Spotlight

What FINTRAC Examines in Your Training Program

FINTRAC publishes the methods its examiners use. Here is what they apply to your credit union AML training program — and the four things they test.

Michael Cosgrove

FINTRAC publishes the playbook its examiners use. Its assessment manual sets out, method by method, how officers test each part of a compliance program — and one short section of it deals specifically with training. [1] Most credit unions have never read it.

This is Canada only. The obligations below flow from the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations, and apply to credit unions as financial entities. The assessment manual itself creates no new requirements — FINTRAC is explicit that it describes its examination approach rather than the law. [1] But if you want to know what an examiner will actually ask for, it is the closest thing to an answer key that exists.

What the manual tests

FINTRAC’s assessment methods for training come down to four questions: is there a written, ongoing program; is there a documented plan for delivering it; is the material tailored to your business and to specific roles; and is the program put into practice — which examiners test by interviewing your staff. The manual also names where its focus falls hardest: the training you provide on detecting suspicious transactions. [1]

The manual is public, and it is specific

Section 3.1.4 of the assessment manual covers the ongoing compliance training program. It states what examiners look at: “who receives training, what topics are covered, when and how often training takes place, how you have implemented your training program, and how training is delivered.” [1]

It then adds the qualifier that decides most findings — that the program must be adequate, take into account the size, type, nature and complexity of your business, and be put into practice.

The obligation itself sits in two places. Section 9.6 of the PCMLTFA requires you to establish and maintain a compliance program; the regulations prescribe what has to be in it. Two of those prescribed elements are a written, ongoing compliance training program under s.156(1)(d), and a documented plan for that program and for delivering the training under s.156(1)(e). [2] Two separate requirements. Two separate documents.

Two documents, not one

This is the most common gap we see, and it is a documentation gap rather than a training gap. Credit unions deliver training every year. What they often cannot produce on demand is the written program describing it, and the delivery plan showing who gets trained, on what, when, how often, and by what method.

That matters because of when the request arrives. FINTRAC’s manual says notification usually comes 30 to 45 days before an examination, and that the date of the notification call is the start of the examination. All the material it requests is reviewed before anyone speaks to your staff, and it is used to prepare the interview questions. The manual is also explicit that documents submitted or corrected after the notification date generally still count as non-compliance. [1]

Readiness is built before the phone rings, not in the thirty days after it.

Worth checking at the same time: who your program actually reaches. The regulation covers employees, agents or mandataries, and other persons authorized to act on your behalf. FINTRAC’s guidance points specifically at those who have contact with clients, are involved in client transaction activities, handle cash, funds or virtual currency, or oversee the compliance program — a group that includes senior management in those roles. [2] Directors are not named as a mandatory training audience, though a board that approves your policies and receives the effectiveness review report has its own reason to understand what it is approving. The group missed outright, most often, is agents and third parties acting on your behalf.

Tailored, or generic

Examiners review your training material to confirm the content is suitable — that it is, in the manual’s words, “tailored to your business and adequate for your employees, agents and their respective responsibilities.” [1]

That is the sentence most off-the-shelf courses fail. Content written for another jurisdiction, or for a large bank’s operating model, does not describe your member terminology, your branch realities, or your own policies and procedures. It teaches the regime; it does not teach your institution.

The manual is equally clear about scope. Its stated focus is whether training helps staff understand the requirements, your policies and procedures, and the indicators and trends of money laundering and terrorist activity financing — and it adds that FINTRAC will “pay close attention to the training you provide regarding the detection of suspicious transactions.” [1]

Indicators move. A course refreshed once a year and left alone teaches last year’s typologies. Two places where that lag shows quickly: ministerial directives, where the manual says examiners may interview employees and agents to assess their knowledge of the requirements; and sanctions evasion, which since 19 August 2024 must be reported through the existing suspicious transaction report rather than any separate form, and which has its own FINTRAC Special Bulletin of indicators behind it. [3]

The interview is the real test

Examinations include employee interviews, and the standard applied is a practical one. Staff are not expected to recite policy from memory. They are expected to be aware of the requirements that apply to their duties, and to know how to seek clarification when they are unsure. [1]

Completion records cannot answer that. They record attendance, not understanding. A program that runs on click-through modules and a completion percentage has no evidence to offer when an examiner asks how you know the training worked — and no mechanism for producing the outcome the interview is testing for.

What does hold up: scenario-based content that requires a decision rather than a scroll, scored assessment with results retained, and frequency high enough that the material is still available to someone months later, on an ordinary Tuesday, when a transaction does not look right.

Training is never examined on its own

Two cross-checks catch programs that look fine in isolation.

The first is your risk assessment. When examiners assess it, they confirm that your policies and procedures, ongoing training documentation and two-year review documentation “adequately address the areas you have assessed as posing a higher risk.” [1] If your risk assessment flags a product line or geography as high risk and your training never mentions it, the disconnect is the finding.

The second is the two-year effectiveness review. The manual says examiners verify that the review covered your policies and procedures, your risk assessment and your training program, that a written report went to a senior officer within 30 days of completion, and that the findings are being actioned. [1] A review that certifies training as effective without describing how it tested that is a weak document in front of an examiner.

And there is a broader point in the manual worth sitting with: deficiencies identified elsewhere may be treated as an indication that one or more of the five compliance program elements is not being applied. [1] A missed suspicious transaction report is rarely only a reporting problem. Someone did not recognize the indicator, or did not escalate it.

The stakes attached to that conclusion changed this year. Under the administrative monetary penalty framework that came into force on 26 March 2026, a prescribed violation committed on or after that date can carry an AMP of up to $20 million for an entity, against a previous ceiling of $500,000; violations occurring entirely before that date are assessed under the earlier framework. [4] That is a law firm’s reading of the new framework — the transition rules repay a look with your own counsel.

Questions for this quarter

  • Can you produce your written training program and your delivery plan today, without assembling them first?
  • Does the plan name every audience the regulation reaches — including agents and anyone else authorized to act on your behalf?
  • Does your training material reference your own policies, products and risk-assessment priorities, or generic Canadian AML content?
  • How would you demonstrate that staff understood the training, rather than completed it?
  • Did your last effectiveness review test the training program, and were its findings actioned?

How TAMLO can help

See where your training program stands

We built a free self-assessment for Canadian credit unions, scored against the assessment methods FINTRAC publishes in its own manual. Fifteen questions across six areas, about five minutes. You get a banded result, your specific gaps named and explained, and a PDF report you can take to your next compliance committee.

Tamlo International provides AML/ATF compliance training for financial institutions, MSBs, credit unions, and fintech companies across Canada and the United States. Whether your team needs foundational AML awareness training, CAMLO-level advanced modules, or a custom compliance program aligned to FINTRAC requirements, we can help. Reach out to Tamlo International to discuss your training needs.

Sources and regulatory references
  1. FINTRAC assessment manual: The approach and methods used during examinations — sections 3.1, 3.1.3, 3.1.4, 3.1.5, 3.8 and Part 2 (regulator guidance)
  2. Compliance program requirements — FINTRAC, on PCMLTFA s.9.6 and PCMLTFR s.156(1)(d) and (e) (regulatory requirement and regulator guidance)
  3. Special Bulletin on financial activity associated with suspected sanctions evasion — FINTRAC (regulator guidance; sanctions evasion reporting in force 19 August 2024)
  4. Canada’s new administrative monetary penalties framework under the PCMLTFA — DLA Piper, May 2026 (legal interpretation)