FINTRAC Foreign Branch Rules: Canada’s Extraterritorial AML Reach

A Canadian bank with a branch in Singapore falls within section 9.7; a life insurance company’s foreign subsidiary is covered only if it carries out similar activities and is wholly owned or consolidated with the company; and a securities dealer’s affiliated London entity can trigger section 9.8 if the statutory affiliation test is met. Canada’s anti-money-laundering rules travel with them. Since 1 June 2021, FINTRAC’s guidance on foreign branches, foreign subsidiaries and affiliates has set out how the Proceeds of Crime (Money Laundering) and Terrorist Financing Act reaches operations sitting well outside Canadian soil.

The FINTRAC foreign branches and subsidiaries requirements live in sections 9.7 and 9.8 of the Act, known in practice as the PCMLTFA. They bind three reporting-entity types and no others: financial entities, life insurance companies and securities dealers. Where you are in scope, the Act requires you to develop group policies that carry your Canadian record-keeping, client-identification and compliance-program controls into your foreign operations, have your board approve them, and apply them to the extent the local law allows.

The obligation is a policy, record-keeping and conditional-notification one that sits inside your compliance program, which means it also falls inside the two-year effectiveness review FINTRAC expects you to run. Get the structure wrong and it surfaces as a compliance deficiency at examination, not as a rejected return.

Related reading: AMLR: What Changes for Luxembourg

The obligations at a glance

Before the detail, the short version a reporting officer can pin to the wall:

  • Guidance in force since 1 June 2021, published March 2021 by FINTRAC.
  • In scope: financial entities, life insurance companies, securities dealers.
  • Covered operations: your foreign branches, and foreign subsidiaries that carry out similar activities and are wholly owned by you or consolidated with your financial statements.
  • Policies must mirror your own PCMLTFA duties for record keeping, client identification and your compliance program, and the board must approve them.
  • Apply the policies wherever the foreign state’s law permits and does not conflict.
  • Where a foreign law blocks a policy, keep a record of that fact and the reasons, and retain it for at least five years.
  • Notify both FINTRAC and your principal supervisor, within a reasonable time, of any such conflict.
  • Affiliates trigger a separate duty: policies and procedures for exchanging information to detect, deter and assess money-laundering and terrorist-financing risk.

Where the FINTRAC foreign branches and subsidiaries obligation comes from

The legal anchor is section 9.7(1) of the PCMLTFA. It requires an entity to develop policies that establish requirements similar to its own obligations under sections 6, 6.1 and 9.6 of the Act. Those three cross-references are the spine of the whole regime. Section 6 is record keeping, section 6.1 is verifying client identity, and section 9.6 is the compliance program. Read together, they say a Canadian reporting entity cannot run a lighter AML standard abroad than the one it runs at home simply because the branch or subsidiary is offshore.

Section 9.7(2) adds a governance step that teams often treat as an afterthought. If you have a board of directors, the board has to approve the foreign-branch and foreign-subsidiary policies before they are applied. A policy drafted by the compliance function and quietly slotted into the manual does not satisfy the Act. Section 9.7(2) requires the board to approve the policies before they are applied. Retaining dated evidence of that approval is a prudent control: FINTRAC examinations assess the implementation of section 9.7 policies, and board approval is a statutory precondition under section 9.7(2).

Section 9.7(4) then covers the record and the notification that follow when local law gets in the way, and section 9.8 handles affiliates. FINTRAC’s guidance ties the individual duties back to these statutory hooks, and each requirement in the guidance carries a footnote to the exact subsection. When you are reconstructing your control framework, cite the exact subsection: the guidance is FINTRAC’s reading of the Act, and the Act is what binds you.

Who is actually in scope, and who quietly falls out

The scope line is narrower than the phrase “Canadian financial institutions” suggests. Only financial entities, life insurance companies and securities dealers carry the section 9.7 and 9.8 duties. Money services businesses, real estate brokers, dealers in precious metals and stones, accountants and casinos are all reporting entities under the PCMLTFA, yet none of them sit inside the foreign-branch and affiliate regime. If your group spans several business lines, the obligation attaches only to the parts that are financial entities, insurers or dealers.

The subsidiary test is where the misreadings start. Your foreign branches are covered outright, because a branch is part of the same legal entity. A foreign subsidiary is only pulled in when two conditions are met together: it carries out activities similar to those of a financial entity, life insurance company or securities dealer, and it is either wholly owned by you or its financial statements are consolidated with yours. A minority stake in a foreign fintech that you do not consolidate does not, on its own, trigger the section 9.7 policy duty for that entity.

That consolidation limb matters more than the ownership limb for large groups. A foreign subsidiary that is majority but not wholly owned still lands in scope if you consolidate it. So the accounting boundary often decides which offshore entities your AML policies have to reach, more than any bright-line ownership percentage. Map the obligation off your consolidation scope first, then check ownership, and you will catch the entities a pure ownership screen misses.

The three control areas your foreign policies must mirror

Section 9.7(1) requires the policies to establish requirements similar to sections 6, 6.1 and 9.6: record keeping and retention, client identification, and the compliance program. The current section 9.6 also requires the program to be reasonably designed, risk-based and effective, in addition to its risk-assessment and high-risk special-measures elements. FINTRAC’s March 2021 guidance predates the addition of section 9.6(1.1), so the current Act must govern the policy build.

The word doing the heavy lifting is “similar”. Section 9.7 requires your Cayman subsidiary to operate under policies that establish requirements similar to your Canadian record-keeping, identity and compliance-program obligations; the result is a local control standard backed by a governance line to the Canadian parent, with no Canadian large-cash-transaction reports filed offshore under this regime.

This is the point where a compliance team can under-build or over-build. Under-building looks like a one-page group statement that gestures at “high standards” without the record-keeping and client-identification specifics the three areas demand. Over-building looks like an attempt to run verbatim Canadian reporting thresholds in a jurisdiction with its own reporting architecture, which creates conflicts you then have to document. The Act requires policies that establish requirements similar to sections 6, 6.1 and 9.6, board approval before application, and application to the extent permitted by and not conflicting with local law.

Apply where local law permits: the conflict-of-laws safety valve

Section 9.7(1) does not demand the impossible. It requires you to ensure your foreign branches and subsidiaries apply the policies to the extent permitted by, and not conflicting with, the laws of the foreign state where the branch or subsidiary sits. That clause is the safety valve. A data-protection or bank-secrecy rule abroad that blocks a Canadian-style identification or record-keeping step does not put you in breach, provided you handle the conflict the way the Act prescribes.

Handling it has two moving parts. First, under section 9.7(4), where a foreign branch or subsidiary cannot apply a policy because local law does not permit it or would conflict with it, you keep a record of that fact and of the reasons why. Second, that record has a retention period. The Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations require you to keep foreign branch and subsidiary records for at least five years following the date they were created, under section 148(1)(c).

Teams sometimes treat the safety valve as a general escape hatch; the provision has a narrower reach. The exception is limited to a policy whose application foreign law does not permit or with which it would conflict. The entity must still apply the policies to the extent permitted by and not conflicting with local law. A useful discipline is a conflict register that names the entity, the blocked control, the local legal basis for the block, and the date the conflict was identified, so the five-year clock and the notification trail both start from something concrete.

The one thing you actually notify: FINTRAC and your supervisor

Here is the part that is genuinely a filing, and the part most easily missed. Section 9.7(4) requires that where the laws of a foreign state do not permit or conflict with a policy you developed for a foreign branch or subsidiary, you notify, within a reasonable time period, both FINTRAC and the principal agency or body that supervises or regulates your sector under federal or provincial law. The notification states the fact of the conflict and the reasons for it.

Two features are worth holding onto. The notification is dual-addressed. FINTRAC alone is not enough. Your prudential or sectoral supervisor has to receive it too, which for a federally regulated bank or insurer means the relevant federal supervisor, and for a provincially regulated dealer means the provincial body. The other feature is that this is event-driven: the trigger is a legal conflict, and the obligation is to notify FINTRAC and the principal supervisor within a reasonable time.

Because the notification is conditional, groups with a stable footprint can go long stretches without ever sending one, which is exactly why the process atrophies. The failure mode is a conflict that a local team quietly worked around, that never reached the group compliance officer, and therefore never reached FINTRAC or the supervisor. Building the escalation path from the foreign entity up to the notification is the operational heart of this obligation.

Affiliates and the information-sharing duty

Section 9.8 runs on a separate track from the branch and subsidiary rules, and it is easy to overlook. It requires a financial entity, life insurance company or securities dealer to develop and apply policies and procedures for exchanging information with entities it is affiliated with, where those affiliates carry out activities similar to a financial entity, insurer or dealer. The trigger is affiliation, so the duty applies whether or not the entity runs foreign operations. The purpose the Act states is to help detect and deter money-laundering and terrorist-financing offences, and to help assess the risk of such an offence occurring.

Affiliation has a precise statutory meaning under section 9.8(2). You are affiliated with another entity when one of you is wholly owned by the other, when both of you are wholly owned by the same entity, or when your financial statements are consolidated. That is the same wholly-owned-or-consolidated logic that governs the subsidiary test, which is a small mercy for anyone building both scopes off one group structure diagram.

The compliance-program link closes the loop. Under the Regulations, at section 156(1)(c)(iv), your compliance program has to assess the risks that arise from the activities of your affiliates. So affiliates generate two things: an information-sharing framework under section 9.8, and a risk-assessment input into the program under section 156. One point of modality is worth keeping straight. FINTRAC frames the keeping of a record where an affiliate cannot implement the information-sharing policies as a best practice, rather than as a hard statutory record-keeping requirement. Treat it as strongly advisable, and do not overstate it as a legal must in your own manual.

The exemptions, read carefully

The section 9.7 policy duty carries a set of carve-outs, and reading them loosely is a common way to either miss an obligation or claim relief you do not have. The requirement to develop foreign-branch and foreign-subsidiary policies does not apply to authorized foreign banks within the meaning of section 2 of the Bank Act, to departments or Crown agents that accept deposit liabilities, to foreign companies within the meaning of section 2 of the Insurance Companies Act, or to life insurance brokers and agents. An authorized foreign bank operating in Canada is the inbound branch of a foreign bank, so Canada does not ask it to build outbound policies for the parent’s own network.

Two structural exemptions matter for group design. Under section 9.7(3)(a), a reporting entity that is itself a subsidiary of another reporting entity, where that parent already has the obligation to develop these policies, does not separately develop them. Under section 9.7(3)(b), a reporting entity that is a subsidiary of a foreign entity is exempt where the foreign parent has developed policies for its subsidiaries that establish requirements similar to the PCMLTFA record-keeping, identity-verification and compliance-program duties, and the Canadian subsidiary applies those policies to the extent permitted by, and not conflicting with, the laws of Canada or its provinces.

The FINTRAC guidance gives the worked example. Where Foreign Bank A already has policies on client identification, record keeping and a compliance program, and its Canadian subsidiaries apply them consistently with Canadian law, the foreign-branch and subsidiary requirement does not separately apply to those Canadian subsidiaries. The affiliate duty under section 9.8 has its own, shorter carve-out list: it does not apply to Crown deposit-taking departments and agents, or to life insurance brokers and agents. Do not assume the section 9.7 exemption list and the section 9.8 exemption list are identical, because they are not.

How this maps to FATF Recommendation 18 and the EU AMLR

For a compliance team that already runs a European or global AML framework, the fastest way to internalise the Canadian regime is to see its parentage. Sections 9.7 and 9.8 address the same subject matter as FATF Recommendation 18, “Internal controls and foreign branches and subsidiaries”. Recommendation 18 asks financial groups to run group-wide programmes against money laundering and terrorist financing, to ensure foreign branches and majority-owned subsidiaries apply AML/CFT measures consistent with home-country requirements, to share information within the group, and, where the host country does not permit proper implementation, to apply additional measures and inform the home supervisor. Our coverage of FATF’s work on Recommendation 16 shows how the same standard-setter drives cross-border transfer-information rules through a different recommendation.

Regulation (EU) 2024/1624 will apply from 10 July 2027 for most obliged entities. Article 16 will require parent undertakings to establish and implement group-wide policies, procedures and controls, including information-sharing controls covering customer identity and characteristics, beneficial ownership, the nature and purpose of business relationships and occasional transactions, and suspicions reported to the financial intelligence unit with the underlying analyses. Articles 16(4) and 17(3) required AMLA to develop and submit draft regulatory technical standards by 10 July 2026. AMLA consulted on a combined draft from 16 April to 15 June 2026; its consultation page states that the consultation is closed and that results will follow. Our explainer on what the AMLR changes for Luxembourg obliged entities walks through the wider group-wide obligations.

The differences are where cross-border teams get caught. Canada’s subsidiary and affiliate tests turn on wholly owned or consolidated status. FATF Recommendation 18 refers to majority-owned subsidiaries, whereas Articles 16 and 17 of Regulation (EU) 2024/1624 apply to branches and subsidiaries within the group and do not use a majority-owned threshold. A majority-owned foreign subsidiary that a group does not consolidate can sit inside a FATF-aligned group-wide programme yet fall outside Canada’s strict section 9.7 policy trigger, and the reverse can also happen. A team that maps its Canadian scope straight off its European group-wide policy will over-include or under-include entities unless it re-runs the wholly-owned-or-consolidated test on Canadian terms. For the supervisory-cooperation angle behind these cross-border frameworks, see our note on the AMLA home-host supervisory cooperation RTS.

Building the workflow for a cross-border compliance team

Turning sections 9.7 and 9.8 into a working control set follows a fairly stable sequence. Start from the group structure and consolidation scope, and tag every foreign branch, every wholly-owned or consolidated foreign subsidiary carrying out similar activities, and every affiliate that meets the section 9.8(2) test. Draft the group policies against the three control areas, then take them through board approval and record the date. Push the policies down to each in-scope entity, and require local confirmation that they are applied to the extent local law permits.

Then build the exception machinery, because that is what examinations probe. Maintain the conflict register, run the five-year retention clock on each conflict record from its creation date, and wire an escalation path so a local legal block reaches the group compliance officer and converts into the dual notification to FINTRAC and the supervisor. Feed affiliate activity into the compliance-program risk assessment under section 156, and fold the whole framework into the two-year effectiveness review so an independent tester checks that the policies exist, were approved, and are actually applied. Groups that already file AML/CFT reporting in other jurisdictions will find the muscle memory transfers, provided they do not assume the Canadian scope tests are the same as their home ones.

One caution on enforcement framing. These are enumerated obligations that FINTRAC assesses in its compliance examinations, and non-compliance with PCMLTFA obligations can attract administrative monetary penalties under the Act. Beyond that, the level of any given penalty is a matter for FINTRAC’s own process and published methodology, and speculating on outcomes for a specific gap is not something a control framework should do. The framework’s job is to make the obligation demonstrable: policies drafted, board-approved, applied where lawful, conflicts recorded and reported. For a sense of how cross-border AML supervision is trending elsewhere, our read of the AUSTRAC 2026 financial-crime risk snapshot tracks a parallel regulator’s priorities.

Frequently Asked Questions

Does FINTRAC require my foreign branch to file Canadian reports directly to FINTRAC?

The section 9.7 duty is to develop and apply group policies that establish requirements similar to your Canadian record-keeping, client-identification and compliance-program obligations at the foreign branch or subsidiary. The only filing this regime generates is the event-driven conflict notification when a foreign law blocks a specific policy, sent to both FINTRAC and your principal supervisor.

Is a majority-owned but not wholly-owned foreign subsidiary in scope?

It depends on consolidation. Section 9.7(1) captures a foreign subsidiary that carries out similar activities and is either wholly owned by you or has consolidated financial statements with you. A majority stake that you consolidate is in scope through the consolidation limb. A majority stake you do not consolidate is not caught by the wholly-owned limb alone.

What exactly do we keep when a foreign law prevents a policy?

Under section 9.7(4) you keep a record of the fact that the branch or subsidiary cannot apply the policy, and of the reasons why the local law does not permit it or would conflict with it. Under section 148(1)(c) of the Regulations, that record is retained for at least five years from the date it was created.

Who counts as the “principal agency or body” we notify alongside FINTRAC?

It is the agency that supervises or regulates your sector under federal or provincial law. For a federally regulated bank or insurer that is the relevant federal prudential supervisor, and for a provincially regulated securities dealer it is the applicable provincial regulator. FINTRAC and that supervisor both have to be notified within a reasonable time.

How is the affiliate duty different from the foreign-branch duty?

The foreign-branch and subsidiary duty under section 9.7 is about extending your own AML controls to operations you own or consolidate abroad. The affiliate duty under section 9.8 is about information sharing between you and entities you are affiliated with, so the two of you can better detect, deter and assess money-laundering and terrorist-financing risk. Affiliation is defined by wholly-owned or consolidated status under section 9.8(2).

We are the Canadian subsidiary of a foreign bank. Do we build our own foreign-branch policies?

Often not. Section 9.7(3)(b) exempts a reporting entity that is a subsidiary of a foreign entity where the foreign parent has developed policies for its subsidiaries establishing requirements similar to the PCMLTFA record-keeping, identity and compliance-program duties, and you apply those policies to the extent permitted by and not conflicting with Canadian and provincial law. Confirm the parent’s policies genuinely meet that standard before relying on the exemption.

Does this obligation sit inside our compliance program and its effectiveness review?

Yes. The foreign-branch, subsidiary and affiliate policies form part of your compliance program, and affiliate risk feeds the program’s risk assessment under section 156(1)(c)(iv). That means the framework is within the scope of the two-year effectiveness review, and an independent tester should be checking that the policies exist, were board-approved and are applied.

Key Takeaways

  • FINTRAC’s guidance on foreign branches, foreign subsidiaries and affiliates came into effect on 1 June 2021. The binding duties are in PCMLTFA sections 9.7 and 9.8 and apply to financial entities, life insurance companies and securities dealers, subject to the statutory exclusions and exemptions.
  • In-scope entities develop board-approved policies that mirror their own record-keeping, client-identification and compliance-program duties for foreign branches and for wholly-owned or consolidated foreign subsidiaries carrying out similar activities.
  • The policies apply to the extent permitted by, and not conflicting with, the foreign state’s law, and every blocked policy needs a record of the fact and reasons.
  • Conflict records are retained for at least five years under Regulations section 148(1)(c), and a legal conflict must be notified to both FINTRAC and the sector’s principal supervisor within a reasonable time.
  • This regime creates no periodic foreign-branch return; the only filing is the event-driven conflict notification.
  • Affiliates trigger a separate section 9.8 duty to develop information-sharing policies, with affiliate risk assessed in the compliance program under section 156(1)(c)(iv).
  • Canada’s wholly-owned-or-consolidated scope tests differ from FATF Recommendation 18’s majority-owned language and from the EU AMLR’s group-based scope, so re-run the scope on Canadian terms rather than copying another jurisdiction’s group-wide policy.

Sources and References

Treat Canada’s border as a control boundary, not a control end

The practical mistake sections 9.7 and 9.8 are built to prevent is the assumption that AML obligations stop at the Canadian border. For an in-scope financial entity, life insurance company or securities dealer, section 9.7 applies to its foreign branches and to foreign subsidiaries that carry out similar activities and are wholly owned or consolidated with it, subject to the statutory exclusions and exemptions. The entity must apply the required policies to those operations to the extent permitted by, and not conflicting with, local law; board approval is required before application, and any legal conflict must be recorded and notified within a reasonable time. Build that once, wire it into the compliance program, and the two-year effectiveness review stops being the moment you discover the gaps.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • Sweden Periodic AML Reporting: Preparing for FI’s Updates

    Updated July 2026In this guidePeriodic AML reporting Sweden: what FI has confirmed for 2027Who must file the Swedish periodic AML reportWhere the new questions come from: the EU common risk methodologyDates to watch for your periodic AML filingFiling through FIDAC, and the EBA taxonomy splitWhat the report is really for: risk-based supervisionHow periodic reporting fits…

  • AML Reporting in Luxembourg: STRs, GoAML, and Your Obligations

    Updated July 2026In this guideIntroductionThe Legal Basis for AML Reporting in LuxembourgWho Must Report? Obliged Entities and ScopeSuspicious Transaction Reports: What Triggers Reporting?Filing Suspicious Transaction Reports: The ProcessOther AML Reporting Obligations Beyond STRsThe CRF: Luxembourg’s Financial Intelligence UnitHow AML Reporting Works in PracticeCommon AML Reporting MistakesRecent Developments: AMLA, the AMLR, and the Single RulebookComing Soon:…

  • CSSF AML/CFT Sanction: Enforcement Lessons From the March 2026 Fine

    Updated July 2026In this guideWhat the CSSF AML/CFT sanction actually coveredLate and incomplete suspicious activity reportsThe client-portfolio takeover trapName screening, sanctions and PEP alert backlogsOutsourced screening and the four-eyes gapDatabase completeness is an AML control, not IT housekeepingHow supervisors surface these gaps before an inspectionFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesReading the sanction as a…

  • AMLR – What Changes for Luxembourg Firms Under the New EU AML Regulation

    Updated July 2026In this guideThe AML Package: Four Instruments, One FrameworkApplication TimelineExpanded Scope of Obliged EntitiesCustomer Due Diligence: What ChangesPolitically Exposed Persons: Harmonized FrameworkSuspicious Transaction ReportingInternal Controls and Compliance FunctionAMLA: What It Means for LuxembourgLuxembourg-Specific ConsiderationsPreparing Now: Practical StepsFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesYour compliance team has spent years building its AML framework around…

  • Regulation 2026/1779: Screening the New EU Sanctions Listings

    On 17 July 2026 the Council of the European Union adopted Council Implementing Regulation (EU) 2026/1779, which amends Annex I to Regulation (EU) No 269/2014 and adds six new designations to the EU list of persons and entities subject to an asset freeze over the situation in Ukraine. The measure entered into force on the…