Library
PublishedRisk & SanctionsLast reviewed 2026-07-09 · 8 min read

Source of Funds and Source of Wealth

Source of funds traces the specific money in a transaction; source of wealth explains how the client built everything they own. Neither is a universal ask — the duty flows from the risk-based approach in PCMLTFA s. 9.6 and PCMLTFR ss. 156–157, and becomes non-negotiable for transactions touching North Korea, Iran or Russia under the ministerial directives.

Reader question

What is the difference between source of funds and source of wealth, and when must you ask about each?

Two different questions about the same money

Source of funds and source of wealth sound interchangeable and are not. Source of funds asks where the money in a specific transaction or account came from: the activity that generated it and the path it travelled — this quarter's revenue from a client's landscaping contracts, the proceeds of selling a truck, an insurance settlement. Source of wealth asks a much bigger question: how did this person or entity accumulate everything they own? Typical answers are years of professional income, the sale of a business, inheritance, or long-term investment growth.

The cleanest way an analyst can explain the distinction: source of funds answers "where did this particular $40,000 come from?"; source of wealth answers "why does this client have money at all?" The two can diverge sharply. A wire from the client's own chequing account has an obvious immediate source but says nothing about the wealth sitting behind it. Conversely, a well-documented inheritance explains a client's net worth without explaining why one payment arrived through three intermediary accounts. A file that verifies one while silently assuming the other is where examiners find gaps.

Where the obligation actually comes from

Canadian law contains no single provision commanding every business to collect source of wealth from every client. The obligation is built from the risk-based approach. PCMLTFA s. 9.6(1) requires every reporting entity to establish and implement a compliance program, and s. 9.6(2) requires that program to include policies and procedures to assess money laundering and terrorist financing risk in the course of the business's activities. PCMLTFR s. 156(1)(c) then requires that risk to be assessed and documented across prescribed factors: clients, business relationships and correspondent banking relationships; products, services and delivery channels; the geographic location of activities; affiliate risk for financial entities referred to in PCMLTFA paragraphs 5(a) to (g); and any other relevant factor.

When the entity considers a risk identified under s. 9.6(2) to be high, PCMLTFA s. 9.6(3) requires the special measures prescribed in PCMLTFR s. 157: written policies and procedures for enhanced identity-verification measures based on an assessment of the risk, and for any other enhanced measure to mitigate the risks — including keeping client identification and s. 138 beneficial-ownership information up to date and conducting ongoing monitoring of business relationships (s. 123.1) at a frequency appropriate to the level of risk. Source-of-funds and source-of-wealth inquiries are the archetypal "other enhanced measure": the deeper the risk, the further back up the money's history the file should reach. Two drafting traps worth flagging: s. 157 is a single undivided section (there is no s. 157(2)), and PCMLTFR s. 156(2) is not the high-risk provision — it is the separate obligation to assess and document risk before launching a new development or new technology.

Politically exposed persons and heads of international organizations carry their own dedicated source-of-funds and source-of-wealth requirements with specific triggers and timing; those sit outside this article's citation pool, so check the current FINTRAC guidance on politically exposed persons before writing PEP procedures.

When asking stops being optional: ministerial directives

Three ministerial directives issued under PCMLTFA s. 11.42 are currently in force: North Korea (in force December 9, 2017), Iran (in force July 25, 2020, amended February 15, 2024 and November 15, 2025 — since that last amendment it applies to every person or entity referred to in PCMLTFA s. 5), and Russia (in force February 24, 2024). Their common core removes discretion: every financial transaction originating from or bound for those countries, regardless of amount, must be treated as a high-risk transaction for the purposes of PCMLTFA s. 9.6(3). That means verifying the identity of any person or entity requesting or benefiting from the transaction, exercising customer due diligence with particular attention to sanctions-evasion risk — expressly including the source of funds or virtual currency, the purpose of the transaction, and beneficial ownership — and keeping a record regardless of amount. The Iran directive additionally requires reporting every such transaction to FINTRAC.

Directive-driven source-of-funds work also feeds the reporting regime: where the inquiry produces reasonable grounds to suspect a transaction is related to a sanctions evasion offence (defined in PCMLTFA s. 2(1)), a suspicious transaction report is required under PCMLTFA s. 7(c), and s. 7.1(1) separately requires reporting to FINTRAC whenever a disclosure duty arises under the underlying sanctions statutes.

Purpose and intended nature: the third question

Alongside the two backward-looking money questions sits a forward-looking one: what is this business relationship for? Recording the purpose and intended nature of a relationship is what makes everything downstream workable. Ongoing monitoring at a risk-appropriate frequency (PCMLTFR ss. 157 and 123.1) only detects anything if there is a documented baseline to compare actual activity against. "General business banking" as a stated purpose can never flag a deviation; "monthly supplier payments to two named jurisdictions, expected volume under $50,000" can — the moment an inbound transfer arrives from an unrelated country, the mismatch itself is the trigger for a source-of-funds inquiry. In practice, purpose is the tripwire, source of funds is the investigation it launches, and source of wealth is the escalation when the explanation still does not add up. For the precise record-keeping particulars required for business relationships, check the current FINTRAC guidance.

What to collect, corroborate and write down

Most programs tier the work. At standard risk: record the stated purpose of the relationship and, where the product warrants it, a declared source of funds. At higher risk: corroborate rather than accept — pay statements, sale agreements, financial statements, probate records — and reserve full source-of-wealth workups for the highest tiers and for directive-covered transactions where the law leaves no choice. What matters as much as asking is documenting why your triggers sit where they do: PCMLTFR s. 156(1)(c) requires the risk to be assessed and documented, and the new PCMLTFA s. 9.6(1.1) (in force March 26, 2026) will require the program to be "reasonably designed, risk-based and effective" — a standard that can only be demonstrated from written rationale, not from an analyst's habit.

This is especially live for sectors recently brought into the regime — mortgage brokers, lenders and administrators (October 11, 2024), factors, cheque-cashing businesses and financing or leasing entities (April 1, 2025), and title insurers and acquirers of private automated banking machines (October 1, 2025). A financing company writing its first compliance program should define its source-of-funds triggers, evidence tiers and escalation path before the first high-risk file arrives, not while it is open.

At a glance

  • Source of funds explains the origin of the specific money in a transaction or account; source of wealth explains how the client accumulated their overall net worth. A file can verify one and still leave the other unexplained.
  • No provision requires either question for every client. The obligation flows from the risk-based approach — assess and document risk under PCMLTFA s. 9.6(2) and PCMLTFR s. 156(1)(c) — and hardens into required enhanced measures for high-risk relationships under PCMLTFA s. 9.6(3) and PCMLTFR s. 157.
  • Ministerial directives under PCMLTFA s. 11.42 make source-of-funds diligence mandatory for every transaction originating from or bound for North Korea, Iran or Russia, regardless of amount, with identity verification and a record kept; the Iran directive also requires reporting each transaction to FINTRAC.
  • Purpose and intended nature of the relationship is the forward-looking third question: it sets the expected-activity baseline that ongoing monitoring (PCMLTFR s. 123.1) measures deviation against — and deviation is what triggers a source-of-funds inquiry.
  • Politically exposed person rules attach their own source-of-funds and source-of-wealth requirements; check the current FINTRAC guidance for the exact triggers and timing.
  • Write down what you ask, what evidence you accept at each risk tier, and why. From March 26, 2026, PCMLTFA s. 9.6(1.1) requires programs to be "reasonably designed, risk-based and effective" — demonstrable only from documented rationale.

Common mistakes

  • Treating the terms as interchangeable — verifying which account the money arrived from (funds) while never explaining how the client accumulated the balance behind it (wealth), or vice versa.
  • Accepting "it came from their bank account" as a source of funds. The account is a channel; the question is what activity generated the money that sits in it.
  • Collecting source of wealth from every client "to be safe." Blanket collection without documented risk rationale creates friction and files you cannot defend; the risk-based approach calls for calibrated, written triggers.
  • Citing PCMLTFR s. 156(2) as the high-risk enhanced-measures provision. It is the new-technology pre-assessment; high-risk special measures live in PCMLTFA s. 9.6(3) and PCMLTFR s. 157 (a single undivided section).
  • Applying internal dollar thresholds to directive-covered transactions. Any transaction originating from or bound for North Korea, Iran or Russia is high-risk regardless of amount, with source-of-funds attention and a record required however small it is.
  • Recording the purpose of a relationship as a generic label. A purpose statement that cannot be contradicted by real activity gives ongoing monitoring nothing to detect.

Sources

Regulatory anchor: PCMLTFA ss. 9.6(2)–(3), 11.42; PCMLTFR ss. 156(1)(c), 157

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.