- Home
- »
- Services
- »
- AML Compliance
- »
- AML Risk Assessment
AML Risk Assessment for Canadian Reporting Entities
Your risk assessment is the document that justifies every control you run. We build a defensible ML and TF risk assessment FINTRAC accepts, tailored to the products, clients, and geographies your business actually touches.
The Risk Assessment FINTRAC Expects to See
Every reporting entity must assess its money laundering and terrorist financing risks in writing. FINTRAC does not dictate a method, which is why so many assessments are too generic to survive examination. We build yours around your real risk factors and document the reasoning behind every rating.
From Inherent Risk to Residual Risk
A credible assessment does more than list risks. We rate your inherent risk across products, delivery channels, geographies, and clients, apply your mitigating controls, then measure the residual risk that remains against your stated risk tolerance. Where residual risk sits too high, we show exactly which controls must strengthen and why.
Risk Identification
We identify your money laundering and terrorist financing risks across every required factor.
Risk Rating
We build the methodology and matrix that rate your clients, products, and geographies consistently.
Control Mapping
We connect each risk to the mitigating control that reduces it to an acceptable level.
Assessment Review
We refresh your assessment as your business, products, and the regulations evolve.
Ready to Simplify Your Compliance?
Businesses We Help Assess
We build risk assessments for money services businesses, payment service providers, cryptocurrency platforms, currency exchanges, real estate firms, and the many other reporting entities that carry obligations under the PCMLTFA.
We support banks with program design, oversight, & regulatory examination readiness.
We help credit unions meet obligations proportionate to their membership and scale.
We handle registration, renewals, reporting, & controls FINTRAC expects from you.
We cover Bank of Canada registration alongside your anti money laundering obligations.
We establish what your wallet activity triggers, then build only what applies.
We build compliance around what your product does, before volumes and questions arrive.
We register virtual currency dealers and build the reporting their activity demands.
We support financial institutions across registration, program build, and reporting duties.
Why Businesses Choose Our Assessments
National Grounding
We build on the National Risk Assessment, which FINTRAC expects reporting entities to use as foundational input to their own.
Defensible Ratings
Every rating is documented and repeatable, so you can explain to an examiner exactly how each conclusion was reached.
Genuinely Specific
A template rates every business identically, which is precisely what examiners look for and immediately distrust.
Serving Businesses Across Canada
We build AML risk assessments right across Canada, from Toronto and Montreal through to Vancouver and Calgary, and for foreign reporting entities that carry Canadian obligations wherever they operate from.
Let's Talk About Your Compliance Needs
Schedule a Free Consultation
Whether you’re starting a new MSB or need ongoing AML support, our team responds within one business day.














Risk Assessment Questions
Clear answers to the questions Canadian businesses ask most about building a defensible ML and TF risk assessment under the PCMLTFA and FINTRAC expectations.
Is a risk assessment legally required?
Yes. The PCMLTFA requires every reporting entity to assess and document its money laundering and terrorist financing risks as part of its program.
What factors must it cover?
Your products and services, your delivery channels, the geographies you operate in, your clients and business relationships, and other factors relevant to your business.
What exactly is residual risk?
The risk that remains after your controls are applied. FINTRAC expects it to sit within your stated risk tolerance, or your controls need strengthening.
How often must it be reviewed?
At least every two years through your effectiveness review, and sooner whenever you launch new products or your business changes materially.
Can we use a risk assessment template?
Templates rarely satisfy examiners. FINTRAC expects an assessment that reflects your specific business, and generic ratings are a common source of findings.











