BriteBase
Compliance program

AML risk assessment in Canada: a step-by-step guide and checklist

An AML risk assessment is the documented analysis of where your business is exposed to money laundering and terrorist financing, and it is a required element of every FINTRAC compliance program. This guide explains what the assessment must cover, gives a step-by-step checklist you can work through, and shows how to mitigate and document the risks you find so the program holds up under examination.

By BriteBase team · Published June 17, 2026 · 9 min read

An AML risk assessment is a documented analysis of how exposed your business is to money laundering and terrorist financing, and how you control that exposure. Under Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its regulations, it is one of the required elements of a compliance program, alongside a compliance officer, written policies and procedures, ongoing training, and a two-year effectiveness review. This guide walks through what to assess, gives a checklist you can use, and shows how to mitigate and document what you find.

Why does the risk assessment matter more under Bill C-12?

Bill C-12 has been in force since March 2026 and sets the standard that every compliance program must be reasonably designed, risk-based, and effective. The risk assessment is what makes a program risk-based: it is the evidence that your controls are aimed at your actual exposure rather than applied at random. A FINTRAC examiner reads the risk assessment first, because everything else in the program should trace back to it. The wider changes are covered in our Bill C-12 compliance guide.

What are the two halves of an AML risk assessment?

FINTRAC guidance frames the assessment in two parts. The first is the inherent risk of your business itself. The second is the risk of the relationships you enter into. You assess each, rate it, then decide how to mitigate it.

Step 1: Assess your business-based risk

Business-based risk is the exposure built into what you offer and how you offer it. Work through each factor and rate it low, medium, or high.

  • Products and services. Which of your products are most attractive for laundering, for example high-value, anonymous, or fast-settlement products?
  • Delivery channels. Do you onboard and transact in person, or non-face-to-face and fully online, which carries higher impersonation risk?
  • Geography. Where are you located and where do you do business, including any higher-risk jurisdictions?
  • New technology. Are you launching new products, channels, or technologies whose risk you have not yet assessed?
  • Volume and velocity. What is the scale and speed of the transactions you handle?

Step 2: Assess your relationship-based risk

Relationship-based risk is the exposure that comes from who you deal with. Assess it across your client base and each business relationship.

  • Client types. Do you serve higher-risk clients, such as cash-intensive businesses, other money services businesses, or politically exposed persons?
  • Client geography. Where are your clients based, and do any operate in or send funds to higher-risk jurisdictions?
  • Patterns of activity. Are the expected transaction patterns consistent with the client's stated business, and what would look anomalous?
  • Beneficial ownership. Can you identify who ultimately owns or controls your business clients?
  • Nature of the relationship. Is this a one-time transaction or an ongoing relationship, and how well do you know the client?

Step 3: Rate the risk and apply a risk-based approach

Combine the factors into an overall rating for each product, channel, and relationship. A simple low, medium, and high scale, applied consistently and explained, is enough. The rating then sets the response: low-risk areas get standard controls, and high-risk areas get enhanced measures. Applying effort in proportion to risk is the risk-based approach in practice.

Step 4: Mitigate the high-risk areas

Every high-risk rating has to carry a control that brings it down, and the control has to be written into your policies. Common enhanced measures include:

  • Enhanced due diligence. Collect more information on higher-risk clients and verify the source of funds where warranted.
  • More frequent monitoring. Review higher-risk relationships and transactions more often than standard ones.
  • Senior approval. Require management sign-off to take on or keep a high-risk relationship.
  • Tighter thresholds. Tune screening and monitoring more sensitively for higher-risk segments.

Step 5: Document, approve, and keep it current

An assessment that is not written down does not exist for an examiner. Record the factors you considered, the ratings you gave, the reasoning behind them, and the mitigation you applied. Have it approved, date it, and revisit it whenever the business changes materially, such as a new product, a new market, or a new channel, and at least as part of the two-year effectiveness review. Keeping the assessment alive is what an audit-ready program looks like.

What should an AML risk assessment checklist cover?

Use this as a working checklist. Each item should end with a documented rating, and where the rating is medium or high, a documented control.

  • Products and services rated for laundering attractiveness
  • Delivery channels rated, with non-face-to-face onboarding addressed
  • Geographic exposure rated, including higher-risk jurisdictions
  • New products, channels, and technologies assessed before launch
  • Client types and higher-risk categories identified and rated
  • Politically exposed persons and their close associates identified
  • Beneficial ownership of business clients determined
  • Expected versus actual activity defined for monitoring
  • Enhanced due diligence applied to high-risk clients
  • Ongoing monitoring frequency set by risk level
  • Senior approval required for high-risk relationships
  • Assessment written, approved, dated, and version-controlled
  • Review triggers and a two-year review cadence in place

How does BriteBase help?

Our platform builds the screening controls a risk assessment calls for. Real-time sanctions, PEP, and adverse-media screening applies the front-door and ongoing controls, and every decision is recorded so the risk-based approach is evidenced rather than asserted. The detail is on the platform overview, and software selection is covered in the AML software buyer's guide.

FAQ

Is an AML risk assessment required in Canada?

Yes. A documented risk assessment is one of the required elements of a compliance program under Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its regulations. It sits alongside the other mandatory elements: an appointed compliance officer, written policies and procedures, ongoing training, and a two-year effectiveness review. Every reporting entity must assess and document its money laundering and terrorist financing risk, so the assessment is not an optional or best-practice add-on. It is also the element the whole program depends on, because the risk-based approach requires that controls, due diligence, and monitoring be set in proportion to the risks the assessment finds. A FINTRAC examiner reads the risk assessment first, since everything else in the program should trace back to it. A program without a current, documented assessment is missing a required element and cannot demonstrate that its controls are aimed at its actual exposure rather than applied at random.

What does an AML risk assessment have to cover?

An AML risk assessment has to cover two halves: business-based risk and relationship-based risk. Business-based risk is the exposure built into what you offer and how you offer it. It includes your products and services and how attractive each is for laundering, your delivery channels and whether onboarding is face-to-face or fully online, your geography and any higher-risk jurisdictions, any new products, channels, or technologies you have not yet assessed, and the volume and velocity of the transactions you handle. Relationship-based risk is the exposure that comes from who you deal with. It covers your client types, including higher-risk categories such as cash-intensive businesses, other money services businesses, or politically exposed persons; your clients' geography; whether you can identify the beneficial owners of business clients; and the expected patterns of activity against what would look anomalous. You assess each factor, rate it low, medium, or high, and then decide how to mitigate it.

What is a risk-based approach?

A risk-based approach means applying your compliance resources and controls in proportion to the risk you have assessed, rather than treating every product, channel, and relationship the same way. Low-risk areas receive standard controls; high-risk areas receive enhanced measures. It is the principle the risk assessment exists to support, which is why you combine the factors into an overall low, medium, or high rating for each product, channel, and relationship, and let that rating set the response. In practice, the enhanced measures for high-risk areas include enhanced due diligence, collecting more information and verifying source of funds where warranted; more frequent monitoring of higher-risk relationships and transactions; senior approval to take on or keep a high-risk relationship; and tighter screening and monitoring thresholds for higher-risk segments. Applying effort where the exposure actually sits, and standing down where it does not, is what the risk-based approach looks like when it is working.

How often should an AML risk assessment be updated?

Update the assessment whenever the business changes materially, and at least as part of the two-year effectiveness review that FINTRAC compliance programs must undergo. Material change means anything that shifts your exposure: launching a new product, entering a new market or higher-risk geography, or adding a new delivery channel. Each of those can introduce risk the existing assessment never considered, so waiting for the two-year cycle to catch up leaves a gap in between. The reason cadence matters is simple: a risk assessment that is not kept current does not reflect your actual exposure, and an out-of-date document cannot show an examiner that your controls are aimed at real risk. Build review triggers into the program so a material change prompts a refresh automatically, and keep the two-year review as the backstop. Then record the update, have it approved, and date it, so the assessment stays a living document rather than a PDF refreshed once and forgotten.

Did Bill C-12 change AML risk assessment requirements?

Bill C-12, in force since March 2026, raised the overall standard so that every compliance program must be reasonably designed, risk-based, and effective. It did not replace the risk assessment requirement; it made that requirement carry more weight. The risk assessment is precisely what makes a program risk-based, because it is the evidence that your controls are aimed at your actual exposure rather than applied at random. Under the new standard, a thorough, current, and well-documented assessment is what lets you show an examiner the program is effective and not just present on paper. That is also why a FINTRAC examiner reads the risk assessment first: everything else in the program should trace back to it. So the practical effect of Bill C-12 is not a new template but a higher bar for the same document. A stale or generic assessment that might once have passed is now a harder gap to defend under examination.

Back to all resources

Turn the risk assessment into a working program.

Book a platform demo and we will show you the screening and recorded decisions that put your risk-based approach into practice.

Book a demo
Prefer to talk now? Email hello@gobritebase.com