DeFi Interfaces, Staking and Token Listings: Scope and Risk Questions
Canadian AML law never names DeFi, staking or token listings — MSB scope under PCMLTFA s. 5(h) turns on what a product actually does with users' virtual currency, and once in scope the obligations arrive as concrete dollar triggers: $1,000 identity verification, $10,000 third-party determinations, $100,000 PEP screening. A token listing decision is a risk-assessment exercise: can you still monitor, value and identify for that asset, and can you show your work.
Reader question
Do DeFi interfaces and staking products trigger FINTRAC obligations, and how do you risk-assess a token listing?
The Act tests functions, not product labels
The PCMLTFA does not contain the words "DeFi," "staking" or "token listing." What it contains is a list of services in s. 5(h) (s. 5(h.1) for foreign businesses) that make a person or entity a money services business, which must then register with FINTRAC. The list is extended by regulation: PCMLTFR s. 29.1, for example, prescribes crowdfunding platform services and cheque-cashing services under subparagraphs 5(h)(v) and (h.1)(v). So the scope question is functional, not about what the product calls itself.
The review a founder should actually run: at any point, does the product receive, hold, exchange or transmit users' funds or virtual currency? A front-end that only displays data and routes transactions a user signs from their own wallet raises different questions than one that pools user assets, executes exchange transactions from accounts it controls, or takes custody during a lock-up. Where a design sits near the line, check the current FINTRAC guidance for money services businesses — and recheck it periodically, because the perimeter moves. Obligations for cheque-cashing businesses, factors and financing or leasing entities came into force on April 1, 2025, and acquirer services for private automated banking machines were written into the Act's MSB definition itself (PCMLTFA s. 5(h)(iv.1)) with obligations from October 1, 2025.
In scope means dollar-figure triggers, not abstractions
Once a business is an MSB, virtual currency obligations attach at exact thresholds under PCMLTFR s. 95(1): verify a person's identity on a transfer of $1,000 or more in virtual currency (s. 95(1)(d)), on a virtual currency exchange transaction of $1,000 or more (s. 95(1)(e)), and when someone is the beneficiary of a virtual currency transfer of $1,000 or more (s. 95(1)(f)). Verification uses one of the five methods in s. 105(1) — government-issued photo ID, government-source information, credit file, dual-process, or affiliate/member — five, not the commonly repeated three. Documents used must be authentic, valid and current (s. 105(5)).
Large receipts carry extra duties: s. 84 requires verifying the identity of the person or entity from which a large virtual currency amount is received, and receiving virtual currency equivalent to $10,000 or more triggers both a large virtual currency transaction record and reasonable measures to determine whether the client is acting for a third party (s. 135). Entity clients — a fund, a corporate treasury staking through your product — are verified under s. 109(1) (corporations) or s. 112(1) (other entities), and an entity service agreement creates an information record with its own third-party determination under s. 137.
Staking and yield products create relationships, not just transactions
A staking client transacts repeatedly — deposits, reward distributions, unstaking — so they cross the identity-verification triggers more than once. Under PCMLTFR s. 4.1(b), a business relationship forms the second time you are required to verify a client's identity; FINTRAC's guidance frames this as the second time within a five-year period, a qualifier that comes from guidance rather than the regulation text. For entity clients, an MSB forms a business relationship the moment it enters a service agreement for listed services (s. 4.1(d)).
Once the relationship exists, s. 123.1 requires ongoing monitoring keyed to your risk assessment under PCMLTFA s. 9.6(2): detecting reportable transactions, keeping client information up to date, reassessing the client's risk level, and testing whether activity is consistent with the client's profile. High-risk clients get enhanced monitoring under the s. 157 special measures. Staking actually helps here — lock-up terms and reward schedules give you a predictable expected pattern, so deviations such as a sudden unstake-and-withdraw to a fresh address, or a staking position funded by someone other than the client, are precisely what the monitoring should surface.
Large positions bring in PEP screening: an MSB must take reasonable measures to determine politically-exposed-person or head-of-international-organization status when a person requests a transfer of $100,000 or more in virtual currency or is the beneficiary of a receipt of $100,000 or more (s. 120(1)). Where the determination is positive for a politically exposed foreign person, or a high-risk domestic PEP or HIO (or their family members and close associates), you must establish the source of the funds or virtual currency and the person's source of wealth and have senior management review the transaction — within 30 days of the transaction (s. 122(9)). A common misconception puts this at 14 days; no such rule exists.
Risk-assessing a token listing
No provision prescribes a token-listing checklist. The anchor is the risk assessment the Act already requires under s. 9.6(2) — the same assessment that calibrates your ongoing monitoring. The practical test for each candidate token: can you still perform every obligation you owe while supporting it? Can your tools trace flows in this token well enough to detect reportable transactions (s. 123.1(a))? Can you value and aggregate receipts reliably enough to catch the $10,000 large-virtual-currency threshold and the $1,000 identification triggers? Anonymity-enhancing features, thin liquidity that makes valuation unstable, and opaque or unreachable issuers all degrade those capabilities — which is exactly why they are risk factors rather than mere reputational concerns.
Issuer diligence can borrow the entity-verification frame. If the issuing entity becomes a client or counterparty, verification runs through s. 109(1) and beneficial ownership through s. 138: names of all directors, names and addresses of everyone owning or controlling 25% or more, and information on ownership, control and structure, with accuracy confirmed at intake and during ongoing monitoring. If that information cannot be obtained or confirmed, s. 138(4) requires verifying the identity of the chief executive officer and applying the s. 157 special measures. Since October 1, 2025, material discrepancies against the federal individuals-with-significant-control database for CBCA corporations assessed as high risk must be reported within 30 days (s. 138.1). A token whose issuer would fail these mechanics is telling you something before the first trade settles.
What to document
Keep the records the regulations name: how each identity was verified, keyed to the method used (s. 108); third-party determination records for at least five years (s. 148(1)(c)); and PEP determination and special-measures records (s. 123). Then add two documents no section names but that make every later conversation shorter: a dated scope memo describing what the product actually does with user assets at each step, revisited whenever the product or the regulations change; and a listing memo per token recording the factors weighed, the decision, and the monitoring plan for that asset. Where a question falls outside these provisions — such as the current treatment of a specific non-custodial design — check the current FINTRAC guidance before building on an assumption.
At a glance
- The PCMLTFA never uses the words "DeFi," "staking" or "token listing" — scope turns on whether the business actually receives, holds, exchanges or transmits users' funds or virtual currency under the MSB definition in PCMLTFA s. 5(h).
- In scope, the triggers are concrete: verify identity on virtual currency transfers or exchanges of $1,000 or more (PCMLTFR s. 95(1)(d)–(f)), identify the source of large virtual currency receipts (s. 84), and make a third-party determination on receipts of $10,000 or more (s. 135).
- Staking clients transact repeatedly, so a business relationship typically forms at the second required identity verification (s. 4.1(b)) — pulling in ongoing monitoring under s. 123.1 keyed to your s. 9.6(2) risk assessment.
- PEP/HIO screening triggers at virtual currency transfers or receipts of $100,000 or more (s. 120(1)); the special-measures deadline is 30 days after the transaction (s. 122(9)), not the often-quoted 14 days.
- Token listing review is a risk-assessment exercise: test each token against your actual ability to monitor, value, aggregate and identify — then document the decision in a listing memo.
- The MSB perimeter is amended regularly (new reporting-entity classes came into force April 1 and October 1, 2025), so recheck current FINTRAC guidance rather than relying on an old scope analysis.
Common mistakes
- Assuming a "non-custodial" label settles FINTRAC scope without a written analysis of what the interface actually does with user assets at each step of the flow.
- Treating staking as a one-off transaction product when repeat deposits and reward payouts form a business relationship carrying ongoing-monitoring duties under s. 123.1.
- Listing a token because peer platforms list it, with no memo showing the risk factors weighed or how transaction monitoring will actually work for that asset.
- Quoting "three methods" of identity verification — PCMLTFR s. 105(1) lists five.
- Applying a 14-day PEP deadline that doesn't exist — the s. 122 measures are due within 30 days of the transaction (s. 122(9)).
- Falling back to a "most senior managing officer" when beneficial ownership can't be confirmed — s. 138(4) requires verifying the chief executive officer and applying the s. 157 special measures.
Sources
Regulatory anchor: PCMLTFA ss. 5(h), 9.6(2); PCMLTFR ss. 4.1, 84, 95(1)(d)–(f), 105, 109, 120, 122, 123.1, 134–138.1
This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.