EST · MMXXVI
Home/Jurisdictions/Canada/AML/cft policy drafting in Canada: Legal Requirements for Businesses
Compliance, AML & Travel Rule

AML/cft policy drafting in Canada: Legal Requirements for Businesses

Aml/cft policy drafting in Canada. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Canada requires every virtual asset service provider (VASP) – a business that exchanges, transfers or deals in virtual assets – to register with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) and to maintain a written, board-approved AML/CFT compliance program before accepting a single client transaction. Without that program in place, a business faces account closures, regulatory penalties and, in the worst cases, criminal exposure for the directors who signed off on operations. The path through the FINTRAC regime is well-defined; the difficulty lies in translating the regime's requirements into a policy document that survives a live examination.

This page maps the legal basis for AML/CFT policy drafting in Canada, the structural components FINTRAC expects, the cross-border obligations that catch foreign operators by surprise, and the decision points every compliance team should reach before the program goes live.

The Canadian AML/CFT Regime for Virtual Asset Businesses

Canada's AML/CFT regime is anchored in the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and the associated Regulations administered by FINTRAC. Since 2021, the regime has applied explicitly to businesses dealing in virtual currencies – including exchanges, peer-to-peer platforms, and any entity that transfers virtual assets on behalf of clients. That coverage is broad by design. FINTRAC treats a foreign VASP that serves Canadian residents as a reporting entity subject to the full compliance-program obligation, regardless of where the entity is incorporated.

The practical consequence is direct: a Cayman-incorporated exchange with Canadian retail users is, in FINTRAC's view, a foreign money services business (FMSB) required to register and comply. That registration is not optional. Operating without it triggers enforcement exposure across the banking rails as well as regulatory sanction. In our cross-border practice, we routinely advise operators who discover this obligation only after a Canadian correspondent bank flags the account for review.

The PCMLTFA regime sits alongside Canada's broader financial-crimes architecture. FINTRAC shares information with the Canada Revenue Agency, the Royal Canadian Mounted Police (RCMP) and provincial securities regulators. A compliance failure at the AML layer can therefore generate concurrent tax and securities consequences – a risk that a single-jurisdiction policy review often misses.

What FINTRAC Expects in a Written Compliance Program

A compliant AML/CFT program under the PCMLTFA regime has five mandatory elements, and FINTRAC examinations are structured to test each one independently.

The first is a designated compliance officer – a senior individual with genuine authority to implement the program. The officer must be named in writing and must have direct access to the board or senior management. A nominal appointment satisfies neither FINTRAC nor a court.

The second is written compliance policies and procedures. These must describe, in operational terms, how the business identifies customers, monitors transactions, detects suspicious activity and escalates internally. A generic template is not sufficient. FINTRAC examiners test whether the written document reflects the actual transaction flows of the specific business – a crypto exchange's policy must address order-book mechanics, wallet screening, and the handling of privacy-enhanced assets in a way that a generic financial-institution template never will.

The third element is a risk assessment. The business must assess its inherent exposure by product type, geography, customer segment and delivery channel, then document how controls are calibrated to that exposure. For a VASP, that means addressing the specific risks of pseudonymous transactions, smart-contract interactions and cross-border transfer patterns.

The fourth is an ongoing training program for all staff who touch compliance-sensitive functions. The fifth is an effectiveness review – an independent evaluation of the program's actual performance, conducted at least every two years or following a material change in the business. In our practice, the effectiveness review is the element most often absent or perfunctory in programs that were drafted once and never revisited.

CTA #1 The program above describes the standard structure. Your facts – the product mix, the user geography, the counterparty relationships – determine how each element is calibrated. Map your options with the OBOLUS compliance team before you draft.

KYC and Customer Due Diligence under the FINTRAC Regime

A KYC framework (know-your-customer program) under Canadian law requires identification, verification and ongoing monitoring across defined customer categories. FINTRAC distinguishes between individual clients, corporations, entities and politically exposed persons (PEPs), with different verification obligations for each category. The threshold at which enhanced due diligence is triggered is set by the Regulations, and the requirement to re-verify when risk indicators change is ongoing – not a one-time event at onboarding.

For virtual-currency dealers, FINTRAC requires identity verification for transactions at or above a defined monetary threshold, for all business relationships, and in any situation where suspicious activity is a consideration regardless of amount. The practical implication is that a VASP cannot rely on wallet screening alone as a substitute for customer identification. Blockchain analytics is a risk-layering tool; it does not replace the identity record that FINTRAC can demand to inspect.

Beneficial ownership obligations also apply. Where a corporate client is involved, the VASP must identify individuals who own or control the entity above a defined ownership threshold and document how that determination was made. For clients in opaque jurisdictions, this requirement demands a documented process – not simply a checkbox.

Transaction Monitoring and Suspicious Activity Reporting in Canada

Transaction monitoring for Canadian VASPs operates on two tracks: mandatory reporting of specific transaction types (large cash transactions, large virtual currency transactions, electronic funds transfers above thresholds, and international electronic funds transfers) and discretionary reporting of suspicious transactions regardless of amount.

The suspicious transaction report (STR) obligation is among the most consequential in the regime. FINTRAC does not require certainty that an offence occurred – only reasonable grounds to suspect. A VASP that fails to file an STR when the grounds existed faces a significant administrative penalty. Equally, a VASP that files an STR cannot inform the subject of the report (the "tipping-off" prohibition). The compliance policy must address both the detection logic and the internal escalation process in writing.

Automated transaction monitoring systems must be calibrated to the specific transaction patterns of the business. A rule set designed for traditional payments will systematically miss the patterns specific to on-chain activity – cluster transactions, rapid internal transfers, layering through decentralised exchange (DEX) interactions. The policy document must specify the monitoring logic, the alert thresholds, and the human review process that sits above the automated system.

In a recent cross-border matter, a payments firm operating in Canada and two other jurisdictions had implemented a monitoring system calibrated to fiat thresholds; it generated no alerts on a pattern of structured virtual-currency deposits that fell below the mandatory-reporting threshold but clearly evidenced structuring. The gap was identified during an effectiveness review, the policy was rewritten to address on-chain structuring indicators, and the system was recalibrated before FINTRAC's examination cycle opened. The firm avoided a finding of non-compliance at the subsequent examination.

How Does the Travel Rule Apply to Canadian VASPs?

The Travel Rule (the obligation to collect and transmit originator and beneficiary information with a virtual-asset transfer) applies to Canadian VASPs under the PCMLTFA Regulations for transfers at or above a defined threshold. Canada's Travel Rule implementation requires the originating VASP to collect and retain the required data elements and to transmit them to the beneficiary VASP as part of the transfer. Where the counterparty is a foreign VASP, the obligation does not disappear – the Canadian entity remains responsible for its side of the exchange.

The practical complexity arises at the unhosted-wallet boundary. Where a customer sends funds to or receives funds from a self-custodied wallet, the VASP must apply enhanced scrutiny and, in many cases, collect additional information about the wallet's beneficial owner. The policy must document the process for this determination and the standard for when enhanced measures are applied.

Cross-border Travel Rule compliance is a two-institution problem. The policy of the Canadian VASP must address what the business does when a counterparty VASP is not Travel-Rule-compliant – including VASP-to-VASP messaging protocol choices (such as IVMS 101 or an equivalent standard), the fallback process when data is missing, and the escalation to the compliance officer for unresolved cases. Operators we advise routinely discover that their policy addresses only their own obligations and says nothing about the counterparty interaction.

Cross-Border Interaction: The Inbound Foreign Operator Problem

A foreign business serving Canadian clients from outside Canada is, for FINTRAC purposes, a foreign money services business (FMSB) subject to registration and the full compliance-program requirement. The obligation is triggered by the direction of service – by the fact of Canadian customers – not by the location of servers or incorporation. This is the most common structural misconception we encounter in inbound digital-asset operators.

The FMSB registration process requires the entity to appoint a compliance officer who can be contacted by FINTRAC, to submit the written compliance program and risk assessment, and to maintain the records required under the Regulations in a form accessible to Canadian regulators. A foreign entity that also holds a VASP licence in another jurisdiction – say, under the VARA regime in Dubai or under the MiCA CASP framework in the EU – does not satisfy the Canadian requirement by virtue of that foreign authorisation. The regimes do not substitute for each other. Each must be satisfied on its own terms.

The banking dimension compounds this. A foreign VASP without FINTRAC registration will find it difficult to maintain a Canadian-dollar banking relationship. Most Canadian chartered banks require confirmation of FINTRAC registration as a condition of account opening for VASPs. The sequence matters: registration and a written compliance program must precede the banking conversation, not follow it.

CTA #2 If a prior application stalled or a banking relationship was closed, a structural review can identify the compliance gap and the path to resolution. Map your options at info@oboluslaw.com or via t.me/oboluslaw.

MLRO Governance, Record-Keeping and the Audit Trail

The Money Laundering Reporting Officer (MLRO) function – in Canadian parlance, the designated compliance officer – must have documented authority, a clear escalation mandate and direct reporting access to senior management. A common failure in FINTRAC examinations is a compliance-officer appointment that exists on paper but has no budget, no escalation authority and no documented interaction with the board. FINTRAC examiners interview the compliance officer directly and test whether the function is operational.

Record-keeping obligations under the PCMLTFA regime are extensive and period-specific. Identity records, transaction records, business-relationship records and the compliance program itself must be retained for defined periods. For virtual-currency businesses, records must capture the technical elements of the transaction – wallet addresses, transaction hashes and the associated chain-of-custody documentation – not merely the fiat equivalent. A policy that specifies only dollar-denominated record fields will fail an examination focused on on-chain activity.

The audit trail requirement runs through every element of the program. Where an alert is generated and not escalated, the reason must be documented. Where a suspicious-transaction report is considered and not filed, the rationale must be recorded. Where a customer is offboarded for risk reasons, the record must reflect the decision-making process. In our cross-border practice, we have seen firms lose enforcement defences because the substantive decision was correct but the documentation was absent.

Decision Matrix: Which Operators Need the Full Program?

The following profiles reflect the decision points that arise most frequently in our practice.

Profile A – Canadian-incorporated exchange with domestic clients: Full FINTRAC registration and compliance program required immediately upon commencement of operations. Timeline to achieve a defensible program: several weeks for a well-resourced team with experienced counsel; longer where internal compliance resources are limited. Key risk: underestimating the specificity FINTRAC expects in the risk assessment and the monitoring-system documentation.

Profile B – Foreign VASP with Canadian users (FMSB): FINTRAC FMSB registration required. The written program must mirror the domestic standard. The critical issue is lead time – registration and program submission must precede active marketing to Canadian residents. Key risk: assuming the foreign licence satisfies the Canadian requirement; it does not.

Profile C – Token issuer with a Canadian investor base: The AML/CFT obligation turns on whether the issuer is conducting activities that fall within the VASP definition. Where the issuance involves exchange or transfer services, the full program applies. Where the issuer is purely distributing tokens without ancillary services, the analysis is more nuanced but the risk of falling inside the perimeter is real. Key risk: relying on a characterisation made at launch that has not been reviewed against current FINTRAC guidance.

Profile D – Custodian holding digital assets for Canadian clients: Custody of virtual assets for third parties falls within the VASP definition as interpreted by FINTRAC. The program must address the specific risks of custody operations – access controls, internal transfer authorisation, and the monitoring of wallet-level activity. Key risk: applying a custody-specific policy that addresses only the internal security layer and ignores the client-identification and transaction-monitoring obligations.

Common Mistakes in Canadian AML/CFT Policy Drafting

A common assumption among operators is that a compliance policy produced for another jurisdiction – the EU's MiCA CASP framework, or the VARA rulebook in Dubai – can be adapted for Canada with minimal revision. That assumption is incorrect. The structural elements may overlap, but the Canadian regime has specific record-keeping formats, reporting timelines, threshold mechanics and examination processes that differ from those of other leading hubs.

The second recurring mistake is a policy that describes the business as it was designed rather than as it operates. FINTRAC examiners test the program against actual transaction flows. A policy that describes a standard spot-exchange model but does not address the DeFi aggregator feature added in the last product cycle will fail on scope.

Third: inadequate coverage of the Travel Rule at the counterparty level. The policy must address not only what the VASP transmits but what it does when the counterparty fails to transmit. That gap has generated enforcement findings in recent examination cycles.

Fourth: a risk assessment that is static. The PCMLTFA Regulations require the risk assessment to be reviewed and updated when the business changes. A risk assessment filed at registration and never revisited is a documented compliance failure waiting to be discovered.

Regulators in leading hubs increasingly expect the compliance policy to function as a living operational document, not an archived submission. That expectation is reflected in FINTRAC's examination methodology.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP initiating a virtual-asset transfer to collect specified originator and beneficiary information and transmit it to the receiving VASP as part of the transfer. In Canada, this obligation applies under the PCMLTFA Regulations at or above a defined transfer threshold. The Canadian VASP remains responsible for its side of the data exchange even where the counterparty is a foreign institution. The policy must document the data elements collected, the transmission protocol used, and the fallback process when counterparty data is incomplete.

Who must act as MLRO for a crypto firm?

Under the PCMLTFA regime, every reporting entity must appoint a designated compliance officer – the functional equivalent of an MLRO – who holds genuine authority to implement and enforce the compliance program. The individual must be senior enough to access the board and must be identifiable to FINTRAC. There is no prescribed external-qualification requirement, but the officer must demonstrate, in examination, a working knowledge of the regime and the business's actual operations. A nominal appointment without operational authority will not satisfy the regulator.

How do regulators audit crypto AML programs?

FINTRAC conducts risk-based examinations of reporting entities' compliance programs. Examiners review the written policy documents, test record-keeping against actual transaction samples, interview the compliance officer and assess whether the monitoring system's alert logic corresponds to the business's real transaction patterns. For VASPs, examinations increasingly include a review of on-chain transaction data and wallet-screening records. A program that exists on paper but does not reflect operational reality will fail. Programs that have not been updated following material business changes are a primary examination risk.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance architecture – AML policies, Travel Rule programs and KYC frameworks – that regulators in those jurisdictions require. We map the licence, compliance and banking stack across operating, custody and payment layers before you commit. Digital assets are the whole of our practice. To discuss your AML/CFT program, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design and FINTRAC compliance for digital-asset businesses operating across Canadian and international regulatory regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours