Module 01 · 15 min

FINTRAC and the mortgage sector: who's a reporting entity, and what a compliance program has to include

Key takeaways
  • Mortgage brokers, brokerages, administrators, and lenders became FINTRAC reporting entities on October 11, 2024, under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act.
  • A compliant program needs five specific components — a designated compliance officer, written policies and procedures, a documented risk assessment, an ongoing training program, and a periodic effectiveness review — not just a written policy on a shelf.
  • Missing any one of the five components, not just having weak policies, is treated as a compliance gap on its own.

Who's actually covered

FINTRAC's amended regulations bring three types of mortgage business under the reporting-entity umbrella: mortgage brokers (the individuals and brokerages who arrange mortgages between borrowers and lenders), mortgage administrators (businesses that service mortgage agreements — collecting and remitting payments — on a lender's behalf), and mortgage lenders themselves, to the extent they aren't already captured as financial entities. This is a broad sweep: it doesn't carve out an exception for a small independent brokerage or a sole-proprietor agent the way some regulatory regimes exempt smaller players. If your business fits one of those three descriptions, the obligations apply regardless of size.

This matters because the obligations aren't just about paperwork the brokerage's principal broker handles once a year. Client identification, record-keeping, and reporting duties apply at the point of each individual client interaction — meaning an agent or associate working files day to day is the one actually executing most of these obligations in practice, even though the compliance program itself is built and maintained at the brokerage level.

The five components a compliance program needs

FINTRAC doesn't accept a written anti-money-laundering policy sitting in a binder as sufficient on its own. A compliant program has five distinct components, and a review that finds even one missing treats that as a real gap, not a minor oversight: a designated compliance officer with actual authority to act on findings; written policies and procedures that reflect the brokerage's specific business, not a generic template; a documented risk assessment of the brokerage's exposure to money laundering and terrorist financing, considering its clients, products, and delivery channels; an ongoing training program that actually reaches everyone handling client files, not just a one-time onboarding session; and a periodic review of the program's effectiveness, carried out by someone with the independence to assess it honestly.

  • A designated compliance officer with real authority.
  • Written policies and procedures specific to the brokerage's own business.
  • A documented risk assessment of money-laundering and terrorist-financing exposure.
  • An ongoing staff training program.
  • Periodic review of the program's effectiveness.

Why the risk assessment component gets skipped most often

Of the five components, the documented risk assessment is the one brokerages most commonly treat as optional or skip entirely, because it requires genuine analytical thought rather than adapting a template — considering, specifically, what kinds of clients the brokerage tends to serve, what products it arranges (private and alternative lending carries different risk than straightforward A-lender purchases), and what delivery channels it uses (a fully remote, digital-first brokerage has different vulnerabilities than one that meets every client in person).

A risk assessment that's just copied from another brokerage's template, without being adapted to reflect the actual client base and product mix, doesn't satisfy the requirement even if it looks complete on paper — the point of the exercise is that it reflects genuine thought about where this specific business is actually exposed.

What a periodic effectiveness review actually checks

The final component — reviewing the program's effectiveness — exists to catch the gap between what the written policy says and what actually happens in practice. It's common for a brokerage to have a technically complete written policy that nobody actually follows consistently on live files; the effectiveness review is what's supposed to surface that gap before an external examination does. Carried out by an internal reviewer with genuine independence from day-to-day file handling, or by an external auditor, this review should test actual files against the written policy, not just confirm the policy document exists.

For an agent or associate, the practical takeaway is that your own file-handling habits are part of what an effectiveness review will look at. Consistent, documented client identification and clear notes on anything unusual you noticed in a file aren't just good practice for your own protection — they're the evidence a compliance officer needs to show the program is actually working, not just written down.

What this looks like for a small brokerage vs. a large one

The five components apply regardless of brokerage size, but what satisfies each one scales with the size and complexity of the business. A sole-proprietor brokerage might reasonably have the owner serve as compliance officer, a shorter but still genuine written policy tailored to a narrower client base, and an annual self-review rather than a formal audit engagement. A larger, multi-agent brokerage handling a wider range of products needs a more substantial program to match — more frequent training, a more granular risk assessment across product lines, and likely an external reviewer for the effectiveness component.

What doesn't scale down, at any size, is having all five components present in some genuine form. A one-person brokerage that skips the written risk assessment entirely, on the theory that its business is too small to need one, has the same compliance gap as a large firm that skips it — the requirement doesn't have a size exemption built in.

Knowledge checkUnanswered

A brokerage has a written anti-money-laundering policy, a designated compliance officer, and a training program, but has never documented a risk assessment specific to its own client base and products. Is this brokerage FINTRAC-compliant?

AYes — three of the five components being in place is generally treated as sufficient.
BNo — a documented risk assessment specific to the brokerage's actual clients, products, and delivery channels is one of five required components, and missing it is treated as a real gap regardless of how strong the other four are.
CYes, as long as the written policy mentions money laundering risk in general terms somewhere in the document.
DIt depends only on whether the brokerage has ever had a suspicious transaction — a risk assessment isn't needed until one occurs.

All five components — compliance officer, written policies, risk assessment, training, and periodic review — are required, and a program missing any one of them, including the risk assessment, has a genuine gap rather than a technicality. A generic mention of money-laundering risk inside a policy document isn't the same as a documented assessment of this specific brokerage's actual exposure, and the requirement to have one doesn't wait for an actual suspicious transaction to occur first — it's meant to be in place before that happens.

← Why compliance became part of the job,Client identification: FINTRAC's know- →