Compliance Programs, File Retention and Inspections
Key Takeaways
AML reporting entities need the prescribed program elements. Assigning a compliance officer or hiring a service provider does not remove organizational responsibility.
Test program effectiveness at least every two years under a documented plan. The reviewer need not universally be an external audit firm.
Retention periods depend on record type and starting event. Preserve accessible records, apply lawful holds and protect personal information throughout the lifecycle.
Make obligations part of daily work
Compliance is a system for carrying out legal and professional duties consistently. A policy binder is useful only when staff understand it and actual files show the procedures being followed. An agency needs responsibilities, controls, training and a way to identify and correct failures.
Insurance oversight and AML compliance are related but distinct. Insurers and agencies have licensing and conduct responsibilities; an AML reporting entity has the prescribed FINTRAC program duties. An MGA acting solely as an MGA does not become an AML reporting entity simply because it supervises distribution, although its separate agent or broker activities can change that analysis.
Start by identifying the organization's activities and applicable regulators. Then assign each duty to an accountable person without assuming that delegation removes the organization's legal responsibility.
The AML program's core elements
-
FINTRAC requires a reporting entity to appoint a compliance officer, maintain written policies and procedures, assess and document risk, provide the required ongoing training program and plan, and conduct an effectiveness review at least every two years.
-
A sole proprietor can appoint themself as compliance officer. A larger organization should give the officer suitable authority, resources and access to decision-makers. Appointing a person without providing the ability to implement controls does not create an effective program.
-
Policies must be current and applicable to the business. Where the reporting entity is an entity, a senior officer approves them. Address identity, beneficial ownership, third parties, PEPs, reports, records, monitoring and relevant directives rather than copying a generic bank manual without adapting it.
Risk assessment and special measures
Assess customers and relationships, products and services, delivery channels, geographic exposure and new developments or technologies as required. Document how the factors affect risk and what controls address them.
A remote corporate transaction funded by unexplained third parties may need different scrutiny from a longstanding customer's ordinary premium payment. High risk calls for applicable enhanced measures, such as more frequent monitoring, additional information or stronger verification controls.
Risk assessment is not permission to ignore a mandatory threshold report because a client seems reputable. Nor should every unfamiliar structure be automatically labelled criminal. Apply prescribed duties and a reasoned risk assessment separately.
Update the assessment when business activities change. Offering a new product, entering another jurisdiction or introducing a new payment channel can create risks absent from the previous assessment.
Training and effectiveness review
Staff training should cover the obligations relevant to each role and how to escalate concerns. Document the program, plan, attendance, dates and content. A sales seminar about obtaining referrals is not a substitute for training on identifying suspicious transactions.
FINTRAC recognizes an exception where a sole proprietor has no employees, agents or others authorized to act on their behalf: a training program and plan for themself are not required. The other applicable program duties still remain.
Start an effectiveness review no later than 24 months from the start of the previous review, completing the earlier review before starting the next. Use the documented plan to test the actual program, including whether procedures, risk assessment and training work in practice.
The review can be performed by an internal or external auditor, or by the reporting entity themself if there is no auditor. Impartial review is a best practice; do not invent a universal requirement to hire an external audit firm. Document findings and corrective actions instead of treating a review as a certificate guaranteeing future compliance.
What an insurance file should show
A sound sales and service file captures client facts, needs, objectives, affordability, coverage considered, advice rationale, disclosures, instructions, applications, signatures and delivery. Include replacement and beneficiary documents where relevant.
Record dates and the version of an illustration or proposal provided. A note should explain the customer's actual decision, such as choosing a lower benefit because of a stated budget. Avoid vague statements that the client “understood everything” without supporting detail.
Keep correspondence and subsequent changes so the file reflects continuing service. Record corrections openly. An updated record should not silently replace earlier evidence in a way that suggests the correction existed before it actually occurred.
Different records have different retention clocks
There is no universal national rule to retain every life file for five, seven or fifteen years. Insurance law, AML, tax, agency contracts, privacy requirements and litigation holds can apply concurrently.
Under FINTRAC's life-sector guidance, an STR copy is retained for at least five years after submission. LCTR and large virtual currency report copies and corresponding transaction records generally use five years from creation. Information records use five years from the last business transaction.
PEP transaction records similarly have a last-business-transaction starting event. A corporate beneficial-ownership discrepancy acknowledgement has its own five-year period from record creation. These clocks should not all be restarted from policy issue or ended at surrender without examining the applicable duty.
For example, an information record with a last business transaction on March 1, 2026 has a different relevant starting date from an STR submitted on April 15, 2026. A policy issued years earlier does not make either newly triggered five-year period expire immediately.
PIPEDA breach records have a separate minimum of 24 months after determining that a breach occurred. Ontario insurers' replacement records and provincial CE evidence have their own rules. Use a retention schedule that states both the period and the triggering event.
Accessibility, privacy and holds
FINTRAC requires records to be maintained so they can be provided within 30 days of a request. Electronic records are permitted subject to the applicable accessibility requirements. Preserve enough information to demonstrate compliance rather than storing an unreadable file.
Arrange transfer of required records before an employee or contractor leaves where they were keeping records for the reporting entity. Outsourcing storage does not eliminate the entity's duty to retain and retrieve them.
Restrict access and dispose of records securely after justified retention ends. A complaint, investigation or threatened lawsuit may require preserving relevant evidence beyond ordinary destruction dates. Coordinate lawful retention with privacy obligations; neither indefinite unnecessary storage nor premature destruction is sound practice.
Inspections and corrective action
Regulators can inspect or examine businesses under their legal powers and request evidence of licensing, E&O, CE, disclosures, files and supervision. FINTRAC examines AML compliance. Respond accurately through the proper process and obtain qualified advice where privilege or legal scope issues arise.
An inspection can lead to education, remediation, further investigation or enforcement, depending on the findings and law. It does not automatically produce a fixed fine or national lifetime ban. Correct identified weaknesses, document the action and monitor whether the correction works.
FINTRAC's program guidance and life-sector record guidance provide the detailed federal rules. Local insurance conduct and record duties remain relevant alongside them.
What is the ordinary FINTRAC starting event for the five-year retention of a life-sector information record?
The policy’s original issue date in every case.
The agent’s first LLQP exam date.
The last business transaction.
The date the agency’s website was launched.
Sections you finish are checked off in the contents.
You've completed this section
Continue exploring other exams