Would Your Compliance Program Survive a FINTRAC Exam?
Most compliance programs have never actually been tested. They get filed, reviewed on a schedule, and left alone until something forces the question. FINTRAC doesn't wait for you to ask whether your program is good enough. Here are the ten questions they'd effectively be asking, so you find out first.

What Does FINTRAC Actually Test in an Examination?
They test whether your program works.
An examiner reads your policies first. What they do next is talk to your staff, pull real client files, and check whether what's written matches what actually happens on the floor. We've written before about how firms fail this exact moment, and about how to build a program that can actually defend itself.
FINTRAC's own compliance program guidance lays out five required pieces, which we've broken down as the five pillars of a compliant MSB: a named compliance officer, written policies and procedures, a documented risk assessment, ongoing training, and an effectiveness review at least every two years by someone independent. Miss one and you don't have a program. You have four-fifths of one.
Because the paper was never the thing being graded.
A binder can say all the right words about a risk-based approach and still describe a business that stopped looking like this two acquisitions ago. A training log can show one hundred percent completion and still mean everyone clicked through a video without reading it. The document proves someone wrote something down. It doesn't prove anyone understood it, or that it still describes the business as it runs today.
Bill C-12 raised the bar specifically because of this gap. As McCarthy Tétrault's analysis of the amendments lays out, "reasonably designed, risk-based and effective" means an examiner can now ask not just do you have a risk assessment, but does this risk assessment actually match your risk.
Part of what changed sits in the 2026 legislative amendments themselves, and BLG's breakdown of the expanded examination powers is worth reading if your compliance officer hasn't seen it yet. That's a harder question, and a lot of programs haven't been tested against it.
So Would Your Program Actually Pass?
Take the Test.

Yes or no….
-
Does your compliance officer have sufficient independence, access and authority to administer the compliance program, investigate matters and escalate concerns, even if final rejection, suspension or termination authority sits with senior management or another designated role?
-
Have your written policies and procedures been reviewed and updated in the last twelve months, not just re-dated?
-
Does your risk assessment cover your actual current products, delivery channels and client base, including anything new in the last year?
-
Can you pull a training completion log, by name and date, for every employee right now, in under five minutes?
-
Has an independent effectiveness review been completed within the last two years?
-
Could you hand over your last five suspicious transaction reports along with the reasoning behind each one, matched against the red flags examiners actually look for?
-
If FINTRAC called three of your front-line staff without warning, would their answers match what's written in your policy manual?
-
Does your risk assessment say anything at all about new or unusual delivery channels, including AI-assisted tools your business has started using?
-
Do you know, right now, the maximum penalty FINTRAC could issue for a serious violation under the current AMP framework?
-
When your last risk assessment flagged a gap, can you show what you actually did about it, not just that you noted it?
Score yourself.
Count the number of yes answers.
8 to 10: your program would likely hold up. Keep testing it anyway.
5 to 7: you have real exposure, and probably don't know exactly where yet.
4 or fewer: an examination would find more than one gap, and the newest rules make each one more expensive than it used to be.
What's Actually at Stake if You Score Low?
Money, mostly, and a lot more of it than it used to be.
Since the amendments described in the PCMLTFA took effect on March 26, 2026, the maximum penalties FINTRAC can issue went up roughly forty times over.

Source: FINTRAC's new AMP framework and DLA Piper's summary of the implemented amendments, current as of the March 2026 changes.
Entities also now face a cumulative cap of $20 million or 3% of gross global revenue, whichever is greater. Individuals, including compliance officers, face the same per-violation tiers.
Picture a Payment Company in Mississauga Taking This Test
Their compliance officer answers every question and gets a 6.
The policy manual is current. The training log looks solid. But the risk assessment still describes the business as it was two years ago, before they added a merchant category the founder calls "the crypto-adjacent stuff" in meetings and nothing more specific than that in writing. Nobody has updated the document to actually name it.
The compliance officer already knew this, in the way people know about a load-bearing crack they've decided to worry about later.
They fix the two easiest gaps that afternoon: naming the compliance officer's actual authority in writing, and pulling the training log into one place instead of three spreadsheets. The risk assessment update takes longer, because it means finally writing down what "crypto-adjacent" means and what controls apply to it. That's the one an examiner would have asked about first.
FAQ
What does FINTRAC actually check in an examination?
Whether your program works as written, not just whether it exists. That means staff interviews, real file reviews, and a comparison between your policy and what actually happens. Examiners now also check whether the program is reasonably designed for your specific business, not just whether the required pieces exist on paper.
Is this self-test the same as an effectiveness review?
No. An effectiveness review has to be done by an independent party and covers your whole program in depth. This test is a fast gut check you can run yourself, and a reason to book the real thing if the score is low.
What happens if I score below 5?
Nothing happens automatically. But it means an examination would likely find more than one issue, and each one now carries a bigger penalty than it did before March 2026.
Does a high score mean we're protected from penalties?
No score protects you completely. It means the visible gaps are smaller, which is not the same as no gaps.
Who should actually take this test?
Anyone running compliance at an MSB, fintech, crypto platform or PSP in Canada, especially if you haven't been through a FINTRAC examination in the last two years.
How often should we retake it?
Every time your risk assessment gets its annual update, and any time you add a product, a market or a new delivery channel.
We scored low. What's the fastest fix?
Start with question 3. A risk assessment that doesn't match your actual business, measured against the five pillars FINTRAC expects, undermines everything else, because it's the document every other answer depends on.
Does FINTRAC publish anything like this test officially?
No. This is built from FINTRAC's own compliance program guidance and the upcoming changes FINTRAC has flagged, not an official FINTRAC product. Treat it as a starting point.
Get In Touch
If your score came back lower than you expected, that's useful information, not a verdict. The next step is finding out exactly where the gap is before an examiner does.
AML Effectiveness Review: an independent review of your program against current FINTRAC expectations, including the parts a self-test can't catch.
CAMLO and MLRO Services: a qualified compliance officer with real authority, built to answer question 1 correctly.
FINTRAC MSB Registration: for firms building their program from the ground up, so the first version is the one that would pass.
Book a discovery call and we'll walk through where your program actually stands.




