Banking & Compliance Readiness

Why One Bank's CDD Approval Doesn't Guarantee Another

Why the same Canadian MSB can receive different banking outcomes β€” and how bank risk appetite, customer acceptance policies and non-portable CDD reviews shape each decision.

On this page
Get Expert Help

Key takeaways

  • FINTRAC registration and AML compliance do not automatically determine whether a particular financial institution will accept an MSB relationship.
  • Different institutions can apply different bank risk appetites, customer acceptance policies and internal review processes to the same underlying MSB facts.
  • A favourable CDD outcome at one bank is not a portable approval that another institution is required to accept.
  • MSBs can reuse current underlying records, but each new application may require refreshed documents, different evidence or additional explanations.
  • The facts about the MSB should remain accurate and consistent across applications; repeated concerns from multiple institutions may point to an AML documentation gap worth remediating.

One MSB, Two Banks, Two Different Risk Decisions

A Canadian MSB submits the same corporate documents, ownership information and AML program materials to two financial institutions. One institution is comfortable proceeding with the relationship. The other asks additional questions, escalates the file internally, imposes conditions, or ultimately decides the relationship does not fit its risk appetite.

This does not necessarily mean either review was wrong, that the MSB became non-compliant between applications, or that the first institution made a mistake. It also does not mean the second institution's questions are routine by default, or that the outcome simply reflects one bank being more conservative than another. Different institutions can apply different internal risk frameworks to the same underlying facts, and understanding that distinction matters more than assuming either institution got it wrong.

Regulatory Compliance and Bank Risk Appetite Are Not the Same Thing

Regulatory compliance is whether the MSB is meeting its obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations β€” FINTRAC registration, a documented compliance program, customer identification, record-keeping and reporting.

Institutional risk acceptance is a separate question: whether a particular financial institution is willing to enter or continue a banking relationship, given its own internal risk appetite, customer acceptance policy and control framework.

Being FINTRAC-registered and operating a functioning compliance program does not require any specific bank to accept the relationship. FINTRAC supervises reporting entities' compliance with the PCMLTFA; it does not direct which customers a bank must onboard. For federally regulated financial institutions, prudential and integrity-related risk oversight sits with OSFI's Integrity and Security Guideline, while FINTRAC remains the primary AML/ATF compliance supervisor β€” a structure that itself illustrates the point: regulatory compliance and an institution's own risk governance run on related but distinct tracks.

Bank discretion is not unlimited. Financial institutions remain subject to applicable laws, regulatory expectations and their own governance and risk-management frameworks. The point is not that a bank can act without constraint β€” it is that regulatory compliance is a threshold input into a bank's own decision, not a determinative one.

What "Bank Risk Appetite" Means for an MSB

An institution's risk appetite describes how much of a given type of risk it is willing to accept in exchange for a customer relationship. For an MSB, this can affect how comfortable a bank is with a given business model, customer base or geographic footprint, even where the MSB's compliance program is sound. One institution may have built the systems and experience to support certain MSB profiles well; another may not have developed the same capability or appetite, independent of how well the MSB manages its own obligations. This is a business and risk-management decision, not a compliance verdict, and it varies from one financial institution to the next.

Why Customer Acceptance Policies Can Differ Between Financial Institutions

Each financial institution sets its own internal customer acceptance policy: which customer types it will serve, what information it requires before onboarding, what circumstances trigger additional internal review or escalation, and what ongoing evidence it expects once a relationship is live. These policies are confidential and vary by institution. No MSB should assume a peer's experience with one institution predicts another institution's policy. Two institutions applying their own, differently calibrated policies to the same underlying facts can reasonably reach different conclusions without either institution having made an error.

How the Same MSB Can Look Different to Two Banks

The factors behind a bank's risk appetite become concrete once an actual application is under review. The same MSB, presenting the same facts, can look different to two institutions for several reasons.

Customer base

One institution may have direct experience serving the MSB's customer profile β€” for example, a remittance provider serving a specific diaspora community β€” while another has less exposure to that segment and reviews it more cautiously as a result.

Products and services

Some institutions have more operational experience supporting particular payment or remittance models than others. That experience can affect how quickly, and how deeply, an application is reviewed.

Geographic and corridor exposure

The same corridor exposure β€” for instance, remittance flows to a specific jurisdiction β€” can be weighed differently depending on how each institution's own risk framework treats that jurisdiction.

Ownership or corporate complexity

Layered, multi-entity or foreign ownership structures may generate more follow-up at one institution than another, depending on how that institution approaches beneficial ownership verification.

Expected transaction activity

An institution's own systems and commercial model can affect its comfort with certain transaction volumes or patterns, independent of whether that activity is legitimate.

Quality and clarity of documentation

Even where the underlying facts are identical, unclear, inconsistent or poorly organized explanations can make one institution's review noticeably more difficult than another's.

No single factor above guarantees a decline. Institutions may weigh these considerations together, alongside their own appetite for the relationship, in ways that are specific to each institution's own process.

Why Previous Approval Is Not Portable

A favourable outcome with one financial institution is not a certification, a licence, or a transferable approval that a second institution is obliged to accept. A second institution may perform its own verification, request its own set of documents, conduct its own sanctions and PEP screening, and interpret the same risk factors through its own framework.

This is a separate question from the detailed mechanics of what a bank's CDD review of an MSB actually involves. The broad categories reviewed may overlap across institutions, even where each institution's process, depth, evidence requirements and outcome differ.

Can You Reuse Documents From a Previous Banking Review?

Often, yes, in part. Current corporate records, ownership information, AML program documentation and risk assessments prepared for one institution may still be substantively useful for another application, since much of the underlying evidence does not change from bank to bank.

However, an MSB should not assume a completed CDD package from one institution will simply be accepted, unread, by another. Documents may need to be refreshed if dates, financials or corporate details have changed. The second institution may ask for a different mix of supporting evidence, and explanations may need to be tailored to the specific questions it raises. Information should never be reused where the underlying facts have actually changed. Treat a previous review as a useful starting inventory of accurate, current information β€” not as a package that transfers automatically.

For broader guidance on the application process, see banking for a Canadian MSB or PSP.

What Should Stay Consistent Across Every Banking Application?

Regardless of which institution is reviewing the file, the underlying facts about the MSB should not change. This includes legal entity details and corporate registration information, ownership and control structure, FINTRAC registration information, the actual services provided, the customer types served, actual transaction flows and corridors, and the AML program's actual content.

Different institutions may ask different questions or focus on different areas of concern, but the facts an MSB presents about its own business should be the same everywhere. Adjusting facts to try to match a particular institution's perceived appetite is a credibility risk, not a strategy, and can itself become the reason a relationship is declined or later terminated.

What Can Legitimately Change From One Application to Another?

Presentation can be tailored without changing the underlying facts. Different institutions may request different supporting documents for the same fact pattern; one may ask for more detail on specific corridors while another focuses more on ownership; information may genuinely need updating because the business has changed since the last application; and a risk explanation may be expanded in direct response to a specific question a particular institution raises.

The MSB can answer each institution's questions directly and in the depth it requests, while keeping the facts underneath consistent from one application to the next.

When a Second Bank Asks More Questions, Does That Mean Something Is Wrong?

Not necessarily. Additional questions from a second institution can reflect a different internal process, a different risk threshold, or a different set of information needs, none of which implies the first institution's review was deficient or that the MSB's compliance has weakened.

At the same time, additional questions are not automatically routine, and some follow-up genuinely identifies an issue that deserves a direct answer. The practical response is the same either way: answer accurately, provide supporting evidence, resolve any apparent contradictions promptly, and take the time to understand precisely what the institution is asking before responding.

When Different Banking Outcomes Point to an AML Documentation Problem

If multiple institutions independently raise the same concern β€” the same gap in ownership documentation, the same unclear description of transaction flows, or an outdated risk assessment that no longer reflects the MSB's current business model, customers, products or geographic exposure β€” the recurring pattern is worth examining on its own. At that point the issue may be less about differing bank risk appetites and more about the strength and clarity of the MSB's own AML documentation.

Common patterns worth reviewing include inconsistent ownership records across filings, unclear or generic descriptions of transaction flows, and AML policies that read as templated rather than specific to the business. Where that pattern shows up, AML advisory support can help identify and remediate the underlying documentation gaps before the next banking application, rather than treating each decline as an isolated, unexplained event.

The Bottom Line

A favourable outcome from one bank's CDD review shows that the MSB successfully navigated that institution's process β€” it is not a portable approval across the Canadian banking market. Different institutions can assess the same business through different internal risk frameworks, and an MSB cannot control any individual bank's risk appetite. What it can control is the accuracy, consistency and currency of what it presents, the clarity of its explanations, and the credibility of the AML controls behind them β€” the factors most likely to hold up no matter which institution is reviewing the file.

Bank CDD Outcomes: A Conceptual Comparison

Factor What Stays the Same What May Differ by Institution
Legal entity Actual corporate identity Documents requested to verify it
Ownership Actual ownership and control structure Depth of follow-up on layered or foreign ownership
Business model What the MSB actually does The institution's comfort level with that model
Geography Actual corridor and jurisdiction exposure How that exposure is interpreted within the institution's risk framework
Transaction activity Expected genuine transaction activity Risk tolerance and depth of review applied to it
AML controls The actual compliance program in place Evidence or explanation requested to support it

This is a conceptual comparison to illustrate the distinction between fixed facts and institution-specific interpretation. Actual requirements, questions and outcomes vary by institution.

Frequently Asked Questions

Can a bank see that another financial institution already approved my MSB?

An MSB should not assume that one institution's internal approval decision is automatically visible to, shared with, or binding on another institution. There is no general basis to assume that a previous decision is disclosed to, or determinative for, a different financial institution's own review.

Should I tell a new bank that my MSB already has another banking relationship?

Disclosure requirements vary by institution and circumstance. An MSB should answer each application accurately and completely, and disclose other banking relationships when asked or otherwise required to do so.

Does having multiple banking relationships reduce future CDD requirements?

Not automatically. An existing relationship with one institution does not remove another institution's own onboarding and due-diligence requirements, since each institution applies its own review process and risk framework to a new relationship.

What should an MSB do if two banks interpret the same risk factor differently?

Answer each institution's questions accurately and provide the supporting evidence it asks for, without changing the underlying facts to fit either institution's apparent expectations. Different institutions can reasonably interpret the same risk factor differently, and that difference will not always be fully resolved through explanation alone.

Sources Referenced

  • Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) β€” Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated regulations
  • Office of the Superintendent of Financial Institutions (OSFI) β€” Integrity and Security Guideline and the OSFI/FINTRAC division of supervisory responsibility for federally regulated financial institutions
ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.