AML Compliance & Regulation

PCMLTFA Requirements in Canada: Compliance Guide for MSBs, PSPs and Fintechs

What the PCMLTFA requires in Canada: reporting-entity status, registration, AML programs, KYC, reporting, records and 2025-2026 changes.

On this page
Get Expert Help

Key takeaways

  • The PCMLTFA is the federal framework behind Canada's anti-money laundering and anti-terrorist financing regime.
  • A business's obligations depend on its reporting-entity status and the specific regulated activities it carries out.
  • Core obligations include a compliance program, client verification, risk assessment, monitoring, recordkeeping and required FINTRAC reports.
  • MSB/FMSB registration and Bank of Canada PSP registration are separate regulatory questions that can overlap for some business models.
  • Canada's AML framework changed materially through 2025 and 2026, so policies and controls should be reviewed against the current rules.

The Proceeds of Crime (Money Laundering) and Terrorist Financing Act, known as the PCMLTFA, is the federal law behind Canada's anti-money laundering and anti-terrorist financing regime. FINTRAC, the Financial Transactions and Reports Analysis Centre of Canada, administers it and examines reporting entities for compliance. What a specific business actually has to do under the PCMLTFA depends entirely on its reporting-entity status and the activities it carries out; there is no single checklist that applies identically to every regulated business.

Canada's AML framework changed materially through 2025 and 2026: new sectors came into scope, agent and mandatary rules changed, the definition of a listed person or entity expanded, and Bill C-12 raised penalties and introduced a new compliance-program effectiveness standard, with a universal FINTRAC enrolment requirement now legislated but not yet in force. This guide sets out how the PCMLTFA's obligations fit together, what changed and when, and where to find ComplyFactor's more detailed guidance on each individual requirement.

What Is the PCMLTFA?

The PCMLTFA is the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, the core federal statute requiring Canadian businesses in defined sectors to identify clients, assess risk, monitor activity, keep records, and report specified transactions to FINTRAC. Its purpose is to detect and deter money laundering and terrorist financing by giving FINTRAC the financial intelligence it needs to support law enforcement and national security.

The Act itself sets out the framework in broad terms; the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations (PCMLTFR) supply the operational detail: dollar thresholds, timing rules, and specific field requirements. FINTRAC's published guidance then interprets both for particular reporting-entity sectors and particular obligations. A business that reads only the Act will miss most of what actually governs its day-to-day compliance; the Regulations and sector-specific guidance are where the real operational rules live.

Who Is Subject to the PCMLTFA in Canada?

The PCMLTFA defines reporting entities by activity, not by industry label. Current sectors include financial entities (banks, credit unions, trust and loan companies), life insurance companies, brokers and agents, securities dealers, casinos, real estate developers, brokers and sales representatives, dealers in precious metals and stones, accountants and accounting firms performing certain activities, British Columbia notaries, mortgage administrators, brokers and lenders, money services businesses (MSBs) and foreign money services businesses (FMSBs), financing or leasing entities, factors, and title insurers. Not every Canadian business falls into one of these categories; the obligation attaches to the specific regulated activity, not to being a business generally.

Businesses Added or Brought Into Scope in 2025

Financing and leasing entities and factors became PCMLTFA reporting entities on April 1, 2025, bringing equipment financing, vehicle leasing, and invoice-factoring businesses under the same compliance-program, identification, and reporting obligations that already applied to MSBs and financial entities. A further wave of changes took effect October 1, 2025, expanding and clarifying obligations across several sectors at once: title insurers were brought into scope with adjusted requirements reflecting their limited direct client contact, real estate brokers and sales representatives gained a duty to identify unrepresented parties in transactions, and reporting entities generally gained the ability to use an agent or mandatary to carry out identity verification on their behalf under a documented arrangement.

ComplyFactor's dedicated guide for this sector covers the full financing, leasing and factoring compliance checklist, including client identification triggers and reporting deadlines specific to those businesses.

PCMLTFA Requirements at a Glance

The obligations connect in a fairly linear sequence, even though a mature compliance program runs most of them continuously and in parallel. The PCMLTFA Compliance Obligations Map below shows how the pieces fit together, from first determining whether the Act applies at all through to keeping the resulting program current.

Determine reporting-entity status: identify which regulated activity, if any, the business carries out

Register where required: MSBs and FMSBs register with FINTRAC before commencing operations

Establish a compliance program: a named compliance officer, written policies, a risk assessment, training, and a periodic effectiveness review

Know and verify clients: confirm identity using a permitted method for the client type and channel

Establish business relationships: recognize when an ongoing relationship (not a one-off transaction) has formed, since this triggers additional obligations

Assess risk: rate customers, products, delivery channels, and geography, and document the reasoning

Conduct ongoing monitoring: watch activity against what is known about the client, at a frequency the risk assessment supports

Make required PEP/HIO and third-party determinations: identify politically exposed persons, heads of international organizations, and undisclosed third parties at the applicable triggers

Keep required records: client identification, transaction, and compliance-program evidence, for the retention period that applies to each record type

Submit required reports: STRs, LCTRs, LVCTRs, EFTRs, and other sector-specific reports, depending on activity

Apply sanctions and ministerial-directive controls: screen against listed persons and entities and apply any directive-specific restrictions

Test effectiveness: an independent review, at least every two years, of whether the program actually works

Keep regulatory information current: registration details, contacts, and policies updated as the business changes

Each of these is a real, separate control with its own trigger and evidence requirements; none of them substitutes for another. The sections below explain how they connect, and where ComplyFactor's dedicated guidance covers the operational detail for each.

Registration and Regulatory Status Under the PCMLTFA

MSB and FMSB Registration

Money services businesses and foreign money services businesses must register with FINTRAC before commencing operations, and renew that registration every two years without exception. Registration is a distinct step from having an active compliance program; a registered MSB with no working AML program is still non-compliant, and an unregistered business conducting MSB activity is operating illegally regardless of how good its internal controls are. For the full registration process, documents, and timelines, see ComplyFactor's MSB registration guidance.

Do All Reporting Entities Register With FINTRAC?

Not under the framework currently in force. Historically, formal FINTRAC registration has applied specifically to MSBs and FMSBs; other reporting entity sectors (real estate brokers, accountants, dealers in precious metals, and others) are subject to the PCMLTFA's obligations without a parallel MSB-style registration step.

That is changing, but has not changed yet. Bill C-12, which received Royal Assent on March 26, 2026, legislates a universal FINTRAC enrolment requirement that will apply to all reporting entities subject to the PCMLTFA, not just MSBs and FMSBs. As of August 2026, this enrolment framework is legislated but not yet in force: its coming-into-force date is tied to regulations still to be published in the Canada Gazette, Part II, and FINTRAC has indicated implementation will be phased. Businesses that are already registered MSBs or FMSBs face no immediate change from this specific amendment; businesses in other reporting-entity sectors that are not currently registered anywhere should treat this as a near-term compliance item to plan for, not as something to act on today.

The PCMLTFA Compliance Program Requirement

Every reporting entity must maintain a written compliance program covering five elements: a designated compliance officer with real authority, written policies and procedures that reflect the actual business, a documented risk assessment, an ongoing training program for relevant staff, and an independent effectiveness review conducted at least once every two years.

Since March 2026, FINTRAC applies a stricter three-part standard when it examines that program: is it reasonably designed for the business's actual risks, is it risk-based (do controls scale with the ratings in the risk assessment), and is it effective in practice, meaning it produces evidence of active compliance rather than existing only on paper. This effectiveness standard, and what changed operationally because of it, is covered in full in ComplyFactor's dedicated article.

For the complete post-Bill C-12 effectiveness standard, including the before-and-after penalty comparison, see ComplyFactor's Bill C-12 and the new FINTRAC effectiveness standard article.

For the full five-pillar build, deliverables, and process, see ComplyFactor's PCMLTFA AML compliance program service.

Know Your Client Requirements Under the PCMLTFA

"Know your client" is not one control; it is a set of separate, connected controls that each answer a different question. Confusing them, or assuming one satisfies another, is one of the most common gaps FINTRAC finds during examinations.

Identity Verification

Confirms that a client, person or entity, is who or what they claim to be, using one of the permitted methods for that client type. The exact trigger and timing depend on the reporting entity's sector and the transaction involved. ComplyFactor's FINTRAC identity verification guide (once published) will cover the full method set, remote-verification rules, and MSB-specific triggers in detail.

Beneficial Ownership

Identifies the individuals who ultimately own or control a corporate or other entity client, separately from confirming the entity itself exists. See ComplyFactor's beneficial ownership verification guide for the full requirement, including the Corporations Canada discrepancy-reporting process introduced in October 2025.

Third-Party Determinations

Establishes whether someone other than the client is actually instructing or benefiting from a transaction. See ComplyFactor's FINTRAC third-party determination guide for the full question workflow and worked examples.

PEP and HIO Determinations

Identifies whether a client, or a family member or close associate of one, is a politically exposed person or a head of an international organization, which then determines whether enhanced measures and senior management review apply. ComplyFactor's guide to politically exposed persons in Canada (once published) covers the domestic, foreign, and HIO categories in full.

Business Relationships and Ongoing Monitoring

A business relationship is what forms once a client conducts more than an isolated transaction, and it is the trigger for several ongoing obligations: periodic reassessment of PEP/HIO status, keeping client identification information current, and monitoring activity against what is known about the client at a frequency the risk assessment supports. Ongoing monitoring is not a one-time check; it is what keeps the KYC controls above accurate as a relationship continues, and it is where a change in a client's risk profile is actually supposed to surface.

Risk Assessment and High-Risk Clients

The PCMLTFA's risk-based approach starts with a business-wide risk assessment covering customer types, products and services, delivery channels, and geography, and it is this assessment that decides how much scrutiny individual relationships receive. A client, product, or transaction rated high risk is not simply flagged; it triggers specific, higher obligations: enhanced due diligence at onboarding, enhanced ongoing monitoring for the life of the relationship, and, for certain PEP and HIO categories, mandatory senior management review.

Some high-risk treatment is automatic under the Act itself, such as the mandatory high-risk classification for foreign PEPs and their family members or close associates, regardless of what a business's own risk assessment concludes. Other high-risk determinations are risk-based, meaning the reporting entity's own documented assessment decides the outcome. A program that treats every client identically, or that cannot show the reasoning behind a risk rating, will not satisfy the effectiveness standard FINTRAC now applies.

What Must Be Reported to FINTRAC?

Reporting obligations depend on sector and activity; no reporting entity files every report type, and assuming otherwise leads to wasted effort in the wrong place. The reports that apply most broadly are set out below at a framework level.

Suspicious Transaction Reports

Required whenever a reporting entity has reasonable grounds to suspect a transaction, completed or attempted, is related to money laundering or terrorist financing, regardless of dollar amount. See ComplyFactor's FINTRAC Suspicious Transaction Report narrative guide for how to write a defensible narrative once that threshold is reached.

Large Cash Transaction Reports

Required when a reporting entity receives $10,000 CAD or more in cash in a single transaction, or an aggregated set of cash transactions within a consecutive 24-hour window. See ComplyFactor's FINTRAC Large Cash Transaction Report guide for the full threshold, timing, and form-structure detail.

Large Virtual Currency Transaction Reports

Required when a reporting entity receives virtual currency equivalent to $10,000 CAD or more in a single transaction, following the same aggregation logic as large cash transactions but reported on a separate form specific to virtual currency, since cash and virtual currency are never combined to reach a single threshold.

Electronic Funds Transfer Reports

Required for qualifying international electronic funds transfers of $10,000 CAD or more, whether initiated or finally received, again subject to 24-hour aggregation. Domestic transfers within Canada do not trigger this report regardless of amount.

Listed Person or Entity Property Reports and Terrorist Property Reporting

A separate obligation from the threshold and suspicion-based reports above: all reporting entities must report property they know is owned or controlled by a listed terrorist group or a person or entity subject to specified sanctions-related orders, and must do so immediately, not within a multi-day filing window.

Other Sector-Specific Reporting Requirements

Certain sectors carry reporting obligations that do not apply generally, such as casino disbursement reporting for casinos. Whether a given reporting entity has an obligation beyond the reports above depends entirely on its specific regulated activity.

For the aggregation logic that governs when multiple smaller transactions must be combined into one report, see ComplyFactor's FINTRAC 24-hour rule guide, which applies across cash, EFT, and virtual currency reporting.

PCMLTFA Recordkeeping Requirements

Reporting entities keep several distinct categories of records, and the retention period is not the same for every category, so a single blanket rule should never appear in a compliance policy. Client identification records, transaction records, business relationship records, beneficial ownership records, PEP/HIO determination records, third-party determination records, copies of reports filed with FINTRAC, and evidence of the compliance program itself (risk assessments, training records, effectiveness review reports) are all retained, but the applicable retention period and the specific content required differ by record type and by sector-specific guidance. A compliance program should map each record category to its own retention rule rather than assuming a single figure covers everything the business keeps.

Sanctions, Listed Persons and Ministerial Directives

These are related but legally distinct controls, and treating them as interchangeable creates real gaps. AML/ATF obligations under the PCMLTFA (client identification, monitoring, STR filing) exist to detect and report suspected money laundering and terrorist financing generally. Listed-person or entity property reporting is a separate, narrower obligation: reporting entities must report property they know is owned or controlled by specified terrorist groups or sanctioned persons and entities, and the definition of a listed person or entity itself was expanded in 2025, first from March 2, 2025 to capture persons and entities subject to United Nations Act orders, and again from October 1, 2025 to capture persons and entities subject to Special Economic Measures Act orders and persons subject to orders under the Justice for Victims of Corrupt Foreign Officials Act (the Magnitsky Law).

Ministerial directives are a further, distinct tool: the Minister can direct reporting entities to apply specified enhanced measures, restrictions, or reporting requirements in relation to transactions connected to a particular foreign jurisdiction or entity of concern, functioning as a geographic countermeasure rather than a general obligation. These directives apply on top of, not instead of, a reporting entity's standard PCMLTFA obligations, and a compliance program needs a process for tracking which directives are currently active and what each one specifically requires.

What Changed Under the PCMLTFA in 2025 and 2026?

Change Status Effective / expected
Financing and leasing entities and factors become reporting entities IN FORCE April 1, 2025
Expanded "listed person or entity" definition (UN Act orders) IN FORCE March 2, 2025
Title insurers brought into scope, with adjusted KYC obligations IN FORCE October 1, 2025
Real estate brokers/sales reps must identify unrepresented parties IN FORCE October 1, 2025
Agent or mandatary may perform identity verification on a reporting entity's behalf IN FORCE October 1, 2025
Beneficial ownership discrepancy reporting to Corporations Canada (high-risk federal corporations) IN FORCE October 1, 2025
Expanded "listed person or entity" definition (SEMA orders; Magnitsky Law orders) IN FORCE October 1, 2025
Bill C-12: post-Bill C-12 effectiveness standard (reasonably designed, risk-based, effective) IN FORCE March 26, 2026 (Royal Assent)
Bill C-12: increased AMP ranges (minor $1,000 to $40,000; serious $100,000 to $4,000,000; cumulative cap $500,000 to $20M or 3% of global revenue) IN FORCE March 26, 2026 (Royal Assent)
Bill C-12: universal FINTRAC enrolment for all reporting entities LEGISLATED, NOT YET IN FORCE Tied to regulations not yet published in the Canada Gazette, Part II

For the complete detail behind the effectiveness standard and penalty changes, see ComplyFactor's Bill C-12 and the new FINTRAC effectiveness standard article.

PCMLTFA Requirements for MSBs and FMSBs

MSBs and FMSBs carry the PCMLTFA's requirements across a defined set of current activities: foreign exchange dealing, remitting or transmitting funds, issuing or redeeming money orders, traveller's cheques or similar negotiable instruments, dealing in virtual currency, crowdfunding platform services, cheque cashing, armoured car (transport) services, and acting as an acquirer for private automated banking machines. Each activity carries its own client-identification and reporting triggers rather than one uniform rule, which is why generic checklists frequently under-trigger for MSBs specifically.

For remittance and foreign exchange controls specifically, see ComplyFactor's currency exchange and remittance MSB compliance guide. For the registration process itself, see ComplyFactor's MSB registration service.

PCMLTFA and PSPs: When FINTRAC and RPAA Overlap

The PCMLTFA/FINTRAC regime and the Retail Payment Activities Act (RPAA), overseen by the Bank of Canada, are separate federal frameworks with different purposes. RPAA registration is an operational and prudential regime focused on payment safety and soundness; it is not an AML regime, and it does not, by itself, make a payment service provider a PCMLTFA reporting entity.

Many PSPs are also FINTRAC reporting entities, but that is because their actual activities, electronic funds transfers, foreign exchange dealing, or remittance, independently meet the PCMLTFA's definition of a regulated activity, not because they are registered as a PSP. A business can be registered under RPAA and have no PCMLTFA reporting-entity obligations, or be a PCMLTFA reporting entity with no RPAA obligation, or be both at once; registering with one regulator never satisfies the other framework's requirements.

For a full comparison of the two regimes, including when a business needs one, the other, or both, see ComplyFactor's MSB vs PSP licences in Canada guide. For the RPAA registration process specifically, see ComplyFactor's PSP registration service.

What Happens if a Business Does Not Comply With the PCMLTFA?

FINTRAC enforces the PCMLTFA primarily through compliance examinations, which test both whether a program is reasonably designed and whether it actually works in practice. Where an examination identifies deficiencies, FINTRAC can require corrective action, and non-compliance can result in administrative monetary penalties (AMPs). Under the post-Bill C-12 penalty framework, AMP ranges increased substantially, from roughly $1,000 to $100,000 previously, to $40,000 for minor violations and up to $4,000,000 for a single serious violation, with a cumulative cap that itself rose to $20 million or 3 percent of global revenue. In serious cases, FINTRAC can also move to revoke an MSB's registration outright, and criminal offences exist under the Act for the most serious categories of non-compliance, separate from the administrative penalty regime.

For a practical breakdown of what an examiner actually checks and how to prepare, see ComplyFactor's FINTRAC examination readiness checklist.

PCMLTFA Compliance Checklist for Canadian Businesses

Have we confirmed our current reporting-entity status against the activities we actually carry out?

Have all applicable registrations (MSB/FMSB with FINTRAC, PSP with the Bank of Canada if relevant) been completed and kept current?

Does our AML compliance program reflect our actual business, not a generic template?

Is our risk assessment business-specific, documented, and reviewed on a defined cycle?

Are current identity-verification triggers mapped to our actual transaction types and channels?

Are beneficial ownership procedures operating for entity clients, including the Corporations Canada discrepancy check where it applies?

Are PEP/HIO determination controls implemented at the correct business-relationship and transaction triggers?

Are third-party determinations configured for the transactions that require them?

Are current reporting thresholds (STR, LCTR, LVCTR, EFTR) built into our systems, not left to manual judgment alone?

Can suspicious activity actually be escalated and filed as an STR without unnecessary delay?

Are record-retention requirements mapped by record type rather than assumed to be a single universal period?

Are high-risk relationships subject to visibly different, enhanced ongoing monitoring?

Are active sanctions, listed-person, and ministerial-directive obligations incorporated into onboarding and monitoring?

Are staff and agents trained against our actual current procedures, not a superseded version?

Has program effectiveness been independently reviewed within the required two-year interval?

Can we produce complete evidence, for a sample of files, of every control above during a FINTRAC examination?

How ComplyFactor Supports PCMLTFA Compliance

Where a business needs its AML program built or rebuilt to reflect the current effectiveness standard, ComplyFactor's AML compliance program service covers the full five-pillar framework from risk assessment through governance. Where a business needs ongoing, day-to-day ownership of the program rather than a one-time build, a fractional compliance officer engagement provides that function without a full-time hire. Where the question is whether an existing program actually holds up, an independent AML audit tests it against current FINTRAC expectations and satisfies the biennial effectiveness-review requirement directly. Where deficiencies have already surfaced, whether through an internal review or a FINTRAC examination, AML advisory support helps correct them and prepare a defensible response. And for businesses that are not yet registered, MSB registration and PSP registration support covers the registration process itself, under whichever framework, or both, actually applies to the business.

Frequently Asked Questions

What does PCMLTFA stand for?

The Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Canada's core federal AML/ATF statute.

What is the purpose of the PCMLTFA?

To detect and deter money laundering and terrorist financing by requiring defined reporting entities to identify clients, assess and manage risk, monitor activity, keep records, and report specified transactions to FINTRAC.

Who must comply with the PCMLTFA in Canada?

Businesses carrying out activities the Act defines as reporting-entity activities, including financial entities, MSBs and FMSBs, securities dealers, casinos, real estate brokers and developers, life insurance companies, dealers in precious metals and stones, accountants performing certain activities, mortgage professionals, financing/leasing entities, factors, and title insurers, among others.

Is FINTRAC the regulator under the PCMLTFA?

Yes. FINTRAC (the Financial Transactions and Reports Analysis Centre of Canada) administers the PCMLTFA, receives reports, and conducts compliance examinations.

Do all PCMLTFA reporting entities need to register with FINTRAC?

Not currently. Formal registration applies specifically to MSBs and FMSBs today. A universal enrolment requirement for all reporting entities has been legislated under Bill C-12 but is not yet in force as of August 2026.

What are the main PCMLTFA compliance requirements?

A written compliance program (compliance officer, policies, risk assessment, training, effectiveness review), client identification and verification, business relationship and ongoing monitoring obligations, PEP/HIO and third-party determinations, required transaction reporting, and recordkeeping.

What records must reporting entities keep?

Client identification, transaction, business relationship, beneficial ownership, PEP/HIO determination, and third-party determination records, plus copies of reports filed and compliance-program evidence, each subject to its own retention period rather than one universal rule.

What transactions must be reported to FINTRAC?

Depending on sector and activity: suspicious transactions (any amount, suspicion-based), large cash transactions of $10,000 or more, large virtual currency transactions of $10,000 or more equivalent, qualifying international electronic funds transfers of $10,000 or more, and listed-person or terrorist property, reported immediately when identified.

How often must an AML compliance program be reviewed?

An independent effectiveness review is required at least once every two years, in addition to ongoing internal monitoring of whether the program is working.

Does the PCMLTFA apply to PSPs?

Not automatically because of RPAA registration alone. A PSP becomes a PCMLTFA reporting entity where its actual activities, such as electronic funds transfers or foreign exchange dealing, independently meet the Act's definition of a regulated activity.

What changed under the PCMLTFA in 2026?

Bill C-12 received Royal Assent on March 26, 2026, introducing a stricter three-part compliance-program effectiveness standard, substantially higher administrative monetary penalties, and a universal FINTRAC enrolment requirement for all reporting entities that is legislated but not yet in force.

Keeping Your PCMLTFA Compliance Framework Current

A defensible PCMLTFA framework connects every piece: confirmed reporting-entity status and registration, a compliance program built for the actual business rather than a template, KYC controls (identity verification, beneficial ownership, third-party determination, PEP/HIO screening) working together rather than assumed to cover each other, a risk assessment that genuinely drives enhanced measures where required, reporting thresholds built into systems rather than left to memory, records mapped to their correct retention periods, and ongoing monitoring that actually catches change in a client's risk profile. Effectiveness testing, at least every two years, is what confirms all of it still works together.

Canada's AML framework moved fast through 2025 and 2026, and it is not finished moving; universal enrolment is still coming. If your current program has not been tested against the requirements set out on this page, ComplyFactor's Canadian AML advisory team can review it before FINTRAC does.

Frequently Asked Questions

No items found.
ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.