BriteBase
Industry primer · MSBs

MSB compliance primer: AML and sanctions expectations in Canada

A money services business (MSB) is a Canadian reporting entity defined under section 5(h) of the PCMLTFA, covering foreign exchange dealing, remittance, the issuance or redemption of money orders, and dealing in virtual currency. This primer lays out, plainly, what Canadian MSBs have to do to satisfy FINTRAC, what controls they have to operate, what their technology stack should cover, and the in-house expertise they need to keep the program defensible.

By BriteBase team · Published June 4, 2026 · 12 min read

Money services businesses sit at the centre of Canada’s AML regime. They handle currency, cross-border value, and (for virtual currency dealers) digital assets at scale, often for customers who do not have access to traditional banking. FINTRAC examines MSBs more frequently than any other sector and, since the March 2026 increase, with materially higher Administrative Monetary Penalty (AMP) exposure on the line. This primer is the operating manual.

What is a money services business under Canadian law?

An MSB is defined in section 5(h) of the PCMLTFA and the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations. A person or entity is an MSB if it engages in any of these activities for the public:

  • Foreign exchange dealing.
  • Remitting or transmitting funds by any means.
  • Issuing or redeeming money orders, traveller’s cheques, or similar negotiable instruments (excluding cheques payable to a named person or entity).
  • Dealing in virtual currency (exchanging, transferring, or providing transfer services).

A foreign MSB that directs services at persons in Canada is treated equivalently and must register with FINTRAC as a foreign MSB.

Registration with FINTRAC

Every MSB and foreign MSB must register with FINTRAC before conducting its first activity. Registration covers all eligible activities and is renewable every two years. The FINTRAC MSB guidance sets out the application requirements. Operating without registration is itself a violation of the PCMLTFA.

What Canadian AML framework applies to MSBs?

Three layers govern MSB compliance:

  1. The PCMLTFA and its regulations. Define the substantive obligations: registration, the compliance program, KYC and recordkeeping, reporting, and sanctions.
  2. FINTRAC guidance and notices. Operational interpretation of the regulations: compliance program requirements, sector guidance, and the AMP policy.
  3. Bill C-12 and the new effectiveness standard. A compliance program must now be reasonably designed, risk-based and effective. We covered the standard in detail in our Bill C-12 guide. The practical implication for MSBs: examiners now test outcomes, not just whether policies exist.

What are the five PCMLTFA program pillars for MSBs?

FINTRAC examines every MSB against five program pillars. Each one has MSB-specific operational expectations.

  • Compliance officer (CAMLO). A named, qualified Chief Anti-Money Laundering Officer with documented authority and a reporting line that does not run through the customer-facing business. For lean MSBs, a fractional CAMLO is the standard pattern.
  • Risk assessment. A written ML/TF risk assessment that reflects the MSB’s products (remittance, FX, money orders, virtual currency), customer base, geographic exposure, and channels. The risk assessment is the document examiners read first. It must drive control calibration, not sit on a shelf.
  • Policies and procedures. Written and version-controlled, covering: customer identification, KYC and beneficial ownership, ongoing monitoring, sanctions and PEP screening, suspicious activity escalation, reporting, recordkeeping, and training.
  • Training program. Role-based, evidenced by completion records, and refreshed on a defined cadence. Frontline staff need different training than the CAMLO. Training must produce detectable behavioural change in alerts and escalations.
  • Independent effectiveness review. Conducted at least every two years by a party genuinely independent of the operating program, with findings tracked to closure.

What are the three layers of an MSB compliance program?

The three layers of an MSB compliance program, and what each must cover, in one view.

GOVERNANCE What the firm owns CAMLO appointment Risk assessment Policies Training Independent review OPERATIONS What the firm operates ID at thresholds Sanctions and PEP Remittance DD STR / LCTR / EFTR Recordkeeping TECHNOLOGY What the firm runs on KYC platform Screening engine Monitoring rules Case workflow F2R integration

Which reports does an MSB have to file?

The reports FINTRAC expects from an MSB, with thresholds and deadlines:

Report Threshold Who files Deadline
Suspicious Transaction Report (STR)No dollar threshold; suspicion testMSBAs soon as practicable after reasonable grounds to suspect
Large Cash Transaction Report (LCTR)CAD $10,000 or equivalent in 24 hoursMSBWithin 15 days of the transaction
Electronic Funds Transfer Report (EFTR)International EFT, CAD $10,000 or equivalentMSB sending or receivingWithin 5 working days
Large Virtual Currency Transaction Report (LVCTR)CAD $10,000 in virtual currency in 24 hoursMSB receiving virtual currencyWithin 5 working days
Terrorist Property Report (TPR)Property in possession of a listed personMSBImmediately

Reports are filed electronically via FINTRAC’s F2R reporting channels (the F2R API for high-volume integration, or the FINTRAC Web Reporting System for lower volumes). The compliance program must specify which channel is used and how filings are reconciled with the underlying case file.

When does an MSB have to identify a customer?

Identification triggers for MSBs are tighter than for many other reporting entities. The key thresholds:

  • Currency exchange. Identify the customer for any transaction of CAD $1,000 or more.
  • Money transfer / remittance. Identify the customer for any transfer at CAD $1,000 or more, including the originator and beneficiary fields required by the Travel Rule.
  • Issuance of negotiable instruments. Identify the customer for CAD $3,000 or more.
  • Virtual currency transfer. Identify the customer at CAD $1,000 or more, with originator and beneficiary information transmitted under the Travel Rule (see our Travel Rule requirements primer).
  • Account-style relationships. Identify on account opening, regardless of transaction value, and confirm beneficial ownership where the customer is a legal entity.

The 24-hour aggregation rule applies: multiple transactions by or on behalf of the same person within 24 hours that together meet a threshold are treated as a single transaction.

Which sanctions lists must an MSB screen against?

MSBs must screen customers, transactions, and beneficial owners against Canadian sanctions lists at onboarding and on a continuous basis. The required lists include:

  • Special Economic Measures Act (SEMA) regulations, country by country (Russia, Belarus, Iran, others). Maintained by Global Affairs Canada.
  • Justice for Victims of Corrupt Foreign Officials Act (JVCFOA) listings.
  • United Nations Act regulations implementing UNSC sanctions.
  • Criminal Code listed entities (terrorist entities) under sections 83.05 and following.
  • OSFI Consolidated Lists. Operationally, the OSFI consolidated lists are the most practical source covering UN, SEMA, and Criminal Code listings in a single dataset.

MSBs serving customers exposed to US-jurisdiction activity should additionally consider OFAC SDN screening, since US extraterritorial sanctions enforcement can affect Canadian counterparty relationships.

What does the MSB technology stack need to cover?

A defensible MSB technology stack covers six capabilities. Off-the-shelf or built in-house, they must integrate end to end:

  • Digital onboarding and KYC. Document authenticity, liveness, name and address verification, beneficial ownership capture.
  • Sanctions and PEP screening. Real-time at onboarding and on a continuous basis. Fuzzy matching, false-positive disposition workflow, audit trail of every hit and decision.
  • Customer risk rating. Risk model that reflects product, geography, channel, occupation, and behaviour. Documented logic and refresh cadence.
  • Transaction monitoring. Rule-based scenarios for the MSB’s actual products: structuring, threshold avoidance, velocity, remittance corridor risk, FX behaviour outliers. Increasingly layered with ML-based anomaly detection (see our AI and AML primer).
  • Case management. One workflow for alert triage, investigations, escalation, STR drafting, and disposition with a defensible audit trail.
  • FINTRAC reporting integration. Automated population and filing of STR, LCTR, EFTR, and LVCTR via F2R, with reconciliation back to the case record.

What in-house expertise does an MSB need?

The minimum competent team for a Canadian MSB at modest volume:

  • CAMLO. Named compliance officer with current Canadian PCMLTFA knowledge and the authority to halt activity. Many MSBs without in-house capacity engage a fractional CAMLO.
  • One or more compliance analysts. Frontline triage of screening hits and transaction monitoring alerts, customer due diligence, and report drafting.
  • Independent reviewer. A party with no operational involvement, engaged for the two-year effectiveness review. Often external.
  • Operational backstop. Frontline staff trained to escalate, not adjudicate.

At higher volume (multi-channel remittance, large currency exchange operations, or VC dealer activity), additional dedicated investigators, a sanctions specialist, and a regulatory affairs lead are typical.

What do FINTRAC examiners look for in an MSB?

The questions a current FINTRAC examination tends to lead with, applied to MSBs:

  • Show me the current risk assessment and when it was last refreshed.
  • Walk me through a sample of recent STRs and the underlying case files.
  • How are sanctions hits disposed of, with what rationale, and by whom?
  • Show me the training records for the past 12 months.
  • Where is the audit trail for an alert that was closed without filing a report?
  • What did the last independent effectiveness review surface, and how is each finding tracked to closure?

An MSB program that can answer those six questions inside a working day is materially harder to fine under the new AMP ceilings. Our audit-ready playbook covers the operational habits in more detail.

How does BriteBase help MSBs?

Our AML screening platform delivers real-time sanctions, PEP, and adverse-media screening with agentic entity resolution, alert triage, and audit-ready case history. MSBs can integrate through the self-serve screening API or run the unified case management interface, and the same watchlist and risk data is available on coverage-based subscriptions.

FAQ

What is a money services business (MSB) in Canada?

A money services business (MSB) is a Canadian reporting entity defined under section 5(h) of the PCMLTFA and its regulations. A person or entity is an MSB if it engages, for the public, in any of four activities: foreign exchange dealing; remitting or transmitting funds by any means; issuing or redeeming money orders, traveller's cheques, or similar negotiable instruments (excluding cheques payable to a named person); or dealing in virtual currency by exchanging, transferring, or providing transfer services. A foreign MSB that directs services at persons in Canada is treated equivalently and must register with FINTRAC as a foreign MSB. MSBs sit at the centre of Canada's AML regime because they handle currency, cross-border value, and digital assets at scale, often for customers without traditional banking access. FINTRAC examines the sector more frequently than any other, which raises the stakes on a defensible program.

Do MSBs have to register with FINTRAC?

Yes. Every MSB and foreign MSB must register with FINTRAC before conducting its first activity, and operating without registration is itself a violation of the PCMLTFA. A single registration covers all eligible MSB activities, so a firm dealing in foreign exchange, remittance, money orders, and virtual currency registers once across that whole footprint. Registration is renewable every two years, and the FINTRAC MSB guidance sets out the application requirements. Foreign money services businesses that direct services at persons in Canada are captured on the same basis and must register as foreign MSBs, even without a Canadian place of business. Registration is separate from, and prior to, the substantive compliance obligations: it establishes the firm as a reporting entity, after which the five program pillars, KYC and recordkeeping, reporting, and sanctions screening all apply. Registration alone does not make a program defensible; it is the entry condition.

What reports does an MSB have to file with FINTRAC?

An MSB files up to five report types with FINTRAC. Suspicious Transaction Reports (STRs) have no dollar threshold and are filed as soon as practicable after reasonable grounds to suspect. Large Cash Transaction Reports (LCTRs) apply to CAD $10,000 or equivalent in cash within 24 hours, filed within 15 days. Electronic Funds Transfer Reports (EFTRs) cover international transfers of CAD $10,000 or more and are due within five working days. Large Virtual Currency Transaction Reports (LVCTRs) apply where the MSB receives CAD $10,000 or more in virtual currency within 24 hours, also within five working days. Terrorist Property Reports (TPRs) are filed immediately when property is in the possession of a listed person. Reports are submitted electronically through FINTRAC's F2R channels, either the F2R API for high volumes or the Web Reporting System, and each filing must reconcile back to the underlying case file.

What sanctions lists do Canadian MSBs have to screen against?

MSBs must screen customers, transactions, and beneficial owners at onboarding and on a continuous basis against Canadian sanctions lists. The required sources are the Special Economic Measures Act (SEMA) regulations maintained by Global Affairs Canada, Justice for Victims of Corrupt Foreign Officials Act (JVCFOA) listings, United Nations Act regulations that implement UNSC sanctions, and Criminal Code listed entities under sections 83.05 and following. Operationally, the OSFI Consolidated Lists are the most practical single source, since they combine the UN, SEMA, and Criminal Code listings into one dataset. MSBs serving customers exposed to US-jurisdiction activity should additionally consider OFAC SDN screening, because US extraterritorial sanctions enforcement can reach Canadian counterparty relationships. Screening is not a one-time onboarding check: because listings change, the customer book has to be re-screened continuously so a name added after onboarding is still caught, with every hit and disposition captured in an audit trail.

At what threshold does a Canadian MSB have to identify a customer?

Identification triggers for MSBs are tighter than for many other reporting entities. Identify the customer at CAD $1,000 or more for currency exchange, for money transfer or remittance, and for virtual currency transfers, with the last two also carrying the originator and beneficiary fields required by the Travel Rule. The issuance of money orders, traveller's cheques, or similar negotiable instruments triggers identification at CAD $3,000 or more. Account-style relationships require identification on account opening regardless of transaction value, and beneficial ownership must be confirmed where the customer is a legal entity. The 24-hour aggregation rule applies throughout: multiple transactions by or on behalf of the same person within 24 hours that together meet a threshold are treated as a single transaction, so a firm cannot avoid identification by splitting one flow into smaller amounts. Getting the trigger right is the foundation for every downstream KYC and screening step.

How often does an MSB need an independent effectiveness review?

At minimum every two years, conducted by a party genuinely independent of the operating compliance program, with every finding tracked to closure. Independence is the operative requirement: the reviewer cannot be someone who runs the program day to day, which is why many MSBs engage an external party for this pillar. Under Bill C-12, the review carries more weight than it once did. The statutory standard now requires a program that is reasonably designed, risk-based and effective, so the review has to evidence that the program actually works in practice, not merely that documentation exists. In practical terms, examiners read the last independent review early in an examination and ask how each finding was resolved. An MSB that can show the review, the findings, and a closed remediation trail is materially better positioned than one whose review sat on a shelf without follow-through. The review is a control, not a formality.

What in-house expertise does a Canadian MSB need?

At a minimum, a Canadian MSB needs a named CAMLO, one or more compliance analysts, and an independent reviewer. The CAMLO, whether in-house or fractional, must hold current PCMLTFA knowledge and the documented authority to halt activity, with a reporting line that does not run through the customer-facing business. Compliance analysts handle frontline triage of screening hits and transaction monitoring alerts, customer due diligence, and report drafting. The independent reviewer has no operational involvement and is engaged for the two-year effectiveness review, often externally. Underneath that, frontline staff act as an operational backstop, trained to escalate rather than adjudicate. Lean MSBs commonly meet the CAMLO requirement through a fractional arrangement rather than a full-time hire. At higher volume, such as multi-channel remittance, large currency exchange operations, or virtual currency dealer activity, firms typically add dedicated investigators, a sanctions specialist, and a regulatory affairs lead to keep the program defensible.

Back to all resources

Reading is useful. A conversation is faster.

Book a platform demo and we will walk you through real-time sanctions, PEP, and adverse-media screening and the data coverage that fits your firm.

Book a call
Prefer to talk now? Email hello@gobritebase.com