The 14 documents you receive
Your fixed fee covers a complete set of PCMLTFA compliance program documents, written for your business:
- AML/ATF Compliance Policy
- KYC and Customer Due Diligence Procedure
- Ongoing Monitoring Procedure
- Business-Wide Risk Assessment
- Sanctions and Watchlist Screening Policy and Procedure
- Ministerial Directive Compliance Policy
- Travel Rule Policy and Procedure
- Applicable FINTRAC Reporting Procedures
- Procedural Registers
- Records Retention Policy
- Staff AML Training Policy
- Compliance Testing and Effectiveness Review Plan
- Risk Appetite Policy
- Fraud Risk Management Policy
Together they cover the policies, procedures, risk assessment, training and review planning behind the five required parts of a FINTRAC compliance program, plus your risk appetite and fraud risk management.
The five parts of a compliance program
FINTRAC's guidance sets out five required elements:
- A compliance officer, appointed to be responsible for implementing the program.
- Written policies and procedures, kept up to date and, for an entity, approved by a senior officer.
- A risk assessment of the business's money laundering and terrorist financing risks, documented.
- A written, ongoing compliance training program, with a plan for delivering it.
- A review of effectiveness of the policies and procedures, risk assessment and training program, at least every two years.
What your policies and procedures cover
- knowing your client: verifying identity, beneficial ownership, and politically exposed persons and heads of international organizations;
- third-party determinations and business relationships;
- ongoing monitoring, and the enhanced measures you apply to high-risk clients;
- sanctions and listed person screening;
- reporting to FINTRAC, including suspicious transactions, and the 24-hour rule;
- record keeping;
- ministerial directives, and how you'll apply new ones;
- travel rule information for funds and virtual currency transfers, where it applies.
The exact list depends on the kind of business you are and the services you offer, which is why we start with how you operate.
Your risk assessment
The risk assessment is the foundation of everything else. It looks at your clients and business relationships, your products, services and delivery channels, the places you operate in and deal with, new developments and technologies, and anything else relevant to your business. Your controls should follow from it: higher risk, closer attention.
If your bank or payment partner has asked for your program
Banks and payment partners usually want to see that your program exists, fits your business, has a named compliance officer, and is actually followed. If you've been asked and don't have one, or aren't sure yours will stand up, book a consultation. We'll tell you what's missing and how quickly it can be put right.
Keeping it current
A program written once and left on a shelf goes out of date as your business and the rules change. We can keep it current through outsourced compliance officer hours, and test it in your two-year effectiveness review.
Sources: FINTRAC, Compliance program requirements; Money services businesses; The 24-hour rule. Checked 11 October 2026. General information, not legal advice.