![]()

Anti-money laundering rules are often discussed as a banking issue, but many businesses outside traditional banking can also face compliance obligations. Money services businesses, payment companies, securities firms, casinos, real estate businesses, dealers in certain goods, and other regulated sectors may need to identify clients, monitor activity, keep records, and report certain transactions.
KYC, or know your customer, is one part of that larger compliance picture. It helps a business understand who it is dealing with, whether a client is acting for someone else, what risk the relationship presents, and whether activity appears consistent with the client’s profile.
For companies operating in Canada and the United States, AML and KYC compliance can become more layered because the legal frameworks are different. A process that works in one country may need to be adjusted when clients, transactions, employees, or operations cross the border.
AML and KYC obligations depend on the business
The first question is whether the business is covered by AML rules. In Canada, obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and related regulations apply to reporting entities. FINTRAC describes these obligations as including compliance programs, client identification, recordkeeping, and reporting certain financial transactions.
In the U.S., AML requirements are largely connected to the Bank Secrecy Act and FinCEN rules. Certain financial institutions and money services businesses are subject to AML program, customer identification, suspicious activity reporting, and related requirements.
That means AML compliance should not start with a template. It should start with classification. A business should determine whether it is covered, which regulator or supervisory body applies, which activities trigger obligations, and whether any state, provincial, federal, or sector-specific rules also apply.
Canada’s framework focuses on reporting entities
In Canada, FINTRAC supervises businesses subject to the federal AML and anti-terrorist financing framework. These reporting entities may have obligations to identify clients, monitor business relationships, keep records, and report certain transactions.
A documented compliance program is a core requirement. FINTRAC guidance states that compliance program requirements apply to all reporting entities under the Act and associated regulations. The program generally involves appointing a compliance officer, developing policies and procedures, assessing risk, training staff, and reviewing the effectiveness of the program.
Money services businesses and foreign money services businesses have added registration issues. FINTRAC states that MSBs and FMSBs must register before beginning to operate in Canada, and MSBs must meet obligations that include registration, reporting, recordkeeping, knowing clients, and having a compliance program.
For businesses, the practical point is that Canadian AML compliance is not only about filing reports. It is about building a repeatable system for identifying clients, assessing risk, documenting decisions, and responding to suspicious activity.
The U.S. framework is tied to the BSA and FinCEN rules
In the United States, the Bank Secrecy Act is a central AML law, and FinCEN administers many of the related rules. The IRS describes the BSA as the first U.S. laws to fight money laundering, with reports used by law enforcement to identify and deter money laundering, terrorism, tax evasion, and other unlawful activity.
Covered U.S. financial institutions may need AML programs that include internal policies, procedures and controls, a designated compliance officer, ongoing employee training, and independent testing. FinCEN’s USA PATRIOT Act summary identifies those minimum AML program elements for financial institutions.
Customer due diligence is also important. FinCEN’s CDD materials explain that covered financial institutions have risk-based procedures for ongoing customer due diligence, including understanding the nature and purpose of customer relationships, monitoring for suspicious transactions, and maintaining and updating customer information on a risk basis.
Businesses should also be careful with beneficial ownership requirements. FinCEN granted 2026 exceptive relief from certain requirements to identify and verify beneficial owners at each new account opening, but covered financial institutions still need to comply with other applicable AML and CFT requirements, including ongoing monitoring and maintaining customer information on a risk basis.
KYC is more than collecting identification
KYC is often misunderstood as simply collecting a passport, driver’s licence, or corporate document.
Identification is important, but KYC is broader. A business may need to understand the client’s identity, ownership, control, source of funds, expected activity, purpose of the relationship, and whether the client presents higher risk.
In Canada, FINTRAC’s ongoing monitoring guidance states that reporting entities must monitor business relationships to detect suspicious transactions that must be reported, keep client identification and beneficial ownership information up to date, and reassess risk based on transactions and activities.
In the U.S., customer identification program rules require certain institutions to use risk-based procedures that allow them to form a reasonable belief that they know the true identity of their customers.
For businesses, the question is not only “Did we collect ID?” It is also “Do we understand the relationship well enough to identify unusual or suspicious activity?”
Beneficial ownership can change the risk picture
Beneficial ownership is a recurring issue in AML and KYC compliance. A company, trust, partnership, or other entity may be acting through layers of ownership or control. A business may need to determine who ultimately owns or controls the customer, who benefits from the transaction, and whether the structure creates higher risk.
FINTRAC guidance states that reporting entities must obtain beneficial ownership information when verifying the identity of an entity under the regulations. FINTRAC has also noted newer requirements tied to consulting Corporations Canada’s database and reporting material discrepancies in certain high-risk circumstances involving corporations incorporated under the Canada Business Corporations Act.
In the U.S., FinCEN’s CDD Rule was designed to strengthen customer due diligence for covered financial institutions, including identifying and verifying beneficial owners of legal entity customers when companies open accounts, subject to later relief and other applicable requirements.
For cross-border businesses, beneficial ownership reviews may need to account for both jurisdictions. A corporate client may be incorporated in one country, operate in another, and be owned through entities in several places.
Risk assessment drives the compliance program
AML and KYC compliance should be risk-based. A small business with limited client types may not need the same controls as a financial institution, payment company, or cross-border money services business. But covered entities still need to understand the risks created by their clients, products, services, geography, delivery channels, and transaction patterns.
FINTRAC guidance states that reporting entities must conduct a risk assessment of money laundering and terrorist financing risks as part of compliance program requirements. It also states that reporting entities remain responsible for the risk assessment obligation even if they use a service provider.
In the U.S., FinCEN materials describe AML programs and customer due diligence as risk-based, including internal controls, ongoing monitoring, and procedures designed to detect and report suspicious activity.
A useful risk assessment should not sit unused. It should influence onboarding, enhanced due diligence, monitoring rules, escalation steps, training, and how often the business reviews client information.
Reporting and recordkeeping are ongoing obligations
AML compliance usually continues after onboarding. In Canada, businesses subject to the PCMLTFA may need to report suspicious transactions, large cash transactions, large virtual currency transactions, international electronic funds transfers, and other reportable activity depending on the business and transaction type.
In the U.S., certain covered financial institutions and MSBs have suspicious activity reporting requirements under the BSA. FinCEN states that certain MSBs must report suspicious activity and file the report through the BSA E-Filing System.
Recordkeeping matters because regulators may ask how a business identified a client, assessed risk, reviewed transactions, escalated concerns, trained staff, or decided whether to file a report. Weak records can make it difficult to show that the compliance program was actually followed.
Cross-border activity can increase compliance risk
Businesses operating between Canada and the U.S. should not assume one AML process covers both countries.
Cross-border activity may raise questions such as:
- which entity is providing the service,
- where the customer is located,
- which regulator applies,
- whether MSB or foreign MSB registration is required,
- how customer identity is verified,
- how beneficial ownership is confirmed,
- which transactions must be reported,
- how records are stored,
- how sanctions screening is handled,
which employees are responsible for escalation.
Sanctions compliance may also be relevant. OFAC’s compliance framework encourages organizations that conduct business in or with the United States, U.S. persons, or U.S.-origin goods or services to use a risk-based approach to sanctions compliance.
For businesses with U.S. and Canadian activity, AML, KYC, sanctions, privacy, and recordkeeping systems should be coordinated rather than treated as separate checklists.
Technology can help, but it does not replace accountability
Many businesses use software for identity verification, sanctions screening, transaction monitoring, case management, and recordkeeping.
Technology can support compliance, but it does not remove responsibility. A business still needs to understand how the tool works, what it checks, when alerts are escalated, how false positives are handled, and whether the process matches the business’s legal obligations.
FINTRAC guidance makes clear that reporting entities remain responsible for meeting risk assessment obligations even if a service provider is used.
A vendor can help perform tasks. It cannot decide the business’s legal obligations, risk tolerance, or escalation duties without proper oversight.
AML and KYC should be reviewed as the business changes
A compliance program may become outdated as the business grows. New products, new payment methods, virtual currency activity, cross-border customers, new investors, acquisitions, high-risk geographies, and changes in law can all affect AML and KYC obligations.
Regular reviews can help identify whether policies still match the business. They can also test whether staff are following procedures, whether alerts are being handled properly, and whether records are complete.
In Canada, FINTRAC’s compliance program guidance includes a review of the effectiveness of the compliance program as part of the compliance framework for reporting entities.
In the U.S., FinCEN materials refer to independent testing as part of AML program expectations for covered institutions and MSBs.
Compliance should fit the business, not a generic checklist
AML and KYC compliance should be practical, documented, and tailored. For covered businesses, the core questions are whether the business knows who it is dealing with, understands the risks, monitors activity, keeps appropriate records, and reports when required.
For cross-border businesses, the questions go further. The business may need to coordinate Canadian and U.S. obligations, identify which entity is responsible, align policies across jurisdictions, and make sure staff know when to escalate concerns.
A strong compliance program does not guarantee that every risk disappears. It does help a business show that it has a structured process for identifying risk, making decisions, and meeting legal obligations.
For businesses reviewing AML and KYC responsibilities in Canada, the U.S., or both, the next step is to understand which rules apply and whether current policies match the way the business actually operates.
For guidance on AML and KYC compliance, corporate governance, contracts, and cross-border business matters, explore Pace Law Firm’s Corporate and Commercial guidance to learn more.
Pace Law Firm
191 The West Mall
Suite 1100
Toronto
ON
M9C 5L6
Canada