Key takeaways
- Required records must be maintained so they can be provided to FINTRAC within 30 days of a request, but that does not mean every examination document carries the same statutory deadline.
- FINTRAC's usual 30–45 day examination-notice window is separate from the 30-day record-producibility standard and from any later 30-day action-plan deadline.
- FINTRAC treats the notification call as the start of the examination, so post-notification corrections do not prove that historical requirements were already met.
- A controlled response should map each request item to a source system and owner, validate source data, preserve version history, use the instructed secure channel, and maintain a production log.
- FINTRAC may request additional material, expand sampling or scope, conduct remote interviews, and issue findings that can lead to follow-up or enforcement action.
FINTRAC has called your compliance officer to notify your business of a compliance examination, and a formal notification letter confirming the details is on its way. Buried inside that letter is a request for information, documents, and records, along with a timeline for producing them. This is a document-production and examination-response playbook: how to read the request correctly, organize what FINTRAC has actually asked for, validate it before you send it, and avoid the mistakes that turn a manageable desk examination into a longer and more difficult one.
Many businesses search for phrases like “FINTRAC desk review,” “how to pass a FINTRAC audit,” or “FINTRAC audit preparation.” FINTRAC's own term for this activity is compliance examination, and where the examination is conducted remotely rather than at your premises, FINTRAC calls it a desk examination. This guide uses that terminology throughout, because getting the vocabulary right also gets the process right: a desk examination is not a lighter version of an on-site visit, and there is no step in it that guarantees a “pass.”
If your business has not yet been contacted and you want to know what documentation you should already have on file, start with our FINTRAC Examination Readiness Checklist, which covers the broader governance, policy, training, and client-file documentation every reporting entity should maintain. This guide picks up from the point FINTRAC has actually made contact and a document request is sitting in your inbox.
What a FINTRAC Desk Examination Is
FINTRAC conducts compliance examinations under its mandate to assess compliance with Parts 1 and 1.1 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its associated Regulations. The PCMLTFA gives FINTRAC the authority to inquire into the business and affairs of any reporting entity covered by the Act, and FINTRAC carries this out through two examination formats.
- On-site examinations, conducted at your place of business.
- Desk examinations, conducted remotely.
You are told which format applies during the notification call and again in the written notification letter. In both formats, you are required to send the requested information, documents, and records to FINTRAC for a preliminary review before the assessment phase begins. For a desk examination, interviews with your compliance officer, employees, and agents are also conducted remotely, by telephone or videoconference.
FINTRAC applies a risk-based approach to decide which businesses it examines and how deeply, drawing on your compliance history, past examination findings, report quality and timing, and information available about your business and sector. Nothing about the desk format changes what is being assessed. FINTRAC uses the same assessment methods, reaches the same categories of findings, and can recommend the same range of outcomes, from no further action through to a Notice of Violation, regardless of whether the examination happens on your premises or remotely.
What Happens When FINTRAC Notifies Your Business
The process opens with a phone call, not a letter. A FINTRAC compliance officer calls the person responsible for implementing your compliance program, commonly your compliance officer, to discuss the upcoming examination's scope and proposed date.
A written notification letter follows, addressed to your compliance officer, confirming where and when the examination will take place. FINTRAC's current assessment manual states that this letter is usually sent 30 to 45 days before the examination date, and that larger businesses may be given more than 45 days given the volume of information and data typically involved.
The letter itself is FINTRAC's formal request for information, documents, and records, and for your assistance throughout the examination. It typically asks you to send your compliance program documents and, where relevant, lists of transactions and records of transactions in advance, so that a portion of the assessment can happen before the examination proper begins. FINTRAC has also been clear that it may come back for additional information or documents later in the process; the initial letter is a substantial request, not necessarily an exhaustive one.
The 30-Day Record Production Rule: What It Actually Means
This is the part of the process most often oversimplified, so it is worth being precise. The Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations require that any record you are legally required to keep be produced within 30 days of a request by an authorized FINTRAC officer. FINTRAC's assessment manual and its sector-specific record-keeping guidance both restate this as a record-keeping standard: your required records must be kept “in such a manner that they can be provided to FINTRAC within 30 days of a request,” and retained for five years, or longer where the PCMLTFA and associated Regulations specify a longer period.
Read that carefully, because it is a standard about how your records are kept, not a one-time courier deadline that starts ticking the moment FINTRAC calls. It is a test FINTRAC can apply at any time, examination or not: could this reporting entity, if asked today, actually produce its required records inside 30 calendar days. An examination is simply one occasion on which that standard gets tested directly.
The requirement attaches to required records specifically: the categories of records the PCMLTFA and its Regulations actually oblige a given reporting entity to keep. Depending on the reporting entity's sector and activities, required records can include account-opening records, large cash and large virtual currency transaction records, records of electronic funds transfers and virtual currency transfers, casino disbursement records, foreign currency and virtual currency exchange transaction tickets, information records, the records required under client identification and know-your-client requirements, and copies of reports submitted to FINTRAC. Which of these actually apply, and what additional sector-specific records also apply, depends on the reporting entity's sector, the services it provides, and the specific PCMLTFA and Regulations requirements attached to those activities; a currency exchange business and a casino, for example, do not carry an identical required-record list.
Not everything FINTRAC asks for in an examination notification letter is a required record in this technical sense. An organizational chart, a description of how your business handles a particular product line, or a list of your active agents is useful and expected material. FINTRAC may also require other relevant information or documents under its examination powers, including through a notice that specifies the time and manner for production; under the PCMLTFA, a person or entity served with such a notice must provide the material in accordance with what the notice actually states. Those requests should be handled according to the instructions and deadlines set out in the applicable notice or examination request, not assumed to be mutually negotiated or open-ended. It is also not accurate to describe every line item in a document request as carrying the identical statutory 30-calendar-day producibility clock that applies to required records. Treat the 30-day rule as the baseline standard your record-keeping systems need to meet at all times, and treat the specific instructions and deadlines in your notification letter and any related notice as the operative dates for that particular examination.
30 Days to Produce Records Is Not the Same as 30–45 Days’ Examination Notice
These two numbers get conflated constantly, and the confusion causes real scheduling mistakes. They are unrelated concepts that happen to share a similar figure.
Do not assume your business automatically has a fixed number of days to respond once the notification call happens. The instructions and dates in your specific notification letter, any related notice, and any dates agreed with your assigned FINTRAC compliance officer are what actually govern your production timeline for that examination.
Why the Notification Call Matters
FINTRAC treats the date of the notification call, not the date the letter arrives, not an interview date, and not the on-site visit date, as the start of the compliance examination process. This single point has two direct consequences that shape everything else in this guide.
- Any reportable financial transaction from the period under review that has not been reported to FINTRAC as of that call date is treated as not having been reported, which can result in a deficiency.
- Any compliance program document, such as your policies and procedures, found to have been created or adjusted after that call date may itself be treated as a deficiency, separate from whatever the document's content says.
In practice, this means your internal examination-response work should begin as soon as the notification call occurs, not when the formal letter later arrives. That said, the notification call marking the start of the examination is not the same thing as a statutory 30-day production clock beginning to run at that moment; it primarily governs how FINTRAC treats late reports and post-notification document changes, as described above. The formal production deadlines for a given examination remain those stated in the applicable notice, request, and your underlying record-keeping requirements.
What FINTRAC May Request in a Desk Examination
The exact request depends on your sector, risk profile, the period under review, and FINTRAC's specific scope decisions, so no single checklist applies to every business. It is more useful to think in terms of categories.
Compliance program documents
Your compliance policies and procedures, your documented risk assessment, training program materials and delivery records, and documentation from your most recent effectiveness review, including evidence that its findings were actioned.
Transaction and reporting materials
This is the category businesses most often get wrong. FINTRAC does not need a list of the reports you already submitted; it already holds those in its own database. What it typically asks for is a list of your underlying large cash, large virtual currency, or electronic funds transfer transactions, pulled directly from your own source systems or the systems your third-party service provider uses, so that FINTRAC can compare that population against what you actually reported and identify any transactions that should have been reported but were not.
Client and know-your-client records
Identity verification evidence, entity information, beneficial ownership records where applicable, and third-party determination records where the activity in question requires them.
Business and operations information
Products and services offered, locations and agents, the systems and workflows behind your compliance program, and general organizational information FINTRAC needs to understand how your business actually operates.
No business should assume it will receive the identical request list as another reporting entity, even a similarly sized one in the same sector. The request in your notification letter, and any related notice, is the one that governs; a generic industry checklist is a starting point for anticipation, not a substitute for reading the letter literally.
Build a Request-to-Record Matrix Before Producing Anything
Before anyone touches a source system, break the notification letter down into a working tracking document. This is a practical project-management tool your team builds for internal use, not a FINTRAC-prescribed template, and it is one of the more useful habits a compliance function can build regardless of whether an examination is underway.
A matrix like this does two things at once: it stops your team from responding to a paraphrased version of the request instead of the actual wording, and it gives you a single source of truth you can hand internally to whoever is coordinating the response, rather than relying on email threads.
Step-by-Step: How to Respond to a FINTRAC Document Request
Step 1 — Read the request literally
Separate the letter into individual, discrete items before assigning any work. Do not respond based on what your team assumes FINTRAC probably wants; respond to the words actually on the page. If a request is genuinely ambiguous, ask your assigned FINTRAC compliance officer for clarification rather than guessing.
Step 2 — Confirm scope and period
Identify internally, as a scoping exercise rather than a formal legal step, exactly which entities, business lines, branches, agents, products, and transaction types the stated review period covers. This internal scoping keeps your retrieval work focused and prevents both under-inclusion and unnecessary over-production.
Step 3 — Assign internal owners
Assign a named, accountable person to each item in your request-to-record matrix. Depending on your organization, this may span compliance, operations, IT or data, finance, agent management, senior management, and any external vendors who hold relevant data on your behalf.
Step 4 — Retrieve from source systems
Pull data directly from the system of record rather than rebuilding it manually in a spreadsheet, wherever a system export exists. Manually reconstructed data is harder to defend, harder to reproduce if FINTRAC asks a follow-up question, and more prone to the kind of gaps FINTRAC's assessment methodology is specifically designed to surface.
Step 5 — Validate completeness
Before anything leaves your building, check the date range, the transaction population, missing fields, duplicate entries, branch and agent coverage, currencies, reporting status, client identifiers, and the export logic used to generate the file. Tie each check to what was actually requested rather than running a generic data-quality pass.
Step 6 — Reconcile related records
Where relevant, reconcile transaction data against the client or KYC record it relates to, and against the required FINTRAC report and any internal decision record connected to it. This does not mean every transaction generates every possible record; it means checking that the chain a given transaction should produce is actually intact where FINTRAC's request calls for that connection.
Step 7 — Document genuine gaps
If a record genuinely cannot be produced, do not fabricate a substitute or quietly recreate it. Record what is missing, why, where it should have existed, what searches were performed to locate it, and what corrective action may be needed. Where this points to a compliance failure that was not previously identified, see the section below on discovering non-compliance after notification.
Step 8 — Package files logically
Use clear file names, folders, and a mapping back to FINTRAC's own request numbers. Include a short data dictionary for anything unusual, and keep version and date information visible so it is obvious which extract is current. FINTRAC does not mandate a specific naming convention; the goal is that an examiner unfamiliar with your systems can navigate the production without needing to ask basic orientation questions.
Step 9 — Submit through the instructed secure channel
Given the sensitivity of client and transaction data, FINTRAC encourages electronic submission through a secure digital mailbox service that uses encryption suited to transmitting sensitive information, and it asks businesses that want to use this option to contact FINTRAC for the current process. Confirm the mechanics with FINTRAC before submitting rather than assuming them from a past examination. Do not send sensitive client or transaction records by ordinary email unless FINTRAC has specifically instructed you to do so.
Step 10 — Maintain a production log
Track what was requested, what was submitted, the submission date, the version, the method used, the person responsible, any follow-up requests received, and anything still outstanding. Like the request-to-record matrix, this is a practical internal control, not a FINTRAC-prescribed record, but it is the single most useful artifact if a later question arises about what was or was not produced.
How to Validate Transaction Data Before Submission
Data exports are where most avoidable production problems originate. Before sending a transaction export to FINTRAC, verify each of the following against the actual wording of the request, rather than assuming every field listed here applies to your situation:
- The date window matches the stated review period exactly, including time-zone handling at the boundaries.
- All relevant branches, agents, and channels are included, not just your primary system of record.
- Each transaction carries a unique identifier consistent across your source system and the export.
- Timestamps and time zones are recorded consistently.
- Amount, currency, and (where applicable) sender or recipient identifiers are populated.
- Product or channel and transaction status fields, including cancelled or reversed transactions, are captured rather than silently excluded.
- The export's totals reconcile against your source system's own totals for the same period.
- The filters used to generate the export are documented, so you can explain exactly what population the file represents.
The objective is not to satisfy a universal FINTRAC field list, because FINTRAC does not publish one that applies identically to every sector. The objective is narrower and more testable: does this export faithfully and completely answer the specific question FINTRAC actually asked.
Multiple Branches, Agents and External Vendors: Where Production Breaks Down
Where a business has multiple locations, FINTRAC's current assessment manual states that it typically asks for information, documents, and records from all locations to be made available for review at the location selected for the examination. This is a frequent point of failure for MSBs and other businesses with distributed operations, because branches and agents often maintain records on separate systems, in separate formats, or under separate retention practices.
Where agents are involved, FINTRAC's assessment methodology specifically contemplates asking a business for a list of its agents, copies of agency agreements, and a list of the transactions each agent has conducted, in order to confirm that reportable transactions handled by agents were actually submitted. A reporting entity remains responsible for its agents' reporting; that responsibility is not something an agency arrangement can shift away.
FINTRAC's record-keeping guidance for money services businesses and foreign money services businesses is direct on the vendor and contractor question. Employees who keep records on the business's behalf are not required to keep them after their employment ends, and the same is true for a contractor once the contractual relationship ends. The obligation runs the other way: the reporting entity must obtain and keep the records that were held for it by an employee or contractor before that employment or contract ends. In practice, this means offboarding a compliance-adjacent vendor, such as an outsourced KYC provider or a transaction-monitoring service, or terminating an agent relationship, should trigger a records-retrieval step, not just a service cancellation. FINTRAC publishes equivalent record-keeping guidance for other reporting-entity sectors; confirm the specific wording that applies to your own sector before relying on this point in a live examination.
What Not to Rewrite After the Examination Starts
Because FINTRAC treats the notification call as the start of the examination, the period after that call is not an opportunity to quietly tidy up your compliance history. Specifically, avoid:
- Rewriting or backdating policies and procedures so they appear to have been current earlier than they actually were.
- Filing missing FINTRAC reports without informing FINTRAC that they relate to a gap identified after notification.
- Quietly recreating client identification or transaction records that should already have existed.
- Adjusting a risk assessment to look more current than it actually was on the notification date.
- Replacing outdated documents with new versions without disclosing that a replacement occurred.
FINTRAC's own guidance is direct on this point: it will generally not accept documents, records, or financial transaction reports created or corrected after the examination has started as evidence that a requirement was already being met during the period under review. Treating the post-notification period as a cleanup window does not remove a deficiency; it typically compounds it, because the timing itself becomes part of what FINTRAC assesses.
None of this means a genuine problem cannot or should not be fixed once it is found. It means fixing it now is not the same thing as proving the requirement was already being met throughout the period FINTRAC is reviewing, and the two should not be conflated in how you describe the correction to FINTRAC.
What to Do If You Discover Non-Compliance After Notification
Discovering a gap while assembling a production is common, and it is not, by itself, a reason to panic or to conceal the finding. FINTRAC's guidance is that if you identify non-compliance after an examination has started, you should inform your FINTRAC officer immediately and submit a voluntary self-declaration of non-compliance.
The distinction that matters here is timing. A voluntary self-declaration made before FINTRAC has started an examination is handled by FINTRAC working with the business to resolve the issue outside the examination context. A self-declaration made after the examination has started is treated differently: FINTRAC will assess the non-compliance as part of the examination itself, work with the business to correct it, and determine whether the non-compliance warrants an enforcement action. A self-declaration during an active examination is not a way to avoid the examination assessing that gap; it is the correct and expected way to disclose it once it has been found. This is a factual description of FINTRAC's process, not legal advice, and a business facing a significant gap discovered mid-examination should weigh that decision with its own legal or compliance counsel.
What Happens During FINTRAC Desk-Examination Interviews
FINTRAC may interview your compliance officer, employees, and agents as part of the assessment phase. For a desk examination, these interviews are conducted remotely, by telephone or videoconference, rather than in person.
FINTRAC has been explicit that it does not expect interviewees to memorize policies, procedures, or other documents word for word. Its stated goal is narrower: confirming that your employees and agents are aware of the requirements that apply to their specific duties, and that they know how to seek clarification when they are uncertain. The practical implication for preparation is straightforward. Staff should understand how their part of the process actually works day to day, be comfortable saying they are not sure and would check with the compliance officer, and describe real practice rather than reciting a script. None of this is an invitation to coach staff toward rehearsed or misleading answers; the value of an interview to FINTRAC, and the credibility of your compliance program generally, depends on the answers reflecting how the business actually operates.
When FINTRAC Requests More Records or Expands the Scope
FINTRAC's process typically begins with a preliminary assessment of the requirements inside the initial scope: reviewing your documents, conducting preliminary interviews, and reviewing a sample of your transaction records and financial transaction reports. Where that preliminary work identifies areas needing more attention, FINTRAC may sample additional client records, transaction records, or reports, and may conduct follow-up interviews. This can lead FINTRAC to broaden the scope of the examination beyond what the original notification letter described.
If the scope changes, FINTRAC will notify you. There is no fixed formula for how much sampling FINTRAC will use or how far scope can expand; it depends on what the preliminary review actually finds, consistent with FINTRAC's risk-based approach to examinations generally. A request for additional material after your initial production is a normal part of the process, not necessarily a sign that something has gone wrong.
What Happens at the Exit Meeting
Once FINTRAC has concluded the desk examination, or reached the point where it is ready to move to conclusions even if some review continues afterward, it holds an exit meeting, typically by telephone or videoconference for a desk examination, to discuss its preliminary findings with you. These preliminary findings are presented as deficiencies, and each deficiency corresponds to a violation of a specific provision of the PCMLTFA or its associated Regulations.
At the exit meeting, you may offer additional information to help clarify a deficiency, and FINTRAC will agree with you on a timeline for providing that material. After reviewing what you provide, FINTRAC may maintain the original deficiency as stated, modify it, or withdraw it. This is the point in the process where clarifying information genuinely can change the outcome, which is another reason accurate, well-organized production earlier in the process matters: it gives you a stronger evidentiary position to draw on if a deficiency needs to be clarified or contested at this stage.
The Other 30-Day Deadline: Post-Examination Action Plans
After the exit meeting, FINTRAC may send an examination findings letter to your compliance officer describing the findings discussed at the exit interview, along with the documents, client records, transaction records, and financial transaction reports it examined, the results of its interviews, and, where applicable, the number of items sampled and the number of instances of non-compliance found. Individual deficient records or reports are listed in an annex. The letter may also note “observations” that are not deficiencies but that FINTRAC believes could strengthen your program; observations can evolve into deficiencies in a future examination if the same pattern recurs.
The letter states one of several possible outcomes: no further compliance or enforcement action, possible follow-up compliance action, a recommendation for an enforcement action such as an administrative monetary penalty, or a Notice of Violation. In some cases, FINTRAC will ask for an action plan describing how and when you will address the causes of the identified deficiencies. Where FINTRAC does request an action plan, it must be sent within 30 calendar days of receipt of the findings letter, unless FINTRAC specifies otherwise.
This is a genuinely separate 30-day concept from the record-production standard discussed earlier in this guide, and the two should never be treated as the same deadline.
Whether or not an action plan is requested, FINTRAC still expects the underlying causes of a deficiency to be addressed within a reasonable time. Where a Notice of Violation is issued, our guide to responding to a FINTRAC Notice of Violation covers that specific process, and our overview of FINTRAC administrative monetary penalties explains how penalty amounts are assessed. Where a prescribed violation triggers a mandatory compliance agreement, see our explanation of FINTRAC mandatory compliance agreements.
Common FINTRAC Record-Production Failures to Avoid
None of the items below is automatically a violation on its own. Some are operational mistakes that simply slow an examination down; others can point to, or create, an underlying regulatory deficiency. Treat the distinction as something to assess case by case rather than assuming every production error is minor.
- An incomplete date range that excludes part of the stated review period.
- Missing branch or agent data because an export only pulled from the head-office system.
- An inconsistent transaction population, where the export logic quietly excludes a category of transaction FINTRAC actually asked about.
- Export filters applied incorrectly, so the file answers a narrower question than the one FINTRAC asked.
- Missing client identifiers that make it difficult to connect a transaction record back to a client file.
- Policy documents submitted without clear version and date information, making it unclear which version applied during the review period.
- Records that turn out to be held only by a former contractor or vendor, discovered too late in the process.
- Manually reconstructed data submitted in place of a genuine source-system export, without disclosing that it was reconstructed.
- Sending the wrong file version because version control broke down between drafting and submission.
- No production log, so the business itself cannot say with confidence what has and has not been sent.
- Mistakes in secure transmission, such as sending sensitive material through an unconfirmed or unauthorized channel.
- Failing to explain a genuine data limitation, rather than simply submitting an incomplete file with no context.
How ComplyFactor Can Support FINTRAC Examination Readiness
Responding well to a FINTRAC desk examination is largely a project-management and evidentiary exercise: reading the request accurately, retrieving the right records from the right systems, validating them, and presenting them in a way that lets FINTRAC do its assessment efficiently. ComplyFactor supports Canadian MSBs, FMSBs, and other FINTRAC reporting entities with examination readiness, document-request mapping, AML program review, transaction and data testing, remediation planning, and independent effectiveness reviews where a business wants an outside perspective before FINTRAC provides one. ComplyFactor does not represent clients legally before FINTRAC, cannot guarantee an examination outcome, does not control FINTRAC's findings, and cannot retroactively cure a compliance gap once an examination has already started; what a well-organized response can do is give FINTRAC an accurate, complete, and defensible picture of your program, which is the most a business can control once notification arrives.
Frequently Asked Questions
What if our source system cannot export data in the requested format?
Raise it with your assigned FINTRAC compliance officer rather than working around it silently. Explain the limitation, and where a system-generated list genuinely is not possible, FINTRAC's own assessment methodology already anticipates providing the underlying records instead, such as transaction tickets or receipts. What matters is that the limitation is disclosed and explained, not that you quietly transform or reconstruct data without saying so.
Should we send extra documents FINTRAC did not request?
Generally, respond to what was actually asked, checked against your request-to-record matrix. Provide additional context only where it genuinely helps answer a specific request, and label it clearly as explanatory material rather than folding it into requested files. Sending a large volume of unrelated documentation does not automatically broaden FINTRAC's scope, but it does add to what FINTRAC has to sort through, and can occasionally invite scrutiny of material you were never actually asked to produce.
Can we ask FINTRAC to clarify an ambiguous document request?
Yes. If a specific item in the notification letter is genuinely unclear, ask your assigned FINTRAC compliance officer rather than guessing at what was meant. Clarifying a request is a normal part of the process, not a concession, and it produces a more accurate response than working from an assumption FINTRAC never confirmed. It does not mean FINTRAC will rewrite or narrow the request; it means you understand it correctly before spending time responding to the wrong thing.
Should one person coordinate the entire examination production internally?
It helps considerably, as a matter of internal governance rather than any FINTRAC requirement. A single production lead who owns the request-to-record matrix and the production log, even where individual departments retrieve and validate their own items, keeps the response consistent and avoids the same request being answered twice, differently, by two teams. FINTRAC does not mandate this structure; it is a practical control most businesses find worth adopting for the duration of an examination.
What if two internal systems produce different transaction totals?
Reconcile the discrepancy rather than submitting whichever total looks more favourable. Check date ranges and time-zone handling, transaction status and reversals, duplicate entries, and whether both systems cover the same branches and agents, and confirm the export filters used in each system are actually comparable. If the discrepancy cannot be fully resolved before the deadline, document what you found, explain the likely cause, and disclose the difference to your assigned FINTRAC compliance officer rather than presenting one figure as though no discrepancy exists.
Can we correct a file after it has already been submitted to FINTRAC?
Contact your assigned FINTRAC compliance officer, explain what was wrong with the original submission, and provide a clearly identified corrected version rather than silently replacing the earlier file. Maintain your own version history so it is obvious internally, and to FINTRAC if asked, which version is current and why it changed. FINTRAC has not published a standalone formal correction procedure for examination production files the way it has for report corrections; treat this as a communication and version-control discipline rather than a prescribed process.
What if FINTRAC asks for a record our business believes it was not legally required to keep?
Do not simply decline to produce it based on your own internal assessment of what the PCMLTFA and its Regulations require. FINTRAC's examination powers extend to relevant information and documents beyond the narrow category of required records, so a request can be legitimate even where the item is not, in your view, a statutorily required record. Raise the disagreement with your assigned FINTRAC compliance officer and ask for clarification of the basis for the request. Where a genuine and significant dispute over a legal obligation remains, that is a question for your own legal counsel, not something to resolve unilaterally by withholding production.
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need — free, no obligation, 30 minutes.
