Registering an MSB with Fintrac is less complicated than most people think, but the follow-through is where things fall apart.
The registration itself takes maybe twenty minutes if you have your documents ready. The portal at fintrac-canafe.gc.ca accepts the application, you fill out the corporate info, designate a compliance officer, and submit. You get a registration number within a few business days. That part is straightforward. What nobody tells you is that registration is the easy half. After that, you're on the hook for ongoing reporting obligations that most small operations completely miss until they get flagged.
Why Fintrac Money Services Business Registration Matters
If you operate as a money services business in Canada — transmitting funds, dealing in foreign exchange, operating a money remittance service, or issuing or redeeming monetary instruments — you are legally required to register with FINTRAC under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act. Operating without registration is a real offence. I've seen people treat it like a bureaucratic formality when it's actually the foundation of your compliance posture. The compliance officer designation is the first real decision point. This person doesn't need to be a lawyer, but they need to be someone who will actually do the work instead of treating it as a checkbox. Pick your operations manager. Don't pick the office manager who already has a full plate. Pick the person who understands how your transaction flow works end to end.
The reporting requirements most people mess up
You need to file three core types of reports depending on your activity. Large transaction reports for cash transactions of $10,000 or more in the course of a single day. Suspicious transaction reports when you have grounds to suspect the funds are connected to money laundering or terrorist financing, regardless of the amount. And electronic funds transfer reports for cross-border transfers of $1,000 or more. The suspicious transaction reporting is where people get stuck. The threshold isn't about certainty. It's about grounds to suspect. If a customer is structuring deposits just below the $10,000 threshold, or their transaction patterns don't match their stated business, you file an STR. You don't need proof. You need a reasonable basis, and you document that basis clearly in the report notes. FINTRAC reviewers can tell when someone files an STR because they were told to rather than because they actually observed something concerning. I ran into a specific issue a couple years back with a client who was processing cross-border remittances to West Africa. They were consistently hitting the electronic funds transfer reporting threshold, but their system was flagging transactions based on the individual transfer amount rather than the aggregate daily total. FINTRAC expects you to track all electronic funds transfers originating from your business on a single calendar day and report them together. Their software was treating each transfer independently, which meant they were under-reporting. I rewrote their monitoring logic to aggregate by recipient and by day rather than by individual transaction, and that fixed the gap. Took about three hours of work once I figured out what the actual requirement was versus what their vendor had built.
Get the Full Details

Record keeping is where compliance programs die
You must retain records of all transactions for five years. This includes the underlying documentation — identification records, account files, and supporting transaction records. Five years from the date of the transaction, not five years from when you stop doing business. If you close your operation, those records still have to survive the retention period. I've seen companies try to argue that destroyed records should be excused because they didn't think the retention period extended that far. That argument doesn't work. Electronic record retention needs actual thought. Cloud storage counts, but you need to verify your provider's data handling policies and make sure you can produce the records in a format FINTRAC can review if asked. I had a situation where a small MSB was using a custom-built ledger that stored transaction data in a proprietary database format. When they needed to pull records for an internal audit, they couldn't export them in any standard format. They ended up having to reconstruct the data manually from backup files, which took two days and was prone to errors. Switching to a system with proper CSV and PDF export capabilities would have solved this permanently.
Independent testing and audits
Once a year, you need to have an independent test of your AML/ATF compliance program. This doesn't mean hiring a Big Four firm. It means someone who isn't your compliance officer and who actually understands what they're looking at. The test should cover your registration status, reporting timelines, record keeping practices, and the adequacy of your customer due diligence procedures. Write the findings down. Fix the issues. Keep the report. FINTRAC doesn't routinely ask for these, but if they come after you during an examination and you can't produce a recent independent test, that's an immediate red flag. Having the report shows you're taking this seriously. Not having one suggests you're guessing.
A few things FINTRAC doesn't make clear upfront
Your compliance program needs to be proportionate to your size and risk profile. A small money transmitter doing $50,000 in monthly volume doesn't need the same compliance infrastructure as a bank. But "proportionate" doesn't mean minimal. You still need written policies, a designated compliance officer, staff training, and an independent test. The difference is in the depth and frequency, not in whether you have these elements at all. Another thing that trips people up: Fintrac registration is federal. If you're incorporated federally, you're registered federally. If you're provincially incorporated, that doesn't change your FINTRAC obligation. Some people think provincial licensing covers them. It doesn't. You need both. The timing of your STR filing matters more than most realize. You have 30 days from the day you have grounds to suspect, but filing sooner is always better. There's no penalty for filing a report that turns out to be unfounded. There is a penalty for not filing when you should have. I've reviewed cases where businesses waited weeks to file because they were hoping to resolve the issue internally first. That's not how it works. You report, you document your internal resolution, and you move on.

Customer due diligence has two levels. Standard and enhanced. For most MSBs, standard CDD covers the basics — verify identity, understand the nature of the customer's business, assess the transaction patterns. Enhanced due diligence kicks in for politically exposed persons, high-risk jurisdictions, or unusual transaction structures. The PEPP check is straightforward enough, but the high-risk jurisdiction part is where people get sloppy. The FATF list changes. FINTRAC publishes its own guidance. Check both regularly rather than relying on a static list you downloaded a year ago.
Practical steps to get started
Create a FINTRAC account on their portal. Gather your corporate information — business number, incorporation documents, address, contact details. Identify your compliance officer and get their consent in writing. Draft your written AML/ATF compliance program. It should cover your risk assessment, customer due diligence procedures, reporting obligations, record keeping, staff training, and independent testing. Submit your registration. Once registered, start tracking your reporting obligations on a calendar. Set reminders for annual testing, policy reviews, and any updates to your program. The whole process from start to active compliance usually takes two to four weeks for a well-prepared operation. For someone starting from scratch without existing policies, plan on six to eight weeks. If your operation is primarily digital — crypto exchanges, peer-to-peer payment platforms, virtual asset service providers — the registration process is the same, but your compliance program needs to account for the additional risks these channels introduce. Virtual assets don't have the same identity verification infrastructure as traditional financial institutions, so your CDD procedures need to be stricter, not looser. That's a common mistake I see with new entrants in that space. They assume the digital nature of their business means lighter oversight. It means heavier oversight. The FINTRAC website has a comprehensive guide for MSBs. It's dry and not particularly well organized, but it's the authoritative source. I reference it constantly. The industry association newsletters are useful too, since FINTRAC updates its guidance periodically and those updates often get discussed there before they become common knowledge in the field.