Effectiveness review · Canada

AML/ATF effectiveness review for Canadian MSBs

A legal requirement under the PCMLTFA, not an optional health check. And the person who runs your compliance program can't be the one who reviews it.

Book free consultation

What the effectiveness review is

Under the PCMLTFA and its regulations, every reporting entity has to have its compliance program reviewed for effectiveness at least once every two years. The review covers the written policies and procedures, the risk assessment, and the training program. It isn't a formality you can settle with a signed memo.

The word that carries the weight is effectiveness. The question isn't whether the documents exist, it's whether they describe what your business actually does and whether the people in it follow them. A policy that says every high-risk client gets enhanced due diligence is only effective if the files show that happening.

The second requirement is independence. The review has to be carried out by someone who isn't responsible for running the program: either an internal person with no involvement in it, or an external reviewer. Most MSBs have nobody internal who qualifies, which is why the work usually goes outside.

What we examine

We work from your documents and your records rather than from a questionnaire. A review that only reads the policy binder tells you nothing about whether the program is being followed, so we test the program against the evidence it leaves behind.

What you receive

You receive a written report. It sets out the scope we covered and the methodology we used, the findings and deficiencies with a severity rating on each one, a remediation action plan that names an owner and a timeline for every item, and your management response recorded alongside the findings.

The report itself is the artifact. It's what FINTRAC asks for in an examination, and examiners read it as a signal of how seriously the program is taken. A short document with a column of green checkmarks says that nobody looked. A report that names real deficiencies, rates them honestly, and shows what was done about them says the opposite, even when the findings aren't flattering.

So it needs to look like it was done properly, because it was. That includes the unglamorous parts: what we sampled, how much of it, what we couldn't test and why.

Why it matters

FINTRAC examinations routinely open with a request for the last effectiveness review. If there isn't one, or if what you produce is superficial, that's a finding in itself, and it shapes everything that follows. An examiner who sees a thin review has good reason to assume the rest of the program received the same attention, and they'll look harder at all of it.

It doesn't stop with the regulator. Banks ask for the review during periodic relationship reviews, and it's among the first documents a buyer's counsel requests in due diligence when you sell the business. A documented review history, including the deficiencies you found and closed, is one of the cheaper ways to protect both relationships.

How this differs from adjacent things

Three pieces of work get confused with one another, and the distinction matters because only one of them is mandatory.

The effectiveness review

Required at least every two years. It looks backward at what your program actually did over the review period, and it has to be performed by someone independent of the program. This page is about that work.

FINTRAC examination preparation

Getting ready for the regulator's own review of your business. It looks forward, it isn't independent by design (the point is to help you), and it often starts from the findings of an effectiveness review. Useful, but it doesn't satisfy the two-year requirement.

Building the compliance program

The first step, before either of the above exists. Without written policies, a risk assessment, and a training program, there's nothing to review. If that's where you are, start with our AML/ATF compliance program service, or with outsourced CAMLO and MLRO if you need someone to run the program day to day.

Independence and conflict of interest

If BEMSB acts as your CAMLO or MLRO, we don't perform your effectiveness review. Reviewing a program we run ourselves would defeat the purpose of the requirement, and a FINTRAC examiner would say exactly that. In that situation we arrange an independent reviewer and stay out of the review itself.

It works in the other direction too. If we perform your review, we can't then take over the compliance function without changing the arrangement first, which means ending the review relationship rather than holding both roles at once.

We'd rather tell you this before you engage us than have it surface in an examination. A reviewer who is willing to review their own work is telling you something about the value of the review.

Who needs it

All registered MSBs and foreign MSBs, regardless of transaction volume. There's no small-business exemption and no threshold you can stay under. A business that registered and then went quiet still has a compliance program on file, and that program still has to be reviewed.

New MSBs are the ones most often caught out. The clock runs from when the program was implemented, not from your first transaction or your first profitable year, so the first review comes due earlier than most founders expect. If you registered a couple of years ago and have been building quietly since, it's worth checking the date on your program today.

How it works

1

Scoping: we agree the review period, the MSB activities in scope, and the documents and records we'll need from you.

2

Testing: we read the program, sample the client files and reports behind it, and speak to the people who operate it.

3

Report and remediation: findings with severity ratings, an action plan with owners and timelines, and your management response on the record.

FAQ

At least once every two years. The requirement sits in the PCMLTFA and its regulations, and the clock runs from the point your compliance program was implemented, not from your first transaction. Two years is the outer limit rather than a target: if your business model changes materially, if you add a new MSB activity, or if a bank review turns up problems, the sensible thing is to review sooner.

It can be an internal person or an external reviewer, but either way they can't be responsible for the program they're reviewing. That rules out your CAMLO, your MLRO, and anyone who wrote the policies or runs the day-to-day controls. In a small MSB there's usually nobody internal who clears that bar, which is why the work normally goes outside. Independence is about the reporting line and the conflict, not about credentials: a qualified person who reports to the CAMLO isn't independent of the CAMLO's program.

You do one now and you document the gap honestly. A missing review is a deficiency, but it's a known and fixable one, and a business that identifies it and remediates it is in a very different position from one that hides it. What you shouldn't do is produce a report dated in the past. That turns a compliance gap into a records problem you can't argue your way out of, and it's the kind of thing that changes how an examiner reads everything else you hand over.

The effectiveness review is yours. You commission it, you own the report, and you decide how to act on the findings. A FINTRAC examination is the regulator reviewing you, on their schedule and against their expectations, with enforcement available if they don't like what they find. Your review is one of the things an examination looks at, so doing it properly is part of how you get through an examination, but it isn't a substitute for one and it doesn't shield you from one.

Yes. The obligation attaches to your registration and your compliance program, not to transaction volume. If you're registered with FINTRAC you have a program, and that program has to be reviewed on the two-year cycle even if it never onboarded a client. Dormant businesses miss this more often than active ones, precisely because nothing in day-to-day operations prompts anyone to open the file. A dormant review is quicker, since there are fewer records to test, but it still has to happen and still has to be documented.

It depends on how much activity there is to test and how well organized your records are, so we scope it with you rather than quoting blind. What we ask for is consistent: the current compliance program with its version history, the risk assessment, client identification and beneficial ownership records, the reporting log with copies of what was filed, training materials and attendance evidence, and access to your CAMLO and the staff who run onboarding and monitoring. If the records are in order, most of the work is reading and sampling. If they aren't, finding that out is itself one of the more useful results.

Is your effectiveness review due?

Free 30-minute consultation. No obligations.

The map is embedded from Google Maps and loads only after you accept analytics & embedded-content cookies.

Office 723, 145 1/2 Church Street, Unit 5
Toronto, Ontario, M5B 1Y4, Canada

Loading the captcha. The send button unlocks once it appears.

Telegram