Library
PublishedRisk & SanctionsLast reviewed 2026-07-09 · 7 min read

Inherent vs Residual Risk: Scoring Without False Precision

The PCMLTFA never uses the words "inherent" or "residual," but s. 9.6(2) and PCMLTFR s. 156(1)(c) require ML/TF risk to be assessed and documented — and the two-step split is how practitioners keep that documentation honest. This article covers the prescribed factors, why a few defined bands beat decimal scores, how to record residual-risk acceptance, and the refresh triggers the regulation actually anchors.

Reader question

How do inherent and residual risk differ, and how do you score risk without inventing precision?

Two ratings, one book of business

Inherent risk is the money-laundering and terrorist-financing exposure a business carries before any control operates — the raw combination of who its clients are, what its products can move, and where the money touches. Residual risk is what remains after the controls actually in place have done their work. A payments business that lets new customers send funds to higher-risk corridors on day one has high inherent risk in that product line no matter how good its onboarding checks are; whether the residual risk is lower depends on whether those checks, limits and monitoring demonstrably run.

The statute uses neither word. PCMLTFA s. 9.6(2) requires policies and procedures to assess, in the course of the business's activities, the risk of a money laundering or terrorist activity financing offence, and PCMLTFR s. 156(1)(c) requires assessing and documenting that risk. The inherent/residual split is the practitioner convention that keeps the exercise honest: you cannot say what a control is worth until you have written down the exposure without it.

What the regulation actually makes you assess

PCMLTFR s. 156(1)(c) enumerates the factors: (i) clients, business relationships and correspondent banking relationships; (ii) products, services and delivery channels; (iii) the geographic location of activities; (iv) for financial entities referred to in PCMLTFA paragraphs 5(a) to (g), risk resulting from the activities of affiliated entities; and (v) any other relevant factor. A common miscite adds "new technologies" to that list — it is not there. New developments and new technologies carry their own obligation in PCMLTFR s. 156(2): assess and document the risk before the launch, not after.

One forward date matters for how defensible your model needs to be: from March 26, 2026, PCMLTFA s. 9.6(1.1) requires the compliance program to be "reasonably designed, risk-based and effective." A scoring model no one in the business can explain is hard to present as reasonably designed.

Scoring without inventing precision

The operative legal question is coarse. PCMLTFA s. 9.6(3) asks whether the person or entity considers the risk to be high — if so, or in prescribed circumstances, the special measures in PCMLTFR s. 157 follow. Nothing in the provision rewards a second decimal place. In practice, three or four bands with a written definition for each — what puts a client, product or geography in that band, and what falls out of it — do the job. A score of 62.4 implies a measurement the underlying judgments cannot support; an examiner cannot test 62.4 against 58.9, but can test whether a file matches its band definition.

Watch weighted averages, because some ratings are dictated. Three ministerial directives are in force under PCMLTFA s. 11.42 — North Korea, Iran and Russia — and each requires every person or entity referred to in PCMLTFA s. 5 to treat every financial transaction originating from or bound for those jurisdictions, regardless of amount, as high-risk for the purposes of s. 9.6(3). A model that averages a dictated-high geography element with lower factor scores into "medium overall" has produced a number the directive does not permit. Dictated elements need an override, not a weight.

Residual risk acceptance is a documented decision

A residual rating lower than the inherent rating is a claim about controls, so the record should name them: which control absorbs which part of the exposure, and what evidence shows it operating — not just that a policy exists. For anything that stays high, PCMLTFR s. 157 (a single undivided section — citations to a "s. 157(2)" point at nothing) requires written policies and procedures for enhanced measures, based on an assessment of the risk, to verify identity, and any other enhanced mitigation, including keeping client identification and s. 138 beneficial-ownership information up to date and conducting ongoing monitoring of business relationships under s. 123.1 at a frequency appropriate to the level of risk.

The acceptance record itself is short: the inherent rating, the controls relied on to reduce it, who accepted the residual level and when, and the date it will be re-reviewed. Monitoring frequency is part of the promise — a file rated high but reviewed on the same cycle as low-risk files contradicts the "frequency appropriate to the level of risk" standard in s. 157 itself.

Refresh cadence and proving the assessment operates

Two refresh triggers are anchored in the regulation. First, the pre-implementation assessment in PCMLTFR s. 156(2): before carrying out a new development or introducing a new technology that may affect clients, business relationships, products, services, delivery channels or geographic location, assess and document the risk. Second, PCMLTFR s. 156(3) requires a review of the compliance program's effectiveness every two years. Neither provision prescribes an annual refresh; many businesses adopt one as internal policy, and for sector-specific expectations check the current FINTRAC guidance.

Event-driven triggers include the regulatory perimeter itself moving. Obligations for factors, cheque-cashing businesses and financing or leasing entities came into force on April 1, 2025, and for acquirers of private automated banking machines and title insurers on October 1, 2025. When clients, counterparties or partners sit in a newly covered class, the client and product factors in the assessment have changed even if the business itself has not.

Evidence that the risk-based approach is operating — the thing an examiner asks for — is mostly by-products of doing the work: dated versions of the assessment with approval records, s. 156(2) memos dated before the launches they cover, monitoring output at the frequency the ratings promise, and residual-risk acceptance records that match what is actually in the files. If the ratings and the by-products disagree, the assessment is a document, not a process.

At a glance

  • Inherent risk is exposure before controls; residual risk is what remains after controls you can evidence are operating. PCMLTFA s. 9.6(2) and PCMLTFR s. 156(1)(c) require the risk to be both assessed and documented.
  • The prescribed s. 156(1)(c) factors are clients and relationships, products/services/delivery channels, geography, affiliate risk for PCMLTFA 5(a)–(g) financial entities, and any other relevant factor — "new technologies" is not on the list; it has its own pre-implementation assessment in s. 156(2).
  • The regulation's operative question is whether risk is high: PCMLTFA s. 9.6(3) then triggers the PCMLTFR s. 157 special measures — so a few bands with written definitions beat decimal scores an examiner cannot test.
  • Ministerial directives set a floor: every transaction to or from North Korea, Iran or Russia is high-risk regardless of amount, and no weighted average may soften that element.
  • Residual-risk acceptance is a recorded decision: inherent rating, controls relied on, who accepted it, when, and the re-review date.
  • The regulation anchors two refresh triggers — the s. 156(2) pre-launch assessment and the s. 156(3) two-year effectiveness review; perimeter changes such as the 2025 new-sector obligations are practical event-driven triggers.

Common mistakes

  • Citing PCMLTFR s. 156(3) or PCMLTFA s. 9.6(3) for the new-technology assessment — the pre-implementation obligation is s. 156(2); s. 156(3) is the two-year effectiveness review.
  • Listing "new technologies" as an enumerated s. 156(1)(c) risk factor — it is addressed separately by s. 156(2).
  • Citing "PCMLTFR s. 157(2)" — s. 157 is a single undivided section.
  • Scoring residual risk below inherent without naming the control relied on or holding evidence that it operates.
  • Weighted-average models that dilute a ministerial-directive high-risk element (North Korea, Iran, Russia transactions) into a "medium" overall rating.
  • Publishing two-decimal risk scores with no written band definitions — precision the underlying judgments cannot support and an examiner cannot test.

Sources

Regulatory anchor: PCMLTFA s. 9.6(1), (1.1), (2), (3); PCMLTFR ss. 156(1)(c), 156(2), 156(3), 157

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.