AML Compliance Effectiveness Reviews
what is a compliance effectiveness review?
A Compliance Effectiveness Review (CER) is an independent assessment of whether your AML compliance program is operating as designed and achieving its intended outcomes. It examines whether your controls are functioning, your staff are applying them consistently, your transaction monitoring is generating appropriate results, and your documentation meets the standards FINTRAC applies in an examination.
A Compliance Effectiveness Review is not a gap assessment. A gap assessment compares your program against the rules and identifies what is missing or incomplete. A CER tests what you already have in place to find out whether it is actually working.
when do you need a compliance effectiveness review?
The Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations require that your compliance program be reviewed for effectiveness every two years. FINTRAC’s stated policy is that the review must start no later than two years after the start of your most recent examination. You may also need to conduct one if:
Your board or financial services partners require it
FINTRAC has issued findings against your program
You have made significant changes to your compliance controls
You are preparing for a scheduled FINTRAC examination
Under Bill C-12, the stakes of an ineffective program have increased materially. Compliance program deficiencies are now assessed per violation rather than per examination, with entity penalties capped at $20 million per violation. A review conducted ahead of FINTRAC is now a commercial decision as much as a regulatory one.
what our compliance effectiveness review covers
The AML Shop conducts effectiveness reviews for all reporting entity types in Canada, including financial entities (including banks and credit unions), money service businesses (MSBs), securities dealers, insurance companies, real estate brokerages, mortgage companies, finance and leasing, factoring companies, dealers in precious metals and stones and more.
Our review assesses:
Whether your compliance program elements are present and current with today’s regulatory requirements
Whether your staff are applying controls correctly and consistently in day-to-day practice
Whether your documentation meets the standard FINTRAC applies in an examination
Whether there are any program deficiencies and gaps to address
We deliver a findings report with a prioritized remediation roadmap. For entities running an ongoing CER under our managed program, we conduct procedures throughout the period using intelligent data analysis to identify control weaknesses before they become examination findings.
what HAPPENS IF YOUR EFFECTIVENESS REVIEW IDENTIFIES GAPS?
An audit finding is the start of a process, not the end of one. If the review identifies control weaknesses or program deficiencies, The AML Shop can support remediation directly.
Where program gaps require sustained operational attention, improvements to alert handling, STR quality, documentation standards, or monitoring coverage, our managed services can provide the operational resource to address them and keep them addressed.
Reach out using the contact form below or email the team directly. We will confirm your sector, program scope, and timeline requirements before proposing a review approach.
FAQs
-
An AML compliance effectiveness review is an independent assessment of whether a reporting entity’s AML compliance program is operating as designed and achieving its intended outcomes. It tests whether controls are functioning correctly, if staff are applying them consistently, that transaction monitoring is generating appropriate alerts, and documentation meets the standards FINTRAC applies during an examination.
-
Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations, reporting entities are required to carry out a review of their compliance program for effectiveness every two years. FINTRAC’s stated policy is that the review must start no later than two years after the start of the most recent FINTRAC examination. Entities may conduct more frequent reviews following significant non-compliance, at the direction of their board, or when required by financial services partners.
-
A gap assessment compares your program against regulatory requirements to identify what is missing or incomplete. A CER goes further: it tests whether the controls you have in place are actually functioning as intended. A program can pass a gap assessment and still produce adverse CER findings if controls are inconsistently applied, monitoring is generating poor-quality results, or staff behaviour in practice does not reflect training.
-
Yes. Bill C-12 (Royal Assent March 2026) introduced a statutory effectiveness standard requiring AML programs to be ‘reasonably designed, risk-based and effective.’ A CER must now provide evidence that the program is working, that monitoring is identifying what it should, that STRs are being filed at appropriate rates, and that controls are consistently applied in practice. This raises the bar compared to previous review requirements.
-
This depends on the size and complexity of the entity. For smaller reporting entities such as MSBs or real estate brokerages, a standard Compliance Effectiveness Review typically takes between two and four weeks from engagement to final report. For financial entities such as credit unions or banks, the timeline is longer based on transaction volume, the number of controls in scope, and the depth of testing required.
KEY CONTACTS
Michael Ecclestone - Principal, Regulatory Assessments / Legal Counsel
michael@theamlshop.ca
LinkedIn
Michael is Governance, Risk and Compliance Leader at The AML Shop, with over 20 years of experience in financial sector risk, regulatory compliance and legislation as an advisor, an executive, a regulator and a practicing lawyer. Read More
Bruce Hauser - Senior Manager, Compliance Effectiveness Reviews
bruce@theamlshop.ca
LinkedIn
As the AML Shop’s Senior Manager of Compliance Effectiveness Reviews, Bruce draws on the many years of experience gained while working in the Money Services Business (MSB) and Dealers in Precious Metals (DPM) sectors where he held positions as a Senior Operations Manager and Chief Anti-Money Laundering and Compliance Officer (CAMLO)…read more.
Abhishek Desai - AML Advisor
abhishek@theamlshop.ca
LinkedIn
Abhishek is an AML Advisor with The AML Shop and has over eight (8) years of experience working within AML compliance that includes working for a Money Service Business. He spearheads the compliance effectiveness reviews for all reporting entity types including financial entities, money service businesses, securities dealers, life insurance companies, real estate, dealers in precious metals and stones, accountants, and casinos.
Reach out to an AML Expert today.
QUICK LINKS
