Key takeaways
- FINTRAC imposed a $224,235 administrative monetary penalty on Commerciale I.C. - Pacific Inc. for five violations.
- The findings covered late EFT reporting, incomplete policies, an incomplete risk assessment, an insufficient effectiveness review, and Iran Ministerial Directive non-compliance.
- FINTRAC identified 110 Iran-related reporting failures between March 1 and August 31, 2022.
- The case predates the March 26, 2026 FINTRAC AMP framework change and remains listed by FINTRAC as appealed to the Federal Court.
On February 5, 2026, FINTRAC published a public notice confirming an administrative monetary penalty of $224,235 against Commerciale I.C. - Pacific Inc., also operating as I.C. - Pacific Trading Inc., a money services business in MontrΓ©al, Quebec. The penalty was imposed on September 2, 2025, following a compliance examination that identified five violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its Regulations. FINTRAC's notice states that Commerciale I.C. - Pacific Inc. has appealed the decision to the Federal Court.
The case is worth reading closely, not for the size of the penalty, but for what FINTRAC's examination actually found. The five violations span late transaction reporting, incomplete policies, an underdeveloped risk assessment, an undocumented effectiveness review, and a very serious failure tied to a Ministerial Directive. Together, the findings show how weaknesses across several compliance-program components can surface in a single FINTRAC examination β a pattern relevant to any Canadian MSB, not only one with Iran-linked transactions.
Commerciale I.C.-Pacific FINTRAC Penalty at a Glance
What Did FINTRAC Find?
Each of these maps to a specific compliance function. Below, each becomes a practical lesson.
Lesson 1 β EFT Reporting Deadlines Need Operational Controls
FINTRAC reviewed 22 incoming and outgoing electronic funds transfer reports submitted during the scoping period. In 8 of those instances, Commerciale I.C. - Pacific Inc. failed to submit the report within five working days of the transfer, as required under subsection 132(1) of the Regulations. FINTRAC classified this as a Minor violation, noting that late submissions delay FINTRAC's ability to analyze and disclose intelligence when it is needed β a concern that is more acute in terrorism-financing contexts.
FINTRAC's current EFT reporting guidance uses slightly different wording than the 2022 conduct described in this case: an EFT report must be submitted within 5 business days after the day you initiate or finally receive the transfer. The substance is the same; the historical finding used "working days" because that was the applicable regulatory language at the time.
FINTRAC identified 8 late filings among the 22 EFT reports it reviewed, making reporting timeliness an important control area for other MSBs to test. For an MSB reviewing its own controls, useful questions include:
- Who is accountable for submitting each EFT report, and by when?
- Is there a system β not a manual tracker β that flags a transfer approaching its reporting deadline?
- Are incoming and outgoing transfer workflows both covered, or only one direction?
- Can compliance management identify an overdue filing before FINTRAC does?
Lesson 2 β Your Compliance Manual Must Match Your Actual Obligations
FINTRAC found that Commerciale I.C. - Pacific Inc.'s written policies and procedures were not fully developed, with incomplete or missing coverage of business relationships, ongoing monitoring, politically exposed persons and heads of international organizations, transaction reporting, the 24-hour rule, the travel rule, and Ministerial Directives and related transaction restrictions. FINTRAC classified this as a Serious violation.
The lesson here is specific, not generic: FINTRAC did not fault the company for lacking a policy manual, but for a manual that did not reflect the full scope of obligations actually applying to the business. A manual that was accurate several years ago, or adapted from a template without being mapped to current products, clients, and reporting obligations, can create exactly this kind of gap. The practical fix is a direct crosswalk: list every applicable obligation under the Act and Regulations, and confirm each one has a corresponding, current policy section.
Lesson 3 β A Generic Risk Assessment Is Not Enough
FINTRAC's review found the company's risk assessment incomplete under subsection 9.6(1) of the Act, failing to adequately address prescribed factors including products and delivery channels, geographic locations, clients and business-based relationships, and other risks specific to the company's own operations. This was also classified as a Serious violation.
A risk assessment built around abstract categories β "high-risk countries," "cash-intensive clients" β without mapping them to the entity's actual product mix, delivery channels, and customer base does not meet this standard. FINTRAC's finding suggests the assessment did not answer basic operational questions: which specific products carry elevated risk here, which geographies the business's clients and transactions actually touch, and which relationships warrant closer scrutiny. A risk assessment that could describe almost any MSB is not describing this one.
Lesson 4 β Effectiveness Reviews Need Evidence, Not Just Existence
Under subsection 9.6(1) of the Act and paragraph 156(1)(f) of the Regulations, a reporting entity must institute and document a review of its policies and procedures, risk assessment, and training program to test their effectiveness, carried out every two years under subsection 156(3) of the Regulations. The review must be carried out by an internal or external auditor, or by the person or entity itself if it does not have such an auditor.
FINTRAC determined that Commerciale I.C. - Pacific Inc. had not conducted a comprehensive review beyond what was documented. Specifically, the documentation was insufficient to establish the period the review covered, the results of any testing performed, or the conclusions, deficiencies, and action plan (if any). This was classified as a Serious violation.
This is a documentation failure as much as a substantive one. FINTRAC's framework does not require every MSB to engage an external firm β the review can be conducted internally where no auditor exists. What it does require is evidence: a defined scope and period, a record of what was tested, and documented findings with a corrective action plan where gaps are identified. An internal assertion that "the program was reviewed," without that evidence, will not satisfy this requirement.
Lesson 5 β Ministerial Directives Cannot Sit Outside the AML Program
This is the most serious finding in the case. FINTRAC determined that Commerciale I.C. - Pacific Inc. conducted multiple transactions originating from or bound for Iran that were not reported as required under the July 25, 2020 Ministerial Directive on the Islamic Republic of Iran. Specifically, FINTRAC identified 110 instances between March 1, 2022 and August 31, 2022 where the EFT reporting obligation under the Directive was not met. FINTRAC also found that the company's policies and procedures did not cover the Directive's requirements at all, and concluded that the company had been non-compliant with it since its 2020 implementation. This was classified as a Very serious violation β the most severe violation classification under the framework applicable to this case.
It is important to be precise about what this finding establishes. FINTRAC's notice describes a failure to comply with reporting and risk-mitigation obligations under a Ministerial Directive β it is not a finding of sanctions evasion, money laundering, or any criminal offence, and FINTRAC's notice does not characterize it as such.
What FINTRAC found in this case is tied to the version of the Iran Directive that applied in 2022. The Directive itself has since been amended twice β on February 15, 2024 and again on November 15, 2025 β and FINTRAC's current guidance on the Directive was last updated June 23, 2026. Under current FINTRAC guidance, covered reporting entities must treat every transaction originating from or bound for Iran as high risk regardless of amount, verify clients requesting or benefiting from the transaction, apply the prescribed customer due diligence measures, keep required records, and report the transaction to FINTRAC. Current guidance also sets out additional, threshold-specific identity-verification measures beyond the standard triggers under the Regulations β these obligations have been extended and refined since 2020 and should not be assumed identical to what applied during the 2022 examination period.
For any MSB, the operational lesson holds regardless of which directive is in play: a Ministerial Directive is not a one-time notice to be filed away. It must be built into policies and procedures, transaction monitoring, customer risk classification, staff training, and reporting workflows, and revisited whenever the Directive is amended.
What Should Canadian MSBs Review After This Case?
- Who owns EFT reporting deadlines, and is there a system to catch late filings before they become a pattern?
- Do written policies and procedures cover the 24-hour rule, the travel rule, PEP/HIO requirements, and all currently applicable Ministerial Directives?
- Does the risk assessment reflect this business's actual products, delivery channels, client base, and geographic exposure β not a generic template?
- Can the last effectiveness review produce a defined scope, test results, and documented conclusions with an action plan?
- Is there a defined process for identifying when a new or amended Ministerial Directive applies, and for updating controls accordingly?
Some of these are strict legal requirements; others (such as the specific method of tracking deadlines) are practical implementation choices left to the reporting entity.
Was the $224,235 Penalty Issued Under the New 2026 FINTRAC Penalty Framework?
No. The conduct in this case predates March 26, 2026, when the Strengthening Canada's Immigration System and Borders Act (Bill C-12) received Royal Assent and introduced a new AMP framework with significantly higher maximum penalty amounts. FINTRAC's transition guidance confirms that violations occurring entirely before that date continue to be assessed under the previous AMP policy and penalty amounts. Commerciale I.C. - Pacific Inc.'s $224,235 penalty was calculated under the earlier framework and should not be compared against today's higher penalty ceilings. ComplyFactor's FINTRAC penalties guide explains the broader pre- and post-March 2026 AMP framework.
What Does This Case Mean for Canadian MSB Compliance?
FINTRAC examinations test whether a compliance program actually functions β not whether the required documents exist in some form. This case shows findings across five distinct control points: transaction reporting timeliness, policy completeness, risk assessment depth, effectiveness-review documentation, and directive-specific controls. The $224,235 penalty covered five separate violations rather than a single compliance deficiency.
For MSBs building or maintaining a program that can withstand this level of scrutiny, independent AML audit and effectiveness review support can identify gaps of exactly this kind before an examination does, and AML compliance program development can close them with documentation that holds up to FINTRAC's standard of evidence, not just existence.
FAQ
Are all transactions involving Iran prohibited for Canadian MSBs?
No. The Ministerial Directive on the Islamic Republic of Iran imposes high-risk treatment, customer due diligence, identity-verification, record-keeping, and reporting obligations on transactions originating from or bound for Iran β it does not itself prohibit such transactions. Separate Canadian sanctions rules may impose actual prohibitions in specific circumstances; MSBs should consult current FINTRAC and sanctions guidance directly rather than relying on this article for that determination.
Does the current Iran Ministerial Directive require reporting below normal EFT thresholds?
Yes. Under FINTRAC's guidance updated June 23, 2026, the Directive extends and enhances normal transaction reporting obligations for transactions originating from or bound for Iran, including transactions that would otherwise fall below standard reporting thresholds. The applicable report type β for example, an Electronic Funds Transfer Report or a Suspicious Transaction Report β depends on the transaction and the entity's normal reporting obligations, flagged using the Ministerial Directive field.
What is the 24-hour rule for EFT reporting?
Under current FINTRAC guidance, an EFT report is required when a reporting entity initiates two or more international EFTs totalling $10,000 or more within a static 24-hour window and knows they were requested by the same person or entity, requested on behalf of the same person or entity, or are for the same beneficiary. For EFTs finally received, the rule applies when two or more international EFTs total $10,000 or more within the window and the entity knows they were requested by the same person or entity or are for the same beneficiary.
What must an entity report to senior management after an effectiveness review?
Under current FINTRAC compliance-program guidance, an entity must report in writing to a senior officer no later than 30 days after completing the two-year effectiveness review. That report must cover the review's findings (including deficiencies, recommendations, and action plans), any updates made to policies and procedures during the period covered by the review that were not made as a result of the review itself, and the status of implementing those updates.
Did FINTRAC revoke Commerciale I.C.-Pacific's MSB registration?
FINTRAC's administrative monetary penalty notice does not state that the company's MSB registration was revoked. An AMP and a registration status are separate matters under FINTRAC's framework; anyone needing the company's current registration status should check FINTRAC's MSB registry directly rather than inferring it from the penalty notice.
Does a FINTRAC administrative monetary penalty mean criminal wrongdoing?
No. An administrative monetary penalty is an administrative enforcement measure, separate from criminal proceedings. FINTRAC's notice in this case describes regulatory non-compliance, not a criminal finding.
---
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need β free, no obligation, 30 minutes.
