Customer due diligence & AML

FINTRAC Identity Verification Requirements: Methods, Rules and Compliance

FINTRAC identity verification explained: the 5 methods for persons, entity verification, remote onboarding, MSB triggers, records and retention.

On this page
Get Expert Help

Key takeaways

  • FINTRAC identity verification is triggered by specific transactions, records and sector-specific events rather than every first contact.
  • FINTRAC permits five methods for verifying a person's identity and separate methods for verifying entities.
  • Remote identity verification is permitted, but remote photo-ID verification still requires document authentication and person matching.
  • Agents, mandataries, affiliates and other reporting entities can be used in defined circumstances, but responsibility remains with the reporting entity.
  • Verification records should show which permitted method was used, when it was completed and the information relied upon.

FINTRAC identity verification is the process reporting entities use to confirm that a client is who they say they are, by matching information from a document or another information source against what the client provided. It is a legal requirement under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its Regulations, and it applies to every reporting entity sector, from banks to money services businesses (MSBs) to real estate brokers.

Identity verification is not something a business does simply because someone becomes a prospective client. It is triggered by specific events: certain transactions, certain records, and certain thresholds that vary by sector. The method available and the timing both depend on two things: whether the client is a person or an entity, and which regulated activity is actually taking place. This article sets out the five permitted methods for verifying a person, the three methods for verifying an entity, how remote verification works under current FINTRAC guidance, and the specific triggers that apply to MSBs and FMSBs, so a compliance program can point to the correct rule rather than a general impression of what FINTRAC expects.

When Does FINTRAC Require Identity Verification?

Identity verification requirements arise from specific transactions and specific records, not from first contact with a prospective client. A reporting entity does not need to verify identity the moment someone walks in the door or opens a chat window; the obligation attaches once a defined trigger occurs, and that trigger differs by sector. This is why a client identification requirements Canada checklist has to be built around a business's actual regulated activities, not a generic "verify everyone at onboarding" rule.

Transaction and Record-Creation Triggers

Across all reporting entity sectors, verification requirements are tied to events such as large cash or virtual currency transactions, the creation of certain client information records, and sector-specific activities like account opening, funds remittance, or foreign currency exchange above a threshold. A person or entity that never crosses one of these triggers, for example a client who only conducts small transactions, may never need to be formally verified under the Regulations, even though the business still applies its normal risk-based monitoring.

Identity Verification Before a Suspicious Transaction Report

A reporting entity must take reasonable measures to verify the identity of any person or entity that conducts or attempts to conduct a suspicious transaction, regardless of the dollar amount, and this includes transactions that would otherwise be exempt from identification requirements. This obligation exists specifically to support the suspicious transaction report (STR) that follows, not as a separate STR filing process in itself. Two exceptions apply: verification is not required again if the entity already verified the person with no doubts about that information, and it is not required where doing so would tip the person off that an STR is being filed.

The Five FINTRAC Methods for Verifying a Person's Identity

FINTRAC permits five methods for verifying an individual's identity. A reporting entity may use any one of them, and the choice does not need to be the same for every client.

Government-Issued Photo Identification Method

The document must be authentic, valid, and current: issued by a federal, provincial, or territorial government (a foreign government document is acceptable if equivalent to a Canadian one), showing the person's name, a photo, and a unique identifying number that matches the name and appearance of the person being identified. Documents issued by municipal governments are not acceptable under this method, and a provincial health card cannot be used where provincial legislation prohibits it. FINTRAC provides a non-exhaustive list of acceptable documents (Canadian passports, provincial driver's licences and identity cards, permanent resident cards, and select foreign documents such as NEXUS or Global Entry cards).

Required records: the person's name, the date of verification, the document type, the document's unique number, the issuing province or state and country, and the expiry date if the document shows one.

Credit File Method

This method relies on information in a person's credit file, not a credit score, and it is not a credit assessment. The credit file must be valid and current, come from a Canadian credit bureau (foreign credit bureau files are not acceptable), have existed for at least three years, contain information derived from more than one source, and match the person's name, address, and date of birth. The search must be conducted at the time of verification; a client cannot hand over a copy of their own credit file, and a previously obtained file cannot be reused. Equifax Canada and TransUnion Canada are the two Canadian credit bureaus that supply this data, and authorized third-party vendors can also provide access.

Required records: the person's name, the date the credit file was consulted, the name of the credit bureau or vendor, and the person's credit file number.

Dual-Process Method

This method combines any two of three information categories, each confirmed from a different reliable source: name and address; name and date of birth; or name plus confirmation of a deposit account, prepaid payment product account, credit card, or loan account. Both pieces of information must be valid and current, and the two sources must be genuinely independent; the same source cannot supply both categories, and neither the client nor the reporting entity itself can be one of the sources. Acceptable formats include statements, letters, certificates, or forms, whether original, faxed, photocopied, scanned, or provided as an electronic image.

Examples that satisfy this method: a driver's licence image (name and address) combined with a bank statement confirming a deposit account; or a utility bill (name and address) combined with a birth certificate (name and date of birth). A Canadian credit file can serve as one of the two sources, but it must have existed for at least six months when used this way, distinct from the three-year requirement for the standalone credit file method.

Required records: the person's name, the verification date, the names of the two different sources, the type of information referred to, and the account or reference number associated with each source.

Affiliate or Member Method

A reporting entity may rely on identity verification already completed by an affiliate that is itself a reporting entity, a foreign affiliate carrying out similar activities outside Canada, or a financial entity that is a member of the same financial services cooperative or credit union central. The affiliate or member must have used the photo ID, credit file, or dual-process method (or the equivalent methods in force before June 1, 2021), and the reporting entity must confirm that the name, address, and date of birth on file match what the current client has provided. If there is any concern about how the affiliate or member originally verified the person, re-verification is the safer path, since responsibility for correct verification stays with the entity relying on it.

Reliance Method

A reporting entity may rely on identity verification measures already taken by another reporting entity, or by an affiliated foreign entity carrying out similar activities abroad. Relying on an affiliated foreign entity additionally requires being satisfied, after considering the money laundering and terrorist financing risk in that foreign state, that the affiliated entity has policies comparable to Canada's recordkeeping, verification, and compliance program requirements, and that a competent foreign authority supervises its compliance with them.

To use this method, the reporting entity must obtain the confirmed information as soon as feasible, be satisfied it is valid and current, confirm it was obtained through one of the three permitted person-verification methods, and have a written agreement in place with the other party that requires them to provide, on request, everything they referred to when verifying identity.

How FINTRAC Identity Verification Works Remotely

Physical presence is not required to verify identity under current FINTRAC guidance, but a business using the government-issued photo ID method remotely must have a process in place to authenticate the document itself, separately from confirming that it belongs to the person providing it.

In practice, this means two distinct steps. First, authenticity: a reporting entity could ask a client to scan their document with a mobile device and use technology that checks features such as security holograms, barcodes, watermarks, or embedded chips against known characteristics for that document type. Second, matching the person to the document: this could be done through a live video chat comparing the person's face to the photo, or a selfie compared against the ID photo using facial recognition technology, alongside a check that the name matches what the client provided. FINTRAC is explicit that simply viewing a person and their ID over a video call is not, on its own, sufficient; an authentication step is still required. Facial recognition and biometric matching are one accepted way to complete the person-matching step, not a legal mandate; a live video comparison is an equally valid alternative under current guidance.

The two steps, authenticating the document and matching the person to it, do not need to happen at the same time, but a compliance program's written procedures must describe how both are actually done. Receiving a scanned or uploaded image on its own does not satisfy the requirement; without a documented authentication process behind it, an uploaded image is just a picture, not a verification. Credit file and dual-process verification are naturally remote-friendly, since both rely on referring to information rather than physically inspecting a document, which is why many onboarding flows combine dual-process checks with, or instead of, remote photo ID verification.

What Information Must Match?

Each method specifies which identification details must match: name and photo for the photo ID method; name, address, and date of birth for the credit file and affiliate/member methods; and the specific two-category combination chosen under dual-process. FINTRAC's guidance acknowledges that real-world records are not always perfectly clean.

A minor typo in an address, or a small variation in how a name is recorded, can still be treated as matching if the reporting entity reasonably determines it refers to the same person. A discrepancy in date of birth is treated differently; FINTRAC's guidance indicates this is more likely to mean the information does not match, in which case that source cannot be relied on for identification purposes. If a credit file or dual-process source shows multiple addresses and the client's stated address appears as a secondary one, that can still satisfy the requirement. Where information is truncated or redacted, such as a partially hidden account number, it cannot be relied on at all. In any case where the reporting entity concludes the information does not match, or is incomplete, the correct response is to use a different source under the same method, or switch to a different permitted method entirely, not to proceed on an unresolved discrepancy.

Can Expired Identification Be Used for FINTRAC Verification?

No. For the government-issued photo ID method, the document must be current, meaning it must not have been expired at the time it was used to verify identity. An expired driver's licence or passport cannot satisfy this method, full stop.

There is one nuance worth understanding, particularly for businesses relying on an agent or the affiliate/member and reliance methods: what has to remain valid and current going forward is the confirmed identifying information (the person's name and photo, for instance), not the physical document itself. If a document was valid and unexpired at the time it was originally used to verify identity, and the person's name and appearance have not changed, that original verification can still be relied on later even after the document has since expired. What breaks that reliance is a change in the underlying facts, such as a legal name change, not the simple passage of the document's expiry date. Where a client cannot produce a currently valid photo ID at all, the credit file or dual-process methods remain available alternatives, and for retail deposit accounts opened by banks, a specific Bank Act-based accommodation exists for people who face genuine barriers to standard identification, subject to product limitations and a defined follow-up timeline.

Verifying the Identity of Corporations and Other Entities

FINTRAC permits three methods for verifying the identity of a corporation or other entity (a trust, partnership, fund, or unincorporated association or organization). Corporations carry a slightly heavier requirement than other entity types, since directors' names must also be confirmed under the primary method.

Confirmation of Existence

For a corporation, this means referring to a certificate of incorporation, a record filed annually under provincial securities legislation, or the most recent version of another record confirming the corporation's existence, name, address, and directors, such as a certificate of active corporate status or a government notice of assessment. For any other entity, the equivalent is a partnership agreement, articles of association, or the most recent record confirming its existence, name, and address. In both cases, the record must be authentic, valid, and current, and a publicly accessible corporate registry, such as the Corporations Canada database, is an acceptable source.

Reliance Method for Entity Verification

This mirrors the reliance method for persons: an entity's identity can be verified by relying on measures already taken by another reporting entity, or an affiliated foreign entity, provided the same conditions apply, valid and current information, verification originally performed using the confirmation of existence method, and a written agreement requiring the other party to supply the underlying information on request.

Simplified Identification Method

Available only to reporting entities in paragraphs 5(a) to (g) of the Act (banks, trust companies, securities dealers, and similar regulated financial entities, not MSBs), this method deems identity verified, without applying the confirmation of existence method, where the entity is itself a qualifying regulated or public body (such as another reporting entity, a foreign equivalent, a regulated pension fund, a company listed on a recognized stock exchange, or a government-owned institution) and the business's own risk assessment supports a low risk of a money laundering or terrorist financing offence. If that risk assessment later changes and the risk is no longer considered low, the entity's identity must be verified using the confirmation of existence method as soon as feasible.

Identity verification confirms that an entity exists and that the people dealing with it are authorized to do so. It does not identify who ultimately owns or controls that entity. That is a separate obligation covered in ComplyFactor's beneficial ownership guide.

FINTRAC Identity Verification Requirements for MSBs and FMSBs

MSBs and FMSBs face one of the more detailed sets of identity-verification triggers of any reporting entity sector, because so much of their business is transaction-based rather than account-based. The thresholds below are current FINTRAC MSB-specific triggers, expressed in Canadian dollars, and they are lower in several cases than the thresholds that apply to other sectors, so an MSB compliance program built from a generic template will typically under-trigger verification.

FINTRAC Identity Verification Trigger Map for MSBs/FMSBs

Trigger Threshold When to verify
Large cash transaction $10,000 or more (subject to the 24-hour rule) At the time of the transaction
Large virtual currency transaction $10,000 or more equivalent (subject to the 24-hour rule) At the time of the transaction
Suspicious transaction Any amount Before sending the STR (subject to the tipping-off exception)
Issuing/redeeming traveller's cheques, money orders or similar instruments $3,000 or more At the time of the transaction
Transmitting funds by means other than an EFT (e.g. informal value transfer) $1,000 or more At the time of the transaction
Initiating an electronic funds transfer $1,000 or more At the time of the transaction
Foreign currency exchange $3,000 or more At the time of the transaction
Transferring virtual currency $1,000 or more equivalent At the time of the transaction
Exchanging virtual currency (VC-funds, funds-VC, or VC-VC) $1,000 or more equivalent At the time of the transaction
Remitting funds to a beneficiary (non-EFT) $1,000 or more At the time of the transaction
Remitting funds to the beneficiary of an international EFT $1,000 or more At the time of the transaction
Remitting virtual currency to a beneficiary $1,000 or more equivalent At the time of the transaction
Information record β€” crowdfunding platform services Any amount, all client types At the time the record is created
Information record β€” cheque-cashing services Any amount (corporations/entities only) At the time the record is created
Information record β€” ongoing service agreement (EFT, remittance, forex, money order/TC issuance, VC exchange/transfer) Any amount (corporations/entities only) Within 30 days of the record being created
Cashing one or more cheques totalling $3,000 or more At the time of the transaction
Crowdfunding platform donation $1,000 or more (funds or VC) At the time of the donation
Transport services $1,000+ cash/VC, or $3,000+ money orders/TC/negotiable instruments Before the first transport
Private ATM acquirer services N/A β€” status-based (owner/lessee/operator, cash owner, settlement account holder) Before acquirer services are provided

Notable exceptions: verification is not required for large cash or virtual currency transactions received from a financial entity, a public body, or someone acting on their behalf, or for amounts deposited to a business account or an automated banking machine. Transport, crowdfunding donation, and cheque-cashing triggers do not apply where the client is a public body, a very large corporation or trust, or a qualifying consolidated subsidiary. An authorized employee conducting a transaction for their employer under an existing service agreement does not need to be separately verified.

For the broader compliance controls MSBs and remittance businesses need beyond identity verification, see ComplyFactor's currency exchange and remittance MSB compliance guide.

Using an Agent or Mandatary to Verify Identity

Effective October 1, 2025, FINTRAC's guidance formally sets out when a reporting entity can use an agent or mandatary to carry out identity verification on its behalf, a distinct arrangement from the affiliate/member and reliance methods described above. For a person, the agent or mandatary must use the photo ID, credit file, or dual-process method. For a corporation or other entity, they must use the confirmation of existence method. A reporting entity can also rely on verification an agent or mandatary already completed previously, whether they were acting in their own capacity at the time or under a written agreement with another reporting entity.

To use this arrangement, a reporting entity must have a written agreement with the agent or mandatary in place before using them, obtain, as soon as feasible, all the information the agent or mandatary referred to and confirmed, and be satisfied that information is valid and current and was obtained through a permitted method. Responsibility for correct verification stays with the reporting entity even though the agent performed the work; if the agent used an expired document or failed to keep the required records, the reporting entity is still accountable for the gap.

Required records: the person's or entity's name, the written agreement with the agent or mandatary, and everything the agent or mandatary referred to and confirmed when performing the verification, including the specific records that method itself requires.

Do Existing Clients Need to Be Re-Identified?

No, not automatically, and FINTRAC draws a clear line between two separate obligations that are easy to conflate.

Once a person or entity's identity has been verified using a current or previously valid method, and the reporting entity has no doubts about that information, there is no requirement to verify it again for subsequent transactions or activities. Re-verification is only required where genuine doubt arises about the original information, for example where a name has legally changed or the original verification looks unreliable. Separately, as part of ongoing monitoring, a reporting entity must keep client identification information, such as a person's occupation or an entity's principal business, up to date at a frequency set by its own risk assessment. Keeping that information current is not the same thing as re-verifying identity, and a policy that instructs staff to re-run photo ID checks on a fixed schedule with no doubt-based trigger is applying a stricter standard than FINTRAC requires. A business merger or acquisition does not require re-identifying the acquired clients either, provided their identities were originally verified in accordance with the Regulations in force at the time; reviewing and updating their information under the acquiring entity's own risk assessment is a recommended practice, not a mandatory re-verification.

Identity Verification vs Other FINTRAC KYC Controls

Identity Verification vs Beneficial Ownership

Identity verification confirms that a client, person or entity, is who or what they claim to be. Beneficial ownership goes further for corporate and other entity clients, identifying the individuals who ultimately own or control that entity. A corporation can be fully verified under the confirmation of existence method while its beneficial ownership remains entirely undetermined; they are separate obligations with separate evidence requirements. See ComplyFactor's beneficial ownership verification guide for the full requirement.

Identity Verification vs Third-Party Determination

Identity verification establishes who the client is. Third-party determination establishes whether someone else is instructing or benefiting from a specific transaction the verified client is conducting. A fully verified client can still turn out to be conducting a transaction on behalf of an undisclosed third party; verifying their identity does not answer that separate question. See ComplyFactor's FINTRAC third-party determination guide for that workflow.

Identity Verification vs PEP Screening

Confirming a client's identity and determining whether they are a politically exposed person, head of an international organization, or a related family member or close associate are two different compliance controls with different triggers, different evidence, and different risk consequences. A client can be fully and correctly identity-verified and still require a separate PEP/HIO determination at the relevant trigger point.

What Identity Verification Records Must Be Kept?

Record content depends on the method used, not a single universal rule. The requirements for each of the five person-verification methods and three entity-verification methods are set out in the relevant section above, and they differ meaningfully: a credit file number and bureau name for the credit file method; two independent source names and reference numbers for dual-process; a corporate registration number and document source for confirmation of existence sourced from a public database, or the physical record itself if sourced elsewhere.

Two categories of records apply across multiple methods and are easy to overlook. Where verification relies on another party, the affiliate/member method, the reliance method, or an agent/mandatary arrangement, the reporting entity must keep the written agreement or arrangement itself, not just a summary of it, plus everything the other party referred to and confirmed. And where an electronic record is consulted in a publicly accessible database for entity verification, only the registration number, document type, and source need to be recorded; a paper record or an electronic record obtained elsewhere must be kept in full, or a copy of it retained. Retention periods for these records generally follow the same recordkeeping schedule as other FINTRAC client records under a reporting entity's sector-specific recordkeeping guidance; where a specific method's guidance states a different retention trigger, that method-specific rule governs.

Common FINTRAC Identity Verification Mistakes

Treating a scanned or uploaded ID image as automatically verified, with no documented authentication step behind it

Using expired photo identification where the document itself, not just the underlying confirmed information, was already out of date at the time of verification

Skipping the authenticity assessment for remote photo ID verification and relying only on a video call to "see" the document

Combining two pieces of information that both come from the same source, which does not satisfy the dual-process method's independence requirement

Using dual-process sources that are not genuinely reliable, such as social media, or using the client or the reporting entity itself as a source

Failing to retain the specific records each method requires, particularly the written agreement required for affiliate/member, reliance, and agent/mandatary arrangements

Treating beneficial ownership verification as though it were entity identity verification, when they are distinct obligations with distinct evidence

Confusing third-party determination with identity verification, when one confirms who the client is and the other asks who else may be involved in a transaction

Applying outdated or generic transaction thresholds instead of the sector-specific figures that actually apply to the business

Re-verifying every returning client on a fixed schedule with no doubt-based trigger, which goes beyond what FINTRAC requires

Written procedures that describe an ideal onboarding workflow that does not match what staff or systems actually do

These are described as operational weaknesses commonly seen across compliance programs, not as documented FINTRAC enforcement findings; a specific enforcement claim should always be checked against FINTRAC's published penalty decisions before being repeated.

A Practical FINTRAC Identity Verification Workflow

Identify the regulatory trigger: which transaction, record, or activity has just occurred

Determine whether the client is a person or an entity, since the permitted methods differ

Select an allowed verification method appropriate to the client type and the channel (in-person or remote)

Obtain information from valid, current, and genuinely reliable sources

Confirm the required information actually matches what the client provided

Resolve discrepancies: distinguish a minor typo from a substantive mismatch, and switch sources or methods where needed

Record the method used and the specific evidence reviewed, in the format that method requires

Complete related but separate KYC controls (beneficial ownership, third-party determination, PEP/HIO screening) where they also apply

Apply risk-based ongoing monitoring rather than repeat verification on a fixed schedule

Retain the evidence in a format and location that can be produced quickly during a FINTRAC examination

How Identity Verification Fits Into an AML Compliance Program

Identity verification procedures should not exist as a standalone checklist. They need to connect directly to onboarding workflows, so staff know exactly which method applies before a transaction is processed, and to transaction processing systems, so the correct trigger fires automatically rather than depending on manual judgment. The same procedures should feed the broader KYC framework (beneficial ownership, third-party determination, and PEP screening), reference the entity's risk assessment for decisions like the simplified identification method, and be reinforced through staff training that covers the actual methods in use, not generic AML theory. Recordkeeping needs to match what each method specifically requires, and quality assurance testing, along with the entity's periodic effectiveness review, should sample verification files the same way a FINTRAC examiner would. A AML compliance program built around a business's actual client base and transaction types is what connects these pieces into something an examiner can follow from policy to practice.

FINTRAC Identity Verification Checklist

Are all applicable identity-verification triggers mapped to the business's actual regulated activities and thresholds?

Are the permitted person-verification methods (photo ID, credit file, dual-process, affiliate/member, reliance) correctly configured in onboarding systems?

For the photo ID method, is there a documented process to confirm documents are authentic, valid, and current, in person and remotely?

For the dual-process method, are the two sources genuinely independent, with neither the client nor the reporting entity as a source?

Does the remote-verification workflow include both a document-authentication step and a person-to-document matching step?

Are corporate and entity verification methods (confirmation of existence, reliance, simplified identification) clearly separated from beneficial ownership procedures?

Is the specific evidence each method requires being recorded, not just a generic "ID verified" note?

Are exceptions to the re-verification requirement documented, rather than defaulting to periodic blanket re-verification?

Do written agreements exist and are they retained for every affiliate/member, reliance, or agent/mandatary arrangement in use?

Do frontline and compliance staff know which trigger requires verification for each transaction type they process?

Do written procedures match what the onboarding system and staff actually do, not an idealized version of the workflow?

Can a sampled verification file be produced quickly, with all required records intact, during a FINTRAC examination?

Frequently Asked Questions

What are FINTRAC's identity verification requirements?

FINTRAC requires reporting entities to confirm a client's identity by matching information from a document or reliable source against what the client provided, at specific transaction or record-creation triggers set out in sector-specific guidance, using one of the permitted methods for persons or entities.

What are the five FINTRAC identity verification methods?

For a person: the government-issued photo identification method, the credit file method, the dual-process method, the affiliate or member method, and the reliance method. Entities are verified separately, using confirmation of existence, reliance, or (for certain regulated sectors only) the simplified identification method.

Can FINTRAC identity verification be completed online?

Yes. Physical presence is not required, but a business using the photo ID method remotely must have a documented process to authenticate the document and separately confirm the person matches it, such as a live video comparison or a selfie check with facial recognition technology alongside document authentication.

Can expired photo ID be used for FINTRAC verification?

No, the document must be current (unexpired) at the time it is used to verify identity. However, if the confirmed information from a document that was valid at the time remains accurate later, that original verification can still be relied on even after the document itself has since expired.

What is the FINTRAC dual-process method?

It combines any two of three categories, name and address, name and date of birth, or name plus confirmation of a financial account, each confirmed from a different, genuinely independent, reliable source. The same source cannot supply both categories.

When must an MSB verify a customer's identity?

At specific transaction thresholds and record-creation events, including large cash or virtual currency transactions ($10,000+), most electronic funds transfers, foreign exchange, and remittances ($1,000-$3,000 depending on the activity), suspicious transactions regardless of amount, and several other MSB-specific triggers set out in FINTRAC's sector guidance.

Do existing customers need to be re-identified?

Not automatically. Once identity has been verified with no doubts about the information, re-verification is not legally required for subsequent transactions. Keeping client identification information up to date, as part of ongoing monitoring, is a separate and distinct obligation from re-verifying identity.

Is identity verification the same as beneficial ownership verification?

No. Identity verification confirms who or what a client is. Beneficial ownership identifies the individuals who ultimately own or control an entity client. A corporation can be fully identity-verified while its beneficial ownership remains a separate, unresolved requirement.

Can an agent verify a client's identity on behalf of an MSB?

Yes, effective October 1, 2025, an MSB may use an agent or mandatary to carry out verification using the permitted methods, provided a written agreement is in place beforehand and the MSB obtains and is satisfied with the confirmed information. Responsibility for correct verification remains with the MSB.

What identity verification records must be retained?

The specific records required differ by method: for example, a document type and number for photo ID, a credit bureau name and file number for the credit file method, or two source names and reference numbers for dual-process. Where verification relies on another party, the written agreement itself must also be retained.

Keeping FINTRAC Identity Verification Defensible

A defensible identity verification program comes down to matching the right method to the right client type, applying the correct trigger for the business's actual regulated activities, documenting authenticity and matching separately for remote verification, keeping the specific records each method requires, and not confusing identity verification with the related but distinct obligations of beneficial ownership, third-party determination, and PEP screening.

None of this requires guesswork once the triggers and methods are mapped correctly for a specific business model. If your current onboarding workflow cannot demonstrate which method was used and why for a sample of client files, ComplyFactor's Canadian AML advisory team can help map the correct triggers and build a verification process that holds up under FINTRAC examination.

Frequently Asked Questions

No items found.
ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.