The Risk-Based Approach: What FINTRAC Expects
Canada's risk-based approach is two documented assessments — one of the business against the prescribed PCMLTFR s. 156(1)(c) factors, one rating each client relationship — that must visibly drive controls, monitoring frequency and training. This article maps PCMLTFA s. 9.6 and PCMLTFR ss. 156–157, the pre-launch assessment for new technologies, and how ministerial directives hard-code part of the geographic rating.
Reader question
What does a risk-based approach actually require a reporting entity to assess and document?
Where the obligation comes from
The risk-based approach is written into the statute, not just guidance. PCMLTFA s. 9.6(1) requires every person or entity referred to in s. 5 to establish and implement a compliance program; s. 9.6(2) requires that program to include policies and procedures "to assess, in the course of their activities, the risk of a money laundering offence or a terrorist activity financing offence"; and PCMLTFR s. 156(1)(c) makes the deliverable concrete: "assessing and documenting" that risk. Both verbs count — an assessment nobody wrote down fails one half, and a document no decision relies on fails the other.
The bar has also risen. PCMLTFA s. 9.6(1.1), in force March 26, 2026, requires the program to be "reasonably designed, risk-based and effective" — a statutory quality standard, not vocabulary. And the population owing this work keeps growing: mortgage administrators, brokers and lenders became reporting entities on October 11, 2024; factors, cheque-cashing businesses and financing or leasing entities on April 1, 2025; acquirers of private automated banking machines and title insurers on October 1, 2025. Each newly covered sector owes a first documented risk assessment, not only reporting and record-keeping mechanics.
The business-based assessment: prescribed factors
The business-based assessment covers the operation as a whole, against the factors prescribed in PCMLTFR s. 156(1)(c): clients, business relationships and correspondent banking relationships; products, services and delivery channels; the geographic location of activities; for financial entities referred to in PCMLTFA paragraphs 5(a) to (g), risk resulting from the activities of affiliated entities; and any other relevant factor. In practice that is an inventory: every product, every channel a client can use to reach it, everywhere funds come from or go to — each element rated, with the reasoning written down.
A persistent misconception: "new technologies" is not an enumerated s. 156(1)(c) factor. New developments and technologies carry their own, sharper obligation in s. 156(2) — if a planned development or new technology may affect your clients, business relationships, products, services, delivery channels or geography, you must assess and document the risk before implementing it. The practical evidence is a dated assessment that precedes launch. And keep s. 156(2) distinct from s. 156(3), which is the separate two-year effectiveness review of the program.
The relationship-based assessment: rating clients and merchants
The second layer rates individual relationships. The clients-and-business-relationships factor is applied by giving each client a risk rating built from the same ingredients as the business-based assessment, scored per relationship. A payments company whose clients are merchants would rate each merchant: what it sells, where it operates and where its own customers sit, how it was onboarded, and how its transaction profile compares with its stated business.
Method matters more than sophistication. Document the rating categories, the factors that feed them, and what moves a relationship between categories, so someone outside the team could reproduce a rating from the file. Re-rate on triggers — a merchant changing lines of business, unexpected geography in the flows — not only on a calendar.
What a high rating triggers
Under PCMLTFA s. 9.6(3), if you consider the risk to be high — or in prescribed circumstances — you must take the special measures referred to in the regulations. Those sit in PCMLTFR s. 157, a single undivided section (the often-cited "s. 157(2)" does not exist): written policies and procedures for taking enhanced measures, based on the assessed risk, to verify identity, and for any other enhanced mitigation measure — expressly including keeping client identification and s. 138 beneficial-ownership information up to date and conducting ongoing monitoring of business relationships (s. 123.1) at a frequency appropriate to the level of risk.
Operationally, the difference between a high-risk and a standard relationship should be visible in the records: shorter refresh cycles for identification and beneficial-ownership information, more frequent monitoring reviews, and file notes showing the enhanced measures actually ran rather than merely existing on paper.
Sanctions and ministerial directives set part of the rating for you
Part of the geographic rating is decided for you. Three ministerial directives are in force under PCMLTFA s. 11.42 — North Korea (December 9, 2017), Iran (July 25, 2020, amended February 15, 2024 and November 15, 2025) and Russia (February 24, 2024). Their common core: treat every financial transaction originating from or bound for those countries, regardless of amount, as high-risk for the purposes of s. 9.6(3); verify the identity of anyone requesting or benefiting from it; apply due diligence with particular attention to sanctions evasion — source of funds or virtual currency, purpose, beneficial ownership; and keep a record regardless of amount. The Iran directive goes further: since November 15, 2025 it applies to every person or entity referred to in s. 5 and requires reporting all such transactions to FINTRAC, with correspondent-banking measures for s. 9.4(1) entities. A risk model that could rate one of these transactions anything but high has a defect.
Sanctions screening itself sits outside the PCMLTFA — the freeze, dealings-prohibition and duty-to-determine obligations flow from the United Nations Act regulations, the Special Economic Measures Act, the Justice for Victims of Corrupt Foreign Officials Act and the Criminal Code. The PCMLTFA bolts reporting onto that regime: s. 7.1(1) requires reporting sanctions-related disclosures to FINTRAC (United Nations Act reporting in force March 1, 2025; SEMA and JVCFOA reporting October 1, 2025), and s. 7(c) requires a suspicious transaction report on reasonable grounds to suspect a sanctions evasion offence, a term defined in s. 2(1). Sanctions-evasion exposure therefore belongs in the assessment as its own line, not a footnote to geography.
Connecting the assessment to policies, controls and training
The assessment is the source document for everything downstream, and the connections should be explicit. A workable pattern is a traceability table: each documented risk maps to the control that mitigates it, the policy section describing that control, and the review step that proves it operates. Section 157 makes the link mandatory at the high end; the two-year effectiveness review in s. 156(3) is where gaps between documented risks and actual controls surface; and the "reasonably designed, risk-based and effective" standard in s. 9.6(1.1) is, in substance, a test of whether that chain holds.
Training closes the loop. Generic typologies with no connection to your products do not prepare staff to spot the risks you documented. Build role-specific content from the assessment itself: the team onboarding merchants trains on the indicators in your merchant-rating model; the team handling cross-border flows trains on the ministerial-directive countries and the escalation path. For the formal requirements of the training program element, check the current FINTRAC guidance on compliance programs — the design principle is that a reader could open your risk assessment and predict what your training covers.
At a glance
- PCMLTFA s. 9.6(2) and PCMLTFR s. 156(1)(c) require you to both assess and document ML/TF risk — the written assessment is the deliverable a reviewer starts from.
- The prescribed factors are clients and business relationships (including correspondent banking), products, services and delivery channels, geography, affiliate risk (financial entities only), and any other relevant factor — "new technologies" is not on that list.
- New developments and new technologies require a separate pre-implementation assessment under PCMLTFR s. 156(2), documented before launch.
- A high rating triggers the PCMLTFA s. 9.6(3) / PCMLTFR s. 157 special measures: enhanced identity verification, keeping identification and beneficial-ownership information up to date, and ongoing monitoring at a risk-appropriate frequency.
- Ministerial directives hard-code every transaction to or from North Korea, Iran or Russia as high-risk regardless of amount; the Iran directive also requires reporting all such transactions to FINTRAC.
- Since March 26, 2026, PCMLTFA s. 9.6(1.1) requires the whole program to be "reasonably designed, risk-based and effective" — controls and training must visibly trace back to the documented risks.
Common mistakes
- Writing a business-based assessment but never rating individual clients or merchants (or the reverse) — PCMLTFR s. 156(1)(c) covers both the business layer and the relationship layer.
- Listing "new technologies" as a s. 156(1)(c) factor and skipping the s. 156(2) pre-launch assessment — the obligation is to assess and document before implementing the new development or technology.
- Citing a non-existent "s. 157(2)" or treating s. 156(2) as the high-risk provision — s. 157 is a single undivided section, and s. 156(2) is the new-technology pre-assessment.
- Rating ministerial-directive countries "medium" in the geographic model, when every transaction to or from North Korea, Iran or Russia must be treated as high-risk regardless of amount.
- High-risk files that look identical to standard files — no shorter refresh cycles or increased monitoring frequency to show the s. 157 special measures actually ran.
- Treating the assessment as a one-time onboarding artifact, with no trigger-based re-rating and no connection to the s. 156(3) two-year effectiveness review.
Sources
Regulatory anchor: PCMLTFA s. 9.6(1)–(3); PCMLTFR ss. 156(1)(c), 156(2) and 157
This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.