What FINTRAC requires
Every business FINTRAC regulates must institute and document a plan to review the effectiveness of its compliance program, and carry out the review at least every two years. The plan must include all the elements of the program: policies and procedures, risk assessment and training.
The review is done by an internal or external auditor or, if you don't have an auditor, by yourself. FINTRAC's best-practice advice is that whoever does it shouldn't be directly involved in the compliance program activities being reviewed, so the review stays impartial.
The checklist
Policies and procedures
- Are they written, current, and approved by a senior officer (if you're an entity)?
- Do they reflect the services you actually offer today, including anything launched since the last review?
- Do they cover identification, beneficial ownership, politically exposed persons, third-party determination, ongoing monitoring, record keeping, reporting, ministerial directives and the travel rule where it applies?
Risk assessment
- Does it cover your clients and business relationships, products, services and delivery channels, geography, and new developments and technologies?
- Has it been updated for new products, markets or agents?
- Do your controls follow from it, with enhanced measures for high risk?
Training
- Is there a written, ongoing training program and plan?
- Did the people who need training, including agents, actually receive it, and are there records?
- Does the content match your risks and your staff's roles?
The program in practice
- Sample client files: was identity verified the way your procedures say?
- Sample transactions: were reportable transactions reported on time, including under the 24-hour rule?
- Review unusual-activity decisions: were STR decisions documented either way?
- Check that records can be produced, and are kept for the required period.
- Check that findings from the last review were actually fixed.
Report to a senior officer within 30 days
No later than 30 days after the review, report in writing to a senior officer: the findings of the review, the updates made to your policies and procedures during the reporting period, and the status of putting those updates in place. Keep the report; it's one of the first things an examiner may ask for.
Common gaps
- A review that checks documents exist but never tests whether they're followed.
- The same review copied from the previous cycle.
- A risk assessment that hasn't changed since launch, though the business has.
- Findings from the last review still open.
- No written report to a senior officer, or one sent late.
Sources: FINTRAC, Compliance program requirements; Risk assessment guidance; The 24-hour rule. Checked 11 October 2026. General information, not legal advice.