FINTRAC IT Controls for Canadian Accountants: A 2026 Practitioner Guide

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

FINTRAC obligations attach to a Canadian accountant the moment the engagement involves receiving, paying or instructing on funds, securities or real estate for a client. The trigger is the activity, not the firm size. A two-partner CPA practice in Burlington that handles trust-account transfers for one estate client is a reporting entity under PCMLTFA Part 1.

That is the line most accounting practices miss until a FINTRAC examination notice arrives. By the time the examiner asks for two years of client-identification records, the Microsoft 365 controls meant to capture them either exist and are intact, or they do not.

This post is the IT-controls deep dive inside our 2026 AI and IT playbook for Canadian accounting firms. It applies to CPAs engaged in trigger activities in any province, with the CPA Code of Professional Conduct as the overlay.

Key Takeaways

  • FINTRAC applies the moment an accountant receives or transfers funds, securities or real estate for a client. Firm size does not change the obligation.
  • FINTRAC Guide 8 requires retention for at least five years from the date the record was created, produced within 30 days of an examiner request.
  • Penalty ceilings changed in 2026. The very-serious administrative range is now CA$1 to CA$20,000,000, not the CA$100,000 figure most accounting-firm guidance still repeats.
  • The PIPEDA, FINTRAC, and CPA Code stack governs the same client record three ways at once. A control that satisfies one regime is incomplete.
  • CPA Ontario Rule 208 confidentiality does not override FINTRAC reporting. Tipping-off restrictions under PCMLTFA section 8 resolve the conflict.

Book a Consultation

When FINTRAC applies to accountants: the trigger-activity test.

According to FINTRAC (2026), accountants become reporting entities when they engage in, or give instructions on, three activity categories. Receiving or paying funds. Purchasing or selling securities, real property or business assets. Transferring funds or securities by any means. Giving advice is not giving instructions, and collecting your own professional fees is not a trigger.

The list is operational. Audit, bookkeeping and assurance work done without instructing on funds movement does not trigger FINTRAC. The moment an engagement letter lets the firm receive estate funds or close a purchase through its trust account, the firm crosses the line. I have seen that happen at 2-partner practices.

Two scenarios show up repeatedly in Canadian practice.

  • Estate work where the firm acts as executor or trustee. The firm receives estate funds and pays beneficiaries. Trigger met.
  • Real-estate closings where the accountant instructs a wire transfer. Trigger met even where the deal closes through a lawyer’s trust account, because the accountant gave the instruction.

The grey zone I get asked about most is advisory work where the accountant recommends a transfer and the client executes it themselves. If the firm does not instruct the bank, the activity is not triggered. I tell Ontario partners to document the engagement scope so that boundary stays visible to an examiner.

Not sure whether your firm has crossed the FINTRAC trigger line? Talk to our team about a scoping review →

FINTRAC Guide 8 and the record-keeping IT controls it requires.

According to FINTRAC record-keeping guidance for accountants (2026), records must be kept for at least five years from the date each record was created. They must also be kept in a way that lets the firm produce them to FINTRAC within 30 days of a request. Those two properties drive every control decision below.

Guide 8 itemizes what a reporting accountant keeps.

  • Client identification records.
  • Large cash transaction records.
  • Electronic funds transfer records over CA$10,000 in 24 hours.
  • Records of suspicious transactions, whether or not reported.
  • Terrorist property records.
  • Compliance program documentation, covering the risk assessment, policies and training records, plus the two-yearly effectiveness review.

Each record type has to deliver four properties when an examiner arrives.

  • Completeness. The record exists.
  • Integrity. It has not been altered after creation.
  • Retention. It survives at least five years.
  • Producibility. It can be retrieved inside 30 days.

The table maps each property to the Microsoft 365 surface most Canadian accounting firms already pay for. I work from this mapping rather than a generic control catalogue, because an examiner asks about records rather than about frameworks.

Record type. IT control. M365 surface.
Client identification. Encrypted at rest. Five-year retention label. Immutable audit log of access events. SharePoint with Purview label. Unified Audit Log.
Large cash transactions. Dated and signed at receipt. Label applied at file creation. Export on demand. SharePoint library with Power Automate.
EFTRs over CA$10,000. Captured from the trust-account banking export. Reconciled monthly. Integrity hash per batch. Banking export to SharePoint with Purview.
Suspicious transactions. Access limited to the compliance officer and named delegates. Tipping-off controls enforced. Restricted site with sensitivity label.
Compliance program. Risk assessment, policies, training records, and effectiveness review, all dated and signed. SharePoint library with version history.

The dominant failure mode at small Canadian firms is not missing records. It is records held in personal email or a departed employee’s OneDrive that was purged at offboarding. A tenant-level label prevents that deletion wherever the file sits.

The PIPEDA + FINTRAC + CPA Code stack, explained.

According to the CPA Ontario Code of Professional Conduct (2026), Rule 208.3(a) requires a member to protect confidential client information. Access by another person must be limited to those with legitimate purpose. Rule 208.3(b) goes further, requiring the firm to obtain the written agreement of anyone granted that access.

A single client record sits inside three regimes at once. PIPEDA governs the personal information of anyone identified in it. PCMLTFA Part 1 governs it as a FINTRAC reporting obligation. The CPA Code governs the firm’s conduct in handling it.

PIPEDA requires safeguards proportionate to sensitivity, retention only as long as necessary, subject access on request, and notification of a breach that poses a real risk of significant harm. PIPEDA section 10.1 (2026) sets the timing as as soon as feasible after the organisation determines the breach occurred. PIPEDA contains no 72-hour deadline, and a good deal of accounting-sector guidance gets that wrong.

The retention conflict is the one I resolve most often. PIPEDA says retain no longer than necessary. FINTRAC says retain at least five years. The FINTRAC requirement is the legal mandate defining the necessary period for records inside Guide 8’s scope, so a five-year label satisfies both regimes at once.

Want help mapping all three regimes onto your Microsoft 365 tenant? Book a consultation →

Quebec Law 25 adds a fourth layer for any firm with a Quebec resident in its client base. Our PIPEDA compliance primer for Canadian small business covers the federal track that sits underneath all of it.

Decision matrix: FINTRAC obligation by IT control and CPA Code overlap.

This is the matrix I use in scoping conversations with Canadian CPA firms inside FINTRAC’s perimeter. Each row maps an obligation to the control that implements it, the CPA Code rule overlaying it, and the Microsoft 365 surface where it lives. It confirms coverage. It does not replace the documented program.

FINTRAC obligation. IT control. CPA Code overlay. M365 mapping.
Client and beneficial-owner identification. Identity capture form, scanned ID storage, retention label. Rule 201 due care. Rule 208 confidentiality. Microsoft Forms, SharePoint, Purview label.
Ongoing monitoring and risk assessment. Risk-rated client list, review schedule, dated assessment artefact. Rule 202 integrity. Rule 203 competence. SharePoint list with Power Automate reminders.
Suspicious transaction reporting. STR template, restricted access, tipping-off enforcement on messaging. Rule 208 with the PCMLTFA carve-out. Restricted site plus Teams sensitivity label.
Compliance program and effectiveness review. Documented program with version history and completion tracking. Rule 203 competence. Rule 204 objectivity. SharePoint training site plus Viva Learning.
Five-year retention with 30-day producibility. Tenant-level retention label, immutable audit log, eDiscovery hold. Rule 208 confidentiality. Rule 215 cooperation. Purview retention plus Purview eDiscovery.
Compliance officer designation. Named individual, documented authority, reporting line to leadership. Rule 102 reputation. Rule 203 competence. Entra ID role assignment plus governance docs.

One column gets forgotten more than any other: tipping-off enforcement on internal messaging. PCMLTFA section 8 makes it an offence to disclose that an STR has been made, is being made, or will be made, with intent to prejudice a criminal investigation. Teams chats and shared mailboxes are the leakage vectors I find first.

Suspicious transaction reporting and the IT audit trail: what is defensible.

According to FINTRAC STR guidance (2026), a reporting entity must submit an STR as soon as practicable after completing the measures that establish reasonable grounds to suspect. There is no fixed clock. The audit trail of when the firm identified the indicator and when it acted is the evidence an examiner weighs.

Reasonable grounds to suspect is a lower bar than reasonable grounds to believe. That distinction catches out partners who wait for certainty they will never have, and under PCMLTFA the waiting is itself the compliance failure.

A defensible trail captures four moments.

  • When the indicator was first identified by any staff member.
  • When the compliance officer received the escalation.
  • When the compliance officer formed reasonable grounds to suspect.
  • When the STR was submitted to FINTRAC.

The gap between each pair is what gets reviewed. Long gaps with no contemporaneous notes are the pattern I see draw findings across our Ontario clients, and my experience is that the notes matter more than the speed.

Four artefacts make that trail hold up, and all four carry the same five-year label.

  • An indicator-logging form routing read-once to the compliance officer.
  • A restricted review log with timestamped notes.
  • An STR draft library with version history.
  • A submission receipt captured into the firm’s record.

Tipping-off overlays every step. The logging form stays invisible to the client. Microsoft Teams channels discussing the file exclude the client’s account team. The engagement-continuation decision lives somewhere separate from the general matter file. Our cybersecurity services hub covers the sensitivity-label architecture in more depth.

[FIELD NOTE] The tipping-off leak is almost always internal chat.

When I run a controls review at a Toronto or Hamilton practice, I ask to see the Teams channel where the engagement partners talk. That is where I find the exposure, not in the document library everybody expects me to audit.

My standard sequence runs to 3 questions. Can the client’s own account team read the channel? Does the compliance officer have a private space at all? Is external sharing on by default in the Microsoft 365 tenant?

Mike Pearlstein, CISSP, Fusion Computing. First-person field observation; anonymized client data.

Want us to map your STR workflow against FINTRAC’s examination expectations? Get in touch →

The 8-step IT compliance rollout for FINTRAC reporting entities: criteria and steps.

According to PCMLTFA section 9.6 (2026), every reporting entity must establish a program that is reasonably designed, risk-based, and effective, including documented policies for assessing money-laundering and terrorist-financing risk. The eight steps below are how we sequence that requirement into a tenant that already exists.

8-step FINTRAC IT controls rollout.

  1. Scope confirmation, days 1 to 3. The compliance officer and legal counsel review engagement letters and the client list to confirm which activities cross the trigger. Output is a scoping memo.
  2. Risk assessment, days 3 to 10. The firm produces a documented assessment covering client and geographic risk, then product and channel risk. The compliance officer dates and signs it.
  3. Compliance program documentation, days 7 to 21. Policies, procedures and the training plan are drafted and signed off alongside the review schedule. The compliance officer is named with explicit authority.
  4. Retention labels and audit logging, days 14 to 28. Purview labels are configured at tenant level, five years for identification and transaction records and for STR records. Unified Audit Log is verified.
  5. SharePoint architecture and sensitivity labels, days 21 to 35. A FINTRAC site collection is provisioned with restricted libraries. Sensitivity labels enforce tipping-off controls.
  6. STR workflow and forms, days 28 to 42. The logging form, review log, draft template, and submission capture are configured. Power Automate timestamps each transition.
  7. Training rollout, days 35 to 49. Every staff member touching client funds, securities, or real-estate work completes role-appropriate training. Completions are dated and retained.
  8. Dry run and effectiveness review, days 49 to 60. The firm runs a tabletop against one historical file. Gaps are remediated and the first effectiveness review is signed.

[FIELD NOTE] Reconstructing under examination pressure.

A Q1 2026 audit-prep engagement with a Hamilton accounting firm in the 6-to-15-partner band opened with an examination notice arriving on a Tuesday. The firm had been a reporting entity for three years on estate-trustee work and had never run a formal risk assessment.

My first 36 hours went into reconstructing the client-identification trail from email attachments, scanned PDFs and one partner’s personal cloud storage. We measured 30-day producibility as met on day 18. Labels and audit logging went live on day 22.

The examination closed with a corrective-action letter rather than a penalty. My lesson from it: reconstructing controls under examination pressure runs roughly 4 to 6 times the effort of building them ahead of time.

Mike Pearlstein, CISSP, Fusion Computing. Anonymized client data; city, sector and size band only.

“The pieces of Microsoft 365 we already paid for did most of the FINTRAC work once they were configured the right way. The unlock was getting retention and sensitivity labels right at the tenant level rather than the file level. After that, the rest was process.”

Managing partner, mid-size CPA firm, Greater Toronto Area. Engagement started Q4 2025; quote shared with permission.

Common FINTRAC IT mistakes Canadian accounting firms make.

According to the PCMLTFA Administrative Monetary Penalties Regulations (2026), section 5 sets three ranges. Minor violations run CA$1 to CA$40,000. Serious violations run CA$1 to CA$4,000,000. Very serious violations now reach CA$20,000,000. Those ceilings rose sharply in 2026, and most accounting-firm guidance still quotes the old CA$100,000 figure.

PCMLTFA penalty ceilings, 2026. Very serious violations now reach twenty million Canadian dollars. Maximum penalty per violation, CA$, 2026. Minor. CA$40,000. Serious. CA$4,000,000. Very serious. CA$20,000,000. Source. SOR/2007-292 section 5, as amended 2026. Bars scaled to the CA$20M ceiling.

Criminal exposure moved with it. Failing to report a suspicious transaction under section 7 now carries a fine of up to CA$10,000,000 on summary conviction and CA$20,000,000 on indictment. Those are ceilings rather than expected outcomes. The realistic risk for a small firm stays a corrective-action letter. The numbers still reset a reluctant partner conversation.

Do not. Why it fails. Do this instead.
Treat retention as a folder problem. Folders depend on staff discipline. Records in personal email or a departed employee’s OneDrive vanish at offboarding. Apply tenant-level Purview labels. A five-year label survives the file’s location and its author.
Discuss STR files in general channels. Section 8 prohibits disclosing a report with intent to prejudice an investigation. Shared mailboxes make that hard to defend. Restrict STR work product to a compliance-officer-only site with a label blocking copy, forward, and external sharing.
Rely on the engagement letter to bound scope. Scope is the activity, not the contract. A letter scoping advisory work while a partner instructs a wire crosses the trigger anyway. Review engagement scope against operational reality twice a year and update the letters to match.
Skip the effectiveness review. It is a section 9.6 requirement. A documented program with no dated review fails a line examiners check first. Run it every two years, signed and dated, with explicit findings and remediation actions.

The floor underneath all of this is ordinary security hygiene. According to the Canadian Centre for Cyber Security (2024), small and medium organizations should implement 13 baseline controls covering patching, multi-factor authentication, backups, training, and incident response. A firm meeting FINTRAC record-keeping while ignoring that baseline still puts the records at risk.

Talk to Fusion

Frequently asked questions.

Does FINTRAC apply if we only do tax and audit work?

Not on that basis alone. Scope is triggered by receiving, paying or instructing on funds, securities or real estate for a client. A practice that is entirely advisory and assurance work, with no funds movement on client account, sits outside the PCMLTFA perimeter, whether it has 2 partners or 40. One engagement crossing the trigger brings the firm inside it.

How long do we have to keep FINTRAC records?

At least five years from the day the record was created, per Guide 8. It must be producible within 30 days of a request. The Microsoft 365 control delivering both is a Purview retention label applied at tenant level rather than file level, so the record survives wherever it lives.

What is the penalty range for FINTRAC non-compliance in 2026?

Administrative penalties under SOR/2007-292 section 5 run CA$1 to CA$40,000 for a minor violation, CA$1 to CA$4,000,000 for a serious violation, and CA$1 to CA$20,000,000 for a very serious one. Criminal conviction for failing to report under section 7 reaches CA$20,000,000 on indictment. These ceilings rose in 2026, and older guidance quoting CA$100,000 is out of date.

Can our IT provider serve as the FINTRAC compliance officer?

No. The compliance officer is a named individual inside the firm with explicit authority and a reporting line to senior leadership. An external provider can support that person with Microsoft 365 controls, training and audit-log review. CPA Code responsibilities do not delegate outward.

Does the CPA Code prevent us from filing an STR?

No. Rule 208 carves out disclosure required by law, and PCMLTFA reporting is required by law, so an STR filed in good faith does not breach the Code. Section 8 then restricts telling the client, which resolves the apparent conflict. Rule 208.3(b) is the clause worth reading twice, because it reaches anyone granted access to client information.

Does PIPEDA give us 72 hours to report a breach?

No, and this is one of the most repeated errors in accounting-sector guidance. PIPEDA section 10.1 requires a report to the Commissioner as soon as feasible after the organisation determines the breach occurred. There is no 72-hour clock in the statute. Quebec Law 25 and contractual insurer deadlines are separate obligations that may well be tighter.

Where in Microsoft 365 should we store FINTRAC records?

A dedicated SharePoint site collection with restricted libraries for identification records, transaction records, and STR work product. Purview labels enforce the five-year rule at tenant level, sensitivity labels enforce tipping-off controls, and the Unified Audit Log carries access events. Personal email and Teams chat are not appropriate storage surfaces.

What does a FINTRAC examination of our IT controls look like?

The examiner asks for the dated risk assessment, the compliance program documentation, and training records for the period. Then the most recent effectiveness review, samples of client identification and transaction records, plus the STR audit trail. Everything is produced within 30 days, and each record class is tested for completeness, integrity, retention, and producibility.

Sector deep dives continue elsewhere in this cluster.

Conclusion.

FINTRAC obligations attach to the activity. Once a firm crosses the trigger on one client file, its controls have to satisfy an examiner testing completeness, integrity, retention, and 30-day producibility.

The control set is ordinary. A tenant-level Microsoft Purview retention label, a restricted site for STR work product, and a signed effectiveness review carry it. Reconstruction is the failure mode.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611