AML audit · Canadian MSBs

Independent AML/ATF Effectiveness Review
for Canadian MSBs

Whether your program is new or already operating, AML effectiveness has to be demonstrable.

FINTRAC generally expects Canadian MSBs to review the effectiveness of their AML/ATF compliance program at least every two years. Banks, payment providers and other financial partners may also request a more recent independent review as part of their own due diligence.

MSBs · Foreign MSBs

Who This Is For

The two-year effectiveness review is owed by every money services business registered with FINTRAC — domestic MSBs, foreign MSBs serving Canada and virtual-currency dealers alike. These are the situations in which it usually lands on our desk.

2 years the longest gap the regulations allow between reviews.

A bank or payment provider may ask for a newer one sooner.

Assess Your Review Readiness

Canadian MSBs approaching their review window

who need a structured, independent assessment before the deadline becomes urgent

Virtual-currency and crypto businesses

whose products, transaction flows, customer risk and technology require more than a generic checklist

Money-transfer, remittance and foreign-exchange businesses

that need to demonstrate effective KYC, monitoring, reporting and record keeping

MSBs responding to a bank or payment-provider request

for a current independent compliance review

Businesses whose program has changed

because of new products, jurisdictions, transaction volumes, systems, agents or mandataries

MSBs with open or undocumented findings

that need a practical remediation plan and evidence of closure

Businesses without sufficient internal compliance capacity

that need an independent review now and may need an outsourced CAMLO / compliance officer to maintain the program afterward

Policy exists.
Does it work?

FINTRAC two-year effectiveness review

What Does FINTRAC Require from an MSB Effectiveness Review?

An AML/ATF effectiveness review — often called an AML audit — is the test of a Canadian MSB’s compliance program that section 156 of the PCMLTF Regulations requires every two years. It checks whether your policies and procedures, risk assessment and training program work in practice, is performed by an internal or external auditor (or by the business itself if it has no auditor), and ends with a written report to a senior officer within 30 days.

2 years
Maximum review cycle

Each review must start no later than 24 months after the start of the previous one, and the previous review must be complete first (PCMLTFR s. 156(3) and FINTRAC guidance).

30 days
To report to a senior officer

Findings, the policy updates made during the period and the status of their implementation go to a senior officer in writing within 30 days of completing the review (s. 156(4)).

CAD 20M
Maximum penalty per violation

Since 26 March 2026 a missing or deficient review is a very serious violation: up to CAD 20,000,000 for an entity, where the ceiling used to be CAD 100,000.

Regulator
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Legal basis
PCMLTFA s. 9.6 and PCMLTF Regulations s. 156(1)(f), (3) and (4) — see the PCMLTFA in the Licensing Atlas
What is tested
Policies and procedures, the risk assessment, and the ongoing compliance training program and plan — including whether day-to-day practice matches the documents
Who performs it
An internal or external auditor, or the business itself if it has no auditor; FINTRAC advises someone knowledgeable who is not directly involved in the program
The review plan
Areas of focus and the rationale for them, the period reviewed, evaluation methods and sample sizes
The record
Date, period covered, who performed it, test results, and conclusions with deficiencies, recommendations and action plans
Since 26 March 2026
The program must be “reasonably designed, risk-based and effective” (PCMLTFA s. 9.6(1.1)), not merely documented

Is the review becoming annual? Not under the regulations: as consolidated on 3 September 2026, s. 156(3) still sets a two-year cycle, and the March 2026 reforms did not change it. What changed is the standard and the stakes — the program must now be effective, not only documented, and a failed review is a very serious violation. The two years are a minimum: banks and payment partners may ask for a newer review within their own due-diligence cycle, and an MSB that is also a payment service provider under the Retail Payment Activities Act reviews its risk-management framework at least once a year under that separate regime.

Why the review matters

What This Actually Protects

The review is owed to the regulator, but most of what it protects is your own: the banking relationship, the budget and the next review cycle.

Your regulatory readiness

A documented review helps management understand whether the AML/ATF program remains aligned with applicable obligations and operating reality.

Your banking and payment relationships

A bank or payment provider may ask for independent evidence of compliance before onboarding or continuing a relationship.

Your ability to answer questions quickly

A good review creates a clearer record of what was tested, what was found and what is being remediated.

Your remediation budget

Prioritized findings help management distinguish urgent control weaknesses from lower-risk documentation improvements.

Your next review cycle

The report gives you a starting point for planning the next biennial, annual, counterparty-driven or trigger-based review.

Request Review Scope
Warning signs

The Moment the Review Becomes Urgent

An AML program built once and left untouched does not become effective simply because a policy manual exists.

Assess Your Review Readiness

Your previous review date is unclear, and nobody can confirm when the next review should begin

Your written procedures no longer match the products, customers or transaction flows you operate today

Customer files contain inconsistent KYC/KYB, beneficial-ownership, PEP/HIO, sanctions or EDD evidence

Transaction monitoring generates alerts, but investigation, escalation and reporting decisions are difficult to reconstruct

Staff completed training, but cannot explain what happens when a transaction or customer creates a concern

A bank, payment provider or financial partner requests a current independent review before your two-year cycle is complete

Previous findings were documented, but the business cannot show who owned remediation or what evidence proves closure

The difference between a program that exists and a program that works rarely appears when everything is calm. It appears when a regulator, bank, investor or senior officer asks a simple question and expects an answer supported by records.

A weak program
A weak program produces a scramble through disconnected files, outdated policies and explanations that do not quite match the evidence.
A functioning program
A functioning program can show how a customer was assessed, why a transaction was escalated, who made the decision, whether reporting was considered and what happened afterward.
An effectiveness review is designed to expose that gap before someone else does.Request Review Scope
What the review connects

Why This Keeps Happening

An effectiveness review is not a formatting exercise. It tests whether your AML/ATF framework remains connected to the business it is supposed to control.

Here is what the review needs to connect:
What needs to work togetherWhat can go wrong
Policies and proceduresThe manual describes controls that teams do not follow in practice
Enterprise risk assessmentThe assessment still reflects the old business model
Client-risk methodologyRisk ratings do not consistently influence monitoring or EDD
KYC/KYB and beneficial ownershipFiles do not contain enough evidence to support decisions
Transaction monitoringAlerts are generated without a clear investigation trail
Reporting and record keepingDecisions cannot be reconstructed or defended later
Training and governanceStaff or management are unclear about escalation and ownership
Prior findings and remediationThe same weakness remains open across review cycles

Most businesses do not need another generic AML checklist. They need an independent view of whether the controls they rely on are designed appropriately, implemented consistently and supported by evidence.

The problem with most reviews

Why Most AML Reviews Fall Short

The market often treats an effectiveness review as a document exercise.

What the market often does
Document-only reviews confirm that policies, risk assessments and training materials exist, but do not test files, transactions, alerts or staff understanding.
How Protegra approaches it
We compare what your policies say with what your business does. Depending on the agreed scope, this may include client-file testing, transaction testing, workflow walkthroughs, interviews and review of alerts or reporting decisions.

The result is a review that looks complete from a distance and becomes unconvincing the moment a bank, regulator or financial partner asks how the conclusion was reached.

What the review covers

What Protegra Actually Does

We do not treat an effectiveness review as a policy checklist or a ceremonial sign-off.

We examine whether your AML/ATF compliance program works across the business you actually operate — then translate the findings into a remediation plan management can use.

Independent AML/ATF Program Assessment

We assess the overall design and operation of your AML/ATF compliance program, including governance, responsibilities, escalation and management oversight.

Policies and Risk Assessments Connected to the Business

We review whether your AML/ATF policies, procedures, enterprise risk assessment and client-risk methodology reflect your current products, services, customers, jurisdictions, technology and transaction flows.

KYC/KYB and Client-Control Testing

We test onboarding and customer-control evidence, including identification and verification, beneficial ownership, PEP/HIO screening, sanctions screening, source-of-funds/source-of-wealth information, EDD and high-risk-client decisions where included in scope.

Transaction Monitoring and Reporting Review

We review the monitoring framework and may test transactions, alerts, investigations, escalation, suspicious-transaction decisions, regulatory reporting and record keeping.

Training and Compliance Governance

We review the training program and records, assess staff understanding where appropriate and examine the compliance officer/CAMLO governance structure, authority and reporting line.

Findings, Recommendations and Remediation

We identify regulatory gaps and control weaknesses, prioritize the findings and produce a remediation action plan with practical next steps, responsible owners, target dates and evidence of closure.

Formal Independent Review Report

You receive a formal report suitable for senior management and potentially useful for regulators, banks and financial partners, subject to their own requirements.

Scope your review

Tell us your business model, products, jurisdictions and prior review history. We will propose the review period, evidence request and sample approach.

Request Review Scope
Our review method

How It Works

Seven stages, from the scope that decides what is tested to the report your senior officer receives.

We start with your business model, products, services, jurisdictions, transaction volumes, systems, prior review history and the reason the review is being requested. This defines the review period, evidence request, testing methodology and sample approach.

We review the relevant policies, procedures, risk assessments, training program, governance records, onboarding framework, reporting processes, monitoring evidence and prior remediation materials.

We compare what your policies say with what your business does. Depending on the agreed scope, this may include client-file testing, transaction testing, workflow walkthroughs, interviews and review of alerts or reporting decisions.

We distinguish between documentation weaknesses, implementation gaps and issues that may affect customer identification, risk assessment, monitoring, escalation, reporting, record keeping or governance.

Every material finding is connected to a recommended action, a responsible owner, a target date and evidence required for closure.

We deliver and explain the independent effectiveness-review report, findings, recommendations, limitations and next steps.

07

Optional CAMLO / Compliance Officer Support

Optional

If the review identifies ongoing ownership or remediation needs, Protegra can discuss outsourced CAMLO / compliance officer support. FINTRAC uses the term “compliance officer”; CAMLO is a commonly used industry title for a chief AML/ATF compliance lead.

Any combined engagement should be scoped carefully so reviewer independence and separation of responsibilities are preserved.

Find the gap.
Before they do.

Pricing

How Much Does an MSB AML Audit Cost in Canada?

One fixed starting price for the review, and a scope-based fee for ongoing compliance ownership if you need it.

01 · REVIEW

Independent AML/ATF Effectiveness Review

from EUR 8,000 + HST

The review may include:

policies and proceduresenterprise risk assessmentclient-risk methodologyKYC/KYBbeneficial ownershipPEP/HIO and sanctions screeningEDDtransaction monitoringreportingrecord keepingtrainingcompliance governanceclient-file testingtransaction testingfindingsrecommendationsremediation planformal report
Request a Scope-Based Quote
02 · ONGOING

Outsourced CAMLO / Compliance Officer

Scope-based ongoing support

If your business needs ongoing AML ownership after the review, Protegra can discuss outsourced CAMLO / compliance-officer support based on your regulatory status, business complexity, transaction profile, internal capacity and required level of oversight.

Discuss CAMLO Pricing ⟶

Final pricing depends on the scope and complexity of the review, business model, transaction volumes, products and services, jurisdictions, regulatory requirements, overall risk profile and number/volume of samples required for testing.

After the review

What Happens After the Review?

A review gives you a clear picture of what is working, what needs attention and which actions should come first.

Protegra can also support the next stage through remediation assistance, policy updates, control improvements and ongoing AML oversight where required.

If your business needs a dedicated person to maintain the program between reviews, learn more about our:

CAMLO Outsourced CAMLO / Compliance Officer Services

FINTRAC uses the term “compliance officer.” CAMLO, meaning Chief Anti-Money Laundering Officer, is a commonly used industry title for a chief AML/ATF compliance lead.

Any combined engagement should be scoped carefully so reviewer independence and separation of responsibilities are preserved.

Hire an Outsourced CAMLO ⟶
FAQ

AML Effectiveness Reviews for Canadian MSBs, Answered

The review
01How often does a Canadian MSB need an effectiveness review?
For businesses subject to the applicable Canadian requirement, the effectiveness review generally must be completed at least every two years. A bank, payment provider or other counterparty may request a more recent independent review.
02Does the review need to be independent?
The review should provide impartial challenge and be performed by someone with the necessary knowledge. If the same person designed or operates the controls, independence and scope limitations should be assessed carefully.
03Does the review include client-file and transaction testing?
It may. Sample-based client-file and transaction testing can be included where relevant to the business model and agreed scope. The number and volume of samples affect final pricing.
04What happens if you find weaknesses?
You receive findings, recommendations and a remediation action plan. Protegra can also discuss follow-up implementation and validation support.
05Can a bank request a review before the two-year deadline?
Yes. A bank, payment provider, financial institution or other counterparty may request a more recent independent review as part of its own due diligence.
06What does FINTRAC call the AML lead?
FINTRAC uses the term “compliance officer.” CAMLO means Chief Anti-Money Laundering Officer and is a commonly used industry title. Protegra uses “Outsourced CAMLO / Compliance Officer” for commercial clarity and regulatory accuracy.
07Does a CAMLO replace the effectiveness review?
No. A CAMLO or compliance officer provides ongoing ownership and oversight. An effectiveness review independently tests whether the program works.
08Does this guarantee a FINTRAC or banking outcome?
No. The review supports readiness and remediation, but no consultant can guarantee a regulatory or banking decision.
What the regulations require
09When must the next effectiveness review start?
No later than 24 months after the start of the previous review, and the previous review must be complete before the next one begins. The two-year cycle in PCMLTFR s. 156(3) is a minimum: a business can review more often, and a counterparty may ask it to.
10Can our own compliance officer perform the review?
The regulations allow the review to be carried out by an internal or external auditor, or by the business itself if it has no auditor. FINTRAC’s guidance adds that the reviewer should know the requirements of the Act and, as a best practice, should not be directly involved in the compliance program activities being reviewed.
11What must the review plan contain?
FINTRAC expects a documented plan that sets out the areas of focus and the rationale behind them, the period under review, the evaluation methods and the sample sizes. No minimum sample size is prescribed; the plan has to justify the one it uses.
12What must the review report record?
The date of the review, the period it covered and who performed it, the results of the tests, and the conclusions — deficiencies, recommendations and action plans. An entity must then report the findings, any policy updates made during the period and the status of their implementation in writing to a senior officer within 30 days of completing the review (s. 156(4)).
13How is the review different from a FINTRAC examination?
An examination is FINTRAC’s own compliance check and can lead to penalties. The effectiveness review is your obligation, carried out on your side. The two meet in practice: FINTRAC’s penalty notices against MSBs show examiners reading the review itself — whether it tested effectiveness and documented its scope, date, period covered and results.
14What happens if the review is missing or only on paper?
Since 26 March 2026, failing to conduct the review or to report it to a senior officer is a very serious violation, with penalties of up to CAD 20,000,000 per violation for an entity; before, it was a serious violation capped at CAD 100,000. FINTRAC’s published penalty guide treats a review that does not test effectiveness almost as harshly as no review at all, and its 2024–2026 notices against MSBs cite reviews that were never done or did not document their testing.
15Do foreign MSBs and virtual-currency dealers need the same review?
Yes. The compliance program requirement, including the two-year review, applies to every reporting entity under the PCMLTFA — domestic MSBs, foreign MSBs serving people in Canada and virtual-currency dealers alike. For a crypto business the testing extends to virtual-currency obligations such as the travel rule and large virtual currency transaction reports.
16Is the effectiveness review becoming annual?
Not under current law. PCMLTFR s. 156(3), as consolidated on 3 September 2026, still requires a review every two years, and the March 2026 amendments to the PCMLTFA did not change the frequency. They raised the standard — the program must be reasonably designed, risk-based and effective — and the penalties. Annual reviews apply under the separate Retail Payment Activities Act to payment service providers, and some banks ask for them contractually.
Request a confidential review scope

Compliance That Holds Up When Someone Looks Closely

Find out what your AML/ATF program needs to prove — and what needs to change before the next review, inquiry or counterparty request.

Need ongoing AML ownership after the review?Hire an Outsourced CAMLO ⟶
Blog

Latest news from Protegra