Library
PublishedFoundationsLast reviewed 2026-07-09 · 8 min read

What Is a Reporting Entity Under Canadian AML Rules?

Reporting-entity status is set by the class list in PCMLTFA s. 5 — sometimes written into the Act, sometimes activated by regulation — and that perimeter widened three times between October 2024 and October 2025. This article maps how coverage is drafted, what obligations follow (compliance program, documented risk assessment, directives and sanctions reporting), and how to read FINTRAC guidance against the provisions it cites.

Reader question

What makes a business a 'reporting entity', and what follows once you are one?

Status follows from activity, not from labels

A reporting entity is a person or entity that falls within one of the classes listed in section 5 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). The test turns on what the business actually does, not what it calls itself — a firm that never uses the word "lender" or "money services business" in its marketing can still sit squarely inside a section 5 class.

The drafting works in three patterns, and knowing which one applies tells you where the rules live. Some activities are written directly into the Act: providing acquirer services in relation to a private automated banking machine appears in PCMLTFA s. 5(h)(iv.1) and (h.1)(iv.1), with "private automated banking machine" defined in s. 2(1). Some are prescribed into an existing class by regulation: PCMLTFR s. 29.1 prescribes cheque-cashing services and crowdfunding platform services as money services business services for s. 5(h)(v) and (h.1)(v), so a business providing cheque-cashing services is an MSB and must register with FINTRAC. And some are standalone classes activated by regulation: PCMLTFR s. 24.1 makes a factor "engaged in a business or profession" for the purposes of s. 5(i), and s. 24.15 does the same for financing or leasing entities under s. 5(j). The practical consequence — you are a reporting entity — is the same, but the sector-specific record-keeping and reporting provisions differ.

The perimeter has moved recently — check the dates

The section 5 perimeter is not static. Mortgage administrators, mortgage brokers and mortgage lenders became reporting entities effective October 11, 2024 (SOR/2023-194, adding PCMLTFR ss. 64.1–64.6). On April 1, 2025, obligations came into force for factors, cheque-cashing businesses, and financing or leasing entities (SOR/2025-68). On October 1, 2025, they came into force for acquirers of private automated banking machines and for title insurers (SOR/2024-266 and SOR/2024-267, the latter adding PCMLTFR ss. 64.7–64.8 and 102.2). A business that correctly concluded it was outside the regime in 2023 may be inside it today.

The coverage tests are precise, so read the definition rather than reasoning from the sector name. A financing or leasing entity is caught under PCMLTFR s. 24.15 only when it is financing or leasing property (other than real property or immovables) for business purposes, passenger vehicles in Canada, or property valued at $100,000 or more. A factor is defined in PCMLTFR s. 1(2) as a person or entity engaged in the business of factoring, with or without recourse against the assignor — so structuring the recourse does not move a business outside the definition. Small wording differences like these decide coverage.

What follows: a compliance program built on documented risk

Once inside section 5, the anchor obligation is PCMLTFA s. 9.6(1): every reporting entity must establish and implement a compliance program. Under s. 9.6(2), that program must include policies and procedures to assess the risk of a money laundering or terrorist activity financing offence in the course of the entity's activities, and PCMLTFR s. 156(1)(c) requires that risk to be assessed and documented against enumerated factors: clients, business relationships and correspondent banking relationships; products, services and delivery channels; the geographic location of activities; for financial entities under PCMLTFA s. 5(a) to (g), risk from affiliated entities; and any other relevant factor.

Two timing rules matter operationally. Before carrying out a new development or introducing a new technology that may affect clients, business relationships, products, services, delivery channels or geography, PCMLTFR s. 156(2) requires the risk assessment to be done and documented in advance — not after launch. And where the entity considers the risk to be high, PCMLTFA s. 9.6(3) requires the special measures in PCMLTFR s. 157: written policies and procedures for enhanced identity verification and other enhanced mitigation, including keeping client identification and beneficial-ownership information up to date and conducting ongoing monitoring of business relationships at a frequency appropriate to the level of risk. From March 26, 2026, a new PCMLTFA s. 9.6(1.1) adds that the program must be "reasonably designed, risk-based and effective" — a standard worth building toward now.

Directives and sanctions reporting attach automatically

Reporting-entity status also pulls in obligations that many new entrants overlook. Three ministerial directives issued under PCMLTFA s. 11.42 are currently in force: North Korea (in force December 9, 2017), Iran (in force July 25, 2020, amended February 15, 2024 and November 15, 2025 — and as of November 15, 2025 it applies to every person or entity referred to in s. 5), and Russia (in force February 24, 2024). Their common core: treat every financial transaction originating from or bound for those jurisdictions, regardless of amount, as high-risk for the purposes of s. 9.6(3); verify the identity of anyone requesting or benefiting from the transaction; apply due diligence with particular attention to sanctions-evasion risk; and keep a record regardless of amount. The Iran directive additionally requires reporting all such transactions to FINTRAC.

Sanctions screening itself is not mandated by the PCMLTFA — the freeze, dealings-prohibition and duty-to-determine obligations flow from the United Nations Act regulations, the Special Economic Measures Act, the Justice for Victims of Corrupt Foreign Officials Act and the Criminal Code. But the PCMLTFA bolts FINTRAC reporting onto that regime: s. 7.1(1) requires a report to FINTRAC whenever a disclosure must be made under those instruments (UN Act reporting in force March 1, 2025; SEMA and JVCFOA reporting in force October 1, 2025), and s. 7(c) requires a suspicious transaction report on reasonable grounds to suspect a transaction is related to a sanctions evasion offence as defined in s. 2(1).

Reading FINTRAC guidance: obligation, expectation, or example

Only the Act and its regulations bind. FINTRAC guidance explains how the regulator interprets and administers those provisions — it is essential reading, but it is a lens, not a second rulebook. The reliable working method is to trace every stated requirement in a guidance page back to the provision it cites, and to treat illustrations as examples of how a rule can be satisfied rather than as additional rules or exhaustive lists of who is caught.

Two examples from this topic show why tracing matters. First, plain-language summaries sometimes present "new technologies" as one of the risk-assessment factors — but the enumerated factors in PCMLTFR s. 156(1)(c) do not include it; the new-technology duty is the separate pre-implementation assessment in s. 156(2). A compliance manual that cites the wrong subsection will mis-time the obligation. Second, regulator web pages get reorganized: the October 11, 2024 mortgage in-force date no longer appears on FINTRAC's current changes page and lives on the mortgage sector requirements page instead. For a junior analyst, the discipline is simple: record the provision, the specific guidance page and the date you relied on it, and when a detail is not clearly anchored to a provision, check the current FINTRAC guidance directly rather than trusting a secondhand summary.

At a glance

  • A reporting entity is any person or entity within a PCMLTFA s. 5 class — status follows from activity, not self-description, and some classes are defined in the Act itself (PABM acquirers, s. 5(h)(iv.1)) while others are activated by regulation (cheque-cashing as an MSB-prescribed service under PCMLTFR s. 29.1; factors under s. 24.1; financing or leasing entities under s. 24.15).
  • The perimeter has widened three times recently: mortgage administrators, brokers and lenders on October 11, 2024; factors, cheque-cashing businesses and financing or leasing entities on April 1, 2025; PABM acquirers and title insurers on October 1, 2025.
  • Once inside, the anchor obligation is a compliance program under PCMLTFA s. 9.6, including a documented risk assessment against the PCMLTFR s. 156(1)(c) factors, a pre-launch assessment for new technologies under s. 156(2), and s. 157 special measures where risk is high.
  • Ministerial directives on North Korea, Iran and Russia, plus sanctions-related reporting under PCMLTFA s. 7.1(1) and the sanctions-evasion STR trigger in s. 7(c), attach to every s. 5 person or entity.
  • In FINTRAC guidance, only the Act and regulations bind — trace each stated requirement to the cited provision, and treat examples as illustrations, not extra rules or exhaustive coverage lists.

Common mistakes

  • Assuming a business is outside the regime because it was outside a year or two ago — six new reporting-entity classes came into force between October 2024 and October 2025.
  • Treating factoring or equipment financing/leasing as MSB activity — factors (PCMLTFA s. 5(i) via PCMLTFR s. 24.1) and financing or leasing entities (s. 5(j) via s. 24.15) are separate classes with their own provisions, unlike cheque-cashing, which is an MSB-prescribed service under PCMLTFR s. 29.1.
  • Listing "new technologies" as an enumerated PCMLTFR s. 156(1)(c) risk factor — new developments and technologies are addressed by the separate pre-implementation assessment in s. 156(2), which must happen before launch.
  • Citing PCMLTFR s. 156(2) as the high-risk provision — high risk triggers PCMLTFA s. 9.6(3) and the special measures in PCMLTFR s. 157 (a single, undivided section).
  • Relying on FINTRAC's changes page as a complete history of in-force dates — the October 11, 2024 mortgage-sector date now appears on the mortgage sector requirements page, not the changes page.
  • Reading guidance examples as exhaustive definitions of who is caught, instead of tracing coverage back to the section 5 class and its defining regulation.

Sources

Regulatory anchor: PCMLTFA s. 5 (reporting entity classes) and s. 9.6 (compliance program); PCMLTFR ss. 24.1, 24.15, 29.1 (class-activating provisions) and ss. 156–157 (risk assessment and special measures).

This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.