Canadian law allows five prescribed methods to verify a client's identity: government-issued photo ID, credit file, dual-process, affiliate/member, and reliance. Mortgage brokers and other regulated professionals must use one of these when FINTRAC's compliance guidance requires verification under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act. This article walks through each method for individuals and entities, plus the privacy rules that apply when verification goes digital.
TL;DR:
- The dual-process method is most common for remote onboarding, requiring two independent and current sources from different originators, not just two documents from the same issuer.
- The credit-file method is limited to files from Canadian bureaus existing for at least three years, with strict matching of client details; foreign credit reports do not qualify.
- Verification involving entities requires confirming beneficial owners who control 25% or more of the company, ensuring they are natural persons, and verifying their identities through prescribed methods.
- Biometric checks demand informed consent, with a preference for the least intrusive method and a clear policy for fallback options, retention, and proportionality.
- Ongoing monitoring involves updating client information based on risk, suspicion, or significant changes, not re-verification unless red flags or major change occurs.
Table of Contents
- Legal framework: who has to follow these rules
- Which method fits your situation
- Government photo ID: acceptable documents and what to check
- Credit file method: bureau rules and what has to match
- Affiliate/member and reliance: using another entity's verification
- Verifying entities and finding the real owners behind them
- Privacy rules for digital ID checks and biometrics
- Ongoing monitoring versus starting verification over
- Building a compliance file that holds up to review
- Where the real friction shows up in practice
- Autowrite: built for the paperwork behind every verification
- Where to read the primary rules yourself
- Sources
- FAQ
Legal framework: who has to follow these rules
The Proceeds of Crime (Money Laundering) and Terrorist Financing Act, along with its associated regulations, sets the legal foundation for identity verification in Canada. FINTRAC, the country's financial intelligence unit, enforces these obligations and publishes the guidance that spells out exactly which methods count as compliant. If you fall under the Act as a "reporting entity," you cannot invent your own verification process. You pick from the five sanctioned methods, document your work, and keep records for the periods FINTRAC specifies.
Reporting entities cover a wide swath of the financial and legal services sector, including:
- Mortgage brokers, agents, and administrators
- Banks, credit unions, and trust companies
- Securities dealers and portfolio managers
- Life insurance companies and agents
- Money services businesses and casinos
- Real estate brokers and developers
Verification is not a one-time formality tucked away in a client's first file. Once identity is confirmed, that information has to stay current, and your compliance program needs a documented process for when and how you re-check it. Recordkeeping obligations run alongside verification: you need to retain evidence of which method you used, what documents or sources you relied on, and when the check took place. FINTRAC examiners will ask for this evidence during an assessment, and gaps in the paper trail are treated the same as gaps in the verification itself.
For mortgage brokers specifically, this framework intersects with existing obligations around anti-money laundering compliance, since identity verification is one piece of a broader due diligence program that also covers source-of-funds checks and suspicious transaction reporting.
Which method fits your situation
Each of the five methods suits a different scenario, and picking the right one up front saves you from re-doing work later.
- Government-issued photo ID works best for in-person meetings where the client can hand over an original document on the spot.
- Credit file suits established Canadian residents with a long financial history, since the file must have existed for at least three years to qualify under this method.
- Dual-process is the go-to for remote onboarding, where you cannot see a physical ID but can cross-check two independent, current sources.
- Affiliate/member applies when a related entity, such as a sister company within the same corporate group, has already verified the client using an accepted method.
- Reliance lets you use another reporting entity's completed verification, provided you obtain a written arrangement and confirm the details match.
A few limits matter more than the rest. The dual-process method requires two different sources from two different originators, not two documents from the same issuer. The credit-file method's three-year existence rule is stricter than the six-month threshold that applies when a credit file is used as just one leg of a dual-process check. Affiliate verification only works if the affiliate actually used one of the five prescribed methods themselves, not an informal check.
When a client's situation is ambiguous, such as a non-resident with no Canadian credit history and no in-person meeting scheduled, combining checks or escalating to a supervisor for a documented decision is safer than forcing a method that does not quite fit. Non-resident clients, for instance, often cannot use the credit-file method at all because Canadian credit bureaus will have no record of them, which pushes most remote non-resident verification toward dual-process with foreign-issued documents that meet the reliability criteria.

Government photo ID: acceptable documents and what to check
The government-issued photo ID method is the most familiar to clients and the most straightforward to execute in person. The document has to be current (not expired), issued by a federal, provincial, or territorial government or a foreign equivalent, and it has to include the client's name, photo, and a unique identifying number.
Common qualifying documents include a driver's license, passport, provincial ID card, or permanent resident card. When you have the physical document in front of you, work through these steps:
- Confirm the name on the document matches the name the client gave you and the name on your engagement paperwork.
- Compare the photo to the person presenting it, checking for consistency in facial features.
- Check the expiry date to confirm the document is still valid on the day of verification.
- Record the unique identifier, such as a license or passport number, along with the issuing authority.
- Note the document type and issue date in the client file for your records.
If anything about the document looks altered (mismatched fonts, a laminate that appears tampered with, or a photo that seems swapped), stop the verification and ask for an alternative document rather than proceeding on a hunch. Document your concern in the file even if the client later produces a valid alternative, since that note protects you if the file is ever reviewed.
Pro Tip: Photograph or scan both sides of the ID at the time of verification rather than relying on a written description; a copy resolves disputes about what was actually checked months later.
Credit file method: bureau rules and what has to match
The credit file method relies on a Canadian credit history rather than a physical document, which makes it useful for clients who prefer not to hand over an ID or who are verifying remotely through a vendor integration. The rules here are specific and worth getting right, since credit-file verification is one of the areas FINTRAC scrutinizes closely.
- The credit file must come from a Canadian credit bureau, meaning Equifax Canada or TransUnion Canada, or from a vendor authorized to resell their data.
- The file must have existed for at least three years to satisfy the credit-file method on its own, a longer threshold than the six-month rule that applies when a credit file supports a dual-process check instead.
- A foreign credit bureau does not qualify, regardless of how established the client's credit history is in another country.
- The information drawn from the file must originate from more than one underlying source to be acceptable.
When you pull a credit file, the name, address, and date of birth on the file need to match what the client provided. Minor discrepancies, such as an old address that predates a recent move, are usually explainable and worth a note in the file rather than an automatic rejection. Larger mismatches, like a different date of birth entirely, mean the credit file does not verify this client and you need to fall back on another method.
For your records, log the bureau or vendor name, the date you queried the file, and the credit-file reference number the bureau assigns. That reference number lets you pull the same file again if a regulator or auditor asks you to substantiate the check, and it separates a completed verification from a client's self-reported credit summary, which does not qualify under this method.
Affiliate/member and reliance: using another entity's verification
You do not always have to verify a client from scratch. Two methods let you build on work someone else has already done, provided you meet specific conditions.
- Affiliate/member reliance applies when a related entity within the same corporate structure, such as a parent company or an affiliated brokerage, has already verified the client using one of the five prescribed methods and shares that record with you.
- The affiliate's original verification must have used an accepted method itself. You cannot rely on an affiliate's informal or undocumented check.
- Reliance on another reporting entity works similarly but applies more broadly, covering any reporting entity (not just an affiliate) that has completed verification and agrees, in writing, to share the record with you.
- You need a written arrangement specifying that the other entity will provide the identifying information on request, and you have to confirm the client details match what you have on file.
- Both methods require you to keep evidence of which method the original entity used, the date it was completed, and enough detail to demonstrate the two files describe the same person.
For your own documentation, treat a reliance arrangement the same way you would treat a direct verification: note the date you obtained the third-party confirmation, the name of the entity you relied on, and a summary of what method they used. If that entity cannot produce records on request later, your reliance-based verification has no backing, so it is worth confirming upfront that the arrangement includes an obligation to retain and share records for the period you need.
Verifying entities and finding the real owners behind them
Entity clients (corporations, partnerships, and trusts) need a different verification approach than individuals, since you are confirming the existence of a legal entity and then identifying the humans who actually control it. The same five methods generally apply, but the evidence looks different: instead of a driver's license, you are looking at articles of incorporation, a certificate of corporate status, or a partnership agreement, and you need to confirm who is authorized to act on the entity's behalf.
Beneficial ownership is the part of entity verification that trips people up most often. A beneficial owner is any individual who directly or indirectly owns or controls 25% or more of the entity's shares or units, or who otherwise exercises control over it regardless of formal ownership percentage. Critically, a beneficial owner must always be a natural person. If your ownership trail leads to another corporation, you keep tracing it back until you reach the individuals who ultimately control that chain.
- Confirm the entity's existence and good standing through Corporations Canada for federally incorporated entities or the relevant provincial registry for provincially incorporated ones.
- Identify every individual who owns or controls 25% or more, and document how you calculated that threshold.
- Verify each identified beneficial owner using one of the five prescribed methods, the same as you would a standalone individual client.
- Confirm the identity of whoever is signing on the entity's behalf and their authority to do so.
When the ownership information a client provides does not match what a corporate registry shows, that is a material discrepancy, and reporting entities are expected to file a Beneficial Ownership Discrepancy Report within the timeframes FINTRAC prescribes rather than simply noting the mismatch and moving on.
Privacy rules for digital ID checks and biometrics
Digital verification tools, from liveness checks to facial recognition, raise privacy questions that FINTRAC's methods do not directly address but that the Office of the Privacy Commissioner of Canada has weighed in on. Identification (a claim about who someone is) and authentication (confirming that claim) are legally distinct, and biometric authentication systems carry heavier privacy obligations than a simple document check.
- Biometric data collection requires express, informed consent under PIPEDA, not a buried clause in a terms-of-service agreement.
- Choose the least intrusive method that gets the job done before reaching for biometrics; a dual-process check often satisfies the same compliance goal without collecting a fingerprint or facial scan.
- Build in a non-biometric alternative for clients who decline or cannot complete a biometric check, since refusal cannot be a barrier to service.
- Plan for false matches: define what happens when a biometric system fails to confirm a legitimate client, and give staff a documented fallback process.
- Limit retention of biometric data to what is strictly necessary and disclose clearly how long it will be kept and for what purpose.
Biometric verification should be proportional to actual risk, and organizations are expected to favor authentication over full identification wherever that satisfies the compliance need, according to OPC guidance on biometrics. That principle matters for brokers evaluating identity verification software: the more invasive the technology, the higher the bar for consent, necessity, and a documented fallback.
Ongoing monitoring versus starting verification over
FINTRAC draws a clear line between ongoing monitoring and full re-verification, and mixing the two up leads to either wasted effort or compliance gaps. Once you have verified a client using an accepted method and kept the associated records, you generally do not have to repeat that verification later. What you do have to do is keep the client's identification information current based on your risk assessment of that relationship.
- Re-verification becomes necessary when doubts arise about the original check, such as a suspicion the ID presented was fraudulent.
- A significant change in the client's circumstances, like a new legal name or a change in beneficial ownership for an entity client, triggers an update to the file even without full re-verification.
- Higher-risk clients typically warrant more frequent monitoring checkpoints than lower-risk ones, reflecting a risk-based approach rather than a fixed schedule for everyone.
- Long gaps in the relationship, such as a client returning after several years of inactivity, are a reasonable prompt to confirm details are still accurate.
Your compliance policy should spell out how often you check in on active files, what counts as a red flag serious enough to trigger re-verification, and how staff document the difference between a routine update and a full re-check in the client record.
Building a compliance file that holds up to review
A verification is only as good as the file behind it. Work through this sequence for every client:
- Choose the method that fits the client's situation (in person, remote, existing relationship, or entity).
- Gather the evidence, whether that is a physical ID, credit file pull, dual-process sources, or a reliance agreement.
- Record the metadata: who performed the check, the date, the method used, and the source or document names.
- Store copies of documents or screenshots where your policy requires them.
- Flag anything unusual, including mismatched details or documents that raised concern, even if you ultimately proceeded.
For each method, your file should capture the specific fields that matter: document type, issuer, and expiry for photo ID; bureau name and file reference for credit-file checks; both source names and check dates for dual-process; and the relying entity's name and agreement date for affiliate or reliance methods. A structured document intake workflow makes this consistent across a team rather than dependent on individual habits.
Pro Tip: Build a one-page red-flag log per file so a reviewer sees not just what you verified, but what gave you pause and how you resolved it.
Where the real friction shows up in practice
The gap between what FINTRAC's methods require on paper and how quickly a broker actually needs to close a deal is where most compliance shortcuts happen. Remote onboarding has made dual-process the default method for a lot of transactions, but two mediocre sources checked in a hurry are worse than one solid source checked carefully. Speed and evidentiary quality trade off against each other constantly, and the brokers who get burned are usually the ones who treated verification as a box to check rather than a record they might have to defend later.
Structured intake, where documents are captured, classified, and logged with metadata at the moment they arrive rather than reconstructed from memory weeks later, reduces the manual risk that turns a routine file into a compliance headache. That is less about any single tool and more about building a habit: every document gets a timestamp, a source, and a note on what it proved.
— Anant Bawa
Autowrite: built for the paperwork behind every verification
Every method in this guide comes with a paper trail, and keeping that paper trail organized across dozens of active files is where most brokerages lose time. Autowrite is built specifically for Canadian mortgage brokers, and it automates the document intake, classification, and data extraction work that sits behind compliant client files.

Instead of manually filing scanned IDs, credit reports, and dual-process source documents into separate folders and typing metadata by hand, Autowrite captures documents as they come in, classifies them, and extracts the relevant data so your compliance package assembles itself alongside the rest of the deal file. The platform is built with Canadian data residency in mind, which matters when the documents you are storing include the same government IDs and financial records this guide covers.
Autowrite offers subscription plans with varying features for brokerages at different stages, with pricing and fees detailed on its official pricing page. Additional fees may apply per deal beyond the plan's included volume. If you want to see how this fits your current workflow, review Autowrite's pricing plans and start a trial.
Where to read the primary rules yourself
This guide summarizes FINTRAC's own framework, and the primary sources are worth bookmarking:
- FINTRAC's compliance guidance lays out all five prescribed verification methods in full detail.
- FINTRAC's dual-process training video walks through a real dual-process check step by step.
- OPC's biometrics guidance covers consent and proportionality for biometric authentication.
- The Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations contain the statutory text behind these obligations.
- For an on-the-ground practitioner view of mortgage processing, CK the Mortgage Guy covers practical workflow topics Canadian brokers deal with daily.
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Sources
Dual-process verification is the workhorse method for remote client onboarding, and it is likely the one mortgage brokers reach for most often given how much business now happens over video calls and e-mail rather than in a branch. The requirement is straightforward in principle: obtain two pieces of information from two different reliable sources, and each source has to be an independent originator, not two documents from the same issuer.
Here is how to run the check:
- Methods to verify the identity of persons and entities : FINTRAC's compliance guidance
- Video 3 – Verifying the identity of a client: Dual-process method — FINTRAC
- Biometrics guidance — Office of the Privacy Commissioner of Canada
Acceptable source categories span government correspondence (a CRA notice of assessment), utility providers (a hydro or telecom bill), financial institutions (a bank or investment statement), and government benefit statements (a CPP or Old Age Security statement). A Canadian credit file can serve as one of the two sources in a dual-process check as long as it has existed for at least six months, a notably lower bar than the three-year rule for the standalone credit-file method.
Where a third party is involved, such as a gift-letter donor whose funds are part of the deal, the same dual-process logic often applies to confirming that person's identity alongside the borrower's. Brokers handling gift letter documentation frequently need dual-process verification for a donor who is not physically present to show ID.
Pro Tip: Keep a running list of acceptable source types for your team so junior staff are not guessing whether a specific bill or statement qualifies; consistency across files matters as much as the individual check.
FAQ
What are the FINTRAC client identification methods?
FINTRAC recognizes five methods: government-issued photo identification, the credit file method, the dual-process method, the affiliate or member method, and the reliance method. Regulated entities such as mortgage brokers must use one of these five when verifying a client's identity under the Act.
What are the accepted forms of identification in Canada?
Accepted government-issued photo ID includes documents like a driver's license, passport, or provincial identification card, provided they are current, show the client's name and photo, and include a unique identifying number. For remote verification, the dual-process method accepts independent sources such as a CRA notice of assessment, a utility bill, or a bank statement in place of physical photo ID.
Is KYC mandatory in Canada?
Yes, know-your-client verification is mandatory for reporting entities covered by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, including mortgage brokers, banks, and securities dealers. These businesses must verify client identity using one of the five FINTRAC-prescribed methods whenever verification is required, and keep records of how that verification was completed.
What are the identification requirements for a client at Law Society Ontario?
The Law Society of Ontario requires lawyers and paralegals to verify the identity of clients they act for, following professional obligations separate from but similar in spirit to FINTRAC's framework. Ontario legal professionals should consult the Law Society's own resources and verification forms for the specific timing and documentation rules that apply to legal practice.
How is the dual-process method different from the credit file method?
The dual-process method combines two independent sources, such as a utility bill and a bank statement, and can include a Canadian credit file as one source if that file is at least six months old. The standalone credit file method instead relies on a single Canadian credit file, but that file must have existed for at least three years to qualify on its own.
