Library
PublishedControl PlaybooksLast reviewed 2026-07-08 · 5 min read

Outsourcing AML: What You Can Delegate and What You Still Own

Canadian law lets a reporting entity hire out AML tasks — drafting policies, running the risk assessment, conducting the two-year effectiveness review — but PCMLTFA s. 9.6 keeps the compliance program obligation with the business itself. This playbook covers what is commonly delegated, what never leaves the entity, and the four questions (vendor scope, internal review, retained evidence, escalation) an outsourcing file should answer.

Reader question

Can a small fintech outsource its AML compliance work, and what does it still own?

The rule: tasks can move, accountability cannot

Under PCMLTFA s. 9.6, every reporting entity must establish a compliance program that is reasonably designed, risk-based, and effective. The regulations (PCMLTFR ss. 156 and 157) spell out the required elements: an appointed compliance officer, written policies and procedures, a documented risk assessment, ongoing training, and an effectiveness review every two years. Nothing in the Act or regulations transfers those obligations to a vendor. The duty sits with the reporting entity, and when FINTRAC examines the business, its questions go to the business — not to the consultant who drafted the manual.

That is the whole test in one sentence: you can pay someone else to do the work, but you cannot pay someone else to be responsible for it. Everything else in this playbook is about making that distinction visible in your records.

What businesses typically delegate

Outsourcing parts of an AML program is common and often sensible, especially for small teams. Businesses routinely hire external help to draft or update policies and procedures, facilitate the risk assessment, configure screening and transaction-monitoring tools, deliver training, and conduct the two-year effectiveness review — a task where an external reviewer's independence is often a genuine advantage. A three-person money services business hiring a consultant to write its first policy manual is doing something normal, not something suspect.

The compliance officer role deserves care. Appointing a compliance officer is one of the required program elements, and while a business can bring in outside expertise to support that person, the appointment and the authority that goes with it belong to the entity. Check the current FINTRAC guidance on compliance program requirements for how the role is expected to function in practice.

What stays with you no matter who does the work

Decisions stay in-house. Whether a policy accurately describes how your business actually operates, whether the risk assessment's conclusions are accepted, whether a review finding gets fixed or formally accepted as a residual risk, whether a client relationship continues — these are judgments the reporting entity makes and owns. A vendor's deliverable is an input; the outcome is yours.

This matters most when the vendor's product is generic. A policy manual that describes a template business rather than your product — say, a payments startup whose manual discusses cheque cashing it has never offered — signals that no one inside the company read and challenged the draft. Using an external consultant for drafting or testing does not transfer responsibility for the result, so someone internal has to read, question, and approve every deliverable before it becomes part of the program.

The four questions your control framework should answer

For each outsourced task, your records should answer four questions. First, what does the vendor do — scoped in an engagement letter or contract that names the deliverables, timelines, and access to working papers. Second, what does the business review — a named internal reviewer, with dated sign-off showing the deliverable was examined rather than filed. Third, what evidence is retained — versions of deliverables, review notes, and a tracker showing what happened to each finding. Fourth, how do issues escalate — who the vendor tells when it finds a problem, within what timeframe, and who inside the business decides what to do about it.

The escalation path is the piece most often missing. Define it before the vendor finds anything: if the effectiveness review surfaces a gap in record keeping, the reviewer should know exactly who receives that finding and the business should be able to show what management decided in response.

What to document

Keep the engagement scope and contract, each deliverable with its version history, evidence of internal review and approval, management's written response to any findings, and the remediation tracker through to closure. For an outsourced two-year effectiveness review in particular, the reviewer's report is only half the record — the other half is the entity's documented response to it.

In an examination, FINTRAC assesses the reporting entity's program, and "our consultant handled that" is not an answer the file can stand on by itself. What a well-run outsourced arrangement looks like on paper is the same thing an in-house one looks like: the work, the review of the work, and the decision that followed — each dated, each attributable to a person, each retrievable.

At a glance

  • A reporting entity may outsource AML tasks — policy drafting, risk assessment support, training, the two-year effectiveness review — but it cannot outsource accountability for meeting its FINTRAC obligations under PCMLTFA s. 9.6.
  • The required program elements in PCMLTFR ss. 156 and 157 (compliance officer, policies and procedures, risk assessment, training, two-year effectiveness review) remain the business's obligations regardless of who performs the work.
  • For every outsourced task, the control framework should answer four questions: what the vendor does, what the business reviews, what evidence is retained, and how issues escalate.
  • Using an external consultant for drafting or testing does not transfer responsibility for the outcome — an internal reviewer must read, challenge, and approve each deliverable with a dated sign-off.
  • Define the escalation path before the vendor finds anything: who receives a finding, within what timeframe, and who inside the business decides the response.
  • In an examination, FINTRAC assesses the reporting entity's program; retained deliverables, review evidence, and documented management responses are what demonstrate the arrangement was governed.

Common mistakes

  • Assuming that outsourcing a task also outsources accountability for the obligation — the PCMLTFA places the compliance program duty on the reporting entity, not the vendor.
  • Not retaining evidence of what the vendor did and what the business reviewed, leaving nothing to show an examiner beyond the vendor's invoice.
  • Having no defined escalation path when the vendor identifies an issue, so findings stall between the consultant and management.
  • Approving a vendor-drafted policy manual without reading it, so the document describes a generic template business rather than your actual products and channels.
  • Treating an outsourced two-year effectiveness review as finished when the report arrives, without a documented management response and remediation tracking.

Sources

Regulatory anchor: PCMLTFA s. 9.6; PCMLTFR ss. 156 and 157.

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.