FINTRAC Enforcement

FINTRAC Credit Union Penalties: Four Credit Unions Fined a Combined $816,750 for Monitoring, Risk Assessment and STR Failures

September 30, 2026
Comply+ Team
8 min read

Primary sources: four FINTRAC public notices of administrative monetary penalties, September 24, 2026

Penalty amounts, dates, violations, provisions and classifications below are taken from the public notices. Statutory text is quoted from the Justice Laws website.

On September 24, 2026, FINTRAC published administrative monetary penalties against four credit unions, three in Ontario and one in New Brunswick. The penalties total $816,750 across 10 violations. Each notice says the violations were found during a compliance examination, and each says the penalty has been paid in full and the case is closed.

Ongoing monitoring appears in all four notices. Two of the four cite the handling of production orders from law enforcement, and in one of those FINTRAC links the gap directly to four suspicious transaction reports that were never filed.

What FINTRAC Announced

Credit unionHeadquartersImposedPenaltyViolations
Caisse populaire acadienne ltée (UNI Financial Cooperation), federally regulatedCaraquet, NBJuly 23, 2026$676,5003 (one very serious, two serious)
Caisse populaire Alliance limitée (Caisse Alliance), provincialNorth Bay, ONJune 5, 2026$82,5004 (all serious)
Pathwise Credit Union, provincialOshawa, ONJune 4, 2026$41,2502 (both serious)
Your Neighbourhood Credit Union Limited, provincialKitchener, ONAugust 10, 2026$16,5001 (serious)

Every notice states that the imposed penalty takes into account the criteria in section 73.11 of the Act and section 6 of the Administrative Monetary Penalties Regulations. For the classification ranges, see our FINTRAC AMP penalty schedule.

Ongoing Monitoring: The Finding in All Four Notices

For high-risk clients, section 157 of the Regulations prescribes written policies and procedures for "conducting, at a frequency appropriate to the level of risk, the ongoing monitoring of business relationships." Here is what each notice found.

  • Caisse Alliance (subsection 9.6(3) of the Act and section 157 of the Regulations, serious). Its policy required an annual review of high-risk clients. 46 of 118 high-risk client files had not been reviewed in over 12 months. Ten had not been reviewed in more than five years, and six had gaps of more than ten years between their two most recent reviews.
  • Your Neighbourhood Credit Union (paragraph 156(1)(b), serious). Approximately 76% of the ongoing monitoring records FINTRAC reviewed contained deficiencies. The notice lists missing principal business and beneficial ownership information for entity clients, the purpose and intended nature of the business relationship, politically exposed person and head of international organization determinations, client risk assessment updates, and documented enhanced measures for high-risk clients.
  • Pathwise Credit Union (paragraph 156(1)(b), serious). FINTRAC found the ongoing monitoring frequency "was not commensurate with a risk-based approach," and the documented frequency was not applied in practice. The notice cites a backlog of medium-risk account reviews and low-risk accounts that were monitored only on a trigger basis, while the policies and procedures established a set frequency.
  • UNI Financial Cooperation (paragraph 156(1)(b), serious). Ongoing monitoring was performed inconsistently, some clients had outdated identification information, and FINTRAC found the credit union failed to address a backlog of transactional alerts.

Each of the four notices describes a documented procedure that was not applied as written. Caisse Alliance's enhanced monitoring procedures "were not consistently applied in practice." Your Neighbourhood's documented policies and procedures "were not applied adequately." Pathwise's documented monitoring frequency "was not applied in practice." At UNI, documented ongoing monitoring procedures "were not consistently followed." Paragraph 156(1)(b) of the Regulations requires compliance policies and procedures to be both developed and applied.

Production Orders and Four Unreported STRs

The notice on UNI Financial Cooperation found that its policies "failed to document procedures for handling production orders related to money laundering and terrorist financing indicators. As a result, 4 suspicious transaction reports were not submitted." The four unreported transactions, cited under section 7 of the Act, are the only very serious violation among the four credit unions.

Your Neighbourhood Credit Union did have documented procedures for production orders, including assessing and reporting suspicious transactions to FINTRAC. FINTRAC found it did not consistently apply them when assessing the context and facts of a production order, "which could impact the reporting of suspicious activity to FINTRAC."

FINTRAC's suspicious transaction reporting guidance addresses this case directly:

"If you are in receipt of a production order from law enforcement related to a predicate offence, you must perform an assessment of the facts, context, and money laundering or terrorist activity financing indicators to determine whether you have reasonable grounds to suspect that a particular transaction is related to the commission of a money laundering or terrorist activity financing offence."

The same guidance lists being "the subject of a production order" as an example of a fact known to a reporting entity, and states that there is no monetary threshold for a suspicious transaction report.

The UNI notice lists indicators present in the four unreported transactions:

  • Size or type of transactions atypical of what is expected from the client.
  • Funds transferred in and out of an account on the same day or within a relatively short period of time.
  • Frequent transfers between different financial institutions.
  • Transaction involving an unusual or unjustified amount.
  • Transactions involving individuals or entities identified by the media, law enforcement, and/or intelligence agencies as being linked to criminal activities.

The notice also found UNI had no manual processes to adjust a client's risk rating for scenarios its transaction monitoring system did not capture automatically, "such as production orders or adverse media."

Risk Assessments, New Systems and Third-Party Tools

Three of the four notices cite paragraph 156(1)(c) and subsection 156(2) of the Regulations. Subsection 156(2) requires a reporting entity that intends to introduce a new technology or carry out a new development to assess and document the risk "before doing so."

  • Caisse Alliance implemented new operational and transaction-processing systems for onboarding, account management, payment processing and lending without assessing the associated risks or establishing mitigation measures. It had not assessed the risks of the geographic locations where its clients reside. Its third-party provider's predefined risk categories "did not generate adequate transactional alerts for all transaction types and client profiles," which the notice says contributed to missed red flags, including international electronic funds transfers to high-risk countries.
  • UNI Financial Cooperation did not conduct the required risk assessment of its transaction monitoring system, and its risk assessment lacked a breakdown of clients across risk categories.
  • Pathwise Credit Union did not fully evaluate risks related to its clients and business relationships, and did not adhere to its own risk assessment, which sets a timeframe for which members must be classified high risk after being the subject of a suspicious transaction report.

Russia Directives, Sanctions Evasion and the Two-Year Review

Caisse Alliance's policies did not include measures addressing the ministerial directives and operational restrictions related to Russia, and did not address the obligation to report suspected sanctions evasion. Section 7 of the Act requires a report where there are reasonable grounds to suspect a transaction is related to "a sanctions evasion offence," alongside money laundering and terrorist activity financing offences.

Caisse Alliance was also cited under paragraph 156(1)(f) and subsection 156(3) because its most recent two-year effectiveness review "did not identify weaknesses subsequently identified by FINTRAC," including gaps in policies and procedures and in identifying and reporting suspicious transactions. We covered what that review must test in our two-year effectiveness review article.

Seven Questions From the Four Notices

  1. When was each high-risk file last reviewed? Section 157 of the Regulations requires ongoing monitoring of high-risk business relationships at a frequency appropriate to the risk. Caisse Alliance's own policy set that frequency at annual, and 46 of 118 files were past it.
  2. Is the documented monitoring frequency the one applied? Pathwise was cited under paragraph 156(1)(b) for a medium-risk backlog and trigger-only low-risk monitoring.
  3. Does each monitoring record hold the required fields? The Your Neighbourhood notice lists beneficial ownership, purpose and intended nature of the relationship, PEP and HIO determinations, risk assessment updates and enhanced measures.
  4. Does every production order get an STR assessment? FINTRAC's STR guidance requires an assessment of the facts, context and indicators when you receive one. At UNI, the missing procedure resulted in four unfiled STRs.
  5. Can a production order or adverse media change a client's risk rating? UNI was cited for having no manual process to do so where its system did not capture them automatically.
  6. Was each new system risk-assessed before launch? Subsection 156(2) requires the assessment before a new technology is introduced. Caisse Alliance and UNI were both cited for systems that were not assessed.
  7. Do your policies cover the Russia directives and sanctions evasion reporting? Caisse Alliance's did not, and section 7 of the Act includes sanctions evasion offences.

Bottom Line

Four credit unions, $816,750, and one very serious violation: four suspicious transaction reports that UNI did not file, which FINTRAC attributes to the absence of a production order procedure. The accompanying news releases state that FINTRAC issued 35 notices of violation in 2025-26, the largest number in one year in the Centre's history, for a total of more than $247 million.

In all four notices, FINTRAC found a documented procedure that was not applied as written.

Disclaimer:

This article is provided for general informational purposes only and reflects our reading of publicly available FINTRAC information as of September 30, 2026. Penalty details are taken from the four FINTRAC public notices published September 24, 2026. Guidance quotations come from FINTRAC's guidance on reporting suspicious transactions, last modified May 22, 2025. Statutory and regulatory text is quoted from the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its Regulations on the Justice Laws website. This is not legal advice, regulatory guidance, or a substitute for professional counsel. Reporting entities should confirm obligations, dates, and enforcement implications against official FINTRAC publications, the PCMLTFA, applicable regulations, and qualified advisors.

Keep Every STR Decision on the Record

Comply+ drafts and validates STR, LCTR and EFTR reports, files them with FINTRAC by API once your analysts review, edit and approve, and keeps submission history, review notes and approvals in one filing record.

We hate spam too. We will not call you unless you ask us to, and we will only send relevant Comply+ emails that you can opt out of at any time. By submitting this form, you agree to our Terms of Service and acknowledge that you have read and accept our Privacy Policy.