AML Independent Review & Effectiveness Review (AML Audit)

The mandatory two-year review of your anti-money laundering program, commonly called an AML audit, conducted against the same criteria a FINTRAC examiner applies, and delivered as a report you can put in front of your board and your regulator.

01
📋 Regulatory Requirement Request a Review

An AML independent review, which most businesses call an AML audit or a FINTRAC audit, is a mandatory assessment of your anti-money laundering (AML) compliance program. Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, every Canadian reporting entity must have the effectiveness of that program reviewed at least once every two years. The review must be independent of the people who operate the program, which for most businesses means engaging an external specialist.

C&G conducts the review against the criteria FINTRAC examiners apply: the five required elements of the compliance program, the quality and currency of the enterprise-wide risk assessment, and, critically, whether the controls you documented are actually operating in practice. Every finding is rated by degree of non-compliance and paired with a corrective action that is specific, owned, and dated.

We have completed independent reviews for credit unions, money services businesses, virtual currency dealers, payment service providers, real estate brokerages, securities dealers, and dealers in precious metals and stones across Canada. What you receive is not a checklist. It is a defensible written assessment of where your program stands and what it will take to close the gap.

What the engagement includes

  • Full review of AML/ATF policies, procedures, and controls documentation
  • Enterprise-wide risk assessment methodology and currency review
  • KYC and ongoing customer due diligence file testing
  • Transaction monitoring coverage, tuning, and alert disposition review
  • Reporting obligations testing: STRs, LCTRs, EFTRs, LVCTRs, and terrorist property reports
  • Employee training program, records, and effectiveness assessment
  • Compliance officer mandate, authority, and resourcing assessment
  • Written report with rated findings, root causes, and recommendations
  • Management and board debrief, plus a remediation roadmap with owners and target dates
How it works

How the engagement runs

STEP 01

Scoping and document request

We confirm your reporting entity classification, the products, channels, and jurisdictions in scope, and issue a structured document request list so you know exactly what is needed up front.

STEP 02

Documentation assessment

Policies, procedures, the risk assessment, training records, and reporting logs are assessed against the PCMLTFA, its regulations, and current FINTRAC guidance.

STEP 03

Testing and sampling

We sample customer files, monitoring alerts, and submitted reports to test whether the controls you documented actually operate as written. This is the step template reviews skip, and the step examiners care about most.

STEP 04

Interviews

Structured interviews with the compliance officer, front-line staff, and senior management to assess awareness, escalation behaviour, and tone from the top.

STEP 05

Report and debrief

A written report with findings rated by degree of non-compliance, a management debrief, and a remediation roadmap you can execute against.

Who this is for

Businesses we deliver this for

FAQ

AML Independent Review: common questions

In practice, yes. The statutory term is a review of the effectiveness of your compliance program, and FINTRAC calls it an independent review or effectiveness review. Most businesses searching for it call it an AML audit or a FINTRAC audit. They describe the same mandatory two-year engagement, and the report we produce satisfies the requirement whichever name you use for it.
Every reporting entity under the PCMLTFA. That includes money services businesses, virtual currency dealers, banks and credit unions, real estate brokers and developers, dealers in precious metals and stones, securities dealers, life insurers, accountants, and legal professionals carrying out triggering activities. If you are registered with FINTRAC, the requirement applies to you.
At least once every two years, measured from the date of your last review. The two-year interval is a maximum, not a target. If your business has materially changed its products, channels, geographies, or ownership since the last review, the sensible practice is to review sooner.
Yes, provided the reviewer is genuinely independent of the compliance function being assessed. An internal auditor who does not report to the compliance officer and had no hand in designing the program can perform it. In practice most small and mid-size reporting entities do not have that separation in-house, which is why they engage an external specialist.
For a typical MSB or small-to-mid-size reporting entity, C&G completes the review in two to four weeks from the point we receive access to your documentation. Larger or multi-jurisdictional organisations generally take four to eight weeks. Timelines depend far more on how quickly documentation arrives than on our capacity.
Missing the deadline is itself a compliance deficiency that FINTRAC will identify at examination, and it can contribute to an administrative monetary penalty. If you are overdue, the right move is to complete a catch-up review promptly and document the circumstances. That context matters if an examination follows.
A written report setting out the scope, methodology, findings rated by degree of non-compliance, root cause analysis, and recommended corrective actions. It is written to be handed directly to your board and, if requested, to FINTRAC. We also deliver a management debrief and a remediation roadmap with assigned owners and target dates.
The effectiveness review is something you commission and control; the examination is something FINTRAC conducts on you. The review is your opportunity to find and fix deficiencies privately, on your own timetable, with no regulatory consequence attached to what it surfaces. The examination applies broadly the same criteria, but its findings go into your compliance record and can carry penalties. Entities that treat the review seriously rarely have difficult examinations.
Fees are driven by scope rather than headcount: how many reporting obligations apply to you, how many products and channels are in scope, the size of the customer and transaction population we need to sample, and whether the documentation is in a reviewable state when we start. A single-product MSB sits at the low end; a multi-entity group with several registrations and cross-border flows sits well above it. We quote a fixed fee after a short scoping call, not an hourly estimate. For indicative ranges by entity type, see what a FINTRAC independent review costs in Canada.
No, and this is a point examiners check. The review must be independent of the people who designed and operate the program. A firm reviewing its own documentation is reviewing its own work, which defeats the purpose and is a finding in itself. Where C&G has built a client’s program, we do not review it; we will refer the review out, and we expect the same discipline from other firms.
Yes. The obligation attaches to being a reporting entity, not to your size, and there is no small-business exemption. What does scale with size is the depth of the review: a three-person MSB with one product has a far smaller sample population and a much shorter engagement than a credit union. Small entities are examined, and "we are too small" has never been an accepted answer.
Yes. A dealer in precious metals and stones becomes a reporting entity once it buys or sells precious metals, precious stones, or jewellery in a single transaction of $10,000 or more. From that point the full compliance program obligation applies, including the two-year effectiveness review. Many DPMS businesses do not realise they were captured until a bank or an examination raises it. Our free DPMS training module covers the obligations in full.
The same five compliance program elements as any reporting entity, plus the reporting and record-keeping obligations that attach to the activity: large cash transaction reports, large virtual currency transaction reports, suspicious transaction reports, customer identification and record keeping on qualifying transactions, and an enterprise-wide risk assessment. See the DPMS quick reference for a condensed version.
Keep reading

Related services

Insights on this topic

Is your two-year review due?

Tell us your entity type and last review date. We will confirm your deadline and scope the work.