- Businesses in the sectors that Canada's anti-money laundering framework designates as "reporting entities" — a defined list that includes money services businesses, certain real estate…
- A functioning compliance program generally needs to address each of the following: - [ ] A designated compliance officer — a specific individual, which in a small business may be the…
- Regulators reviewing a compliance program tend to ask not just whether a policy document exists, but whether it's actually being followed.
If your Ontario business falls into one of the sectors regulated under federal anti-money laundering law — money services, real estate, certain insurance activities, and others — having a compliance program isn't optional paperwork. It's a legal requirement, and regulators expect the program to actually function, not just exist on paper.
This article walks through the components a baseline anti-money laundering compliance program typically needs to include, so you know what you're building toward before you start.
Who Needs One
Businesses in the sectors that Canada's anti-money laundering framework designates as "reporting entities" — a defined list that includes money services businesses, certain real estate professionals, life insurance companies and intermediaries, securities dealers, casinos, and several other categories — are generally required to maintain a compliance program. If you're not sure whether your business falls into a regulated category, resolve that question first; the specifics of the program only matter once you know it applies to you.
The Core Components of a Baseline Program
A functioning compliance program generally needs to address each of the following:
- [ ] A designated compliance officer — a specific individual, which in a small business may be the owner, responsible for the program.
- [ ] Written compliance policies and procedures — documenting how your business identifies clients, assesses risk, and reports as required, rather than relying on informal practice.
- [ ] A documented risk assessment — an honest assessment of where your specific business is most exposed to money laundering or terrorist financing risk, considering your clients, products, delivery channels, and geography.
- [ ] An ongoing training program — for anyone in the business who deals with clients or transactions covered by the rules, not just a one-time onboarding session.
- [ ] A periodic effectiveness review — a review of whether the program is actually working, generally expected at a set interval and, depending on the size of the business, carried out by someone independent of the program's day-to-day operation.
Why "Written and Filed Away" Isn't Enough
Regulators reviewing a compliance program tend to ask not just whether a policy document exists, but whether it's actually being followed. A program that exists only on paper — never updated, never trained on, never tested — creates the appearance of compliance without the substance, and that gap is precisely what a regulatory review is designed to find.
Building a Program That Fits Your Business
A compliance program should be proportionate to your business's actual size and risk — a two-person money services business and a large multi-branch operation will reasonably have very different programs, even though both need to cover the same core components. Steps that generally help:
- Confirm your reporting-entity status and which specific obligations apply to your sector.
- Assign the compliance officer role explicitly, in writing.
- Draft policies that reflect what your business actually does, rather than adapting a generic template you don't fully understand.
- Schedule training and the periodic effectiveness review as recurring items, not one-time tasks.
- Revisit the whole program whenever your business changes — new services, new locations, or new ownership can all change your risk profile.
Getting Help Building or Reviewing a Program
Many regulated businesses use a combination of legal advice, to confirm status and review the legal sufficiency of policies, and a compliance consultant, to help implement day-to-day procedures and training. For a business building its first program, starting with a lawyer to confirm scope and legal requirements is usually the more efficient first step.
Frequently asked questions
Do I need a lawyer to write my compliance program, or can I use a template?
A template can be a useful starting point, but a program that doesn't reflect your actual business and risks is unlikely to satisfy a regulator on review. Having a lawyer or qualified compliance professional confirm the program is legally sufficient and genuinely fits your business is worth the investment.
How often does the program need to be reviewed?
Regulated businesses are generally expected to review their compliance program's effectiveness at a set interval. The current specifics are set out in FINTRAC's guidance and change from time to time, so confirm the current requirement rather than relying on an assumed schedule.
What happens during a compliance review or audit?
A regulator or examiner will typically look at whether your policies exist, whether staff have actually been trained on them, and whether your records show the program being followed in practice, not just whether a policy binder exists.
My business is very small — do I still need all five components?
Generally yes, at a scale proportionate to your business. Being small can shape how simple the program is, but it doesn't usually remove the underlying legal requirement to have each component in some form.
This is a corporate question
Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.