The AML Evidence Pack: What Banks and FINTRAC Actually Ask For
FINTRAC examiners test whether the five statutory program elements under PCMLTFA s. 9.6 and PCMLTFR ss. 156–157 actually operated; sponsor banks run commercial diligence on the business model, funds-flow, and MSB scope analysis before onboarding. A single maintained evidence pack — artifacts plus dated proof of operation — serves both, with the framing tailored to each reader.
Reader question
What should go in an AML evidence pack when FINTRAC or a bank partner comes asking?
What an evidence pack is — and who asks for it
An AML evidence pack is a curated, maintained set of documents that shows a compliance program exists and actually operates. It is not a binder assembled the week before a review; it is the standing record a business can hand over when someone with leverage asks hard questions.
Four audiences ask, and they ask differently. FINTRAC examiners want to see the statutory program elements operating over time. Sponsor or partner banks run commercial diligence before they will hold your funds or process your flows. Boards want assurance that oversight is real. Investors increasingly treat AML posture as a diligence item in payments and fintech deals. One well-organized pack, tailored per audience, can serve all four.
The regulatory backbone the pack has to map to
Under PCMLTFA s. 9.6, reporting entities must establish a compliance program, and PCMLTFR ss. 156 and 157 set out its required elements: an appointed compliance officer, written policies and procedures, a documented risk assessment, an ongoing training program, and a review of the program's effectiveness every two years.
Those five elements are the spine of the evidence pack. For each one, the pack should hold both the artifact (the policy, the risk assessment, the training deck, the review report) and the proof it was used: approval records, dated version history, attendance logs, findings and the remediation that followed. FINTRAC's compliance program guidance describes what each element should contain; the pack's job is to show each element in motion.
What FINTRAC examinations tend to probe
The recurring theme in examinations is operation, not existence. A policy dated three years ago with no evidence anyone followed it is close to worthless. Stronger evidence looks like: successive dated versions of the risk assessment showing it was revisited when the business changed; training records tied to named staff and dates; the most recent two-year effectiveness review with its findings and what was done about them; and samples of real compliance decisions — an escalation memo, a record of why a flagged transaction was or was not reported.
Businesses that fare better in reviews typically keep this trail as they go. Reconstructing decisions months later is slow, and gaps in the record read as gaps in the program.
What bank partners ask for — and why it is different
Bank diligence is commercial, not a regulatory filing. A sponsor bank is deciding whether your risk becomes its risk, so it starts upstream of the program itself: what the business actually does, a documented funds-flow showing how money moves and who holds it at each step, who the customers are, and a written scope analysis of whether the business is a money services business under the PCMLTFA — with registration status if it is.
The scope analysis deserves care. FINTRAC withdrew its earlier PI-7670 positions on merchant servicing and payment processing effective April 27, 2022 (see the FINTRAC notices of 2022-04-27 and 2022-07-21), so a scope memo that leans on those older interpretations is stale. A payroll platform that briefly holds employer funds, for example, should analyze its position against the current MSB definitions and notices, not a withdrawn policy interpretation.
Beyond scope, banks generally expect the compliance program documents, the risk assessment, and evidence that transaction review actually happens — sample alerts, dispositions, and escalation records. A company that arrives with the funds-flow, scope analysis, and risk assessment already written tends to move through onboarding faster than one that drafts them under deadline.
Building and maintaining the pack
A workable structure is one folder per program element plus one for business context: corporate and product overview, funds-flow diagram, scope analysis, registration record if applicable, then compliance officer appointment, policies, risk assessment versions, training records, effectiveness review, and a sample set of operating evidence such as monitoring outputs and decision memos.
Keep documents dated and versioned, note who approved what and when, and refresh the pack on a schedule rather than on demand — after product launches, new corridors or customer segments, and after each effectiveness review. Tailor the cover narrative to the reader: an examiner wants the statutory elements mapped cleanly; a bank wants the funds-flow and risk story first. The underlying documents stay the same; the framing changes.
At a glance
- An evidence pack is a curated, maintained set of documents proving the AML program exists and operates — for FINTRAC examinations, bank-partner diligence, board oversight, and investor review.
- Its spine is the statutory program: PCMLTFA s. 9.6 and PCMLTFR ss. 156–157 — compliance officer, policies and procedures, risk assessment, training, and a two-year effectiveness review.
- For each element, keep the artifact plus proof of operation: dated versions, approvals, training logs, review findings, and records of real compliance decisions.
- Bank diligence is commercial, not a filing: expect to show the business model, a documented funds-flow, customer types, an MSB scope analysis, and the program and risk assessment.
- Scope analyses should rest on current guidance — FINTRAC withdrew the PI-7670 payment-processing positions effective April 27, 2022.
- Refresh the pack on business change and on schedule; tailor the framing to the reader, not the underlying documents.
Common mistakes
- Assembling documents reactively once a review is announced instead of maintaining a curated, versioned pack.
- Proving policies exist without proving the controls operated — no training logs, no dated risk assessment versions, no decision records.
- Handing the same untailored package to FINTRAC, a sponsor bank, and the board, when each reads it for different things.
- Approaching a sponsor bank without a documented funds-flow, scope analysis, and risk assessment already prepared.
- Relying on the withdrawn PI-7670 payment-processing interpretations in a scope analysis instead of the current FINTRAC notices and guidance.
- Filing the two-year effectiveness review without recording findings and the remediation that followed.
Sources
Regulatory anchor: PCMLTFA s. 9.6; PCMLTFR ss. 156 and 157.
This topic touches archived FINTRAC policy interpretations. Archived interpretations are used for historical context only — not as current authority. Always confirm against current guidance and legislation.
This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.