Operating a digital-asset business in Canada without a defensible anti-money laundering (AML) program is not a grey-area risk – it is a near-certain path to a FINTRAC examination, a public non-compliance finding, and potentially frozen correspondent-banking relationships. Canada's regulator, FINTRAC (the Financial Transactions and Reports Analysis Centre of Canada), treats virtual-asset businesses as reporting entities subject to the full weight of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. When an examination arrives – announced or unannounced – the business that survives it is the one that built, tested and documented its compliance program before the examiner asked the first question.
This page sets out what the Canadian AML regime requires of digital-asset businesses, how a FINTRAC examination proceeds, and what a credible audit-defence posture looks like in practice. It addresses the cross-border dimension: a foreign-registered entity serving Canadian residents, or a Canadian entity with users abroad, carries obligations that neither a domestic lawyer nor a foreign compliance consultant alone can resolve.
Who Must Comply With Canada's AML Regime?
Any business that operates as a virtual asset service provider (VASP) – meaning it exchanges, transfers, or keeps custody of virtual assets for clients – is a reporting entity under the PCMLTFA. This applies regardless of where the business is incorporated. A Cayman-registered exchange that onboards Canadian residents is a VASP for PCMLTFA purposes. FINTRAC's jurisdictional reach extends to entities that direct services at the Canadian market, not merely to entities with a Canadian corporate seat.
Registration with FINTRAC is mandatory. Operating without it is itself a compliance failure and a trigger for enforcement. The regime covers exchanges, custodians, transfer services, OTC desks and – following the expansion of the VASP definition in recent regulatory amendments – certain DeFi-adjacent intermediaries that hold client assets at any stage of a transaction cycle. In our practice, the most common gap we identify is a business that registered at the exchange layer but failed to register separately for a custody or transfer function it added later.
FINTRAC assesses compliance across five documented pillars: written policies and procedures, a designated compliance officer, a risk assessment, an ongoing training program, and a two-year effectiveness review cycle. An examination tests each pillar in turn. A missing pillar is an automatic finding. Two or more missing pillars place the entity in the category FINTRAC designates as a serious deficiency, which carries a higher probability of administrative monetary penalties (AMPs).
The cross-border angle is immediate. An entity registered in the EU under MiCA (the Markets in Crypto-Assets Regulation) or licensed by MAS (the Monetary Authority of Singapore) under the Payment Services Act still needs a standalone FINTRAC registration if it serves Canadian users. MiCA passporting does not extend to Canada. Each regime is satisfied on its own terms. We regularly advise operators who assumed their EU or Singapore licence provided a compliance umbrella – it does not.
What Does FINTRAC Actually Examine?
A FINTRAC examination is a structured document review combined with transactional testing – not a conversation. The examiner arrives with a pre-examination questionnaire, a transaction sample, and a set of operational questions. A business that treats the examination as an administrative visit rather than an adversarial legal proceeding will make preventable errors.
FINTRAC examiners focus on three areas with the highest enforcement yield. First, large cash transaction reports (LCTRs) and suspicious transaction reports (STRs) – whether the business is filing them, filing them on time, and filing them with adequate narrative. A pattern of late STRs is a finding even when the underlying transaction was identified correctly. Second, the business's know-your-customer (KYC) framework: identity verification methodology, the records retained, and the process for enhanced due diligence on higher-risk customers. Third, transaction monitoring: is the system calibrated to the actual risk profile of the customer base, or is it a generic ruleset applied without documented rationale?
In our cross-border practice, we have seen businesses that maintained strong AML programs in their primary licensing jurisdiction but held only a skeleton compliance function for Canadian operations. FINTRAC examiners are experienced at identifying that mismatch. The examination finding in those cases is not that the business was non-compliant in substance – it is that the compliance program was not demonstrably applied to the Canadian business line. Documentation of application is as important as the quality of the underlying controls.
Administrative monetary penalties under the PCMLTFA are structured on a per-violation basis. FINTRAC publishes its penalty matrix and its non-compliance findings publicly. A public finding is not merely a financial consequence – it is a disclosure event that correspondent banks, institutional counterparties and licensing regulators in other jurisdictions will note. We have advised clients on the banking and licensing cascade that follows a public FINTRAC finding. The remediation cost often exceeds the penalty itself.
To discuss a FINTRAC examination that is already underway or expected, contact OBOLUS at info@oboluslaw.com. The process above describes the standard examination path. Your facts – the entity structure, the user base, the transaction profile – change the analysis and the exposure.
How Do You Build a Defensible Audit Posture?
A defensible AML audit posture is not assembled after the examination notice arrives – it is the continuous state of a compliant program, documented in a way that survives scrutiny. The businesses that perform best in FINTRAC examinations are those that have run internal gap assessments against the examination checklist before the examiner does.
The core elements of audit readiness in Canada are as follows. The written compliance program must be current – version-controlled, dated, and signed by the compliance officer. A policy drafted in the first year of registration and never updated is a finding waiting to happen. Risk assessments must be documented at the customer, product, and geographic level, not as a generic statement. The examiner will ask: "Show me how you assessed the risk of a customer sending virtual assets to a non-custodial wallet." A qualitative narrative supported by data is the answer; a checkbox is not.
Transaction monitoring calibration records are among the most examined documents. FINTRAC examiners want to see that the threshold and typology rules in the monitoring system were chosen deliberately, reviewed periodically, and adjusted when the business's risk profile changed. A system deployed at launch and never reviewed is a structural weakness. For exchanges that operate across multiple fiat corridors – CAD, USD, EUR – the monitoring system must address the risk profile of each corridor, not just the domestic book.
Training records matter equally. Every staff member with a customer-facing or transaction-processing role must be trained on the PCMLTFA obligations specific to virtual assets. Generic AML training that does not address crypto-asset typologies is inadequate. Operators we advise maintain a training log with individual completion records and periodic assessments – the kind of record that closes an examiner's question in seconds rather than creating a follow-up item.
What Does the Travel Rule Require in Canada?
The Travel Rule – the obligation to collect and transmit originator and beneficiary information with virtual-asset transfers above a defined threshold – applies to VASPs under both FATF Recommendation 15 and Canada's own PCMLTFA amendments. Canada implemented Travel Rule requirements as part of the 2022 regulatory amendments to the PCMLTFA framework, making originator and beneficiary data collection and transmission mandatory for virtual-asset transfers at the applicable threshold.
In practice, the Travel Rule creates three compliance challenges for a VASP serving a cross-border user base. First, counterparty VASP identification: the sending VASP must verify that the receiving entity is itself a registered or licensed VASP before transmitting the transfer data. Sending to an unregistered entity triggers different obligations. Second, data format and transmission: the rule requires a method of secure data exchange. Canada does not mandate a single technical protocol, but the business must document its chosen method and apply it consistently. Third, non-custodial wallet transfers: the rules for transfers to or from unhosted wallets require separate procedures, including a documented risk-based approach to verifying wallet ownership.
The cross-border complexity is acute. A Canadian VASP transferring assets to a user at a Singapore-licensed exchange must satisfy both FINTRAC's Travel Rule requirements and MAS's equivalent requirements under the Payment Services Act. Where a user transfers to an exchange licensed under VARA (Virtual Assets Regulatory Authority) in Dubai, the Canadian VASP's obligations run to the Canadian side of the transfer; the VARA-licensed exchange carries its own obligations. These regimes do not harmonise automatically, and a business that applies only one side's rules will be non-compliant on the other.
How Does Canadian AML Interact With Tax and Banking?
AML compliance and banking access are inseparable in the Canadian digital-asset environment. Canadian correspondent banks apply their own AML/KYC assessments to VASP clients before opening or maintaining a business account. A FINTRAC registration alone is not sufficient – the bank will review the compliance program, the customer risk profile, and the transaction monitoring framework as part of its own due diligence. A VASP with a weak or undocumented compliance program will find banking access difficult to obtain and fragile once held.
The tax dimension runs alongside the AML frame. The Canada Revenue Agency (CRA) treats virtual-asset transactions as taxable events. For a business operating an exchange or OTC desk, the tax reporting obligations on client transactions intersect with the AML record-keeping obligations under the PCMLTFA. Both regimes require transaction records, but the retention periods and the form of the records differ. A compliance program designed for FINTRAC alone may leave gaps in the CRA-facing record set. We map both layers when advising on compliance architecture.
For inbound operators – entities registered outside Canada that are expanding into the Canadian market – the sequence matters. The optimal approach is to establish the FINTRAC registration and the core compliance program before approaching a Canadian banking partner, not after. Banks that review a business with no FINTRAC registration or a placeholder compliance policy will decline and are unlikely to reconsider quickly. We structure this process: registration, policy build, bank introduction, in that order.
If a prior FINTRAC registration or Canadian banking relationship has stalled or closed, contact OBOLUS at info@oboluslaw.com. A structured review can surface the specific deficiency and the path to remediation.
A Practical Illustration: Responding to a FINTRAC Examination
In a recent matter, a payment and exchange platform that had operated under FINTRAC registration for several years received an examination notice with a 30-day document production deadline. The business had a written compliance program but had not completed its two-year effectiveness review, and its transaction monitoring thresholds had not been revisited since the platform expanded from CAD-only to multi-currency operations. We were instructed within days of the notice. We conducted a pre-examination gap assessment, produced a remediation log documenting each corrective action and its completion date, and prepared the compliance officer for the examiner's operational interview. The examination resulted in a single minor finding – the absent effectiveness review – with no penalty. The business addressed the finding within the period FINTRAC specified. Banking relationships were unaffected. The key factor was not that the compliance program was perfect before the examination; it was that the remediation was documented, credible and complete by the time the examiner arrived.
What Are the Most Common AML Mistakes by VASPs in Canada?
The compliance failures we see most frequently in the Canadian VASP environment are structural rather than accidental. They reflect a compliance architecture built for registration rather than for examination.
The first and most consequential mistake is treating FINTRAC registration as a one-time event. The compliance program must evolve as the business evolves. A business that adds a lending product, an OTC desk, or a new fiat corridor without updating its risk assessment and policies has created a documented gap that an examiner will find.
The second mistake is an unqualified compliance officer. The designated compliance officer must have meaningful authority within the business and genuine familiarity with the PCMLTFA obligations. Appointing a junior operations staff member in a nominal role does not satisfy the regime. FINTRAC examiners test the compliance officer's knowledge directly. In our practice, we have seen examination findings generated entirely by inadequate responses in the compliance officer interview – not by deficiencies in the written program.
The third mistake is failing to document the rationale for decisions. When a business decides not to file an STR on a transaction it reviewed and assessed as non-suspicious, that decision must be documented. When it adjusts a monitoring threshold, the reason must be recorded. Regulators across all the major digital-asset regimes – FINTRAC, ESMA's guidelines under MiCA, FATF member implementations – converge on the same principle: the quality of the decision matters, but the record of the decision is what survives an examination.
A fourth structural failure is the cross-border compliance gap described earlier. The business that operates under a MiCA CASP authorisation in Europe and a FINTRAC registration in Canada must apply a compliance program to each jurisdiction separately, with documentation that evidences the application. A unified policy that addresses both regimes is achievable – but it must be designed for both, not retrofitted.
When Should a Digital-Asset Business Engage Legal Counsel on AML?
The decision to engage counsel is most effective at three points in the compliance lifecycle, not just at the examination stage.
The first is at business launch or market entry. A VASP entering the Canadian market should have counsel review its registration application, draft or audit its compliance program, and map the interaction with any existing compliance infrastructure from other jurisdictions before it onboards the first Canadian user. A compliance program built correctly from the start is materially cheaper to maintain than one rebuilt under examination pressure.
The second decision point is a material business change: adding a product category, expanding to a new user base, or restructuring the corporate entity. Each of these events has the potential to alter the FINTRAC registration category, the risk assessment, and the Travel Rule obligations. We regularly advise clients who have experienced one of these changes and need to assess whether their existing compliance framework remains adequate.
The third decision point – and the most urgent – is receipt of an examination notice, a request for information from FINTRAC, or a communication from a correspondent bank citing AML concerns. At that stage, speed and documentation discipline are the variables that determine the outcome. Counsel retained after an examination finding has already been issued is working against a much shorter window.
Profile A – a well-funded exchange entering Canada from an existing licensed position in the EU or UAE: the optimal path is a MiCA or VARA-based compliance architecture adapted for FINTRAC, with a dedicated Canadian compliance officer and a bank introduction process managed in sequence. Timeline from instruction to operational registration is typically a matter of weeks, with the program build running concurrently. Key risk: underestimating the granularity of FINTRAC's transaction-monitoring expectations relative to the home-jurisdiction standard.
Profile B – a growth-stage DeFi-adjacent business with a Canadian user base and no existing FINTRAC registration: the first priority is registration; the second is a risk assessment calibrated to the actual transaction flow; the third is a banking strategy that is realistic about the due diligence a Canadian bank will apply. Timeline and risk profile vary by the complexity of the transaction model and the jurisdictions involved. Key risk: assuming that a non-custodial product design removes the VASP classification.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – cross-jurisdictional program design, FINTRAC and beyond
- AML/CFT policy drafting in Mauritius – how the VAITOS framework compares for cross-border operators
- Utility token legal opinion: where the legal lines are drawn – token classification and its compliance consequences
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP that initiates a virtual-asset transfer to collect the originator's identifying information and the beneficiary's information, and to transmit that data to the receiving VASP before or during the transfer. Under Canada's PCMLTFA framework and FATF Recommendation 15, these obligations apply at the threshold set by the applicable regulations. Non-custodial wallet transfers require a separate, documented risk-based procedure. The specific data fields and the transmission method must be set out in the business's written compliance policies.
Who must act as MLRO for a crypto firm?
Under the PCMLTFA regime, a virtual-asset business must designate a compliance officer – the functional equivalent of a Money Laundering Reporting Officer (MLRO) in other jurisdictions. That individual must hold genuine authority within the business, have direct access to senior management, and be able to demonstrate substantive knowledge of the PCMLTFA obligations as they apply to virtual assets. FINTRAC examiners assess the compliance officer's knowledge directly. Appointing a nominal officer without real compliance authority is a finding. For businesses operating across Canada and a second jurisdiction – such as the UAE under VARA – the two compliance functions may be held by different individuals, but the programs must be coordinated.
How do regulators audit crypto AML programs?
FINTRAC examinations follow a structured methodology: a pre-examination questionnaire, a document production phase covering policies, risk assessments, training records and transaction files, and an operational interview with the compliance officer. Examiners test the five PCMLTFA compliance pillars, review a sample of STRs and LCTRs for completeness and timeliness, and assess whether the transaction monitoring system reflects the business's actual risk profile. Findings are graded by severity; serious findings can result in administrative monetary penalties and public disclosure. Other regulators – including ESMA under MiCA and MAS under the Payment Services Act – apply analogous structured examination methodologies.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP registration, AML program design and multi-jurisdiction examination defence for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.