If you run a money services business, a payment service provider, a virtual currency business or any other FINTRAC reporting entity in Canada, you will eventually need to answer a practical question: what should we budget for our independent review?
It is a hard question to answer online, because almost nobody publishes a number, and “it depends” is not a budget. For most established Canadian MSBs and fintechs, a properly scoped independent effectiveness review lands somewhere between $8,000 and $15,000. Smaller and genuinely simple reporting entities can come in lower. Multi-product businesses, PSPs and virtual currency dealers routinely come in higher. The detailed ranges, and the conditions attached to them, are further down this article.
The number matters less than what sits behind it. A review priced below the cost of doing the work properly is not a saving. FINTRAC’s own penalty guidance treats a review that fails to test effectiveness as a violation carrying a base penalty of $75,000. That comparison, not the difference between two quotes, is the one that should drive your decision.
Is a FINTRAC Audit the Same Thing as an Effectiveness Review?
In practice, yes. In terminology, no, and the gap causes real confusion.
Businesses commonly say “FINTRAC audit,” “AML audit,” “MSB audit” or “FINTRAC independent review.” FINTRAC itself uses none of those terms. Its formal language is the two-year effectiveness review.
Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its Regulations, every reporting entity must institute and document a plan for reviewing its compliance program, and must carry out that review at least every two years. FINTRAC states that the review tests the effectiveness of three things: your compliance policies and procedures, your risk assessment, and your ongoing compliance training program and plan.
The distinction matters for one commercial reason. When a firm sells you an “AML audit,” ask whether what they are actually delivering is the prescribed two-year effectiveness review as FINTRAC defines it, or something narrower that happens to share a name. A financial statement audit, an ISO-style controls review and a FINTRAC effectiveness review are three different exercises.
One further point on scope. FINTRAC is explicit that the review has to go beyond confirming that documents exist: it must assess whether the compliance program is being applied in practice, and it must be tailored to the type, nature, size and complexity of your business. That principle is the single largest driver of price variation, and it is why a flat-rate quote should make you cautious.
One point that is frequently missed in older content: since FINTRAC’s October 2024 guidance update, sanctions evasion risk sits alongside money laundering and terrorist activity financing throughout the compliance program requirements. Your risk assessment must consider it, your training must cover it, and therefore your effectiveness review must test it. If a proposal you receive still describes scope purely in ML/TF terms, the reviewer is working from an outdated framework.
Does the Review Have to Be Done by an External Firm?
No, and any consultant who tells you otherwise is selling rather than advising.
FINTRAC states that the review must be carried out and documented by an internal or external auditor, or by you if you do not have an auditor. The reviewer should be knowledgeable about your requirements under the Act. As a best practice, to preserve impartiality, the review should not be conducted by someone directly involved in your compliance program activities.
That last clause is where most small and mid-sized businesses land on engaging externally. If your compliance officer wrote the policies, built the risk assessment, delivers the training and files the reports, then that same person reviewing their own work does not produce an impartial assessment, whatever the technical permissibility.
There is a second, less discussed reason. FINTRAC’s penalty framework assigns harm where an internal or external auditor did not conduct the review in circumstances where one was required. Getting the reviewer question wrong is itself a finding.
What Should You Expect to Pay?
There is no FINTRAC-prescribed fee. The ranges below are market-oriented budgeting estimates based on typical scope. They are not quotations, and they are not approved, prescribed or endorsed by FINTRAC.
| Type of reporting entity | Complexity | Indicative review cost |
|---|---|---|
| Small MSB meeting all the conditions below | Low | $5,000 – $8,000 |
| Established MSB or fintech | Low to moderate | $8,000 – $15,000 |
| Multi-product MSB, PSP or virtual currency dealer | Moderate to high | $15,000 – $25,000 |
| Large or complex reporting entity | High | $25,000 – $40,000 |
| Financial institution or highly complex environment | Very high | Individually scoped |
The entry-level row of that table is narrow, and deliberately so. A reporting entity qualifies for it only where substantially all of the following are true:
- a single registered MSB service category, not several
- domestic activity only, or a single well-defined corridor
- a low reportable transaction count across the full 24-month review period
- no prior FINTRAC examination findings
- no unresolved deficiencies from the previous effectiveness review
- complete records, available in digital form, retrievable on request
Most businesses that believe they belong in the entry-level range fail at least two of those conditions, usually the transaction count and the state of the records. That is not a sales tactic. It is the most common reason a scoping call ends with a different number than the client expected.
The useful question is therefore not “how much does the review cost,” but “what work is included for that price.”
What Drives the Cost
Size and complexity of the business
A single-service remittance business is a fundamentally different engagement from a fintech running fiat payments, virtual currency services, payment accounts and several cross-border corridors. More products means more controls to assess and more testing to perform.
Transaction volumes
Volume drives sampling. A business with a few hundred transactions in the review period requires materially less testing than one with hundreds of thousands. The reviewer needs to test transactions against client identification, reporting, record keeping, business relationship and ongoing monitoring requirements, and sample sizes have to be defensible.
Quality of the existing program
Organised businesses are cheaper to review. Where policies, risk assessments, training records, KYC files, transaction data and regulatory reports are readily retrievable, the engagement moves quickly. Where records are incomplete, inconsistent or scattered across systems, a significant portion of the fee goes to reconstruction rather than assessment.
Previous FINTRAC findings
A prior examination changes scope. The reviewer should establish whether previously identified deficiencies were remediated and whether that remediation is operating effectively. The same applies to findings from your last effectiveness review. Unremediated history expands the work.
Transaction and customer file testing
This is the cost driver that separates a real review from a document read, and it is where cheap engagements cut.
FINTRAC’s examination methodology looks specifically at the scope and methodology of your effectiveness review, and at whether the testing methods used were adequate and reasonable. FINTRAC may also examine whether the review covered all requirements applicable to your sector.
Testing takes time, and time is what you are buying.
Do Foreign MSBs and PSPs Need One Too?
Yes, and this catches people out.
Foreign money services businesses (FMSBs) registered with FINTRAC carry the same compliance program obligations as domestic MSBs, including the two-year effectiveness review. Having no place of business in Canada does not exempt you. If you direct services at persons or entities in Canada and provide those services to Canadian clients, you are a reporting entity, and the review applies. In practice FMSB reviews often cost more rather than less, because the reviewer has to reconcile a Canadian regulatory framework against operations, systems and records that sit in another jurisdiction.
Payment service providers need to hold two separate obligations apart. Registration with the Bank of Canada under the Retail Payment Activities Act is not a FINTRAC registration, and RPAA obligations are not PCMLTFA obligations. A PSP that is also a FINTRAC reporting entity carries both, and the two-year effectiveness review sits on the FINTRAC side. Several businesses we speak to have completed an RPAA registration and assumed it discharged something on the AML side. It does not.
If you are unsure which regime you fall under, that determination should happen before you request review quotes, not after.
What Should Be Included in the Fee
A properly scoped engagement should cover, at minimum:
- the five required elements of your compliance program, including the risk assessment and its treatment of sanctions evasion risk
- the client due diligence obligations that apply to your sector
- the reporting obligations that apply to your sector, tested against the underlying transaction data
- record keeping and retention
- open findings from your previous effectiveness review and from any FINTRAC examination
- transaction and customer file testing, with the sampling basis stated in writing
One further step businesses regularly miss: if you are an entity, you must report the results of the review in writing to a senior officer no later than 30 days after the review is completed. The report must cover the findings, any updates made to policies and procedures during the review period that were not made as a result of the review, and the implementation status of those updates. Ask your reviewer whether they will prepare that senior officer report, or whether it lands on your compliance officer’s desk.
Beware of the $1,000 FINTRAC Audit
Low price does not automatically mean poor quality. But an unusually low price should prompt very specific questions about scope.
Ask any prospective reviewer to put three things in writing before you sign:
- what will be tested, as distinct from what will be read
- how the scope of that testing was determined for a business of your type, size and volumes
- what you receive at the end, including whether the senior officer report is prepared
A reviewer who can answer those three in writing is quoting an engagement. One who cannot is quoting a template, and the gap between the two is not something you will see until an examiner does.
If the answer amounts to reading the policy manual and returning a checklist, that is not effectiveness testing, and FINTRAC’s own framework says so.
What FINTRAC Actually Penalises
This is the part of the analysis that changes the arithmetic.
FINTRAC classifies violations related to the prescribed review as serious, with a statutory range of $1 to $100,000. Within that range, its published harm assessment guide sets out four levels, each with a base penalty applied before mitigating factors:
| What went wrong with the review | Harm level | Base penalty |
|---|---|---|
| No review conducted, or only a minimal one | Level 1 | $100,000 |
| No effectiveness testing, or scope omits policies and procedures, risk assessment or training | Level 2 | $75,000 |
| Documentation not evaluated for completeness and currency | Level 3 | $50,000 |
| Review conducted late, methods not clearly documented, or not conducted by an auditor where required | Level 4 | $25,000 |
Level 2 is the one to read twice. FINTRAC describes a review that omits effectiveness testing as “essentially only a theoretical review of the documentation.” Its reasoning is that even where the documentation is in order, the policies may not be applied in practice, and the gap goes undetected.
That is a regulator stating, in published guidance, that a documentation-only review carries a $75,000 base exposure.
A separate set of levels applies to the senior officer reporting requirement, ranging from $25,000 where the report is delivered beyond the 30-day window up to $100,000 where the results are not reported at all.
Important, as of 2026. The levels above reflect FINTRAC’s harm assessment guide as it stood before Bill C-12, which came into force on 26 March 2026 and raised maximum penalty amounts substantially. Violations occurring entirely before that date continue under the previous framework; violations on or after it fall under the new one. See what changed on 26 March 2026, and confirm the current position against FINTRAC’s published policy.
Two caveats, in fairness. These are base amounts before mitigating factors, and FINTRAC states that mitigating factors can reduce a penalty as far as the statutory minimum of $1. FINTRAC also states that the purpose of an administrative monetary penalty is to encourage compliance rather than to punish. Nobody should read this table as a schedule of fines you will automatically receive.
But the comparison stands. The real economic question is not the gap between a $6,000 review and a $12,000 review. It is the gap between a review that tests effectiveness and one that does not.
Final Thoughts
Price is one input, and not the decisive one. The purpose of the two-year review is not to produce a report that sits on a shelf until FINTRAC asks for it. It is to establish whether your compliance program works, and to tell you where the weaknesses are before an examiner does. In the current Canadian enforcement environment, that head start is worth considerably more than the difference between two quotes.
Frequently Asked Questions
Sources
- Compliance program requirements, FINTRAC — fintrac-canafe.canada.ca/guidance-directives/compliance-conformite/Guide4/4-eng
- FINTRAC assessment manual, approach and methods used during examinations — fintrac-canafe.canada.ca/guidance-directives/exam-examen/cam/cams-eng
- Guide on harm done assessment for compliance program violations, FINTRAC — fintrac-canafe.canada.ca/pen/guides/cp-eng
Claudius O. Otegbade
CPA (New York) · FCA · MBA · CAMS · CFE · CFCS · CBP · CIPP/CClaudius is Co-Founder and Lead Partner of C&G Professional Services Inc., with close to two decades in anti-money laundering compliance, forensic accounting, and regulatory audit. He led AML engagements at Grant Thornton LLP and MNP LLP, previously served as Director and Chief Compliance Officer at WFCU Credit Union, and has conducted over 100 AML effectiveness reviews and FINTRAC examination support engagements for reporting entities across Canada.
Full profile → LinkedIn →Need a scoping call on your independent review?
C&G conducts independent AML effectiveness reviews for MSBs, FMSBs, PSPs, virtual currency businesses and other FINTRAC reporting entities across Canada. Tell us your entity type, volumes and last review date, and we will scope it properly.