On this page
Your procedure says you verify a client's identity. Now open a few files. Can you find when the verification happened, how it was done and what record was kept? A two-year effectiveness review looks for the difference between a written compliance program and the work carried out in practice.
FINTRAC requires a documented plan and an effectiveness review at least every two years. The plan must cover policies and procedures, the risk assessment, and the training program and plan when applicable. A firm should be able to explain its tests, findings and corrective actions.
Two different reviews
“Preparing for a FINTRAC review” can mean two different things:
Your effectiveness review
You arrange it to test your own compliance program. You set a method, examine records and document the results.
A FINTRAC examination
The regulator assesses your firm's compliance. It may ask to see your effectiveness review plan and results. Our FINTRAC guide for brokers covers that examination.
FINTRAC's assessment manual says its examiners consider the scope and method of your effectiveness review, supporting records and what you did about the findings. Keep a clear trail from each test to its conclusion.
When is the first review due?
For mortgage-sector businesses subject to the law since October 11, 2024, FINTRAC says it expects the first two-year review to be completed before October 11, 2026. This is FINTRAC's published expectation for that group, not a universal deadline for every business. If you became subject to the law later, or your circumstances differ, check the date that applies to you.
FINTRAC's compliance program guidance also says the next review must begin within 24 months of the start of the previous review, and the previous review must be completed before the next one begins. Record both start and completion dates, not just the year on a report.
What the plan should cover
A heading that says “review client files” does not explain why those files were chosen or what was tested. FINTRAC calls for a documented plan covering every element of the compliance program. The depth of review depends on the business's complexity, transaction volume, earlier findings and current risks.
Before opening a file, write down five things:
- The period and activities covered. Which versions of your procedures applied?
- The areas under review. Policies, risk assessment, applicable training and the obligations relevant to your activities.
- How files were selected. What sampling criteria did you use, and why?
- The method. Document review, file testing and interviews with employees or agents, as relevant.
- How results will be recorded. For each test, note the record examined, finding, limitation and next step.
Test files without presuming the outcome
FINTRAC gives sampling records as one way to check whether client identity verification procedures are followed. First identify the procedure in force during the period under review. Explain the sampling criteria and sample size in the plan. The guidance does not prescribe one universal number of files.
For each selected file, compare the required steps with the records retained. Write down what the records show, what they do not show, and any limits to your test. Support every finding with an identifiable record. The results you actually observe then determine what to correct and how to test the correction.
FINTRAC lists sampling, interviews and document review among possible methods. Your plan should explain the size and selection of any sample.
Report and corrective action
A useful report lets a reader follow the evidence: review dates and period, reviewer, tests, results, gaps, recommendations and action plan. A simple table works if every finding can be traced back to the record examined. Include what could not be tested, too; an unexplained gap weakens the report.
If you are an entity, FINTRAC requires written reporting to a senior officer within 30 days after the review is completed. The report must include the review results, other policy and procedure updates during the period covered, and the status of changes. Those 30 days do not extend the time available to carry out the review itself.
Close the loop on each gap: say who will correct it, what will change and how you will check that the change worked. A report alone does not prevent the same gap from recurring.
Who can conduct the review?
FINTRAC allows an internal or external auditor or, if you have neither, a review by yourself. The reviewer should understand the requirements that apply to your business. Using someone who is not directly involved in the compliance program is described as a best practice for impartiality, not a general requirement to hire a consultant.
If you work alone, document your method and its limitations clearly. FINTRAC also says a sole proprietor with no employees, agents or others authorized to act on their behalf does not need to establish a training program for themselves. The other applicable parts of the compliance program still need to be reviewed.
Final checklist
- I have checked the date that applies to my business and will complete the review on time.
- My plan covers the relevant program elements and explains the scope, methods and sample.
- Each result points to an identifiable record or interview.
- Gaps, limitations, owners and follow-up dates are documented.
- If I am an entity, I have planned written reporting to a senior officer after completion.
Preparation starts before the report: well-kept files make testing possible. See how Hypora organizes the evidence of work in each file. The review, its conclusions and regulatory responsibility remain with the reporting business.

