Reporting QA: Corrections, Quality and Proof of Filing
Most FINTRAC reporting failures are process failures: a deadline matrix that treats every report like an LCTR, 24-hour aggregation run under one lens instead of three, and no retained proof of what was actually filed. This article turns the verified deadlines and aggregation rules into a pre- and post-submission QA checklist, a correction record worth keeping, and a seeded-scenario script for testing monitoring controls.
Reader question
How do you keep FINTRAC reports accurate — and prove they were filed?
The three ways a filed report goes wrong
Canada's reporting obligations sit in a handful of provisions: PCMLTFA s. 7 (suspicious transactions), s. 7.1 (listed person or entity property), s. 9 (the statutory basis for the prescribed transaction reports — LCTR, EFTR, LVCTR) and s. 9.5 (the EFT travel rule). Quality failures cluster into three types: the wrong report or no report, a missed deadline, and wrong content — most often an aggregation or field error. A useful QA program assigns a check to each failure type rather than reviewing reports impressionistically.
One structural detail trips up many teams: STRs are governed by their own regulation, the Suspicious Transaction Reporting Regulations (SOR/2001-317), not the PCMLTFR. A QA calendar built only from PCMLTFR s. 132 deadlines has a blind spot on STR timing, which lives in SOR/2001-317 s. 9(2).
Before submission: deadline and aggregation checks
Verify the deadline against the report type, not a single house rule. The LCTR is due within 15 days after the day the cash is received (PCMLTFR s. 132(3)). The EFTR is due within five working days after initiation or final receipt (s. 132(1)). The LVCTR is also five working days (s. 132(2)) — not the LCTR's 15 days, a distinction QA calendars frequently get wrong. The STR must be sent 'as soon as practicable' after the entity has taken measures enabling it to establish reasonable grounds to suspect (SOR/2001-317 s. 9(2)) — so document when those assessment measures concluded, because that is when the clock starts. The Listed Person or Entity Property Report is due immediately.
Before filing an LCTR, LVCTR or EFTR, run the 24-hour rule under all three lenses FINTRAC's guidance describes: same conductor, same third party, and same beneficiary (PCMLTFR ss. 126–130). Each lens is assessed separately. Where groupings under different lenses overlap but are not identical, each generates its own report; only identical groupings may share one. The beneficiary lens has carve-outs for public bodies, large listed corporations with $75M+ net assets, and regulated pension-fund administrators.
For STRs, check the grounds are complete: since August 19, 2024, suspected sanctions evasion is a third reporting ground alongside money laundering and terrorist activity financing, filed on the same STR — one report can cover both suspected offences. Confirm the review also caught attempted transactions (PCMLTFA s. 7 covers transactions that occur or are attempted) and that no one screened out a suspicion for being 'too small' — STRs have no monetary threshold.
After submission: what proof of filing looks like
For every report, retain four things: the submission confirmation or reference identifier issued at filing; the filing date recorded next to the computed deadline date, so timeliness is provable without reconstruction; who prepared, reviewed and submitted; and a copy of the report as submitted — not just the case file behind it, because the question an examiner asks is what FINTRAC actually received. The specific acknowledgment artifacts depend on the filing channel, so check the current FINTRAC guidance for each report type.
On who can see this evidence: PCMLTFA s. 8 prohibits disclosing that an STR has been, is being or will be made — or its contents — with intent to prejudice a criminal investigation. It is not an unconditional confidentiality ban, but most businesses restrict STR records by default and log access anyway, which also keeps the proof-of-filing trail intact and attributable.
Corrections: the record matters as much as the fix
When QA, an auditor or an examiner finds an error in a filed report, the correction record should capture: exactly what was wrong (field, value, or aggregation logic); how it was discovered; the dates of discovery and correction; the root cause; and a sweep — whether the same defect exists in other filed reports. A single wrong report is an error; an unswept error class is a program weakness. The mechanics of amending a submitted report vary by report type and filing system, so check the current FINTRAC guidance before assuming a correction path.
Two defects are worth sweeping for specifically because they are systematic rather than one-off. First, a deadline table that applies 15 days to virtual currency reports — the LVCTR deadline is five working days under PCMLTFR s. 132(2). Second, procedures that still reference the 'Terrorist Property Report' — FINTRAC guidance confirms it has been replaced by the Listed Person or Entity Property Report, due immediately, and expanded to cover United Nations Act, Special Economic Measures Act and Justice for Victims of Corrupt Foreign Officials Act listings as well as Criminal Code terrorist lists.
Testing monitoring controls: a seeded-scenario script
The cleanest test of transaction monitoring is a seeded-scenario run: push known inputs through the pipeline and compare expected output to actual. A workable script from the verified thresholds: (1) a single cash receipt of CAD $10,000 should queue an LCTR with a 15-day deadline; (2) two cash receipts by the same conductor totalling $10,000+ within 24 consecutive hours should be deemed a single transaction under PCMLTFR s. 126 and produce one LCTR; (3) a receipt of virtual currency equivalent to $10,000 should queue an LVCTR with a five-working-day deadline; (4) an international EFT of $10,000 should be reportable at both initiation and final receipt within five working days, while a domestic transfer of any size should produce no EFTR; (5) overlapping-but-not-identical 24-hour groupings under different lenses should produce separate reports; (6) an attempted transaction flagged with reasonable grounds to suspect should route to STR review regardless of amount.
Add a scope refresh to the script, because the reporting perimeter has moved recently: mortgage administrators, brokers and lenders came into scope on October 11, 2024; factors, cheque-cashing businesses and financing or leasing entities on April 1, 2025; PABM acquirers and title insurers on October 1, 2025. If the business has started touching any of those activities, monitoring rules and report routing may need to change with it.
Document every test the same way: the input, the expected report and deadline, the actual system behaviour, the remediation if they differ, and the retest date. That record is the evidence that the control was tested — a test without documentation is indistinguishable from no test.
At a glance
- Deadlines differ by report: 15 days for LCTRs (PCMLTFR s. 132(3)), five working days for EFTRs and LVCTRs (s. 132(1)-(2)), 'as soon as practicable' after establishing reasonable grounds to suspect for STRs (SOR/2001-317 s. 9(2)), and immediately for the Listed Person or Entity Property Report
- Pre-submission QA means checking report type, deadline, and 24-hour aggregation under three separate lenses — same conductor, same third party, same beneficiary (PCMLTFR ss. 126-130)
- Proof of filing is a retained record: the submission confirmation, the filing date beside the computed deadline date, who filed and reviewed, and the report as submitted
- A correction record documents what was wrong, how it was found, when it was fixed, the root cause, and a sweep for the same defect in other filed reports
- Test monitoring with seeded scenarios keyed to verified thresholds: $10,000 cash, $10,000 in virtual currency, $10,000 international EFTs, 24-hour aggregation, and attempted-transaction routing to STR review
- STR grounds now include suspected sanctions evasion (effective August 19, 2024); one STR can cover both a money laundering/terrorist financing suspicion and a sanctions evasion suspicion
Common mistakes
- Applying the LCTR's 15-day deadline to LVCTRs — the virtual currency report is due within five working days (PCMLTFR s. 132(2))
- Filing one aggregate report when 24-hour groupings under different lenses (conductor, third party, beneficiary) overlap but are not identical — each lens generates its own report
- Treating domestic transfers as EFTR-reportable — only international EFTs of $10,000+ are reportable, at both initiation and final receipt
- Keeping procedures that reference the 'Terrorist Property Report' — it was replaced by the Listed Person or Entity Property Report, due immediately and now covering sanctions listings
- Describing PCMLTFA s. 8 as a blanket STR confidentiality ban — the prohibition is conditioned on intent to prejudice a criminal investigation, though restricted access remains sensible practice
- Testing only completed transactions above a dollar floor — PCMLTFA s. 7 covers attempted transactions, and STRs have no monetary threshold
Sources
Regulatory anchor: PCMLTFA ss. 7, 7.1, 8, 9, 9.5; PCMLTFR ss. 126-132; SOR/2001-317 s. 9
This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.