A mortgage compliance package is the written, operational anti-money laundering and anti-terrorist-financing program that FINTRAC requires of mortgage brokers, lenders, and administrators. The immediate priority is appointing a compliance officer and documenting the five mandated elements, including the two-year effectiveness review and six-year record retention rule. Tools like Autowrite can help assemble and retrieve the supporting evidence, but the program itself remains the broker's responsibility.
TL;DR:
- Mortgage businesses must document and implement a five-element compliance program, including appointing a compliance officer and conducting a two-year effectiveness review.
- Records such as client identification, transaction details, and filed reports must be retained for several years and easily retrieved within 30 days upon request.
- A risk assessment must be written for clients, products, geography, and technology, with each rating justified by clear rationale.
- Automation tools like Autowrite can streamline record collection but do not replace the need for final policy approval and sign-off by the broker.
- The first two-year review deadline is October 11, 2026, requiring efforts to confirm the program’s effectiveness and close any identified gaps before then.
Table of Contents
- The five mandatory elements of a FINTRAC-compliant program
- Records, reporting, and client identification: the day-to-day checklist
- How to plan and run the two-year effectiveness review
- Conducting a practical risk assessment for mortgage businesses
- Operationalizing policies, access controls, and fraud prevention
- What automation can and cannot do for compliance documentation
- A practical option for building retrievable compliance records
- Authoritative FINTRAC and FSRA links to bookmark
- Sources
- FAQ
The five mandatory elements of a FINTRAC-compliant program
Every mortgage business subject to the Proceeds of Crime (Money Laundering) and Terrorist Financing Act must build a program around five elements, and examiners expect each one in writing, not just in practice.
- Compliance officer: a named individual with the authority and resources to oversee the program, even if some duties are delegated to staff.
- Written policies and procedures: documented processes covering client identification, recordkeeping, reporting, and how enhanced measures get applied, approved by senior management and accessible to staff who need them.
- Risk assessment: a documented evaluation of clients, products, delivery channels, geography, and new technologies, updated as the business changes.
- Training program and plan: content tailored to each role, a delivery schedule, and attendance records that prove staff actually completed it.
- Two-year effectiveness review: an independent look at whether the program works as designed, with businesses subject as of October 11, 2024, required to complete their first review by October 11, 2026.
FINTRAC and FSRA both note that templates and vendor services can support these elements, but the reporting entity has to adapt them to its own business model and sign off on the result. A generic policy manual copied from another firm will not survive an examination.
Records, reporting, and client identification: the day-to-day checklist
Beyond the five program elements, FINTRAC sets specific expectations for what gets kept and how fast it can be produced.
- Information records: identifying details collected during client verification.
- Mortgage loan records: terms, parties, and transaction details for each file.
- Receipt-of-funds records: where deposits and payments originated.
- Copies of any reports filed with FINTRAC, including suspicious transaction reports.
Records must be retained for several years after a transaction expires and produced promptly upon a FINTRAC request. That retrieval window is often the part firms underestimate: a file scattered across email threads and personal drives rarely comes together in a month.
Identity verification typically happens at the start of a client relationship and again when a transaction pattern looks unusual. Enhanced due diligence, such as confirming source of funds or requesting additional documentation, applies to higher-risk files, a topic covered in more depth in our source of funds verification playbook. Suspicious activity, including patterns suggesting structuring or unexplained large cash movements, should trigger a suspicious transaction report rather than a judgment call left undocumented. A practical intake checklist for building these records is outlined in our mortgage document checklist.

How to plan and run the two-year effectiveness review
The review is not a formality. It has to test whether the program actually catches what it is supposed to catch, and FINTRAC's mortgage-sector training video walks through the recommended approach.
- Set the scope: cover policies and procedures, the risk assessment, and the training program together rather than in isolation.
- Sample files: pull a cross-section of transaction types, including any flagged as higher risk, and check whether the paperwork matches what the policy required.
- Interview staff: confirm training was understood, not just attended.
- Document findings and remediation: write down gaps found and what was fixed, with dates, so the next review can confirm closure.
Pro Tip: Start the review well before the two-year deadline so remediation work is finished, not still open, when the next cycle begins.
Conducting a practical risk assessment for mortgage businesses
FINTRAC expects a written rating across five prescribed factors, each with its own rationale rather than a single blanket score.
- Clients: occupation, transaction behavior, and any links to higher-risk jurisdictions.
- Products and delivery channels: whether a mortgage is arranged in person, remotely, or through a third-party referral.
- Geography: whether a property or client is tied to a region flagged for elevated money laundering risk.
- New technologies: e-signature platforms, remote verification tools, or other systems that change how identity gets confirmed.
- Written rationale: a short explanation of why each factor earned its rating, not just the rating itself.
A file rated high risk on client behavior might call for enhanced due diligence, a lower transaction threshold before manager sign-off, or third-party verification of identity documents.
Operationalizing policies, access controls, and fraud prevention
Written policies only work if someone is accountable for following them, and FSRA's fraud-prevention guidance treats this as a supervisory obligation, not a paperwork exercise.
- KYC procedures: who verifies identity, what documents are acceptable, and when a second reviewer is required.
- Recordkeeping roles: who owns file storage, who can access it, and what happens when an agent leaves the brokerage.
- STR handling: a clear path from a flagged transaction to a filed report, with a named decision-maker.
- Fraud red flags: document verification steps and escalation triggers, detailed further in our guide to mortgage fraud red flags.
- Escalation flow: agents report concerns to a principal broker or compliance officer, not to each other informally.
Pro Tip: Restrict who can edit closed files, and log any changes, since an unexplained edit to a completed record is one of the fastest ways to fail an audit.
What automation can and cannot do for compliance documentation
Certain software solutions can assemble searchable, retrievable file packages, useful when a two-year review needs sampled files or FINTRAC requests records within its 30-day window. They can also organize training logs and intake records. What it cannot do is write your policies or take responsibility for your ratings: those calls, and the final sign-off, stay with the broker and compliance officer.
— Anant Bawa
A practical option for building retrievable compliance records
Chasing down scattered emails and file notes for a review or a FINTRAC request eats hours that could go toward clients instead. Autowrite automates document intake, classification, and data extraction so a compliance package for a review or audit request can be pulled together in minutes rather than days, with Canadian data residency built in. Plans start with Starter at $149 per month, with Pro, Legend, and Enterprise options available for larger teams, plus a $20 one-off fee per additional deal. Compliance content still needs your review and approval before it goes into a file. Visit Autowrite's pricing page to start a trial and see how it fits your brokerage.

Authoritative FINTRAC and FSRA links to bookmark
Keep FINTRAC's Guide 4, the sector training video, and FSRA's fraud guidance close at hand. For broader practitioner context, CK the Mortgage Guy covers day-to-day broker topics.
Sources
- Guide 4 — Compliance program requirements (FINTRAC)
- Proposed Guidance: Detecting and Preventing Mortgage Fraud (FSRA)
FAQ
What are the new mortgage rules in Canada for 2026?
Businesses subject to FINTRAC's compliance program requirements as of October 11, 2024, must complete their first two-year effectiveness review by October 11, 2026. There is no single new rulebook for 2026: the deadline applies to the existing five-element program most mortgage businesses already operate under.
What is a compliance mortgage?
The term usually refers to a mortgage business's compliance program rather than a type of loan. It is the written policies, risk assessment, training, and review structure FINTRAC requires of mortgage brokers, lenders, and administrators under anti-money laundering law.
How much does a mortgage broker make on a $500,000 mortgage?
Broker compensation varies by lender, product, and arrangement, and no single commission rate is published across the industry. A broker's own brokerage agreement, not a fixed public schedule, determines what is earned on any given file.
What is the $10,000 bank rule in Canada?
Financial entities in Canada must report certain cash transactions to FINTRAC, and mortgage businesses handling receipt-of-funds records need to recognize when a transaction pattern may require a report. Definitions of what counts as a reportable transaction vary by scenario, so mortgage professionals should confirm specifics against FINTRAC's guidance.
