FINTRAC compliance for mortgage brokerages
FINTRAC compliance became a mortgage brokerage's own obligation in October 2024, when mortgage brokers, lenders and administrators became reporting entities in their own right. The obligations are not difficult individually — the difficulty is that they must be evidenced on every file, years later, by whoever is asked.
What changed in October 2024
Amendments to the Proceeds of Crime (Money Laundering) and Terrorist Financing Act brought mortgage brokers, mortgage lenders and mortgage administrators into scope as reporting entities, effective 11 October 2024. FINTRAC defines a mortgage broker as a person or entity “authorized under provincial legislation to act as an intermediary between a lender and a borrower” on mortgage loans — so if you hold a provincial brokerage licence, you are in. Its mortgage sector page lists every obligation and has a self-assessment tool.
Before that date the obligations largely sat with the lender at the end of the chain. They now sit with you as well.
This is a different kind of obligation from provincial licensing. Your provincial regulator supervises how you conduct business; FINTRAC supervises whether you have a functioning anti-money-laundering program and whether you can demonstrate it. The two examinations ask different questions and neither accepts the other's paperwork.
The practical consequence is that a brokerage now needs a compliance program that exists as a document, runs as a process, and leaves a record on every single file.
The law has also moved since. Bill C-12, which received Royal Assent on 26 March 2026, requires compliance programs to be reasonably designed, risk-based and effective, raised the maximum administrative monetary penalties to $4 million for a person and $20 million for an entity (section 73.1), and gave FINTRAC compliance agreements and compliance orders. If your program was written in 2024, re-read it against that standard.
This guide is an operational overview written for brokerage owners, not legal advice. FINTRAC's own guidance is the authority and it is updated regularly — confirm current requirements with FINTRAC directly, and take advice from a compliance professional before finalising your program.
The compliance program: five parts, all mandatory
A compliance program is not a binder you produce when asked. Section 156 of the regulations sets out its elements, and FINTRAC's compliance program guidance explains each. They group into five obligations, each examined separately, and a gap in any one of them is a finding on its own.
- 1
Appoint a compliance officer
A named individual with the authority to actually implement the program. In a small brokerage this is frequently the principal broker; the point is that it is a specific person with the standing to change how the firm operates, not a job title nobody has claimed.
- 2
Write policies and procedures
Documented, kept current, and approved by a senior officer. They have to describe what your firm actually does — a template downloaded and never adapted is the single most common finding, because the procedures describe a business that is not yours.
- 3
Assess your risk
A documented assessment of the money-laundering and terrorist-financing risk in your business: your clients, your products, your delivery channels, your geography, and any new technology you adopt. High-risk situations then attract enhanced measures, which is why the assessment has to come first.
- 4
Train your people
A written, ongoing training program, and a separate documented plan for delivering it, for everyone who deals with clients or handles transactions — plus a record of who was trained, on what, and when. The regulation lists the program and the plan as two items, and undocumented training did not happen as far as an examination is concerned.
- 5
Review the whole thing every two years
A documented review of the program's effectiveness every two years, carried out by your internal or external auditor — or by the brokerage itself if it has no auditor (section 156(3)). FINTRAC's guidance adds that the reviewer should not be someone directly involved in running the program. This is the pillar small firms most often miss entirely.
What has to happen on every file
The program is the frame. The obligations that generate the most work are the ones attached to each client and each transaction.
Identity verification is the visible one. FINTRAC recognises five methods — government-issued photo identification, credit file (the file must have existed for at least three years), dual-process, affiliate or member, and reliance — each with its own conditions and record requirements. Since October 2025 you can also have an agent or mandatary verify on your behalf using the first three, but the obligation stays yours. What you cannot do is verify identity one way and record it as another.
For the mortgage sector, the business relationship starts the first time you are required to verify a client's identity — not the second, as in some other sectors. From that point you owe ongoing monitoring and a record of the purpose and intended nature of the relationship.
- Verify the identity of the client using an acceptable method, and record which method, which document or source, and the date.
- For entities, confirm the entity's existence and its beneficial ownership: the directors, and every individual who directly or indirectly owns or controls 25% or more — then take separate reasonable measures to confirm it.
- Make a third party determination when you keep an information record — is someone else instructing? — and record it either way, including your reasons if you suspect one but cannot confirm it.
- Make politically exposed person and head-of-international-organisation determinations when you enter a business relationship, periodically while it lasts, and on receipt of $100,000 or more in cash or virtual currency; apply enhanced measures when one is identified.
- Keep the records for at least five years; the start point differs by record, and records must be produced within 30 days of a FINTRAC request.
- Watch for and act on FINTRAC's ministerial directives.
Record the negative determinations too. 'We checked and this client is not a PEP, on this date, by this person' is a compliant record. Silence is indistinguishable from never having checked.
Reporting obligations
Reports go to FINTRAC directly, through their reporting system, on their timelines. The one that catches people out is the suspicious transaction report, because the trigger is lower than most people assume: reasonable grounds to suspect, not proof, and it applies to attempted transactions as well as completed ones.
Suspicion is not defeated by the deal falling through. A client who withdraws once you ask for source-of-funds documentation is exactly the pattern the attempted-transaction rule exists to capture.
| Report | Trigger | Timing |
|---|---|---|
| Suspicious transaction report | Reasonable grounds to suspect a transaction — completed or attempted — relates to money laundering or terrorist financing | As soon as practicable after the measures establishing those grounds are complete |
| Listed person or entity property report | Property in your possession or control that you know is owned or controlled by or on behalf of a terrorist group or listed person (this report replaced the terrorist property report) | Immediately |
| Large cash transaction report | Receipt of $10,000 or more in cash, including two or more amounts totalling $10,000 within 24 consecutive hours | Within 15 calendar days of receiving the cash |
| Large virtual currency transaction report | Receipt of virtual currency worth $10,000 or more, subject to the same 24-hour rule | Within 5 working days of receiving it |
Never tell a client you have filed or intend to file a suspicious transaction report. Section 8 of the Act prohibits disclosing that a report has been or will be made, or its contents, with intent to prejudice a criminal investigation — whether or not one has begun. The safe practice is to disclose nothing at all.
What an examination actually asks for
An examination is a request for evidence, on a deadline, about files that closed years ago. Every brokerage believes it is compliant. The ones that come through cleanly are the ones whose records were created as the work happened.
The failure mode is not dishonesty, it is reconstruction. Somebody spends three weeks going through email trying to establish which piece of identification was seen in March two years ago and by whom. Sometimes the answer is genuinely unknowable, and an unknowable answer is a finding.
FINTRAC is required by section 73.22 of the Act to make public the nature of the violation, the name of the entity and the amount of each penalty, and its public notices stay online for five years. The reputational cost of appearing on that list is, for most brokerages, larger than the penalty.
- Your written policies and procedures, and evidence they were approved and kept current.
- Your risk assessment, and evidence that enhanced measures followed from it.
- Training records: who, what, when.
- Your last effectiveness review and what you did about its findings.
- Client identification records for named files, with the method used and the date.
- Beneficial ownership records for entity clients.
- Evidence that reports were filed when they should have been.
Build the record as the work happens
Everything above is achievable with a folder convention and discipline. It stops being achievable somewhere around the point where you have more agents than you can personally watch, because compliance then depends on the least diligent person in the firm on their busiest day.
The design principle that makes this survivable is that the compliance record should be a by-product of doing the work, not a separate task performed afterwards by someone with good intentions. If verifying a client's identity is a step in the deal, the record exists. If it is a form somebody is supposed to fill in later, it exists sometimes.
That is how compliance is built in Mortgage360: identity verification, method, date and verifier live on the deal; determinations are recorded either way; retention runs on the record rather than on someone's memory; and the principal broker can see which files are incomplete now rather than at examination time. Harvey, the compliance AI, runs PEP, sanctions and adverse-media screening and ID validation on the parties to a deal — it surfaces evidence, and a person makes the determination.
- Identity verification recorded on the deal, with the method and who performed it.
- PEP, third-party and beneficial-ownership determinations captured as answered questions, including the negatives.
- Retention tracked per record so nothing is deleted early or kept without reason.
- A live view of incomplete compliance records by agent, so gaps surface while the client is still reachable.
- An activity timeline on every change, so the question 'who did this and when' has an answer.
Test your own position with one question: pick a file that funded eighteen months ago and try to produce the identity verification record in five minutes. Whatever that exercise feels like is what an examination will feel like, multiplied by the number of files they ask for.
Sources
- Mortgage administrators, brokers and lenders: FINTRAC's requirements — FINTRAC
- Proceeds of Crime (Money Laundering) and Terrorist Financing Act, S.C. 2000, c. 17 — Justice Laws Website
- Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations, SOR/2002-184 — Justice Laws Website
- Compliance program requirements — FINTRAC
- Methods to verify the identity of persons and entities — FINTRAC
- Know your client requirements for the mortgage sector — FINTRAC
- Record keeping requirements for the mortgage sector — FINTRAC
- Reporting large cash transactions — FINTRAC
- Listed person or entity property reports — FINTRAC
- Administrative monetary penalties and the Bill C-12 changes — FINTRAC
Questions
Does this apply to a solo licensed agent?
The reporting-entity obligations attach to the brokerage, but the work happens on your files, and your brokerage's program will place requirements on you. If you are the brokerage as well as the agent, all of it is yours.
How long do we have to keep records?
At least five years, though the start point differs by record type — for a client information record it runs from the last business transaction. The practical advice is to hold to the longest applicable period rather than trying to run several clocks by hand.
Our lender verifies identity — do we still have to?
Your obligations are your own. Another reporting entity meeting its obligations does not discharge yours, and 'the lender did it' is not a record you can produce at examination.
What is the most common gap you see?
The two-year effectiveness review, followed closely by training records. Both are program-level obligations with no client sitting in front of you demanding they be done, so they are the ones that quietly never happen.
Can software make us compliant?
No — a program, a trained team and an appointed officer make you compliant. What software can do is make the evidence a by-product of the work instead of a reconstruction exercise, which is where most examination findings come from.
We will walk your compliance record with you and show you where the gaps are.
See what an examination would find
We will walk your compliance record with you and show you where the gaps are.