A single mortgage file, from a Canadian broker's desk, sits inside four separate compliance regimes at once, and it's worth being precise about which one does what before going any further. FINTRAC — the Financial Transactions and Reports Analysis Centre of Canada — governs anti-money-laundering and anti-terrorist-financing duties: verifying who your client actually is, watching for suspicious patterns, and reporting specific transactions. PIPEDA — the Personal Information Protection and Electronic Documents Act — governs what you're allowed to do with the personal information a client hands you: how it's collected, used, disclosed, and protected. CASL — Canada's Anti-Spam Legislation — governs the narrower question of what it takes to legally send someone a commercial email or text. And your provincial regulator, whichever one issued your licence, governs professional conduct: whether the advice you gave and the disclosure you made met the standard a licensed professional owes a client.
None of these four make any of the others optional. A broker who nails FINTRAC identification but mishandles a client's personal information is still exposed under PIPEDA. A broker who handles privacy well but keeps emailing a lead who unsubscribed is still exposed under CASL. This course takes each regime in turn, then closes by showing how the provincial layer sits on top of all three.
It matters to know which of these obligations is recent and which has quietly applied for years, because the recent one is the one brokers are most likely to be under-prepared for. FINTRAC's mortgage-sector rules are the new arrival: mortgage brokers, brokerages, administrators, and lenders became reporting entities under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act on October 11, 2024. Before that date, the mortgage sector simply wasn't captured by this regime the way banks, money services businesses, and real estate professionals already were.
PIPEDA, by contrast, has applied to mortgage brokerages as commercial organizations handling personal information for as long as the brokerage has existed — it isn't new, it's just easy to under-invest in because there's no licence renewal that forces you to revisit it. CASL has applied to commercial electronic messages since 2014. And provincial conduct rules — the duty to assess suitability, disclose costs, and flag conflicts — have applied since each province's mortgage-broker legislation came into force, which in most provinces predates all three of the others by decades. The result is a compliance picture where the newest rule (FINTRAC) is the one most likely to be missing from an established broker's routine, while the oldest rules (provincial conduct duties) are the ones most likely to have quietly drifted out of date as a brokerage's practices evolved.
It's tempting to treat all of this as background — something the brokerage's compliance officer or principal broker handles, while an agent or associate just originates files. That division of labour is real at the corporate level, but individual licensees still carry personal exposure. A mortgage agent who fails to properly identify a client, who shares a client's file with an unauthorized third party, or who keeps emailing a lead after an unsubscribe request, is personally answerable for that failure — the existence of a brokerage-level compliance officer doesn't transfer the underlying professional duty away from the person actually handling the file.
There's also a more practical reason to know this material well rather than treating it as a box to check: a broker who understands why these rules exist tends to build habits that satisfy them without extra friction, while a broker who treats them as arbitrary paperwork tends to build workarounds that eventually create exactly the exposure the rule was meant to prevent.
Modules 01 through 03 cover FINTRAC in sequence: who's covered and what a compliance program needs, how client identification actually works, and what gets reported and kept on file. Module 04 covers the anti-money-laundering red flags that show up in real files — the practical companion to the FINTRAC modules. Module 05 covers PIPEDA's privacy and breach-notification duties. Module 06 covers CASL and consent for marketing messages. The final module steps back to provincial regulator conduct rules — suitability, disclosure, and conflicts of interest — and how they sit alongside everything covered before it. This course assumes you've already built a solid intake process; if you haven't, Treadstone's Client Intake & Discovery course covers the conversation these compliance duties get layered onto.
A broker who has always been careful about PIPEDA and provincial disclosure rules assumes their existing compliance habits already cover FINTRAC. What's the flaw in that assumption?
FINTRAC asks a genuinely different question than PIPEDA or provincial conduct rules — not what you're allowed to do with information you have, but who your client actually is and whether a transaction looks suspicious — and it's a new obligation for the mortgage sector specifically as of October 11, 2024. Good habits under one regime don't automatically satisfy another, and FINTRAC very much does apply to mortgage brokers now, not just banks; it hasn't replaced PIPEDA, which continues to apply in full alongside it.