How Do You Pick an AML Compliance Firm Without Buying Someone Else's Template?
Somebody is going to sit across from a FINTRAC examiner and answer for your compliance program. It won't be your vendor. You can outsource the program but not the blame. This should shape how you pick a compliance firm, and buyers dont think about it until the exam notice lands. They compare monthly fees, count pages in the sample policy, and sign with whoever answered the email fastest. Then the examiner asks who approved the risk rating for a customer in a high-risk country, and everyone is stunned. This is a guide to picking better than that.

Can You Really Outsource All of This?
Can you outsource AML compliance in Canada? Yes. You can outsource the program build, the day-to-day work, the reporting, and even the compliance officer role.
What can't you outsource?
Accountability.
Your business stays legally responsible under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, no matter who does the typing.
The one conflict to watch for is the firm that builds your program cannot be the firm that independently reviews it. Plenty of vendors will happily sell you both.
The fastest quality test: ask for one redacted page of a real risk assessment. You'll know inside two minutes.
You Think You're Buying Documents. So What Are You Really Paying For?
People think they're buying documents but they’re buying four things.
-
A person.
Someone whose name goes on the file, who FINTRAC will contact, and who has the standing to tell your CEO no. -
A document set.
Policies, procedures, a risk assessment, a training plan. These matter, but they're the easiest part to fake. -
A response time.
Regulators send letters with deadlines. Your bank sends questionnaires with deadlines. Somebody has to answer inside them. -
An evidence trail.
Proof that the program ran. Training records, reviewed alerts, dated approvals, meeting notes. This is what an examiner actually opens. This can make or break the outsourcing relationships.
The policy says a quarterly review happens.
What Can You Hand Over, and What Sticks to You Forever?
You can outsource nearly all of the work. However, you cannot outsource being the reporting entity.
FINTRAC's compliance program guidance sets out five elements every reporting entity needs: a named compliance officer, written policies and procedures, a documented risk assessment, ongoing training, and an effectiveness review every two years.
Nothing in that list says who has to hold the pen.
Canadian practice allows an external CAMLO, and the guidance focuses on authority and access to senior management rather than whose payroll the person sits on. That's why the outsourced model works here.
What doesn't transfer is the liability.

Since Bill C-12 came into force in March 2026, that right-hand column got heavier. Penalties for very serious violations now reach $20 million, and the criminal provisions extend to directors and officers who let problems continue. FINTRAC's own page on upcoming changes tracks what's landed and what's still coming. Our breakdown of the 2026 amendments covers what changed.
Read a vendor contract with that column in mind and the marketing reads differently.
"A Dedicated Team of Experts." Great. What's Their Name?
"You'll have a dedicated team of compliance experts" is a sentence designed to avoid a question.
The question is: who, specifically?
Ask for the name of the person who will act as your CAMLO. Then ask for three more things:
-
Their CV.
Sector experience, years, and what they did before consulting. Someone who has sat through a FINTRAC examination from the inside is worth more than someone who has read about one. -
How many other clients they carry.
If your CAMLO is also responsible for 30 other companies, you're getting a fraction of their attention, split thin. -
What happens when they leave?
A lot of institutional knowledge; your risk assessments, your history with regulators, the reasoning behind past decisions lives in one person's head if it's not documented. Losing that person can mean starting over.
If the answer to question one is a company name instead of a person's name, you've learned something. Our guide on how to hire a CAMLO in Canada covers what the role actually requires.
Should the People Who Built It Be the Ones Grading It?
Sometimes, technically.
It's also the single fastest way to weaken the review you paid for.
Your effectiveness review has to be independent. That's the entire point of it. Someone checks whether the program works, and the check means nothing if the checker built the thing.
So when a firm offers to write your program, run it, and then perform your two-year review, they're offering to grade their own homework.
Ask directly: "If you build my program, who does my effectiveness review?"
A good firm has an answer ready and doesn't get defensive. A firm that says "we do both, it's more efficient" has just told you how your next examination will go. If yours is already overdue, start with what happens when you miss the deadline.
Why Does Your Payments Policy Mention Casinos?
Ask any firm for a single redacted page from a real risk assessment they've delivered. Then look for two things.
Does it mention your kind of business? A payment company's risk assessment that spends a paragraph on casino chip purchases has been recycled. It happens more than anyone admits.
Could it belong to anyone? If the document would fit a competitor without edits, it just a description of the industry with your logo on top.
Since March 2026, programs have to be "reasonably designed, risk-based and effective." That was written to kill exactly this kind of document. McCarthy Tétrault's summary of the change explains how the bar moved.
Examiners have read hundreds of these. They recognise the recycled paragraphs faster than you will, and our piece on how to completely fail a FINTRAC examination is mostly a list of what those documents look like.
They've Never Touched Crypto. Does That Really Matter?
An AML program for a foreign exchange dealer and an AML program for a crypto exchange share around half their content.
Crypto brings blockchain analytics, travel rule obligations, and wallet screening. Payment service providers carry RPAA duties from the Bank of Canada on top of FINTRAC's. Real estate has its own reporting patterns. Cheque cashers deal in physical cash and the record-keeping that comes with it.
Ask which of your sector's clients the firm currently serves. Ask what the last regulatory change in your sector was and what they did about it.
A firm that specializes in your exact regime; your jurisdiction, your industry, your license type can answer specific questions immediately, from memory, because they live in that world every day. A generalist has to go look it up.
What Happens When FINTRAC Emails at 4:58 on a Friday?
FINTRAC sends a request for information with a deadline. Your bank sends a questionnaire with a shorter one. A suspicious transaction shows up and the clock on the report starts running.
None of those wait for your vendor's Monday.
Ask three questions before you sign:
-
What's the guaranteed response time for regulatory correspondence?
-
Who covers the file when my CAMLO is on vacation?
-
Is there an after-hours contact, and has anyone ever used it?
Then ask for it in the engagement letter. Verbal reassurance is not a service level.
If You Walk Away, Do You Get to Take Anything With You?
It costs firms months.
If you end the relationship, do you receive your policies, risk assessment, training materials, and records in editable form? Or do you get a locked PDF and an invitation to start over?
Some providers build on proprietary platforms and hand back nothing usable. Others hold records hostage over final invoices. Neither is illegal. Both are avoidable with one clause in the contract.
Ask for the exit terms in writing before you sign the entry terms.
Which Nine Questions Make a Weak Firm Squirm?
Bring these to the call.

No firm has a spotless record across every client.
When Should You Just Hang Up?
Any one of them is enough.
A guaranteed registration approval.
Nobody can promise what FINTRAC will do.
A price with no scope.
"$X a month for full compliance" without a defined deliverable list means the definition arrives later, and it won't favour you.
No engagement letter.
If a firm won't put the scope in writing, the scope doesn't exist.
A CAMLO who won't take a call before you sign.
You're hiring a person. Meet the person.
Turnaround promises measured in days for work that takes weeks.
A real risk assessment needs your transaction data, your customer base, and a conversation with your operations lead. A two-day program is a template.
Selling you a shelf company alongside the program.
Different product, different problem, and it tells you what kind of firm you're dealing with.
Why Is the $400 Option the Most Expensive One?
Cheap compliance is the most expensive thing a Canadian fintech can buy, and the bill arrives late.
Our breakdown of real compliance costs lays out market salaries, software pricing, and what a review-ready budget looks like in 2026. Read it before you take the first quote, so you know which end of the range you're standing in.
The useful comparison is the annual fee against one very serious violation, which now tops out at $20 million.
How Does a Tidy 60-Page Policy Freeze Your Bank Account?
Picture a payments startup, eighteen months old, four people. The founder signs with a provider at $400 a month because the alternative quoted six times that.
Sixty pages arrive within a week. They look professional and go in a folder.
Fourteen months later the bank asks for the risk assessment during a review. The founder opens it for the first time and finds three references to casino operations, a compliance officer field still marked "TBD," and a customer risk model built for a business with branches.
The bank freezes onboarding, and asks for a remediated program in thirty days.
The remediation costs more than four years of the retainer.
FAQ: The Questions People Ask With the Pen Already in Hand
Can you outsource AML compliance in Canada?
Yes. Program build, ongoing operation, reporting and the compliance officer role can all be outsourced. Legal accountability stays with your business.
Can an outsourced CAMLO satisfy FINTRAC?
Yes, provided the person has real authority, access to senior management, and knowledge of your sector. FINTRAC's guidance is about the role's substance, not whose payroll it sits on.
Can the same firm build my program and do my effectiveness review?
Only with genuine separation between the teams, and even then it invites questions. The cleanest answer is to use a different firm for the review.
How long does it take to set up an outsourced program?
For a straightforward business, a few weeks. Anyone promising a complete, defensible program in 48 hours is selling a template.
What's the difference between a gap analysis and remediation?
A gap analysis tells you what's wrong. Remediation fixes it. Some quotes include only the first and mention the second afterwards.
We're pre-launch. Is it too early?
It's the cheapest moment you'll ever have. Building it later means rebuilding it, and starting from day one costs a fraction of retrofitting.
How do I check if a firm is credible?
Ask for client references in your sector, ask question eight above, and ask who signs the work. Then call one of the references and ask what went wrong at some point in the relationship. Something always did. What matters is what happened next.
Get In Touch
If you're comparing compliance firms right now, the fastest useful thing you can do is ask each one who would perform your independent review. The answers will sort the list for you.
These AMLI services cover the three places most buyers need help:
AML Effectiveness Review: a structured, independent review of your program, risk assessment and evidence trail against current FINTRAC expectations, built to find gaps before an examiner does.
CAMLO and MLRO Services: an embedded, qualified compliance officer who meets FINTRAC's actual standard for authority and sector knowledge, without the cost of a full-time hire.
FINTRAC MSB Registration: for firms that need the program structured correctly from the start, including registration, renewals and regulatory correspondence.
Book a discovery call and we'll walk through where your program actually stands, and what a defensible one would take.




