Library
PublishedRisk & SanctionsLast reviewed 2026-07-09 · 8 min read

Product, Channel and New-Technology Risk

PCMLTFR s. 156(2) requires a documented ML/TF risk assessment before a new product, delivery channel or technology goes live — a separate trigger from the ongoing s. 156(1)(c) factors it is often confused with. This article covers how to decompose product and channel risk, what a high-risk rating obliges you to do under s. 157, why a launch can change your reporting-entity status entirely, and where fraud risk ends and AML risk begins.

Reader question

How do you assess the AML risk of a new product, delivery channel, or technology before launch?

The rule: assess and document before you go live

Every business caught by section 5 of the PCMLTFA must establish and implement a compliance program (PCMLTFA s. 9.6(1)) that includes policies and procedures to assess, in the course of its activities, the risk of a money laundering or terrorist financing offence (s. 9.6(2)). PCMLTFR s. 156(1)(c) requires that risk to be assessed and documented. The pre-launch piece is PCMLTFR s. 156(2): if you intend to carry out a new development or introduce a new technology that may have an impact on your clients, business relationships, products, services, delivery channels or the geographic location of your activities, you must assess and document that risk before doing so. Timing is the whole point of the provision — launch first, assess later is exactly what it rules out.

Two misconceptions are worth clearing up. First, "new technologies" is not one of the enumerated ongoing risk factors in s. 156(1)(c); new developments and technologies are handled separately by the s. 156(2) pre-implementation assessment. Second, the new-technology rule is sometimes miscited as s. 156(3) — that subsection is actually the two-year compliance-program effectiveness review. One forward-looking note: from March 26, 2026, PCMLTFA s. 9.6(1.1) requires the program to be "reasonably designed, risk-based and effective," and a dated, reasoned pre-launch assessment is one of the clearest ways to evidence design.

First question: does the launch change what you are?

Before rating a new product's risk, check whether it changes your regulatory perimeter — the boundary has moved quickly. Obligations for mortgage administrators, brokers and lenders took effect October 11, 2024; on April 1, 2025, obligations came into force for factors, cheque-cashing businesses and financing or leasing entities; and on October 1, 2025, for acquirers of private automated banking machines and title insurers. The mechanics differ by product: cheque-cashing services are a prescribed MSB service under PCMLTFR s. 29.1, so a business offering them becomes a money services business that must register with FINTRAC; factoring is its own reporting-entity class under PCMLTFA s. 5(i) via PCMLTFR s. 24.1; and financing or leasing is a class under s. 5(j) via PCMLTFR s. 24.15 when the entity finances or leases property (other than real property) for business purposes, passenger vehicles in Canada, or property valued at $100,000 or more. A lending platform that adds an invoice-factoring feature, or a payments business that adds cheque cashing, is not merely adding a row to its risk matrix — it may be acquiring an entirely new set of obligations.

Rating the product and service itself

PCMLTFR s. 156(1)(c) prescribes the factors: (i) clients, business relationships and correspondent banking relationships; (ii) products, services and delivery channels; (iii) the geographic location of activities; (iv) for financial entities under PCMLTFA paragraphs 5(a) to (g), risk from affiliated entities; and (v) any other relevant factor. For a new fintech product, decompose factor (ii) into operational questions: what value moves through the product and how fast it settles; whether it can be funded or drained without the business seeing who is on the other end; whether it can move value to unrelated third parties; whether it touches cash or virtual currency at any point; and which other businesses sit in the flow. The file should record the rating, the reasoning behind it, and the mitigations chosen — so a reviewer can see how you got there, not just where you landed.

Delivery channels: remote onboarding, agents and APIs

A delivery channel is how the product reaches clients, and the same product carries different risk depending on the route: sold face to face, onboarded remotely, distributed through agents, or embedded in another business's app through an API. Remote onboarding removes in-person verification cues and raises impersonation and synthetic-identity exposure. API or embedded distribution puts another business between you and your client, so you inherit the quality of their intake. Because s. 156(2) expressly covers new developments that affect delivery channels, adding a new channel to an existing product triggers the same documented pre-launch assessment as a new product would.

Agent networks concentrate this problem: your obligations are performed by people you do not employ. Treat selection, training, monitoring and records as part of the channel assessment — how agents are vetted before appointment, how they are trained on what to identify and escalate, how their transaction patterns are monitored against expectations, and which records evidence all of it. Agent-specific requirements vary by sector, so check the current FINTRAC guidance for yours. Where any channel is rated high risk, PCMLTFA s. 9.6(3) requires the special measures prescribed by PCMLTFR s. 157: written policies and procedures for enhanced identity-verification measures based on the assessed risk, and other enhanced mitigations — including keeping client identification and beneficial-ownership information up to date and conducting ongoing monitoring of business relationships at a frequency appropriate to the risk level.

Geography and sanctions ride along with every launch

A new channel usually widens geographic reach, which is factor (iii) in its own right. Three ministerial directives are in force under PCMLTFA s. 11.42 — North Korea (December 9, 2017), Iran (July 25, 2020, amended so that as of November 15, 2025 it applies to every person or entity referred to in s. 5) and Russia (February 24, 2024). Each requires treating every transaction originating from or bound for those countries, regardless of amount, as high risk for the purposes of s. 9.6(3), verifying the identity of anyone requesting or benefiting from the transaction, exercising due diligence with particular attention to sanctions evasion, and keeping a record; the Iran directive additionally requires reporting all such transactions to FINTRAC.

Sanctions list-screening itself is not mandated by the PCMLTFA — the freeze, dealings-prohibition and duty-to-determine obligations flow from the United Nations Act regulations, the Special Economic Measures Act, the Justice for Victims of Corrupt Foreign Officials Act and the Criminal Code. But the PCMLTFA bolts FINTRAC reporting onto that regime: s. 7.1(1) requires reporting to FINTRAC when those disclosure duties are triggered (UN Act reporting in force March 1, 2025; SEMA and JVCFOA reporting October 1, 2025), and s. 7(c) requires a suspicious transaction report on reasonable grounds to suspect a sanctions evasion offence. A pre-launch file for any cross-border product should state which corridors the product can reach and how directive and sanctions exposure will be handled.

Fraud risk versus AML risk

Fraud risk is the risk that the business or its customers lose money to deception; managing it is a commercial decision about loss tolerance. AML risk is the risk that the product is used to move proceeds of crime or finance terrorism; assessing it is a legal obligation under PCMLTFA s. 9.6(2), with documentation required by PCMLTFR ss. 156(1)(c) and 156(2). The two overlap heavily in signals — synthetic identities, mule accounts and rapid pass-through activity feed both — and because fraud proceeds are proceeds of crime, fraud detection often supplies the facts behind suspicious transaction reporting decisions.

They are not substitutes. A product can be low-fraud and still attractive for laundering: a money mule using genuine credentials generates no fraud loss for the platform while moving criminal proceeds through it. And fraud tooling, however good, does not produce the documented risk assessment the regulation requires. Run them as connected but distinct assessments, and let each inform the other's controls.

At a glance

  • PCMLTFR s. 156(2) requires you to assess and document ML/TF risk before introducing a new development or technology that may affect your clients, products, services, delivery channels or geography — before launch, not after.
  • "New technologies" is not an enumerated factor in PCMLTFR s. 156(1)(c); the ongoing factors are clients and relationships, products/services/delivery channels, geography, affiliate risk (for financial entities) and any other relevant factor — new tech is the separate s. 156(2) pre-implementation trigger.
  • A high-risk rating engages PCMLTFA s. 9.6(3) and the PCMLTFR s. 157 special measures: enhanced identity verification, keeping client-ID and beneficial-ownership information current, and ongoing monitoring at a risk-appropriate frequency.
  • A new product can change what you are: cheque-cashing (an MSB prescribed service under PCMLTFR s. 29.1), factoring (PCMLTFA s. 5(i)) and financing/leasing (s. 5(j)) obligations came into force April 1, 2025; PABM acquirers and title insurers followed October 1, 2025; the mortgage sector was October 11, 2024.
  • Ministerial directives require treating every transaction from or to North Korea, Iran or Russia as high risk regardless of amount — a new cross-border channel imports that exposure on day one.
  • Fraud controls protect against loss; the AML assessment is a documented legal obligation about ML/TF risk — the two share signals but neither replaces the other.

Common mistakes

  • Launching first and writing the risk assessment afterward — s. 156(2) requires the assessment and documentation before the new product, channel or technology goes live.
  • Citing s. 156(3) as the new-technology provision (it is the two-year program effectiveness review) or treating "new technologies" as an enumerated s. 156(1)(c) factor.
  • Assessing the product but not the channel or geography it opens — a familiar product delivered through a new API partner or into a new corridor is a new risk profile.
  • Assuming a product extension cannot change registration status, when factoring, cheque-cashing, financing/leasing, PABM acquiring and title insurance all became regulated activities in 2024–2025.
  • Rating a channel high risk but never writing the s. 157 special measures — enhanced verification, refreshed IDs and beneficial ownership, risk-tuned monitoring frequency — into policy.
  • Treating fraud tooling as satisfying the AML obligation: fraud detection informs the assessment but does not produce the documented s. 156 analysis the regulation requires.

Sources

Regulatory anchor: PCMLTFA ss. 9.6(1)–(3); PCMLTFR ss. 156(1)(c), 156(2), 157

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.