Compliance hub

FINTRACUPDATED 2026-06-116 MIN READ

The five elements of a FINTRAC compliance program

FINTRAC expects covered businesses to run a documented compliance program. Here are its five published elements — compliance officer, policies, risk assessment, training, and effectiveness review — framed as an operating calendar.

This is general information, not legal advice. It is not legal, accounting, or compliance advice — rely on the official sources listed at the end of this guide and on your professional advisors.

Why the program itself is the foundation

Businesses covered by Canada’s anti-money-laundering regime are required to establish and maintain a compliance program. This is easy to underweight: the program is not paperwork around the “real” obligations — it is itself an obligation, and it is typically the first thing a FINTRAC examination asks to see.

FINTRAC’s published guidance describes the elements a program must include. The five below follow that structure, translated into the operating question each one answers.

Element one: appoint a compliance officer

Someone must be formally responsible for the program. In a brokerage this is often the managing broker or a senior administrator; what matters is that the appointment is real and documented — the person has the authority, time, and access to do the job.

Operating question: if FINTRAC called today, does everyone in the office know who answers?

Element two: written policies and procedures

The program needs written, current policies covering how your business meets its obligations — identification, record keeping, reporting, and the situations your team actually encounters. Generic templates age badly; the test is whether the document describes what your staff really do.

Operating question: does the written procedure match the workflow your newest hire was actually taught?

Element three: risk assessment

Covered businesses must assess and document their exposure to money laundering and terrorist financing risk — typically considering clients and business relationships, products and delivery channels, geography, and the impact of new technologies, in line with FINTRAC’s published guidance.

For a brokerage this is more useful than it sounds: it forces a conversation about which transaction patterns deserve closer attention, and it gives the review workflow a documented rationale.

Element four: ongoing training

Staff who touch covered work need training on the obligations and on your procedures — and the training needs to recur, not happen once at onboarding. Keep evidence: dates, attendees, and materials.

Operating question: can you show when each current staff member was last trained, and on what?

Element five: effectiveness review

The program must be reviewed for effectiveness on a recurring cycle — FINTRAC’s published guidance sets the expected cadence (a minimum two-year cycle is the commonly described baseline; confirm the current requirement). The review can be internal or external, but it must be documented, and findings should visibly change the program.

Operating question: what did your last review change?

Making it a calendar, not a binder

The pattern across all five elements: an owner, a date, and evidence. Put the review cycle, training cadence, and policy refresh on a recurring operations calendar with named owners, and the program becomes routine work instead of an annual scramble.

Workflow software can hold the calendar, route the sign-offs, and keep the evidence trail — OpSphere’s task and approval workflows are built for exactly that kind of recurring obligation. The judgment calls stay with your compliance officer and counsel.

OFFICIAL SOURCES

WHERE THIS LIVES IN OPSPHERE

OpSphere DealFlowRecurring task and approval workflows that hold the program calendar — review cycles, training cadence, and sign-off evidence. The judgment stays with your compliance officer.

RELATED GUIDES

DISCLAIMER

This guide is a general educational overview written for operations teams. It is not legal, accounting, or compliance advice, it is not a substitute for the official sources it references, and requirements change. Confirm current requirements against the official sources cited on this page and consult your lawyer, accountant, or compliance professional before acting.