← Back to blog

Anti-Money Laundering Mortgage Compliance: What Brokers Must Do

August 20, 2026
Anti-Money Laundering Mortgage Compliance: What Brokers Must Do

Mortgage administrators, mortgage brokers, and mortgage lenders became reporting entities under Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act on October 11, 2024. If you fall into any of those three categories, you now need a documented anti-money laundering mortgage compliance program and a working reporting relationship with FINTRAC. There's no grace period left to hide in.

Three things need to happen this week, not next quarter. Appoint a compliance officer, even if that's you wearing a second hat. Run FINTRAC's self-assessment to confirm exactly which obligations apply to your business model. And set up a basic workflow for filing Suspicious Transaction Reports (STRs) and Large Cash Transaction Reports (LCTRs) before you need one in a hurry.

  • Appoint and document a compliance officer
  • Complete the FINTRAC self-assessment for your business type
  • Build (or buy) a reporting workflow for STR, LCTR, LVCTR, and TPR filings

Reporting entities must file reports on single cash or virtual currency transactions of C$10,000 or more, with limited exceptions for funds from financial entities or public bodies.

Pro Tip: Don't wait for your first large transaction to test your reporting workflow. Run a dry drill with a fake file this month so you're not improvising when a real one lands on your desk.

Key Takeaways

Mortgage administrators, brokers, and lenders must run a documented, risk-based compliance program and report to FINTRAC on a defined timeline, or face penalties that scale with the size of the gap found.

PointDetails
Reporting entity status is mandatoryMortgage administrators, brokers, and lenders became FINTRAC reporting entities on October 11, 2024.
Reports have specific triggersFile STRs on suspicion regardless of amount, and LCTR/LVCTR reports at C$10,000 or more.
Records need a 30-day production planStructure files now so you can produce five years of records within 30 days of a request.
Risk assessments need written rationaleDocument why each client got their risk rating, not just the rating itself.
Automation reduces manual compliance riskAutowrite automates document classification and extraction to build audit-ready compliance packages.

Table of Contents

Who Falls Under Anti-Money Laundering Mortgage Rules?

Three business types are squarely in scope: mortgage administrators (who service loans on behalf of investors), mortgage brokers (who arrange financing between borrowers and lenders), and mortgage lenders (who fund the loans directly). If your business touches any part of originating, arranging, or servicing a mortgage, you're almost certainly a reporting entity under FINTRAC's framework.

The edge cases trip people up. A private lender funding deals out of personal capital is still a lender under the PCMLTFA framework. A brokerage that only places loans and never funds them is still a broker, and still on the hook. Agents working across multiple lender relationships don't get to point at the lender and assume coverage. FINTRAC requires each reporting entity to maintain its own independent compliance program, even when a partner in the transaction has one too.

  • Mortgage administrators servicing loans for third-party investors
  • Mortgage brokers arranging financing, regardless of loan volume
  • Mortgage lenders funding deals directly, including private lenders
  • Agents and sub-brokers operating under a brokerage's license

Confirming your exact scope takes fifteen minutes. FINTRAC's self-assessment tool asks a handful of business-model questions and tells you which obligations attach to your operation, which makes it the fastest way to stop guessing about federal versus provincial requirements. Provincial licensing bodies like FSRA set supervisory expectations, but the federal FINTRAC rules govern your AML program itself.

What Changed on October 11, 2026?

The amendment brought mortgage administrators, brokers, and lenders into the PCMLTFA's reporting entity regime for the first time. Before that date, mortgage professionals in most provinces had no federal AML reporting obligation at all, even though real estate transactions have long been recognized as a laundering vector. FINTRAC's regulatory update closed that gap directly.

FSRA frames the change as a deliberate move to strengthen the federal government's ability to protect the economy by closing gaps that mortgage transactions had previously allowed. Real estate has been flagged internationally as a laundering-friendly asset class for years. Large dollar values, complex ownership structures, and financing arrangements that can obscure the source of funds made mortgages a logical next sector for federal oversight.

The instruments you need to know by name:

  • The PCMLTFA itself, the statute establishing reporting entity status
  • The associated Regulations, which set out specific obligations and thresholds
  • FINTRAC guidance documents, which translate the law into operational steps

Every mortgage professional in scope has had over a year to build a program. FINTRAC assessments don't care whether you knew the rule existed.

What Are Your Core Statutory Obligations?

Seven items make up the checklist FINTRAC expects every mortgage sector entity to satisfy. Skip one and you have a gap that shows up the moment an examiner asks for evidence.

  • Compliance program: written policies, a designated officer, and documented risk assessment
  • KYC and identity verification: confirming who you're dealing with before or during the transaction
  • Record-keeping: retaining transaction, verification, and reporting records per regulatory minimums
  • Suspicious Transaction Reports (STR): filed whenever you have reasonable grounds to suspect a transaction relates to money laundering or terrorist financing
  • Large Cash/Virtual Currency Transaction Reports (LCTR/LVCTR): filed for qualifying transactions at or above C$10,000
  • Terrorist Property Reports (TPR): filed when you know a client possesses or controls terrorist property
  • Two-year effectiveness review: an internal audit of whether your program actually works, not just whether it exists on paper

Each item maps to a specific operational task. Your compliance program is the umbrella document; KYC and record-keeping are the daily habits; the reports are the outputs when something meets a threshold or raises suspicion; the effectiveness review is the checkup that proves the whole system holds together. Legal analysis from Fasken notes that some records must be kept for at least five years, and FINTRAC expects that whatever you're storing can be produced within 30 days of a formal request. That 30-day window is the detail that separates firms with real systems from firms with good intentions.

What Should a Mortgage Compliance Program Include?

FINTRAC expects five core elements, and it expects them sized to your actual business, not copied from a template a friend at another brokerage handed you. A program built for a five-person shop looks nothing like one built for a multi-branch lender, and regulators know the difference on sight.

The five non-negotiable components:

  • A compliance officer, named in writing, with real authority to act on findings
  • Written policies and procedures covering intake, verification, monitoring, and reporting
  • A documented risk assessment covering clients, products, geography, delivery channels, and any other relevant factor
  • A training program for everyone who touches client files, not just the compliance officer
  • A review of program effectiveness at least every two years

Solo brokers and small shops can run a lean version of this. One person can hold the compliance officer role, policies can run a handful of pages instead of a binder, and training can be a documented annual session rather than a rolling program. What can't shrink is the paper trail. Even a one-person operation needs a written risk assessment and a dated training record, because FINTRAC's expectations don't scale down with headcount, only with complexity.

Mid-sized brokerages with multiple agents need something closer to a real governance structure: a compliance officer with actual bandwidth, periodic training sessions logged by attendee, and a risk assessment that's revisited when the business changes, not just when the calendar says two years have passed. Lenders funding their own deals face the highest bar, since they're often handling larger dollar volumes and more direct exposure to source-of-funds questions.

FINTRAC's own guidance is explicit that a one-size-fits-all program is insufficient precisely because risk varies so much by business model.

Pro Tip: Write down the reasoning behind every risk rating you assign, not just the rating itself. "Rated high due to third-party wire from an offshore account with no prior relationship" survives an audit. "High risk" alone does not.

What Do You Report to FINTRAC, and When?

Four report types cover almost every scenario a mortgage professional will encounter, and each one has a distinct trigger.

Report typeTriggerThreshold or condition
Suspicious Transaction Report (STR)Reasonable grounds to suspect ML/TF connectionNo dollar threshold; filed regardless of amount
Large Cash Transaction Report (LCTR)Cash received in a single transaction or seriesC$10,000 or more, with financial-entity exceptions
Large Virtual Currency Transaction Report (LVCTR)Virtual currency received in a single transactionC$10,000 or more equivalent value
Terrorist Property Report (TPR)Knowledge that a client possesses or controls terrorist propertyNo threshold; filed immediately

The threshold reports are mechanical: hit the number, file the report. The STR is where judgment matters most, and it's also where mortgage professionals most often fall short. A single large cash gift for a down payment might be entirely legitimate, or it might be a straw buyer arrangement designed to move funds through real estate. A rapid property flip with no obvious market rationale, a third party wiring closing funds with no stated relationship to the borrower, or gift letters with inconsistent or unverifiable sourcing all warrant an STR even when no single transaction crosses the C$10,000 cash threshold.

File through FINTRAC's designated electronic channels and keep a submission record for every report, including the ones you decided not to file after documented review. That negative decision, properly recorded, is often what protects you during an assessment. FINTRAC's reporting threshold guidance also covers the 24-hour aggregation rule for related cash transactions, which matters if a client structures deposits to stay under the single-transaction threshold.

What Do You Report to FINTRAC, and When? — overview diagram

When Do You Need to Verify a Client's Identity?

Identity verification kicks in the first time you establish a business relationship with a client, and again in specific prescribed circumstances, like large payments or instructions coming from someone other than the named client. Waiting until closing day to ask for identification is the single most common gap examiners find.

Verification elementWhat to collectWhen required
Individual IDGovernment-issued photo ID, verified in person or through approved electronic methodsAt first business relationship or before a large transaction
Beneficial ownershipOwnership and control information for corporate or trust clientsWhen the client is an entity, not an individual
Third-party informationIdentity of anyone instructing or benefiting from the transaction who isn't the named clientWhenever instructions or funds come from someone other than the client
Source of fundsDocumentation supporting where deposit or gift funds originatedFor gift funds, third-party payments, or unusual sourcing

Acceptable verification methods include in-person photo ID checks and approved electronic verification services, but whichever method you use, document it the same way every time. For corporate borrowers or trusts, you need beneficial ownership information identifying who actually controls the entity, not just who signed the application. Build the intake form to capture all of this at the first point of contact rather than chasing it down mid-file, and store the proof of verification, not just a checkbox saying it happened.

What Records Must You Keep, and for How Long?

FINTRAC's recordkeeping rules cover more than transaction files. You need receipt-of-funds records, client identification and verification records, beneficial ownership documentation, copies of every report you file, training attendance logs, your written risk assessment, and the findings from each effectiveness review.

Record typeMinimum retentionFormat notes
Client identification and verificationAt least five years from the date the relationship endsElectronic acceptable if paper copy can be produced on request
Transaction and report records (STR, LCTR, LVCTR, TPR)At least five years from the date of the transactionKeep submission confirmations alongside the report itself
Training logsAt least five yearsShould include date, attendees, and topics covered
Risk assessments and effectiveness reviewsAt least five years, updated on scheduleWritten rationale required, not just conclusions

FINTRAC expects to receive requested records within 30 days of a formal request, and electronic files are fine as long as you can produce a readable paper copy on that timeline. That means your filing structure matters as much as what's inside the files. A compliance officer who has to reconstruct a client's history from six different systems will blow through 30 days fast.

Pro Tip: Set up a single naming convention and folder structure across every file before you need to pull one for FINTRAC. Retrofitting an organizational system under a 30-day deadline is how firms miss it.

How Should You Monitor Business Relationships Over Time?

Ongoing monitoring exists to catch what a one-time verification misses: activity that shifts after the relationship starts, identity or ownership details that go stale, and risk ratings that no longer reflect reality. A client who looked low risk at application can look very different eighteen months later.

Hands adjusting risk assessment checklist at desk

Monitoring cadence should track your risk ratings. High-risk files warrant frequent review, sometimes at every transaction touchpoint. Medium-risk files might get a periodic check tied to specific triggers. Low-risk files still need occasional reconfirmation, just on a longer cycle.

Watch for these triggers regardless of risk tier:

  • Payments arriving from someone other than the named borrower
  • Occupancy that doesn't match what was declared on the application
  • Income or source-of-funds documentation that shifts materially between application and closing
  • A pattern of rapid refinances or flips with no clear economic logic

Any of these should push a file into escalated review, and depending on what you find, that review may end in an STR rather than a routine note in the file.

How Do You Determine Third Parties and Screen for PEPs?

A third-party determination asks one question: is the person instructing this transaction, or benefiting from it, someone other than your named client? If a spouse is directing the deal, if a family member is providing the deposit, or if funds are arriving from an account that doesn't belong to your client, you have a third party, and you need their identity information, not just their name on a gift letter.

Screening for politically exposed persons (PEPs) and heads of international organizations (HIOs) is a related but separate step. PEPs are current or former senior government officials and their close associates; PEFPs cover foreign counterparts specifically; HIOs cover leaders of international bodies. Screening typically combines open-source checks with commercial screening databases, run at onboarding and periodically afterward.

  • Identify who is instructing the transaction versus who is named on the file
  • Collect identity information for any third party providing funds or instructions
  • Run PEP and HIO screening at onboarding and on a periodic refresh cycle
  • Escalate any positive match to enhanced due diligence immediately

When a client screens positive as a PEP, PEFP, or HIO, or is otherwise flagged high risk, you need source-of-wealth documentation, typically within 30 days, along with enhanced verification and tighter ongoing monitoring.

Pro Tip: Screen before you accept the file, not after you've done the work. Discovering a PEP match mid-underwriting means redoing verification steps you already thought were finished.

What Are the Red Flags for Mortgage Money Laundering?

Cash isn't the main story in mortgage-related laundering anymore. FSRA points to indicators like unusual gift funds, straw buyers, occupancy inconsistencies, and rapid property flips as the patterns worth watching.

  • A large gift letter with a donor who has no traceable relationship or income history to support the gift
  • A buyer who never occupies or rents the property despite stating owner-occupancy on the application
  • A property purchased and resold within weeks at a price jump with no market justification
  • A third party wiring closing funds with no documented connection to the borrower

When you see one of these, document what you observed, escalate to your compliance officer, and file an STR if the facts support reasonable grounds for suspicion, even without a dollar threshold involved.

Pro Tip: Train your intake staff to flag small, odd details, not just big dollar amounts. A borrower who can't explain a modest gift is often a bigger warning sign than a borrower with a large, well-documented one.

What Happens If You Don't Comply?

FINTRAC can levy administrative monetary penalties for gaps in your compliance program, and criminal penalties exist for more serious violations tied to reporting failures. Blakes notes that forthcoming legislation tied to broader AML reforms could push maximum penalties as high as C$20 million, a figure that signals how seriously enforcement is trending across real estate and lending generally.

A FINTRAC assessment typically starts with a records request, moves into an examination of your program against the regulatory checklist, and ends with findings that either clear you or require a remediation plan with deadlines.

  • Fix the specific gap identified immediately, not just on paper
  • Update your written policies to reflect the correction
  • Consider voluntary disclosure if you find a reporting failure before FINTRAC does

Firms that treat an assessment finding as a to-do list, rather than a crisis, tend to come out the other side with a stronger program and no repeat findings.

What's a Realistic 30/60/90-Day Compliance Timeline?

Trying to build everything at once is how firms stall out. Sequence the work instead.

  1. Days 1-30: Appoint your compliance officer in writing. Run the FINTRAC self-assessment. Document your current intake workflow exactly as it operates today, warts and all. Identify which parts of your business carry the highest risk.
  2. Days 31-60: Finalize your written policies and procedures based on what the self-assessment revealed. Start staff training, even if it's a single session to begin with. Stand up your record-keeping system and your STR/LCTR/LVCTR filing workflow.
  3. Days 61-90: Run a test transaction through your reporting workflow end to end. Complete your first internal effectiveness review, even an informal one. Refine risk ratings based on what the first three months showed you. Assemble a sample evidence package as if FINTRAC asked for one tomorrow.
  • Assign one owner per checklist item, not a vague "the team will handle it"
  • Calendar the two-year effectiveness review now, so it doesn't quietly slip

Ninety days sounds tight, but the sequence matters more than the speed. Skipping straight to reporting workflows before you've documented your risk assessment just means rebuilding it later.

How Do You Prepare for a FINTRAC Records Request?

FINTRAC assessments commonly ask for the same set of documents: your written policies and procedures, training logs, client identification records, your risk assessment, and copies of every STR, LCTR, LVCTR, and TPR you've filed in the review period.

  1. Build a standing evidence package now, before you're asked, covering each of those categories.
  2. Name one point of contact responsible for pulling and submitting records so the request doesn't bounce between three people.
  3. Time yourself producing a sample package to see if you'd actually hit the 30-day window under real conditions.
  4. Loop in legal counsel early if a records request surfaces a gap that needs remediation, rather than after you've already responded.
  • Policies and procedures document, current version with revision history
  • Training attendance logs with dates and topics
  • Risk assessment and its supporting rationale
  • Full set of filed reports for the assessment period

Run a mock request internally once a year. It's the cheapest way to find out your evidence package has a hole in it before FINTRAC finds it for you.

Where Does Automation Fit in Your Compliance Program?

Document intelligence tools now handle a lot of the grinding work that used to eat a compliance officer's week: classifying incoming files, pulling identity and beneficial ownership fields off scanned documents, and populating report drafts from data that's already sitting in the file. Practitioner commentary from Blakes points to automation as a high-leverage control specifically because it produces audit-ready records and cuts human error out of repetitive KYC and reporting steps.

  • Automated classification sorts intake documents so nothing sits unreviewed in a shared inbox
  • Extraction tools pull ID and ownership fields directly into your file, reducing manual re-entry errors
  • Auto-populated report drafts speed up STR and LCTR filing without skipping the human judgment call
  • Audit trail generation keeps a timestamped record of every step, ready for a 30-day production request

None of this replaces human review on high-risk files. A flagged PEP match or an ambiguous gift letter still needs a person making the call. Data residency and encryption matter too. If you're evaluating any vendor, confirm where client data physically lives and how it's encrypted before you sign anything, and don't skip vendor due diligence just because the sales demo looked polished.

Pro Tip: Map every manual step in your current intake process on paper first. You can't measure time saved from automation if you never timed the process it's replacing.

What Actually Worked When We Built This Program

The single highest-leverage move early on wasn't the fanciest one. It was naming a compliance officer with real authority and giving that person two uninterrupted weeks to document the current intake process exactly as it happened, mistakes included. Everything else, the policies, the training, the reporting workflow, got easier once that baseline existed on paper.

The second win was automating document intake before touching anything else. Manual re-entry was where errors crept into files, and fixing that early freed up hours for the harder judgment calls, like third-party determinations and risk ratings that actually needed a human brain.

Treat this as an operational discipline you run every quarter, not a binder you build once and file away. The firms that struggle are the ones that treated October 11, 2024 as a deadline instead of a starting point.

How Autowrite Supports Your Anti-Money Laundering Mortgage Program

Building the audit trail FINTRAC expects means someone has to classify documents, extract identity and ownership fields, and keep a timestamped record of every step, and doing that by hand across dozens of active files is where most brokerages lose time and accuracy. Autowrite automates the document-heavy parts of that workflow: it classifies incoming files, extracts the data underwriting and compliance both need, and assembles e-sign and compliance packages that are ready to hand over the moment a records request lands on your desk.

Autowrite

When you're evaluating any automation platform for this work, four criteria matter more than the sales pitch: Canadian data residency, audit trails built for FINTRAC's 30-day production window, integration with the mortgage software you already run, and support for remote identity verification. Autowrite is built around those four requirements specifically for Canadian mortgage brokers, which is a narrower and more useful target than a generic document tool retrofitted for compliance. For brokerages that want practical implementation support alongside the technology, WeFinanceU offers guidance on the operational side of these obligations.

If your current process still means manually re-typing ID fields into a spreadsheet before you can even start underwriting, start a free trial of Autowrite and see how much of that work disappears in your next file.

Frequently Asked Questions

Is anti-money laundering compliance mandatory for all mortgage brokers in Canada? Yes. Since October 11, 2024, mortgage administrators, mortgage brokers, and mortgage lenders are all classified as reporting entities under the PCMLTFA, regardless of firm size or transaction volume.

What is the FINTRAC reporting threshold for mortgage transactions? Single cash or virtual currency transactions of C$10,000 or more generally require a Large Cash Transaction Report or Large Virtual Currency Transaction Report, with exceptions for funds from financial entities or public bodies. Suspicious Transaction Reports have no dollar threshold at all.

How long must mortgage brokers keep AML compliance records? Retention periods run at least five years for client identification, verification, transaction, and reporting records, and files must be producible within 30 days of a FINTRAC request.

Do private mortgage lenders need a FINTRAC compliance program? Yes. Private lenders funding deals directly are mortgage lenders under the PCMLTFA framework and carry the same compliance program and reporting obligations as institutional lenders.

What penalties can FINTRAC impose for non-compliance? FINTRAC can levy administrative monetary penalties for compliance program gaps, with criminal penalties available for serious reporting violations. Broader AML reform efforts point toward maximum penalties as high as C$20 million under forthcoming legislation.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

Keep these on hand for day-to-day compliance decisions rather than relying on secondhand summaries.

Use FINTRAC's own pages for operational rules, law firm analysis for interpreting ambiguous language, and FSRA for how provincial supervision layers on top of the federal framework.