Abstract architecture to illustrate structured finance and securitization

27 July 20268 minute read

FINTRAC key compliance takeaways: Industry Day webinar 2026

On June 29, 2026, the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) hosted its annual Industry Day webinar, providing reporting entities with an overview of commonly observed compliance deficiencies, recommended best practices, and comprehensive guidance for strengthening anti-money laundering and anti-terrorist financing (AML/ATF) programs. FINTRAC did not announce new legal or reporting requirements for reporting entities, though they did provide insight as to how FINTRAC may expect reporting entities to conform to their existing obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its associated regulations.

This article summarizes the key themes from that session as they relate to institutional compliance programs. FINTRAC’s observations are organized across five core program areas: Risk Assessment, Ongoing Monitoring, Specialized Training and Plan, Application of Policies and Procedures, and Two-Year Effectiveness Review. For each area, we highlight the deficiencies that FINTRAC has identified, their potential impacts, and the corresponding best practices recommended by the regulator.

We encourage you to review this bulletin alongside your existing compliance framework and to contact our Financial Services or Compliance teams with any questions regarding remediation or enhancement strategies.

Risk assessment

Commonly observed deficiencies

FINTRAC noted that risk assessment methodologies were often inconsistently applied, with risk ratings not clearly linked to underlying controls or overall client risk ratings. Key risk factors were not fully identified or adequately explained, and supporting documentation often lacked sufficient detail and clear connections to mitigating controls. In many cases, clients’ business structures remained unclear or unknown. FINTRAC also found that policies and procedures were not consistently updated to reflect recent guidance and publications. Ongoing client monitoring did not always incorporate new or emerging risk indicators. In addition, documentation supporting both inherent and residual risk assessments was often unclear and failed to demonstrate meaningful links between identified risks, controls, and resulting risk outcomes.

Impact

  • Inadequate application of enhanced due diligence
  • Unreported suspicious transaction reports (STRs)
  • Prioritization that is out of step with a risk-based approach

Best practices

Reporting entities should leverage FINTRAC operational briefs, alerts, and other published guidance to better understand their exposure to money laundering and terrorist financing (ML/TF) risks. Organizations should regularly review FINTRAC guidance and maintain current, comprehensive client-, product-, and business-based risk assessments that reflect evolving risk factors and emerging typologies. The rationale supporting both inherent and residual risk ratings should be clearly documented to ensure assessments are accurate, defensible, and supported by evidence. Reporting entities should also consider Canada's National Risk Assessment and other relevant risk publications when evaluating and documenting their overall ML/TF risk exposure.

Ongoing monitoring

Commonly observed deficiencies

FINTRAC noted that periodic reviews were often conducted infrequently or inconsistently, while enhanced due diligence refreshes frequently lacked sufficient depth and rigor. Communication gaps were also identified among teams responsible for ongoing monitoring, particularly between those managing automated and manual monitoring processes. Reviews were often overly simplified, performed at a high level, and completed at inconsistent intervals. In addition, trigger-event monitoring was frequently limited or applied inconsistently. FINTRAC further found that audit trails were insufficient in many cases, with documentation relying heavily on templates and failing to demonstrate a clear link between analysis performed and the conclusions reached.

Impact

  • Increased exposure to higher ML/TF risks
  • Ineffective periodic client reviews
  • Backlogs in transaction monitoring (TM) or gaps in periodic reviews
  • No prioritization of high-risk alerts and investigations

Best practices

Reporting entities should establish review schedules that are commensurate with the level of risk and ensure that TM processes are appropriately aligned with client risk profiles. Transaction monitoring frameworks should be regularly assessed and updated to reflect changes in risk exposure, customer behaviour, and emerging threats. In addition, TM systems should be tested on a periodic basis to validate the effectiveness of monitoring rules, scenarios, and alert-generation logic, ensuring they remain capable of identifying potentially suspicious activity in a timely and risk-based manner.

Specialized training and plan

Commonly observed deficiencies

FINTRAC noted that training programs were often overly general, outdated, or insufficiently tailored to the specific risks and requirements of the sector. In addition, processes for assessing and testing employee understanding were frequently weak, with gaps identified in the tracking, completion, and documentation of mandatory training activities.

Impact

  • Poor quality investigations and inconsistent outcomes, resulting in the STR threshold not being consistently applied
  • Suspicious transactions may go unreported
  • Increased exposure to risk

Best practices

Reporting entities should deliver targeted, role-specific training that reflects the unique risks associated with their clients, products, services, and operations. Specialized training should be reviewed and updated on an ongoing basis to ensure continued relevance and alignment with regulatory expectations and emerging risk trends. Organizations should maintain robust processes to track training completion and assess employee understanding through appropriate testing and evaluation mechanisms. Training plans and programs should also be adjusted in a timely manner to address identified knowledge gaps, changes in risk exposure, and evolving compliance requirements.

Application of policies and procedures

Commonly observed deficiencies


FINTRAC noted that sanctions indicators and typologies were often outdated, unclear, or applied inconsistently, with supporting documentation lacking clarity and consistency. Documentation relating to reporting obligations and regulatory guidance was frequently incomplete or insufficiently detailed. Guidance pertaining to sanctions and Listed Person or Entity Property Reports was often outdated and provided limited direction on documentation requirements and expectations. Thresholds for identifying and escalating suspicious activity were not always clearly defined, creating uncertainty in decision-making. In addition, policies addressing sanctions evasion, fraud, and other money laundering indicators were often outdated or incomplete, and guidance on the escalation, investigation, and filing of STRs was frequently insufficient.

Impact

  • Weaknesses across all AML program elements
  • Inconsistent application of requirements across all teams
  • Knowledge gaps during staff turnover or business growth

Best practices

Reporting entities should regularly review and update their policies and procedures to ensure alignment with evolving regulatory requirements, emerging risks, and current typologies. Policies should provide clear and practical guidance on escalation processes, documentation standards, and reporting obligations, ensuring that employees understand their roles and responsibilities and can apply requirements consistently across the organization.

Two-year effectiveness review

Commonly observed deficiencies

FINTRAC noted limited evidence demonstrating the outcomes of effectiveness testing, with testing results often being incomplete, insufficiently documented, or lacking meaningful analysis. Risk coverage frameworks were frequently outdated, and remediation efforts were applied inconsistently or proved ineffective in addressing identified deficiencies. Testing activities tended to focus on the existence of controls rather than their effectiveness in mitigating risk. In addition, scenario validation was often limited in scope or not aligned with a risk-based approach. Sample sizes were frequently inadequate or incomplete, and end-to-end testing either lacked sufficient coverage or omitted key components of the process.

Impact

  • Practices not aligned with changes in the organization or regulatory updates
  • Control gaps remain unidentified or unvalidated
  • Reduced confidence in program effectiveness

Best practices

Reporting entities should maintain clear, comprehensive, and well-documented working papers to support their compliance activities and decision-making processes. Testing programs should be designed using a risk-based approach and focus on evaluating the effectiveness of controls rather than merely confirming their existence. In addition, remediation activities should be formally tracked, monitored, and validated to ensure that identified issues are appropriately addressed and that corrective actions have achieved the intended outcomes.

Key takeaways

  • Take a genuinely risk-based approach. Your risk assessment should help you understand where your greatest risks exist, identify the highest-risk areas of your program, determine where enhanced measures are needed, and ensure that measures in place are proportionate to the risks identified.
  • Consistent application matters. Risk assessments, ongoing monitoring, and documentation processes must be applied consistently in practice and supported by clear rationale.
  • Keep your program current. Periodically reviewing the program helps ensure it continues to reflect the current risk environment and that controls remain proportionate to identified risks.
  • Focus on effectiveness testing. Testing should evaluate whether program controls are effective in practice.
  • Ensure program agility. Your program must be able to meet ongoing monitoring obligations by ensuring testing frameworks can respond to emerging ML/TF and sanctions evasion risks.

Next steps

We recommend reviewing these findings against current AML/ATF compliance programs and considering whether enhancements are warranted in light of FINTRAC’s expectations. In particular, institutions should evaluate whether their risk assessments are current and consistently applied, whether monitoring processes are adequately documented and aligned to risk, and whether effectiveness testing goes beyond confirming the mere presence of controls.

If you require assistance or have concerns about your compliance with FINTRAC’s expectations, please reach out to our Financial Services or Compliance teams.