Library
PublishedControl PlaybooksLast reviewed 2026-07-08 · 6 min read

The Compliance Operating Rhythm: Calendar and Regulatory Change

A compliance calendar turns the PCMLTFR program elements into a monthly and quarterly rhythm with named owners and completion evidence, while a five-step change-management loop — notice, assess, assign, update, evidence — keeps that rhythm current as the law moves. Recent shifts such as armoured-car coverage in 2024 and private-ATM acquirer registration in 2025 show why neither control works without the other.

Reader question

How do small teams turn FINTRAC obligations into a compliance calendar and a regulatory change-management process?

One obligation, two moving parts

PCMLTFA s. 9.6 requires a compliance program that is reasonably designed, risk-based, and effective, and PCMLTFR ss. 156–157 name its elements: an appointed compliance officer, written policies and procedures, a risk assessment, ongoing training, and a review of the program's effectiveness at least every two years. None of those elements is a one-time deliverable. A risk assessment written at launch decays as products change; training completed at onboarding fades as staff turn over; policies drift out of date as guidance moves.

In practice, small teams keep the program alive with two connected controls. A compliance calendar gives the program its pulse — it converts the standing obligations into scheduled, owned, recurring work. A regulatory change-management process keeps the calendar itself correct when FINTRAC guidance or the legislation changes. Each is weaker without the other: a calendar that never absorbs new obligations schedules the wrong work, and a change process with no operating rhythm has nowhere to land its updates.

What belongs on the calendar

The calendar's job is to make sure nothing depends on someone remembering. Typical monthly items: a reporting quality check (sample recent reports for completeness and timeliness), and a review of open remediation items so identified gaps actually close. Typical quarterly items: training progress against the plan, a check on registration details and renewal timing, and reviews of vendors that touch compliance functions such as identity verification or screening.

Slower cycles matter most, because nothing in daily operations prompts them. The calendar should carry the risk-assessment refresh (and the triggers that force an earlier one, such as a new product or corridor), the periodic policy-and-procedure review, and — critically — the two-year effectiveness-review clock, scheduled far enough ahead that scoping and independence questions are settled before the deadline arrives.

Every entry needs two fields beyond a date: an owner and a pointer to completion evidence. A payroll platform that briefly holds employer funds might run this as a shared task list where each item links to the artifact produced — the QA sample, the training records, the signed-off review. An item marked done with nothing behind it is a wish list, not a control.

The change-management loop

Regulatory change management is a five-step loop: notice the change, assess its impact, assign an owner, update the affected controls, and keep evidence. The first step is the one most small businesses lack entirely — a deliberate way to learn that FINTRAC guidance or the legislation has moved, such as a named person responsible for reviewing FINTRAC's published updates and checking the current consolidations on Justice Laws.

Assessment asks three questions: does the change alter who is covered, what must be reported or recorded, or how existing controls must operate? The answer drives the update: policies and procedures, training content, the risk assessment, and sometimes registration itself. Assigning a named owner with a deadline is what separates a process from a news feed — a change that everyone read but nobody owns changes nothing.

Keep evidence at every step, including when the conclusion is "no impact on us." A short change log — what changed, when it was noticed, the assessment, the decision, and the updates made — is the record that the loop actually ran.

Why the loop is not optional: recent changes

The past few years show how obligations arrive between effectiveness reviews. Businesses transporting currency or certain negotiable instruments (armoured-car services) became reporting entities effective July 1, 2024. Acquirer services for private automated banking machines became a registerable MSB/FMSB activity in force October 1, 2025. And change runs both directions: FINTRAC withdrew its long-standing PI-7670 policy positions on merchant servicing and payment processing effective April 27, 2022, so businesses that had structured their analysis around that interpretation needed to reassess against the current statutory tests.

Each of these is a different species of change — new sector coverage, a new registration trigger, and a withdrawn interpretation — and none of them would surface through the calendar alone. A business that checks its obligations only when it first registers, or only at the two-year review, can run a stale program for months without knowing it.

What to document

The working set is small: the calendar itself with owners, due dates, and completion status; the evidence each completed item points to; the change log with impact assessments and resulting updates; and notes from any meeting where a change decision was made. Version-date policy documents so it is clear which version was in force when.

This documentation pays for itself twice. Day to day, it is how a two-person team hands work across vacations and turnover without dropping obligations. At the two-year effectiveness review required by PCMLTFR ss. 156–157, it is the raw material: the reviewer can see what was scheduled, what was done, what changed in the regulatory environment, and how the program responded. A program that can show its operating rhythm is answering the effectiveness question with records rather than recollection.

At a glance

  • PCMLTFA s. 9.6 and PCMLTFR ss. 156–157 require a program that stays effective over time — a compliance calendar and a change-management process are how small teams operationalize that.
  • The calendar schedules the recurring work: reporting QA, training, registration checks, vendor reviews, remediation tracking, the risk-assessment refresh, policy reviews, and the two-year effectiveness-review clock.
  • Every calendar item needs a named owner and a link to completion evidence — an item marked done with nothing behind it is not a control.
  • Regulatory change management is a five-step loop: notice the change, assess impact, assign an owner, update the affected controls, keep evidence.
  • Recent in-force dates — armoured-car coverage July 1, 2024, private-ATM acquirer registration October 1, 2025, and the April 27, 2022 withdrawal of PI-7670 — show obligations move between effectiveness reviews, in both directions.
  • Record "no impact" conclusions too: the assessment itself is the evidence the process ran.

Common mistakes

  • Treating FINTRAC obligations as a static onboarding checklist instead of a scheduled recurring rhythm with owners and dates.
  • Omitting the slow-cycle items — risk-assessment refresh, two-year effectiveness-review timing, vendor reviews — because nothing in daily operations prompts them.
  • Marking calendar items complete with no evidence attached, leaving nothing to show at the effectiveness review.
  • Having no defined way to notice FINTRAC guidance or legislative changes until a bank or examiner asks about one.
  • Noticing a change but assigning no owner, so policies, training, and the risk assessment quietly go stale.
  • Keeping no record of the impact assessment — including when the conclusion was that no change was needed.

Sources

Regulatory anchor: PCMLTFA s. 9.6; PCMLTFR ss. 156 and 157.

This topic touches archived FINTRAC policy interpretations. Archived interpretations are used for historical context only — not as current authority. Always confirm against current guidance and legislation.

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.