A FINTRAC examination does not have to become a crisis. But for most reporting entities it starts the same way: a phone call, usually to the compliance officer, that nobody was expecting.
What will FINTRAC ask for? How far back will it look? Which transactions get tested? Who gets interviewed? And what happens if it finds something?
FINTRAC has become unusually transparent about how it works. Its Assessment Manual sets out how examinations are planned and scoped, which methods are applied, how transactions and suspicious activity are tested, and how findings turn into enforcement outcomes. Read properly, that manual is a readiness roadmap. This guide walks through it, and through what changed on 26 March 2026.
1. What Changed on 26 March 2026
Bill C-12, the Strengthening Canada’s Immigration System and Borders Act, came into force on 26 March 2026. It is the most significant expansion of FINTRAC’s enforcement toolkit in years.
The new penalty framework in brief
For violations occurring after 26 March 2026, FINTRAC has authority to:
- define prescribed violations and compliance order violations subject to penalties
- apply maximum penalty amounts up to 40 times previous limits
- consider a reporting entity’s ability to pay when setting a penalty
- require mandatory compliance agreements for prescribed violations
- issue compliance orders, with breach of an order designated a distinct violation
The transitional rule. Violations occurring entirely before 26 March 2026 continue under the previous policy and penalty amounts. FINTRAC has said it will scope examination review periods so that each falls entirely within one legislative framework, so that every examination is assessed against a single set of compliance expectations.
FINTRAC is still updating its penalty policy and developing new guidance. Check the current position before relying on any published summary, including this one.
The commercial consequence is easy to miss. If your last examination or effectiveness review left issues unresolved and they have persisted past March 2026, the exposure attached to them is no longer the exposure you priced two years ago. The same deficiency, in a review period scoped after that date, now sits inside a regime with penalty ceilings up to forty times higher.
2. The Examination Begins With a Phone Call, and That Date Matters
FINTRAC calls the person responsible for implementing your compliance program to discuss the scope and date. A notification letter follows, confirming where and when the examination will take place. That letter is FINTRAC’s formal request for information, documents, records and your assistance.
The letter usually arrives 30 to 45 days before the examination date, with more time for larger businesses given the data they must assemble.
Here is what catches people out. FINTRAC treats the date of the notification call as the start of the examination. Not the date of the letter, and not the day an examiner appears.
That single fact governs remediation timing. FINTRAC has said it will not generally accept certain documents, records or reports once an examination has started. A required transaction report filed after the notification date will still be treated as a failure to meet the requirement. Compliance program documents created or adjusted after that date may lead FINTRAC to conclude the compliance program requirements were not met.
You cannot fix your way out of a FINTRAC examination after the phone rings. Preparation has to happen before the call, which is another way of saying it has to be continuous.
3. How FINTRAC Decides What to Examine
Examinations are risk-based. There is no standard scope and no standard review period.
Before contacting you, FINTRAC builds a picture from what it already holds: your compliance history and previous examination findings, including from other regulators it shares information with; correspondence in which you described how you would fix past non-compliance; voluntary self-declarations; the reports you have submitted and how you responded to FINTRAC’s feedback on their quality or timeliness; and your policies, risk assessments and effectiveness reviews held on file.
It also draws on two sources reporting entities forget: your enforcement history with FINTRAC, other regulators and law enforcement, and information about your business or your clients available on the internet.
From that, FINTRAC sets the requirements it will examine, the assessment methods, the examination period, the sample sizes and who it will interview. Where it has limited information on file, it relies on comparable businesses and on what it learns during the notification call.
Two implications. What you previously told FINTRAC about how you would remediate is on file and will be checked. And the notification call is not small talk; what you say during it helps shape the scope.
4. The Data Request, and Whether Your Systems Can Answer It
The notification letter identifies what FINTRAC wants. Expect to produce: AML policies and procedures; your risk assessment covering money laundering, terrorist activity financing and sanctions evasion; training materials and records; your most recent effectiveness review and evidence its findings were actioned; corporate, location and agent information; a description of how funds move through the business; client and KYC records; beneficial ownership records; transaction records; high-risk client information; monitoring records and alerts; submitted reports; and records of unusual transactions you investigated and chose not to report.
Transaction data is where examinations get uncomfortable.
FINTRAC does not want a list of the reports you submitted. It already holds those. It wants the underlying population, extracted from your own systems: cash transactions of $10,000 or more, virtual currency transactions of $10,000 or more, international electronic funds transfers of $10,000 or more, with transaction and client identification information. It then compares that population against what you actually reported and asks about every discrepancy. It may request a sample list first, to confirm the format is usable.
If you cannot produce that extract, FINTRAC will ask for the underlying source records instead: deposit slips, invoices, receipts, transfer slips, wire logs, exchange transaction tickets.
So the readiness question is not whether your policy says you report large transactions. It is whether, on 30 days’ notice, you can produce a complete and accurate transaction population from your own systems in a format someone else can work with.
Test that before you need it. “Our payment processor handles that” does not transfer the obligation. You remain responsible.
5. Test Your Program the Way FINTRAC Will
FINTRAC’s approach is holistic. It says it focuses less on technical non-compliance and more on the overall soundness of the areas it examines, and that technical non-compliance inside an otherwise adequate system may not drag down the overall result.
That is both reassuring and clarifying. Tidy documents will not rescue a program that is not operating, and an isolated slip inside a program that demonstrably works is unlikely to sink you.
So test operation, not documentation. Ask the questions FINTRAC asks:
- Your policy says high-risk clients are reviewed every six months. Can you show those reviews happened?
- Your procedure requires occupation at onboarding. Is it actually in the files?
- Your risk assessment flags certain jurisdictions, products or client types as high risk. Are enhanced measures applied to them, and can you evidence it?
- Your monitoring rules exist on paper. Are they running, are alerts generated, and does anyone have time to work them?
Reconcile your reporting. Pull the transaction populations FINTRAC would pull and check them against your filed LCTRs, LVCTRs and EFTRs. Test your 24-hour aggregation logic specifically, including the rules about not combining lump-sum transfers of $10,000 or more with smaller ones, and not combining incoming with outgoing transfers. Do not assume that because a system was configured to generate reports, every required report was identified, completed accurately and filed on time.
Test your suspicious transaction process hardest. FINTRAC describes STRs as the cornerstone of its mandate. It may review your monitoring rules for reasonableness, whether thresholds have a documented rationale, whether you have the resources to work your alert volume, whether indicators are applied consistently, whether a client’s actual activity differs from expected activity, and whether apparently unrelated clients share addresses or phone numbers.
Critically, FINTRAC reviews the unusual transactions you decided not to report, to test whether those decisions were sound. Your record of why you did not file can matter as much as the STRs you did.
6. Interviews: Less Frightening Than You Think
FINTRAC may interview your compliance officer, employees and agents, in person, by phone or by videoconference.
FINTRAC states plainly that it does not expect interviewees to memorise your policies. Its goal is to confirm that people are aware of the requirements applicable to their own duties and know how to seek clarification when they need it.
That should change how you prepare. Do not script answers. Make sure people understand the parts of the program they operate. A transaction-processing employee should know the identification and record keeping requirements that apply to their work. An analyst should be able to describe how an unusual transaction gets escalated. The compliance officer should be able to walk through the risk assessment, the monitoring framework, the governance structure and the significant compliance judgements made during the period.
The failure mode to avoid is common: the written procedure says one thing, and the person who does the work describes something different. Role-specific training is what closes that gap.
7. The Exit Meeting Is Your Best Opportunity. Use It.
Most guidance treats the exit meeting as a debrief. It is more than that, and it is the most actionable moment in the entire process.
FINTRAC holds an exit meeting to discuss preliminary findings, presented as deficiencies, each one a violation of a provision of the Act or Regulations. At that meeting you may offer additional information to clarify a deficiency. FINTRAC will agree a timeline for you to provide it. After reviewing what you send, FINTRAC may maintain the deficiency, modify it, or withdraw it.
Deficiencies are negotiable at this stage in a way they are not later. Go in prepared:
- have someone taking detailed notes of exactly how each deficiency is characterised
- ask factual clarifying questions on the spot, particularly about sample composition and how a finding was extrapolated
- identify immediately which findings rest on records FINTRAC may not have seen, or on a misreading of how a control operates
- agree a realistic timeline, then meet it
The findings letter follows. It sets out the records and reports examined, consolidated interview results, sample sizes and instances of non-compliance, with individual deficient records in an annex. It may also include observations, which are not deficiencies but which FINTRAC notes can evolve into deficiencies over time as examples accumulate across examinations. Treat observations as early warnings, not as a pass.
The letter details one of four outcomes: no further action; possible follow-up compliance action; a recommendation for enforcement action; or a notice of violation setting out a penalty.
Where FINTRAC asks for an action plan, it must be sent within 30 calendar days of receiving the findings letter, unless FINTRAC specifies otherwise. You are not required to send documents proving the deficiencies were fixed; FINTRAC assesses those during any follow-up activity.
8. If a Penalty Is Proposed
FINTRAC is clear that penalties are not an automatic response to non-compliance and that the objective is behavioural change rather than punishment. In deciding whether to impose one, it assesses the nature, relative importance, extent and root cause of the non-compliance, mitigating and aggravating factors, and your compliance history.
If a penalty is imposed, you have the right to make representations to FINTRAC’s Director and Chief Executive Officer for a review of your file, and the right to appeal that decision to the Federal Court.
One caveat on process. The representation and review mechanics described in most published guidance, including timelines, reflect the framework in place before Bill C-12. FINTRAC has confirmed it is still updating its penalties policy and developing guidance on compliance agreements, compliance orders and penalty calculation. If you receive a notice of violation, check FINTRAC’s current policy and take advice promptly. These windows are short.
Whatever the framework, treat a notice of violation as a formal enforcement proceeding, not another round of correspondence with the examination officer. Our remediation practice handles findings response and the remediation programme that follows.
9. Voluntary Self-Declaration, and Running a Mock Examination
FINTRAC’s voluntary self-declaration process can be genuinely valuable, but only on the right side of the notification call.
Where a self-declaration is made on a new issue before an examination has started, FINTRAC will work with the entity to resolve it. Where it arrives during an examination, FINTRAC assesses the non-compliance as part of the examination and decides whether it warrants enforcement action. You should still disclose issues you find after notification, but the value of the tool collapses the moment that call happens.
That is the strongest practical argument for periodic internal testing there is.
The weak version of preparation asks: do we have an AML policy? The useful version asks: can we demonstrate that this control operated throughout the period FINTRAC will examine?
A mock examination built on FINTRAC’s own methodology should cover, at minimum: reconciliation of filed reports against transaction populations; transaction and 24-hour aggregation testing; KYC and client file testing; STR testing including decisions not to file; high-risk client and beneficial ownership testing; monitoring rule and alert review; remediation of previous deficiencies; employee interviews; and a live test of whether you can actually extract the data.
The objective is unglamorous and entirely the point: find the problems before FINTRAC does, while a voluntary self-declaration still counts for something.
Final Thoughts
A FINTRAC examination is an evidence exercise. The question is not whether your compliance program reads well. It is whether you can demonstrate that it worked throughout a period someone else chooses.
That was true before March 2026. With penalty ceilings now up to forty times higher and compliance orders on the table, the cost of finding out otherwise has gone up considerably.
Frequently Asked Questions
Sources
- FINTRAC assessment manual: the approach and methods used during examinations — fintrac-canafe.canada.ca/guidance-directives/exam-examen/cam/cams-eng
- Administrative monetary penalties: changes following legislative amendments — fintrac-canafe.canada.ca/pen/3-eng
- Administrative monetary penalties policy — fintrac-canafe.canada.ca/pen/2-eng
- Compliance program requirements — fintrac-canafe.canada.ca/guidance-directives/compliance-conformite/Guide4/4-eng
- Voluntary self-declaration of non-compliance — fintrac-canafe.canada.ca/guidance-directives/exam-examen/vsdonc/1-eng
Claudius O. Otegbade
CPA (New York) · FCA · MBA · CAMS · CFE · CFCS · CBP · CIPP/CClaudius is Co-Founder and Lead Partner of C&G Professional Services Inc., with close to two decades in anti-money laundering compliance, forensic accounting, and regulatory audit. He led AML engagements at Grant Thornton LLP and MNP LLP, previously served as Director and Chief Compliance Officer at WFCU Credit Union, and has conducted over 100 AML effectiveness reviews and FINTRAC examination support engagements for reporting entities across Canada.
Full profile → LinkedIn →Examination notice received, or want to know where you stand?
C&G assists MSBs, foreign MSBs, PSPs, fintechs, virtual currency businesses, credit unions and other Canadian reporting entities with examination readiness, mock examinations, remediation and live examination support — built around FINTRAC’s own assessment methodology.