Library
PublishedRisk & SanctionsLast reviewed 2026-07-09 · 7 min read

Geography Risk: Corridors, High-Risk Jurisdictions and Ministerial Directives

Geography is a prescribed factor in every PCMLTFA risk assessment, and three ministerial directives — covering North Korea, Iran and Russia — make every transaction to or from those countries high-risk regardless of amount. This article covers how corridor ratings drive the PCMLTFR s. 157 special measures, what each directive requires, and where sanctions obligations sit relative to the PCMLTFA reporting layer.

Reader question

How should geography shape an AML risk assessment, and what do the ministerial directives require?

Geography is a prescribed risk factor — and the assessment must be documented

Every person or entity covered by section 5 of the PCMLTFA must establish and implement a compliance program (s. 9.6(1)), and that program must include policies and procedures to assess money laundering and terrorist financing risk in the course of the business's activities (s. 9.6(2)). PCMLTFR s. 156(1)(c) turns that into a documentation duty and lists the factors the written assessment must cover: clients, business relationships and correspondent banking relationships; products, services and delivery channels; the geographic location of activities; affiliate risk for financial entities under PCMLTFA paragraphs 5(a) to (g); and any other relevant factor. Geography is item (iii) on that list — not an optional overlay a business adds once it goes international.

A common misreading: "new technologies" is not on that list. New developments and technologies are handled separately by PCMLTFR s. 156(2), which requires the risk to be assessed and documented before the change goes live — and the trigger expressly includes changes that may affect the geographic location of activities. Opening a new send or receive corridor is exactly that kind of change. From March 26, 2026, PCMLTFA s. 9.6(1.1) will also require the program as a whole to be "reasonably designed, risk-based and effective" — a written corridor-by-corridor rationale is part of making that demonstrable.

Rating corridors, and what a high rating triggers

In practice, geography risk is assessed per corridor, not per country in isolation: where funds originate, where they are bound, and what rails and counterparties sit in between. A remittance business serving a single corridor may reasonably rate its home-market activity differently from the receiving side; a payments business adding a new destination should treat that as a s. 156(2) pre-launch assessment, not a post-launch memo. Whatever method you use, record the rating and the reasons — the s. 156(1)(c) obligation is to assess and document.

The rating has consequences. If the business considers a risk high, PCMLTFA s. 9.6(3) requires the prescribed special measures in PCMLTFR s. 157: written policies and procedures for enhanced identity-verification measures based on the assessed risk, and any other enhanced mitigation measure — including keeping client identification and s. 138 beneficial-ownership information up to date, and conducting ongoing monitoring of business relationships at a frequency appropriate to the level of risk. Two drafting traps: s. 157 is a single, undivided section (there is no s. 157(2)), and s. 156(2) is the new-technology pre-assessment, not the high-risk provision.

The three ministerial directives: North Korea, Iran, Russia

Under PCMLTFA s. 11.42, the Minister of Finance has issued three directives currently in force: the Democratic People's Republic of Korea directive (in force December 9, 2017), the Iran directive (in force July 25, 2020, amended February 15, 2024 and November 15, 2025), and the Russia directive (in force February 24, 2024). Their common core: every person or entity referred to in PCMLTFA s. 5 must treat every financial transaction originating from or bound for those countries — regardless of amount — as high-risk for the purposes of s. 9.6(3); verify the identity of any person or entity requesting or benefiting from the transaction; exercise customer due diligence with particular attention to sanctions evasion risk (source of funds or virtual currency, purpose, beneficial ownership); and keep a record of the transaction regardless of amount.

The Iran directive goes further: all such transactions must also be reported to FINTRAC, and correspondent-banking measures apply to PCMLTFA s. 9.4(1) entities. Since the November 15, 2025 amendment, it applies to every s. 5 person or entity, not only financial institutions. Operationally, the directives make the geography rating for you: these corridors are high-risk by law, transaction by transaction, with no dollar floor.

Directives are not sanctions — the PCMLTFA layer is reporting

Sanctions list-screening is not itself mandated by the PCMLTFA or its regulations. The freeze, dealings-prohibition and duty-to-determine obligations flow from the United Nations Act regulations, the Special Economic Measures Act, the Justice for Victims of Corrupt Foreign Officials Act and the Criminal Code. What the PCMLTFA bolts on is reporting: s. 7.1(1) requires a report to FINTRAC whenever a disclosure must be made under Criminal Code s. 83.1, a United Nations Act order or regulation (in force March 1, 2025), a SEMA Part 1 order or regulation, or JVCFOA s. 7(2) (the SEMA and JVCFOA reporting hooks in force October 1, 2025). Separately, s. 7(c) requires a suspicious transaction report where there are reasonable grounds to suspect a transaction is related to a sanctions evasion offence, a term defined in PCMLTFA s. 2(1) by reference to those statutes.

For a geography risk assessment, that means two documented layers: which corridors intersect sanctioned jurisdictions and parties (obligations under the sanctions statutes), and how the business would recognize and report evasion patterns — including activity re-routed through neighbouring corridors — under the PCMLTFA.

High-velocity activity through a corridor: what to ask, when to escalate

Velocity — many transactions through one corridor in a short window — is where geography risk meets ongoing monitoring. PCMLTFR s. 157 does not set numeric thresholds; it requires monitoring at a frequency appropriate to the level of risk, so a high-risk corridor warrants more frequent review and tighter triggers than a low-risk one. Escalation questions worth building into procedures: does the volume and pace fit the client's profile and the stated purpose of the relationship; are funds arriving from or bound for a directive country, or hopping through adjacent corridors in a way consistent with the sanctions evasion risk all three directives flag; and does the pattern reach reasonable grounds to suspect, triggering an STR under s. 7(c)?

Document who asks these questions, when, and what happens next. For sector-specific monitoring indicators and the current text of each directive, check the current FINTRAC guidance on ministerial directives.

At a glance

  • Geographic location of activities is a prescribed risk factor under PCMLTFR s. 156(1)(c)(iii) — the assessment must be written down, not just performed.
  • A high rating triggers PCMLTFA s. 9.6(3) and the special measures in PCMLTFR s. 157: enhanced identity verification, keeping client and beneficial-ownership information current, and monitoring at a risk-appropriate frequency.
  • Three ministerial directives are in force under PCMLTFA s. 11.42 — North Korea (2017), Iran (2020, amended 2024 and 2025) and Russia (2024); each makes every transaction to or from those countries high-risk regardless of amount.
  • The Iran directive additionally requires reporting every in-scope transaction to FINTRAC, and since November 15, 2025 it applies to every PCMLTFA s. 5 person or entity.
  • Sanctions freezes and dealings prohibitions come from the UN Act, SEMA, JVCFOA and Criminal Code — the PCMLTFA adds the reporting layer: s. 7.1(1) reports and s. 7(c) STRs for suspected sanctions evasion.
  • Opening a new corridor can require a pre-launch risk assessment under PCMLTFR s. 156(2) — assess and document before go-live, not after.

Common mistakes

  • Listing "new technologies" as a PCMLTFR s. 156(1)(c) factor — it is not enumerated there; new developments and technologies are covered by the separate pre-implementation assessment in s. 156(2).
  • Citing s. 156(2) as the high-risk provision — the prescribed special measures are in s. 157 (a single, undivided section), triggered by PCMLTFA s. 9.6(3).
  • Applying ministerial-directive controls only above a dollar threshold — all three directives apply regardless of amount, for the high-risk treatment, identity verification and record-keeping alike.
  • Assuming the Iran directive only reaches banks and money services businesses — since November 15, 2025 it applies to every person or entity referred to in PCMLTFA s. 5.
  • Rating only the destination side of a corridor — the directives capture transactions "originating from or bound for" the named countries, so inbound flows count too.
  • Treating a ministerial directive as a sanctions freeze — directives impose enhanced due diligence, records and (for Iran) reporting; dealings prohibitions come from the sanctions statutes, not the PCMLTFA.

Sources

Regulatory anchor: PCMLTFA ss. 7(c), 7.1(1), 9.6(2)–(3), 11.42; PCMLTFR ss. 156(1)(c), 156(2), 157

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.