Coming soon: Mortgage360 mobile app for iOS & Android — Client portal + Broker portal in your pocket.
Mortgage360
Compliance guide

FINTRAC compliance for mortgage brokerages

Since October 2024, mortgage brokers, lenders and administrators have been reporting entities in their own right. The obligations are not difficult individually — the difficulty is that they must be evidenced on every file, years later, by whoever is asked.

By the Mortgage360 teamUpdated August 202612 min read

What changed in October 2024

Amendments to the Proceeds of Crime (Money Laundering) and Terrorist Financing Act brought mortgage brokers, mortgage lenders and mortgage administrators into scope as reporting entities, effective 11 October 2024. Before that date the obligations largely sat with the federally regulated lender at the end of the chain. They now sit with you as well.

This is a different kind of obligation from provincial licensing. Your provincial regulator supervises how you conduct business; FINTRAC supervises whether you have a functioning anti-money-laundering program and whether you can demonstrate it. The two examinations ask different questions and neither accepts the other's paperwork.

The practical consequence is that a brokerage now needs a compliance program that exists as a document, runs as a process, and leaves a record on every single file.

This guide is an operational overview written for brokerage owners, not legal advice. FINTRAC's own guidance is the authority and it is updated regularly — confirm current requirements with FINTRAC directly, and take advice from a compliance professional before finalising your program.

The compliance program: five parts, all mandatory

A compliance program is not a binder you produce when asked. It is five distinct obligations, each of which is examined separately, and a gap in any one of them is a finding on its own.

  1. 1

    Appoint a compliance officer

    A named individual with the authority to actually implement the program. In a small brokerage this is frequently the principal broker; the point is that it is a specific person with the standing to change how the firm operates, not a job title nobody has claimed.

  2. 2

    Write policies and procedures

    Documented, kept current, and approved by a senior officer. They have to describe what your firm actually does — a template downloaded and never adapted is the single most common finding, because the procedures describe a business that is not yours.

  3. 3

    Assess your risk

    A documented assessment of the money-laundering and terrorist-financing risk in your business: your clients, your products, your delivery channels, your geography, and any new technology you adopt. High-risk situations then attract enhanced measures, which is why the assessment has to come first.

  4. 4

    Train your people

    An ongoing training program, in writing, for everyone who deals with clients or handles transactions — plus a record of who was trained, on what, and when. Undocumented training did not happen as far as an examination is concerned.

  5. 5

    Review the whole thing every two years

    An effectiveness review of the program at least every two years, conducted by someone independent of the program's day-to-day operation, with the findings and the response documented. This is the pillar small firms most often miss entirely.

What has to happen on every file

The program is the frame. The obligations that generate the most work are the ones attached to each client and each transaction.

Identity verification is the visible one, and there is more than one acceptable method — the government-issued photo identification method, the credit file method, and the dual process method each have their own conditions and their own record requirements. What you cannot do is verify identity one way and record it as another.

  • Verify the identity of the client using an acceptable method, and record which method, which document or source, and the date.
  • For entities, confirm the entity's existence and its beneficial ownership — the individuals who ultimately own or control it, plus directors and senior officers.
  • Determine whether you are dealing with a third party — someone instructing on another's behalf — and record the determination either way.
  • Make politically exposed person and head-of-international-organisation determinations where required, and apply enhanced measures when one is identified.
  • Keep the client information record and the supporting records for the retention period — five years is the general rule.
  • Watch for and act on any applicable ministerial directives.

Record the negative determinations too. 'We checked and this client is not a PEP, on this date, by this person' is a compliant record. Silence is indistinguishable from never having checked.

Reporting obligations

Reports go to FINTRAC directly, through their reporting system, on their timelines. The one that catches people out is the suspicious transaction report, because the trigger is lower than most people assume: reasonable grounds to suspect, not proof, and it applies to attempted transactions as well as completed ones.

Suspicion is not defeated by the deal falling through. A client who withdraws once you ask for source-of-funds documentation is exactly the pattern the attempted-transaction rule exists to capture.

ReportTriggerTiming
Suspicious transaction reportReasonable grounds to suspect a transaction — completed or attempted — relates to money laundering or terrorist financingAs soon as practicable after the measures establishing those grounds are complete
Terrorist property reportProperty in your possession or control that you know is owned or controlled by or on behalf of a terrorist group or listed personImmediately
Large cash transaction reportReceipt of $10,000 or more in cash, including in two or more amounts within 24 hoursWithin the prescribed deadline for the report
Large virtual currency reportReceipt of $10,000 or more in virtual currency, subject to the same 24-hour aggregationWithin the prescribed deadline for the report

Never tell a client you have filed or intend to file a suspicious transaction report. Tipping off is a separate offence, and it is the disclosure that turns a compliance obligation into a criminal one.

What an examination actually asks for

An examination is a request for evidence, on a deadline, about files that closed years ago. Every brokerage believes it is compliant. The ones that come through cleanly are the ones whose records were created as the work happened.

The failure mode is not dishonesty, it is reconstruction. Somebody spends three weeks going through email trying to establish which piece of identification was seen in March two years ago and by whom. Sometimes the answer is genuinely unknowable, and an unknowable answer is a finding.

FINTRAC publishes administrative monetary penalties it issues, including the entity name. The reputational cost of appearing on that list is, for most brokerages, larger than the penalty.

  • Your written policies and procedures, and evidence they were approved and kept current.
  • Your risk assessment, and evidence that enhanced measures followed from it.
  • Training records: who, what, when.
  • Your last effectiveness review and what you did about its findings.
  • Client identification records for named files, with the method used and the date.
  • Beneficial ownership records for entity clients.
  • Evidence that reports were filed when they should have been.

Build the record as the work happens

Everything above is achievable with a folder convention and discipline. It stops being achievable somewhere around the point where you have more agents than you can personally watch, because compliance then depends on the least diligent person in the firm on their busiest day.

The design principle that makes this survivable is that the compliance record should be a by-product of doing the work, not a separate task performed afterwards by someone with good intentions. If verifying a client's identity is a step in the deal, the record exists. If it is a form somebody is supposed to fill in later, it exists sometimes.

That is how compliance is built in Mortgage360: identity verification, method, date and verifier live on the deal; determinations are recorded either way; retention runs on the record rather than on someone's memory; and the principal broker can see which files are incomplete now rather than at examination time.

  • Identity verification recorded on the deal, with the method and who performed it.
  • PEP, third-party and beneficial-ownership determinations captured as answered questions, including the negatives.
  • Retention tracked per record so nothing is deleted early or kept without reason.
  • A live view of incomplete compliance records by agent, so gaps surface while the client is still reachable.
  • An activity timeline on every change, so the question 'who did this and when' has an answer.

Test your own position with one question: pick a file that funded eighteen months ago and try to produce the identity verification record in five minutes. Whatever that exercise feels like is what an examination will feel like, multiplied by the number of files they ask for.

Questions

Does this apply to a solo licensed agent?

The reporting-entity obligations attach to the brokerage, but the work happens on your files, and your brokerage's program will place requirements on you. If you are the brokerage as well as the agent, all of it is yours.

How long do we have to keep records?

Five years is the general retention period, though the precise start point differs by record type. The practical advice is to hold to the longest applicable period rather than trying to run several clocks by hand.

Our lender verifies identity — do we still have to?

Your obligations are your own. Another reporting entity meeting its obligations does not discharge yours, and 'the lender did it' is not a record you can produce at examination.

What is the most common gap you see?

The two-year effectiveness review, followed closely by training records. Both are program-level obligations with no client sitting in front of you demanding they be done, so they are the ones that quietly never happen.

Can software make us compliant?

No — a program, a trained team and an appointed officer make you compliant. What software can do is make the evidence a by-product of the work instead of a reconstruction exercise, which is where most examination findings come from.

See what an examination would find

We will walk your compliance record with you and show you where the gaps are.

Ready when you are

See what an examination would find

We will walk your compliance record with you and show you where the gaps are.