Risk assessment & compliance programs

Canada's 2025 National Risk Assessment: What FINTRAC Reporting Entities Need to Update in 2026

Canada's 2025 National Risk Assessment explained: key threats, vulnerable sectors, and how FINTRAC reporting entities should update their risk assessment.

On this page
Get Expert Help

Key takeaways

  • Canada's 2025 National Risk Assessment remained the operative national assessment as of August 2026.
  • FINTRAC reporting entities should use the assessment as an input to their own risk-based approach rather than copy national ratings directly.
  • A defensible business risk assessment documents which national threats and vulnerabilities are relevant to the actual business and which are not.
  • The assessment can inform customer risk, geographic risk, transaction monitoring, enhanced measures and staff training.
  • Reporting entities should retain evidence showing how the National Risk Assessment was considered and translated into practical controls.

Canada's National Risk Assessment is the federal government's periodic, country-level analysis of the money laundering and terrorist financing threats and vulnerabilities facing Canada. The current edition, the 2025 Assessment of Money Laundering and Terrorist Financing Risks in Canada, was published in August 2025 and remains the operative national assessment as of August 2026; no newer edition has replaced it. FINTRAC expects reporting entities to use it as a foundational input into their own risk-based approach, not as a document to file away once read.

That does not mean copying the report's national findings directly into a business risk assessment. A threat rated high nationally may have little relevance to a specific reporting entity's actual clients, products, and geography, and a business that treats every national finding as automatically applicable to itself ends up with a risk assessment that looks thorough but explains nothing about its own operations. This article translates the 2025 findings that matter most to MSBs, PSPs, and fintechs into concrete questions a compliance officer should be asking in 2026, and explains how to combine the report with newer FINTRAC intelligence rather than treating it as the only current risk source.

What Is Canada's 2025 National Risk Assessment?

The 2025 Assessment of Money Laundering and Terrorist Financing Risks in Canada is a federal report, published by the Department of Finance Canada in August 2025, that identifies and rates the country's most significant money laundering and terrorist financing threats and vulnerabilities. It is an inherent risk assessment: it rates threats and vulnerabilities before mitigation measures are applied, and then separately discusses the residual risk picture once existing policy, supervisory, and law enforcement mitigation is taken into account.

The report draws on consultations across government, law enforcement, the private sector, and international partners, and it primarily reflects information available up to December 31, 2024, unless a specific section states otherwise. It builds on prior national assessments published in 2015 and 2023. Its stated purpose is to support evidence-based policymaking and resource allocation for public authorities, and to help reporting entities and other organizations apply focused, proportionate risk mitigation measures of their own.

Why the National Risk Assessment Matters to FINTRAC Reporting Entities

FINTRAC has stated directly that it expects reporting entities to integrate the National Risk Assessment as a foundational input when identifying and understanding the inherent money laundering and terrorist financing risks relevant to their sector and operations. This connects to three specific compliance-program obligations: the business-based risk assessment itself, know-your-client measures (deciding where simplified, standard, or enhanced due diligence applies), and transaction monitoring and reporting (recognizing patterns consistent with the threats the report describes).

Citing the report in a policy document is not the same as using it. A defensible risk assessment shows the work: which national threats and vulnerabilities were reviewed, which ones the business actually has exposure to given its products, services, customers, geographies, delivery channels, technologies, and business relationships, and which ones were considered and found not to apply. That last category matters as much as the first; a documented reason why a national finding is not relevant to a specific business is just as much evidence of a working risk assessment as a documented reason why one is.

National risk information and a business-specific AML risk assessment are related but different things. The National Risk Assessment describes what is happening across the country as a whole. A business's own risk assessment describes what is actually happening, or could plausibly happen, in that specific business, and it is the second document, not the first, that FINTRAC tests during an examination.

The Most Important Money Laundering Threats Identified in Canada

The 2025 Report rates threats using actor sophistication, complexity, geographic scope, and estimated annual proceeds of crime. Four threats received the report's highest rating.

Illegal Drug Trafficking

The report identifies illegal drug trafficking, and fentanyl trafficking specifically, as the highest money laundering threat in Canada, driven by organized crime groups that blend illicit funds with legitimate business revenue, move bulk cash, and increasingly use trade-based structures and crypto assets alongside cash. For a reporting entity, the relevant exposure question is whether its client base or transaction patterns intersect with cash-intensive businesses, informal value transfer, or crypto on-ramps and off-ramps that could plausibly carry drug proceeds.

Fraud

Fraud is rated a high threat and, per the report, a growing one, with reported losses increasing year over year and the true scale believed to be far higher than what victims report. Mass marketing fraud, investment fraud (with a significant share tied to crypto asset schemes), romance fraud, mortgage fraud, identity fraud, and payment card fraud each carry distinct laundering patterns. The relevant exposure question for a reporting entity is whether it could be an unwitting conduit for fraud proceeds, through funnel accounts, rapid pass-through transfers to unrelated third parties, or the use of nominees and money mules.

Commercial Trade Fraud and Trade-Based Money Laundering

This threat involves misrepresenting the price, quantity, or nature of goods in international trade to move value across borders while disguising its criminal origin. It is most directly relevant to reporting entities that handle international trade finance, cross-border payments tied to goods transactions, or clients whose stated business involves import/export activity that does not obviously match their transaction patterns.

Tax Evasion and Other Tax Crimes

Proceeds from tax evasion and related tax crimes are assessed as a high threat, connected to Canada's underground economy. This is most relevant to reporting entities dealing in cash-intensive sectors or business clients whose declared income does not plausibly support their transaction volume.

Terrorist financing in Canada, by contrast, remains assessed as low in volume and value overall, driven mainly by ideologically motivated lone actors domestically, with foreign-based threat actors relying on diversified funding including crowdfunding, crypto assets, informal value transfer systems, and abuse of non-profit organizations. Low volume does not mean low consequence; the relevant exposure question for MSBs, crypto businesses, and crowdfunding platforms specifically is whether their services could be used as one of these funding channels, however infrequently.

Which Sectors and Products Does Canada Consider Most Vulnerable?

The report names domestic systemically important banks, private corporations, express trusts, crypto assets, and certain types of money services businesses as the sectors, corporate structures, and payment products most inherently vulnerable to exploitation. What they share is high accessibility, high transaction volume, rapid processing, and, in some cases, the potential for reduced transparency or complex structures that obscure the origin and destination of funds. The report is explicit that this vulnerability is inherent, meaning before mitigation; PCMLTFA-regulated sectors carry compliance obligations specifically because they are already recognized as facing these vulnerabilities, and existing controls measurably reduce the residual risk.

Crucially, the report does not treat every MSB as carrying identical risk, and neither should a reporting entity's own risk assessment. A retail multi-service MSB handling walk-in cash exchange carries a different risk profile than a remittance business operating international corridors, which differs again from a virtual currency dealer, an alternative remittance or informal value transfer operator, or a payment intermediary processing merchant flows. Treating "MSB" as a single risk category in an internal risk assessment misses exactly the distinction the national assessment itself draws.

For the beneficial ownership transparency measures connected to corporate and express-trust vulnerability, see ComplyFactor's beneficial ownership verification guide.

What the 2025 National Risk Assessment Means for Canadian MSBs

For MSBs specifically, the practical implications cluster around a handful of exposure points. Cash remains attractive to launderers precisely because of its anonymity, even though cash use in the broader Canadian economy continues to decline; an MSB handling significant cash volume, especially without a clear, documented explanation of source, carries elevated exposure regardless of transaction size. Remittance corridors to jurisdictions with weak AML/ATF frameworks, or jurisdictions FINTRAC has identified as intermediary points for sanctions evasion or laundering, warrant closer monitoring than corridors to well-regulated destinations. Foreign exchange activity that does not match a client's stated purpose or occupation is a documented pattern in several of the report's fraud and trade-fraud typologies. Virtual currency activity, including exchange between fiat and crypto assets, carries its own vulnerability rating independent of cash. And payment intermediary or agent-network models, where an MSB relies on third parties to conduct business on its behalf, introduce oversight and accountability questions the report's discussion of nominees and money mules speaks to directly.

None of this means every MSB must treat every client as high risk. It means an MSB's risk assessment should explicitly address which of these exposure points apply to its actual business model, and document why the others do not. A remittance business with no crypto offering does not need a crypto risk section that pretends otherwise; it needs a clearly reasoned statement that virtual currency exposure is not applicable to its current activities, revisited if that changes.

For the operational controls specific to currency exchange and remittance business models, see ComplyFactor's currency exchange and remittance MSB compliance guide.

What the Assessment Means for PSPs and Fintechs

Registration with the Bank of Canada under the Retail Payment Activities Act does not, by itself, make a payment service provider a FINTRAC reporting entity. Whether the National Risk Assessment's findings create a compliance obligation for a given PSP depends on whether its actual activities, electronic funds transfers, foreign exchange dealing, or similar regulated services, independently meet the PCMLTFA's definition of a reporting entity. Many PSPs do fall under both frameworks because of what they actually do, not because of how they are licensed.

For PSPs and fintechs that are FINTRAC reporting entities, the report's findings translate into a specific set of risk questions: does the payment flow model create funnel or pass-through activity where funds arrive and leave with little apparent economic purpose in between; are merchant relationships vetted with enough rigour to catch beneficial-ownership opacity behind a merchant account; does cross-border transfer activity route through jurisdictions the report or current FINTRAC intelligence flags as points of concern; and does the technology stack (API-driven onboarding, instant settlement, embedded finance partnerships) create speed that outpaces the business's actual ability to catch anomalous activity before funds move.

For the full comparison between PCMLTFA/FINTRAC obligations and RPAA registration, see ComplyFactor's MSB vs PSP licences in Canada guide, and ComplyFactor's PSP registration service for the registration process itself.

How to Use the National Risk Assessment in Your AML Risk Assessment

This is the operational core of the exercise. A national report becomes useful only once it is run through a structured process that connects national findings to a specific business's actual exposure.

Identify the national threats relevant to your business: work through the report's high and medium threat ratings and note which ones plausibly connect to your products, clients, or transaction types

Map the vulnerable sectors and products to your actual activities: confirm whether you operate in, or transact with, any of the sectors or products the report names as inherently vulnerable

Review customer and business-relationship risk: identify which client segments carry the exposure characteristics the report describes (cash-intensive, PEP-adjacent, operating in or connected to weak AML/ATF jurisdictions)

Review geographic and corridor risk: compare your actual transaction corridors against the jurisdictions of concern and active ministerial directives current as of your review date

Reassess products, services and delivery channels: confirm whether new products launched since your last review (a crypto offering, an agent network, an API integration) introduce exposure the report speaks to

Review emerging technologies and payment methods: consider whether AI-enabled fraud, DeFi interaction, or instant-payment rails create exposure your current controls were not designed around

Compare current controls with the identified risks: for each relevant exposure, confirm whether an existing control actually addresses it, or whether a gap exists

Document residual risk and mitigation: record what risk remains after your current controls are applied, and whether that residual level is acceptable or requires further action

Update monitoring and escalation where needed: adjust transaction-monitoring scenarios and escalation thresholds to reflect the exposures you have confirmed are relevant

Record why a national risk is or is not relevant to your business: for every threat and vulnerability you reviewed, keep a documented conclusion, not just a list of the ones you acted on

Six Areas of Your AML Program to Revisit After the National Risk Assessment

Business-Based Risk Assessment

Confirm the risk assessment reflects the report's current threat and vulnerability picture, not a prior edition or a generic template, and that it is dated and version-controlled so a reviewer can see when it was last updated against current national risk information.

Customer Risk Rating

Check whether your customer risk-rating criteria capture the exposure factors the report actually describes, cash intensity, jurisdiction of connection, PEP proximity, business type, rather than a generic scoring model inherited from a template that predates the report.

Geographic and Transaction-Corridor Risk

Confirm your list of higher-risk jurisdictions reflects both FATF's current lists and Canada's own jurisdictions of concern, and that active ministerial directives (currently covering the DPRK, Iran, and Russia, each periodically updated) are built into onboarding and monitoring, not just referenced in policy text.

Transaction Monitoring and Alert Scenarios

Review whether your monitoring scenarios would actually catch the patterns the report and current FINTRAC intelligence describe, funnel activity, structuring, rapid pass-through to unrelated third parties, rather than only generic velocity or threshold rules.

Enhanced Measures for Higher-Risk Relationships

Confirm enhanced due diligence and enhanced ongoing monitoring are visibly different in practice for relationships your updated risk assessment now rates higher, not just documented as a policy that is not actually applied differently in files.

Training and Escalation Procedures

Update front-line and compliance training to reflect any material change in what your risk assessment now flags, and confirm escalation paths route the relevant scenarios to someone with the authority to act on them.

Do Your Transaction Monitoring Rules Reflect Canada's Current Risk Picture?

National risk information should inform monitoring logic; it should not mechanically dictate it, since a rule built directly from a national threat description without reference to your own transaction data will generate noise rather than useful alerts. That said, several patterns the report and FINTRAC's published intelligence describe are worth testing your existing scenarios against: unusual transaction velocity inconsistent with a client's stated profile, funnel or pass-through activity where funds move in and out with little apparent purpose, interaction between cash and crypto asset activity, third-party involvement inconsistent with a client's normal pattern of instruction, and activity connected to jurisdictions currently flagged by an active ministerial directive or FINTRAC intelligence as points of concern.

Where you make a specific claim in a monitoring scenario, such as designating a jurisdiction as higher risk or flagging a particular typology, that claim should trace back to an official FINTRAC or government source, not an assumption about what seems risky. FINTRAC's published strategic intelligence and operational alerts are the appropriate source for typology-level detail beyond what the National Risk Assessment itself states.

How the National Risk Assessment Should Affect High-Risk Client Controls

National risk intelligence should inform, but never mechanically replace, individual customer risk assessment. A client operating in a sector the report names as vulnerable, or transacting through a jurisdiction of concern, is not automatically a high-risk client; that connection is one input the risk assessment weighs alongside the client's actual behaviour, the plausibility of their stated activity, and any other risk indicators specific to the relationship. Where the national findings do change something concrete, it is usually the trigger for enhanced due diligence or enhanced ongoing monitoring on relationships that already carry some elevated characteristic, not a blanket reclassification of an entire client segment.

This connects directly to controls that already have their own dedicated FINTRAC obligations and their own ComplyFactor guidance rather than being reinvented here.

For the full PEP and HIO determination framework, ComplyFactor's guide to politically exposed persons in Canada (once published) covers domestic, foreign, and HIO categories in detail.

For beneficial ownership procedures relevant to the corporate and express-trust vulnerabilities the report names, see ComplyFactor's beneficial ownership verification guide.

The 2025 Assessment Is Not Enough on Its Own in 2026

FINTRAC itself is explicit on this point: the National Risk Assessment provides a snapshot based on historical data (largely information available up to December 31, 2024), and businesses are expected to supplement it with other available risk information, including FINTRAC's ongoing strategic intelligence and published guidance, to keep pace with a threat landscape that keeps moving after the report's data cut-off.

Several developments confirmed through official sources since the report's publication are directly relevant to how it should be read and applied in 2026. FINTRAC issued an operational alert on money laundering indicators connected to illegal fentanyl trafficking in 2025, adding typology-level detail beyond what the National Risk Assessment itself sets out. The ministerial directives covering Russia and the DPRK were updated in March 2025 with additional required measures, meaning a risk assessment that still references the pre-March-2025 directive requirements is out of date on that point specifically. And Canada listed several transnational organized crime groups as terrorist entities in February 2025, a development that sits directly at the intersection of the report's discussion of a growing nexus between organized crime and terrorism financing.

The practical discipline this calls for is a living risk-information process, not a document that gets revisited only when a new National Risk Assessment eventually publishes. A compliance officer should have a routine, whatever cadence fits the business, for checking FINTRAC's published strategic intelligence, operational alerts, and guidance updates, and for recording when something in that stream changes what the risk assessment should say. This is not the place to reproduce a general AML trends roundup; the point here is narrower and more durable: treat the National Risk Assessment as the baseline, and treat ongoing FINTRAC intelligence as the mechanism that keeps that baseline current between editions.

How to Document That You Used the National Risk Assessment

FINTRAC guidance does not prescribe a specific template for this documentation, and no such requirement should be implied where one does not exist. What follows is a description of what defensible, examination-ready evidence tends to look like in practice, distinguished from what current guidance actually requires.

A legally required baseline exists: the PCMLTFA and its Regulations require a documented risk assessment as part of the compliance program, reviewed and updated as the business changes. Beyond that baseline, good practice, not a separate legal mandate, typically includes recording which version and date of the National Risk Assessment (and any supplementary FINTRAC intelligence) was reviewed, which threats and vulnerabilities were assessed as relevant with the reasoning behind that conclusion, which were assessed as not relevant and why, what specific control or monitoring changes resulted, what training was updated as a consequence, who in senior management reviewed and approved the update, the date of that review, and a note confirming that newer intelligence beyond the report itself was also considered as part of the same update cycle.

For the broader evidence standards a FINTRAC examination tests across a compliance program, see ComplyFactor's FINTRAC examination readiness checklist.

National Risk Assessment Update Checklist for Canadian Reporting Entities

Have we reviewed the current 2025 National Risk Assessment in full, not just the executive summary?

Have we identified which national threats (drug trafficking, fraud, trade fraud, tax crimes, and the medium-rated threats) actually connect to our business?

Have we documented which national threats and vulnerabilities are not relevant to us, and why?

Have we reassessed our products and services against the vulnerabilities the report names?

Have we reviewed our geographic exposure against current jurisdictions of concern and active ministerial directives?

Have we reviewed and, where needed, updated our customer risk-rating criteria?

Have we reassessed our transaction-monitoring scenarios against the typologies the report and current FINTRAC intelligence describe?

Have we reviewed our high-risk-client controls to confirm enhanced measures are visibly different in practice, not just in policy?

Have we reviewed our PEP and beneficial ownership exposure in light of the report's corporate and PEP-adjacent vulnerability findings?

Have we considered current FINTRAC strategic intelligence and operational alerts published after the report, not just the report itself?

Have resulting policy and procedure changes been documented with a clear version history?

Have staff been trained on any material changes to risk criteria or monitoring rules?

Can management explain, in plain terms, what changed and why?

Can we produce documented evidence of this entire update process during a FINTRAC examination?

Has the updated risk framework been tested, whether through internal quality assurance or an independent effectiveness review, to confirm it actually works in practice?

How ComplyFactor Can Help Update Your AML Risk Framework

Where a business risk assessment has not been meaningfully updated since the 2025 National Risk Assessment published, or was never built to connect national findings to actual business exposure in the first place, ComplyFactor's AML compliance program and risk assessment service rebuilds it from the business outward, and AML advisory support can work through a targeted update where the rest of the program is sound but the risk assessment specifically needs revisiting. Where a business wants independent confirmation that its updated risk assessment actually holds up, independent AML effectiveness review testing samples the risk assessment, customer files, and monitoring rules against current FINTRAC expectations, satisfying the biennial effectiveness-review requirement in the process. And where a business lacks internal ownership to keep the risk assessment current between reviews, fractional compliance officer support provides that ongoing function, including the routine monitoring of FINTRAC intelligence this article describes.

Frequently Asked Questions

What is Canada's National Risk Assessment?

A periodic federal report, produced by the Department of Finance Canada, that identifies and rates the country's most significant money laundering and terrorist financing threats and vulnerabilities at a national level, before individual mitigation measures are applied.

What is the latest National Risk Assessment in Canada?

The 2025 Assessment of Money Laundering and Terrorist Financing Risks in Canada, published in August 2025. It is the operative national assessment as of August 2026.

Is there a 2026 Canadian National Risk Assessment?

No. As of August 2026, no separate 2026 National Risk Assessment has been published. The 2025 edition remains current, supplemented by ongoing FINTRAC strategic intelligence and guidance.

Does FINTRAC require businesses to use the National Risk Assessment?

FINTRAC expects reporting entities to integrate it as a foundational input into their risk-based approach and compliance program. It supplies risk information rather than creating new statutory obligations in itself; the underlying legal requirement is the risk assessment obligation under the PCMLTFA and its Regulations.

How should an MSB use the National Risk Assessment?

By identifying which national threats and vulnerabilities connect to its specific business model (cash exposure, remittance corridors, virtual currency activity, agent networks) and documenting both the relevant exposures and the ones assessed as not applicable, rather than copying national ratings directly into its own risk assessment.

Which sectors are considered highly vulnerable to money laundering in Canada?

The 2025 Report names domestic systemically important banks, private corporations, express trusts, crypto assets, and certain types of money services businesses as the most inherently vulnerable sectors, corporate structures, and products, based on accessibility, transaction volume, and potential for reduced transparency.

Does the National Risk Assessment automatically determine customer risk ratings?

No. It is one input into a broader, business-specific risk assessment. A client connected to a nationally vulnerable sector or jurisdiction is not automatically high risk; that connection is weighed alongside the client's actual behaviour and other relationship-specific factors.

Should an AML risk assessment be updated after the 2025 National Risk Assessment?

Yes, where a business has not already reviewed its risk assessment against the current report. The update should document which findings are relevant, which are not, and what control or monitoring changes resulted.

How often should a Canadian AML risk assessment be updated?

The PCMLTFA requires the risk assessment to be reviewed and updated as the business changes, and it should also be revisited when material new risk information, such as a new National Risk Assessment edition or significant FINTRAC intelligence, becomes available.

What evidence should a business keep to show its risk assessment is current?

At minimum, the dated, documented risk assessment itself as required by the PCMLTFA. Good practice beyond that legal minimum includes recording the source and date of risk information reviewed, the relevance determinations made, resulting control changes, training updates, and management approval.

Turning Canada's National Risk Assessment Into Practical AML Controls

The 2025 National Risk Assessment is an input, not a substitute, for a business-specific AML risk assessment. Its value comes from translating the findings that actually connect to your products, clients, and geography into real changes: updated risk ratings, sharper monitoring scenarios, enhanced measures that are visibly different in practice, and training that reflects what changed. Newer FINTRAC intelligence published since the report's data cut-off needs to sit alongside it, not be ignored in favour of a static document. And every step of that update deserves a documented trail, since a risk assessment that cannot show its own reasoning is difficult to defend during an examination regardless of how sound the underlying thinking was.

A risk framework that has not been tested against the current national risk picture is a framework FINTRAC is likely to test for you. ComplyFactor's Canadian AML advisory team can help translate the 2025 findings into a defensible, business-specific update before that happens.

Frequently Asked Questions

No items found.
ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.