FINTRAC Correspondent Banking Requirements: A Canadian Compliance Guide

Canada’s anti-money laundering regime draws one line for correspondent banking that leaves no room for a risk-based judgment call. Under subsection 9.4(2) of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, no person or entity may have a correspondent banking relationship with a shell bank. FINTRAC’s correspondent banking guidance explains the pre-entry, record-keeping and monitoring duties that apply when an in-scope Canadian financial entity enters into a correspondent banking relationship with a prescribed foreign financial institution.

The obligations live inside the compliance program a financial entity already runs, and they are specific. Senior management has to approve the relationship. The arrangement has to be set out in writing. The foreign institution’s identity and its money laundering and terrorist activity financing standing have to be assessed before transactions flow. A defined set of records has to survive for five years after the last business transaction. Failing to complete a statutory pre-entry measure before entering the relationship creates a compliance breach risk.

Related reading: supervisory expectations on de-risking and ML/FT risk management.

Who the correspondent banking rules actually bind

The requirement attaches to financial entities, and only when one of them enters into a correspondent banking relationship. FINTRAC lists the entities caught: banks, cooperative credit societies, credit unions and caisses populaires, federally or provincially regulated trust or loan companies, unregulated trust companies, financial services cooperatives, certain life insurance companies and brokers or agents that offer loans or prepaid payment products, a credit union central when it serves non-members, an agent of the Crown accepting deposit liabilities, and loan companies regulated by a provincial Act. The statutory hook is paragraphs 5(a), (b), (d), (e), (e.1) and (f) of the Act, read with section 16(1) of the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations.

A single distinction changes whether the regime applies at all: the relationship has to fit the prescribed definition, and the counterparty has to be a prescribed foreign financial institution. A cross-border payment, an occasional wire to a foreign bank, or a vendor arrangement is not automatically a correspondent banking relationship. The rules apply where a Canadian financial entity enters into an agreement or arrangement to provide a prescribed foreign financial institution with prescribed services, or with international electronic funds transfers, cash management or cheque clearing services.

What counts as a correspondent banking relationship

Subsection 9.4(3) of the Act defines the relationship as one created by an agreement or arrangement under which a listed entity undertakes to provide a prescribed foreign entity with prescribed services, or international electronic funds transfers, cash management or cheque clearing services. Section 16(1)(b) of the Regulations supplies the prescribed-foreign-entity limb. The trigger is the agreement itself, so the analysis starts at the point a Canadian entity commits to provide those services, ahead of the first transaction that runs across them.

That framing matters for perimeter decisions. An arrangement sits outside subsection 9.4(3) only if it does not undertake to provide the foreign financial institution with prescribed services, international electronic funds transfers, cash management or cheque clearing services; the number of payments or the domestic character of a payment is not, by itself, the statutory test. As a perimeter control, the correspondent banking file should document which service class supports the scope conclusion, because the same counterparty can be in scope for one product and out of scope for another.

The one counterparty the Act forbids outright

Section 9.4 of the Act does two things a risk-based program cannot soften. Subsection 9.4(1) requires the pre-onboarding measures set out in the regulations. Subsection 9.4(2) prohibits the relationship outright where the counterparty is a shell bank. There is no enhanced-monitoring workaround and no senior-sign-off exception: if the foreign institution is a shell bank, the relationship may not be entered into.

The Regulations define a shell bank as a foreign financial institution that does not have a place of business at a fixed address in a country where it is authorised to conduct banking activities, employs one or more persons there on a full-time basis, maintains operating records related to its banking activities and is subject to inspection by the licensing authority, and that is not controlled by, or under common control with, a depository institution, credit union or foreign financial institution that maintains such a place of business in Canada or a foreign country. The financial entity must separately ensure that the foreign institution is not itself a shell bank. In addition, subsection 16(2) of the Regulations requires a written statement that the foreign institution does not have, directly or indirectly, a correspondent banking relationship with a shell bank; that statement addresses direct and nested shell-bank relationships.

What the regulations require before onboarding

Before entering the relationship, a financial entity must obtain prescribed information about the foreign institution and its activities, ensure that the institution is not a shell bank, obtain senior-management approval, and set out in writing the parties’ obligations for the correspondent banking services. When it enters the relationship, it must also keep the records required by subsection 16(2) of the Regulations and carry out the applicable verification, assessment and monitoring measures in sections 16, 90 and 91.

Senior-management approval and the written allocation of the parties’ obligations are pre-entry requirements under subsection 9.4(1) of the Act. Identity verification, the subsection 16(2) records and the additional due-diligence measures are separate requirements that apply when the relationship is entered.

Verifying identity and assessing the foreign institution

The verification set is concrete. A financial entity has to confirm the foreign institution’s name and address by examining its banking licence, banking charter, an authorisation or certification to operate issued by the competent authority in its jurisdiction of incorporation, its certificate of incorporation, or a similar document. On top of identity, the entity has to take reasonable measures, using publicly available information, to check whether civil or criminal penalties have been imposed on the institution for breaching AML or ATF requirements, to assess the institution’s compliance reputation, and to assess the quality of AML/ATF supervision in the jurisdictions where it is incorporated and where it transacts. It also has to take reasonable measures to determine the nature of the institution’s clientele and markets, and to ascertain whether the institution has AML/ATF policies and procedures in place, including procedures for approving new accounts.

Reasonable measures is a defined standard, and it is worth being precise about what it does not demand. FINTRAC describes reasonable measures as steps taken to achieve an outcome even where they do not achieve it: asking the counterparty, running open-source searches, retrieving information already held, or consulting commercially available sources. The obligation is to take the reasonable measures, not to guarantee the desired outcome; records of those measures and their results are required where subsection 16(2) expressly prescribes them. Two of these enquiries carry a consequence when the answer is adverse or unavailable. Where penalties have been imposed, the entity must monitor all transactions in the relationship to detect reportable suspicious transactions. Where reasonable measures to ascertain the institution’s AML/ATF policies are unsuccessful, or those policies are not in place, the entity must take reasonable measures to monitor all transactions conducted in the relationship.

Building FINTRAC’s correspondent banking requirements into policies and monitoring

Correspondent banking is not a standalone regime bolted onto the side of the compliance program. FINTRAC requires that, as part of the risk assessment within the compliance program, a financial entity assess and document the money laundering and terrorist activity financing risks tied to its correspondent banking relationships. That means the entity must assess and document the ML/TF risks related to its correspondent banking relationships and conduct periodic monitoring at a frequency appropriate to the assessed risk.

This is where correspondent banking connects to the wider financial-crime picture supervisors keep flagging, from typology work such as AUSTRAC’s 2026 financial crime risk snapshot to the cross-border transparency debate around the FATF Recommendation 16 travel rule. A documented risk assessment provides an evidence base for the firm’s monitoring and relationship-management decisions.

Ongoing monitoring at a frequency set by risk

Once the relationship is live, the entity has to conduct ongoing monitoring periodically, at a frequency appropriate to the level of risk in its risk assessment. The stated purposes are to detect suspicious transactions that must be reported to FINTRAC, to keep the onboarding information current, to confirm the foreign institution maintains appropriate AML/ATF measures, to reassess the risk level of the institution’s transactions, and to confirm those transactions are consistent with what the entity knows about the institution and with its risk assessment.

The periodic, risk-scaled monitoring is the default. It is distinct from the all-transactions monitoring that the penalty trigger and the missing-policies trigger switch on. A file can therefore carry two monitoring standards at once: periodic monitoring at a frequency appropriate to risk, and all-transactions monitoring where a penalty has been imposed; where AML/ATF policies cannot be confirmed or are not in place, the entity must take reasonable measures to monitor all transactions. When monitoring identifies a transaction that meets the reporting threshold under section 7 of the Act, the financial entity must submit the applicable report to FINTRAC. Copies of Suspicious Transaction Reports and Listed Person or Entity Property Reports filed as a result of the relationship must be retained under the applicable report-retention rules.

Records to keep, and for how long

The record set is prescriptive. For the enquiries identified in subsection 16(2), the financial entity must retain a record of the measures taken and, where specified, the results of those measures. A financial entity has to keep the foreign institution’s name, address, primary business line and directors; its most recent annual report or audited financial statement; a copy of the banking licence, charter, authorisation or certificate of incorporation; the correspondent banking agreement or product agreements defining each side’s responsibilities; a record of the anticipated account activity and the products or services to be used; the written statement that the institution has no direct or indirect correspondent relationship with a shell bank; the written statement that it complies with AML and ATF legislation in every jurisdiction where it operates; a record of the measures taken to determine clientele and markets; and a record of the measures taken, with their results, to check for penalties, to assess compliance reputation, and to assess the quality of supervision in the relevant jurisdictions. Every suspicious transaction report and Listed Person or Entity Property Report filed as a result of the relationship also has to be retained.

Records required by subsection 16(2) of the Regulations must be kept for at least five years after the day of the last business transaction, under paragraph 148(1)(b). Copies of Suspicious Transaction Reports and Listed Person or Entity Property Reports follow a separate clock: they must be kept for at least five years after the day the report is sent, under section 12.1 of the Suspicious Transaction Reporting Regulations.

Direct-access clients and the narrow credit-card carve-out

Two situations sit at the edge of the regime. Where a client of the foreign institution has direct access to the services the Canadian entity provides, section 91 of the Regulations requires reasonable measures to verify that the foreign institution has met client-identification requirements consistent with the Canadian entity’s own, and has agreed to hand over relevant client-identification information on request. This is how the regime reaches through to end clients the Canadian entity never onboards directly.

The carve-out points the other way, and it is narrow. For processing payments by credit card or prepaid payment product for a merchant, several duties do not apply: keeping the correspondent banking records, ascertaining whether the institution has AML/ATF policies and procedures, and conducting the periodic ongoing monitoring. A financial entity also does not have to keep account-opening and transaction records beyond what the guidance itself specifies. The exception is tied to that specific merchant-processing activity under sections 16 and 150 of the Regulations, so reading it as a general exemption for card-linked relationships is a misread that leaves the rest of the framework unaddressed.

Frequently Asked Questions

Does the correspondent banking requirement apply to a relationship with a foreign money services business, or only to a foreign bank?

For the section 9.4 due-diligence requirements, the counterparty must be a prescribed foreign entity, which paragraph 16(1)(b) of the Regulations identifies as a foreign financial institution, and the Canadian entity must provide one of the services identified in subsection 9.4(3) of the Act. A foreign money services business is a separate statutory category and is not automatically a foreign financial institution. However, subsection 9.31(1) of the Act separately prohibits an in-scope financial entity from opening or maintaining an account for, or having a correspondent banking relationship with, a foreign money services business unless it is registered with FINTRAC.

We already have a live relationship and the foreign institution is later penalised for an AML breach. What changes?

The penalty trigger applies on an ongoing basis, well beyond onboarding. Once reasonable measures show that civil or criminal penalties have been imposed for AML or ATF failures, the entity must monitor all transactions conducted in the relationship to detect reportable suspicious transactions, in addition to the periodic risk-based monitoring already in place.

Is a nostro or vostro account automatically a correspondent banking relationship?

Scope depends on the service class: whether the arrangement provides the prescribed services or the international EFT, cash management or cheque clearing services in the definition. An account that does supply those services to a prescribed foreign institution falls in scope; one that does not, does not. The file should record which service class the account rests on.

What if we take reasonable measures but cannot confirm whether the foreign institution has AML and ATF policies?

An inconclusive result does not stop the relationship by itself, but it changes the monitoring obligation. Where reasonable measures are unsuccessful or the policies are not in place, the entity must take reasonable measures to monitor all transactions in the relationship for suspicious activity. Subsection 16(3) requires the reasonable measures and, where they are unsuccessful or the policies are not in place, reasonable measures to monitor all transactions, but it does not prescribe a separate record of those measures and their results.

Does the five-year retention period run from account closure or from the last transaction?

From the last business transaction. The record set has to be kept for at least five years after the day the last business transaction is conducted, which can differ from the date an account is formally closed.

How do the correspondent banking duties interact with our suspicious transaction reporting?

They feed it. Both the periodic monitoring and the all-transactions monitoring exist partly to detect transactions that must be reported to FINTRAC. STR obligations under the Act continue to apply on their own terms, and a copy of every STR and Listed Person or Entity Property Report filed as a result of the relationship has to be retained in the correspondent banking record set.

Are prepaid and credit-card acquiring relationships fully exempt from these rules?

No. The carve-out covers specific duties for processing card or prepaid payments for a merchant, namely the record-keeping, the ascertainment of AML/ATF policies, and the periodic ongoing monitoring. The prohibition on dealing with shell banks and the other elements of the framework are not switched off by that activity.

Key Takeaways

  • Subsection 9.4(2) of the PCMLTFA prohibits a correspondent banking relationship with a shell bank outright. Separately, subsection 16(2) of the Regulations requires a written statement that the foreign institution has no direct or indirect correspondent banking relationship with a shell bank.
  • Senior management approval and a written statement of each side’s obligations are preconditions to entry, not paperwork to backfill.
  • Two triggers escalate periodic monitoring into all-transactions monitoring: penalties imposed on the foreign institution, or AML/ATF policies that cannot be ascertained or are not in place.
  • The risk assessment inside the compliance program has to name and document correspondent banking ML/TF risk specifically, and that rating sets the monitoring frequency.
  • Keep the records required by the applicable provisions: subsection 16(2) records for at least five years after the last business transaction, and copies of Suspicious Transaction Reports and Listed Person or Entity Property Reports for at least five years after they are sent.
  • The credit-card and prepaid merchant-processing carve-out lifts only record-keeping, AML-policy ascertainment and periodic monitoring; the shell bank prohibition still applies.
  • FINTRAC’s guidance page is marked ‘Date Modified: 11 October 2024’; confirm the current text before finalising policy.

Sources and References

Getting the correspondent banking file in order before the first wire

The sequence the regulations describe is unforgiving in one respect and flexible in another. The pre-entry gates are the measures in subsection 9.4(1) of the Act: obtaining prescribed information, ensuring that the foreign institution is not a shell bank, obtaining senior-management approval and setting out the parties’ obligations in writing. The records and additional measures required when the relationship is entered must then be maintained in accordance with the Regulations. Everything after that, the monitoring frequency and the depth of the periodic review, flexes with the documented risk rating. A compliance officer preparing for a FINTRAC examination should pull one live correspondent relationship and check it against that order: any missing gate, or any gap in the measures-and-results record, needs to be addressed before the next reference period.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • CSSF de-risking communique: managing ML/FT risk instead of avoiding it, what Luxembourg-regulated firms must address in their AML/CFT frameworks

    Updated July 2026In this guideWhat the CSSF de-risking communique actually saysThe Luxembourg legal basis the communique sits onWhy blanket exits weaken your own frameworkWhat the EBA guidance expects insteadHow simplified and enhanced due diligence fit the pictureWhat AMLR and AMLA change from July 2027The FATF backdrop and why “proportionate” is now the testBuilding a de-risking…

  • AMLA Direct Supervision: How Luxembourg Entities Are Identified for the 2027 Selection

    Updated July 2026In this guideWhat the CSSF announced, and what it did notThe eligibility gate: a cross-border footprint, not sizeHow risk classification turns eligibility into selectionEligible, selected, and under AMLA direct supervisionThe timeline that drives the data workFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesWhere the next decision really sitsIf a Luxembourg credit institution or financial…

  • Regulation 2026/1779: Screening the New EU Sanctions Listings

    On 17 July 2026 the Council of the European Union adopted Council Implementing Regulation (EU) 2026/1779, which amends Annex I to Regulation (EU) No 269/2014 and adds six new designations to the EU list of persons and entities subject to an asset freeze over the situation in Ukraine. The measure entered into force on the…

  • Wolfsberg Non-Bank PSP Guidance: Banking the Sector Without De-Risking

    On 15 July 2026 the Wolfsberg Group published its Guidance on the Provision of Banking Services to non-bank Payment Service Providers, and it lands on a problem most financial crime teams already know by feel: the bank holds the account, but it is several parties removed from the person actually sending the money. The new…

  • Sweden Periodic AML Reporting: Preparing for FI’s Updates

    Updated July 2026In this guidePeriodic AML reporting Sweden: what FI has confirmed for 2027Who must file the Swedish periodic AML reportWhere the new questions come from: the EU common risk methodologyDates to watch for your periodic AML filingFiling through FIDAC, and the EBA taxonomy splitWhat the report is really for: risk-based supervisionHow periodic reporting fits…

  • FATF Travel Rule Implementation: The Enforcement Gap

    On 16 July 2026 the Financial Action Task Force published its seventh targeted update on how countries are implementing the FATF standards for virtual assets and virtual asset service providers. The headline finding is that implementation remains uneven. Of the 109 jurisdictions answering the Travel Rule legislation question, 91, or 83 percent, reported legislation in…