AML compliance

5 AML Compliance Requirements Canadian Credit Unions Should Review in 2026

Five practical FINTRAC review areas Canadian credit unions should check in 2026, including risk assessment, KYC, reporting, governance and effectiveness reviews.

On this page
Get Expert Help

Key takeaways

  • Canadian credit unions and caisses populaires are financial entities under the PCMLTFA and must meet the FINTRAC requirements that apply to their activities.
  • Since March 26, 2026, compliance programs must be reasonably designed, risk-based and effective.
  • Risk assessments should reflect the credit union's real products, members, channels and relevant new developments or technologies before rollout.
  • Effectiveness reviews are required at least every two years, with prescribed results reported in writing to a senior officer within 30 days after completion.

Canadian credit unions and caisses populaires are financial entities under the PCMLTFA, alongside banks, authorized foreign banks and other covered financial institutions. They are subject to FINTRAC compliance-program requirements and the reporting, record-keeping and know-your-client obligations that apply to their activities.

On March 26, 2026, the Strengthening Canada's Immigration System and Borders Act received Royal Assent and amended the PCMLTFA. Section 9.6 now requires reporting entities to ensure their compliance programs are reasonably designed, risk-based and effective. That standard is now the one FINTRAC applies, not an upcoming change to plan for.

This article sets out five practical areas a Canadian credit union should review against that current standard, followed by a proportionality section for smaller institutions and a scannable checklist.

Why Credit Union AML Compliance Deserves a Fresh Review in 2026

FINTRAC supervises credit unions as financial entities, alongside banks, trust companies, and other deposit-taking institutions. That supervision hasn't changed. What changed on March 26, 2026 is the legal bar the program is measured against, and the tools FINTRAC has to act when it isn't met.

The amendments strengthened the administrative monetary penalty framework: they introduced "ability to pay" as an explicit criterion in setting penalty amounts, made compliance agreements mandatory wherever a penalty is imposed, added compliance orders as a new enforcement instrument, and elevated certain compliance-program violations to a more serious category. This isn't evidence that FINTRAC is specifically targeting credit unions β€” the changes apply across all reporting-entity sectors β€” and it reinforces that documentation alone is not enough to demonstrate that a compliance program is effective in practice.

The practical implication for a credit union: a program that reads well but doesn't reflect what staff actually do at the branch or in day-to-day member service is now a more exposed position than it was before March 2026.

1. Make the Risk Assessment Reflect the Credit Union You Actually Operate

FINTRAC's risk-based approach starts with a documented risk assessment, and a generic financial-institution template may not reflect a credit union's actual risk profile. The assessment should reflect factors specific to the institution, including:

  • Member and customer types, including retail members, business members, and any non-member services offered where permitted
  • Products and services β€” deposit accounts, lending, wire transfers, and any newer digital or payment offerings
  • Cash exposure across branches, including branches in higher cash-volume communities
  • Geographic footprint, delivery channels (in-branch, telephone, online/mobile), and any correspondent relationships used for cross-border clearing, where applicable
  • Higher-risk jurisdictions relevant to member activity

The risk assessment must also address the risks of any new development or new technology a credit union intends to introduce β€” a new product, service, delivery channel, or system β€” before rolling it out, not after. A credit union piloting a new digital account-opening flow or a new payment rail should assess the risk impact as part of that rollout, not treat it as a future documentation update.

Where a risk assessment identifies higher-risk members, products, or relationships, FINTRAC expects corresponding enhanced measures β€” not simply a higher risk rating with no operational difference. A credit union whose risk assessment hasn't been revisited since it was first drafted, or that was adapted from a generic financial-institution template without being recalibrated to its actual member base and delivery channels, should treat this as the starting point for a 2026 review. This is a foundational document, not a service in itself β€” where it needs rebuilding, that's a separate underlying AML compliance program exercise.

2. Test KYC and Ongoing Monitoring Against Real Member Activity

Depending on the account, client, transaction and applicable trigger, a financial entity's obligations can include client identity verification, beneficial ownership requirements, PEP/HIO determinations, third-party determinations, and ongoing monitoring. The review point for 2026 isn't whether these procedures exist on paper β€” it's whether the credit union can demonstrate staff actually followed them for real member files.

That distinction matters more than it used to. A written procedure describing how identity is verified at account opening is not the same thing as being able to pull a sample of recent onboarding files and show the verification steps were actually completed, documented, and β€” where the member was rated higher risk β€” followed by enhanced measures. Ongoing monitoring should be similarly testable: frequency calibrated to a member's risk rating, with a record of what was reviewed and when.

A small credit union may have fewer staff and simpler systems than a large regional institution, but its FINTRAC obligations do not disappear. Its controls should still match its actual size, products, member base, and risk profile β€” proportionate, not absent.

3. Review Transaction Reporting and Suspicious Activity Escalation

Where applicable to a credit union's activities, reporting obligations can include suspicious transaction reports (STRs), large cash transaction reports, and electronic funds transfer reports. The operational question worth reviewing isn't just whether these reports get filed β€” it's the quality of the escalation trail behind them.

An alert being generated by a monitoring process is not, on its own, evidence of an effective program. Effectiveness reviews and FINTRAC's own examination methods can include assessing why a particular transaction was not reported, to determine whether that decision was reasonable given the information available at the time β€” not only checking that filed reports were accurate. A clear review, escalation, and decision trail β€” including a documented reason for a decision not to escalate β€” is what demonstrates how the process actually operated, rather than just that alerts were raised.

Specific dollar thresholds and filing deadlines should always be confirmed against current FINTRAC guidance rather than assumed from a checklist. Software isn't a legal requirement in itself β€” a credit union's monitoring approach should be proportionate to its transaction volume and complexity, not tied to a specific technology because a vendor says so.

4. Make Governance, Training and the Compliance Officer Work in Practice

A named compliance officer is a starting point, not an endpoint. The officer needs the necessary authority and access to resources to implement the program, and should have independent oversight with the ability to communicate directly with the people who make decisions about the business. For larger institutions, FINTRAC guidance points to senior-level access to senior management and the board as an appropriate governance model; the specific reporting structure a smaller credit union uses can look different, provided the officer's authority and resourcing are genuinely adequate for the role.

Training is the same story: role-specific content for frontline staff, onboarding teams, and senior management, delivered on a documented schedule with completion records retained. A credit union with strong branch-level member relationships has a particular advantage here β€” frontline staff can be well placed to notice unusual behaviour in person β€” but that advantage only translates into compliance value if staff are trained to recognize red flags and know the escalation path, and if that training is documented.

Management should be able to demonstrate β€” not just assert β€” that material compliance issues, remediation needs, and resource requirements reach the appropriate decision-makers. Under the current standard, evidence that governance functions in practice carries real weight in an examination.

5. Use the Two-Year Effectiveness Review as a Real Test, Not a Formality

FINTRAC requires reporting entities to carry out and document an effectiveness review at least every two years. Under the Regulations, the review may be carried out by an internal or external auditor, or by the reporting entity itself where it does not have an auditor; FINTRAC identifies impartiality β€” the reviewer not being directly involved in the compliance program's day-to-day operation β€” as a best practice, not a mandatory outsourcing requirement.

A meaningful review can sample across several areas: whether written policies match what actually happens day to day, a sample of KYC files and risk ratings, evidence of ongoing monitoring, a review of transactions to assess whether reportable ones were reported (and whether decisions not to report were reasonable), training completion records, higher-risk member files, governance and escalation records, and β€” where a prior review identified findings β€” evidence those findings were actually remediated.

There's also a reporting step that's easy to miss: for entities, the findings of the review, any policy or procedure updates made during the period covered that weren't a result of the review itself, and the status of implementing those updates must be reported in writing to a senior officer no later than 30 days after the review is completed. A review that identifies real findings but is never formally reported to a senior officer within that window is itself a gap.

A credit union whose two-year clock is approaching, or whose last independent AML effectiveness review treated the exercise as a documentation check rather than a test of whether things work, should treat 2026 as the point to change that.

What Changes for Small Credit Unions?

The PCMLTFA framework applies regardless of size, although particular obligations can depend on the credit union's activities and applicable triggers. What can reasonably scale is the design and implementation of controls: reflecting the credit union's size, complexity, products, transaction volume, member base, and risk profile.

A few things to keep in mind regardless of size:

  • The compliance officer still needs adequate authority and resources, even where that person wears more than one hat.
  • Documentation should accurately describe what the credit union actually does β€” a program copied from a larger institution's template, sized down only in appearance, can fail to reflect the credit union's actual business and risk profile.
  • The two-year effectiveness review requirement applies the same way regardless of size.

There's no basis for assuming smaller credit unions are less likely to face a FINTRAC examination. Size affects how a program should be built and resourced, but it does not remove the underlying legal obligations that apply.

What Drives AML Compliance Cost for a Credit Union?

There's no FINTRAC-prescribed cost for AML compliance, and the range across credit unions is wide enough that a single benchmark figure wouldn't be meaningful. Cost is driven by factors specific to each institution: size and branch count, product mix (particularly higher-risk products like wire transfers or foreign exchange), transaction volume, monitoring technology where used, staffing and training delivery, the frequency and depth of effectiveness reviews, remediation work following prior findings, and the pace of regulatory change itself β€” the March 2026 amendments being a current example.

A credit union sizing its compliance budget should start from these drivers relative to its own risk profile rather than a generic industry figure.

Credit Union AML Compliance Checklist for 2026

  • Has the risk assessment been updated to reflect current products, delivery channels, and member segments β€” including any new development or technology introduced?
  • Are sanctions-evasion risks reflected in the risk assessment where relevant?
  • Can the credit union produce evidence of ongoing monitoring, not just a monitoring policy?
  • Are transaction-reporting procedures current, and is the escalation trail behind them documented?
  • Are decisions not to escalate an alert documented with their reasoning, the same as decisions to escalate?
  • Does the compliance officer have adequate authority, resourcing, and access to decision-makers?
  • Are training records complete, role-specific, and up to date?
  • Is the two-year effectiveness review current, and did it test implementation as well as documentation?
  • Was the review reported in writing to a senior officer within the required timeframe?
  • Have findings from the prior review or any FINTRAC examination been remediated and documented?

FAQs

1. Are Canadian credit unions subject to FINTRAC requirements?

Yes. Credit unions and caisses populaires are financial entities under the PCMLTFA and are subject to FINTRAC's compliance-program, reporting, record-keeping and know-your-client requirements that apply to their activities.

2. What AML requirements apply to small credit unions?

The same legal framework applies regardless of size. What can scale is implementation β€” a small credit union may combine responsibilities across fewer people and run simpler processes β€” provided the compliance officer has adequate authority, documentation accurately reflects actual practice, and the program remains proportionate to the institution's real risk profile.

3. Does a credit union have to use AML transaction-monitoring software?

No. FINTRAC's requirements focus on having effective, risk-based controls and meeting applicable reporting obligations, not on using a specific software product. A credit union's monitoring approach should be proportionate to its transaction volume and complexity.

4. Does a FINTRAC effectiveness review have to be performed by an external auditor?

No. Under the Regulations, the review may be carried out by an internal auditor, an external auditor, or the reporting entity itself if it doesn't have an auditor. FINTRAC identifies impartiality β€” the reviewer not being directly involved in operating the program day to day β€” as a best practice, which is distinct from a legal requirement to outsource the review.

5. What must happen after a two-year effectiveness review is completed?

For entities, the findings of the review, any policy or procedure updates made during the period covered that weren't a result of the review, and the status of implementing those updates must be reported in writing to a senior officer no later than 30 days after the review is completed.

6. Does a credit union need to reassess AML risk before launching a new product or technology?

Yes. The risk assessment must address the risks of a new development or new technology before it's introduced, where it may affect clients, business relationships, products, services, delivery channels, or geographic exposure.

7. Can a credit union outsource parts of its AML compliance function?

Yes, in whole or in part β€” outside support can be used for functions such as effectiveness reviews or compliance officer support. Outsourcing a function doesn't transfer legal responsibility away from the reporting entity or its appointed compliance officer, who remains accountable under the PCMLTFA regardless of who performs the work.

8. What drives the cost of AML compliance for a credit union?

Cost is driven by factors specific to the institution β€” size, branch count, product mix, transaction volume, monitoring technology, staffing, training, and the frequency of effectiveness reviews β€” rather than a single industry-wide figure, since no universal FINTRAC-prescribed cost exists.

ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.