Every Canadian mortgage brokerage now needs a FINTRAC-compliant compliance program. The regulation came into force October 11, 2024. Bill C-12, which received Royal Assent in March 2026, raised the stakes by rewriting the program standard from “intended to ensure compliance” to “reasonably designed, risk-based and effective.”
Many mortgage brokerages are still building their programs for the first time. Others have programs in place but haven’t stress-tested them against the new effectiveness standard. This post is the practical template.
The five pillars, what each contains, how they fit together, and where the most common gaps are. Written for the compliance officer or principal broker building or refreshing a program, not as legal advice - if you need a formal program review, engage a Canadian AML-specialist firm.
The five required pillars
Every FINTRAC-compliant compliance program is built on the same five components. Miss any of them and the program is deficient.
- A designated compliance officer. The named individual responsible for the program.
- Written compliance policies and procedures. The documented framework that everyone in the brokerage follows.
- A documented risk assessment. The brokerage’s specific understanding of its money laundering and terrorist financing risks.
- An ongoing training program. Delivered to everyone with compliance responsibilities.
- A prescribed review. Independent assessment of the program, required at least every two years.
5 pillars
required for every FINTRAC-compliant compliance program. Officer, policies, risk assessment, training, prescribed review. Miss any one and the program is deficient at examination.
We’ll walk through each, what’s required, and where most brokerages get it wrong.
Pillar 1: The designated compliance officer
The compliance officer is the named person with authority and responsibility for the program. For most Canadian mortgage brokerages, this is the principal broker or a senior staff member who reports directly to the principal broker.
Requirements:
- Named in the compliance program documentation.
- Authority to implement and enforce the program across the brokerage.
- Sufficient knowledge of FINTRAC requirements to perform the role.
- Reports to senior management on compliance matters.
Common gaps:
- Nominal compliance officer without real authority. FINTRAC will look for evidence the officer actually runs the program.
- Compliance officer with insufficient training. The officer needs ongoing training at a level that exceeds general staff training.
- No succession planning. What happens if the compliance officer leaves? The program needs continuity.
For smaller brokerages: the principal broker often serves as compliance officer. This is fine, but the dual role means the principal broker must actually perform compliance officer duties, not just hold the title. Documented calendar time spent on compliance matters, oversight of screenings, response to alerts - all of this needs to be real.
For larger brokerages: a dedicated compliance officer role makes sense once the brokerage reaches 30+ agents. Before that, a combined principal broker / compliance officer role is typical.
Pillar 2: Written compliance policies and procedures
The written framework every person in the brokerage follows. This is the single document (or set of documents) that describes how the brokerage meets every FINTRAC requirement.
Required coverage:
- Client identification. Which methods are used, how evidence is captured, how records are retained.
- Third-party determination. How the determination is made, how it’s documented.
- PEP and HIO screening. How screening is performed, how results are reviewed, how EDD is triggered and executed.
- Sanctions screening. Same, for sanctions.
- Ongoing monitoring. How continuous monitoring runs, how alerts are handled.
- Record retention. What’s retained, for how long, in what format.
- Suspicious transaction reporting. How STRs are identified, analyzed, decided on, and filed.
- Ministerial directives. How the brokerage complies with specific ministerial directives in force (Iran, Russia, North Korea, etc.).
- Agent supervision. How the brokerage supervises its agents’ compliance with the program.
- Large cash transaction reports. Less common for mortgage brokers but required when applicable.
Common gaps:
- Generic templates. Downloaded or copied from other brokerages without tailoring to the specific business. FINTRAC will spot this immediately.
- Inadequate detail on ongoing monitoring. Most brokerages’ policies describe onboarding screening but have thin coverage of what happens afterwards.
- Missing third-party determination procedures. One of the most common deficiencies in real estate broker AMPs; expect the same in mortgage broker examinations.
- Senior officer approval. Policies must be approved by a senior officer. Many brokerages have the document but not the approval record.
Version control matters. FINTRAC will want to see current policies and previous versions. Keep a version history showing when policies were updated, what changed, and who approved the change.
Pillar 3: The documented risk assessment
Your brokerage’s specific understanding of the money laundering and terrorist financing risks it faces. Not a generic checklist. A specific analysis of your specific business.
Required coverage:
- Client risk factors. Types of clients you work with, geographic distribution, presence of higher-risk categories.
- Business relationship risk. New clients vs established, one-time vs ongoing, complexity of client structures.
- Product and delivery channel risk. The mortgage products you offer, how clients engage (in-person, digital, referral), any higher-risk channels.
- Geographic risk. Where your clients are located, including connections to higher-risk jurisdictions.
- Technology and new developments. How you handle evolving risks (cryptocurrency-sourced funds, digital-only clients, cross-border transactions).
The risk assessment isn’t a snapshot. It’s an ongoing process. When your business changes - new product offerings, new client segments, new geographic markets - the risk assessment should update.
Common gaps:
- Generic risk matrices. A checklist that could apply to any business isn’t a risk assessment. Examiners will look for specific reasoning tied to the specific brokerage.
- Missing mitigation measures. Identifying risks without describing how you mitigate them is half a risk assessment.
- No update history. A risk assessment last revised in 2023 doesn’t reflect current business or current regulation (Bill C-12 effectiveness standard in particular).
Among real estate brokers that received FINTRAC AMPs, 88 percent failed to conduct risk assessments that met the standard. This is the pillar where brokerages are most vulnerable.
Pillar 4: The ongoing training program
Training for everyone in the brokerage with compliance responsibilities. In practice, this means training for all agents and administrative staff who touch client files.
Required coverage:
- Orientation training. New agents and staff receive training on the program when they join.
- Ongoing training. Regular refreshers, typically annual at minimum, with content updated for regulatory changes.
- Role-specific training. Compliance officers receive more in-depth training than general staff; principal brokers may receive supervisory-specific training.
Required documentation:
- Training materials and content.
- Attendance records showing who received training and when.
- Assessment records where applicable (quizzes, acknowledgments, certifications).
Common gaps:
- Training documented but not delivered. Agents sign a form but didn’t actually complete the training.
- No refresh after regulatory changes. Bill C-12 took effect in March 2026. If your training hasn’t been updated to reflect the new effectiveness standard, your program has a gap.
- One-size-fits-all. A single training deck for principal brokers and brand-new agents won’t meet expectations for either.
- No record of agents who joined between training cycles. New agents need orientation training, not just a pointer to the next annual session.
Practical note: Many networks (DLC, Mortgage Architects, Mortgage Alliance, etc.) provide compliance training to their affiliated brokers. This is a starting point, not a complete program. Brokerage-specific training on brokerage-specific policies is still required.
Pillar 5: The prescribed review
An independent assessment of your compliance program, required at least every two years.
Requirements:
- Independence. The reviewer cannot be the compliance officer or anyone who developed or runs the program being reviewed. Most brokerages use an external AML specialist or compliance consultant.
- Scope. The review must cover all elements: policies, risk assessment, training, effectiveness, and any prescribed areas.
- Documentation. A written report documenting the scope, methodology, findings, and recommendations.
- Action on findings. Deficiencies identified must be addressed, and remediation documented.
Common gaps:
- No prescribed review at all. Over half of real estate brokers that received FINTRAC AMPs had no documented prescribed review. This is a very serious deficiency.
- Insufficient scope. A review that addresses some elements but not all doesn’t meet the requirement.
- No remediation. A review that finds deficiencies but produces no remediation action is arguably worse than no review - it demonstrates awareness of gaps that weren’t closed.
Cost and logistics: Expect $5,000-$25,000 for a prescribed review depending on brokerage size and complexity. Budget every two years. Schedule the next review at the conclusion of the current one.
How the pillars fit together
The five pillars aren’t independent; they reinforce each other.
- The risk assessment informs which policies and procedures are needed and how they should be calibrated.
- Policies and procedures document what the compliance officer enforces and what the training program teaches.
- The compliance officer implements the policies, maintains the risk assessment, and delivers or arranges training.
- Training ensures the broader team executes the policies.
- The prescribed review validates that all of the above is working in practice.
A program where one pillar is weak tends to weaken the others. Strong risk assessment without strong policies is an analytical exercise that doesn’t operationalize. Strong policies without strong training become a binder no one reads. Strong training without a strong compliance officer becomes annual theatre.
How to build or refresh a program in 2026
For a brokerage without an existing program, or one that needs significant overhaul:
- Month 1: Designate the compliance officer. Name the person, document the role, ensure they have the authority and training.
- Month 1-2: Document the risk assessment. Specific to your brokerage. Spend real time on this. Among the five pillars, risk assessment has the highest examination failure rate.
- Month 2-3: Draft policies and procedures. Use FINTRAC’s guidance as the structural backbone, tailor the content to your brokerage. Get senior officer approval.
- Month 3-4: Implement screening and monitoring. This is where software matters most. A program that requires continuous screening won’t work on manual effort. Deploy the technical stack first, then roll out policies.
- Month 4-5: Deliver orientation training. To the full team. Document attendance and assessment.
- Month 5-6: Schedule the prescribed review. Engage a qualified reviewer. Complete within the two-year window from program implementation.
Six months is aggressive but realistic for a brokerage committed to building a strong program. Slower than six months leaves the brokerage exposed during the buildout. Faster than six months usually means corners got cut on the risk assessment or training.
Where software fits
The compliance program is a program, not a piece of software. But software changes how operational and examinable the program is.
Continuous screening and ongoing monitoring can’t be done manually at scale - software like BrokerPlus handles this automatically, producing the audit trail the prescribed review will expect. Centralized client data makes file retrieval at examination a non-issue. Integrated PEP identification with automatic classification prevents the manual-error gap that plagues generic CRM approaches.
None of this replaces the five pillars. All of it makes the five pillars easier to implement and easier to demonstrate working.
Frequently asked questions
What’s the difference between a compliance program and compliance software?
A compliance program is the five-pillar framework: the officer, the policies, the risk assessment, the training, the review. Compliance software is a tool that supports specific operational elements of the program (screening, monitoring, record retention). A brokerage needs both. Software without a program is insufficient documentation; a program without software is usually unworkable at scale.
Can I just adopt another brokerage’s compliance program?
No. The risk assessment specifically must reflect your brokerage. Policies and procedures can be adapted from templates but must be tailored to your operations. FINTRAC examiners can spot a generic program within minutes of opening it. A borrowed-and-pasted program is worse than no program because it creates a false sense of coverage.
How much does a compliance program cost to run?
Rough annual ranges by brokerage size: Solo broker / 1-5 agents: $2,000-$8,000/year. Mid-size brokerage (10-30 agents): $15,000-$40,000/year. Larger brokerage (50+ agents): $50,000-$150,000/year. Includes compliance officer time, software, training, and prescribed review amortized. Does not include legal fees if you’re dealing with an active examination or AMP.
Do I need a compliance program if I’m a solo broker?
Yes. The regulation doesn’t distinguish by brokerage size. A solo broker needs a scaled-down but complete program: designated compliance officer (you), written policies, risk assessment, training (for yourself), and prescribed review. The total effort is smaller than a multi-agent brokerage’s but the requirement is the same.
Who can conduct the prescribed review?
An independent party qualified to evaluate AML compliance programs under the PCMLTFA. This is typically a law firm’s AML practice, a compliance consultancy, or in some cases an internal audit function separated from the compliance function (which works for larger brokerages but not smaller ones). The reviewer should have Canadian AML experience specifically.
How often should the risk assessment be updated?
At minimum when the business changes materially (new products, new markets, new client segments, new regulatory environment). Many brokerages update annually as part of their standard review cycle. After Bill C-12, every Canadian brokerage should refresh their risk assessment to reflect the new effectiveness standard.
What’s the single highest-priority gap to close in 2026?
Continuous monitoring and ongoing screening infrastructure. Whether through integrated platform software or standalone vendors, the brokerage needs a demonstrable ongoing monitoring function. Post-Bill C-12, this is the operational gap most likely to show up at examination.