Canada KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Canada.

Direct answer
What does the Canada compliance checklist cover?
The Canada checklist translates primary KYC, KYB and AML rules into 11 control areas and 44 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML framework
- PCMLTFA and its regulations, with sector-specific reporting-entity duties
- Financial intelligence unit
- Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
- Suspicious transaction report
- No monetary threshold; submit as soon as practicable after reasonable grounds to suspect are established
- Large cash report
- CAD 10,000 or more, including qualifying 24-hour aggregation; file within 15 calendar days
- Large virtual-currency report
- CAD 10,000 equivalent or more, including qualifying 24-hour aggregation; file within 5 working days
- International EFT report
- CAD 10,000 or more for prescribed initiation or final-receipt roles; file within 5 business days
- AML beneficial ownership
- Individuals directly or indirectly owning or controlling at least 25%, plus ownership and control structure
- CBCA significant control
- 25% voting rights or fair-market-value shares, or control in fact; federal corporations have register and filing duties
- Core AML retention
- Generally at least 5 years, but the event starting the clock varies by record
- MSB registration
- Canadian and qualifying foreign MSBs must register with FINTRAC before operating
- Retail payment providers
- In-scope PSPs must register with the Bank of Canada and meet operational-risk and safeguarding rules
- FATF public lists
- Canada was not named on the FATF public-list page reviewed 31 July 2026
Implementation detail
Canada compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensing perimeterResolve the legal entity, activities, customers, delivery model and provincial nexus first. Federal AML registration or reporting status does not replace another federal or provincial authorization.4 items+
PCMLTFA obligations apply to the persons and entities in section 5, with detailed duties that vary by reporting-entity category and activity.
- Implementation action
- Map each entity, product and flow to the applicable section 5 category and regulations before assigning controls.
- Evidence to retain
- Signed perimeter memorandum, activity map, reporting-entity classification, regulator mapping and legal conclusions.
- Primary citation
- PCMLTFA, ss. 5-6; FINTRAC, Who must report
Canadian MSBs and foreign MSBs that direct and provide prescribed services to persons or entities in Canada must register with FINTRAC before beginning covered operations.
- Implementation action
- Classify foreign exchange, remittance, money-order, crowdfunding and virtual-currency services; complete registration before launch and keep registration information current.
- Evidence to retain
- Service analysis, registration application, FINTRAC number, registry extract, renewal calendar and change filings.
- Primary citation
- PCMLTFA, ss. 11.1-11.2; FINTRAC, Money services businesses
An in-scope payment service provider must be registered with the Bank of Canada before performing retail payment activities, subject to the RPAA geographic test and exclusions.
- Implementation action
- Apply the five payment-function test, geographic scope and exclusions; obtain registration before launch and separately assess FINTRAC MSB status.
- Evidence to retain
- RPAA scope memo, registration decision, public-registry extract and AML registration reconciliation.
- Primary citation
- RPAA, ss. 2, 4-6 and 23; Bank of Canada, Criteria for registering PSPs
Provincial laws can separately regulate money services, securities, consumer contracts, privacy and corporate records.
- Implementation action
- Build a province-by-province matrix for every customer and operating nexus; document licences, registrations and exemptions before service begins.
- Evidence to retain
- Provincial matrix, regulator correspondence, licences, exemptions, counsel advice and renewal controls.
- Primary citation
- FINTRAC, MSB guidance; Bank of Canada, RPAA registration criteria
02Compliance program, governance and risk assessmentA reporting entity's program must be reasonably designed, risk-based and effective, not a generic policy pack detached from its Canadian activities.4 items+
Every reporting entity must establish and implement the prescribed compliance program and ensure it is reasonably designed, risk-based and effective.
- Implementation action
- Obtain senior approval for a program mapped to the entity's category, products, customers, channels, geography and sanctions-evasion exposure.
- Evidence to retain
- Approved program, legal mapping, board record, risk appetite, control inventory and accountable owners.
- Primary citation
- PCMLTFA, s. 9.6(1)-(2); PCMLTFR, s. 156
The program includes a compliance officer, written policies and procedures, documented risk assessment, ongoing training and an effectiveness review at least every two years.
- Implementation action
- Appoint an empowered officer, calendar training and independent testing, and track findings to verified closure.
- Evidence to retain
- Appointment, role charter, policy set, risk assessment, training logs, two-year review and remediation register.
- Primary citation
- PCMLTFR, s. 156; FINTRAC, Compliance program requirements
High-risk situations require prescribed special measures, including enhanced identification, relationship information and ongoing monitoring measures appropriate to the risk.
- Implementation action
- Define high-risk triggers and enhanced controls, approvals, review frequency and transaction monitoring; record the rationale for residual risk.
- Evidence to retain
- Risk methodology, high-risk file, enhanced checks, approvals, monitoring results and exception log.
- Primary citation
- PCMLTFA, s. 9.6(3); PCMLTFR, s. 157
Use of an agent, mandatary or service provider does not remove the reporting entity's responsibility; MSBs also have current duties to review agent eligibility and criminal records.
- Implementation action
- Perform pre-appointment and prescribed periodic agent checks, contract for compliance evidence, monitor performance and retain exit capability.
- Evidence to retain
- Eligibility review, criminal-record material, contract, agent list, oversight reports, issues and termination plan.
- Primary citation
- PCMLTFA, ss. 9.92-9.93; PCMLTFR, ss. 37.1 and 133; FINTRAC, MSB guidance
03Natural-person identification and verificationIdentity triggers and permitted methods depend on the reporting-entity sector and transaction. Configure the precise rule, not a single universal onboarding threshold.4 items+
FINTRAC permits prescribed verification methods including government-issued photo identification, Canadian credit file, dual process, qualifying affiliate or member confirmation, and reliance arrangements.
- Implementation action
- Configure methods by sector and use case; retain required details showing the source was authentic or reliable, valid and current.
- Evidence to retain
- Method matrix, vendor configuration, source details, verification result, timestamps and quality tests.
- Primary citation
- PCMLTFR, ss. 105-109; FINTRAC, Methods to verify identity
Remote use of government-issued photo identification requires a process that authenticates the document and matches it to the person; collecting an image alone is insufficient.
- Implementation action
- Test document security, liveness or person match as appropriate, fraud signals, accessibility and manual escalation before accepting remote identity.
- Evidence to retain
- Authentication specification, vendor tests, decision logs, fraud review, exceptions and sampled files.
- Primary citation
- FINTRAC, Methods to verify identity, government-issued photo ID method
Identity must be verified at the prescribed sector and transaction triggers, including suspicious completed or attempted transactions regardless of amount where the rule applies.
- Implementation action
- Map every account, service and transaction trigger to timing, method and exceptions; route failed or incomplete verification to a controlled decision before proceeding.
- Evidence to retain
- Trigger matrix, workflow rules, attempted-transaction records, restrictions, closure decisions and STR assessment.
- Primary citation
- PCMLTFR, ss. 83-104 and 154; FINTRAC, When to verify identity
An agent or mandatary used for verification must operate under the prescribed written arrangement and provide the information needed for the reporting entity's records.
- Implementation action
- Execute a compliant agreement, validate the agent's method, retrieve evidence promptly and test the arrangement periodically.
- Evidence to retain
- Agreement, agent due diligence, method records, retrieval tests, sample reviews and corrective actions.
- Primary citation
- PCMLTFR, ss. 109 and 109.1; FINTRAC identity-method guidance
04KYB, registries and beneficial ownershipKeep AML beneficial ownership under the PCMLTFR separate from a corporation's own ISC duties. Provincial entities also require their own registry analysis.4 items+
Entity verification uses prescribed sources to confirm existence and requires the reporting entity to record the relevant incorporation, registration or governing details.
- Implementation action
- Obtain current registry and constitutional material, verify status and authority, and identify persons authorized to bind or instruct for the entity.
- Evidence to retain
- Registry extract, constituting documents, business number, addresses, directors, signatory authority and verification log.
- Primary citation
- PCMLTFR, ss. 106-109; FINTRAC, Methods to verify identity
For a corporation, AML records include directors, individuals directly or indirectly owning or controlling at least 25% of shares, and information establishing ownership, control and structure; trusts and other entities have tailored tests.
- Implementation action
- Trace every ownership layer to natural persons, calculate direct and indirect interests, record control and trust parties, and document when nobody reaches 25%.
- Evidence to retain
- Ownership chart, calculations, director list, trust records, source documents, confirmation steps and approvals.
- Primary citation
- PCMLTFR, s. 138; FINTRAC, Beneficial ownership requirements
Beneficial-ownership accuracy must be reasonably confirmed initially and during ongoing monitoring; prescribed high-risk CBCA cases require consultation of public ISC information. A material discrepancy must be reported within 30 days unless resolved within that period.
- Implementation action
- Compare customer data with reliable records and the federal ISC registry when required; resolve the discrepancy within 30 days or submit the prescribed report and retain the acknowledgement.
- Evidence to retain
- Registry search, comparison record, discrepancy case, customer clarification, Schedule 7 report and receipt.
- Primary citation
- PCMLTFR, ss. 138(2)-(5), 138.1 and Schedule 7
Most CBCA corporations maintain an ISC register and file ISC information with Corporations Canada; significant control includes at least 25% of voting rights or fair-market-value shares and control in fact.
- Implementation action
- For a federal corporation, identify ISCs, update the register at least annually and within 15 days of known changes, and make the required event and annual filings.
- Evidence to retain
- ISC register, annual enquiry, shareholder responses, change log, filings, receipts and exemption record.
- Primary citation
- CBCA, ss. 2.1, 21.1 and 21.21; Corporations Canada, ISC filing guidance
05PEPs, HIOs and enhanced due diligenceCanadian PEP and head-of-international-organization duties vary by sector, account, relationship and transaction. Family-member and close-associate scope must follow the precise rule.4 items+
Financial entities, securities dealers and casinos have prescribed account-related duties to determine PEP, HIO, family-member and specified close-associate status at opening, through periodic monitoring and when relevant facts are detected.
- Implementation action
- Screen at each legal trigger, capture relationship and office details, and route possible matches to trained adjudication.
- Evidence to retain
- Screening configuration, match evidence, periodic-monitoring log, relationship analysis and disposition.
- Primary citation
- PCMLTFR, ss. 121-123; FINTRAC, Account-based PEP and HIO guidance
Specified sectors have transaction-related PEP and HIO determinations for prescribed transactions of CAD 100,000 or more, including certain international EFT and virtual-currency events.
- Implementation action
- Configure the exact sector and transaction triggers, aggregation where required, determination steps and escalation.
- Evidence to retain
- Trigger rules, transaction sample, determination record, relationship data, approval and monitoring case.
- Primary citation
- PCMLTFR, ss. 121-123; FINTRAC, Account-based PEP and HIO guidance
A foreign PEP determination triggers prescribed source-of-funds and source-of-wealth measures, senior-management review and enhanced ongoing monitoring for account-based sectors.
- Implementation action
- Establish and corroborate wealth and funds, obtain the required senior decision, define enhanced scenarios and review the relationship at the prescribed cadence.
- Evidence to retain
- Wealth narrative, source documents, senior approval, enhanced-monitoring plan, alerts and periodic review.
- Primary citation
- PCMLTFR, ss. 121-123; FINTRAC, PEP and HIO guidance
Domestic PEP and HIO status requires a risk determination rather than an automatic prohibition; prescribed measures follow when the relationship is high risk.
- Implementation action
- Document the risk assessment and apply enhanced measures proportionately, without treating status alone as proof of criminality.
- Evidence to retain
- Risk decision, supporting factors, enhanced checks, approvals, monitoring and review record.
- Primary citation
- PCMLTFR, ss. 121-123; FINTRAC, PEP and HIO guidance
06Monitoring, suspicious reporting and confidentialitySuspicion reporting has no monetary threshold. Case records must show when reasonable grounds to suspect were established and why submission was timely.4 items+
A reporting entity submits an STR for a completed or attempted transaction when there are reasonable grounds to suspect a connection to money laundering, terrorist activity financing or sanctions evasion.
- Implementation action
- Monitor relevant activity, connect indicators to facts and context, and document the legal threshold for both filing and non-filing outcomes.
- Evidence to retain
- Scenario inventory, alerts, linked activity, investigation notes, decision rationale and STR receipt.
- Primary citation
- PCMLTFA, s. 7; Suspicious Transaction Reporting Regulations, s. 9; FINTRAC STR guidance
The STR is due as soon as practicable after completing the measures that enable the entity to establish reasonable grounds to suspect; there is no fixed monetary threshold or ordinary day count.
- Implementation action
- Timestamp detection, investigation and threshold decisions; prioritize submission and record a suitable explanation for any delay.
- Evidence to retain
- Case chronology, threshold approval, queue metrics, delay rationale, filing time and acknowledgement.
- Primary citation
- Suspicious Transaction Reporting Regulations, s. 9(2); FINTRAC, Reporting suspicious transactions
Subsequent suspicious transactions remain reportable while suspicion persists, and a threshold report does not replace an STR.
- Implementation action
- Link related cases and reports, reassess the customer periodically, and file every separately applicable cash, virtual-currency or EFT report.
- Evidence to retain
- Related-report references, customer reassessment, filing reconciliation and monitoring history.
- Primary citation
- FINTRAC, Reporting suspicious transactions, sections 7-8
A person must not disclose an STR or its contents with the intent to prejudice a criminal investigation.
- Implementation action
- Restrict STR access, prevent customer-facing tipping off, control legal and law-enforcement requests, and train staff on permitted handling.
- Evidence to retain
- Access list, audit logs, training, disclosure procedure, tested response and incident records.
- Primary citation
- PCMLTFA, s. 8; FINTRAC STR guidance
07Cash, virtual currency, EFTs and the travel ruleBuild separate reporting decisions for cash, virtual currency and international electronic funds transfers. Apply the current 24-hour aggregation mechanics and exceptions for each report type.4 items+
A reporting entity generally files an LCTR after receiving CAD 10,000 or more in cash in one transaction or qualifying aggregated transactions within a consecutive 24-hour window, subject to exceptions.
- Implementation action
- Aggregate by the prescribed conductor, third-party or beneficiary relationship, identify required parties and file within 15 calendar days after receipt.
- Evidence to retain
- Aggregation logic, LCTR, acknowledgement, identity and third-party records, exception and reconciliation.
- Primary citation
- PCMLTFR, ss. 126 and 132(3); FINTRAC LCTR and 24-hour-rule guidance
A reporting entity in scope generally files an LVCTR after receiving virtual currency worth CAD 10,000 or more in one transaction or qualifying 24-hour aggregation.
- Implementation action
- Apply the prescribed valuation, receipt and aggregation rules; capture wallet and transaction details and file within 5 working days.
- Evidence to retain
- Valuation source, wallet data, aggregation output, LVCTR, receipt, exceptions and quality review.
- Primary citation
- PCMLTFR, ss. 125, 126 and 132(4); FINTRAC LVCTR guidance
Prescribed financial entities, MSBs, foreign MSBs and casinos report initiation or final receipt of qualifying international EFTs of CAD 10,000 or more, including applicable 24-hour aggregation.
- Implementation action
- Determine the entity's role, cross-border character and aggregation; file within 5 business days after initiation or final receipt.
- Evidence to retain
- Funds-flow map, transaction data, aggregation test, EFTR, acknowledgement and filing reconciliation.
- Primary citation
- PCMLTFR, ss. 127-129 and 132(1); FINTRAC EFT guidance
The travel rule requires specified originator and beneficiary information to accompany prescribed EFT and virtual-currency transfers; recipients take reasonable measures when information is missing.
- Implementation action
- Configure mandatory message fields, preserve received information, hold or reject according to a documented risk-based policy, and test intermediaries and vendors.
- Evidence to retain
- Message specification, transfer samples, missing-data cases, disposition rationale, vendor tests and monitoring.
- Primary citation
- PCMLTFA, s. 9.5; PCMLTFR, ss. 124-124.1; FINTRAC travel-rule guidance
08Targeted financial sanctions and listed propertyCanada's sanctions programs are regulation-specific. The consolidated autonomous list is a useful screening aid but has no force of law and does not replace the operative schedules and prohibitions.4 items+
Canadian persons and persons in Canada must comply with applicable prohibitions and dealing restrictions under the Criminal Code, United Nations Act, SEMA, JVCFOA and program-specific regulations.
- Implementation action
- Map products, persons, ownership, control, geography and activity to every applicable regulation and screen against current operative schedules.
- Evidence to retain
- Sanctions perimeter, regulation inventory, list versions, screening logs, ownership analysis and legal decisions.
- Primary citation
- United Nations Act; SEMA; JVCFOA; Global Affairs Canada, Current sanctions
The consolidated Canadian autonomous sanctions list is administrative and may lag amendments; the relevant regulation determines who is listed and what prohibition applies.
- Implementation action
- Use the consolidated list for detection but verify every potential match against the current regulation and schedule before disposition.
- Evidence to retain
- Screening hit, regulatory verification, identity evidence, disposition, approval and list-update testing.
- Primary citation
- Global Affairs Canada, Consolidated Canadian Autonomous Sanctions List
Where the statutory trigger is met, listed person or entity property must be reported to FINTRAC without delay, in addition to disclosures, freezes or other action required by the underlying law.
- Implementation action
- Freeze or restrict as the operative rule requires, escalate immediately, submit the FINTRAC property report and make every other required disclosure without tipping off.
- Evidence to retain
- Property record, freeze or restriction, legal analysis, FINTRAC report, authority disclosure and timestamps.
- Primary citation
- PCMLTFA, s. 7.1; FINTRAC, Reporting listed person or entity property
A completed or attempted transaction suspected to relate to sanctions evasion also requires an STR; a property report does not replace that assessment.
- Implementation action
- Run a separate reasonable-grounds-to-suspect assessment, file promptly when met and link related property and transaction reports.
- Evidence to retain
- Sanctions-evasion case, facts and indicators, STR decision, filings, cross-references and acknowledgement.
- Primary citation
- PCMLTFA, ss. 2 and 7; FINTRAC, Report suspected sanctions evasion
09Records, retrieval and regulator accessFive years is common in the AML regulations, but the event that starts the clock depends on the record. Keep a record-level schedule rather than applying one deletion date to every file.4 items+
Records required by the PCMLTFR are generally retained for at least five years after the record-specific event, such as the transaction, account closure or last business transaction.
- Implementation action
- Map each record class to its exact trigger and legal hold; prevent early deletion and dispose securely when retention and other-law needs end.
- Evidence to retain
- Retention schedule, trigger mapping, system rules, legal holds, deletion certificates and sampled records.
- Primary citation
- PCMLTFR, s. 148; FINTRAC record-keeping guidance
Required records may be electronic if a paper copy can readily be produced and must be retrievable in the form and time required by FINTRAC.
- Implementation action
- Preserve authenticity, readability and linkages; test regulator retrieval across customers, accounts, transactions, reports and source evidence.
- Evidence to retain
- Data map, retrieval test, access logs, export sample, backup restore and issue remediation.
- Primary citation
- PCMLTFR, ss. 147-149
Beneficial-ownership records are kept for at least five years after the last business transaction, and STR-related records have their own prescribed retention requirements.
- Implementation action
- Create separate clocks for business relationships, beneficial ownership, transaction records and report copies; record the closure or last-transaction event.
- Evidence to retain
- Customer timeline, beneficial-owner record, STR copy, clock calculation and retention test.
- Primary citation
- PCMLTFR, ss. 138(5) and 148; Suspicious Transaction Reporting Regulations
Outsourcing storage or case management does not transfer accountability for complete, secure and prompt production.
- Implementation action
- Contract for Canadian legal requirements, access, export, preservation, incident notice and exit; exercise retrieval and migration periodically.
- Evidence to retain
- Vendor contract, data locations, access controls, retrieval exercise, incident test and exit package.
- Primary citation
- PCMLTFA, ss. 6 and 62; PCMLTFR, ss. 147-149
10Privacy, biometrics and transfersResolve whether PIPEDA, a substantially similar provincial law, sector law or several regimes apply. AML retention authority does not authorize unrelated collection or indefinite reuse.4 items+
PIPEDA requires accountability, identified purposes, appropriate consent where required, collection limitation, safeguards, access and retention controls for personal information in scope.
- Implementation action
- Map every KYC data element and purpose, identify legal authority and consent, minimize collection, control access and set defensible retention and deletion.
- Evidence to retain
- Data inventory, purpose and authority register, notices, consent record, access matrix, retention and privacy assessment.
- Primary citation
- PIPEDA, ss. 5-7 and Schedule 1; OPC, Privacy Guide for Businesses
Biometric templates and identity signals can be sensitive personal information; necessity, effectiveness, proportionality, consent and security must be assessed in the applicable jurisdiction.
- Implementation action
- Complete a privacy impact assessment before biometric use, document alternatives and bias testing, separate templates, limit reuse and provide deletion controls.
- Evidence to retain
- Privacy impact assessment, necessity test, consent flow, model tests, security design, vendor terms and deletion proof.
- Primary citation
- PIPEDA, ss. 5-7 and Schedule 1; OPC guidance on biometrics and sensitive information
Under PIPEDA, a breach posing a real risk of significant harm must be reported to the OPC and notified to affected individuals as soon as feasible; records of every safeguards breach are kept for 24 months.
- Implementation action
- Assess harm promptly, document the decision, report and notify when required, inform relevant third parties, and retain the complete breach record.
- Evidence to retain
- Incident chronology, harm assessment, OPC report, notices, third-party communications and 24-month record control.
- Primary citation
- PIPEDA, ss. 10.1-10.3; Breach of Security Safeguards Regulations, s. 6
An organization remains accountable for personal information transferred to a processor, including processing outside Canada, and must use contractual or other means to provide comparable protection.
- Implementation action
- Map locations and sub-processors, assess legal-access and security risk, contract for comparable safeguards, disclose cross-border practices and test deletion and return.
- Evidence to retain
- Transfer map, vendor assessment, contract, transparency notice, security review, audit and exit evidence.
- Primary citation
- PIPEDA Schedule 1, principles 4.1.3 and 4.8; OPC cross-border processing guidance
11Payments, agents and practical evidence packsTurn the legal perimeter into testable launch gates. Payment providers may simultaneously face RPAA, FINTRAC and provincial obligations.4 items+
Since 8 September 2025, in-scope PSPs must maintain the prescribed operational-risk and incident-response framework and safeguard end-user funds when they hold them.
- Implementation action
- Implement the written frameworks, map systems and third parties, test incidents, reconcile safeguarded funds and obtain legal support for the safeguarding arrangement.
- Evidence to retain
- Frameworks, risk register, incident exercise, safeguarding legal analysis, daily reconciliation, exceptions and remediation.
- Primary citation
- RPAA, ss. 17-20; RPAR, ss. 5-17; Bank of Canada supervisory framework
Registered PSPs submit an annual report by 31 March following the reporting year and make other prescribed change, incident and new-activity reports.
- Implementation action
- Maintain a Bank of Canada obligations calendar, assign owners and reconcile every report to source data and registration information.
- Evidence to retain
- Calendar, annual report, source reconciliation, change notices, incident reports, acknowledgements and approvals.
- Primary citation
- RPAA, ss. 21 and 22; RPAR, ss. 18-20; Bank of Canada reporting guidance
A reporting entity remains responsible for activities performed through agents or service providers and must maintain evidence that delegated controls operate effectively.
- Implementation action
- Define responsibility, data and escalation in contracts; test onboarding, monitoring, reporting, privacy and sanctions controls end to end.
- Evidence to retain
- Responsibility matrix, contracts, control tests, case samples, service metrics, findings and verified remediation.
- Primary citation
- PCMLTFR, s. 133; RPAA, s. 87; Bank of Canada registration guidance
Each checklist row requires an explicit applicability decision, owner, current source and reconstructable operating evidence before launch.
- Implementation action
- Mark each row applicable, not applicable or pending legal confirmation; close blockers and obtain compliance, privacy, security and product approvals.
- Evidence to retain
- Completed checklist, applicability rationale, source snapshot, owner sign-off, test result, gap ticket and launch approval.
- Primary citation
- PCMLTFA, s. 9.6; PCMLTFR, s. 156; RPAA, ss. 17-20
Primary-source register
35 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Proceeds of Crime (Money Laundering) and Terrorist Financing ActJustice Laws Website · Primary legislation
- Proceeds of Crime (Money Laundering) and Terrorist Financing RegulationsJustice Laws Website · Primary regulation
- Suspicious Transaction Reporting RegulationsJustice Laws Website · Primary regulation
- FINTRAC obligations and guidance directoryFINTRAC · Official regulator guidance
- Compliance program requirementsFINTRAC · Official regulator guidance
- Methods to verify the identity of persons and entitiesFINTRAC · Official regulator guidance
- When to verify identity - factorsFINTRAC · Official regulator guidance
- Beneficial ownership requirementsFINTRAC · Official regulator guidance
- PEP and HIO guidance for account-based sectorsFINTRAC · Official regulator guidance
- Reporting suspicious transactionsFINTRAC · Official regulator guidance
- Reporting large cash transactionsFINTRAC · Official regulator guidance
- Reporting large virtual currency transactionsFINTRAC · Official regulator guidance
- Reporting electronic funds transfersFINTRAC · Official regulator guidance
- Reporting transactions under the 24-hour ruleFINTRAC · Official regulator guidance
- Travel rule for EFT and virtual-currency transfersFINTRAC · Official regulator guidance
- Reporting listed person or entity propertyFINTRAC · Official regulator guidance
- FINTRAC money services business guidanceFINTRAC · Official regulator guidance
- Money Services Business RegistryFINTRAC · Official register
- Canada Business Corporations ActJustice Laws Website · Primary legislation
- Individuals with significant controlCorporations Canada · Official registry guidance
- ISC filing requirementsCorporations Canada · Official registry guidance
- United Nations ActJustice Laws Website · Primary legislation
- Special Economic Measures ActJustice Laws Website · Primary legislation
- Current sanctions imposed by CanadaGlobal Affairs Canada · Official government guidance
- Consolidated Canadian Autonomous Sanctions ListGlobal Affairs Canada · Official administrative screening list
- Personal Information Protection and Electronic Documents ActJustice Laws Website · Primary legislation
- Breach of Security Safeguards RegulationsJustice Laws Website · Primary regulation
- Privacy Guide for BusinessesOffice of the Privacy Commissioner of Canada · Official regulator guidance
- Privacy breaches at your businessOffice of the Privacy Commissioner of Canada · Official regulator guidance
- Retail Payment Activities ActJustice Laws Website · Primary legislation
- Retail Payment Activities RegulationsJustice Laws Website · Primary regulation
- Retail payments supervisory frameworkBank of Canada · Official regulator framework
- Criteria for registering payment service providersBank of Canada · Official regulator guidance
- FATF Canada country pageFinancial Action Task Force · Official international assessment
- FATF black and grey listsFinancial Action Task Force · Official current-status source
Direct answers
Canada KYC, KYB and AML questions
Is every Canadian business a FINTRAC reporting entity?+
No. PCMLTFA section 5 and the regulations define covered categories and activities. Classify the entity and each product before applying reporting, verification or record-keeping duties.
When is a suspicious transaction report due?+
As soon as practicable after the reporting entity completes the measures that establish reasonable grounds to suspect a completed or attempted transaction relates to money laundering, terrorist financing or sanctions evasion. There is no monetary threshold.
What are the major CAD 10,000 reports?+
Depending on reporting-entity type and transaction, CAD 10,000 can trigger large cash, large virtual-currency or international EFT reporting, including prescribed 24-hour aggregation. Their scope and deadlines differ.
What is Canada's AML beneficial-ownership threshold?+
For corporations and many other entities, FINTRAC rules focus on individuals who directly or indirectly own or control at least 25%. The reporting entity must also understand ownership, control and structure and apply tailored trust rules.
Is the CBCA ISC register the same as FINTRAC beneficial ownership?+
No. They overlap but have different legal actors and duties. Federal corporations maintain and file ISC information; reporting entities separately collect and confirm beneficial ownership under the PCMLTFR.
Must an MSB register before launch?+
Yes. A Canadian MSB, and a qualifying foreign MSB directing covered services at Canada, must register with FINTRAC before operating. Registration is not a licence or endorsement and does not replace provincial requirements.
Does a payment provider need both FINTRAC and Bank of Canada registration?+
Potentially. FINTRAC MSB status and RPAA payment-service-provider status use different activity and scope tests. A business can fall within both and may also face provincial requirements.
What is the core AML retention period?+
Many required records are kept for at least five years, but the event that starts the period differs by record. Use a record-level schedule rather than one universal deletion date.
What is the PIPEDA breach deadline?+
Where a breach creates a real risk of significant harm, report to the OPC and notify affected individuals as soon as feasible. Keep records of every safeguards breach for 24 months, while checking provincial and sector overlays.
Is Canada on a FATF public list?+
Canada was not named on FATF's current public-list page reviewed on 31 July 2026. It remains a FATF member with published assessment and follow-up history.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
This checklist is general regulatory information, not legal advice, a licence determination or a statement that every row applies to every Canadian business. It reflects primary and authoritative material reviewed on 31 July 2026. Confirm entity type, reporting-entity category, activity, customer, province or territory, incorporation jurisdiction, regulator, registration and licensing perimeter, live FINTRAC reporting instructions, sanctions regulations, privacy scope and later legal developments with qualified Canadian counsel and the competent authorities before launch.