The FINTRAC Compliance Program: the Five Required Elements
The PCMLTFA requires every reporting entity to have a compliance program, and the regulations spell out five elements: a compliance officer, written policies and procedures, a risk assessment, training, and a two-year effectiveness review. The harder question is what evidence shows each element genuinely operating rather than sitting in a binder.
Reader question
What are the required elements of a FINTRAC compliance program, and what does each one look like when it actually works?
Five elements, and why you sometimes hear six
PCMLTFA s. 9.6 requires every reporting entity to establish a compliance program, and PCMLTFR ss. 156 and 157 set out its elements: an appointed compliance officer, written policies and procedures, a risk assessment, training, and an effectiveness review every two years. That is the list a FINTRAC examiner works from, and it applies whether you are a bank or a three-person money services business.
You will sometimes see the count given as six. That version splits training in two: the training program (the content staff actually learn) and the training plan (who gets trained, how often, and how completion is tracked). Current FINTRAC guidance treats these as distinct expectations even though the regulation counts training once. The honest reconciliation is simple — however you count, you need both the material and a written plan for delivering it. A business with a slide deck but no schedule, audience list, or completion records has half an element.
The compliance officer: a role, not a title
Appointing someone by name satisfies nothing on its own. The officer needs real authority, adequate resources, and working knowledge of the business and its risks — a payments founder who wears the hat part-time can meet this, but only if the role has substance behind it.
The evidence that matters: documented decision rights (can the officer block a risky customer or product change?), escalation access to senior management or the board, defined reporting lines, and the practical ability to update controls when something changes. The recurring gap FINTRAC examinations surface is the named-only officer — a person listed in the policy manual with no defined responsibilities, no escalation path, and no record of ever making a compliance decision.
Policies, procedures, and the risk assessment
Written policies and procedures must describe what your business actually does, not what a template vendor assumed. If your product briefly holds employer payroll funds, or settles in virtual currency, or onboards customers entirely remotely, the documents should say so and describe the controls for those specific flows. A generic program that never mentions your real products is a finding waiting to happen.
The risk assessment is the element the others hang from. FINTRAC's risk-based-approach guidance expects you to identify and document the money-laundering and terrorist-financing risks of your products, delivery channels, customers, and geographies, then show how your controls respond to the higher-risk areas. When the risk assessment and the procedures visibly disagree — the assessment flags remote onboarding as high risk, but the procedures apply the same checks everywhere — that inconsistency itself is what an examiner will pull on.
Training: the program and the plan
Training is where the six-element framing earns its keep, because businesses routinely build one half and not the other. The program is content: what money laundering looks like in your product, what staff must do when they see it, and what the reporting obligations are. The plan is logistics: which roles get trained, at what frequency, how new hires are covered, and how completion is recorded.
What businesses typically keep as evidence: dated training materials versioned to the current procedures, an attendance or completion log, and a short written plan naming audiences and frequency. Frontline staff who can describe, in their own words, what they would do with a suspicious transaction are worth more at examination time than any certificate.
The two-year effectiveness review — and who owns the program
Every two years the program must be tested for effectiveness. The point is not to confirm the documents exist; it is to test whether the controls operate — sampling real onboarding files, checking that flagged transactions were escalated, verifying training actually happened. The review needs enough independence to be credible: someone who did not build the controls, whether an external reviewer or an internal person outside the compliance function.
Senior management approval is how the business — not just the compliance function — shows it owns the program. Useful approval records capture what was approved, who approved it, what risks were discussed, and when the next review is due. A board minute that says 'compliance update noted' evidences almost nothing; one that records the risk assessment version, the discussion of a new product's exposure, and a dated follow-up does the job.
For structure, many small fintechs borrow a simplified three-lines-of-defence model: the first line (operations) owns day-to-day controls, compliance guides and challenges, and independent review tests whether the program works. This is a governance framework, not a FINTRAC-mandated structure — the aim is role clarity a five-person team can sustain, not bank-scale committees. Kept that light, it maps neatly onto the five elements: the first line runs the procedures, the officer challenges, and the two-year review is the third line doing its job.
At a glance
- PCMLTFA s. 9.6 requires a compliance program; PCMLTFR ss. 156 and 157 list its five elements: a compliance officer, written policies and procedures, a risk assessment, training, and a two-year effectiveness review.
- Current FINTRAC guidance effectively splits training into a program (content) and a plan (audience, frequency, tracking) — some summaries count six elements, and you need both halves either way.
- The compliance officer needs documented authority, resources, and business knowledge — decision rights, escalation access, and reporting lines, not just a name in the policy manual.
- Policies and the risk assessment must describe your actual products and flows; a template that never mentions what you really do is a standing examination finding.
- The two-year review should test whether controls operate — sampled files, escalation records, training logs — and be done by someone who did not build the controls.
- Management approval records should show what was approved, who approved it, what risks were discussed, and when the next review is due.
Common mistakes
- Treating the program as a document to produce rather than controls that operate day to day — a binder built for show, disconnected from the actual business model.
- Having training material but no training plan: no defined audience, frequency, new-hire coverage, or completion tracking.
- Appointing a compliance officer in name only, with no decision rights, escalation access, or evidenced responsibilities.
- Keeping approval records that do not show who approved what, when, what risks were discussed, or when the next update is due.
- Skipping independent testing — no one outside the control-builders ever checks whether the program actually works.
- Building bank-scale governance a small team cannot sustain, then letting first-line ownership and second-line challenge blur into one person doing everything unchecked.
Sources
Regulatory anchor: PCMLTFA s. 9.6; PCMLTFR ss. 156 and 157.
This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.