BSA/AML

Fractional BSA Officer vs. Independent BSA/AML Reviewer: Why the Same Person Cannot Perform Both Roles

Learn how U.S. MSBs should separate fractional BSA officer and independent BSA/AML reviewer roles under 31 CFR Β§ 1022.210 and FinCEN guidance.

On this page
Get Expert Help

Key takeaways

  • Under 31 CFR Β§ 1022.210(d)(4), the person designated for day-to-day BSA/AML compliance cannot also perform the MSB's independent review.
  • FinCEN guidance adds that the reviewer should not report directly to the designated compliance officer.
  • An outside CPA or audit firm is not universally required; a qualified internal reviewer may perform the review if the independence conditions are met.
  • A fractional or outsourced staffing model does not change the same-person restriction or automatically create reviewer independence.
  • Current FinCEN materials do not establish a blanket same-firm prohibition when different personnel provide the two functions, so objectivity and self-review risks still require careful scoping.
  • FinCEN guidance allows either the reviewer or designated compliance officer to track deficiencies and corrective actions after the review, while material remediation design can create a future self-review concern.

For a U.S. money services business (MSB) subject to 31 CFR Β§ 1022.210, the person designated to assure day-to-day BSA/AML compliance under Β§ 1022.210(d)(2) cannot also be the person who performs the MSB's independent review under Β§ 1022.210(d)(4). That restriction comes from the regulation itself. FinCEN's own guidance on conducting these reviews (FIN-2006-G012) goes one step further and states that the reviewer should not report directly to the compliance officer either β€” a separate, additional expectation layered on top of the regulatory text, not a restatement of it.

None of this turns on whether the compliance officer is a full-time internal employee or a fractional, outsourced one. "Fractional BSA officer" describes how a business staffs the Β§ 1022.210(d)(2) role commercially; it is not a distinct legal category with its own independent-review rules. Whoever holds that designation, in whatever employment arrangement, is subject to the same restriction when it comes to reviewing their own program.

Businesses often search for this distinction as "fractional BSA officer vs. independent auditor," and that framing is a reasonable way to find this article β€” but Β§ 1022.210(d)(4) itself uses the term "independent review," not "audit," and that terminology choice matters for what follows.

This article works through what the regulation requires, what FinCEN's guidance adds on top of it, why the two roles cannot overlap in the same person, and how an MSB β€” particularly one running a fractional compliance model β€” can structure genuine independence rather than assume it exists because a consultant's invoice says "independent."

For the section-by-section detail of what an independent review should actually test, see ComplyFactor's Independent BSA/AML Audit Checklist for U.S. MSBs. This article does not repeat that testing framework; it addresses a different question β€” who can perform the review, and how to structure that separation when the compliance officer is fractional or outsourced.

Fractional BSA Officer and Independent Reviewer Are Two Different Functions

It helps to state the distinction plainly before getting into the regulatory text, because the rest of the article builds on it.

The BSA officer designated under Β§ 1022.210(d)(2) is responsible for assuring day-to-day compliance with the AML program: overseeing policies, monitoring, reporting, training, and the countless operational decisions that keep the program functioning. The independent reviewer under Β§ 1022.210(d)(4) evaluates that program β€” including the decisions and activities of the person responsible for it. One function implements; the other tests the implementation. A person who genuinely carries out the first function is not positioned to perform the second on the same program, regardless of job title, employment status, or whether they bill the MSB as an employee or as a consultant.

What 31 CFR Β§ 1022.210 Actually Requires

The regulatory text is short, and it is worth reading exactly as written rather than as commonly paraphrased.

Β§ 1022.210(d)(2) requires every MSB to:

Designate a person to assure day to day compliance with the program and this chapter. The responsibilities of such person shall include assuring that: (i) The money services business properly files reports, and creates and retains records, in accordance with applicable requirements of this chapter; (ii) The compliance program is updated as necessary to reflect current requirements of this chapter, and related guidance issued by the Department of the Treasury; and (iii) The money services business provides appropriate training and education in accordance with paragraph (d)(3) of this section.

Β§ 1022.210(d)(4) requires every MSB to:

Provide for independent review to monitor and maintain an adequate program. The scope and frequency of the review shall be commensurate with the risk of the financial services provided by the money services business. Such review may be conducted by an officer or employee of the money services business so long as the reviewer is not the person designated in paragraph (d)(2) of this section.

That is the entire codified restriction: the reviewer cannot be the person designated under (d)(2). The regulation does not use the word "audit," does not require a CPA or outside firm, and does not itself address reporting lines, same-firm engagements, or a compliance officer's colleagues. Everything beyond "not the designated person" comes from FinCEN's interpretive guidance, discussed next β€” and the distinction matters, because guidance and regulation carry different legal weight and should not be cited as though they were the same thing.

What FinCEN Guidance Adds to the Independence Requirement

FinCEN's FIN-2006-G012, "Frequently Asked Questions β€” Conducting Independent Reviews of Money Services Business Anti-Money Laundering Programs," is the operative guidance on this requirement. Two points from it matter directly to the fractional-officer question:

The reporting-line point. FinCEN states that the review "may be conducted by an officer, employee or group of employees, so long as the reviewer is not the designated compliance officer and does not report directly to the compliance officer." The second half of that sentence β€” the reporting-line restriction β€” appears in guidance, not in the text of Β§ 1022.210(d)(4) itself. It is a real expectation FinCEN has stated plainly, and an MSB should treat it as governing how it structures a review. It is not, however, a sentence that can be cited as regulatory text, and this article does not blur the two.

The scope point. FinCEN's guidance states that the review "should cover all of the anti-money laundering program actions taken by β€” or defined as part of the responsibility of β€” the designated compliance officer," giving examples such as the compliance officer's risk-level determinations, training-frequency decisions, and the adoption of program controls. This is the guidance's own explanation for why the restriction exists in the first place: the review is specifically supposed to test the officer's own actions and decisions, which is a structurally different exercise from that officer testing themselves.

FinCEN also confirms, directly and unambiguously, that a certified public accountant or outside consultant is not required: "we determined to make clear that money services businesses are not required to hire a certified public accountant or an outside consultant to conduct a review of their programs." An officer, employee, or group of employees can perform the review, so long as the two conditions above are satisfied.

What a Fractional BSA/AML Officer Actually Is

"Fractional BSA officer" is a commercial staffing model, not a term that appears in Β§ 1022.210 or in FinCEN guidance. The regulation requires a designation β€” a specific person the MSB names as responsible for day-to-day compliance under (d)(2). It does not specify that this person be a full-time employee, does not prohibit engaging an external provider to support the function, and does not create a separate set of rules for how that person is engaged commercially. What it does require is that the designation attach to an identifiable individual: an MSB may engage an external provider or firm to support the compliance function, but Β§ 1022.210(d)(2) requires the MSB to designate a specific person responsible for assuring day-to-day compliance β€” the consulting firm itself is not, and cannot be, the "person" the regulation names.

In practice, an MSB may staff the (d)(2) role with a full-time internal hire, a part-time internal employee, or a specific individual engaged through an external provider on a fractional or retained basis, sometimes described as an outsourced or virtual BSA officer. Whichever staffing model is used, the individual holding the designation is doing the same legal job: assuring day-to-day compliance, which includes the reporting, recordkeeping, program-maintenance, and training-oversight responsibilities Β§ 1022.210(d)(2) names. Changing who employs that person, or how they are paid, does not change what the role legally is β€” and it does not exempt that person from the (d)(4) restriction on reviewing their own program.

What an Independent BSA/AML Reviewer Does

The independent reviewer's job is to determine whether the AML program is adequate and whether it is actually operating the way its policies say it should β€” not merely whether policies exist on paper. FinCEN's guidance describes the review as covering the program's policies, procedures, and internal controls; recordkeeping and BSA reporting functions; training; the actions taken by or assigned to the designated compliance officer; and testing of internal controls and transactional systems, with corrective-action recommendations to management where problems are found.

This article does not walk through that testing scope section by section β€” ComplyFactor's Independent BSA/AML Audit Checklist for U.S. MSBs already does that in depth, including sample selection, documentation, and a full testing framework by program area. What matters here is the function: the reviewer's job is to independently test what the officer built and ran, which is precisely why the reviewer cannot be that same person.

Why the Designated BSA Officer Cannot Review Their Own Program

This is the central logic of the whole restriction, and it is worth making concrete rather than abstract.

Consider a typical fractional BSA officer engagement. The officer:

  • approves the AML risk assessment and its risk ratings;
  • decides how often training occurs and for whom;
  • owns the SAR investigation and filing procedures;
  • oversees transaction-monitoring rule configuration; and
  • tracks remediation of previously identified issues.

FinCEN's guidance is explicit that the independent review is specifically supposed to evaluate whether those exact activities were adequate and properly carried out. If the same person who made those decisions is also the one evaluating whether they were made adequately, the review is not testing anything the officer did not already conclude was fine β€” there is no independent perspective introduced at any point in the process. This is true regardless of whether the officer is an internal employee or an outsourced consultant; the self-review problem is a function of the role, not the employment arrangement.

Fractional BSA/AML Officer vs Independent BSA/AML Reviewer: Role Comparison

Area Fractional BSA/AML Officer Independent BSA/AML Reviewer
Core purpose Runs the AML program day to day Tests whether the program is adequate and operating as intended
Program role Owner and implementer Evaluator
Day-to-day responsibility Yes β€” this is the role's defining feature No β€” periodic, not ongoing
Implements controls? Yes No β€” reviews controls someone else implemented
Tests controls? Not independently β€” may self-monitor as part of running the program Yes β€” this is the role's defining feature
Reports findings to management? Reports on program status generally Reports specific review findings and recommendations
Tracks remediation? Owns remediation execution May recommend remediation; execution sits with the program owner
Regulatory basis Β§ 1022.210(d)(2) Β§ 1022.210(d)(4)
Independence requirement None β€” this is the position being reviewed Cannot be the (d)(2) designee; per FinCEN guidance, should not report directly to that designee
Typical engagement type Ongoing, retained Periodic, scoped and time-bound
Can be internal? Yes Yes β€” regulation and guidance both permit an internal officer, employee, or group of employees
Can be external? Yes Yes β€” but external status alone does not establish independence; see below

Does an Independent Reviewer Have to Be External?

No. This is one of the more commonly misunderstood points in the market, and FinCEN's guidance addresses it directly: an MSB does not need to hire a CPA or an outside consultant. A qualified internal officer, employee, or group of employees can perform the review, provided the two independence conditions are met β€” not the designated compliance officer, and not someone who reports directly to that officer.

Internal review can be a practical option where the business is sufficiently staffed to have a genuinely separate reviewer, that reviewer sits outside the compliance officer's direct reporting line, and that reviewer has adequate BSA/AML expertise to conduct a meaningful test rather than a superficial one.

External review tends to be commercially preferable β€” not legally required β€” where the MSB is small and does not have a second qualified person available internally, the business runs a fractional compliance model with limited staff depth, the transaction profile is complex (multi-corridor remittance, virtual-currency exposure, a large agent network), prior findings warrant an outside perspective, or a banking partner, investor, or acquirer specifically expects external validation as part of its own diligence. These are all business reasons for choosing an external reviewer, not a regulatory mandate for one β€” the regulation's bar is the same whether the reviewer is internal or external.

Why Outsourcing the BSA Officer Does Not Automatically Create Independence

A common assumption is worth addressing directly: "our BSA officer is an external consultant, so anyone else at that consultancy is automatically independent enough to do our review." This does not follow from the regulation or the guidance, and it should not be treated as established.

What matters under Β§ 1022.210(d)(4) and FIN-2006-G012 is function, not invoice status. The designated (d)(2) person remains the program owner for purposes of the independent-review restriction regardless of whether they are paid as an employee or as a contractor. Changing a person's employment classification does not change what they actually do inside the program, and it does not cure the self-review problem if that same individual is asked to evaluate their own work.

Two distinct scenarios deserve separate treatment here, because they raise different questions:

Same individual. If the fractional BSA officer β€” the specific person designated under (d)(2) β€” is also the person conducting the independent review, this is a clear violation of the regulation's own restriction. There is no ambiguity in this scenario.

Different individual at the same vendor. If a different person from the same consulting firm conducts the review, this does not trip the (d)(2) restriction on its face β€” that restriction names the individual, not the firm. But it raises a more nuanced independence and objectivity question, addressed in the next section, that does not have a single bright-line answer in current FinCEN guidance.

Can the Same Consulting Firm Provide Both Services?

This is genuinely one of the more consequential questions for a fractional-officer engagement, and it deserves a direct answer about what the sources do and do not say.

Neither Β§ 1022.210(d)(4) nor FIN-2006-G012 expressly addresses same-firm engagements. The regulation's restriction names "the person designated in paragraph (d)(2)" β€” an individual, not an organization. FinCEN's guidance extends that to a reporting-line condition, again phrased around the individual reviewer's relationship to the individual compliance officer. No FinCEN rule or guidance located in this research states that a consulting firm may never provide both fractional-officer support and independent-review services to the same MSB using different personnel, and none was found stating the reverse β€” that this is categorically permitted without further inquiry.

What that means practically: the regulation's own bar can, on its text, be satisfied by different individuals at the same firm, provided the reviewer genuinely is not the designated officer and does not report to them within that engagement structure. But satisfying the letter of the restriction is not the same as satisfying its underlying purpose β€” an independent, unbiased evaluation of the program. A same-firm arrangement raises legitimate objectivity questions a business should not wave away simply because no rule names them:

  • Does the reviewing team have a commercial or reporting relationship to the officer-side team that could affect their willingness to flag problems?
  • Would the firm effectively be evaluating its own prior program design or advisory work, even if performed by different people?
  • Are the two engagement teams organizationally and operationally separate, with distinct scopes, distinct points of contact, and no shared supervision of the specific work being reviewed?

These are engagement-design and objectivity safeguards a firm can choose to apply β€” separate personnel, separate reporting lines, separate engagement leads, and no self-review of material work the same individual performed β€” not federally mandated conditions. A firm that applies stricter separation than the regulatory minimum is exercising professional judgment about objectivity, not complying with an additional rule that does not currently exist. An MSB evaluating this kind of proposal should ask the firm directly how it separates the two engagement teams, rather than assume the arrangement is either automatically fine or automatically prohibited.

Does the Reviewer's Reporting Line Matter?

Yes, and this is where FinCEN's guidance does real, independent work beyond the regulation's text. A structure where the reviewer reports directly to the compliance officer being reviewed does not satisfy FinCEN's stated expectation, even where the reviewer is a different individual from the officer.

Consider a structure like this:

Designated BSA Officer β†’ AML Analyst β†’ same AML Analyst is asked to "independently" review the officer's program

Here, the reviewer is not the designated officer, so the regulation's own text is technically satisfied. But the analyst reports directly to the officer whose work is being tested, which is the exact structure FinCEN's guidance calls out. An analyst reviewing the work of the person who supervises them, sets their objectives, and can affect their role has an obvious incentive problem, whatever their individual integrity β€” this is why FinCEN added the reporting-line condition on top of the bare "not the same person" rule.

A properly separated structure removes that direct reporting relationship: the reviewer reports to someone other than the compliance officer β€” senior management, a board or oversight committee, or, in an external engagement, a different point of contact at the reviewing firm entirely disconnected from the officer's chain.

This guidance does not, on its own text, extend to indirect organizational relationships beyond direct reporting β€” for example, two people who both ultimately report to the same CEO in a small business. FinCEN's stated condition is about direct reporting to the compliance officer specifically; extending it further than that is a reasonable risk-management judgment for a business to make, not something the guidance itself requires.

Five Governance Structures: Which Ones Work?

These scenarios are illustrative, not an exhaustive list, and each is assessed against what the regulation and guidance actually say β€” not extended beyond them.

Scenario 1 β€” The founder is the designated BSA officer. Can another qualified employee perform the review? Potentially yes, provided that employee is not the founder and does not report directly to the founder in a way that compromises the review. In a very small MSB, this can be difficult to structure cleanly if nearly everyone reports to the founder in some capacity β€” which is often exactly the situation where an external reviewer becomes the more practical option, even though it is not the only legally available one.

Scenario 2 β€” A fractional external BSA officer holds the (d)(2) designation. Can that same individual perform the independent review? No. That person is the designated officer under (d)(2), and Β§ 1022.210(d)(4) names that exact restriction. The MSB needs a different reviewer β€” internal, or from a different firm, or from the same firm through a genuinely separate team, as discussed above.

Scenario 3 β€” An internal compliance officer plus an outside audit firm. This is generally a more straightforward separation structure to defend, assuming the outside reviewer is not the designated compliance officer, does not report to that officer, and is not placed in a material self-review conflict through prior work on the program. External status by itself does not establish independence or competence β€” the reviewing firm still needs to be assessed on both, as discussed below.

Scenario 4 β€” The same consultancy provides both the fractional officer and the independent review, using different teams. This is the same-firm question addressed in full above; it is not repeated here. The short version: not automatically prohibited by the regulation's text, not automatically acceptable either, and worth a direct conversation with the firm about how the two teams are actually separated.

Scenario 5 β€” The independent reviewer later assists with remediating the findings they identified. FinCEN's guidance directly contemplates that either the reviewer or the designated compliance officer may track deficiencies and weaknesses identified during a review and document the corrective actions taken β€” tracking findings and documenting remediation after a review is not, on its own, something FinCEN guidance treats as a problem. The more careful question is different: if the reviewer becomes materially involved in designing or implementing the remediation itself, rather than simply tracking that it happened, that reviewer may end up testing their own work in a future review cycle. No FinCEN rule located in this research prohibits a reviewer from assisting with remediation after completing a review. Many firms nonetheless choose to separate review work from subsequent design/implementation work on the same program specifically to avoid that future self-review problem β€” a professional-practice safeguard, not a stated legal prohibition.

Independence vs. Reviewer Competence

Independence and competence are separate qualities, and a defensible review needs both. A reviewer can be organizationally well-separated from the compliance officer β€” no reporting relationship, no shared supervision β€” and still lack the substantive knowledge to identify a real control failure: MSB-specific regulatory knowledge, an understanding of transaction-monitoring logic, the ability to test records against applicable retention and reporting rules, and familiarity with the business's actual risk profile.

The reverse is equally true: deep BSA/AML expertise does not cure a genuine independence problem. A highly capable reviewer who reports directly to the person whose work they are testing has not produced an independent review, however technically sound their findings are. An MSB assessing a proposed reviewer β€” internal or external β€” should ask about both dimensions separately: is this person genuinely separated from the officer's chain, and does this person actually have the expertise to test an MSB's specific risk profile.

How to Document Reviewer Independence

FinCEN's guidance sets a documentation floor for the review itself: the reviewer should document the scope of the review, procedures performed, transaction testing completed, findings, and recommendations, and that documentation should be accessible to examiners and law enforcement with authority to request it.

Beyond that floor, an MSB can strengthen its position by keeping a clear record of the independence structure itself, not just the review's substantive findings. Useful documentation includes:

  • the current designation record identifying who holds the Β§ 1022.210(d)(2) compliance-officer role;
  • the reviewer's identity and their reporting line, showing they do not report directly to that officer;
  • the engagement scope and any written independence or conflict-of-interest statement from the reviewer or firm;
  • an organizational chart showing the reviewer's position relative to the compliance function;
  • a description of any prior work the reviewer or their firm performed for the business, and how that was accounted for in scoping the review; and
  • management's acknowledgment of the review's scope and the independence structure used.

This is practical evidence an MSB can produce for a banking partner, an examiner, or a diligence process β€” it is not a FinCEN-mandated "independence certificate," and no such formal requirement exists in current guidance. Framing it that way to a business would overstate what the sources actually require.

What If the Same Person Already Performed Both Roles?

Discovering that a past review was conducted by the same person who held the compliance-officer designation, or by someone reporting directly to that officer, is a governance gap worth addressing carefully rather than reactively. A reasonable, cautious sequence:

  1. Identify which specific review period or periods are affected.
  2. Confirm, from the designation record, whether the reviewer was in fact the designated (d)(2) officer at the time, or reported directly to them.
  3. Preserve the original review documentation as it exists β€” do not delete or rewrite prior records.
  4. Assess whether an appropriately independent re-review of the affected period is warranted, based on the significance of the program elements involved and any findings from the earlier review.
  5. Document the corrective governance change going forward: who now holds the designation, who now performs the review, and how the reporting lines are separated.
  6. Where the issue surfaces during an active examination or enforcement matter, involve legal counsel before deciding how to characterize or address the prior gap.

Not every historical review conducted this way is automatically void or unusable β€” that is a stronger claim than current guidance supports, and this article does not make it. The reasonable response is to identify the gap, assess its practical significance, and fix the governance structure going forward, rather than assume a single correct outcome applies to every situation.

Bank-Partner Requirements vs. FinCEN Requirements

A sponsor bank, payment partner, investor, or acquirer may require more than FinCEN's federal minimum, and it is important to keep these two sets of expectations separate rather than describe a bank's request as though FinCEN itself required it. A banking partner might request a fully external, third-party independent review; an annual review regardless of the MSB's own risk-based schedule; a formal written independence statement from the reviewer; or evidence of remediation for every finding before onboarding or renewal.

These are private, contractual due-diligence expectations reflecting that partner's own risk appetite β€” they can be more demanding than Β§ 1022.210(d)(4) requires, and an MSB should treat them as a separate commercial requirement layered on top of the federal floor, not as a restatement of what FinCEN itself mandates.

What the 2026 AML/CFT Program NPRM May Change

On April 7, 2026, FinCEN published a Notice of Proposed Rulemaking (Docket FINCEN-2026-0034, RIN 1506-AB72) proposing to substantially revise AML/CFT program requirements across the categories of financial institutions covered by the Bank Secrecy Act, including the MSB program rule at Β§ 1022.210. The proposal was published in the Federal Register on April 10, 2026, with a public comment period that closed June 9, 2026, and it addresses program governance, independent testing, and a shift toward risk-based, effectiveness-oriented program design more broadly.

As of this article's publication, the proposal remains just that β€” a proposal. No final rule had been issued, and FinCEN has indicated that, if finalized as proposed, the rule would take effect approximately 12 months after issuance. This article is based on the currently operative Β§ 1022.210 and FIN-2006-G012, not on the NPRM's proposed text. If a final rule is issued that changes the independent-review requirement, this article β€” and any governance structure built against the current rule β€” will need to be reassessed against the final rule's actual text, not the proposal.

How ComplyFactor Separates Fractional Officer and Independent Review Work

ComplyFactor provides both fractional BSA/AML officer support and independent BSA/AML audit services for U.S. MSBs, and treats these as genuinely separate engagements rather than interchangeable offerings from the same practice. Engagements are scoped to preserve reviewer independence and avoid self-review conflicts β€” including where ComplyFactor has previously supported a client's day-to-day compliance function or advised on a program's design, which is accounted for directly in how a later independent-review engagement is scoped and staffed. Businesses that need ongoing day-to-day compliance ownership should look to the fractional officer function; businesses that need an independent test of whether that program actually works should look to the independent-review function β€” and where a business needs the underlying program itself rebuilt rather than reviewed, ComplyFactor's BSA/AML compliance program services address that separately. None of this is a guarantee of any particular examination or audit outcome; it is a description of how the engagement roles are kept distinct.

Frequently Asked Questions

Can the independent reviewer help track remediation after the review?

Yes, in the narrow sense FinCEN's guidance actually addresses: either the reviewer or the designated compliance officer may track deficiencies identified during the review and document the corrective actions taken. That is different from the reviewer designing or implementing the fix itself β€” if the reviewer becomes materially involved in building the remediation, that can create a self-review problem the next time the same program is reviewed.

Who should receive the independent-review report if the reviewer cannot report directly to the BSA officer?

FinCEN's guidance requires the review to be documented and reported to management; it does not name a specific required recipient beyond that. Depending on the MSB's structure, this is typically senior management, an owner or founder, or another appropriate oversight function distinct from the compliance officer's own chain β€” there is no universal board-reporting requirement under Β§ 1022.210 itself.

What if the proposed reviewer previously helped design part of the AML program?

This depends on the materiality of that prior work. If the reviewer would effectively be evaluating decisions or controls they personally created, that is a genuine self-review risk worth addressing directly β€” either by using a different reviewer for the affected areas or by having the firm explain how it separates that prior work from the current review. No blanket rule prohibits this arrangement outright, but it is not something to overlook simply because no rule names it.

Can a former BSA officer later perform the independent review?

There is no simple blanket answer. It depends on whether they still hold or report into the same structure, whether the review would in substance evaluate decisions they made while holding the designation, and how much time and organizational separation exists since they left the role. This should be assessed against the same self-review and reporting-line logic used throughout this article rather than treated as automatically resolved either way.

What happens if an MSB discovers the same person previously served as both BSA officer and reviewer?

Identify which review period is affected, confirm the designation record, preserve the existing documentation rather than rewriting it, and assess whether an independent re-review of that period is warranted based on what was at stake. Not every past review conducted this way is automatically void β€” the practical response is to fix the governance structure going forward and document that change, not to assume one universal outcome applies.

ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.