BriteBase
Penalties

Inside the March 2026 AMP increase: new ceilings, new exposure

March 2026 brought a substantial increase in administrative monetary penalty ceilings. Here's what changed, why it matters, and how to think about your firm's exposure.

By BriteBase team · Published April 5, 2026 · Updated April 30, 2026 · 7 min read

In March 2026, the administrative monetary penalty (AMP) framework that backs the PCMLTFA was updated with materially higher ceilings. The change is technical in form but strategic in effect: the worst-case dollar exposure for a Canadian reporting entity that fails its compliance obligations has gone up, in some categories, several-fold.

What does the AMP increase actually do?

AMPs in the AML regime are tiered by violation severity, minor, serious, and very serious, and by whether the entity is a natural person or an entity. The March 2026 changes lifted the per-violation ceilings across these tiers and, importantly, did not change the rule that violations can be assessed per occurrence. A pattern of recurring violations across a customer book or a reporting period can therefore aggregate quickly.

Why did the AMP ceilings rise now?

Two pressures converged. Internationally, Canada has been responding to FATF mutual evaluation feedback that the AMP framework was not proportionate or dissuasive enough relative to the size of regulated firms and the volumes they process. Domestically, FINTRAC and policymakers wanted to close the gap between the cost of compliance and the cost of non-compliance, which had, in some segments, tilted in the wrong direction.

Where does exposure change most?

  • High-volume MSBs and PSPs, where per-occurrence violations across thousands of transactions can compound.
  • Crypto-asset service providers, where reporting and recordkeeping obligations interact with high transaction velocity.
  • Firms with weak documentation, because each undocumented decision becomes a potential separate violation.
  • Firms with stale risk assessments, because foundational deficiencies tend to drive multiple downstream findings.

How to think about it as a board or executive

The right framing is no longer 'what's the worst single fine we could receive?' It's 'what's the multi-million-dollar aggregate exposure across our current book if an examination surfaces a foundational deficiency?' That number, for many lean firms, now exceeds the cost of materially upgrading the compliance program, which is precisely the behavioural change the increase is designed to drive.

Practical next steps

  • Re-run a gap assessment against the current PCMLTFA standard, not the one your program was built against.
  • Quantify exposure: estimate per-occurrence violations across your book if a foundational gap were found.
  • Prioritize remediation by exposure-weighted risk, not by ease.
  • Make sure your audit trail can prove what you actually did, in the order you did it.

The takeaway

Higher ceilings don't automatically mean higher fines for everyone. They do mean that the firms who treated compliance as a checkbox now have a much larger, much more visible downside. The cost of doing the work properly has, for the first time in years, become clearly cheaper than the cost of not doing it.

FAQ

What changed in the March 2026 AMP increase?

The March 2026 update lifted the per-violation ceilings of the administrative monetary penalty framework that backs the PCMLTFA. AMPs are tiered by severity, minor, serious, and very serious, and by whether the entity is a natural person or an entity, and the change raised the ceilings across all of those tiers and categories at once. The technical form is narrow, but the strategic effect is not: the worst-case dollar exposure for a Canadian reporting entity that fails its obligations has gone up several-fold in some categories. Crucially, the update did not change the rule that violations can be assessed per occurrence. That combination is what makes the increase matter. A pattern of recurring violations across a customer book or a reporting period can aggregate quickly, so higher ceilings and per-occurrence assessment together turn a foundational deficiency into a much larger aggregate number than the headline ceiling alone suggests.

Why did Canada raise the AMP ceilings now?

Two pressures converged. Internationally, Canada has been responding to FATF mutual evaluation feedback that the AMP framework was not proportionate or dissuasive enough relative to the size of regulated firms and the volumes they process. A ceiling that looks meaningful for a small operator is trivial for a high-volume business, and the old framework did not scale to that reality. Domestically, FINTRAC and policymakers wanted to close the gap between the cost of compliance and the cost of non-compliance, which in some segments had tilted in the wrong direction. Where cutting corners was cheaper than running the program properly, the incentive structure worked against the regime's own goals. Raising the ceilings, while keeping per-occurrence assessment, is designed to flip that calculation. The intended behavioural change is to make materially upgrading a compliance program clearly cheaper than absorbing the aggregate exposure an examination could surface across a firm's book.

Who is most exposed under the higher AMP ceilings?

Four kinds of firm carry the most exposure under the higher ceilings, and the common factor is how quickly a single weakness multiplies across a book. High-volume MSBs and PSPs are first, because per-occurrence violations across thousands of transactions can compound into a very large aggregate. Crypto-asset service providers follow, since reporting and recordkeeping obligations interact with high transaction velocity in the same way. Firms with weak documentation are exposed because each undocumented decision becomes a potential separate violation, so poor recordkeeping directly inflates the count. And firms with stale risk assessments are exposed because a foundational deficiency tends to drive multiple downstream findings rather than one. Higher ceilings do not automatically mean higher fines for everyone; they mean that firms which treated compliance as a checkbox now have a much larger and more visible downside. For these four profiles, the aggregate exposure, not the single fine, is the number that matters.

How should an owner or board reframe AMP exposure?

The right framing is no longer 'what is the worst single fine we could receive?' That question underweights how the regime actually works. The better question is 'what is the multi-million-dollar aggregate exposure across our current book if an examination surfaces a foundational deficiency?' Because violations are assessed per occurrence and the ceilings are now higher, a single systemic gap can repeat across thousands of transactions and customer files, producing a total that dwarfs any one penalty. For many lean firms, that aggregate number now exceeds the cost of materially upgrading the compliance program, which is precisely the behavioural change the increase is designed to drive. Reframed this way, compliance spending stops being a cost centre and becomes exposure reduction. A board that quantifies the downside in aggregate terms, rather than as a worst-case single fine, will usually find the business case for remediation makes itself.

What practical steps reduce AMP exposure quickly?

Four steps move exposure down fastest. First, re-run a gap assessment against the current PCMLTFA standard, not the one your program was originally built against, because the standard and the ceilings have both moved. Second, quantify exposure: estimate the per-occurrence violations that would be assessed across your book if a foundational gap were found, so the risk is a number rather than a worry. Third, prioritize remediation by exposure-weighted risk rather than by ease, so the work that closes the largest aggregate liability goes first instead of the work that is simplest to finish. Fourth, make sure your audit trail can prove what you actually did, in the order you did it, since an undocumented decision can become a separate violation. Together these steps convert an abstract worst-case ceiling into a ranked, costed remediation plan, and for most lean firms that plan is cheaper than the exposure it removes.

Back to all resources

Reading is useful. A conversation is faster.

Book a platform demo and we will walk you through real-time sanctions, PEP, and adverse-media screening and the data coverage that fits your firm.

Book a call
Prefer to talk now? Email hello@gobritebase.com