How Much Does an Independent FINTRAC AML Audit Cost? Scope & Pricing Factors
How much does a FINTRAC AML audit cost? See the scope, testing, transaction volume, and risk factors that drive effectiveness-review pricing in Canada.

Key takeaways
- FINTRAC does not prescribe a fixed market fee for an external AML effectiveness review; external-provider pricing is a separate, scope-based commercial question.
- FINTRAC says review breadth and depth may vary based on business complexity, transaction volume, previous findings, and current money laundering, terrorist activity financing, and sanctions evasion risks.
- An external third-party reviewer is not universally required: current FINTRAC guidance permits an internal auditor, an external auditor, or the entity itself if it has no auditor, with impartiality recommended as a best practice.
- Reliable quotes should clearly define the review scope, testing approach, sample areas, deliverables, timeline assumptions, and whether remediation support is included or separately scoped.
FINTRAC does not set a fixed market price for an independent AML effectiveness review. What it does set is the regulatory requirement β every reporting entity must have its compliance program's policies and procedures, risk assessment, and training program reviewed for effectiveness at least once every two years. What an external provider charges to carry out that review is a separate, scope-based commercial question, and FINTRAC itself identifies several factors that legitimately drive how broad or deep that review needs to be. This article works through those factors so you know what actually shapes a quote, and what to have ready before you request one.
Is There a Fixed FINTRAC AML Audit Fee?
No. There is no official FINTRAC fee schedule for hiring an external reviewer, and no regulation that sets a standard market price for an effectiveness review. It helps to separate two distinct things: the regulatory requirement β a two-year effectiveness review of your policies and procedures, risk assessment, and training program, documented in a specific way β and the commercial pricing an external provider charges to perform that review. Different providers structure their fees differently, and a reliable quote depends on how much work a defensible review of your specific business actually requires, not on a published rate card.
What Actually Determines FINTRAC AML Audit Cost?
FINTRAC's own guidance says the breadth and depth of your effectiveness review may vary depending on factors including the complexity of your business, your transaction volumes, findings from previous reviews, and your current money laundering, terrorist activity financing, and sanctions evasion risks. Everything below either reflects one of those four factors directly or explains a practical consequence of them for how much work a review takes.
1. Business Complexity
More products, delivery channels, customer types, or agents and mandataries generally mean more moving parts for a reviewer to test. This is one of FINTRAC's own named factors, and it affects both the number of areas the review plan needs to cover and how deeply each one needs to be tested.
2. Transaction Volume
FINTRAC explicitly names transaction volume as a factor affecting review breadth and depth. Higher volumes typically mean larger populations to sample from, more transaction testing, and more reporting records to review β though there is no single formula for how sample sizes must scale with volume.
3. Reporting Obligations in Scope
Testing may cover Suspicious Transaction Reports, Large Cash Transaction Reports, electronic funds transfer reports, large virtual currency transaction reports, or other applicable reports β but only the ones that actually apply to your business. Not every reporting entity has every obligation, and a review scoped to obligations you don't have wastes fieldwork on both sides.
4. Customer and KYC File Sampling
Reviewers typically sample client files to test identity verification, beneficial ownership records, risk-tiering, and ongoing monitoring against your own policies. A larger or more varied customer population, or a higher proportion of high-risk files, generally means more files to pull and test β again, without a single mandated sample size.
5. Quality of Existing AML Documentation
Current, well-organized policies, a risk assessment that reflects your actual operations, and clear records from your last review all make a program faster to understand and test. Thin or outdated documentation increases the time a reviewer needs simply to establish what your program is supposed to do before testing whether it works β this is a driver of review effort, not a reason to expect the audit fee to include rewriting your compliance program.
6. Previous Audit or FINTRAC Findings
FINTRAC names findings from previous reviews as a factor in scoping the next one. Unresolved findings may need to be retested, and remediation evidence may need to be examined to confirm it was actually implemented. This can add areas of focus to the plan, though it does not translate into a fixed fee increase β the effect depends on how much retesting the specific findings require.
7. Current Risk Profile
FINTRAC's own language covers money laundering, terrorist activity financing, and sanctions evasion risk. A business with higher-risk customers, geographies, products, or delivery channels β or one introducing new technology or services β may need a review plan that focuses more heavily on those areas.
8. Number of Legal Entities, Branches, or Jurisdictions
This is a practical pricing consideration rather than a FINTRAC-named factor, but it matters in real engagements. More legal entities, branches, or operating jurisdictions in scope generally means more evidence to collect and more testing to coordinate.
What Should Be Included in a FINTRAC Effectiveness Review Quote?
Before accepting a quote, confirm it makes clear: the review scope and which entities are covered; the period being reviewed; the documents you'll need to provide; the testing methodology and expected sample areas; whether staff interviews are included; the written report deliverable; whether a management debrief is included; whether remediation support is included or separately scoped; timeline assumptions; what falls outside scope; and whether the fee is fixed or subject to change orders if scope expands. Not every provider structures quotes identically β these are the points worth clarifying before you compare two proposals side by side.
Audit Cost vs Remediation Cost: Are They the Same?
Not necessarily, and this is worth confirming in writing before you compare prices. An effectiveness review identifies and documents findings β deficiencies, recommendations, and an action plan where relevant. Fixing those findings is a separate piece of work that may be included in the audit fee, partly included, or scoped as a distinct engagement, depending on the provider. If the same firm offers both the review and remediation support, that arrangement doesn't automatically satisfy any universal independence requirement on its own β the review itself still needs to be conducted and documented by someone with the knowledge and, as a best practice, the impartiality FINTRAC describes.
Why Can Two MSBs Receive Very Different Quotes?
How to Get a More Accurate AML Audit Quote
Before your scoping call, have ready: your legal entity and reporting-entity type; FINTRAC registration details, if applicable; the products and services you offer; approximate transaction volumes; your number of customers; the reporting types that apply to you; your current AML policies, risk assessment, and training records; the date and outcome of your last effectiveness review; any known open findings; the number of branches or entities in scope; the systems or platforms you use for monitoring and reporting; and your target completion deadline. The more of this a provider has upfront, the more reliable the quote you'll receive.
Does a Lower Audit Price Mean Better Value?
Not automatically, and a higher price doesn't guarantee a better review either. Price is one input; scope adequacy is the one that actually matters for meeting the effectiveness-review requirement. Before comparing quotes on price alone, ask: what will actually be tested? What samples will be reviewed, and how were they chosen? Will your reporting obligations be tested against actual filings? Will the risk assessment be validated against your current operations, not just checked for existence? What written deliverable do you receive? Are findings, recommendations, and action plans documented the way FINTRAC expects? And what happens to the price if additional scope is discovered mid-engagement?
How Often Do You Need a FINTRAC Effectiveness Review?
At least once every two years, and you must start the next review no later than 24 months from the start of the previous one. The review must be carried out and documented by an internal auditor, an external auditor, or by yourself if you don't have an auditor β an external independent firm is not universally mandated, though FINTRAC recommends impartiality as a best practice, meaning the reviewer ideally isn't someone directly involved in your compliance program's day-to-day activities. If you're an entity, specified results from the review must also be reported in writing to a senior officer no later than 30 days after completion.
How ComplyFactor Prices FINTRAC AML Audits
ComplyFactor uses scope-based pricing rather than a fixed rate card, because the factors above genuinely do change how much work a defensible review requires. Engagements start with a free 30-minute scoping call, followed by a written quote within 48 hours, with no retainer required for a standalone audit engagement. If your review surfaces gaps that need fixing, ComplyFactor's AML Compliance Program service is a separate, clearly scoped next step rather than an assumed add-on. Request an AML audit quote.
FAQ
Does FINTRAC require a minimum number of files or transactions to be sampled?
No. There is no universal minimum sample size that applies to every reporting entity. Your review plan should explain the evaluation methods and sample sizes used, and the appropriate scope depends on your business and risk profile.
What happens if an effectiveness review is overdue?
The effectiveness review is required at least every two years, with the next one starting no later than 24 months after the previous one began. Missing that window can itself be a compliance deficiency and may be cited if FINTRAC examines your business β though it doesn't automatically trigger a specific penalty.
Does a FINTRAC compliance examination replace the required two-year effectiveness review?
No. A FINTRAC examination is regulatory supervision carried out by FINTRAC itself. The two-year effectiveness review is a separate compliance-program requirement that you must carry out and document regardless of whether FINTRAC has examined you.
Can one effectiveness review cover multiple legal entities or branches?
It depends on your legal and reporting-entity structure and what the review actually covers. Where multiple entities or branches are included in scope, the review plan needs to make clear what's covered, and testing needs to be sufficient for each applicable compliance program β one review doesn't automatically satisfy every entity's separate obligation.
Can an MSB conduct the effectiveness review internally instead of hiring an external firm?
Yes, under current FINTRAC guidance the review may be conducted by an internal auditor, an external auditor, or by the entity itself if it has no auditor. Impartiality is a FINTRAC best practice, not a universal external-review requirement.
Does FINTRAC set the price of an AML effectiveness review?
No. FINTRAC sets the compliance requirement β the two-year review itself, who can conduct it, and how it must be documented β not the fee an external provider charges.
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need β free, no obligation, 30 minutes.