A risk assessment isn’t a form you complete once and file away. FINTRAC frames it as a set of factors you assess and document about your own practice — your clients, your services, your geography — then revisit as your business changes.
Key takeaways
FINTRAC’s guidance on the compliance programme lists what “all reporting entities must implement,” in order: appoint a compliance officer responsible for the programme; develop written policies and procedures, kept up to date; conduct a risk assessment of your business to document your money laundering, terrorist financing and sanctions-evasion risk; maintain a written, ongoing training programme; and institute a documented plan to review the programme’s effectiveness at least once every two years. All five apply regardless of practice size — the guidance draws no distinction based on how many transactions you close in a year.
On who can hold the compliance-officer role, FINTRAC is direct: “If you are a person rather than an entity, such as a sole proprietor, you can appoint yourself as the compliance officer.” The same logic appears in FINTRAC’s PEP guidance, which states that “If you are a sole proprietor with no employees, agents or other persons authorized to act on your behalf, you are considered to be the senior manager.” A one-person practice is not exempt from the structure — it just occupies every role in it at once.
FINTRAC lists the specific factors a risk assessment must consider, verbatim: your clients, business relationships and their activity patterns and geographic locations; the products, services and delivery channels you offer; the geographic locations where you conduct your activities; the risks from new developments or new technologies you intend to introduce, assessed before you introduce them; the risks named in the latest National Risk Assessment for your sector; and any other relevant factors affecting your business. That new-technology clause is worth pausing on for any practice weighing an AI tool for client intake or lead handling — the assessment is meant to happen before the tool goes live, not after.
FINTRAC draws a clean line between two categories of politically exposed person. A foreign PEP is treated as high risk without a separate decision: “You must treat all persons that you determine to be foreign politically exposed persons or family members or close associates of foreign politically exposed persons as posing a high risk.” A domestic PEP or head of an international organization gets a different, lighter default — treated as high-risk only “if you consider, based on your risk assessment, that there is a high risk” of a money-laundering or terrorist-financing offence. The status itself is also durable in a way worth noting: FINTRAC states that once you determine a person is a foreign PEP, “they remain a foreign politically exposed person forever” — you are not required to re-determine it. A domestic PEP, by contrast, stops being one five years after leaving office.
A high-risk determination isn’t just a label in a file — FINTRAC requires written policies for the enhanced measures that follow, which can include obtaining additional information on a client, information on their source of funds or wealth, or information on the reasons for a transaction, plus updating identification and beneficial-ownership information more frequently and monitoring the relationship more closely than you would a standard-risk client. See why real estate is a reporting sector for how this compliance structure connects to the broader reporting-entity definition, and red flags that should slow a deal down for the indicators most likely to trigger a high-risk finding in the first place.
A risk assessment doesn’t stay on the shelf as a standalone document — it’s meant to shape the training programme FINTRAC also requires. The guidance describes a written training programme that explains, among other things, “how your business or profession could be vulnerable to money laundering and terrorist activity financing activities” using the indicators and examples relevant to your own risk profile, plus the specific policies and procedures you’ve developed to meet your reporting, record-keeping and know-your-client duties. For a one-person practice this can feel redundant with the risk assessment itself — but FINTRAC still requires a documented training plan and its delivery, even where the compliance officer, the trainer, and the person being trained are the same individual.
The review that keeps the assessment honest
FINTRAC requires the whole programme — not just the risk assessment — to be tested for effectiveness on at least a two-year cycle. A risk assessment written once at licensing and never revisited is not what the rule describes; a practice that changes its client base, adds a new marketing channel, or starts using a new intake tool has, by FINTRAC’s own list of factors, a reason to look at it again sooner.
FINTRAC’s guidance requires an entity to “report, in writing, the following to a senior officer no later than 30 days after the completion of the effectiveness review” — the findings, any policy updates made outside the review, and the status of implementing them.
Yes — FINTRAC’s compliance-programme requirements apply to every reporting entity, and its own guidance describes how a sole proprietor fills every required role, including compliance officer, rather than being excused from having one.
Yes, explicitly — a sole proprietor with no employees or authorized persons can appoint themselves.
FINTRAC requires the effectiveness of the whole compliance programme to be reviewed at least every two years, and its own list of risk factors — new clients, new technology, new delivery channels — gives practical reasons to revisit it sooner than that.
Yes — FINTRAC’s guidance requires a documented training programme and a plan for delivering it for anyone with reporting obligations, and does not carve out a solo practice from that requirement, even where the same person fills every role in the programme.
That can be a legitimate conclusion for a straightforward practice — the requirement is that you actually assess and document the factors FINTRAC lists, not that you arrive at a particular risk level. What matters is that the reasoning is written down and revisited as your client base, services, or technology change, not that every practice must find itself high-risk somewhere.
A short call can help you put a documented risk assessment together for your specific practice.