Third-Party Determination — and KYB for Merchants and Agents
Third-party determination under PCMLTFR ss. 134–137 asks who a transaction is really for, while merchant and agent KYB verifies the business itself — its existence, directors and 25% beneficial owners — under ss. 109, 112 and 138. This article covers the exact triggers and records for each, why signing a merchant service agreement starts a business relationship for an MSB, and why a low-risk rating never switches off the fixed identification thresholds in s. 95.
Reader question
How do you determine whether someone is acting on behalf of a third party, and what should payment companies collect for merchant and agent KYB?
Third-party determination: asking who the transaction is really for
A third party, for AML purposes, is a person or entity that gives instructions for a transaction or is the one the transaction is really being conducted for — even though someone else is standing in front of you (or filling in your onboarding form). Third-party determination is governed by PCMLTFR ss. 134–137. A common citation error puts the range at 134–138; s. 138 is actually beneficial ownership, a different test entirely. Beneficial ownership asks who owns or controls your client. Third-party determination asks who is behind a specific transaction or arrangement.
The triggers that matter to payment companies and MSBs: when you receive $10,000 or more in cash (s. 134) or the equivalent in virtual currency (s. 135), you must take reasonable measures to determine whether the person is acting on behalf of a third party. Section 137 applies whenever an information record must be kept — which for MSBs includes entity service agreements — and requires the same determination. Section 136, the account-opening trigger, applies to financial entities, securities dealers and casinos, not MSBs.
"Reasonable measures" in practice usually means asking a direct question at onboarding or at the transaction — "Are you conducting this on behalf of anyone else?" — and paying attention to what you can see. Build the question into your flow and record the answer either way.
On-behalf-of records: what to write down, including when you can only suspect
Where there is a third party, subsections 134(2)–137(2) require you to record: for a person, their name, address, date of birth and occupation or nature of principal business; for an entity, its name, address, nature of principal business, registration or incorporation number and the jurisdiction and country of issue — plus, in every case, the relationship between the third party and your client. Keep these records at least five years (s. 148(1)(c)).
The rule people miss: even when you cannot determine that a third party is involved, if you have reasonable grounds to suspect one, subsections 134(3)–137(3) require a record of whether the client states they are acting on their own behalf only, and your reasons for the suspicion. "They said no" is not the end of the obligation — the suspicion itself gets documented.
Typical signals: a bookkeeper depositing cash collected from someone else's business, a customer reading transfer instructions off a phone mid-transaction, or an account funded by one person while a different person directs where the money goes. None of these prove a third party exists; each is a reason to ask and to write down what you learned.
Merchant KYB: what a payment company collects and verifies
When a payment company signs up a business, entity verification comes first. A corporation is verified under PCMLTFR s. 109(1) by referring to its certificate of incorporation, an annual filing required under provincial securities legislation, or the most recent version of another record that confirms its existence and contains its name, address and directors' names. FINTRAC guidance also accepts a certificate of active corporate status, a signed published annual report, or a government letter or notice of assessment. Entities other than corporations are verified under s. 112(1) — partnership agreement, articles of association, or another record confirming existence, name and address. In each case the record must be authentic, valid and current (ss. 109(2), 112(2)) — that standard sits in the regulation itself, not just guidance.
Beneficial ownership comes next (s. 138): obtain the names of all directors and the names and addresses of everyone who owns or controls, directly or indirectly, 25% or more of the corporation's shares (25% or more of a non-corporate entity), plus information on its ownership, control and structure — and take reasonable measures to confirm accuracy when first obtained and during ongoing monitoring (s. 138(2)). If you cannot get or confirm the information, s. 138(4) requires reasonable measures to verify the identity of the entity's chief executive officer (the older phrase "most senior managing officer" is outdated) and application of the s. 157 special measures — FINTRAC describes this as treating the client as high risk. Since October 1, 2025, material discrepancies with the Corporations Canada individuals-with-significant-control database for high-risk CBCA corporations must be reported to the CBCA Director within 30 days (s. 138.1).
Two more pieces complete merchant onboarding. Entering a service agreement with an entity puts an MSB into a business relationship at that moment (s. 4.1(d)), which switches on ongoing monitoring under s. 123.1 — detecting reportable transactions, keeping client information current, and reassessing risk. And because the service agreement generates an information record, the s. 137 third-party determination applies at signing.
Agent KYB and oversight: who verifies, and who answers for it
Verification can be operationally delegated without transferring the obligation. Under PCMLTFR s. 106, a reporting entity may rely on an agent or mandatary to take the identity-verification measures in s. 105(1); under s. 107, it may rely on verification previously done by another entity referred to in s. 5 of the Act, or an affiliated foreign entity with similar identification and record-keeping requirements. Either way, the records of how identity was verified — keyed to the method used — must exist under s. 108, and the responsibility remains with the reporting entity whose client it is. Onboarding an agent as a business partner follows the same entity steps as a merchant: verify existence under s. 109 or 112, collect beneficial ownership under s. 138, and monitor the relationship. For the operational detail of agent oversight programs, check the current FINTRAC guidance.
One trigger worth flagging in agent and merchant flows that move large sums: an MSB must take reasonable measures to make a PEP/HIO determination when a person initiates or benefits from an international electronic funds transfer, or a virtual currency transfer or receipt, of $100,000 or more (s. 120(1)), with the source-of-funds, source-of-wealth and senior-management-review measures completed within 30 days of the transaction (s. 122(9)) — there is no 14-day rule.
Low risk is not no KYC — and collect only what you can protect
A low-risk rating changes how intensively you monitor a client; it does not turn off the identification triggers. The MSB thresholds in s. 95(1) are fixed dollar amounts — $1,000 for EFTs, non-EFT fund transmission and virtual currency transfers or exchanges; $3,000 for foreign exchange, money orders and cheque cashing — and they apply regardless of the client's risk score. The genuine exemptions in s. 95(5) are narrow: public bodies, corporations or trusts with net assets of $75 million or more listed on a Canadian or designated FATF-member-state exchange, and their subsidiaries. What risk rating legitimately governs is the cadence and depth of ongoing monitoring under s. 123.1, with the s. 157 special measures reserved for high-risk relationships.
The same record-keeping rules that force collection also bound it. The regulations specify exactly what an on-behalf-of record, a verification record or a beneficial ownership record must contain — collecting more than that adds privacy exposure without adding compliance value. A workable discipline: map each data field you collect to the provision that requires it, retain for the mandated period (at least five years for third-party records under s. 148(1)(c)), restrict access to staff who need it, and resist keeping identity documents or ownership charts you have no regulatory reason to hold.
At a glance
- Third-party determination lives in PCMLTFR ss. 134–137 (not 134–138): reasonable measures are triggered by receiving $10,000+ in cash (s. 134) or virtual currency (s. 135), and whenever an information record must be kept — for MSBs, that includes entity service agreements (s. 137).
- If a third party exists, record their name, address, date of birth and occupation (or entity details and registration number) plus the relationship to your client; if you can only suspect one, record the client's own-behalf statement and your reasons — and keep it all at least five years (s. 148(1)(c)).
- Merchant KYB means verifying the entity's existence with an authentic, valid and current record (ss. 109, 112), then collecting directors and all 25%+ beneficial owners with ownership and structure information (s. 138) — falling back to CEO verification plus s. 157 high-risk measures if ownership can't be confirmed.
- Signing a service agreement with an entity starts an MSB's business relationship immediately (s. 4.1(d)), switching on ongoing monitoring under s. 123.1.
- Verification can run through an agent or mandatary (s. 106) or the reliance method (s. 107), but the s. 108 records and the obligation itself stay with the reporting entity.
- A low-risk rating adjusts monitoring intensity, not the identification triggers — the s. 95(1) thresholds are fixed, and the s. 95(5) exemptions (public bodies, $75M+ listed entities) are narrow.
Common mistakes
- Confusing third-party determination with beneficial ownership: s. 138 asks who owns or controls your client; ss. 134–137 ask who is behind a specific transaction or arrangement. They are separate tests with separate records.
- Recording only confirmed third parties — the regulations also require a record when you merely have reasonable grounds to suspect one, including the client's statement and your reasons (ss. 134(3)–137(3)).
- Treating a "low-risk" merchant as exempt from identification: the s. 95(1) dollar thresholds apply regardless of risk rating, and the s. 95(5) exemptions cover only public bodies and large listed entities.
- Assuming that outsourcing verification to an agent transfers the obligation — s. 106 delegates the measures, not the responsibility or the s. 108 record-keeping.
- Verifying a corporation's existence but skipping the ownership, control and structure information — or never taking the reasonable measures to confirm its accuracy required by s. 138(2).
- Applying a 14-day window to PEP measures on large transfers: the actual rule for MSB transaction-based determinations is 30 days after the transaction (s. 122(9)).
Sources
Regulatory anchor: PCMLTFA ss. 6.1, 9.3; PCMLTFR ss. 4.1, 95, 105–108, 109, 112, 123.1, 134–138.1, 148(1)(c)
This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.