FINTRAC Guidance

FINTRAC Two-Year Effectiveness Review: What It Must Test, Who Can Conduct It, and What a Missing One Costs

September 16, 2026
Comply+ Team
9 min read

Primary sources: FINTRAC public notice, FINTRAC compliance program guidance, and the Regulations

Penalty details in this article come from the public notice FINTRAC published on July 9, 2026 concerning VIP Realty Inc. The review requirements are quoted from section 156 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations, from section 9.6 of the Act as amended, and from FINTRAC's compliance program guidance. Harm levels come from FINTRAC's guide on harm done for compliance program violations.

On July 9, 2026, FINTRAC published a penalty against an Ottawa real estate brokerage. The public notice lists one violation, and it concerns the two-year review of the compliance program. FINTRAC determined the brokerage had not conducted a review to assess the effectiveness of its policies and procedures, risk assessment and training program. The penalty was $33,000, it was paid in full, and the case is closed.

The notice records the penalty as imposed for one violation: failure to institute and document the prescribed review, under subsection 9.6(1) of the Act and paragraph 156(1)(f) of the Regulations. FINTRAC classifies that violation as serious.

This article sets out what section 156 of the Regulations requires, how FINTRAC's guidance measures the two-year interval, who the regulation allows to conduct the review, and how FINTRAC's harm-done guide grades a review it finds deficient. Each requirement below is quoted from the regulation, the Act or FINTRAC's published guidance.

What Section 156 Actually Requires

Subsection 156(1) of the Regulations lists the elements every compliance program must have. The review is paragraph (f): instituting and documenting a plan for a review of the compliance program for the purpose of testing its effectiveness. Two further subsections carry the operative rules.

Subsection 156(3): the review shall be carried out and the results documented every two years by an internal or external auditor of the person or entity, or by the person or entity if they do not have an auditor.

Subsection 156(4), for entities: you shall report the findings of the review, any updates made to the policies and procedures within the reporting period and the status of the implementation of those updates in writing to a senior officer within 30 days after the day on which the review is completed.

The regulation therefore names three documented outputs: the plan under paragraph 156(1)(f), the results of the review under subsection 156(3), and the written report to a senior officer under subsection 156(4). FINTRAC's harm-done guide lists the failure to report the prescribed information within 30 days as a separate violation from the failure to conduct the review.

How the Two-Year Clock Is Measured

FINTRAC's guidance is specific: you must start your effectiveness review no later than 2 years (24 months) from the start of your previous review, and you must complete the previous review before the next one begins. The clock runs from start to start.

Applied to a review that started in October 2024, the next review must start by October 2026, whatever the completion date or reporting date of the first. FINTRAC's harm-done guide lists a review conducted beyond the prescribed two-year period among the Level 4 findings in the table below.

The Four Ways FINTRAC Says a Review Falls Short

FINTRAC's guide on harm done for compliance program violations sets out how it grades a deficient review before applying the penalty criteria. The violation is classified as serious, with a range of $1 to $100,000, and the guide assigns four levels of harm.

Level of harmWhat FINTRAC findsBase amount
Level 1: complete or widespreadThe reporting entity has not conducted any part, or most, of the prescribed review.$100,000
Level 2: important weaknessesThe review does not include testing for effectiveness, and its scope does not cover the compliance policies and procedures, risk assessment and training program.$75,000
Level 3: moderate weaknessesThe review does not evaluate the compliance program documentation, such as policies and procedures, to ensure it is complete and up to date.$50,000
Level 4: lesser weaknessesThe review is conducted beyond the two-year period, the methods are not clearly documented and do not show how effectiveness was tested, or an internal or external auditor did not conduct the review when one was required.$25,000

The notice on VIP Realty states that no review had been conducted. Level 1 of the guide describes a reporting entity that has not conducted any part, or most, of the prescribed review. The guide separates that case from a review that exists but, in its Level 2 description, does not include testing for effectiveness, and from a review that is late, undocumented in its methods, or conducted by someone other than the auditor the regulation requires, which it places at Level 4.

Two caveats on that table. The guide was last modified in 2019, and FINTRAC's page on the amended penalties framework states that review periods falling entirely before March 26, 2026 continue to use the existing penalties policy. The VIP Realty penalty was imposed on December 1, 2025. For violations on or after March 26, 2026, the same page states that FINTRAC can apply increased maximum penalty amounts, up to 40 times the previous limits, will define which violations are prescribed, and is updating its penalties policy and developing new guidance.

Effective Is Now a Word in the Act

Bill C-12 added a sentence to section 9.6 of the Act that did not exist before March 26, 2026. Subsection 9.6(1.1) reads: The person or entity shall ensure that the program is reasonably designed, risk-based and effective.

Among the elements listed in subsection 156(1) of the Regulations, the review under paragraph (f) is the only one whose stated purpose is testing its effectiveness. FINTRAC has said it is updating its penalties policy and developing new guidance to reflect the amendments.

Who Can Conduct It

The regulation names the reviewer: an internal or external auditor, or the reporting entity itself if it has no auditor. FINTRAC's guidance adds the independence point as best practice: to ensure that your review is impartial, it should not be conducted by someone who is directly involved in your compliance program activities.

FINTRAC's harm-done guide lists, among its Level 4 findings, that when required, an internal or external auditor did not conduct the review. On responsibility, the guidance states: regardless of who carries out the review, as a reporting entity it is your responsibility to ensure that the review is conducted (at a minimum) every 2 years and that the review tests the effectiveness of your compliance program.

What Testing for Effectiveness Looks Like

FINTRAC's guidance describes the plan before it describes the review. The plan should not only describe the scope of the review, but it should include the rationale that supports the areas of focus, the time period that will be reviewed, the anticipated evaluation methods and sample sizes. The guidance says breadth and depth can vary with the complexity of your business, your transaction volumes, the findings of the previous review and your current risks.

The guidance then lists what the review itself may include: interviews with the people who handle transactions, a review of a sample of your records, a review of transactions to assess whether suspicious transactions were reported, and verification that enhanced measures were taken for the clients you rated high risk.

Comply+ keeps submission history, review notes and approvals in the filing record for the reports it prepares, and your analysts review, edit and approve every report before it is filed. The review itself, who conducts it and what it finds remain the reporting entity's responsibility.

Related Comply+ resources: If you are planning a review or preparing for the examination that follows one, these pages cover the examination process, a penalty where the review was one of four findings, the penalty schedule, a compliance checklist, and the option to have the reporting work handled for you.

Eight Questions to Answer Before Your Next Review Starts

  1. When did the last review start? FINTRAC's guidance requires the next review to start no later than 24 months from that date, and the previous review to be completed before the next one starts.
  2. Is there a written plan? The guidance says the plan should describe the scope, the rationale for the areas of focus, the time period reviewed, the evaluation methods and the sample sizes.
  3. Does the scope cover all three elements? The regulation names the policies and procedures, the risk assessment and the training program. A scope that omits them appears in the guide's Level 2 description.
  4. Does the method test effectiveness? The guidance gives examples: interviews with those handling transactions, a review of a sample of records, a review of transactions to assess whether suspicious transactions were reported, and verification that enhanced measures were taken for high-risk clients.
  5. Who is conducting it? The regulation requires an internal or external auditor, or the reporting entity itself if it has no auditor. The guidance adds, as best practice, that the reviewer should not be directly involved in the compliance program's activities.
  6. Are the results documented? Subsection 156(3) requires the results of the review to be documented, and the guide's Level 4 description covers review methods that are not clearly documented.
  7. Is the senior officer report scheduled? Subsection 156(4) requires an entity to report the findings, the updates made to policies and procedures within the period, and the status of their implementation, in writing, within 30 days of completion.
  8. What happened to the last findings? The senior officer report must state the implementation status of updates, and the guidance lists findings from previous reviews among the factors that set the breadth and depth of the next one.

Bottom Line

Section 156 of the Regulations requires the review every two years, with results documented, carried out by an internal or external auditor where the reporting entity has one, and reported in writing to a senior officer within 30 days of completion. Since March 26, 2026, subsection 9.6(1.1) of the Act also requires the compliance program to be reasonably designed, risk-based and effective. The July notice on VIP Realty shows that the absence of the review is penalized as a violation on its own.

The two-year review is the one element of the compliance program whose stated purpose in the regulation is testing its effectiveness.

Disclaimer:

This article is provided for general informational purposes only and reflects our interpretation of publicly available FINTRAC information as of September 16, 2026. Penalty details are taken from the FINTRAC public notice concerning VIP Realty Inc., published July 9, 2026. The harm levels and base amounts come from FINTRAC's guide on harm done assessment for compliance program violations, last modified in 2019, which belongs to the penalties policy governing review periods that fall before March 26, 2026; FINTRAC has stated that its penalties policy and guidance under the amended framework are still being developed. Statutory and regulatory text is quoted from the Justice Laws website, current to July 21, 2026. This is not legal advice, regulatory guidance, or a substitute for professional counsel. Reporting entities should confirm obligations, dates, and enforcement implications against official FINTRAC publications, the PCMLTFA, applicable regulations, and qualified advisors.

Keep the Records Your Next Effectiveness Review Will Sample

Comply+ drafts and validates STR, LCTR and EFTR reports, files them with FINTRAC by API once your analysts review, edit and approve, and keeps submission history, review notes and approvals in one filing record.

We hate spam too. We will not call you unless you ask us to, and we will only send relevant Comply+ emails that you can opt out of at any time. By submitting this form, you agree to our Terms of Service and acknowledge that you have read and accept our Privacy Policy.