Library
PublishedRisk & SanctionsLast reviewed 2026-07-09 · 8 min read

High-Risk Clients and Enhanced Measures

Rating a client high-risk under PCMLTFA s. 9.6 is not the end of the exercise — it triggers the mandatory PCMLTFR s. 157 special measures: enhanced identity verification, current beneficial-ownership information, and monitoring at a frequency matched to the risk. This article covers how to rate against the s. 156(1)(c) factors, what the three ministerial directives impose regardless of your model, and how PSPs review merchants and nested MSB clients.

Reader question

How do you identify high-risk clients and what enhanced measures does the regulation expect?

Where the high-risk obligation comes from

Every person or entity covered by section 5 of the PCMLTFA must establish and implement a compliance program (PCMLTFA s. 9.6(1)), and that program must include policies and procedures to assess, in the course of the business's activities, the risk of a money laundering or terrorist activity financing offence (s. 9.6(2)). PCMLTFR s. 156(1)(c) turns that into a documentation duty: the risk must be assessed and documented, not just held in someone's head.

The high-risk trigger sits in PCMLTFA s. 9.6(3): if you consider the risk to be high — or in prescribed circumstances, such as those set by ministerial directive — you must take the special measures referred to in the regulations. Those special measures live in PCMLTFR s. 157. One more date worth diarizing: a new PCMLTFA s. 9.6(1.1) comes into force on March 26, 2026, requiring the compliance program to be "reasonably designed, risk-based and effective" — a shift from having a program on paper to being able to show that it works.

Identifying high-risk clients: the prescribed factors

PCMLTFR s. 156(1)(c) prescribes the factors the assessment must consider: (i) clients, business relationships and correspondent banking relationships; (ii) products, services and delivery channels; (iii) the geographic location of activities; (iv) for financial entities under PCMLTFA paragraphs 5(a) to (g), risk from the activities of affiliated entities; and (v) any other relevant factor. A common misreading adds "new technologies" to this list — it is not an enumerated factor. New developments and new technologies get their own obligation under PCMLTFR s. 156(2): if a change may affect your clients, business relationships, products, services, delivery channels or geography, you must assess and document the risk before implementing it.

In practice, businesses translate the factors into a client rating with a written rationale: what the client does, how funds move (cash-intensive, cross-border, third parties transacting through the client), where the client and its counterparties are located, and how the relationship was established. The document that survives review is the one that names the factor, states the evidence, and records the resulting rating and date — so that when the rating changes, the file shows why.

Enhanced measures: what section 157 actually requires

PCMLTFR s. 157 is a single, undivided section — there is no s. 157(2), despite how often one is cited. It requires developing and applying written policies and procedures for (a) taking enhanced measures, based on the assessed risk, to verify identity, and (b) taking any other enhanced measure to mitigate the risks — expressly including keeping client identification information and section 138 beneficial-ownership information up to date, and conducting the ongoing monitoring of business relationships (s. 123.1) at a frequency appropriate to the level of risk.

The operational work is defining what "enhanced" means in your program before an examiner asks. Typical choices: shorter refresh cycles for identification and beneficial-ownership information on high-risk files, senior approval to onboard or retain the relationship, closer transaction review, and asking about source of funds where the risk warrants it. Whatever you choose, record which measure applied to which client, when it ran, and what it found — an enhanced measure that leaves no record is indistinguishable from one that never happened.

Clients and transactions that are high-risk by law, not by your model

Three ministerial directives are in force under PCMLTFA s. 11.42: North Korea (in force December 9, 2017), Iran (in force July 25, 2020, amended February 15, 2024 and November 15, 2025 — and since November 15, 2025 the Iran directive applies to every person or entity referred to in PCMLTFA s. 5), and Russia (in force February 24, 2024). Their common core: treat every financial transaction originating from or bound for those countries, regardless of amount, as high-risk for the purposes of s. 9.6(3); verify the identity of anyone requesting or benefiting from the transaction; exercise due diligence with particular attention to sanctions-evasion risk; and keep a record regardless of amount. The Iran directive additionally requires reporting every such transaction to FINTRAC and imposes correspondent-banking measures on PCMLTFA s. 9.4(1) entities. Your risk model cannot rate these down.

Sanctions screening itself is a neighbouring regime: the freeze and dealings-prohibition duties flow from the United Nations Act regulations, the Special Economic Measures Act, the JVCFOA and the Criminal Code — but the PCMLTFA bolts reporting on. Section 7.1(1) requires reporting to FINTRAC when a disclosure is required under those regimes (UN Act reporting in force March 1, 2025; SEMA and JVCFOA reporting in force October 1, 2025), and s. 7(c) requires a suspicious transaction report on reasonable grounds to suspect a sanctions evasion offence.

Merchant portfolios and nested MSB risk

A payment service provider reviewing merchants applies the same s. 156(1)(c) lens one level down: what the merchant actually sells, through which channels, where its payment flows originate and settle, and — critically — whether the merchant provides money services to its own customers. That last question is the nested-MSB problem: when your client is itself moving funds for end-parties you never see, your visibility into who is really transacting stops at your client's edge, which is exactly the situation the s. 157 enhanced measures are built for.

Two recent perimeter changes sharpen this review. Since April 1, 2025, cheque-cashing services are a prescribed MSB service under PCMLTFR s. 29.1, so a business providing them is an MSB under PCMLTFA s. 5(h)/(h.1) and must register with FINTRAC. And since October 1, 2025, acquirers of private automated banking machines are covered directly by the Act's MSB definition (PCMLTFA s. 5(h)(iv.1) and (h.1)(iv.1)). For a client whose activity looks like money services, the practical controls are: confirm FINTRAC registration where the law requires it, understand the client's own compliance program well enough to rely on the relationship, and set the monitoring frequency to the risk. Where it is unclear whether a client's activity makes it an MSB, check the current FINTRAC guidance rather than guessing — the perimeter has moved several times in the last two years.

At a glance

  • PCMLTFA s. 9.6(2) requires assessing and, via PCMLTFR s. 156(1)(c), documenting ML/TF risk; once a client is rated high, PCMLTFA s. 9.6(3) makes the PCMLTFR s. 157 special measures mandatory, not discretionary.
  • Rate clients against the prescribed s. 156(1)(c) factors — clients and business relationships (including correspondent banking), products/services/delivery channels, geography, affiliated entities for financial entities, and any other relevant factor. "New technologies" is not on that list; it has its own pre-implementation assessment under s. 156(2).
  • PCMLTFR s. 157 requires written policies for enhanced identity verification plus other risk-mitigating measures — expressly including keeping client ID and s. 138 beneficial-ownership information current and ongoing monitoring at a frequency appropriate to the risk.
  • Three ministerial directives (North Korea, Iran, Russia) under PCMLTFA s. 11.42 force every transaction to or from those countries, regardless of amount, to be treated as high-risk; the Iran directive also requires reporting each such transaction to FINTRAC.
  • A client that provides money services to its own customers is nested-MSB risk: end-parties transact through your rails unseen. Cheque-cashing became a prescribed MSB service on April 1, 2025, and PABM acquirers came into scope October 1, 2025 — confirm registration and apply s. 157 measures.
  • From March 26, 2026, PCMLTFA s. 9.6(1.1) requires the whole compliance program to be "reasonably designed, risk-based and effective" — documentation of how measures actually ran becomes the evidence.

Common mistakes

  • Citing "new technologies" as a PCMLTFR s. 156(1)(c) risk factor — it is not enumerated there; new developments and technologies trigger a separate pre-implementation assessment under s. 156(2), done before launch.
  • Referring to "PCMLTFR s. 157(2)" for enhanced measures — s. 157 is a single, undivided section, and PCMLTFR s. 156(2) is the new-technology assessment, not the high-risk provision.
  • Treating enhanced measures as a one-time onboarding step — s. 157 expressly requires keeping identification and beneficial-ownership information up to date and monitoring at a frequency matched to the risk, for as long as the relationship stays high-risk.
  • Letting the internal risk model outrank ministerial directives — every transaction originating from or bound for North Korea, Iran or Russia is high-risk regardless of amount and regardless of how the client is otherwise rated.
  • Rating a merchant on its storefront while missing that it provides money services to its own customers — cheque-cashing, for example, has been a prescribed MSB service requiring FINTRAC registration since April 1, 2025.
  • Assuming sanctions list-screening is itself a PCMLTFA obligation — the dealings prohibitions come from the United Nations Act regulations, SEMA, the JVCFOA and the Criminal Code; the PCMLTFA adds FINTRAC reporting (s. 7.1(1)) and the sanctions-evasion STR ground (s. 7(c)).

Sources

Regulatory anchor: PCMLTFA ss. 9.6(2)–(3), 7(c), 7.1(1), 11.42; PCMLTFR ss. 156(1)(c), 156(2), 157

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.