As of October 11, 2024, Canada’s mortgage sector falls under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). Mortgage administrators, brokers, and lenders are now reporting entities with the same compliance obligations that have applied to banks, credit unions, and real estate brokerages for years. You need a documented compliance program. You verify client identities with FINTRAC-accepted methods, keep records for five years, and report certain transactions. FINTRAC is examining newly covered entities and issuing public penalties. This guide breaks down the FINTRAC requirements for mortgage brokers, lenders, and administrators, and what to do about them.
Who Must Comply with FINTRAC
FINTRAC coverage applies to three categories of non-bank mortgage businesses:
- Mortgage administrators: Entities that administer mortgage agreements on behalf of lenders, including collecting payments and managing defaults.
- Mortgage brokers: Individuals and entities that negotiate mortgage agreements between borrowers and lenders for compensation.
- Mortgage lenders: Entities that advance funds under mortgage agreements, excluding federally and provincially regulated financial institutions, which operate under separate existing obligations.
If your mortgage business operates outside a regulated financial entity, FINTRAC’s mortgage sector self-assessment tool can confirm whether the Act applies to your specific operations.
One point worth flagging: while most compliance obligations fall on the employer entity, Suspicious Transaction Reports apply to employees directly. Individual brokers and agents cannot delegate that obligation to their brokerage.
The Five Elements of a Compliance Program
A FINTRAC compliance program is a documented, functional system that FINTRAC examiners assess against your actual operations. The Act requires five specific elements, and each one must be tailored to your business.
- Compliance officer. A designated individual with the knowledge and authority to oversee the program. This person needs to understand FINTRAC obligations and have real standing within the organization to implement them.
- Written policies and procedures. Documented procedures covering all FINTRAC obligations: client identification, record keeping, transaction monitoring, and reporting. These must be kept current and approved by a senior officer. A policy that reflects how the business operated two years ago is not a compliant policy.
- Risk assessment. A documented analysis of your business’s specific money laundering and terrorist financing vulnerabilities, based on your client base, transaction types, geographic exposure, and delivery channels. Generic risk assessments copied from templates consistently fail FINTRAC examination.
- Ongoing training. All employees with FINTRAC-relevant responsibilities must receive regular training. Training records should be kept and updated as requirements change.
- Prescribed review. A comprehensive review of the entire compliance program, conducted at minimum every two years, by a qualified party with sufficient independence from day-to-day operations.
The enforcement data is instructive here. MNP’s analysis of 49 FINTRAC penalties through March 2025 found that 63% of penalized entities had policies and procedures deficiencies, 63% had risk assessment failures, and 51% had missed report filings. These are not obscure technical violations. They are documentation gaps that a structured program would prevent.
FINTRAC Identity Verification for Individual Clients: When and How
Identity verification is the highest-frequency FINTRAC obligation in mortgage origination and the most documented examination failure point. Getting the trigger right, using an accepted method, and producing a retrievable record are three separate requirements, all of which must be met.
When verification is required
Identity verification is required at the establishment of a new business relationship. For mortgage brokers and lenders, this typically means when a client first engages for mortgage services, before any funds are advanced. If a client has not previously been verified under the Act, that verification must happen before the business relationship proceeds.
The three methods most relevant to mortgage workflows
FINTRAC accepts five methods for verifying an individual’s identity. Three are operationally relevant for most mortgage originators: the government-issued photo ID method, the credit file method, and the dual-process method. Each has distinct requirements and a different documentation footprint.
Government-issued photo ID method
The client presents a valid, current government-issued photo ID containing their full name, a unique identifier, and their photo. Acceptable documents include driver’s licences, provincial identity cards, and passports.
For in-person verification, the broker reviews the original document and checks it for authenticity and security features. For remote verification, FINTRAC permits the use of a live selfie or video matched against the presented ID. The compliance element goes beyond viewing the document: you confirm its authenticity and record the outcome with a date.
Credit file method
A Canadian credit file at least three years old, drawing from more than one credit bureau source, with name, address, and date of birth matching the client. The critical compliance element: the check must be documented at the point of verification, not treated as incidental to a credit pull done during underwriting.
For mortgage brokers who already pull credit at application, the compliance step is adding a timestamped verification record tied to that pull. The pull itself is not sufficient without documentation of the date and purpose.
Dual-process method
The dual-process method combines two separate sources to establish identity where a single document or credit file is not sufficient on its own. One source must confirm the client’s name and address; the other must confirm their name and date of birth. Both must be drawn from reliable, independent sources, and neither can duplicate information from the other.
In mortgage origination, this method is particularly relevant when a client cannot present acceptable photo ID, when a credit file is too thin or too recent to meet the three-year requirement, or when the broker needs additional confidence before proceeding. It is also a strong compliance posture for higher-risk client profiles, since it produces corroboration from two independent data points rather than one.
The documentation requirement is the same as for other methods: the sources used, the date of verification, and the outcome must all be recorded at the time of the check.
ID Verify and Bank Verify satisfy the dual-process method when used together. ID Verify validates the client’s government-issued photo ID and confirms their name and date of birth. Bank Verify then corroborates the client’s name and address against their bank account through Name Match, with the bank-held record serving as the independent second source. Bank Verify can also confirm the tenure of the client’s bank account, which adds a practical fraud-prevention layer: a long-standing account held in the same name is a meaningful signal that the identity is genuine, not recently constructed.
Used together through Inverite’s ID Verify, the two products produce a single documented verification trail that covers both required data points under the dual-process method, with a dated, retrievable record that meets FINTRAC’s documentation requirement. FINTRAC compliance is explicitly listed as a supported use case.
Documentation: the part that fails examinations
Whichever method you use, the record must capture three things: which method you used, the verification date, and the result. Manual notes in a client file are not sufficient for scalable, examination-ready compliance. They are difficult to retrieve, easy to lose, and inconsistent across staff. For brokers using ID Verify and Bank Verify in tandem for the dual-process method, both verification outputs are retained as a combined record, covering the photo ID validation, the Name Match result, and the bank account tenure confirmation in a single retrievable file.
Record Keeping and Reporting Obligations
Record keeping
All client identification records, transaction records, and filed reports must be retained for a minimum of five years from the date of the record. FINTRAC can request records within 30 days, and the obligation to produce them is not negotiable. Records must be organized and accessible, not buried in email threads or paper client files.
The four report types mortgage entities must know
Suspicious Transaction Reports (STRs): Filed when there are reasonable grounds to suspect that a transaction is related to money laundering or terrorist financing. STRs apply to individual employees, not only to the entity. A broker who forms reasonable grounds must file, regardless of what the brokerage does.
Large Cash Transaction Reports (LCTRs): Required when you receive $10,000 or more in cash or virtual currency in a single transaction or in connected transactions within 24 hours.
Listed Person or Entity Property Reports (LPEPRs): As of October 1, 2025, required when you hold or control property belonging to a person or entity listed under applicable sanctions legislation. This was introduced through October 2025 amendments.
PEP and HIO determination: When a client receives $100,000 or more in cash or virtual currency, the mortgage entity must take reasonable measures to determine whether they are a politically exposed person or the head of an international organization.
Applying This to Your Origination Workflow
Compliance is easier to build into origination than to add on top of it. Here is a practical step-level summary a mortgage professional can run against their current process.
Step 1: Determine client type. Is this an individual or an entity? Individual and entity verification follow different requirements under FINTRAC. The steps below apply to natural persons.
Step 2: Verify identity before the business relationship is established. Use the government-issued photo ID method or the credit file method. For remote origination, use a digital verification tool that produces a dated, auditable record.
Step 3: Document immediately. Record the method you used, when the verification happened, and what it returned. For remote verification, confirm your tool produces a timestamped record that is retrievable without manual reconstruction.
Step 4: Check PEP and HIO status for transactions at or above the $100,000 cash threshold.
Step 5: Retain all records in a searchable format that can be produced within 30 days.
ID Verify handles Steps 2 and 3 for the government-issued photo ID method, including the dated verification record FINTRAC requires. Bank Verify adds account confirmation and Name Match corroboration at Step 2. Used together through Inverite’s digital onboarding workflow, they produce a documented verification trail without manual handling at each step.
If your mortgage business is building toward FINTRAC compliance, identity verification is where the workflow starts. See how ID Verify and Bank Verify handle client verification with the documentation trail FINTRAC requires.
Frequently Asked Questions
When did FINTRAC requirements start applying to mortgage brokers?
FINTRAC requirements under the PCMLTFA took effect for mortgage brokers, lenders, and administrators on October 11, 2024. There was no phase-in period. Full obligations applied from that date, including the requirement to have a documented compliance program in place before FINTRAC examination.
What are the penalties for not complying with FINTRAC as a mortgage broker?
FINTRAC issues administrative monetary penalties (AMPs) for non-compliance, tiered by violation severity. Minor violations can reach $1,000 for individuals. Serious violations carry penalties up to $100,000. Very serious violations reach $500,000 for individuals, with higher maximums for entities. Penalties are published publicly, so reputational exposure accompanies financial penalties. FINTRAC issued a record 23 notices of violation in fiscal 2024-25, the most in the agency’s history, totalling over $25 million. The mortgage sector, newly brought under the Act, is a current examination focus.
Can digital tools be used to meet FINTRAC identity verification requirements?
Yes. FINTRAC explicitly permits remote identity verification. For the government-issued photo ID method, verification can be completed digitally by having the client photograph their ID and complete a live selfie or video check against it. The requirements are consistent whether verification happens in-person or remotely: the process must produce a dated, auditable record, and the method must follow FINTRAC’s guidance on acceptable remote verification. FINTRAC’s guidance on methods to verify identity covers the specific requirements for each method.
This article provides general information and does not constitute legal advice. Readers should consult qualified legal counsel for compliance guidance specific to their business.
