Compliance Effectiveness Reviews: Ask Us Anything Q&A session highlights

ICYMI, our recent Ask Us Anything webinar all about Compliance Effectiveness Reviews was a hit with a variety of reporting entities. Here are a couple of key question and answer highlights from the session ✨ 

Question: What is the expected scope of depth of a Compliance Effectiveness Review from FINTRAC’s perspective? 

The scope of the review needs to cover the full compliance program of the entity and should be risk-based.  You need to cover the main pillars of your compliance program materials including your:

🟠 Policies and procedures

🟠 Risk based assessment

🟠 AML training program and plan

🟠 Appointment of a compliance officer

Your review then needs to be tested against these pillars. Testing of the program itself typically is done on a sample basis and involves review of client files or transactions and then testing the KYC related to prescribed transactions. 

Question: What are some common findings that come out of an effectiveness review?

  1. Gaps and weaknesses in Risk-Based Assessment.  Including a weak methodology or a risk assessment not being fully documented. Additionally in practice, gaps like the application of your risk assignment being fully applied to clients or other risk-based factors. On the flip side, stating you have “no” high risk clients can also be a red flag - it is rare that a business can credibly defend they have never had a high risk client.

  2. Missing risk considerations related to Ministerial Directives

  3. No link between a risk-based assessment and transaction monitoring

  4. Policies & procedures (P&P’s) not being updated in real time upon legislation updates

  5. Lack of full implementation of P&P’s.  You may have P&P’s documented - but are you applying them in practice?  For example, your policies show Beneficial Ownership checks are part of your compliance program - but your staff isn’t actually doing Beneficial Ownership checks in practice (and this gap is  revealed when looking into your records).

Question: What evidence demonstrates that STR identification and other processes are operating as intended? How do we demonstrate this to FINTRAC?

✅ Ensure you have examples that your processes are working. Your program policies should stipulate what staff are supposed to do when encountering a suspicious transaction, but, you also need to show examples of how that process was applied in practice.

✅ Are you actually scrutinizing transactions effectively for suspicious activity?  It is a red flag if you raise no suspicious activity - regulators may assume suspicious activity exists and you just aren’t noticing it. This is one of the largest findings we see that lead to significant penalties. Suspecting nothing is dicey - it’s better to make sure your process to assess suspicion is being utilized in practice and you are evaluating transactions critically against regulatory standards. A validation of transaction monitoring rules to confirm that the transaction monitoring system is working is one of the most effective and proactive measures that can be taken to demonstrate that STR identification processes are working as intended.

There were so many other great questions and we thank you all for attending…and if you are an MSB, you might want to attend our next session all about Transaction Monitoring for MSBs! Details here https://www.linkedin.com/feed/update/urn:li:activity:7513288321083805699

If you need any further Compliance Effectiveness Review assistance or AML compliance help, contact our experts to learn how we can help you reduce friction with regulators. 
We Help Keep FINTRAC Happy  🇨🇦


The article is provided for informational purposes only and is based on The AML Shop's understanding of the regulatory and legislative standards that were in place at the time that the session was held and the article was written. Those standards and FINTRAC's enforcement of them vary and change over time.  The AML Shop is not a law firm and this article does not constitute legal advice.  This summary also may not be applicable to your specific situation.