Canada KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Canada.
- Dernière revue
- Dernière revue:
- Version
- Version 1.1

Réponse directe
Que couvre la checklist de conformité pour Canada ?
La checklist pour Canada traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 44 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Primary AML framework
- PCMLTFA and its regulations, with sector-specific reporting-entity duties
- Financial intelligence unit
- Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
- Suspicious transaction report
- No monetary threshold; submit as soon as practicable after reasonable grounds to suspect are established
- Large cash report
- CAD 10,000 or more, including qualifying 24-hour aggregation; file within 15 calendar days
- Large virtual-currency report
- CAD 10,000 equivalent or more, including qualifying 24-hour aggregation; file within 5 working days
- International EFT report
- CAD 10,000 or more for prescribed initiation or final-receipt roles; file within 5 business days
- AML beneficial ownership
- Individuals directly or indirectly owning or controlling at least 25%, plus ownership and control structure
- CBCA significant control
- 25% voting rights or fair-market-value shares, or control in fact; federal corporations have register and filing duties
- Core AML retention
- Generally at least 5 years, but the event starting the clock varies by record
- MSB registration
- Canadian and qualifying foreign MSBs must register with FINTRAC before operating
- Retail payment providers
- In-scope PSPs must register with the Bank of Canada and meet operational-risk and safeguarding rules
- FATF public lists
- Canada was not named on the FATF public-list page reviewed 31 July 2026
Détail d’implémentation
Exigences et actions de conformité pour Canada
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and licensing perimeterResolve the legal entity, activities, customers, delivery model and provincial nexus first. Federal AML registration or reporting status does not replace another federal or provincial authorization.4 éléments+
PCMLTFA obligations apply to the persons and entities in section 5, with detailed duties that vary by reporting-entity category and activity.
- Action d’implémentation
- Map each entity, product and flow to the applicable section 5 category and regulations before assigning controls.
- Preuves à conserver
- Signed perimeter memorandum, activity map, reporting-entity classification, regulator mapping and legal conclusions.
- Source primaire
- PCMLTFA, ss. 5-6; FINTRAC, Who must report
Canadian MSBs and foreign MSBs that direct and provide prescribed services to persons or entities in Canada must register with FINTRAC before beginning covered operations.
- Action d’implémentation
- Classify foreign exchange, remittance, money-order, crowdfunding and virtual-currency services; complete registration before launch and keep registration information current.
- Preuves à conserver
- Service analysis, registration application, FINTRAC number, registry extract, renewal calendar and change filings.
- Source primaire
- PCMLTFA, ss. 11.1-11.2; FINTRAC, Money services businesses
An in-scope payment service provider must be registered with the Bank of Canada before performing retail payment activities, subject to the RPAA geographic test and exclusions.
- Action d’implémentation
- Apply the five payment-function test, geographic scope and exclusions; obtain registration before launch and separately assess FINTRAC MSB status.
- Preuves à conserver
- RPAA scope memo, registration decision, public-registry extract and AML registration reconciliation.
- Source primaire
- RPAA, ss. 2, 4-6 and 23; Bank of Canada, Criteria for registering PSPs
Provincial laws can separately regulate money services, securities, consumer contracts, privacy and corporate records.
- Action d’implémentation
- Build a province-by-province matrix for every customer and operating nexus; document licences, registrations and exemptions before service begins.
- Preuves à conserver
- Provincial matrix, regulator correspondence, licences, exemptions, counsel advice and renewal controls.
- Source primaire
- FINTRAC, MSB guidance; Bank of Canada, RPAA registration criteria
02Compliance program, governance and risk assessmentA reporting entity's program must be reasonably designed, risk-based and effective, not a generic policy pack detached from its Canadian activities.4 éléments+
Every reporting entity must establish and implement the prescribed compliance program and ensure it is reasonably designed, risk-based and effective.
- Action d’implémentation
- Obtain senior approval for a program mapped to the entity's category, products, customers, channels, geography and sanctions-evasion exposure.
- Preuves à conserver
- Approved program, legal mapping, board record, risk appetite, control inventory and accountable owners.
- Source primaire
- PCMLTFA, s. 9.6(1)-(2); PCMLTFR, s. 156
The program includes a compliance officer, written policies and procedures, documented risk assessment, ongoing training and an effectiveness review at least every two years.
- Action d’implémentation
- Appoint an empowered officer, calendar training and independent testing, and track findings to verified closure.
- Preuves à conserver
- Appointment, role charter, policy set, risk assessment, training logs, two-year review and remediation register.
- Source primaire
- PCMLTFR, s. 156; FINTRAC, Compliance program requirements
High-risk situations require prescribed special measures, including enhanced identification, relationship information and ongoing monitoring measures appropriate to the risk.
- Action d’implémentation
- Define high-risk triggers and enhanced controls, approvals, review frequency and transaction monitoring; record the rationale for residual risk.
- Preuves à conserver
- Risk methodology, high-risk file, enhanced checks, approvals, monitoring results and exception log.
- Source primaire
- PCMLTFA, s. 9.6(3); PCMLTFR, s. 157
Use of an agent, mandatary or service provider does not remove the reporting entity's responsibility; MSBs also have current duties to review agent eligibility and criminal records.
- Action d’implémentation
- Perform pre-appointment and prescribed periodic agent checks, contract for compliance evidence, monitor performance and retain exit capability.
- Preuves à conserver
- Eligibility review, criminal-record material, contract, agent list, oversight reports, issues and termination plan.
- Source primaire
- PCMLTFA, ss. 9.92-9.93; PCMLTFR, ss. 37.1 and 133; FINTRAC, MSB guidance
03Natural-person identification and verificationIdentity triggers and permitted methods depend on the reporting-entity sector and transaction. Configure the precise rule, not a single universal onboarding threshold.4 éléments+
FINTRAC permits prescribed verification methods including government-issued photo identification, Canadian credit file, dual process, qualifying affiliate or member confirmation, and reliance arrangements.
- Action d’implémentation
- Configure methods by sector and use case; retain required details showing the source was authentic or reliable, valid and current.
- Preuves à conserver
- Method matrix, vendor configuration, source details, verification result, timestamps and quality tests.
- Source primaire
- PCMLTFR, ss. 105-109; FINTRAC, Methods to verify identity
Remote use of government-issued photo identification requires a process that authenticates the document and matches it to the person; collecting an image alone is insufficient.
- Action d’implémentation
- Test document security, liveness or person match as appropriate, fraud signals, accessibility and manual escalation before accepting remote identity.
- Preuves à conserver
- Authentication specification, vendor tests, decision logs, fraud review, exceptions and sampled files.
- Source primaire
- FINTRAC, Methods to verify identity, government-issued photo ID method
Identity must be verified at the prescribed sector and transaction triggers, including suspicious completed or attempted transactions regardless of amount where the rule applies.
- Action d’implémentation
- Map every account, service and transaction trigger to timing, method and exceptions; route failed or incomplete verification to a controlled decision before proceeding.
- Preuves à conserver
- Trigger matrix, workflow rules, attempted-transaction records, restrictions, closure decisions and STR assessment.
- Source primaire
- PCMLTFR, ss. 83-104 and 154; FINTRAC, When to verify identity
An agent or mandatary used for verification must operate under the prescribed written arrangement and provide the information needed for the reporting entity's records.
- Action d’implémentation
- Execute a compliant agreement, validate the agent's method, retrieve evidence promptly and test the arrangement periodically.
- Preuves à conserver
- Agreement, agent due diligence, method records, retrieval tests, sample reviews and corrective actions.
- Source primaire
- PCMLTFR, ss. 109 and 109.1; FINTRAC identity-method guidance
04KYB, registries and beneficial ownershipKeep AML beneficial ownership under the PCMLTFR separate from a corporation's own ISC duties. Provincial entities also require their own registry analysis.4 éléments+
Entity verification uses prescribed sources to confirm existence and requires the reporting entity to record the relevant incorporation, registration or governing details.
- Action d’implémentation
- Obtain current registry and constitutional material, verify status and authority, and identify persons authorized to bind or instruct for the entity.
- Preuves à conserver
- Registry extract, constituting documents, business number, addresses, directors, signatory authority and verification log.
- Source primaire
- PCMLTFR, ss. 106-109; FINTRAC, Methods to verify identity
For a corporation, AML records include directors, individuals directly or indirectly owning or controlling at least 25% of shares, and information establishing ownership, control and structure; trusts and other entities have tailored tests.
- Action d’implémentation
- Trace every ownership layer to natural persons, calculate direct and indirect interests, record control and trust parties, and document when nobody reaches 25%.
- Preuves à conserver
- Ownership chart, calculations, director list, trust records, source documents, confirmation steps and approvals.
- Source primaire
- PCMLTFR, s. 138; FINTRAC, Beneficial ownership requirements
Beneficial-ownership accuracy must be reasonably confirmed initially and during ongoing monitoring; prescribed high-risk CBCA cases require consultation of public ISC information. A material discrepancy must be reported within 30 days unless resolved within that period.
- Action d’implémentation
- Compare customer data with reliable records and the federal ISC registry when required; resolve the discrepancy within 30 days or submit the prescribed report and retain the acknowledgement.
- Preuves à conserver
- Registry search, comparison record, discrepancy case, customer clarification, Schedule 7 report and receipt.
- Source primaire
- PCMLTFR, ss. 138(2)-(5), 138.1 and Schedule 7
Most CBCA corporations maintain an ISC register and file ISC information with Corporations Canada; significant control includes at least 25% of voting rights or fair-market-value shares and control in fact.
- Action d’implémentation
- For a federal corporation, identify ISCs, update the register at least annually and within 15 days of known changes, and make the required event and annual filings.
- Preuves à conserver
- ISC register, annual enquiry, shareholder responses, change log, filings, receipts and exemption record.
- Source primaire
- CBCA, ss. 2.1, 21.1 and 21.21; Corporations Canada, ISC filing guidance
05PEPs, HIOs and enhanced due diligenceCanadian PEP and head-of-international-organization duties vary by sector, account, relationship and transaction. Family-member and close-associate scope must follow the precise rule.4 éléments+
Financial entities, securities dealers and casinos have prescribed account-related duties to determine PEP, HIO, family-member and specified close-associate status at opening, through periodic monitoring and when relevant facts are detected.
- Action d’implémentation
- Screen at each legal trigger, capture relationship and office details, and route possible matches to trained adjudication.
- Preuves à conserver
- Screening configuration, match evidence, periodic-monitoring log, relationship analysis and disposition.
- Source primaire
- PCMLTFR, ss. 121-123; FINTRAC, Account-based PEP and HIO guidance
Specified sectors have transaction-related PEP and HIO determinations for prescribed transactions of CAD 100,000 or more, including certain international EFT and virtual-currency events.
- Action d’implémentation
- Configure the exact sector and transaction triggers, aggregation where required, determination steps and escalation.
- Preuves à conserver
- Trigger rules, transaction sample, determination record, relationship data, approval and monitoring case.
- Source primaire
- PCMLTFR, ss. 121-123; FINTRAC, Account-based PEP and HIO guidance
A foreign PEP determination triggers prescribed source-of-funds and source-of-wealth measures, senior-management review and enhanced ongoing monitoring for account-based sectors.
- Action d’implémentation
- Establish and corroborate wealth and funds, obtain the required senior decision, define enhanced scenarios and review the relationship at the prescribed cadence.
- Preuves à conserver
- Wealth narrative, source documents, senior approval, enhanced-monitoring plan, alerts and periodic review.
- Source primaire
- PCMLTFR, ss. 121-123; FINTRAC, PEP and HIO guidance
Domestic PEP and HIO status requires a risk determination rather than an automatic prohibition; prescribed measures follow when the relationship is high risk.
- Action d’implémentation
- Document the risk assessment and apply enhanced measures proportionately, without treating status alone as proof of criminality.
- Preuves à conserver
- Risk decision, supporting factors, enhanced checks, approvals, monitoring and review record.
- Source primaire
- PCMLTFR, ss. 121-123; FINTRAC, PEP and HIO guidance
06Monitoring, suspicious reporting and confidentialitySuspicion reporting has no monetary threshold. Case records must show when reasonable grounds to suspect were established and why submission was timely.4 éléments+
A reporting entity submits an STR for a completed or attempted transaction when there are reasonable grounds to suspect a connection to money laundering, terrorist activity financing or sanctions evasion.
- Action d’implémentation
- Monitor relevant activity, connect indicators to facts and context, and document the legal threshold for both filing and non-filing outcomes.
- Preuves à conserver
- Scenario inventory, alerts, linked activity, investigation notes, decision rationale and STR receipt.
- Source primaire
- PCMLTFA, s. 7; Suspicious Transaction Reporting Regulations, s. 9; FINTRAC STR guidance
The STR is due as soon as practicable after completing the measures that enable the entity to establish reasonable grounds to suspect; there is no fixed monetary threshold or ordinary day count.
- Action d’implémentation
- Timestamp detection, investigation and threshold decisions; prioritize submission and record a suitable explanation for any delay.
- Preuves à conserver
- Case chronology, threshold approval, queue metrics, delay rationale, filing time and acknowledgement.
- Source primaire
- Suspicious Transaction Reporting Regulations, s. 9(2); FINTRAC, Reporting suspicious transactions
Subsequent suspicious transactions remain reportable while suspicion persists, and a threshold report does not replace an STR.
- Action d’implémentation
- Link related cases and reports, reassess the customer periodically, and file every separately applicable cash, virtual-currency or EFT report.
- Preuves à conserver
- Related-report references, customer reassessment, filing reconciliation and monitoring history.
- Source primaire
- FINTRAC, Reporting suspicious transactions, sections 7-8
A person must not disclose an STR or its contents with the intent to prejudice a criminal investigation.
- Action d’implémentation
- Restrict STR access, prevent customer-facing tipping off, control legal and law-enforcement requests, and train staff on permitted handling.
- Preuves à conserver
- Access list, audit logs, training, disclosure procedure, tested response and incident records.
- Source primaire
- PCMLTFA, s. 8; FINTRAC STR guidance
07Cash, virtual currency, EFTs and the travel ruleBuild separate reporting decisions for cash, virtual currency and international electronic funds transfers. Apply the current 24-hour aggregation mechanics and exceptions for each report type.4 éléments+
A reporting entity generally files an LCTR after receiving CAD 10,000 or more in cash in one transaction or qualifying aggregated transactions within a consecutive 24-hour window, subject to exceptions.
- Action d’implémentation
- Aggregate by the prescribed conductor, third-party or beneficiary relationship, identify required parties and file within 15 calendar days after receipt.
- Preuves à conserver
- Aggregation logic, LCTR, acknowledgement, identity and third-party records, exception and reconciliation.
- Source primaire
- PCMLTFR, ss. 126 and 132(3); FINTRAC LCTR and 24-hour-rule guidance
A reporting entity in scope generally files an LVCTR after receiving virtual currency worth CAD 10,000 or more in one transaction or qualifying 24-hour aggregation.
- Action d’implémentation
- Apply the prescribed valuation, receipt and aggregation rules; capture wallet and transaction details and file within 5 working days.
- Preuves à conserver
- Valuation source, wallet data, aggregation output, LVCTR, receipt, exceptions and quality review.
- Source primaire
- PCMLTFR, ss. 125, 126 and 132(4); FINTRAC LVCTR guidance
Prescribed financial entities, MSBs, foreign MSBs and casinos report initiation or final receipt of qualifying international EFTs of CAD 10,000 or more, including applicable 24-hour aggregation.
- Action d’implémentation
- Determine the entity's role, cross-border character and aggregation; file within 5 business days after initiation or final receipt.
- Preuves à conserver
- Funds-flow map, transaction data, aggregation test, EFTR, acknowledgement and filing reconciliation.
- Source primaire
- PCMLTFR, ss. 127-129 and 132(1); FINTRAC EFT guidance
The travel rule requires specified originator and beneficiary information to accompany prescribed EFT and virtual-currency transfers; recipients take reasonable measures when information is missing.
- Action d’implémentation
- Configure mandatory message fields, preserve received information, hold or reject according to a documented risk-based policy, and test intermediaries and vendors.
- Preuves à conserver
- Message specification, transfer samples, missing-data cases, disposition rationale, vendor tests and monitoring.
- Source primaire
- PCMLTFA, s. 9.5; PCMLTFR, ss. 124-124.1; FINTRAC travel-rule guidance
08Targeted financial sanctions and listed propertyCanada's sanctions programs are regulation-specific. The consolidated autonomous list is a useful screening aid but has no force of law and does not replace the operative schedules and prohibitions.4 éléments+
Canadian persons and persons in Canada must comply with applicable prohibitions and dealing restrictions under the Criminal Code, United Nations Act, SEMA, JVCFOA and program-specific regulations.
- Action d’implémentation
- Map products, persons, ownership, control, geography and activity to every applicable regulation and screen against current operative schedules.
- Preuves à conserver
- Sanctions perimeter, regulation inventory, list versions, screening logs, ownership analysis and legal decisions.
- Source primaire
- United Nations Act; SEMA; JVCFOA; Global Affairs Canada, Current sanctions
The consolidated Canadian autonomous sanctions list is administrative and may lag amendments; the relevant regulation determines who is listed and what prohibition applies.
- Action d’implémentation
- Use the consolidated list for detection but verify every potential match against the current regulation and schedule before disposition.
- Preuves à conserver
- Screening hit, regulatory verification, identity evidence, disposition, approval and list-update testing.
- Source primaire
- Global Affairs Canada, Consolidated Canadian Autonomous Sanctions List
Where the statutory trigger is met, listed person or entity property must be reported to FINTRAC without delay, in addition to disclosures, freezes or other action required by the underlying law.
- Action d’implémentation
- Freeze or restrict as the operative rule requires, escalate immediately, submit the FINTRAC property report and make every other required disclosure without tipping off.
- Preuves à conserver
- Property record, freeze or restriction, legal analysis, FINTRAC report, authority disclosure and timestamps.
- Source primaire
- PCMLTFA, s. 7.1; FINTRAC, Reporting listed person or entity property
A completed or attempted transaction suspected to relate to sanctions evasion also requires an STR; a property report does not replace that assessment.
- Action d’implémentation
- Run a separate reasonable-grounds-to-suspect assessment, file promptly when met and link related property and transaction reports.
- Preuves à conserver
- Sanctions-evasion case, facts and indicators, STR decision, filings, cross-references and acknowledgement.
- Source primaire
- PCMLTFA, ss. 2 and 7; FINTRAC, Report suspected sanctions evasion
09Records, retrieval and regulator accessFive years is common in the AML regulations, but the event that starts the clock depends on the record. Keep a record-level schedule rather than applying one deletion date to every file.4 éléments+
Records required by the PCMLTFR are generally retained for at least five years after the record-specific event, such as the transaction, account closure or last business transaction.
- Action d’implémentation
- Map each record class to its exact trigger and legal hold; prevent early deletion and dispose securely when retention and other-law needs end.
- Preuves à conserver
- Retention schedule, trigger mapping, system rules, legal holds, deletion certificates and sampled records.
- Source primaire
- PCMLTFR, s. 148; FINTRAC record-keeping guidance
Required records may be electronic if a paper copy can readily be produced and must be retrievable in the form and time required by FINTRAC.
- Action d’implémentation
- Preserve authenticity, readability and linkages; test regulator retrieval across customers, accounts, transactions, reports and source evidence.
- Preuves à conserver
- Data map, retrieval test, access logs, export sample, backup restore and issue remediation.
- Source primaire
- PCMLTFR, ss. 147-149
Beneficial-ownership records are kept for at least five years after the last business transaction, and STR-related records have their own prescribed retention requirements.
- Action d’implémentation
- Create separate clocks for business relationships, beneficial ownership, transaction records and report copies; record the closure or last-transaction event.
- Preuves à conserver
- Customer timeline, beneficial-owner record, STR copy, clock calculation and retention test.
- Source primaire
- PCMLTFR, ss. 138(5) and 148; Suspicious Transaction Reporting Regulations
Outsourcing storage or case management does not transfer accountability for complete, secure and prompt production.
- Action d’implémentation
- Contract for Canadian legal requirements, access, export, preservation, incident notice and exit; exercise retrieval and migration periodically.
- Preuves à conserver
- Vendor contract, data locations, access controls, retrieval exercise, incident test and exit package.
- Source primaire
- PCMLTFA, ss. 6 and 62; PCMLTFR, ss. 147-149
10Privacy, biometrics and transfersResolve whether PIPEDA, a substantially similar provincial law, sector law or several regimes apply. AML retention authority does not authorize unrelated collection or indefinite reuse.4 éléments+
PIPEDA requires accountability, identified purposes, appropriate consent where required, collection limitation, safeguards, access and retention controls for personal information in scope.
- Action d’implémentation
- Map every KYC data element and purpose, identify legal authority and consent, minimize collection, control access and set defensible retention and deletion.
- Preuves à conserver
- Data inventory, purpose and authority register, notices, consent record, access matrix, retention and privacy assessment.
- Source primaire
- PIPEDA, ss. 5-7 and Schedule 1; OPC, Privacy Guide for Businesses
Biometric templates and identity signals can be sensitive personal information; necessity, effectiveness, proportionality, consent and security must be assessed in the applicable jurisdiction.
- Action d’implémentation
- Complete a privacy impact assessment before biometric use, document alternatives and bias testing, separate templates, limit reuse and provide deletion controls.
- Preuves à conserver
- Privacy impact assessment, necessity test, consent flow, model tests, security design, vendor terms and deletion proof.
- Source primaire
- PIPEDA, ss. 5-7 and Schedule 1; OPC guidance on biometrics and sensitive information
Under PIPEDA, a breach posing a real risk of significant harm must be reported to the OPC and notified to affected individuals as soon as feasible; records of every safeguards breach are kept for 24 months.
- Action d’implémentation
- Assess harm promptly, document the decision, report and notify when required, inform relevant third parties, and retain the complete breach record.
- Preuves à conserver
- Incident chronology, harm assessment, OPC report, notices, third-party communications and 24-month record control.
- Source primaire
- PIPEDA, ss. 10.1-10.3; Breach of Security Safeguards Regulations, s. 6
An organization remains accountable for personal information transferred to a processor, including processing outside Canada, and must use contractual or other means to provide comparable protection.
- Action d’implémentation
- Map locations and sub-processors, assess legal-access and security risk, contract for comparable safeguards, disclose cross-border practices and test deletion and return.
- Preuves à conserver
- Transfer map, vendor assessment, contract, transparency notice, security review, audit and exit evidence.
- Source primaire
- PIPEDA Schedule 1, principles 4.1.3 and 4.8; OPC cross-border processing guidance
11Payments, agents and practical evidence packsTurn the legal perimeter into testable launch gates. Payment providers may simultaneously face RPAA, FINTRAC and provincial obligations.4 éléments+
Since 8 September 2025, in-scope PSPs must maintain the prescribed operational-risk and incident-response framework and safeguard end-user funds when they hold them.
- Action d’implémentation
- Implement the written frameworks, map systems and third parties, test incidents, reconcile safeguarded funds and obtain legal support for the safeguarding arrangement.
- Preuves à conserver
- Frameworks, risk register, incident exercise, safeguarding legal analysis, daily reconciliation, exceptions and remediation.
- Source primaire
- RPAA, ss. 17-20; RPAR, ss. 5-17; Bank of Canada supervisory framework
Registered PSPs submit an annual report by 31 March following the reporting year and make other prescribed change, incident and new-activity reports.
- Action d’implémentation
- Maintain a Bank of Canada obligations calendar, assign owners and reconcile every report to source data and registration information.
- Preuves à conserver
- Calendar, annual report, source reconciliation, change notices, incident reports, acknowledgements and approvals.
- Source primaire
- RPAA, ss. 21 and 22; RPAR, ss. 18-20; Bank of Canada reporting guidance
A reporting entity remains responsible for activities performed through agents or service providers and must maintain evidence that delegated controls operate effectively.
- Action d’implémentation
- Define responsibility, data and escalation in contracts; test onboarding, monitoring, reporting, privacy and sanctions controls end to end.
- Preuves à conserver
- Responsibility matrix, contracts, control tests, case samples, service metrics, findings and verified remediation.
- Source primaire
- PCMLTFR, s. 133; RPAA, s. 87; Bank of Canada registration guidance
Each checklist row requires an explicit applicability decision, owner, current source and reconstructable operating evidence before launch.
- Action d’implémentation
- Mark each row applicable, not applicable or pending legal confirmation; close blockers and obtain compliance, privacy, security and product approvals.
- Preuves à conserver
- Completed checklist, applicability rationale, source snapshot, owner sign-off, test result, gap ticket and launch approval.
- Source primaire
- PCMLTFA, s. 9.6; PCMLTFR, s. 156; RPAA, ss. 17-20
Registre des sources primaires
35 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Proceeds of Crime (Money Laundering) and Terrorist Financing ActJustice Laws Website · Primary legislation
- Proceeds of Crime (Money Laundering) and Terrorist Financing RegulationsJustice Laws Website · Primary regulation
- Suspicious Transaction Reporting RegulationsJustice Laws Website · Primary regulation
- FINTRAC obligations and guidance directoryFINTRAC · Official regulator guidance
- Compliance program requirementsFINTRAC · Official regulator guidance
- Methods to verify the identity of persons and entitiesFINTRAC · Official regulator guidance
- When to verify identity - factorsFINTRAC · Official regulator guidance
- Beneficial ownership requirementsFINTRAC · Official regulator guidance
- PEP and HIO guidance for account-based sectorsFINTRAC · Official regulator guidance
- Reporting suspicious transactionsFINTRAC · Official regulator guidance
- Reporting large cash transactionsFINTRAC · Official regulator guidance
- Reporting large virtual currency transactionsFINTRAC · Official regulator guidance
- Reporting electronic funds transfersFINTRAC · Official regulator guidance
- Reporting transactions under the 24-hour ruleFINTRAC · Official regulator guidance
- Travel rule for EFT and virtual-currency transfersFINTRAC · Official regulator guidance
- Reporting listed person or entity propertyFINTRAC · Official regulator guidance
- FINTRAC money services business guidanceFINTRAC · Official regulator guidance
- Money Services Business RegistryFINTRAC · Official register
- Canada Business Corporations ActJustice Laws Website · Primary legislation
- Individuals with significant controlCorporations Canada · Official registry guidance
- ISC filing requirementsCorporations Canada · Official registry guidance
- United Nations ActJustice Laws Website · Primary legislation
- Special Economic Measures ActJustice Laws Website · Primary legislation
- Current sanctions imposed by CanadaGlobal Affairs Canada · Official government guidance
- Consolidated Canadian Autonomous Sanctions ListGlobal Affairs Canada · Official administrative screening list
- Personal Information Protection and Electronic Documents ActJustice Laws Website · Primary legislation
- Breach of Security Safeguards RegulationsJustice Laws Website · Primary regulation
- Privacy Guide for BusinessesOffice of the Privacy Commissioner of Canada · Official regulator guidance
- Privacy breaches at your businessOffice of the Privacy Commissioner of Canada · Official regulator guidance
- Retail Payment Activities ActJustice Laws Website · Primary legislation
- Retail Payment Activities RegulationsJustice Laws Website · Primary regulation
- Retail payments supervisory frameworkBank of Canada · Official regulator framework
- Criteria for registering payment service providersBank of Canada · Official regulator guidance
- FATF Canada country pageFinancial Action Task Force · Official international assessment
- FATF black and grey listsFinancial Action Task Force · Official current-status source
Réponses directes
Questions KYC, KYB et AML pour Canada
Is every Canadian business a FINTRAC reporting entity?+
No. PCMLTFA section 5 and the regulations define covered categories and activities. Classify the entity and each product before applying reporting, verification or record-keeping duties.
When is a suspicious transaction report due?+
As soon as practicable after the reporting entity completes the measures that establish reasonable grounds to suspect a completed or attempted transaction relates to money laundering, terrorist financing or sanctions evasion. There is no monetary threshold.
What are the major CAD 10,000 reports?+
Depending on reporting-entity type and transaction, CAD 10,000 can trigger large cash, large virtual-currency or international EFT reporting, including prescribed 24-hour aggregation. Their scope and deadlines differ.
What is Canada's AML beneficial-ownership threshold?+
For corporations and many other entities, FINTRAC rules focus on individuals who directly or indirectly own or control at least 25%. The reporting entity must also understand ownership, control and structure and apply tailored trust rules.
Is the CBCA ISC register the same as FINTRAC beneficial ownership?+
No. They overlap but have different legal actors and duties. Federal corporations maintain and file ISC information; reporting entities separately collect and confirm beneficial ownership under the PCMLTFR.
Must an MSB register before launch?+
Yes. A Canadian MSB, and a qualifying foreign MSB directing covered services at Canada, must register with FINTRAC before operating. Registration is not a licence or endorsement and does not replace provincial requirements.
Does a payment provider need both FINTRAC and Bank of Canada registration?+
Potentially. FINTRAC MSB status and RPAA payment-service-provider status use different activity and scope tests. A business can fall within both and may also face provincial requirements.
What is the core AML retention period?+
Many required records are kept for at least five years, but the event that starts the period differs by record. Use a record-level schedule rather than one universal deletion date.
What is the PIPEDA breach deadline?+
Where a breach creates a real risk of significant harm, report to the OPC and notify affected individuals as soon as feasible. Keep records of every safeguards breach for 24 months, while checking provincial and sector overlays.
Is Canada on a FATF public list?+
Canada was not named on FATF's current public-list page reviewed on 31 July 2026. It remains a FATF member with published assessment and follow-up history.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
This checklist is general regulatory information, not legal advice, a licence determination or a statement that every row applies to every Canadian business. It reflects primary and authoritative material reviewed on 31 July 2026. Confirm entity type, reporting-entity category, activity, customer, province or territory, incorporation jurisdiction, regulator, registration and licensing perimeter, live FINTRAC reporting instructions, sanctions regulations, privacy scope and later legal developments with qualified Canadian counsel and the competent authorities before launch.