Each review must start no later than 24 months after the start of the previous one, and the previous review must be complete first (PCMLTFR s. 156(3) and FINTRAC guidance).
Independent AML/ATF Effectiveness Review
for Canadian MSBs
Whether your program is new or already operating, AML effectiveness has to be demonstrable.
FINTRAC generally expects Canadian MSBs to review the effectiveness of their AML/ATF compliance program at least every two years. Banks, payment providers and other financial partners may also request a more recent independent review as part of their own due diligence.
Who This Is For
The two-year effectiveness review is owed by every money services business registered with FINTRAC — domestic MSBs, foreign MSBs serving Canada and virtual-currency dealers alike. These are the situations in which it usually lands on our desk.
A bank or payment provider may ask for a newer one sooner.
Assess Your Review ReadinessCanadian MSBs approaching their review window
who need a structured, independent assessment before the deadline becomes urgent
Virtual-currency and crypto businesses
whose products, transaction flows, customer risk and technology require more than a generic checklist
Money-transfer, remittance and foreign-exchange businesses
that need to demonstrate effective KYC, monitoring, reporting and record keeping
MSBs responding to a bank or payment-provider request
for a current independent compliance review
Businesses whose program has changed
because of new products, jurisdictions, transaction volumes, systems, agents or mandataries
MSBs with open or undocumented findings
that need a practical remediation plan and evidence of closure
Businesses without sufficient internal compliance capacity
that need an independent review now and may need an outsourced CAMLO / compliance officer to maintain the program afterward
Policy exists.
Does it work?
What Does FINTRAC Require from an MSB Effectiveness Review?
An AML/ATF effectiveness review — often called an AML audit — is the test of a Canadian MSB’s compliance program that section 156 of the PCMLTF Regulations requires every two years. It checks whether your policies and procedures, risk assessment and training program work in practice, is performed by an internal or external auditor (or by the business itself if it has no auditor), and ends with a written report to a senior officer within 30 days.
Findings, the policy updates made during the period and the status of their implementation go to a senior officer in writing within 30 days of completing the review (s. 156(4)).
Since 26 March 2026 a missing or deficient review is a very serious violation: up to CAD 20,000,000 for an entity, where the ceiling used to be CAD 100,000.
- Regulator
- Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
- Legal basis
- PCMLTFA s. 9.6 and PCMLTF Regulations s. 156(1)(f), (3) and (4) — see the PCMLTFA in the Licensing Atlas
- What is tested
- Policies and procedures, the risk assessment, and the ongoing compliance training program and plan — including whether day-to-day practice matches the documents
- Who performs it
- An internal or external auditor, or the business itself if it has no auditor; FINTRAC advises someone knowledgeable who is not directly involved in the program
- The review plan
- Areas of focus and the rationale for them, the period reviewed, evaluation methods and sample sizes
- The record
- Date, period covered, who performed it, test results, and conclusions with deficiencies, recommendations and action plans
- Since 26 March 2026
- The program must be “reasonably designed, risk-based and effective” (PCMLTFA s. 9.6(1.1)), not merely documented
Is the review becoming annual? Not under the regulations: as consolidated on 3 September 2026, s. 156(3) still sets a two-year cycle, and the March 2026 reforms did not change it. What changed is the standard and the stakes — the program must now be effective, not only documented, and a failed review is a very serious violation. The two years are a minimum: banks and payment partners may ask for a newer review within their own due-diligence cycle, and an MSB that is also a payment service provider under the Retail Payment Activities Act reviews its risk-management framework at least once a year under that separate regime.
What This Actually Protects
The review is owed to the regulator, but most of what it protects is your own: the banking relationship, the budget and the next review cycle.
Your regulatory readiness
A documented review helps management understand whether the AML/ATF program remains aligned with applicable obligations and operating reality.
Your banking and payment relationships
A bank or payment provider may ask for independent evidence of compliance before onboarding or continuing a relationship.
Your ability to answer questions quickly
A good review creates a clearer record of what was tested, what was found and what is being remediated.
Your remediation budget
Prioritized findings help management distinguish urgent control weaknesses from lower-risk documentation improvements.
Your next review cycle
The report gives you a starting point for planning the next biennial, annual, counterparty-driven or trigger-based review.


