BriteBase
Identity verification

FINTRAC identity verification methods: the accepted ways to verify identity in Canada

FINTRAC does not let a reporting entity verify identity any way it likes. It sets out specific accepted methods, and an examiner will ask which one you used and whether you can evidence it. This guide explains each accepted method, when it applies, and how AI-powered identity verification maps onto the rules rather than around them.

By BriteBase team · Published June 13, 2026 · 11 min read

Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), FINTRAC sets out the methods a reporting entity may use to verify the identity of a person, and you have to use one of them. The methods are not interchangeable with whatever a vendor happens to offer. This guide walks through each accepted method, when it fits, and where modern AI-powered verification sits within the rules.

Why does the verification method matter?

Identity verification is the foundation of a FINTRAC compliance program. If the method is wrong, or applied incorrectly, every downstream control inherits the weakness, and an examiner who finds it will treat onboarding as unreliable. Since Bill C-12 came into force in March 2026, the standard is explicit: a program has to be reasonably designed, risk-based, and effective. A method that technically exists on paper but does not confirm a real, present human will not meet that test. For the wider framework, see the Bill C-12 compliance guide.

What is the government-issued photo identification method?

The most common method for remote onboarding. The reporting entity confirms that an authentic, valid, and current government-issued photo identity document belongs to the person, and that the person is who they claim to be. The document has to be issued by a federal, provincial, or territorial government, and the entity has to be satisfied the document is authentic and that the person in front of it is the document holder.

This is where AI-powered verification lives. Facial recognition matches the live selfie to the photo on the document, passive liveness confirms the person is real and present, document checks confirm the ID is authentic, and deepfake detection screens out a generated face before it ever becomes an account. None of that changes the legal method; it is a stronger, recorded way of applying it.

How does the credit file method work?

The reporting entity verifies identity by referring to information in a credit file that has existed for at least three years, held by a Canadian credit bureau, and confirms the name, address, and date of birth match. The credit file has to be consulted at the time of verification, and the information has to correspond to what the customer provided.

The credit file method confirms that a consistent record exists. It does not, on its own, confirm that the live human applying is the person the record describes, which is why it is often paired with a document or biometric check in higher-risk flows. A credit file is also exactly what a synthetic identity is engineered to build, so relying on it alone is a known weak point.

When can you use the dual-process method?

Where a photo document or a usable credit file is not available, the dual-process method verifies identity by referring to information from two different reliable and independent sources. Each source has to confirm at least two of: the person's name, their address, and their date of birth, drawn from sources such as a government record, a utility statement, or a financial account, with specific combinations required.

The dual-process method is more administrative and is common where biometric capture is not practical. Whatever the sources, they have to be reliable, independent of each other, and recorded, and the combination has to meet FINTRAC's requirements rather than simply being two documents.

What other verification approaches does FINTRAC accept?

FINTRAC also recognises reliance on the verification done by an affiliate or another reporting entity in defined circumstances, and the use of an agent or mandatary to carry out verification on the entity's behalf. In both cases the responsibility for getting it right, and for keeping the record, stays with the reporting entity. Reliance is a way to avoid duplicating work, not a way to outsource the obligation.

The method is not the evidence

Choosing an accepted method is the first step. The part that survives an examination is the evidence that you applied it correctly: which method, what was checked, what the result was, who decided, and the record retained for the required period. This is the difference between a program that looks compliant and one that is. Modern verification software helps precisely because it records this automatically for every customer, producing the examiner-ready file as a by-product of onboarding. That model is explained in our identity verification software guide, and the supporting controls are covered in document verification and screening. Terms used here are defined in the AML and KYC glossary.

How do you choose the right method?

For digital-first firms onboarding customers remotely, the government-issued photo ID method applied with facial recognition and liveness is usually the strongest fit: it confirms the live human, it scales, and it records itself. The credit file and dual-process methods remain useful fallbacks where biometric capture is not available or the risk profile calls for corroboration. The right answer is risk-based, which is exactly the standard FINTRAC now holds you to.

FAQ

What methods does FINTRAC accept to verify identity?

Under the PCMLTFA, FINTRAC sets out the methods a reporting entity may use to verify a person's identity, and you have to use one of them; they are not interchangeable with whatever a vendor happens to offer. The most common are the government-issued photo identification method, the credit file method, and the dual-process method, which together cover the large majority of remote onboarding. FINTRAC also recognises reliance on the verification already done by an affiliate or another reporting entity in defined circumstances, and the use of an agent or mandatary to carry out verification on the entity's behalf. Whichever method is chosen, the reporting entity has to apply it correctly and record which one it used. The method is only step one; the evidence that it was applied correctly, retained for the required period, is what actually survives an examination, so the record matters as much as the choice.

What is the government-issued photo ID method?

The government-issued photo identification method verifies identity by confirming that an authentic, valid, and current government-issued photo identity document belongs to the person, and that the person is who they claim to be. The document has to be issued by a federal, provincial, or territorial government, and the entity has to be satisfied both that the document is genuine and that the person presenting it is the document holder. It is the most common method for remote onboarding. AI-powered verification lives inside this method: facial recognition matches a live selfie to the photo on the document, passive liveness confirms the person is real and present, document checks confirm the ID is authentic, and deepfake detection screens out a generated face before it becomes an account. None of that changes the legal method; it is a stronger, self-recording way of applying it, which matters because Bill C-12 now expects the method to confirm a real, present human.

Does FINTRAC require liveness or biometric verification?

FINTRAC does not mandate a specific technology by name, so there is no rule that says you must use liveness or biometrics as such. What it requires is that verification be carried out by an accepted method and, under Bill C-12, that the program as a whole be reasonably designed, risk-based, and effective. That standard is where the technology comes back in. For remote onboarding, liveness detection and facial recognition are how a firm demonstrates that the accepted method it chose, typically the government-issued photo identification method, actually confirms a real, present person rather than simply matching a static document. A method that technically exists on paper but does not confirm a live human will not meet the effectiveness test. So while biometrics are not named as a requirement, in practice they are how many digital-first firms evidence that their chosen method works, which is exactly what an examiner now probes.

Is a credit check enough to verify identity for FINTRAC?

The credit file method is an accepted method on its own, but only when its conditions are met. The reporting entity refers to information in a credit file held by a Canadian credit bureau that has existed for at least three years, consults it at the time of verification, and confirms that the name, address, and date of birth match what the customer provided. Where those conditions hold, a credit check can be enough. The limitation is what it proves. A credit file confirms that a consistent record exists; it does not, on its own, confirm that the live human applying is the person the record describes. That is why higher-risk flows often pair it with a document or biometric check. It is also a known weak point against synthetic identity fraud, because a credit file is exactly what a synthetic identity is engineered to build, so relying on it alone leaves that gap open.

What is the dual-process method?

The dual-process method verifies identity using information from two different reliable and independent sources, and it is the fallback used where a photo document or a usable credit file is not available. Each of the two sources has to confirm at least two of the person's name, address, and date of birth, drawn from sources such as a government record, a utility statement, or a financial account, in the specific combinations FINTRAC requires. It is more administrative than the photo ID method and is common where biometric capture is not practical. The important constraint is that the two sources must be genuinely reliable, independent of each other, and recorded; the combination has to meet FINTRAC's requirements rather than simply being any two documents. Because it does not involve a live biometric check, higher-risk flows may still layer additional corroboration on top, but applied correctly and documented, the dual-process method is a fully accepted route to verification.

How long do you have to keep identity verification records?

Reporting entities have to keep records of how identity was verified, including which accepted method was used and the information relied on, for the retention period FINTRAC sets, and be able to produce them on request. The exact length is the retention period FINTRAC prescribes rather than a single fixed number, and the obligation runs for that full period, not just through onboarding. What the record has to capture is the substance of the verification: which method was applied, what was checked, what the result was, who decided, and the underlying evidence. That is the difference between a program that looks compliant and one that is. Keeping the evidence is as important as choosing the method, because an examination tests the record, not the intention. Modern verification software helps by recording this automatically for every customer, producing the examiner-ready file as a by-product of onboarding rather than a later scramble.

Back to all resources

Apply the right method, and evidence it.

Book a platform demo and see real-time sanctions, PEP, and adverse-media screening with audit-ready case history for every decision.

Book a platform demo
Prefer to talk now? Email hello@gobritebase.com