FINTRAC

FINTRAC AML Training Requirements: Training Plan, Frequency, Role-Based Training and Records

Practical guide to FINTRAC AML training programs and plans, role-based training, frequency, evidence records, effectiveness testing and real enforcement lessons.

On this page
Get Expert Help

Key Takeaways

  • Program and plan are separate obligations. Maintain a written ongoing training program plus a documented plan covering recipients, materials, methods and frequency.
  • Annual training is not universally mandatory. FINTRAC permits scheduled, event-triggered or combined delivery; choose a justified schedule for each role and business risk.
  • Train people according to their duties. Use role-specific modules for front-line staff, operations, compliance, management, IT and relevant agents.
  • Keep delivery and competency evidence. Record dates, attendees and topics; track materials, completion, assessments and remedial action where appropriate.
  • Review effectiveness at least every two years. Test the training program and plan as part of the documented compliance-program effectiveness review.
  • Use real findings to improve the program. FINTRAC enforcement examples show why missing training materials, delivery records and plans can create compliance exposure.

FINTRAC's AML training requirements come from paragraphs 156(1)(d) and (e) of the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations. A reporting entity with employees, agents, mandataries or other people authorized to act for it must do two things:

  • Training program: develop and maintain a written, ongoing compliance training program for those people.
  • Training plan: institute and document a plan for the program and for delivering the training.

The plan sets out who is trained, on which topics and materials, by which methods and how often.

FINTRAC does not prescribe one training interval for every business. Its compliance program guidance allows training at regular intervals, when certain events occur, or both. Monthly, semi-annual and annual cycles are given as examples, not mandates. What the business must be able to show is that the program exists, that the plan was followed, and that training was actually delivered. FINTRAC's guidance expects records of the dates, attendees and topics covered.

One exception applies. A sole proprietor with no employees, agents or other individuals authorized to act on their behalf does not need a training program or a training plan for themselves. The exception ends as soon as the first employee or agent starts acting for the business.

Training is one of five compliance program elements, set out alongside the others in the overview of PCMLTFA compliance program requirements. This article covers what a compliance officer actually has to build, run and evidence.

Training program versus training plan

The two are separate legal requirements, and FINTRAC enforcement decisions cite failures in each. Treat them as two documents with different jobs.

Training program Training plan
Purpose Defines what people must know and be able to do Defines how the program is delivered: to whom, with what, how and when
Core content The business's obligations under the Act and Regulations; ML/TF background and methods; the business's own vulnerabilities; its policies and procedures; each person's role Recipients, topics and materials, delivery methods, and frequency
Operational form Approved curriculum, module outlines and training materials, with version control A schedule or matrix linking roles to modules, methods and timing, with a named owner
Evidence Current approved materials and their version history Delivery records showing the plan was followed
Common deficiency Generic content that omits the business's actual obligations or risks No plan at all, or a plan that exists on paper but does not match what was delivered

In practice: a remittance MSB's program includes a module on its procedure for escalating unusual transactions, written against its own risk assessment. Its plan states that tellers complete that module before serving clients, receive a refresher on a set cycle, and are retrained after any change to the escalation procedure. The plan also says who delivers each session and how attendance is recorded. Neither document substitutes for the other.

Who needs AML training?

FINTRAC's guidance points to four groups:

  • people who have contact with clients, such as front-line staff or agents
  • people involved in client transaction activities
  • people who handle cash, funds or virtual currency for the business in any way
  • people responsible for implementing or overseeing the compliance program, such as the compliance officer, senior management, IT staff and internal auditors

Job duties, not job titles, decide who is in scope and what they need. A product manager who designs onboarding flows needs training on identity verification rules, even without ever meeting a client. A receptionist who never handles client information or funds may need only general awareness.

The same logic covers people outside the payroll. Agents and mandataries who deal with clients on the business's behalf are within the training obligation. The principal business remains responsible for that training. For a remittance MSB, agent training sits inside a broader oversight framework, covered in the guide to FINTRAC agent oversight and training controls.

Agent training should not be confused with the agent eligibility checks that took effect for MSBs on October 1, 2025. Those checks cover eligibility verification and criminal record checks before an agent is engaged. They are a separate control, and completing one does not satisfy the other.

Role-based training matrix

Larger businesses can tailor training to specific roles. The matrix below is illustrative. It shows how content, practice and evidence change by role. No role needs every module.

Role Training focus Practical exercise Evidence of completion
Front-line staff When identity must be verified; behaviour and transaction indicators relevant to the business; internal escalation route; confidentiality of escalations Short scenarios where the trainee decides whether, how and to whom to escalate Attendance or completion record; scenario results
KYC and onboarding analysts Permitted identity verification methods; beneficial ownership; third-party determinations; PEP determinations; documentation standards Review of sample files containing deliberate defects Completion record; file-review exercise results
Transaction operations The reporting triggers the business actually has, such as cash, EFT or virtual currency thresholds; 24-hour aggregation; data quality; deadlines Building a report from raw transaction data and identifying aggregated groups Completion record; exercise output checked by a reviewer
Compliance officer and MLRO Current legal obligations and changes; STR decision-making and documentation; training governance; remediation External or specialist training; case-review discussions Certificates or agendas where available; notes of regulatory updates applied
Senior management and board Oversight duties; the business's risk profile; examination findings; resourcing and escalation Briefing using the latest risk assessment and review findings Minutes or briefing record
IT and product teams How systems support AML controls: alert logic, data fields, report generation, access to records; when a change needs compliance sign-off Walk-through of a proposed system change against the controls it affects Attendance record; change-management sign-offs
Internal audit and QA How the controls are meant to operate, so they can be tested Joint testing of a sample against procedures Attendance record; testing workpapers
Agents The parts of the principal's procedures that agents perform: identification, records, escalation to the principal Escalation scenarios using the agent's own transaction types Completion records held by the principal

What the training should cover

FINTRAC expects the program to cover the business's obligations under the Act and Regulations, background on money laundering and terrorist financing, the business's own vulnerabilities, its policies and procedures, and each person's role. In practice, that usually means the following topics, scaled to each role and limited to what the business actually does:

  • Legal obligations that apply to this business. Not every sector files every report. A real estate brokerage, for example, has no Electronic Funds Transfer Report obligation, while an MSB generally does.
  • ML/TF methods relevant to the sector, drawn from the business's risk assessment rather than generic examples.
  • Sanctions-related risks and obligations, where relevant. Training should separate three things:
    • Canada's sanctions laws and the Criminal Code restrict dealings with property of listed persons and entities, subject to any exemptions or authorizations those laws provide.
    • Where a business has a disclosure obligation under those laws, it must also submit a Listed Person or Entity Property Report to FINTRAC immediately. That report is triggered by the property itself and does not require a transaction. FINTRAC's listed person and entity property guidance explains when that applies.
    • A transaction connected to sanctions evasion can also require a suspicious transaction report, since sanctions evasion offences are within the STR obligation.
    Staff exposed to these risks need to recognize sanctions-evasion indicators and know to escalate a possible match to the compliance officer, rather than decide alone how to proceed.
  • Client identification, beneficial ownership, third-party and PEP determinations for the roles that perform them.
  • Recognizing unusual activity and escalating it internally. This includes attempted transactions, which can still give rise to a suspicious transaction report.
  • Confidentiality. Staff should understand that escalations and reports are not discussed with the client.
  • Record keeping and ongoing monitoring, at the level each role touches them.
  • The business's own procedures and each person's responsibilities under them.
  • How to escalate a suspected control failure, such as a system not flagging a threshold or a report that failed to submit. Staff then treat failures as compliance events, not IT tickets.

Content should change when the business does. Since March 26, 2026, compliance programs have had to be reasonably designed, risk-based and effective. Training built around last year's products or procedures is difficult to defend under that standard.

Choosing and documenting training frequency

The legal requirement is a documented plan that states frequency. The schedule itself is an internal decision, and it should be justified by risk and by operational need. The table separates the types of training a plan typically combines.

Training type Typical trigger (internal decision) Notes
Initial training Before a person begins regulated duties FINTRAC's guidance gives "before a new employee deals with clients" as an example of event-based delivery
Planned refresher A fixed cycle chosen for each audience Higher-risk roles may justify shorter cycles than administrative roles
Regulatory update A change in law, regulations or FINTRAC guidance that affects the business Delivered to the roles affected, not necessarily to everyone
Procedure or system change A new product, corridor, policy, form or reporting system Ideally delivered before the change goes live
Remedial Errors found in QA, examinations or effectiveness reviews; repeated individual mistakes Targeted at the people and topics involved
High-risk function Roles handling high-risk clients, corridors or products May need deeper content as well as more frequent delivery

Factors that justify a shorter or longer cycle include:

  • the business's activities and products
  • client and geographic risk
  • new services
  • past deficiencies
  • staff turnover
  • employee performance
  • gaps found through testing

Record the rationale in the plan. An annual refresher can be reasonable, but it does not guarantee compliance on its own, and a single annual session for all staff is rarely enough on its own for a business with several distinct roles.

Illustrative 12-month training calendar for a Canadian MSB

This is an example internal calendar for a mid-sized remittance and foreign exchange MSB. It is not a FINTRAC schedule.

Timing Recipients Focus Method Follow-up and evidence
On hire, before client contact New front-line, KYC and operations staff Core obligations, procedures and escalation route Self-directed module plus supervised shifts Completion record; supervisor sign-off before working alone
Quarter 1 Front-line staff and agents Refresher on indicators, using recent internal escalations, anonymized Live or virtual session Attendance list; short scenario check
Quarter 2 Transaction operations Reporting data quality and aggregation, using error trends from QA Workshop Exercise results reviewed by the compliance officer
Quarter 2 Senior management Risk assessment update and examination readiness Briefing Minutes
Quarter 3 All in-scope staff Full-program refresher (this business's chosen annual cycle, not a FINTRAC requirement) E-learning Completion report; follow-up list for anyone overdue
Quarter 4 IT and product Upcoming system changes and the controls they affect Walk-through Attendance and change-management records
As needed Affected roles New FINTRAC guidance, new corridor, procedure change, remedial needs Targeted session or bulletin with acknowledgement Record linked to the trigger event

The calendar answers when and how training happens. The role matrix answers who learns what. A business needs both, and both belong in, or are referenced by, the training plan.

Delivery methods

FINTRAC's guidance names several methods, including self-directed learning, information sessions, face-to-face meetings, classroom sessions, conferences and on-the-job training. Trainers can be internal or external, provided they know the Act and Regulations. FINTRAC does not require a particular learning management system, course provider or certification.

Choose the method according to what the person must be able to do:

  • Knowledge of a rule, such as a reporting threshold, can be taught through e-learning or a briefing.
  • Judgement, such as deciding whether behaviour is unusual enough to escalate, needs scenario work and discussion.
  • Procedural skill, such as completing a report correctly, is best learned on the job, under review.

Circulating a policy and collecting an acknowledgement shows that a person received a document. It does not show they can apply the procedure. That difference matters later when training effectiveness is tested.

Training records: what to keep and why

FINTRAC's guidance expects a record of training delivered, such as dates, attendees and topics covered. The fields below separate those expected items from additional internal evidence that makes the record usable.

Field Status
Date delivered Expected in FINTRAC guidance
Attendees or completers Expected in FINTRAC guidance
Topics covered Expected in FINTRAC guidance
Employee or agent identifier and role Recommended. Links the record to the role matrix
Module and material version Recommended. Shows which version of the content was used
Delivery method Recommended. The plan must describe methods, so this shows the plan was followed
Completion status and assessment result, where used Recommended
Follow-up assigned, such as overdue or remedial training Recommended
Next scheduled training date Recommended

Keep the program and plan documents themselves with a version history. Many training deficiencies are really a mismatch between what the plan says and what the records show.

On retention, no specific retention period for training records was identified in the Regulations or in FINTRAC's compliance program guidance. Set one in your own policy. A practical approach is to keep records long enough to cover the periods an examination or the next effectiveness reviews could examine. That is an internal recommendation, not a stated legal rule.

Testing whether training works

Attendance is not competence. The common failure is a business where everyone completed the module, yet nobody can explain when to escalate. Practical ways to test understanding include:

  • short scenario assessments after a module
  • staff interviews, which FINTRAC itself uses in examinations
  • role-specific quizzes
  • observing live transactions or onboarding
  • file reviews
  • simulated escalations
  • tracking error trends before and after training

Hypothetical scenario.

  • The error: A quarterly QA review at a remittance MSB samples 40 transactions flagged by its monitoring rules. In several, tellers recorded the client's explanation for an unusual pattern but did not escalate to the compliance officer. Every teller had completed the escalation module in the past year.
  • How it was identified: Interviews show the cause. The module taught indicators, but staff believed a plausible explanation from the client meant no escalation was needed.
  • What changed: The compliance officer rewrites the module around decision scenarios in which a plausible explanation still requires escalation. Tellers repeat the training in small groups, and the procedure is amended to make the escalation step explicit.
  • Evidence of improvement: The next two QA samples show escalations recorded for comparable cases. The training plan is updated to add the revised module, with a short follow-up assessment for new hires.

Nothing in that example sets a FINTRAC pass mark or sample size. Those are internal choices, and they should be recorded in the plan or QA procedure.

FINTRAC examinations and the two-year effectiveness review

Examiners and effectiveness reviewers look at training in layers:

  1. Is there a written program?
  2. Is there a documented plan covering recipients, topics and materials, methods and frequency?
  3. Was training delivered according to the plan?
  4. Are there records?
  5. Does the content match the business's actual obligations and risks?
  6. Do staff understand and apply it?
  7. Were weaknesses corrected?

FINTRAC's examination methods include interviewing employees and agents about the requirements that apply to their duties.

The prescribed effectiveness review is a separate obligation from routine training. Under paragraph 156(1)(f) of the Regulations, a business must institute and document a plan for the review, then carry it out at least every two years. FINTRAC's guidance sets out how this works:

  • The review plan should cover the scope, its rationale, the period reviewed, the evaluation methods and the sample sizes. It should cover each element tested: the policies and procedures, the risk assessment, and the training program and plan.
  • Timing: a new review must start no later than 24 months after the previous review started, and the previous review must be finished before the next one begins.
  • Who conducts it: an internal or external auditor, or the business itself if it has no auditor. FINTRAC recommends, as a best practice rather than a rule, that the reviewer not be directly involved in the compliance program.
  • Reporting: an entity must report in writing to a senior officer within 30 days after the review is completed. The report covers the findings, updates made to policies and procedures during the period, and the status of implementing those updates.

For training, the review typically tests whether the plan was followed, whether the content matches current obligations and risks, and whether staff understand the procedures. FINTRAC gives staff interviews as an example method.

The review does not require every training session to be validated externally, and more frequent internal QA is a choice, not a legal requirement. Where the review needs to be independent of the people running training, an independent AML effectiveness review can test the training element alongside the rest of the program.

What recent enforcement shows

Two recent FINTRAC decisions included the same training violation, failure to develop and maintain a written ongoing compliance training program, in two very different reporting entities. In each case it was one of four violations, and FINTRAC did not publish separate amounts for each violation.

Decision Training findings Total penalty (all four violations) Status
Manor Windsor Realty Ltd. , real estate brokerage, Windsor, Ontario. Imposed November 27, 2025; published February 12, 2026 Training material missing key regulatory requirements; no records of training delivered to employees; no documented training plan $107,250 Appealed to the Federal Court
Northern Isga Foundation , a non-profit charitable organization established by the Alexis Nakota Sioux Nation, headquartered in Glenevis, Alberta. FINTRAC describes it as a reporting entity that receives a portion of the revenues of Eagle River Casino. Imposed March 2, 2026; published March 26, 2026 No ongoing training program developed; no documented training plan; no delivery records $91,162.50 Appealed to the Federal Court

The other violations in both decisions concerned policies and procedures, the risk assessment and the two-year review.

The lessons differ slightly:

  • Manor Windsor had training material, but it omitted key obligations and could not be shown to have been delivered. Content mapped to the obligations and a delivery record are the controls that address that kind of gap.
  • Northern Isga lacked the program and plan altogether. Writing the documents is the starting point there, before delivery or testing can mean anything.

These outcomes reflect those cases. They are not a guide to the penalty in any other matter. Each published decision states that the entity has appealed to the Federal Court.

Sector examples: remittance MSB and real estate brokerage

Both examples are hypothetical.

Remittance MSB. The training weight sits with tellers, KYC staff and transaction operations. Tellers practise recognizing transfers split to stay under thresholds and escalating them. Operations staff practise 24-hour aggregation and EFTR data quality. Agents receive the subset of procedures they perform, and the principal keeps their completion records. A change in the reporting procedure triggers targeted training for operations staff before it takes effect.

Real estate brokerage. The audience is mostly licensed representatives who meet clients during a transaction, and the content looks quite different:

  • verifying the identity of clients
  • since October 1, 2025, verifying unrepresented parties to a transaction
  • third-party determinations
  • receipt-of-funds records
  • recognizing real estate indicators such as unexplained last-minute buyer changes or prices well outside market value

There is no EFT reporting content, because brokerages do not have that obligation. The brokerage, not each representative, owns the program and plan. Its frequency decisions should reflect transaction volume and how often representatives actually encounter regulated situations. Further sector detail is in the guide to FINTRAC compliance for real estate brokers and developers.

Building or fixing a training program: checklist

  • ☐ List everyone who acts for the business, including agents and mandataries, and confirm whether the sole-proprietor exception applies
  • ☐ Map each role to the obligations and procedures it performs
  • ☐ Pull risks and indicators from the current risk assessment
  • ☐ Define modules and write or update materials, with version control
  • ☐ Choose delivery methods according to the skill required
  • ☐ Set and justify frequency for each audience, including event triggers
  • ☐ Approve the program and plan, and name owners for delivery and records
  • ☐ Deliver, and record dates, attendees and topics as a minimum
  • ☐ Test understanding and application, not just attendance
  • ☐ Assign remedial training and fix the materials where testing shows gaps
  • ☐ Revisit the plan after regulatory changes, review findings or business changes

Where nobody has the time or authority to run that cycle, ongoing compliance officer oversight can own the plan, the records and the follow-up.

Frequently asked questions

What evidence should we obtain when an external provider delivers training?

Ask for the provider's outline or a copy of the materials, with a version or date, before you rely on the course. Record which version each person took. Obtain completion or attendance reports that identify individuals and dates, not just a summary count, and import them into your own training log. Assessment results are worth obtaining too, where the course includes them.

Then map the course against your training program. Wherever it does not cover your own procedures, risk indicators or escalation route, note the gap and fill it with a business-specific module. The provider delivers content, but the program, the plan and the records remain your responsibility, so keep copies rather than relying on the provider's portal staying available.

What should happen when someone misses scheduled training?

Record the miss, set a short catch-up date, and decide whether the person can continue the relevant duties in the meantime. That is particularly important for initial training planned before client contact. A pattern of overdue training is worth reporting to senior management, because examiners compare records against the plan, and repeated gaps undermine the claim that the plan is followed.

How should agents or staff who work in other languages be trained?

The training must be understood to be effective, so deliver it in a language the recipient works in where needed, and keep the materials consistent with the approved version. Keep a record of which language version each person received. Test understanding in the same language rather than assuming a translated document was absorbed.

Building a training program that will stand up to an examination or effectiveness review takes more than a course library. ComplyFactor helps Canadian reporting entities develop role-appropriate AML training content and a documented training plan as part of the written compliance program, with templates for recording training delivered and completed.

ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.