Library
PublishedKYC & Due DiligenceLast reviewed 2026-07-09 · 7 min read

Verifying a Person's Identity: the FINTRAC Methods

PCMLTFR s. 105(1) gives five ways to verify a person's identity — government photo ID, government-source information, a Canadian credit file at least three years old, dual-process, and the affiliate or member method — with reliance and agent arrangements sitting separately in ss. 106–107. The binding 'authentic, valid and current' standard in s. 105(5) is what remote flows most often fail: an image of a document proves it exists, not that it is genuine.

Reader question

What are the accepted ways to verify an individual's identity under FINTRAC rules, and what does each method actually require?

Five methods in the regulation, not three

PCMLTFA s. 6.1 sets the duty — every person or entity referred to in s. 5 must verify identity in accordance with the regulations — and PCMLTFR s. 105(1) supplies the how. For an individual, it lists five methods, not the three most people can name: (a) government-issued photo identification; (b) information received, on request, from a federal or provincial government body (or its agent or mandatary) authorized in Canada to verify the identity of persons; (c) a Canadian credit file that has existed for at least three years; (d) the dual-process method; and (e) the affiliate or member method — confirming that a listed affiliated or member entity previously verified the person using one of methods (a) through (d).

The familiar 'photo ID, credit file, or dual-process' trio corresponds to paragraphs 105(1)(a), (c) and (d). FINTRAC's methods guidance also profiles five named methods, but a slightly different five — photo identification, credit file, dual-process, affiliate or member, and reliance — and does not present the s. 105(1)(b) government-information route as a standalone method, which is why counts differ depending on where you look. Reliance sits outside s. 105(1) altogether: under s. 107, a reporting entity may rely on identity verification previously done by another entity referred to in s. 5 of the Act, or by an affiliated foreign entity with similar identification and record-keeping requirements.

What 'authentic, valid and current' actually demands

The standard for photo ID is in the regulation itself, not just guidance. PCMLTFR s. 105(5) requires that a document used to verify identity under s. 105(1) 'must be authentic, valid and current,' and that other information used for that purpose 'must be valid and current.' Read as three separate questions, that means: is this a genuine document rather than an altered or fabricated one; is it a legitimately issued document of its type; and is it current on the day you check it — an expired card is hard to defend on the plain words. FINTRAC's methods guidance interprets each term; check the current version when you design the check rather than assuming a quick visual glance covers all three.

Document what your process examined for each question. A file note or system record showing how authenticity was assessed is far easier to stand behind later than a bare copy of the ID.

Remote verification: why video alone is not enough

Nothing in s. 105 requires the person to be physically in front of you, but s. 105(5) applies with full force to remote flows. A video call or an uploaded photo demonstrates that a document exists and what it appears to say — it does not, by itself, establish that the document is authentic. That is the gap a remote flow has to close: the process must be capable of assessing whether the document is genuine, not merely capturing an image of it.

What FINTRAC accepts as an authenticity determination is set out in its methods guidance, and it evolves — check the current FINTRAC guidance before selecting a vendor tool or building the step in-house. Whatever you use, record what the process actually checked, because the s. 108 record has to reflect the method as performed, not as intended.

The credit file method: what to check before relying on it

Paragraph 105(1)(c) carries two built-in conditions that analysts should confirm before anything else: the credit file must be Canadian, and it must have been in existence for at least three years. The age test is about the file, not the person's credit quality — a thin but four-year-old file can qualify where a rich six-month-old one cannot. The information relied on must also be valid and current under s. 105(5).

If the file cannot be located, is too young, or does not line up with the details the client gave you, the method fails for that client and you move to one of the other methods. For exactly which data elements the file must confirm, check the current FINTRAC guidance rather than improvising a matching rule.

Dual-process: two categories of information, reliable sources

Under paragraph 105(1)(d), dual-process means confirming any two of the following, each from a reliable source: the person's name and address; the person's name and date of birth; or the person's name and the confirmation of a financial account. The two confirmations must come from different categories — two separate name-and-address checks do not add up to dual-process. As with every method, the information used must be valid and current under s. 105(5).

What qualifies as a 'reliable source,' and how distinct the sources must be from each other and from the client, is addressed in FINTRAC's methods guidance — check the current version when building the workflow. Record which two categories you used, which source supplied each, and what each confirmed.

Agents, reliance, records — and when the duty is triggered

Two adjacent provisions matter for how verification is actually delivered. Under PCMLTFR s. 106, a reporting entity may rely on an agent or mandatary to take the verification measures for it — this is where most outsourced ID-verification vendor arrangements sit legally. Under s. 107, it may instead rely on verification previously done by another s. 5 entity. Either way, s. 108 requires records of how identity was verified, with paragraphs (a) through (i) keyed to the specific method used.

When the duty arises depends on sector. For money services businesses, s. 95(1) consolidates the transaction triggers with exact thresholds — for example, a request to initiate an electronic funds transfer of $1,000 or more, a foreign currency exchange transaction of $3,000 or more, or a transfer of $1,000 or more in virtual currency. Two cross-sector triggers apply to everyone: s. 84 (verify the person or entity from which a large cash or large virtual currency amount is received) and s. 85 (reasonable measures to verify identity for transactions reportable as suspicious, with a tipping-off exception). One more reason the records matter: under s. 4.1(b), the second time you are required to verify a client's identity is generally the point at which a business relationship forms — so the trail you keep from the first verification onward carries forward obligations.

At a glance

  • PCMLTFR s. 105(1) lists five methods to verify a person's identity — government-issued photo ID, government-source information on request, a Canadian credit file at least three years old, dual-process, and the affiliate or member method; the familiar 'three methods' framing covers only paragraphs (a), (c) and (d).
  • Reliance is a sixth route that sits outside s. 105(1): under PCMLTFR s. 107 you may rely on verification previously done by another reporting entity, and under s. 106 an agent or mandatary may perform the measures for you.
  • 'Authentic, valid and current' is in the regulation itself — PCMLTFR s. 105(5) — not just FINTRAC guidance; other information used to verify must be valid and current.
  • A video call or uploaded photo shows a document exists; it does not by itself establish authenticity — remote flows need a process capable of assessing whether the document is genuine.
  • Dual-process means any two of name+address, name+date of birth, or name+financial account confirmation, from different categories, each from a reliable source.
  • Whatever method you use, PCMLTFR s. 108 requires a record of how identity was verified, keyed to that method — and the second required verification is generally when a business relationship forms under s. 4.1(b).

Common mistakes

  • Assuming there are only three methods — s. 105(1) lists five, and FINTRAC's guidance separately profiles reliance, so a program that only contemplates photo ID, credit file and dual-process is leaving lawful options unused.
  • Treating 'authentic, valid and current' as a guidance preference rather than a binding requirement in PCMLTFR s. 105(5).
  • Accepting a live video call or a selfie-with-ID as proof of authenticity on its own, without a process that actually assesses whether the document is genuine.
  • Relying on a credit file that is not Canadian or has existed for less than three years — the age test applies to the file, not the person's credit history.
  • Running dual-process with two confirmations from the same category (for example, two name-and-address sources) instead of two different categories.
  • Verifying identity correctly but keeping no record of how — s. 108 requires records keyed to the method used, and a missing record is indistinguishable from a missing verification.

Sources

Regulatory anchor: PCMLTFA s. 6.1; PCMLTFR ss. 105(1)(a)–(e), 105(5), 106–108

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.