On March 26, 2026, Bill C-12 received royal assent, amending the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and resetting the requirements Canadian firms have to meet for their anti-money laundering (AML) programs.
The Act introduces a new, very serious violation for failing to ensure that a compliance program is “reasonably designed, risk-based and effective.” Penalties have increased forty-fold, with cumulative fines capped at the greater of C$20 million or 3% of gross global revenue.
The question a regulator asks has changed to whether a compliance program works. Six months on, Andrew Davies, Global Head of FCC Strategy at ComplyAdvantage, was joined by Claude Baksh, Co-founder and President of Grace CSI, to review the Bill C-12’s impact on the PCMLTFA in a recent webinar, which you can watch on demand, and what that means in practice.
What FINTRAC is assessing now
The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) published updated administrative monetary penalty guidance in May 2026, and the basis of assessment moved with it.
“They’re no longer stopping at that evaluation of your written policies and procedures or your training. Now they’re looking at the operational effectiveness. The test is whether your program is achieving the outcomes that it’s expected to achieve based on your institution’s assessed risk profile and risk exposures.”
– Claude Baksh, Co-founder and President of Grace CSI
That’s already visible in the enforcement record. A clear share of penalties issued since March 2026 reflects repeated failures to file suspicious transaction reports (STRs) – cases in which FINTRAC found sufficient evidence to conclude that a report should have been filed in the first place.
FINTRAC is also benchmarking across sectors, using cross-entity data to establish expectations for firms with comparable products and threat exposure. An entity filing fewer STRs than its peers becomes a prospect for examination on that basis alone.
“Your reporting output now serves as direct evidence for or against your program effectiveness.”
– Claude Baksh, Co-founder and President of Grace CSI
The State of Financial Crime 2026, North America edition
For more on how compliance teams across the region are approaching these questions, download The State of Financial Crime 2026, North America edition.
Download nowEffectiveness vs efficiency
A program can run efficiently yet still fail to meet the new effectiveness standard. The two are often confused, but their distinction is critically important.
“You can have an efficient system that delivers garbage versus an effective system.”
– Claude Baksh, Co-founder and President of Grace CSI
The alert backlog is where that distinction bites. A monitoring system that produces more alerts than a team can clear indicates the program is ineffective.
“If you’re overwhelmed with alerts, if you’ve got that huge operational backlog, how can you possibly be effective?”
– Andrew Davies, Global Head of FCC Strategy at ComplyAdvantage
As part of the new effectiveness standard, examiners will usually ask for alerts on cases, cases to STRs, headcount, and overall question the governance around it.
“There are a lot of reporting entities who in the past carried continuous backlogs. Post March 2026, I do not believe that’s an acceptable position to be in.”
– Claude Baksh, Co-founder and President of Grace CSI
Where programs fall short
Our State of Financial Crime 2026 research found 35% of Canadian firms report limitations in their ability to screen customers against sanctions and watchlists, with respondents running an average of more than six separate screening solutions.
Legacy, fragmented platforms are largely a part of the problem. They resist integration and data export, sit behind siloed operations with inconsistent data definitions, and run static rule engines that cannot scale with real-time payment volumes or evolving threat typologies. Configuration compounds it – firms acquire these tools and apply off-the-shelf rules without tailoring them to their specific risk environment, producing noise rather than converting alerts to STRs.
“If we want to follow the money that’s moving instantaneously, either domestically in Canada or around the world, we need to have data and technology that can react at the speed of these financial services.”
– Andrew Davies, Global Head of FCC Strategy at ComplyAdvantage
The solution starts further back than most technology conversations do. Consistent data definitions, reliable capture, and a unified ingestion process come before any recalibration of thresholds against the firm’s risk profile. And a fragmented estate raises a question an examiner can now reasonably ask: can the firm explain why similar products carrying similar risk generate different alert and STR volumes across different systems?
The evidence to have ready
First, to meet FINTRAC’s and auditors’ expectations, firms should demonstrate a thorough, documented risk assessment including all detection scenarios and rules running in production.
Second, firms should fine-tune their records with documented tests and logs that explain why each threshold was adjusted over time, along with a mechanism to adjust them as threat typologies and customer behavior evolve.
Third, firms should keep end-to-end STR trails, walk an examiner through high-priority alerts and show how they converted into filings, and where they did not, why. In short, where models inform those decisions, explainability is the requirement.
“You’ve got to have notes on your files. You can’t just have automated decisions being made without that plain language explanation that’s factual, that you can defend.”
– Claude Baksh, Co-founder and President of Grace CSI
Around that sit model validation, drift management, bias testing, and a human-in-the-loop – which would be expected in any STR filing. Historical model versions also need to be retained and re-runnable, so an examiner can track the basis for a past decision.
Making the business case
Funding this work means widening the frame. Compliance competes for limited budget, and the argument improves when the investment serves objectives beyond AML – fraud detection, emergent risk across business lines, product and market segmentation.
“Don’t only focus on your narrow part of the world that’s tied to your specific role. The underlying principle is one he returned to throughout: “It’s your data as a reporting entity.”
– Claude Baksh, Co-founder and President of Grace CSI
The AML case stands on its own terms too. Accurate risk-based screening reduces false positives and accelerates customer acquisition; less noise frees analysts to focus on genuine risk. Both are also what an effectiveness examination is designed to find.
“Your AML system has historically got a lot of information about your customers and their behavior. Let’s look at that behavior through a different lens, and maybe there’s business opportunity there.”
– Andrew Davies, Global Head of FCC Strategy at ComplyAdvantage
Six months in, the programs best placed are those that can evidence the line from risk assessment to detection scenario to alert to filing, explain every automated decision in language a person can follow, and show what changed when the threat environment did.
Can your AML program evidence its effectiveness?
Under the amended PCMLTFA, FINTRAC expects to see every automated decision explained in plain language. See how ComplyAdvantage helps Canadian firms calibrate screening and monitoring to real risk, and evidence it when an examiner asks.
Request a demoOriginally published 18 September 2026, updated 21 September 2026
Disclaimer: This is for general information only. The information presented does not constitute legal advice. ComplyAdvantage accepts no responsibility for any information contained herein and disclaims and excludes any liability in respect of the contents or for action taken based on this information.
Copyright © 2026 IVXS UK Limited (trading as ComplyAdvantage).
