Key takeaways
- For prescribed violations under the post-March 26, 2026 framework, FINTRAC must require a compliance agreement after the violation proceedings have ended.
- The agreement must identify the prescribed violation and provision, set out the corrective measures required, and include a remediation deadline.
- The six-month period for entering the agreement is separate from the deadline for completing remediation; FINTRAC may extend the remediation deadline by up to one year if the statutory conditions are met.
- Refusing to enter the agreement, or failing to comply by its deadline, leads to a compliance order that FINTRAC must make public and that requires the entity to publicize its remediation measures.
- Breaching a compliance order is a separate compliance order violation, with statutory maximums of the greater of $5 million or 3% of gross global income for a person and $30 million or 3% of gross global revenue for an entity.
- The former pre-March 26, 2026 regime was different: FINTRAC could offer a compliance agreement with a 50% penalty reduction; the current mandatory-agreement framework does not contain that same reduction mechanism.
If FINTRAC has found that your business committed a prescribed violation under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), you will be required to enter into a compliance agreement. As of the current Part 4.1 framework, this is not something your business proposes as an alternative to paying a penalty β it is something the Financial Transactions and Reports Analysis Centre of Canada (the Centre) must require, once the violation proceedings themselves have ended.
This article explains how that mandatory process actually works under sections 73.16 to 73.18 of the PCMLTFA: when the agreement is triggered, what it must contain, the deadlines that apply to entering it versus completing it, and what happens if a reporting entity refuses or falls short. It also sets out what a compliance team should do operationally once an agreement is required, and how the current regime differs from what older material β including some earlier FINTRAC-focused guides β describes.
For the broader administrative monetary penalty (AMP) framework, including violation classifications and penalty calculation, see ComplyFactor's guide to FINTRAC administrative monetary penalties. This article covers what happens after a prescribed violation is established, not the penalty framework itself.
What Changed in FINTRAC's Compliance Agreement Regime
Before the amendments introduced by the Strengthening Canada's Immigration System and Borders Act (Bill C-12) took effect on March 26, 2026, a compliance agreement was something FINTRAC itself offered, built into the notice of violation. Under the former section 73.13(2)(b), FINTRAC could issue a notice of violation with an offer to reduce the proposed penalty by half if the entity entered into a compliance agreement covering the provision the violation related to. The former section 73.16(1) then required that agreement to set out the violation, the period for coming into compliance, and the reduced penalty amount. The entity had 10 days from receiving the notice of violation to both enter into the agreement and pay the reduced penalty; missing that window meant a deemed refusal, after which the full proposed penalty applied. If the entity entered the agreement but later failed to meet its terms, FINTRAC could issue a notice of default making the entity liable for the remainder of the original penalty plus a prescribed additional amount β there was no separate "compliance order" concept under the former regime.
The current Part 4.1 text changes this in two respects: who initiates the agreement, and whether entering one is optional. Under section 73.16(1):
If a person or entity has committed a prescribed violation, then as soon as feasible after proceedings with respect to that prescribed violation are ended, the Centre shall require the person or entity to enter into a compliance agreement with the Centre.
The word "shall" matters here, and so does the sequencing: the agreement now follows the conclusion of the notice-of-violation proceedings, rather than being offered as an alternative path within them. The Act does not attempt to catalogue every event that ends those proceedings. It does say expressly that payment of the proposed penalty has that effect (section 73.15(1)). Other outcomes β a deemed violation for non-response, or a decision following representations to the Director β engage their own provisions, and whether proceedings are "ended" for the purpose of section 73.16(1) in a given case, particularly where review or appeal rights may still be open, should be assessed against those provisions rather than assumed from a general rule.
When a Compliance Agreement Becomes Mandatory
A "prescribed violation" is a contravention designated as such under section 73.1(1)(a) and carries an AMP determined under sections 73.1 and 73.11. The compliance-agreement requirement is tied specifically to this category, not to every finding FINTRAC makes during an examination. A finding that does not rise to a confirmed prescribed violation β for example, an observation addressed through follow-up assessment or voluntary corrective action β does not on its own trigger section 73.16.
Once a prescribed violation has been established and the notice-of-violation proceedings under section 73.15 have ended, the sequence becomes automatic on FINTRAC's side: the Centre must require the entity to enter into a compliance agreement "as soon as feasible" afterward. There is no separate application process for the entity to request one, and no equivalent process for the entity to decline consideration before FINTRAC issues the requirement.
What a Compliance Agreement Must Contain
Section 73.16(2) sets a statutory floor for the agreement's content. It must identify:
- the prescribed violation, and
- the provision of the Act or Regulations to which it relates.
In addition to any other terms the parties agree to, it must include:
- the measures the entity must take to comply with the provision, and
- the deadline for complying with the agreement.
The measures themselves are not standardized by the Act. What FINTRAC requires will depend on the nature of the underlying violation β a gap in identity verification controls, an incomplete risk assessment, missed suspicious transaction reporting, or another prescribed violation category. The agreement is the document that turns FINTRAC's finding into a specific, deadline-bound remediation obligation.
The Six-Month Rule: Entering the Agreement vs Completing the Remediation
This is the point where the two timelines in a compliance agreement are easiest to confuse, and the Act treats them as genuinely separate.
Timeline one β entering the agreement. Section 73.16(4) provides that unless the entity enters into a compliance agreement within six months after the Centre requires it, or within any other longer period the Centre allows, the entity is deemed to have refused to enter into the agreement. This clock measures whether the entity signs the agreement at all.
Timeline two β completing the remediation. Once the agreement exists, it carries its own deadline under section 73.16(2)(b) β the date by which the specific remedial measures must actually be completed. This is a separate, negotiated date set out inside the agreement itself, not the six-month entry window.
An entity that signs a compliance agreement within the six-month window has satisfied timeline one. Whether it has satisfied timeline two depends entirely on whether it completes the measures the agreement specifies, by the deadline the agreement specifies. Missing the remediation deadline inside a signed agreement is treated the same way, procedurally, as never signing at all: both lead to a compliance order under section 73.17(1).
Can FINTRAC Extend the Compliance Deadline?
Yes, but only within defined limits. Section 73.16(3) allows the Centre to amend the agreement by extending the section 73.16(2)(b) deadline by a maximum of one year, and only if the Centre is satisfied that the entity is making substantial progress toward the agreement's terms, such that an extension would encourage compliance with the Act.
Two things follow from this wording. First, the extension is discretionary β the Centre "may" grant it, not "shall." Second, it is conditional on demonstrated progress, not simply requested because a deadline is approaching. An entity that has made little visible progress on its remedial measures has a materially weaker basis for requesting an extension than one that can show substantive, documented work already completed.
What to Do When FINTRAC Requires a Compliance Agreement
Once the requirement is served, treat it as the start of a formal remediation project, not a document-signing exercise. A reasonable operational sequence:
- Confirm the prescribed violation and the exact provision it relates to. The agreement should name both precisely; do not assume you understand the scope from the earlier Notice of Violation alone.
- Map every required remedial measure to a specific, testable action. Vague commitments ("update the policy") should be broken into concrete steps with an owner and a target date.
- Separate legal-response questions from compliance-implementation work. Matters involving legal rights, disputed statutory interpretation, or formal representations to FINTRAC may warrant legal counsel; building and evidencing the actual remediation is compliance-implementation work.
- Assign a single accountable owner for the agreement as a whole, distinct from whoever owns individual measures.
- Identify dependencies β a system change that a vendor must implement, a policy revision that requires board or senior-management sign-off, a training rollout that depends on the revised policy being finalized first.
- Build a remediation tracker that ties each measure to the agreement's deadline, not just to an internal project timeline.
- Identify what evidence each measure will need before you start the work, not after.
- Establish management oversight with a defined reporting cadence, not a single check-in at the end.
- Track progress against the agreement deadline continuously, not just before it arrives.
- Escalate early if completion risk emerges. A realistic conversation with FINTRAC about an extension request, supported by evidence of substantial progress, is a materially stronger position than raising the issue after the deadline has passed.
This sequence reflects practical compliance-program management, not a workflow FINTRAC itself prescribes.
Remediation Tracker: What to Include
A working tracker for a compliance agreement should typically capture, for each remedial measure:
- the prescribed violation and the specific provision it relates to
- the exact agreement requirement, in the agreement's own wording
- the root cause identified for the gap
- the corrective action taken
- the control or policy owner responsible
- key milestones toward completion
- the agreement's compliance deadline (and any FINTRAC-approved extension)
- current implementation status
- the evidence collected to date
- any outstanding dependency
- the point of management sign-off
- any unresolved issue still open
This is a practical management tool for the reporting entity, not a FINTRAC-issued template. FINTRAC has not published a standard format for tracking remediation under a compliance agreement.
What Evidence Should Support Each Corrective Measure?
Completing a remedial measure and being able to demonstrate that it was implemented are different operational questions. Depending on what the specific measure requires, useful evidence can include:
- the revised policy or procedure itself, dated and version-controlled
- the approval record for that revision
- an updated risk assessment, where the gap touched risk-rating logic
- training records showing completion, not just scheduling
- evidence of transaction-monitoring or system configuration changes
- a documented escalation workflow where one was missing
- records of management review and sign-off
- results of any internal testing performed on the fix
- an issue-tracker entry showing the item closed with supporting detail
Not every category applies to every measure, and FINTRAC does not universally require each item listed above. The evidence needed should be tied directly to what the specific compliance agreement actually requires, not applied as a generic checklist.
Governance: Managing the Agreement as a Formal Workstream
A compliance agreement is an enforcement instrument with a statutory deadline attached, and it warrants governance proportionate to that. Depending on the size and structure of the business, this typically involves the compliance officer or MLRO as the operational lead, senior management oversight of overall progress, board or committee visibility where the entity's governance structure calls for it, and coordination with operations, IT, or vendors where a measure depends on system or process change outside the compliance function itself. Where the underlying facts involve a genuine legal question β an appeal, a dispute over the facts FINTRAC relied on, or the terms of the agreement itself β involving legal counsel directly may be warranted. Nothing in the Act requires a specific governance structure for managing a compliance agreement; the requirement is to meet its terms, and how an entity organizes itself to do that is a matter of its own operating model.
What Happens If You Refuse or Miss the Agreement Deadline
Two distinct triggers lead to the same next step. Under section 73.17(1), if a person or entity refuses to enter into a compliance agreement β including a deemed refusal after the six-month window in section 73.16(4) β or enters into one and fails to comply with it before the section 73.16(2)(b) deadline, the Director of the Centre must, as soon as feasible after the refusal or the missed deadline, make a compliance order and cause it to be served.
As with the agreement requirement itself, this is not framed as discretionary once the statutory conditions are met. Refusal or a missed deadline leads to a compliance order; there is no intermediate step in the current text.
When FINTRAC Must Issue a Compliance Order
A compliance order under section 73.17(2) must identify the entity, the prescribed violation, and the relevant provision, and must specify whether the trigger was a refusal to enter the agreement or a failure to comply with one. It must also include:
- a requirement that the entity comply with the underlying provision;
- a requirement that the entity make public the measures it has taken, or will take, to comply with the provision; and
- a deadline for complying with the order.
The Director may include reasons for making the order, including the relevant facts, analysis, and considerations behind the decision (section 73.17(3)). As with the compliance agreement, the order's own deadline can be extended by the Director by a maximum of one year, under the same substantial-progress standard that applies to agreement extensions (section 73.17(5)) β again discretionary, not automatic.
Why a Compliance Order Creates a Public-Disclosure Risk
A compliance order carries a disclosure dimension that a compliance agreement, on the current statutory text, does not clearly share. Under section 73.17(4), the Director must make the compliance order itself public as soon as feasible after making it. Separately, the order's own required terms include the section 73.17(2)(b) requirement that the entity itself make public the measures it has taken or will take to comply.
These are two distinct obligations sitting inside the same order: FINTRAC publishing that the order exists, and the entity separately publishing its own remediation measures under the order's terms. Neither should be confused with FINTRAC's broader publication duty under section 73.22, which applies to a deemed violation or a Notice of Decision confirming a violation and covers the violation's nature, the entity's name, and the penalty amount.
Whether entering into a compliance agreement itself β as distinct from a compliance order β triggers a separate publication obligation is not established in the current text of section 73.22 as it stands, which does not list agreement entry among its publication triggers. This is worth confirming directly against FINTRAC's finalized AMP policy once published, rather than assumed either way.
Compliance Order Violation: The Major Escalation Point
Contravening a compliance order made under section 73.17 is itself a distinct violation β a compliance order violation β under section 73.18(1). This is a different, and considerably more serious, exposure category than the prescribed violation that started the process.
Under section 73.18(2), the penalty for a compliance order violation must not exceed:
- for a person, the greater of $5,000,000 or 3% of the person's gross global income in the year before the penalty is imposed; and
- for an entity, the greater of $30,000,000 or 3% of the entity's gross global revenue in its financial year before the penalty is imposed.
Where an entity is part of an affiliated group, section 73.18(3) deems the entity's gross global revenue, for this purpose, to be the group's combined gross global revenue for the relevant financial year β a meaningful consideration for reporting entities operating inside a larger corporate structure.
These are statutory maximums, not predictions of what any specific matter will be penalized at. The penalty is still determined under section 73.11's criteria: the non-punitive purpose of the AMP regime, the harm done, and the entity's ability to pay. A statutory ceiling of $30 million does not mean a $30 million penalty is the expected or typical outcome of a compliance order violation; it defines the outer limit the Centre cannot exceed.
Old vs New: FINTRAC Compliance Agreement Rules
Older material describing a compliance agreement as something FINTRAC offers alongside a notice of violation, in exchange for a reduced penalty, reflects the pre-March-26-2026 model accurately for violations that occurred before that date. Applied to a prescribed violation occurring on or after March 26, 2026, that description no longer matches the statute: the agreement is now a mandatory step that follows the violation proceedings, not an offer made within them, and no equivalent penalty reduction is provided for.
Transitional Application: Which Regime Applies
The new Part 4.1 provisions do not reach back to conduct that predates them. FINTRAC's own published guidance on the transition states that it will continue to use the existing AMP policy, penalty amounts, and processes for violations that occurred entirely before March 26, 2026, and will apply the new legislative framework to violations occurring on or after that date. To keep each examination anchored to a single set of compliance expectations, FINTRAC has stated that it will scope examination review periods so that they fall entirely within one legislative framework β applying the former policy where a review period sits entirely before March 26, 2026, and the new framework where it sits entirely on or after that date. If your business is uncertain which framework applies to a specific finding, that determination should be confirmed directly against FINTRAC's current published guidance rather than assumed from the examination date alone.
Compliance Agreement vs Effectiveness Review
These serve different functions and should not be conflated. A compliance agreement is an enforcement and remediation instrument that only arises after FINTRAC has found a prescribed violation. An effectiveness review is a periodic compliance-program requirement that exists independently of any enforcement action. An independent AML review can be a useful way to test whether remediation under a compliance agreement is actually working in practice, but a compliance agreement does not itself create a universal requirement to engage an external auditor β that depends on what the specific agreement actually requires.
Legal Counsel vs Compliance Implementation
Questions involving legal rights, appeal strategy, privilege, disputed statutory interpretation, or formal enforcement strategy may warrant legal counsel. That is different from compliance-implementation work: corrective-action design, policies and procedures, remediation tracking, evidence preparation, and readiness for a follow-up review. ComplyFactor's role sits in the latter category β remediation design, program rebuild, and evidence preparation β not legal representation or formal advocacy before FINTRAC or the Federal Court.
How ComplyFactor Supports Compliance Agreement Remediation
Where a compliance agreement requires rebuilding parts of an AML program, AML compliance program services address the underlying design gap the agreement identified. Where the gap is oversight rather than program design β no accountable owner tracking the agreement's deadlines β fractional MLRO or fractional compliance officer support provides that function on an ongoing basis. Where a business wants an independent test of whether remediation actually holds up before a follow-up FINTRAC review, an independent AML audit evaluates the program the way an examiner would. None of these prevent a compliance order or reduce a statutory penalty; they close the gap between what an agreement requires and what the program can actually demonstrate.
Frequently Asked Questions
Can a compliance agreement include terms beyond the minimum listed in section 73.16?
Yes. Section 73.16(2) requires the agreement to identify the prescribed violation and provision, the required measures, and the compliance deadline, but it also allows "any other terms to which the parties may agree." The statutory minimum is a floor, not the full extent of what an agreement can cover.
Does every corrective measure require a new policy or procedure?
Not necessarily. Depending on the underlying violation, remediation may involve an operating process, a system configuration, a change in control ownership, a training gap, a data issue, an escalation workflow, or documentation β a policy rewrite on its own does not automatically satisfy a measure that actually requires a change in practice.
What if a remediation measure depends on a third-party vendor or software provider?
This is a genuine project-management risk, since the entity remains responsible for meeting the agreement's deadline regardless of a vendor's own timeline. A vendor dependency does not itself extend the statutory deadline; if it puts completion at risk, that risk should be identified and raised with FINTRAC well before the deadline, not treated as an automatic excuse.
Should remediation be tested before the agreement deadline?
Testing can help confirm that an implemented control actually works as intended, which is a different question from whether it has been implemented at all. The Act does not impose a universal testing requirement; whether testing is expected depends on what the specific agreement calls for.
What should a business do if it may miss the remediation deadline despite making substantial progress?
Identify the risk as early as possible, document the substantial progress made to date, and understand that an extension under section 73.16(3) is discretionary and conditional, not automatic. This is a point where compliance and legal advice both have a role β compliance to evidence the progress, and legal counsel where the approach to FINTRAC involves a formal request or representation.
Can controls that already exist satisfy part of a compliance agreement?
Potentially, but only to the extent they actually satisfy the specific measure the agreement requires. An existing control does not automatically count simply because it predates the agreement; it needs to be tested against what the agreement's terms actually call for.
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need β free, no obligation, 30 minutes.
