Anonymised, illustrative composite. An internal 1-year filing habit, never checked against the actual retention rule, collided with a request that arrived two years and three months after closing.
At a glance
A former client emailed the brokerage asking for a complete copy of their purchase file — the agreement, identification records, and communications — two years and three months after their closing. They needed it for an unrelated matrimonial proceeding where the purchase price and closing date were relevant evidence. The request was simple, and should have been a same-week turnaround: pull the file, redact anything the other party had no right to see, send a copy.
Instead, the front-desk coordinator who fielded the request spent two weeks going back and forth with the broker of record before anyone would admit, in writing, that the file simply no longer existed.
The brokerage’s internal admin manual instructed staff to purge client files after one year, a number nobody currently at the brokerage could trace back to any actual regulatory source — it had simply been the practice for years. The file had already been deleted under that policy by the time the request arrived. But the real retention authority is federal, not a house habit: under FINTRAC’s record-retention guidance, an information record and a business-relationship record must each be kept for 5 years, with the clock starting from the day of the last business transaction conducted — not from the day the file was opened, and nowhere close to the one-year mark the brokerage had been working from.
Two years and three months since closing, against a 5-year mandatory retention window that had roughly two years and nine months still left to run. The brokerage’s internal purge cycle was less than a quarter of the length the law actually requires.
Two federal regimes intersected on this one file, and each has its own instrument. FINTRAC’s retention rule required the record to still exist — it did not. Separately, because the request came from the client themselves asking to see their own personal information, PIPEDA s.8(3) required a response “not later than thirty days after receipt of the request,” extendable by up to 30 further days with proper notice under s.8(4) — and under s.8(5), failing to respond within the time limit is deemed a refusal in its own right, regardless of the retention question underneath it. A third clock ran underneath both: FINTRAC’s own guidance requires records to be kept “in such a manner that they can be provided to FINTRAC within 30 days of a request” — a production duty independent of the client’s own access request, and one the missing file had already failed regardless of who asked.
The brokerage could not produce the requested records because they no longer existed, which is itself a retention failure independent of anything else, and it also could not meet PIPEDA’s 30-day response clock with a substantive answer, only with an explanation of why the file was gone. FINTRAC’s administrative monetary penalty regime scales by the seriousness of the violation — up to $1,000 per violation at the minor tier, up to $100,000 at the serious tier for both individuals and entities, and up to $500,000 for an entity at the very-serious tier — and the brokerage’s exposure sat squarely inside that framework once the retention gap was identified.
Had the brokerage followed FINTRAC’s actual 5-year rule instead of the internal one-year habit, producing the file would have taken minutes: pull the folder, copy it, send it. The entire exposure in this file — the retention gap, the missed PIPEDA response window, the regulatory conversation that followed — traces to a single number in an internal manual that nobody had ever checked against the rule it was supposedly following. The cost was not the request itself; it was a policy that had been quietly wrong for years before anyone happened to ask for a file old enough to expose it.
The one-year figure in the admin manual had no citation, no source, and no one at the brokerage could say where it had originally come from — it had simply been copied forward through several rounds of staff turnover. An internal policy number with no traceable source behind it is worth checking against the actual rule before it becomes the reason a file doesn’t exist when it’s needed. A retention schedule that was never sourced to a specific regulation, section, or guidance page is not really a policy at all — it is a habit wearing a policy’s clothing, and habits do not hold up when a regulator or a former client actually tests them.
A 30-minute call is enough to tell you whether AI pays for itself here.