Key takeaways
- FINTRAC imposed a $231,826 administrative monetary penalty on Nova Scotia Gaming Corporation on July 23, 2026, publicly announced September 3, 2026.
- The penalty covered 3 violations found during a compliance examination; Nova Scotia Gaming Corporation has paid it in full and the case is closed.
- Violation #1: failure to submit 2 suspicious transaction reports (Very Serious).
- Violation #2: written compliance policies and procedures that failed to document and apply Ministerial Directives (Serious).
- Violation #3: failure to complete and document an enterprise-level money laundering and terrorist financing risk assessment (Serious).
Nova Scotia Gaming Corporation, a reporting entity in the casino sector headquartered in Halifax, was imposed an administrative monetary penalty of $231,826 on July 23, 2026, for three violations found during a FINTRAC compliance examination. FINTRAC publicly announced the penalty on September 3, 2026. The corporation has paid the penalty in full, and FINTRAC's notice states the case is closed.
The case is useful reading for reporting entities well beyond the casino sector, because the three findings sit at three different layers of an AML compliance program: detecting and reporting suspicious activity at the transaction level, keeping written policies and procedures current and operational, and completing an enterprise-wide assessment of money laundering and terrorist financing risk. Together, they show how a gap at any one layer can create regulatory exposure, even where the other layers are functioning.
What Happened to Nova Scotia Gaming Corporation?
FINTRAC's notice states that the violations were found during the course of a compliance examination. It does not explain what prompted the examination, and this article does not speculate on that point.
The Three FINTRAC Violations at a Glance
Failure #1: Two Suspicious Transaction Reports Were Not Filed
FINTRAC found that Nova Scotia Gaming Corporation failed to submit 2 suspicious transaction reports where there were reasonable grounds to suspect that one or more attempted transactions were related to the commission of a money laundering or terrorist activity financing offence. Section 7 of the PCMLTFA contains the underlying suspicious transaction reporting obligation itself. FINTRAC's enforcement notice separately identifies this failure as a Very Serious violation under the applicable administrative monetary penalty classification framework β the most severe classification FINTRAC applies.
What indicators did FINTRAC identify?
FINTRAC's notice states that the 2 unreported suspicious transactions contained some of the following indicators: common identifiers, such as an address or phone number, shared across multiple players who did not appear to be related; identification information suspected to be false, stolen, altered, inaccurate, forged, or based on aliases or generic addresses such as post office boxes; an inability to properly identify the player or unresolved questions about the player's identity; seemingly false, counterfeited, or inaccurate identification; evidence of untruthful or misleading information from the player; and notification of a chargeback on the financial instrument used for a player deposit, suggesting unauthorized use.
It's important not to overstate what any one of these indicators means on its own. FINTRAC's own guidance is clear that identifying an indicator is not the same as reaching the reporting threshold β it takes a holistic assessment of facts, context, and indicators together to determine whether a report is required.
Why the STR Threshold Matters
The legal threshold for filing a suspicious transaction report is reasonable grounds to suspect β described by FINTRAC as a step above simple suspicion, meaning there is a possibility that a money laundering or terrorist activity financing offence has occurred. Reaching this threshold does not require verifying the underlying facts or proving that an offence actually occurred; it requires considering the facts, the context, and the applicable money laundering or terrorist activity financing indicators together, and being able to articulate that assessment in a way another trained person would likely reach the same conclusion.
This is a meaningfully lower bar than "reasonable grounds to believe," which requires verified facts supporting a probability that an offence occurred, and it does not require certainty. It's also not a checklist exercise β a single red flag in isolation does not automatically require a report. Where activity is assessed and no STR is filed, keeping a clear rationale is a strong evidentiary practice that can help show how the decision was reached if FINTRAC later reviews it.
Current FINTRAC guidance also directs reporting entities to consider sanctions-evasion characteristics alongside facts, context, and money laundering or terrorist financing indicators when assessing whether the reporting threshold has been reached. That current guidance describes what entities should consider today; it should not be read back into the wording of the Nova Scotia Gaming finding itself, which FINTRAC framed specifically in terms of a money laundering or terrorist activity financing offence.
Attempted transactions matter here too. FINTRAC's current guidance treats attempted and completed transactions the same way for reporting purposes, and there is no monetary threshold associated with the suspicious transaction reporting requirement β a transaction that never completes can still trigger a reporting obligation if the reasonable-grounds-to-suspect threshold is met.
What a Reporting Entity Should Review
These are practical control-design questions, not a restatement of the legal threshold itself:
- Are alerts and unusual player patterns assessed promptly once identified?
- Is the assessment of facts, context, and indicators actually documented, not just concluded informally?
- Can staff or systems identify linked players β shared addresses, phone numbers, or other identifiers across accounts that appear unrelated?
- Are identity inconsistencies or suspected false documentation escalated to a defined decision-maker?
- Are chargebacks and similar payment-instrument anomalies incorporated into suspicious-activity monitoring, not just handled as a payments issue?
- Are decisions not to file a report documented with rationale? Documenting why activity was assessed as not meeting the threshold can help demonstrate that it was properly considered if FINTRAC later reviews the same transaction.
- Do staff understand that an attempted transaction can trigger a reporting obligation on the same basis as a completed one?
- Are STR procedures reviewed against current FINTRAC guidance, including as part of the two-year effectiveness review?
Failure #2: Compliance Policies Did Not Address Ministerial Directives
FINTRAC determined that the compliance policies and procedures Nova Scotia Gaming Corporation had implemented were incomplete. Specifically, FINTRAC found that the policies and procedures failed to document and apply Ministerial Directives, pursuant to section 11.42(1) of the PCMLTFA, at the time of the examination. This was classified as a Serious violation under PCMLTFA subsection 9.6(1) and PCMLTFR paragraph 156(1)(b), which require written compliance policies and procedures that are kept up to date and, for an entity, approved by a senior officer.
FINTRAC's notice does not state that Nova Scotia Gaming Corporation ignored every Ministerial Directive, processed prohibited transactions, or violated sanctions law. The finding is specifically about the policies and procedures themselves β they did not document and apply the applicable Directive requirements at the time of the examination.
Why Written Policies Need to Match Current Obligations
Having an AML manual and having a current, operational set of compliance procedures are not the same thing. A compliant policy suite needs to reflect the obligations that actually apply to the business today, assign clear responsibility for each obligation, define an escalation and decision process, be capable of producing evidence that it was actually followed, for an entity, be approved by a senior officer, and be revised when the underlying regulatory obligations change β including when a new Ministerial Directive is issued or an existing one is amended. A manual that was accurate when written but never updated as obligations evolved creates exactly the kind of gap this violation describes.
What Are FINTRAC Ministerial Directives?
Under Part 1.1 of the PCMLTFA, in force since June 19, 2014, the Minister of Finance may issue directives requiring reporting entities to apply countermeasures to transactions coming from or going to designated foreign jurisdictions or entities, and may separately recommend regulations restricting reporting entities from entering into transactions connected to designated jurisdictions or entities. Directives currently in force cover Russia, Iran, and the Democratic People's Republic of Korea, and each is reviewed at least every three years.
The practical requirement for a reporting entity is to have a process for identifying which directives apply to its business, and for building the resulting countermeasures β enhanced due diligence, reporting, or other specified measures β into policies, procedures, and day-to-day operations. A directive that exists only as a notice on file, without being reflected in operational procedures, does not meet this requirement β which is the core of what FINTRAC found here.
Failure #3: No Documented Enterprise-Level ML/TF Risk Assessment
FINTRAC determined that Nova Scotia Gaming Corporation failed to complete and document an enterprise-level risk assessment of money laundering and terrorist financing risks based on its overall business activities, as required under PCMLTFA subsection 9.6(1) and PCMLTFR paragraph 156(1)(c). This was classified as a Serious violation.
This finding is specific: it is not a statement that Nova Scotia Gaming Corporation had no controls at all. FINTRAC's notice describes a missing enterprise-level assessment of overall business risk β individual transaction-level controls or site-specific procedures, even where they exist, do not substitute for a documented assessment of risk across the business as a whole.
What Should a FINTRAC Risk Assessment Consider?
Under PCMLTFR paragraph 156(1)(c), the risk assessment must take into consideration: clients, business relationships, and correspondent banking relationships; products, services, and delivery channels; the geographic location of the entity's activities; for certain entity types, risk arising from affiliates; and any other relevant factor. FINTRAC's dedicated risk-based approach guidance builds on this list and also directs entities to consider new developments and technologies before they're implemented, and factors such as Ministerial Directives and the national risk assessment under the "other relevant factors" category.
Separately, FINTRAC's current compliance program guidance describes the breadth and depth of the related two-year effectiveness review as varying based on factors including business complexity, transaction volumes, findings from previous reviews, and current money laundering, terrorist activity financing, and sanctions evasion risks. That sanctions-evasion language describes today's effectiveness-review guidance β it is not part of how FINTRAC characterized the Nova Scotia Gaming risk-assessment violation itself, which its notice frames specifically in terms of money laundering and terrorist financing risk. The two should not be merged: what applies today to the scope of effectiveness reviews is a separate question from what FINTRAC found in this historical examination.
Enterprise-Level vs Transaction-Level Risk
Transaction-level controls answer a narrow question: is this specific activity suspicious? An enterprise-level risk assessment answers a broader one: where is this business exposed to money laundering and terrorist financing risk overall β across its products, customers, geography, and delivery channels β and how should that exposure shape controls, resourcing, and training? A business can have functioning transaction monitoring and still lack this broader assessment, and FINTRAC treats the two as separate obligations. Site-level or department-level risk documentation, even if genuinely good, does not substitute for an enterprise-level assessment unless, taken together, it actually provides a documented assessment of risk across the business as a whole.
What These Three Findings Show About FINTRAC Compliance
These three violations map cleanly onto three layers of a compliance program β a useful analytical framework for understanding this case, not an official FINTRAC model:
Layer 1 β Transactions: Can the organization actually identify and report suspicious activity when it occurs, including attempted transactions?
Layer 2 β Policies and procedures: Has the organization translated its current legal obligations, including applicable Ministerial Directives, into operational controls that are actually followed?
Layer 3 β Risk governance: Has the organization assessed and documented its money laundering and terrorist financing risk across the business as a whole, not just at the transaction or site level?
FINTRAC identified deficiencies across all three layers, with the STR violation classified as Very Serious and the other two violations classified as Serious. A weakness at any one of these layers can create regulatory exposure on its own; this case shows findings across all three at once.
Practical Compliance Checklist After the Nova Scotia Gaming Penalty
Suspicious transaction reporting
- Current STR procedures reflect current FINTRAC guidance (current FINTRAC expectation)
- Attempted transactions are captured in scope for STR assessment (required)
- Alerts are escalated to a defined decision-maker within a reasonable time (practical control)
- Identity anomalies and chargebacks are incorporated into suspicious-activity assessment (practical control)
- Decisions not to file a report are documented with rationale (strong evidentiary/practical control)
- Training equips relevant personnel to recognize and escalate suspicious activity, including attempted transactions where relevant to their role (training program required under PCMLTFA subsection 9.6(1); this specific content focus is current FINTRAC expectation rather than a separately enumerated statutory requirement)
Policies and procedures
- Policies reflect current PCMLTFA and Regulations obligations, not a stale baseline (required)
- A defined process exists for identifying and operationalizing new or amended Ministerial Directives (required β this is the specific gap FINTRAC's notice describes, under PCMLTFR paragraph 156(1)(b) as applied to directives under s.11.42(1))
- Ownership and responsibility for each obligation are clearly assigned (practical control)
- Senior-officer approval of written compliance policies and procedures is documented (required for an entity, per PCMLTFR paragraph 156(1)(b))
- Version control shows when and why policies were last updated (practical control)
- Procedures reflect what staff actually do, not only what was originally written (current FINTRAC expectation)
Risk assessment
- An enterprise-level assessment exists and is documented, separate from site-level controls (required)
- The assessment addresses clients/business relationships, products/services/delivery channels, and geography at minimum (required, per PCMLTFR 156(1)(c))
- New products, services, or technologies are assessed for risk before implementation (required, per PCMLTFR subsection 156(2))
- High-risk elements identified have documented mitigation measures (required)
- The assessment is reviewed and updated when the business changes, and tested as part of the two-year effectiveness review (required)
Very Serious vs Serious FINTRAC Violations
In this case, Violation #1 (the missing STRs) was classified as Very Serious, while Violations #2 and #3 (policies/procedures and risk assessment) were classified as Serious. These classifications come from the Proceeds of Crime (Money Laundering) and Terrorist Financing Administrative Monetary Penalties Regulations, and FINTRAC's notice states that the penalty took into account the criteria in section 73.11 of the PCMLTFA and section 6 of those Regulations. For a fuller explanation of how the classification system and FINTRAC administrative monetary penalties framework work in general, including the penalty ranges attached to each classification and how the framework changed in 2026, see ComplyFactor's dedicated guide to that topic.
FINTRAC published a single, overall penalty of $231,826 covering all three violations together. Its notice does not provide a public breakdown attributing a specific dollar figure to each individual violation, and this article does not attempt to reverse-engineer one.
Does Paying a FINTRAC Penalty End the Compliance Issue?
Nova Scotia Gaming Corporation paid the $231,826 penalty in full, and FINTRAC's notice states the case is closed. That closure reflects resolution of this specific enforcement matter β it is not a certification from FINTRAC that the corporation's broader compliance program is now fully compliant going forward, and FINTRAC's notice makes no such statement. This article does not speculate about what remediation, if any, Nova Scotia Gaming Corporation has since undertaken, since that is not disclosed in the public notice.
Why This Case Matters Beyond the Casino Sector
The specific obligations here, and the operational context they sit in, are particular to the casino sector's activities under the PCMLTFA. Other reporting entities β MSBs, financial entities, real estate brokers and developers, dealers in precious metals and stones, and others β do not share identical transaction types, reporting triggers, or sector-specific rules, and this article does not suggest otherwise.
What does transfer across sectors is the underlying pattern: STR decisions should be based on the facts, context, and indicators considered, with documentation that supports how the assessment was reached; written policies and procedures need to stay current with actual obligations, including Ministerial Directives, rather than existing as a static document; and an enterprise-level risk assessment is a distinct requirement from transaction-level or site-level controls, however good those controls are. Any PCMLTFA reporting entity can usefully ask whether its own program would hold up against this same three-layer review.
How ComplyFactor Can Help
Nova Scotia Gaming Corporation's three findings β reporting-function gaps, incomplete policies and procedures, and a missing enterprise-level risk assessment β are exactly the areas an independent AML audit is designed to surface before a FINTRAC examination does. ComplyFactor's Independent AML Audit service tests whether a compliance program's STR processes, policies, and risk assessment are actually operating as intended, and its AML Compliance Program service supports building or updating the program itself, including a properly documented enterprise-level risk assessment and a process for tracking applicable Ministerial Directives. Review your FINTRAC compliance program.
FAQ
Is a FINTRAC Ministerial Directive the same thing as Canadian sanctions legislation?
No. Ministerial Directives are issued by the Minister of Finance under Part 1.1 of the PCMLTFA and require reporting entities to apply specified countermeasures to transactions connected to designated jurisdictions or entities. Canada's economic sanctions regimes are separate legislation, administered through different mechanisms. The two are related in practice β FINTRAC's own risk-assessment guidance lists them alongside each other as relevant factors β but they are not the same legal instrument, and a Ministerial Directive finding is not itself a sanctions finding.
How often should a FINTRAC risk assessment be reviewed or updated?
FINTRAC's guidance does not set a fixed calendar for updates outside the two-year effectiveness review, which must test the risk assessment along with the rest of the compliance program. In practice, an entity should also update its risk assessment whenever its business model changes β a new product, service, technology, or location β rather than waiting for the next scheduled review.
Does FINTRAC prescribe one specific methodology or format for an enterprise-level risk assessment?
No. FINTRAC's guidance states plainly that there is no prescribed methodology, and an entity is responsible for developing and documenting its own approach. FINTRAC does expect the assessment to cover the prescribed factors under PCMLTFR paragraph 156(1)(c) and to be tailored to the size and complexity of the business, but it does not mandate a specific template or document structure.
What should a reporting entity do when a new Ministerial Directive is issued?
At minimum: identify whether and how the directive applies to the business, update policies and procedures to document and apply its requirements, train relevant personnel where needed, and implement and document the resulting controls. FINTRAC does not prescribe one universal workflow for this β the specific steps depend on the entity's structure and the directive's requirements.
Does FINTRAC stating that a case is "closed" prevent future examinations?
No. FINTRAC's notice describes this specific enforcement matter as resolved because the penalty was paid in full β it says nothing about immunity from future compliance examinations, which operate independently of any past AMP.
Does a paid FINTRAC AMP mean the company has admitted criminal wrongdoing?
No. FINTRAC's public notice describes an administrative monetary penalty for regulatory non-compliance found during a compliance examination β this is a civil enforcement mechanism, not a criminal conviction, and FINTRAC's notice does not characterize the conduct as criminal.
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need β free, no obligation, 30 minutes.
