 156(2), which requires you to assess and document the risk before launching anything that may affect your clients, products, channels or geography. PCMLTFR s. 156(3) then requires an effectiveness review of the program every two years.

For the other program elements — a compliance officer, written policies, training and review — check the current FINTRAC compliance guidance for your sector. And plan ahead: from March 26, 2026, new PCMLTFA s. 9.6(1.1) requires the program to be 'reasonably designed, risk-based and effective,' which raises the bar from having documents to being able to show they work.

High-risk ratings trigger written special measures

If you rate a risk as high under PCMLTFA s. 9.6(2), s. 9.6(3) requires the special measures in the regulations. Those live in PCMLTFR s. 157 — a single, undivided section (citations to a 's. 157(2)' are wrong). It requires written policies and procedures for enhanced identity verification measures based on the assessed risk, and any other enhanced mitigation measures, including keeping client identification and s. 138 beneficial-ownership information up to date and conducting ongoing monitoring of business relationships (s. 123.1) at a frequency appropriate to the risk level. Practically: for each high-risk segment in your day-one risk assessment, the file should show what extra step is taken, how often, and where it is recorded.

Ministerial directives and sanctions reporting bind from your in-force date

Three ministerial directives issued under PCMLTFA s. 11.42 are in force: North Korea (December 9, 2017), Iran (July 25, 2020, amended February 15, 2024 and November 15, 2025 — since that last amendment it applies to every person or entity referred to in s. 5), and Russia (February 24, 2024). Their common core: treat every financial transaction originating from or bound for those countries, regardless of amount, as high-risk for s. 9.6(3) purposes; verify the identity of anyone requesting or benefiting from it; apply customer due diligence with particular attention to sanctions evasion risk; and keep a record regardless of amount. The Iran directive additionally requires reporting all such transactions to FINTRAC.

Sanctions list-screening itself is not mandated by the PCMLTFA — the freeze, dealings-prohibition and duty-to-determine obligations flow from the United Nations Act regulations, the Special Economic Measures Act, the Justice for Victims of Corrupt Foreign Officials Act and the Criminal Code. But the PCMLTFA bolts reporting onto that regime: s. 7.1(1) requires a report to FINTRAC whenever you must make a disclosure under those instruments (UN Act reporting in force March 1, 2025; SEMA and JVCFOA reporting in force October 1, 2025), and s. 7(c) requires a suspicious transaction report where there are reasonable grounds to suspect a transaction relates to a sanctions evasion offence as defined in s. 2(1). A newly covered business needs a screening procedure and an escalation path for these on day one, not in quarter two.

Records and training: build both from your sector's own sections

A workable recordkeeping matrix is just your sector's regulation sections turned into rows: factors map ss. 24.11–24.14 and 93.1; financing or leasing entities map ss. 24.16–24.2 and 93.2; the mortgage sector maps ss. 64.1–64.6; title insurers map ss. 64.7–64.8 and 102.2; PABM acquirers include s. 33(k). Add a row for ministerial-directive transaction records, which apply regardless of amount. For the exact record fields and retention periods in each section, check the current FINTRAC guidance for your sector before drafting.

Day-one training follows the same map. Staff need to know: which provision makes the business a reporting entity and what activity triggers it (for a financing or leasing entity, for example, the $100,000 property threshold and the passenger-vehicle and business-purpose prongs); the s. 156(1)(c) factor categories their observations feed; how to recognize a transaction touching North Korea, Iran or Russia at any amount; when suspicion of a sanctions evasion offence requires escalation toward an STR; and what s. 157 special measures apply to high-risk files. Keep dated records of who was trained on what — under the effectiveness standard arriving in March 2026, undocumented training is hard to defend.

At a glance

  • Coverage arrived in three waves: the mortgage sector on October 11, 2024; factors, cheque-cashing businesses and financing or leasing entities on April 1, 2025; PABM acquirers and title insurers on October 1, 2025.
  • Classification drives day one: cheque-cashing is a prescribed MSB service (PCMLTFR s. 29.1) requiring FINTRAC registration, while factors (s. 24.1) and financing or leasing entities (s. 24.15) are separate reporting-entity classes under PCMLTFA s. 5(i) and 5(j) — not MSBs.
  • Day one requires an established, implemented compliance program (PCMLTFA s. 9.6(1)) with a documented risk assessment covering clients, products/services/channels, geography and other relevant factors (PCMLTFR s. 156(1)(c)).
  • High-risk ratings require written special measures under PCMLTFR s. 157: enhanced identity verification, up-to-date beneficial-ownership information, and risk-calibrated ongoing monitoring.
  • Ministerial directives (North Korea, Iran, Russia) and sanctions-linked reporting under PCMLTFA s. 7.1(1) and s. 7(c) apply from your in-force date — directive transactions are high-risk and recorded regardless of amount, and the Iran directive has applied to every s. 5 entity since November 15, 2025.
  • From March 26, 2026, PCMLTFA s. 9.6(1.1) requires the program to be 'reasonably designed, risk-based and effective' — documents alone won't be enough.

Common mistakes

  • Registering a factoring or financing/leasing business as an MSB — those are separate reporting-entity classes under PCMLTFA s. 5(i) and 5(j); only cheque-cashing routes through the MSB definition via PCMLTFR s. 29.1.
  • Listing 'new technologies' as a PCMLTFR s. 156(1)(c) risk factor — new developments and technologies belong to the separate pre-implementation assessment in s. 156(2).
  • Citing 'PCMLTFR s. 157(2)' for high-risk special measures — s. 157 is a single, undivided section.
  • Deferring ministerial-directive procedures because exposure seems unlikely — directive obligations apply to every transaction regardless of amount, and the Iran directive has covered every PCMLTFA s. 5 entity since November 15, 2025.
  • Assessing risk without documenting it — s. 156(1)(c) requires assessing and documenting, and the assessment is typically the first artifact an examiner asks for.
  • Treating the compliance program as a one-time launch deliverable — PCMLTFR s. 156(3) requires a two-year effectiveness review, and s. 9.6(1.1)'s 'reasonably designed, risk-based and effective' standard arrives March 26, 2026.

Sources

Regulatory anchor: PCMLTFA ss. 5, 7(c), 7.1(1), 9.6, 11.42; PCMLTFR ss. 24.1–24.2, 29.1, 64.1–64.8, 156–157

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.