Key takeaways
- FINTRAC assesses both design and implementation — a policy manual doesn't prove controls actually work in practice.
- Central document repository matters — FINTRAC document requests should be answered in days, not weeks.
- Client files must show documented reasoning — beneficial ownership determinations, PEP decisions, and risk classifications need written evidence.
- High-risk clients need visible enhanced measures — treatment should differ from low-risk accounts in documented ways.
- Effectiveness review is mandatory — you must be able to produce a documented review within the last two years showing corrective actions completed.
You receive a letter from FINTRAC. It contains a compliance examination notice and a preliminary document request. Your compliance officer has assured you that your AML program is solid. Policies are in place. Training was conducted. Now comes the real test: Can you actually produce the evidence that these controls were implemented and working?
Many businesses discover, in the weeks after receiving the notice, that having a policy manual is not the same as demonstrating that controls were followed. Risk assessments exist, but they're generic. Training happened, but attendance records are scattered across email and spreadsheets. Client files contain identity documents, but not the documented reasoning for PEP determinations. Transaction reports were filed, but the supporting analysis is incomplete or sits in individual investigator notes that are hard to retrieve.
Examination readiness is not about rushing to create documents after the notice arrives. It depends on whether you can immediately produce current policies, documented risk assessments, proof of staff training, complete and accurate client files, timely transaction reports with clear reasoning, records of ongoing monitoring decisions, evidence of corrective actions, and a completed effectiveness review.
What a FINTRAC Compliance Examination Assesses
FINTRAC examines both the design of your compliance program and its actual implementation. A well-designed program on paper, but poorly executed in practice, will be identified as deficient. FINTRAC evaluates:
- Whether your compliance program is reasonably designed to manage risk
- Whether it reflects your business model and risk profile
- Whether it was actually implemented
- Whether it remains effective over time
Design assessment focuses on your documented policies, procedures, risk assessment, governance structure, and authority granted to the compliance function. This is where FINTRAC checks that your program is structured to address money laundering, terrorist financing, and sanctions evasion risk.
Implementation assessment checks whether those documented policies and procedures are actually followed. This is where FINTRAC tests your client files, reviews how transactions were assessed and reported, verifies staff training, and interviews employees about their daily responsibilities. The gap between design and implementation is where many examinations uncover deficiencies.
FINTRAC also assesses whether your program remains current and effective. Compliance programs must evolve as your business changes: new products, new services, expanded geographic reach, new delivery channels, technology upgrades, organizational restructuring. A program designed five years ago for a single office may be inadequate for a multi-branch operation with online services. An effectiveness review—a documented internal assessment of whether your program is working—is part of this standard.
What Happens During a FINTRAC Examination
FINTRAC examinations typically follow a consistent process, though specific timelines and scope vary based on your sector and risk profile:
- Initial communication and scope: FINTRAC contacts you and outlines the examination scope. This may be a general compliance examination, a thematic examination focused on a specific area (sanctions screening, transaction reporting), or a targeted review of a particular business line or risk area.
- Document request: FINTRAC provides a list of documents and records to be produced. This is your first roadmap of what to gather.
- Review of policies and records: FINTRAC's team reviews your compliance documentation, governance structure, risk assessment, and procedures to evaluate program design.
- File or transaction sampling: FINTRAC samples client files, transaction decisions, or reports to test whether procedures were followed and controls were effective.
- Staff interviews: FINTRAC meets with compliance staff, business line managers, or front-line employees to understand how controls operate and to test compliance knowledge.
- Preliminary findings: FINTRAC communicates preliminary observations and may request additional information or explanation.
- Final findings and corrective action: FINTRAC issues a formal examination report detailing findings and expected corrective actions. Your entity responds with a remediation plan.
Documents and Evidence to Prepare Now
Organize your evidence now by category. Completeness and quick retrieval matter.
Compliance Program Governance
Gather the appointment letter or board resolution designating your compliance officer. Document their authority, responsibilities, and reporting line. Include evidence of senior management approval of the compliance program, board or committee oversight structure, and any compliance function budget or resources. If compliance responsibilities are shared across multiple roles, document the division of duties and accountability.
Policies and Procedures
Collect current versions of all compliance procedures, including customer due diligence (CDD), enhanced due diligence (EDD), ongoing monitoring, sanctions screening, transaction reporting, record retention, and employee compliance responsibilities. Document the approval date and any change history. Critically, verify that your written procedures actually match what your staff and systems are doing. A procedure that describes one process but your team follows another creates risk. If procedures have been updated but not consistently implemented, document when the transition occurred.
Risk Assessment and High-Risk Measures
Produce your documented risk assessment covering products, services, customer types, geographic exposure, delivery channels, and emerging technologies. Document how you've rated different risk areas (low, medium, high) and what enhanced measures you've applied to high-risk clients, products, or geographies. For example, if you identify wire transfer services and international clients as higher risk, document what additional scrutiny these receive. Include any PEP or HIO policies and evidence they're applied consistently.
Training Records
Compile training content, attendance records, dates, and roles trained. Document initial training for all relevant staff and annual refresher training. If training is role-specific (tellers receive different training than compliance analysts), document this differentiation. Include evidence that staff new to the organization received training before or shortly after starting. If anyone missed training, document follow-up.
Client Identification and KYC Files
This is often where examinations find gaps. For each client file, ensure you have:
- Identity verification documents (copy of ID, proof of address)
- Documented beneficial ownership determination (who ultimately controls the client)
- Documented decisions on whether the client meets PEP or HIO criteria and why
- Evidence of the business relationship (what services the client uses, stated purpose of the relationship)
- Third-party information to corroborate client information and results
- For corporate clients: documentation of how you verified directors, officers, and owners
Ongoing Monitoring and Transaction Review
Produce records showing how you monitor transactions. For clients flagged through transaction monitoring, document the investigation: what was the alert, why was it generated, what did you investigate, what was your conclusion, and if you escalated for potential reporting, what documentation supported that decision? Include monitoring schedules for high-risk clients. For clients you've classified as high-risk, document evidence that they received enhanced monitoring—more frequent transaction review, additional scrutiny, or documented checking of publicly available information.
Transaction Reporting
Gather copies of all suspicious transaction reports (STRs), terrorism-related reports, and any other filings you've submitted to FINTRAC. Include the submission receipts. For each report, produce the supporting analysis: internal notes, transaction records, decisions about reasonable grounds to suspect, and any escalation documentation. This is where FINTRAC will test whether your reported suspicions were well-founded and whether you understood the threshold for reporting.
Recordkeeping
Document your records retention and retrieval procedures. This includes where you store client files, transaction records, compliance documentation, and audit trails. Demonstrate that records can be retrieved promptly and accurately. Some records may be kept in multiple locations (client files in branch offices, transaction data in central systems, compliance records at head office). Document a clear map of what is stored where and how you can produce it on request.
Two-Year Effectiveness Review
Produce your documented effectiveness review completed within the last two years. This should include:
- The scope of the review (which areas of your program you assessed)
- Who conducted it (internal team or external auditor)
- What testing or sampling you performed
- What findings or gaps you identified
- Management's response and corrective actions
- Evidence that corrective actions were completed
This document demonstrates that you actively assess whether your program is working, not just that it exists on paper.
How FINTRAC Tests Whether Controls Actually Work
During an examination, FINTRAC uses several methods to verify that your controls are actually in place and functioning:
- Sampling client files: FINTRAC selects a sample of your client files and checks whether the required due diligence steps were actually completed and documented. They verify that identity documents are present, beneficial ownership determination was recorded, and business purpose is documented.
- Comparing procedures to actual practice: They compare what your written procedures say should happen against what actually happened in the files and transactions they sample. If your procedure says clients should be re-screened annually against sanctions lists, FINTRAC checks whether this re-screening is documented.
- Reviewing transaction and reporting decisions: FINTRAC examines how specific transactions were assessed and whether reporting decisions were appropriate and well-documented.
- Checking reporting accuracy and timeliness: They verify that STRs you submitted contain accurate information and were filed within appropriate timeframes.
- Interviewing staff: FINTRAC meets with compliance personnel, front-line staff, and management to assess compliance knowledge and whether employees understand their responsibilities.
- Auditing decision trails: They follow the path from initial alert or transaction through to final decision and action. If a transaction was flagged for review, did someone actually review it? What was the decision and why?
- Verifying remediation of previous findings: If FINTRAC or an external auditor previously identified gaps, they verify that your corrective actions were completed.
Common Examination Readiness Gaps
Experienced compliance professionals know these gaps most commonly emerge during examinations:
Policies written for the ideal, not the actual: Your procedures describe a perfect world, but your team has adapted them based on time constraints, system limitations, or business pressures. Document what is actually being done, then align procedures or change practice.
Risk assessment is generic: The risk assessment reads like a template that could apply to any business. It doesn't reflect your specific products, client mix, geography, or delivery channels. A strong risk assessment is specific and documented in language that matches your business.
Missing or incomplete training records: You've trained staff, but records are scattered—some in email, some in spreadsheets, some noted in personnel files. Compile a complete roster with dates and content.
Incomplete beneficial ownership documentation: Client files contain identity documents, but not the documented reasoning for beneficial ownership determinations. If you determined that a corporate client is a small family business with one owner, document how you reached that conclusion.
High-risk clients without enhanced measures: You've identified certain clients as high-risk, but the treatment in your files looks identical to low-risk clients. Enhanced monitoring should be visible: more frequent review, additional documentation, or verification steps.
Transaction reporting decisions without supporting analysis: You've filed STRs, but the reasoning is sparse. FINTRAC will ask why you believed reasonable grounds to suspect existed, and the answer cannot be "we thought it looked suspicious."
Effectiveness review findings not addressed: Your 2024 review identified gaps, but nothing was done. Corrective actions were planned but not completed. This signals that compliance is not a priority.
Documents scattered across systems: Your client files are in a CRM, transaction data in a separate banking system, compliance records in email and shared folders, and effectiveness review on someone's local drive. When FINTRAC makes a request, retrieving everything takes weeks.
Staff confusion about roles: Compliance staff can't clearly explain their responsibilities or authority. There's ambiguity about who approves high-risk clients or escalates suspicious transactions. Roles should be clear and documented.
A Practical 30-Day Internal Readiness Plan
If you have not received an examination notice but want to assess your readiness now, this 30-day framework is a practical starting point. (This is an internal preparation schedule, not an official FINTRAC deadline.)
Days 1–7: Document Inventory and Collection
- List all compliance-related documents, policies, training records, and files
- Determine where they are stored
- Designate one person to coordinate retrieval
- Create a central repository (a shared folder, shared drive, or secure system) where examination-related documents can be consolidated
- Involve IT to ensure you can produce records from all systems in a consistent format
Days 8–14: Sample Testing
- Select a sample of recent client files and review them against your documented procedures
- Are identity documents present? Is beneficial ownership documented? Are clients screened against sanctions lists?
- Select 5–10 transaction or monitoring decisions and follow the trail from alert to decision
- Are decisions documented? Do monitoring notes explain the conclusion?
- Look for gaps between what your procedures say and what the files show
Days 15–21: Correct Priority Gaps and Brief Staff
- Based on sampling, identify the most critical gaps: missing beneficial ownership determinations, incomplete monitoring documentation, training records not compiled, procedures that don't match practice
- Create a prioritized action list. Address the most material items first
- Brief your compliance team and relevant business line managers on the readiness assessment and expected FINTRAC focus areas
- Clarify roles and responsibilities
Days 22–30: Mock Examination and Final Review
- Conduct an internal mock examination: ask your compliance team to produce a sample of documents as if responding to a real FINTRAC request
- How quickly can you retrieve them? Are they complete and accurate? Are labels and references clear?
- Schedule a final management review to discuss readiness, remediation status, and any remaining risks
- Document the outcomes and any follow-up actions beyond the 30 days
When Independent Review or Advisory Support Is Needed
Many organizations benefit from external perspective before facing a formal examination. Two distinct types of support serve different purposes:
An independent AML audit in Canada tests whether your program is actually working and identifies evidence gaps. An external auditor brings no prior knowledge of your institution and can honestly assess whether controls are effective. They sample files, test procedures, and produce a detailed report identifying weaknesses and their severity. This is a realistic assessment of how FINTRAC will view your program.
AML advisory services in Canada helps you correct deficiencies, prepare responses to examination inquiries, and develop remediation plans. Advisory support is often paired with an audit: the audit identifies gaps, and advisory helps you fix them. This combination—external assessment plus corrective support—significantly improves examination outcomes.
Frequently Asked Questions
How much notice does FINTRAC provide before an examination?
Is an effectiveness review the same as a FINTRAC examination?
Can FINTRAC interview employees?
What if requested records are incomplete or lost?
Should a business address gaps after receiving an examination notice?
Final Takeaway
Examination readiness is not a panic response triggered by a FINTRAC letter. It is a discipline of continuous improvement: maintaining current policies, documenting your risk assessment, keeping training records organized, ensuring client files are complete and accurate, documenting transaction and monitoring decisions, and periodically testing whether your program actually works.
The businesses that navigate examinations most effectively are those that have treated compliance as ongoing work, not as an annual checkbox. They know what documents exist, where to find them, and whether they tell a coherent story of deliberate, thoughtful compliance.
If you've been postponing these tasks, the 30-day readiness plan above is a starting point. If you've moved beyond the basics but want expert external validation, an independent audit followed by targeted advisory support will significantly reduce examination risk and improve your program.