FINTRACUPDATED 2026-06-116 MIN READ
The five elements of a FINTRAC compliance program
FINTRAC expects covered businesses to run a documented compliance program. Here are its five published elements — compliance officer, policies, risk assessment, training, and effectiveness review — framed as an operating calendar.
This is general information, not legal advice. It is not legal, accounting, or compliance advice — rely on the official sources listed at the end of this guide and on your professional advisors.
Why the program itself is the foundation
Businesses covered by Canada’s anti-money-laundering regime are required to establish and maintain a compliance program. This is easy to underweight: the program is not paperwork around the “real” obligations — it is itself an obligation, and it is typically the first thing a FINTRAC examination asks to see.
FINTRAC’s published guidance describes the elements a program must include. The five below follow that structure, translated into the operating question each one answers.
Element one: appoint a compliance officer
Someone must be formally responsible for the program. In a brokerage this is often the managing broker or a senior administrator; what matters is that the appointment is real and documented — the person has the authority, time, and access to do the job.
Operating question: if FINTRAC called today, does everyone in the office know who answers?
Element two: written policies and procedures
The program needs written, current policies covering how your business meets its obligations — identification, record keeping, reporting, and the situations your team actually encounters. Generic templates age badly; the test is whether the document describes what your staff really do.
Operating question: does the written procedure match the workflow your newest hire was actually taught?
Element three: risk assessment
Covered businesses must assess and document their exposure to money laundering and terrorist financing risk — typically considering clients and business relationships, products and delivery channels, geography, and the impact of new technologies, in line with FINTRAC’s published guidance.
For a brokerage this is more useful than it sounds: it forces a conversation about which transaction patterns deserve closer attention, and it gives the review workflow a documented rationale.
Element four: ongoing training
Staff who touch covered work need training on the obligations and on your procedures — and the training needs to recur, not happen once at onboarding. Keep evidence: dates, attendees, and materials.
Operating question: can you show when each current staff member was last trained, and on what?
Element five: effectiveness review
The program must be reviewed for effectiveness on a recurring cycle — FINTRAC’s published guidance sets the expected cadence (a minimum two-year cycle is the commonly described baseline; confirm the current requirement). The review can be internal or external, but it must be documented, and findings should visibly change the program.
Operating question: what did your last review change?
Making it a calendar, not a binder
The pattern across all five elements: an owner, a date, and evidence. Put the review cycle, training cadence, and policy refresh on a recurring operations calendar with named owners, and the program becomes routine work instead of an annual scramble.
Workflow software can hold the calendar, route the sign-offs, and keep the evidence trail — OpSphere’s task and approval workflows are built for exactly that kind of recurring obligation. The judgment calls stay with your compliance officer and counsel.