FINTRAC Enforcement

FINTRAC Imposes $816,750 in Penalties on Four Credit Unions: Compliance Lessons for Financial Entities

FINTRAC announced $816,750 in penalties against four Canadian credit unions. See the findings, recurring AML weaknesses, and practical compliance lessons.

On this page
Get Expert Help

Key Takeaways

  • FINTRAC announced $816,750 in administrative monetary penalties against four Canadian credit unions on September 24, 2026.
  • The cases repeatedly involved gaps between documented controls and how policies, monitoring, risk assessment and alert handling were applied in practice.
  • UNI Financial Cooperation received the largest penalty at $676,500, while Caisse Alliance was the only case with an effectiveness-review violation.
  • Financial entities should test actual files, monitoring schedules, risk ratings, alerts and remediation evidence rather than only confirming that policies exist.

On September 24, 2026, FINTRAC announced $816,750 in administrative monetary penalties against four Canadian credit unions following separate compliance examinations. Across the cases, FINTRAC identified recurring weaknesses involving policy implementation, risk assessment, ongoing monitoring, suspicious transaction reporting and effectiveness testing.

These are administrative monetary penalties (AMPs) under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its associated Regulations β€” not criminal convictions. FINTRAC's notices do not allege that any of the four institutions committed or facilitated money laundering; the issue is non-compliance with administrative and reporting obligations under Part 1 of the Act.

FINTRAC's September 2026 Credit Union Penalties at a Glance

Institution Penalty Penalty Date Violations Key Areas Identified Status
Caisse populaire acadienne ltΓ©e (UNI Financial Cooperation) $676,500 July 23, 2026 3 STR reporting (Very Serious); policies & procedures; risk assessment Paid in full, closed
Caisse populaire Alliance limitΓ©e (Caisse Alliance) $82,500 June 5, 2026 4 Policies & procedures; high-risk client controls; risk assessment; effectiveness review Paid in full, closed
Pathwise Credit Union $41,250 June 4, 2026 2 Policies & procedures (monitoring frequency); risk assessment Paid in full, closed
Your Neighbourhood Credit Union Limited $16,500 August 10, 2026 1 Policies & procedures (production orders, ongoing monitoring) Paid in full, closed

September 24, 2026 was FINTRAC's public announcement date for all four notices. The penalties themselves were imposed on separate dates between June and August 2026, following examinations conducted earlier.

UNI Financial Cooperation: The Largest Penalty at $676,500

Caisse populaire acadienne ltΓ©e, headquartered in Caraquet, New Brunswick, and operating as UNI Financial Cooperation, is a federally regulated credit union. FINTRAC's examination identified three violations.

Suspicious transaction reporting

FINTRAC found that in four instances, UNI failed to report financial transactions that exhibited money laundering or terrorist activity financing indicators and met the reasonable-grounds-to-suspect threshold. The indicators cited in FINTRAC's notice included transaction sizes or types atypical of the client, funds moved in and out of an account within a short period, frequent transfers between institutions, unusual or unjustified amounts, and links to individuals or entities identified by media, law enforcement or intelligence sources as connected to criminal activity. FINTRAC classified this violation as Very Serious.

Policies and procedures

UNI's procedures did not document how staff should handle production orders tied to money-laundering indicators, and FINTRAC linked this gap directly to the four unreported STRs. FINTRAC also found weaknesses in how unusual transaction alerts were analyzed β€” incomplete transaction assessments, missing linked-account searches, and thin documented conclusions. Ongoing monitoring was applied inconsistently, with some client identification information left outdated, and FINTRAC identified a backlog in transactional alerts that put accurate client risk ratings, enhanced measures, and STR reporting at risk. This violation was classified Serious.

Risk assessment

FINTRAC found UNI's risk-based assessment incomplete: it lacked sufficient analysis of the client base and a breakdown of clients across risk categories, and was not applied in practice β€” high-risk activity was not consistently reflected in client risk scoring or STR decisions. FINTRAC also found that UNI had not assessed the risk of its own transaction monitoring system, and had no manual process to adjust a client's risk rating for events the system would not automatically capture, such as a production order or adverse media hit. This violation was classified Serious.

Pathwise Credit Union: Policies, Monitoring and Risk Assessment

Pathwise Credit Union, headquartered in Oshawa, Ontario, was penalized $41,250 for two violations, both classified Serious.

Policies and procedures

FINTRAC found that Pathwise's documented ongoing-monitoring frequency was not commensurate with a risk-based approach, and that even the frequency it had documented was not applied in practice. The examination identified a backlog of medium-risk account reviews, and low-risk accounts that were monitored only when a transaction triggered a review, rather than at the frequency the credit union's own policy specified.

Risk assessment

Pathwise's risk assessment did not fully evaluate the risks tied to its clients and business relationships. FINTRAC also found that Pathwise did not follow its own documented rule for how long a member should remain classified as high risk after being the subject of an STR.

Your Neighbourhood Credit Union: One Violation, Wide-Ranging Findings

Your Neighbourhood Credit Union Limited, headquartered in Kitchener, Ontario, received the smallest penalty of the four β€” $16,500 β€” for a single violation, classified Serious. Although FINTRAC recorded one violation, the public notice describes multiple implementation deficiencies within that violation.

FINTRAC determined that YNCU had documented policies and procedures for handling law-enforcement production orders and for assessing and reporting suspicious transactions, but did not consistently apply them when assessing the context and facts of a production order β€” a gap FINTRAC said could affect whether suspicious activity gets reported at all.

The examination also reviewed YNCU's ongoing-monitoring records against the frequencies the credit union's own policies established by client risk level. Approximately 76% of the ongoing-monitoring records reviewed contained deficiencies. These included missing information on a client's principal business, missing beneficial ownership information for entity clients, gaps in documenting the purpose and intended nature of the business relationship, incomplete politically-exposed-person or head-of-international-organization determinations, missing client risk-assessment updates, and incomplete documentation of measures taken for high-risk clients.

Caisse Alliance: High-Risk Controls, Risk Assessment and Effectiveness Review

Caisse populaire Alliance limitΓ©e, operating as Caisse Alliance and headquartered in North Bay, Ontario, was penalized $82,500 for four violations, all classified Serious.

Policies and procedures

FINTRAC found Caisse Alliance's policies incomplete on several fronts: they did not address ministerial-directive obligations and operational restrictions related to Russia, and did not address the obligation to report suspected sanctions evasion. FINTRAC also identified gaps in client information β€” including missing occupation details β€” inconsistently applied in practice, along with incomplete evaluations of unusual-transaction alerts, limited adverse-media research, and ongoing-monitoring practices that did not consistently reflect client risk.

High-risk client controls

Caisse Alliance's own policy required an annual review of high-risk clients. FINTRAC reviewed its high-risk client files and found that 46 of 118 had not been reviewed in over 12 months. Within that group, 10 files had not been reviewed in more than five years, and 6 had gaps exceeding ten years between their two most recent reviews. FINTRAC noted that Caisse Alliance had established procedures for enhanced ongoing monitoring, including more frequent review for higher-risk clients β€” the gap was in whether those procedures were actually carried out.

Risk assessment

FINTRAC found Caisse Alliance's risk assessment incomplete on geography β€” its branch locations were assessed, but not the risk associated with where its clients themselves reside. The credit union had also introduced new operational and transaction-processing systems supporting onboarding, account management, payment processing and lending, without assessing the money-laundering or terrorist-financing risk those systems introduced or putting mitigation measures in place. FINTRAC further found that a third-party provider's client risk-scoring categories did not generate adequate transactional alerts across all transaction types and client profiles, a limitation FINTRAC linked to missed red flags, including international electronic funds transfers to higher-risk countries. FINTRAC also stated that Caisse Alliance's evolving business model should have triggered a comprehensive update to its risk assessment, and that update was not conducted.

Effectiveness review

FINTRAC found that Caisse Alliance's most recent two-year effectiveness review was incomplete and inadequate: it did not fully assess the effectiveness of the program in either documentation or practical implementation. The review identified certain findings, but did not identify the weaknesses FINTRAC subsequently found, including the gaps in policies and procedures, unusual-transaction analysis, and suspicious-transaction identification and reporting described above.

The Compliance Weaknesses That Repeated Across the Four Cases

Control Area UNI Caisse Alliance Pathwise YNCU
Policies & procedures (documentation and application) βœ“ βœ“ βœ“ βœ“
Risk assessment βœ“ βœ“ βœ“ β€”
High-risk client controls / enhanced measures β€” βœ“ β€” β€”
Ongoing monitoring execution βœ“ βœ“ βœ“ βœ“
STR identification / reporting βœ“ β€” β€” β€”
Alert investigation and documentation βœ“ βœ“ β€” β€”
Transaction monitoring / alert coverage βœ“ βœ“ β€” β€”
Effectiveness review β€” βœ“ β€” β€”

Only findings explicitly supported by the four public notices are marked above.

Five Compliance Lessons From FINTRAC's Four Enforcement Actions

1. Written policies must match actual operations. A documented monitoring frequency, alert-review step, or production-order procedure is only as good as its consistent application. Three of the four institutions in these cases had procedures on paper that were not reliably followed in practice.

2. Risk assessments must evolve with the business. A new operational system, an evolving client mix, or a changing business model each carries its own money-laundering and terrorist-financing risk. A risk assessment that isn't updated alongside these changes stops reflecting the business it's meant to describe.

3. High-risk classifications must change what happens operationally. Assigning a client a high-risk rating only matters if the enhanced review and monitoring requirements attached to that rating are actually performed and evidenced β€” not just documented as a policy.

4. Alert investigation needs documented reasoning. A complete assessment of a transaction or alert β€” including linked-account searches and a documented conclusion β€” is what makes a closed investigation defensible on examination. An undocumented "we looked at it" is difficult to distinguish from not having looked at all.

5. Effectiveness reviews must identify operational weaknesses, not just confirm a program exists. Completing a scheduled review and testing whether the program actually works are different exercises. A review that never samples real files against real policy is unlikely to catch the kind of implementation gaps found across these four cases.

These four enforcement notices should not be read as evidence that FINTRAC is targeting credit unions generally or that the findings represent the wider sector. They show what FINTRAC identified in these four examinations.

What These Penalties Say About FINTRAC Effectiveness Reviews

The PCMLTFA requires every reporting entity's compliance program to include a review β€” conducted at least every two years, by an internal or external party β€” of its policies and procedures, risk assessment, and training, in order to test their effectiveness.

In practice, testing effectiveness means going beyond confirming that a risk assessment, policies, and training exist. It means sampling actual client files and transactions against what the policy requires, checking whether documented monitoring frequencies were followed, and looking for exactly the kind of gap between a written procedure and its application that appears throughout these four notices. A review that stops at confirming presence β€” the risk assessment is on file, the training was delivered β€” has not tested whether the program functions as designed.

What Financial Entities Should Test Now

  • Do documented ongoing-monitoring frequencies match what the compliance team actually performs, file by file?
  • Is there a backlog in customer reviews or transaction-monitoring alerts, and is anyone tracking its size and age?
  • Are high-risk clients receiving the review frequency the institution's own policy commits to β€” not just at file opening, but years later?
  • Does the risk assessment reflect the current client base, current products, and any new operational or transaction-processing systems introduced since it was last updated?
  • Has the transaction-monitoring system itself been risk assessed for its own gaps and blind spots?
  • Can events such as a production order or adverse-media hit change a client's risk rating outside of the automated system?
  • Are investigators documenting why an alert was closed, including the linked-account searches and transaction assessments behind that decision?
  • Are beneficial ownership, principal-business, and business-relationship-purpose records complete at the point ongoing monitoring is actually performed, not just at onboarding?
  • Does the two-year effectiveness review test whether policies were followed in practice, or does it stop at confirming the policies exist?
  • Could management promptly produce evidence showing that previously identified weaknesses were remediated?

How ComplyFactor Can Help

The gap between a documented compliance program and an effective one only shows up when someone actually tests implementation β€” sampling files, checking whether monitoring frequencies were followed, and confirming risk assessments reflect the business as it operates today. That is the function of an independent AML audit, and where remediation is needed, of a properly scoped AML compliance program review.

Frequently Asked Questions

Does a FINTRAC administrative monetary penalty mean the institution committed money laundering?

‍No. An AMP addresses non-compliance with administrative and reporting obligations under the PCMLTFA β€” such as failing to report a suspicious transaction or maintain an adequate risk assessment. It is not a finding that the institution or its clients committed money laundering or terrorist financing, and it is not a criminal proceeding.

Why does the detailed public notice identify four violations for Caisse Alliance when the short news release lists three?

‍FINTRAC's short September 24 news release for Caisse Alliance lists three bullet-point areas of non-compliance. The detailed public notice, which is the controlling source for violation-level findings, identifies four violations β€” the fourth concerns the required two-year effectiveness review. This article relies on the detailed public notice for all violation-level analysis.

Were all four penalties paid and the cases closed?

‍Yes. Each of the four detailed public notices confirms the penalty was paid in full and the case is closed.

ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.