MSB DeskGet My Estimate

CANADIAN MSB GUIDE

The Five Parts of a FINTRAC Compliance Program

Every Canadian MSB must establish a compliance program. FINTRAC identifies five required elements, but the value comes from connecting those elements to daily decisions, customer onboarding and transaction activity.

A usable program tells people what to do, who is responsible and what evidence to keep. This guide explains each part and why replacing business analysis with generic wording leaves important work unfinished.

The five elements reinforce each other. Risk assessment drives procedures and training; the compliance officer oversees their use; and the effectiveness review tests whether they work. Treating any element as a standalone document makes gaps harder to see and responsibilities harder to enforce.

1. Appoint a compliance officer

The compliance officer is responsible for implementing the program. The person needs enough authority and access to influence procedures, obtain information, escalate issues and report to senior management. The appointment should be documented rather than left as an informal expectation.

The officer may receive support from employees, vendors or advisers, but accountability cannot be outsourced. Responsibilities should cover registration maintenance, policies, risk assessment, training, reports, records, quality checks and the effectiveness review.

  • Document the appointment and reporting line
  • Define decision and escalation authority
  • Give access to customer and transaction records
  • Set regular reporting to senior management
  • Plan cover for absence or role changes

2. Write policies and procedures

Policies and procedures translate legal requirements into repeatable actions. They should address when identity is verified, how beneficial ownership is established, which records are retained, how transactions are monitored and when prescribed reports are submitted.

A policy states the rule; a procedure explains the steps. The documents should name roles, systems, review points and evidence. They also need senior-officer approval and a process for updates when the business or legal requirements change.

  • Customer identification and verification
  • Beneficial ownership and third-party determination
  • Record keeping and retention
  • Transaction monitoring and escalation
  • Prescribed reports and deadlines
  • Registration updates and compliance governance

3. Assess business and relationship risk

The risk assessment considers the MSB’s products, services, delivery channels, geography, new technologies and other relevant factors. It should explain why a factor creates lower or higher exposure and which controls respond to it.

Customer or business-relationship risk is related but more specific. The MSB needs a method to rate relationships, apply enhanced measures to high-risk cases and keep those ratings current. A list of generic risk labels is not enough without criteria and actions.

  • Services and transaction types
  • Customer types and expected behaviour
  • Countries and geographic exposure
  • Non-face-to-face and other delivery channels
  • Agents, branches and third parties
  • New technology and virtual-currency features

4. Maintain an ongoing training program and plan

Training should reach employees, agents and other people whose work affects compliance. Content should reflect their role. An onboarding agent needs different practical scenarios from a director receiving compliance reporting.

The plan records who is trained, on what topics, when and how understanding is checked. It should include onboarding, periodic refreshers and updates after material changes. Attendance records alone do not show that people understood how to apply the procedure.

  • Identify every role requiring training
  • Match content to responsibilities
  • Set onboarding and refresher timing
  • Use realistic scenarios from the business
  • Record completion and test understanding
  • Update material when risks or procedures change

5. Review effectiveness at least every two years

FINTRAC requires a review of the effectiveness of the compliance program at least every two years. The review tests whether the program is properly designed and whether people actually follow it. It should examine records, reports, files, training and risk controls rather than simply confirm that documents exist.

The reviewer needs appropriate independence and knowledge. Findings should be documented, reported to senior management and followed by tracked corrective action. Serious gaps should be addressed promptly rather than waiting for the next two-year cycle.

  • Define review scope and testing method
  • Use samples of real records and cases
  • Assess all five program elements
  • Report findings to senior management
  • Assign owners and dates for remediation
  • Retain the review and follow-up evidence

Why generic templates are not enough

A template cannot know the MSB’s customer journey, transaction rails, wallet model, countries, staffing or technology. Generic language often postpones the decisions that matter: which event triggers a check, who sees an alert and where the record is kept.

The registration and compliance documents should use the same services, ownership, volumes and flows. When the documents are built separately, contradictions appear and staff are left to invent procedures during launch.

  • Map each service and transaction flow first
  • Connect risks to controls and evidence
  • Name systems and responsible roles
  • Remove procedures that the business will not use
  • Test the documents against realistic cases

Keep the program current after launch

The compliance program is a working system. A new product, market, agent, payment rail, owner or transaction pattern can change risk and require updates to policies, training, monitoring and registration details.

Set a regular review calendar and define which changes trigger an immediate assessment. Management reporting should show material issues, overdue actions and changes in the business. This keeps the program connected to operations between formal effectiveness reviews.

  • Monitor regulatory and business changes
  • Review high-risk relationships on schedule
  • Update training after material procedure changes
  • Track reports, exceptions and remediation
  • Keep FINTRAC registration information current

See what your MSB project is likely to cost

Choose your company status and planned services to receive an immediate estimate before sharing contact details.

Get My Estimate