Necosmart FINTRAC Penalty: 5 Compliance Failures Canadian MSBs Should Review
FINTRAC imposed a $693,742.50 penalty on Necosmart after identifying five compliance violations. See the findings and practical lessons for Canadian MSBs.

Key takeaways
- FINTRAC imposed a $693,742.50 administrative monetary penalty on 13010431 Canada Inc., operating as Necosmart, on March 27, 2026.
- The five findings covered suspicious transaction reporting, policies and procedures, enhanced measures, risk assessment, and virtual-currency record keeping.
- FINTRAC found 94 record-keeping deficiencies in the virtual-currency exchange transaction records it reviewed.
- The penalty notice does not establish that Necosmart's MSB registration was revoked; registration status is a separate question.
FINTRAC imposed an administrative monetary penalty of $693,742.50 on 13010431 Canada Inc., operating as Necosmart, a money services business in Edmonton, Alberta. The penalty was imposed on March 27, 2026, and publicly announced by FINTRAC on May 14, 2026, following a compliance examination that identified five violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations.
This article sets out what FINTRAC found in the Necosmart case and what other Canadian MSBs — particularly those handling virtual currency — can learn from it.
What Happened to Necosmart?
An administrative monetary penalty and an MSB registration revocation are separate regulatory actions. FINTRAC's public notice on Necosmart addresses the penalty and the underlying violations only. It does not state that Necosmart's MSB registration was revoked, and FINTRAC's current public penalty listing does not identify the matter as appealed, paid, or closed. Current registration status should be checked separately in FINTRAC's registry rather than inferred from the penalty notice.
Primary source: FINTRAC's public notice on 13010431 Canada Inc. / Necosmart.
The 5 Compliance Failures FINTRAC Identified
1. Suspicious Transactions Were Not Reported
FINTRAC found that Necosmart failed to submit four transaction reports in situations where there were reasonable grounds to suspect a transaction was related to money laundering or terrorist financing. This is classified as a Very Serious violation under the regulations.
FINTRAC's notice lists the specific indicators present but not acted on, including: transactional activity inconsistent with a client's apparent financial standing or occupation; transaction size or type atypical for the client; unknown source of funds for large virtual currency purchases; unnecessarily complex transactions; inconsistent client identification details; and activity linked to jurisdictions of concern.
In three of the four instances, Necosmart had already identified some of these indicators but did not take additional measures, including a holistic review, to determine whether the reasonable-grounds-to-suspect threshold had been reached. Identifying red flags individually is not the same as reaching a reportable decision. MSBs need a documented, repeatable process for combining multiple indicators, escalating them internally, and arriving at a defensible STR decision.
2. Policies and Procedures Did Not Match Operations
FINTRAC determined that Necosmart's written compliance policies and procedures were inadequate, incomplete, and not tailored to reflect how the business operated in practice. Deficiencies were identified across several core areas: suspicious transaction reporting procedures, client identification and know-your-client processes, ongoing monitoring, third-party determination, and record-keeping procedures. This was classified as a Serious violation.
Having a compliance manual is not the same as having a compliance program that reflects current operations. Where a business's product mix, transaction volumes, or client base has changed, the written policies need to be updated so they continue to describe the business as it actually operates. This is a core function of maintaining an AML compliance program.
3. Enhanced Measures for High-Risk Clients Were Not Followed
This violation, also classified as Serious, involved a gap between what Necosmart's policies described and what was actually carried out. FINTRAC's examination identified specific examples:
- Necosmart's policy required address confirmation using proof no older than three months for higher-risk clients, but this was not evidenced in the client files reviewed.
- Its enhanced due diligence procedures called for reviewing 3 to 6 months of a client's transaction history, but FINTRAC found only one month had been reviewed in practice.
- Necosmart had documented crypto-wallet scanning as part of its enhanced due diligence measures, but this was not being carried out.
A documented control has limited compliance value if the business cannot demonstrate that it is actually being applied. If a measure is written into policy, it needs to be evidenced in client files as something that is actually performed.
4. The Risk Assessment Was Incomplete
FINTRAC found that Necosmart's risk assessment did not adequately account for all relevant inherent risks, citing gaps related to high-risk jurisdictions and client occupations. FINTRAC also found that some mitigating measures had been documented in the risk assessment but were not carried out. This was a Serious violation.
A risk assessment needs to connect directly to the controls a business applies. Where the assessment identifies a risk, the corresponding mitigation needs to exist in practice, not only in the document itself.
5. Virtual-Currency Records Had Deficiencies
FINTRAC reviewed Necosmart's virtual currency exchange transaction tickets against the record-keeping requirements in the PCMLTFA Regulations and found 94 record-keeping deficiencies. This was classified as a Minor violation — the least serious of the five, though still material to the overall penalty.
This figure does not represent 94 separate criminal acts or unreported transactions. It reflects the number of instances where required information was missing or incomplete within the set of transaction records FINTRAC reviewed. For any MSB dealing in virtual currency, complete and accurate transaction records support the ability to reconstruct activity and assess risk after the fact.
What Canadian MSBs Should Learn From the Necosmart Case
- Do the written policies and procedures describe how the business operates today, or an earlier version of it?
- Can every documented enhanced due diligence measure be evidenced in client files, not just described in the policy manual?
- When multiple suspicious indicators appear on the same client or transaction, is there a documented process for reviewing them together and reaching an STR decision?
- Are high-risk relationships subject to review that matches what the policy actually requires?
- Does the risk assessment reflect the jurisdictions, client types, and products the business currently deals with?
- For virtual currency activity specifically, are transaction records complete against the prescribed record-keeping requirements?
- Could management produce evidence that documented controls are being performed as written?
Could the Same Gaps Exist in Your AML Program?
The pattern across the Necosmart findings is a gap between what was written down and what was actually carried out. Such gaps can emerge when a business grows, adds products, or changes its transaction flows without updating the controls and documentation that support them.
An MSB does not need to wait for a FINTRAC examination to find out whether its documented program still reflects its actual operations. If your business has changed its products, transaction flows, virtual currency activity, client base, or monitoring processes since its last review, a targeted compliance review can help identify whether gaps like these already exist.
ComplyFactor supports Canadian MSBs through AML audits and FINTRAC effectiveness reviews, as well as AML compliance program development and updates, to help align documented policy with actual practice.
For a broader look at how FINTRAC's penalty framework works, including how violations are classified and penalties calculated, see our guide to FINTRAC administrative monetary penalties.
Frequently Asked Questions
Did FINTRAC revoke Necosmart's MSB registration?
FINTRAC's penalty notice does not state that Necosmart's MSB registration was revoked. An administrative monetary penalty and a registration revocation are separate regulatory actions. Current registration status should be confirmed from FINTRAC's registry or revocation records rather than inferred from the penalty notice.
Is Necosmart the same company as 13010431 Canada Inc.?
FINTRAC identifies 13010431 Canada Inc. as also operating as Necosmart.
Does a FINTRAC administrative monetary penalty mean criminal wrongdoing?
No—not by itself. The Necosmart matter described in this article concerns administrative compliance violations identified under the PCMLTFA framework. FINTRAC's public notice does not characterize the company as having committed money laundering or any other criminal offence, and this article does not either.
Does FINTRAC require every virtual-currency MSB to scan crypto wallets?
No. In the Necosmart case, crypto-wallet scanning was one of Necosmart's own documented enhanced due diligence measures, and FINTRAC found that it was not being carried out in practice. The public notice does not establish crypto-wallet scanning as a requirement that applies to every MSB; the violation was Necosmart's failure to apply a measure it had itself documented.
Why did the suspicious transactions matter if Necosmart had already identified some red flags?
FINTRAC stated that in three of the four instances, Necosmart had identified some of the relevant indicators but did not take additional measures, including a holistic review, to determine whether the reasonable-grounds-to-suspect threshold had been reached. Identifying isolated indicators without a process for combining and escalating them did not satisfy the reporting obligation.
Can an MSB face a FINTRAC penalty when written controls are not followed in practice?
Based on the Necosmart findings, yes. FINTRAC identified multiple instances where documented enhanced measures and risk mitigations were not carried out as written, which contributed to the violations identified in this examination.
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need — free, no obligation, 30 minutes.