FINTRAC obligations attach to what your firm does for a client, not to the tools it uses. The regulation names the activities — and expressly carves out audit, review and compilation work.
Key takeaways
No. Reporting obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act attach to what your firm does for a client, not to the software it does it with. The regulations name specific activities. A language model is not one of them, and running one over a trial balance does not make you a reporting entity any more than buying a faster scanner did.
The useful version of the question is different: does using AI change how a firm that is already captured has to behave? There the answer is yes, in three specific places — where client data goes, who forms the suspicion, and what the two-year effectiveness review has to look at.
section 47 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations says an accountant or accounting firm is engaged in a business or profession for the purposes of paragraph 5(j) of the Act when, on behalf of a person or entity, they: receive or pay funds or virtual currency; purchase or sell securities, real property or immovables or business assets or entities; transfer funds, virtual currency or securities by any means; or give instructions in connection with any of those activities.
The carve-out matters more than the list. Subsection 47(2) states, for greater certainty, that those activities do not include activities carried out in the course of an audit, a review or a compilation engagement. A great deal of what a Canadian accounting firm does is therefore outside the regime entirely — and that boundary is drawn by the engagement, not by the technology inside it.
FINTRAC’s guidance glossary defines an accounting firm as an entity engaged in the business of providing accounting services to the public with at least one partner, employee or administrator who is an accountant. If your firm never touches client money and never gives instructions to move it, section 47 is not engaged.
1. Where the client data goes. A transaction-monitoring feature that sends ledger extracts to a vendor is a disclosure of personal information, and your safeguards obligation under Canadian privacy law follows it there. Settle the data-handling terms — residency, retention, whether inputs train the vendor’s models — before the pilot, not after a concern lands. If it goes wrong, you are on the breach path described in our article on what to do when an AI tool leaks client data.
2. Who forms the suspicion. A model can rank transactions against indicator patterns. It cannot hold reasonable grounds to suspect, which FINTRAC describes as a step above simple suspicion — a possibility that an offence has occurred. That is a person’s state of mind, reached after taking the measures the guidance describes. Treat every model output as a prompt to look, never as the conclusion.
3. What the effectiveness review has to cover. If a tool now sits between your staff and your transaction data, the two-year review has to test whether it works: what it flags, what it misses, whether staff were trained on it, and whether anyone has been quietly treating a green screen as clearance.
An STR narrative. FINTRAC publishes expectations for completing a suspicious transaction report and a list of common deficiencies to avoid, and a report that reads fluently while describing facts nobody observed is worse than a plain one. Draft with a tool if it helps; the person who submits it must be able to say where each sentence came from.
The same caution applies to client correspondence. It is prohibited to disclose the contents of an STR, or the fact that one has been or will be made, where the intent is to prejudice a criminal investigation. An assistant that drafts a chatty explanation of why a transaction is being queried is a risk worth thinking about before you turn it on.
A nine-person Ontario CPA firm does year-end compilations for about 120 owner-managed corporations, plus bookkeeping for 40 of them. For the compilation work, section 47(2) puts it outside the regime. For three clients the firm also receives and pays funds from a firm-held account — that is a section 47(a) activity, and for those clients the firm is captured.
The firm turns on a monitoring feature in its practice software. In month one it flags eleven transactions. Nine are payroll timing. One is a duplicated entry. One is a payment to a jurisdiction the client has never dealt with, structured just under a round figure. The compliance officer looks at the last one, asks the client, is not satisfied by the answer, and submits an STR.
Nothing about the firm’s legal position changed. What changed is that a partner saw the eleventh transaction in week two rather than at year end. The countable metric is not hours saved — it is the interval between the transaction and the review, which you can measure before and after.
This article is about a firm delivering accounting services to a book of clients. If the question is really about closing your own books faster — reconciliation, AP and AR, month-end — that lives on the accounting automation page. If it is about front-desk intake and scheduling in a practice, see professional practice owners. For the legal background, Treadstone’s sister firm covers FINTRAC obligations for Ontario businesses and AML compliance program basics.
Does buying an AML tool make me a reporting entity?
No. Section 47 is a list of activities carried out on behalf of a client. Software is not on it. If you were outside the regime yesterday you are outside it today.
Can a model decide there are no reasonable grounds to suspect?
No, and you should not configure it to look like it has. A clean screen is the absence of a flag, not a finding. Record who reviewed what, so the two-year effectiveness review has something to test.
Can I paste client transaction data into a general-purpose chatbot?
Not without knowing the terms you are pasting it under. That is a safeguards and confidentiality question before it is an AML one, and the answer usually belongs in a written AI use policy rather than in an individual’s judgement.
Does the tool need to appear in my compliance policies?
If it touches client identification, monitoring or reporting, yes — the policies and procedures FINTRAC requires are meant to describe how the work is actually done, and a tool that changes how it is done belongs in them.
A 30-minute call is enough to tell you whether AI pays for itself here.