Key Takeaways
- Program and plan are separate obligations. Maintain a written ongoing training program plus a documented plan covering recipients, materials, methods and frequency.
- Annual training is not universally mandatory. FINTRAC permits scheduled, event-triggered or combined delivery; choose a justified schedule for each role and business risk.
- Train people according to their duties. Use role-specific modules for front-line staff, operations, compliance, management, IT and relevant agents.
- Keep delivery and competency evidence. Record dates, attendees and topics; track materials, completion, assessments and remedial action where appropriate.
- Review effectiveness at least every two years. Test the training program and plan as part of the documented compliance-program effectiveness review.
- Use real findings to improve the program. FINTRAC enforcement examples show why missing training materials, delivery records and plans can create compliance exposure.
FINTRAC's AML training requirements come from paragraphs 156(1)(d) and (e) of the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations. A reporting entity with employees, agents, mandataries or other people authorized to act for it must do two things:
- Training program: develop and maintain a written, ongoing compliance training program for those people.
- Training plan: institute and document a plan for the program and for delivering the training.
The plan sets out who is trained, on which topics and materials, by which methods and how often.
FINTRAC does not prescribe one training interval for every business. Its compliance program guidance allows training at regular intervals, when certain events occur, or both. Monthly, semi-annual and annual cycles are given as examples, not mandates. What the business must be able to show is that the program exists, that the plan was followed, and that training was actually delivered. FINTRAC's guidance expects records of the dates, attendees and topics covered.
One exception applies. A sole proprietor with no employees, agents or other individuals authorized to act on their behalf does not need a training program or a training plan for themselves. The exception ends as soon as the first employee or agent starts acting for the business.
Training is one of five compliance program elements, set out alongside the others in the overview of PCMLTFA compliance program requirements. This article covers what a compliance officer actually has to build, run and evidence.
Training program versus training plan
The two are separate legal requirements, and FINTRAC enforcement decisions cite failures in each. Treat them as two documents with different jobs.
In practice: a remittance MSB's program includes a module on its procedure for escalating unusual transactions, written against its own risk assessment. Its plan states that tellers complete that module before serving clients, receive a refresher on a set cycle, and are retrained after any change to the escalation procedure. The plan also says who delivers each session and how attendance is recorded. Neither document substitutes for the other.
Who needs AML training?
FINTRAC's guidance points to four groups:
- people who have contact with clients, such as front-line staff or agents
- people involved in client transaction activities
- people who handle cash, funds or virtual currency for the business in any way
- people responsible for implementing or overseeing the compliance program, such as the compliance officer, senior management, IT staff and internal auditors
Job duties, not job titles, decide who is in scope and what they need. A product manager who designs onboarding flows needs training on identity verification rules, even without ever meeting a client. A receptionist who never handles client information or funds may need only general awareness.
The same logic covers people outside the payroll. Agents and mandataries who deal with clients on the business's behalf are within the training obligation. The principal business remains responsible for that training. For a remittance MSB, agent training sits inside a broader oversight framework, covered in the guide to FINTRAC agent oversight and training controls.
Agent training should not be confused with the agent eligibility checks that took effect for MSBs on October 1, 2025. Those checks cover eligibility verification and criminal record checks before an agent is engaged. They are a separate control, and completing one does not satisfy the other.
Role-based training matrix
Larger businesses can tailor training to specific roles. The matrix below is illustrative. It shows how content, practice and evidence change by role. No role needs every module.
What the training should cover
FINTRAC expects the program to cover the business's obligations under the Act and Regulations, background on money laundering and terrorist financing, the business's own vulnerabilities, its policies and procedures, and each person's role. In practice, that usually means the following topics, scaled to each role and limited to what the business actually does:
- Legal obligations that apply to this business. Not every sector files every report. A real estate brokerage, for example, has no Electronic Funds Transfer Report obligation, while an MSB generally does.
- ML/TF methods relevant to the sector, drawn from the business's risk assessment rather than generic examples.
- Sanctions-related risks and obligations, where relevant. Training should separate three things:
- Canada's sanctions laws and the Criminal Code restrict dealings with property of listed persons and entities, subject to any exemptions or authorizations those laws provide.
- Where a business has a disclosure obligation under those laws, it must also submit a Listed Person or Entity Property Report to FINTRAC immediately. That report is triggered by the property itself and does not require a transaction. FINTRAC's listed person and entity property guidance explains when that applies.
- A transaction connected to sanctions evasion can also require a suspicious transaction report, since sanctions evasion offences are within the STR obligation.
- Client identification, beneficial ownership, third-party and PEP determinations for the roles that perform them.
- Recognizing unusual activity and escalating it internally. This includes attempted transactions, which can still give rise to a suspicious transaction report.
- Confidentiality. Staff should understand that escalations and reports are not discussed with the client.
- Record keeping and ongoing monitoring, at the level each role touches them.
- The business's own procedures and each person's responsibilities under them.
- How to escalate a suspected control failure, such as a system not flagging a threshold or a report that failed to submit. Staff then treat failures as compliance events, not IT tickets.
Content should change when the business does. Since March 26, 2026, compliance programs have had to be reasonably designed, risk-based and effective. Training built around last year's products or procedures is difficult to defend under that standard.
Choosing and documenting training frequency
The legal requirement is a documented plan that states frequency. The schedule itself is an internal decision, and it should be justified by risk and by operational need. The table separates the types of training a plan typically combines.
Factors that justify a shorter or longer cycle include:
- the business's activities and products
- client and geographic risk
- new services
- past deficiencies
- staff turnover
- employee performance
- gaps found through testing
Record the rationale in the plan. An annual refresher can be reasonable, but it does not guarantee compliance on its own, and a single annual session for all staff is rarely enough on its own for a business with several distinct roles.
Illustrative 12-month training calendar for a Canadian MSB
This is an example internal calendar for a mid-sized remittance and foreign exchange MSB. It is not a FINTRAC schedule.
The calendar answers when and how training happens. The role matrix answers who learns what. A business needs both, and both belong in, or are referenced by, the training plan.
Delivery methods
FINTRAC's guidance names several methods, including self-directed learning, information sessions, face-to-face meetings, classroom sessions, conferences and on-the-job training. Trainers can be internal or external, provided they know the Act and Regulations. FINTRAC does not require a particular learning management system, course provider or certification.
Choose the method according to what the person must be able to do:
- Knowledge of a rule, such as a reporting threshold, can be taught through e-learning or a briefing.
- Judgement, such as deciding whether behaviour is unusual enough to escalate, needs scenario work and discussion.
- Procedural skill, such as completing a report correctly, is best learned on the job, under review.
Circulating a policy and collecting an acknowledgement shows that a person received a document. It does not show they can apply the procedure. That difference matters later when training effectiveness is tested.
Training records: what to keep and why
FINTRAC's guidance expects a record of training delivered, such as dates, attendees and topics covered. The fields below separate those expected items from additional internal evidence that makes the record usable.
Keep the program and plan documents themselves with a version history. Many training deficiencies are really a mismatch between what the plan says and what the records show.
On retention, no specific retention period for training records was identified in the Regulations or in FINTRAC's compliance program guidance. Set one in your own policy. A practical approach is to keep records long enough to cover the periods an examination or the next effectiveness reviews could examine. That is an internal recommendation, not a stated legal rule.
Testing whether training works
Attendance is not competence. The common failure is a business where everyone completed the module, yet nobody can explain when to escalate. Practical ways to test understanding include:
- short scenario assessments after a module
- staff interviews, which FINTRAC itself uses in examinations
- role-specific quizzes
- observing live transactions or onboarding
- file reviews
- simulated escalations
- tracking error trends before and after training
Hypothetical scenario.
- The error: A quarterly QA review at a remittance MSB samples 40 transactions flagged by its monitoring rules. In several, tellers recorded the client's explanation for an unusual pattern but did not escalate to the compliance officer. Every teller had completed the escalation module in the past year.
- How it was identified: Interviews show the cause. The module taught indicators, but staff believed a plausible explanation from the client meant no escalation was needed.
- What changed: The compliance officer rewrites the module around decision scenarios in which a plausible explanation still requires escalation. Tellers repeat the training in small groups, and the procedure is amended to make the escalation step explicit.
- Evidence of improvement: The next two QA samples show escalations recorded for comparable cases. The training plan is updated to add the revised module, with a short follow-up assessment for new hires.
Nothing in that example sets a FINTRAC pass mark or sample size. Those are internal choices, and they should be recorded in the plan or QA procedure.
FINTRAC examinations and the two-year effectiveness review
Examiners and effectiveness reviewers look at training in layers:
- Is there a written program?
- Is there a documented plan covering recipients, topics and materials, methods and frequency?
- Was training delivered according to the plan?
- Are there records?
- Does the content match the business's actual obligations and risks?
- Do staff understand and apply it?
- Were weaknesses corrected?
FINTRAC's examination methods include interviewing employees and agents about the requirements that apply to their duties.
The prescribed effectiveness review is a separate obligation from routine training. Under paragraph 156(1)(f) of the Regulations, a business must institute and document a plan for the review, then carry it out at least every two years. FINTRAC's guidance sets out how this works:
- The review plan should cover the scope, its rationale, the period reviewed, the evaluation methods and the sample sizes. It should cover each element tested: the policies and procedures, the risk assessment, and the training program and plan.
- Timing: a new review must start no later than 24 months after the previous review started, and the previous review must be finished before the next one begins.
- Who conducts it: an internal or external auditor, or the business itself if it has no auditor. FINTRAC recommends, as a best practice rather than a rule, that the reviewer not be directly involved in the compliance program.
- Reporting: an entity must report in writing to a senior officer within 30 days after the review is completed. The report covers the findings, updates made to policies and procedures during the period, and the status of implementing those updates.
For training, the review typically tests whether the plan was followed, whether the content matches current obligations and risks, and whether staff understand the procedures. FINTRAC gives staff interviews as an example method.
The review does not require every training session to be validated externally, and more frequent internal QA is a choice, not a legal requirement. Where the review needs to be independent of the people running training, an independent AML effectiveness review can test the training element alongside the rest of the program.
What recent enforcement shows
Two recent FINTRAC decisions included the same training violation, failure to develop and maintain a written ongoing compliance training program, in two very different reporting entities. In each case it was one of four violations, and FINTRAC did not publish separate amounts for each violation.
The other violations in both decisions concerned policies and procedures, the risk assessment and the two-year review.
The lessons differ slightly:
- Manor Windsor had training material, but it omitted key obligations and could not be shown to have been delivered. Content mapped to the obligations and a delivery record are the controls that address that kind of gap.
- Northern Isga lacked the program and plan altogether. Writing the documents is the starting point there, before delivery or testing can mean anything.
These outcomes reflect those cases. They are not a guide to the penalty in any other matter. Each published decision states that the entity has appealed to the Federal Court.
Sector examples: remittance MSB and real estate brokerage
Both examples are hypothetical.
Remittance MSB. The training weight sits with tellers, KYC staff and transaction operations. Tellers practise recognizing transfers split to stay under thresholds and escalating them. Operations staff practise 24-hour aggregation and EFTR data quality. Agents receive the subset of procedures they perform, and the principal keeps their completion records. A change in the reporting procedure triggers targeted training for operations staff before it takes effect.
Real estate brokerage. The audience is mostly licensed representatives who meet clients during a transaction, and the content looks quite different:
- verifying the identity of clients
- since October 1, 2025, verifying unrepresented parties to a transaction
- third-party determinations
- receipt-of-funds records
- recognizing real estate indicators such as unexplained last-minute buyer changes or prices well outside market value
There is no EFT reporting content, because brokerages do not have that obligation. The brokerage, not each representative, owns the program and plan. Its frequency decisions should reflect transaction volume and how often representatives actually encounter regulated situations. Further sector detail is in the guide to FINTRAC compliance for real estate brokers and developers.
Building or fixing a training program: checklist
- β List everyone who acts for the business, including agents and mandataries, and confirm whether the sole-proprietor exception applies
- β Map each role to the obligations and procedures it performs
- β Pull risks and indicators from the current risk assessment
- β Define modules and write or update materials, with version control
- β Choose delivery methods according to the skill required
- β Set and justify frequency for each audience, including event triggers
- β Approve the program and plan, and name owners for delivery and records
- β Deliver, and record dates, attendees and topics as a minimum
- β Test understanding and application, not just attendance
- β Assign remedial training and fix the materials where testing shows gaps
- β Revisit the plan after regulatory changes, review findings or business changes
Where nobody has the time or authority to run that cycle, ongoing compliance officer oversight can own the plan, the records and the follow-up.
Frequently asked questions
What evidence should we obtain when an external provider delivers training?
Ask for the provider's outline or a copy of the materials, with a version or date, before you rely on the course. Record which version each person took. Obtain completion or attendance reports that identify individuals and dates, not just a summary count, and import them into your own training log. Assessment results are worth obtaining too, where the course includes them.
Then map the course against your training program. Wherever it does not cover your own procedures, risk indicators or escalation route, note the gap and fill it with a business-specific module. The provider delivers content, but the program, the plan and the records remain your responsibility, so keep copies rather than relying on the provider's portal staying available.
What should happen when someone misses scheduled training?
Record the miss, set a short catch-up date, and decide whether the person can continue the relevant duties in the meantime. That is particularly important for initial training planned before client contact. A pattern of overdue training is worth reporting to senior management, because examiners compare records against the plan, and repeated gaps undermine the claim that the plan is followed.
How should agents or staff who work in other languages be trained?
The training must be understood to be effective, so deliver it in a language the recipient works in where needed, and keep the materials consistent with the approved version. Keep a record of which language version each person received. Test understanding in the same language rather than assuming a translated document was absorbed.
Building a training program that will stand up to an examination or effectiveness review takes more than a course library. ComplyFactor helps Canadian reporting entities develop role-appropriate AML training content and a documented training plan as part of the written compliance program, with templates for recording training delivered and completed.
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need β free, no obligation, 30 minutes.
