12.03.25
Written by Haik Kazarian, Head of Business Development
Reviewed by Tigran Rostomyan, Compliance Expert
Laying the Foundations for AML Compliance: The Five Pillars of an Effective Compliance Program
The 5 pillars every AML compliance program needs in 2026: compliance officer, written policies, risk assessment, training and effectiveness review. Free checklist included.

Quick answer: An effective AML compliance program rests on five pillars: (1) a designated compliance officer, (2) written policies and procedures, (3) a documented risk assessment, (4) an ongoing training program, and (5) a regular effectiveness review. In Canada, these are legal requirements for every reporting entity under the PCMLTFA, including money services businesses (MSBs), fintechs and crypto firms.
Last updated: September 24, 2026
Why the Five Pillars Matter More in 2026
Regulators no longer ask "Do you have an AML program?" They ask "Does it actually work?" FINTRAC examinations increasingly focus on whether controls are applied in practice, not just written down, and banks now ask MSBs and fintechs for proof of a working program before opening or keeping accounts.
What's changed recently:
- Penalties are up to 40 times higher. PCMLTFA amendments in force since March 26, 2026 allow FINTRAC to impose much larger administrative monetary penalties, plus mandatory compliance agreements and compliance orders for serious violations. FINTRAC's new penalty framework
- Universal enrolment is coming. Bill C-12 requires all reporting entities, not just MSBs, to enrol with FINTRAC. Bill C-12 and universal enrolment
- Crypto scrutiny is rising, with a wave of MSB registration revocations in 2026. FINTRAC's 2026 crypto crackdown
If any of the five pillars is missing or out of date, it is one of the first things an examiner will flag.
Pillar 1: A Designated Compliance Officer (CAMLO)
Every AML program needs one accountable person, often called the Chief Anti-Money Laundering Officer (CAMLO) or MLRO, with the authority, independence and resources to run it.
What they are responsible for:
- Running day-to-day AML compliance
- Keeping policies aligned with current regulations
- Overseeing suspicious transaction reports (STRs) and other FINTRAC reports
- Acting as the main contact for FINTRAC examinations and bank due diligence
- Reporting to senior management and the board on compliance
Common mistake: naming a founder or operations lead as CAMLO "on paper" with no time, training or authority to do the job.
No in-house CAMLO? Learn more about our outsourced CAMLO/MLRO services. See also: How to Hire a CAMLO in Canada.
Pillar 2: Written Policies and Procedures
Your compliance program must be written, kept up to date and approved by a senior officer. It should reflect your business, not a generic template.
It should cover:
- Know Your Client (KYC) and identity verification
- Beneficial ownership and politically exposed person (PEP) checks
- Enhanced due diligence (EDD) for high-risk clients
- Transaction monitoring and reporting (STRs, LCTRs, EFTRs, LVCTRs and terrorist property reports)
- Ministerial directives and sanctions screening
- Record keeping
- The travel rule for virtual currency and electronic funds transfers
Common mistake: policies that describe what the business used to do, not what it does today.
Need help with high-risk clients? Explore our Enhanced Due Diligence services.
Pillar 3: A Documented Risk Assessment
A risk assessment shows you understand where money laundering and terrorist financing risk exists in your business, and what you are doing about it.
Assess risk across:
- Clients and business relationships
- Products, services and delivery channels (for example, non-face-to-face onboarding)
- Geographic locations you deal with
- New technologies and developments
- Any other relevant factors
Then document how your controls reduce each risk, and update it whenever your business changes: a new product, a new country or a new type of client.
Common mistake: a risk assessment written once at launch and never touched again.
Pillar 4: An Ongoing Training Program
Everyone who handles clients or transactions needs to know how to spot and escalate suspicious activity. In Canada, the training program itself must be written and ongoing.
A strong training program includes:
- Onboarding training for new staff, agents and mandataries
- Annual refreshers
- Role-specific modules for frontline staff, compliance and senior management
- Red flag recognition and how to escalate
- Updates when regulations change
- Records of who completed what, and when
Common mistake: a single slideshow at hiring with no records kept.
For more information, visit our AML Training Programs or read Top 10 AML Red Flags Every Compliance Officer Must Know.
Pillar 5: The Effectiveness Review
An effectiveness review tests whether your policies, risk assessment and training actually work. In Canada, it must be done at least every two years, and the results must be reported to senior management.
What a good review includes:
- Independent testing of your policies, controls and records
- Sample testing of KYC files, monitoring alerts and reports
- A check on whether past findings were fixed
- A written report with clear recommendations and deadlines
Common mistake: missing the two-year deadline, or having the review done by the same person who runs the program.
Learn more about conducting an AML effectiveness review. Missed a deadline? Read what Canadian MSBs and fintechs must know.
AML Compliance Program Checklist
Use this quick check to see where you stand:
| Pillar | You're in good shape if... |
|---|---|
| Compliance Officer | A named CAMLO with real authority, time and AML experience |
| Policies and Procedures | Written, approved by senior management and updated in the last 12 months |
| Risk Assessment | Documented, covers all risk areas and updated after any business change |
| Training | Written program, annual refreshers and completion records kept |
| Effectiveness Review | Completed within the last two years, with findings fixed and documented |
Can't tick all five? That is exactly what FINTRAC and your bank will notice first.
Frequently Asked Questions
What are the 5 pillars of AML compliance?
A compliance officer, written policies and procedures, a risk assessment, an ongoing training program, and a regular effectiveness review.
Who needs an AML compliance program in Canada?
All reporting entities under the PCMLTFA, including money services businesses, crypto and virtual currency dealers, securities dealers, financial entities, real estate, accountants, casinos and dealers in precious metals and stones.
How often do I need an effectiveness review?
In Canada, at least every two years. Many businesses do one sooner after major changes or before a bank review.
Can a small MSB outsource its compliance officer?
Yes. Many MSBs and fintechs use an outsourced CAMLO, but the business remains responsible for compliance.
What happens if my compliance program is missing a pillar?
FINTRAC can issue findings, require an action plan and impose administrative monetary penalties. Gaps also make it harder to open or keep bank accounts.
Need Help Building or Fixing Your Program?
AML Incubator helps MSBs, fintechs and crypto firms build all five pillars, from outsourced CAMLO services to risk assessments, training and effectiveness reviews. Book a free consultation.
For organizations seeking expert guidance on AML compliance, explore services such as:
- Regulatory Remediation
- Token Due Diligence
- MSB Registration
- Retail Payment Activities Act (RPAA) Compliance
Related reading:




