Blog/Opinion

What FINTRAC looks for in a crypto MSB examination

A compliance officer's view of the examination process.

TypeOpinion
PublishedJuly 2026
AuthorTokenNest editorial

Why we are writing this

Most Canadians have never seen the inside of a FINTRAC examination and assume it is a formality. It is not. An examiner arrives with a document request that runs to several pages, spends days in your records, and leaves with findings that can become published penalties. Having been through the process, we think clients deserve to know what is actually checked — because it is a better test of a platform than any marketing claim.

The compliance program itself

The first thing an examiner asks for is the written program: the compliance officer appointment, the policies and procedures, the risk assessment, the training plan and the most recent two-year effectiveness review. They read it for whether it describes what you actually do. A policy that says "enhanced due diligence on high-risk clients" is tested by pulling a sample of high-risk files and asking to see the enhanced due diligence. The gap between the document and the file is where most findings live.

Client identification and records

Next comes a sample of client files — usually a few dozen, weighted towards large and unusual activity. For each: was identity verified using an accepted method before the first transaction, is the record complete, was beneficial ownership established for business clients, and were politically exposed persons screened? Records must be retrievable within 30 days; in practice the examiner wants them the same afternoon. Virtual-currency transfer records of $1,000 CAD and above and large transaction records of $10,000 CAD and above are checked line by line against the transaction system.

Reporting and monitoring

Every large virtual currency transaction report must be filed within 24 hours of the transaction, so the examiner reconciles the transaction ledger against what FINTRAC received and looks for gaps. Suspicious transaction reports are reviewed for quality — was the narrative specific, were the indicators named, was it filed promptly once suspicion formed? The transaction-monitoring rules themselves are tested: what alerts fired in the period, how each was resolved, and whether the resolution was documented by someone other than the person who cleared it.

What it taught us

Three lessons. First, monitoring has to be tuned to your actual client base — rules copied from a bank generate noise and miss what matters for a non-custodial MSB. Second, the compliance officer needs real independence: the ability to stop a transaction without a business sign-off, and a reporting line to the board. Third, document the decision, not just the outcome. An examiner who can see why you cleared an alert trusts the next hundred. This is the discipline behind our AML/KYC policy — and why we publish it.

Related pages
BlogRead →Why we built a non-custodial platformRead →Stablecoins are becoming payment railsRead →The real cost of a SWIFT wireRead →

Ready when you are.

Open an accountContact us