Skip to content Skip to sidebar Skip to footer

FINTRAC High-Risk Jurisdictions: A Practical AML Workflow Guide for Canadian Reporting Entities

Six-step AML workflow for assessing FINTRAC and FATF jurisdiction risk

When a customer, beneficial owner, counterparty, payment route, or transaction is connected to a jurisdiction with elevated AML risk, identifying the country is only the first step.

The more important task is understanding why the jurisdiction is considered higher risk and what that means for the customer’s file. Does it require additional due diligence? Does it affect the customer’s risk rating? Does a Canadian ministerial directive apply? Should the relationship be escalated for further review? Most importantly, can the organization explain how those decisions were made?

FINTRAC’s July 15, 2026 advisory addresses jurisdictions subject to a FATF Call for Action, jurisdictions under Increased Monitoring, Canadian ministerial directives, and related risk and reporting considerations. Although these categories are closely related, they serve different purposes and may require different operational responses.

For reporting entities, compliance is not simply about recognizing that a jurisdiction appears in a public statement. It is about classifying the risk correctly, assessing it within the broader customer relationship, applying appropriate controls, and maintaining a clear record that supports every significant decision.

This guide explains the different jurisdiction-risk categories and provides a practical workflow for applying them consistently throughout the customer lifecycle.

Important: This article is for general information only and does not constitute legal advice. Reporting entities should confirm their obligations against current FINTRAC guidance, applicable ministerial directives, sanctions requirements, internal policies, and qualified legal counsel where appropriate.

Key takeaways

  • FATF Call for Action jurisdictions and jurisdictions under Increased Monitoring require different responses.
  • Grey-list status does not, by itself, mean that every customer or transaction requires enhanced due diligence.
  • Canadian ministerial directives may impose specific requirements independently of FATF classifications.
  • Geographic risk may arise through beneficial owners, counterparties, payment routes, sources of funds, business activities, and other connections—not only residence.
  • Material jurisdiction-risk decisions should be supported by a clear record that another reviewer can reconstruct.

What changed in July 2026?

FINTRAC published its updated advisory on July 15, 2026, following the FATF plenary held from June 17 to 19.

The principal changes were:

  • The Democratic People’s Republic of Korea, Iran, and Myanmar remained subject to a FATF Call for Action.
  • Bosnia and Herzegovina and Iraq were added to the list of jurisdictions under Increased Monitoring.
  • Algeria and Namibia were removed from Increased Monitoring.
  • Canadian ministerial directives continued to apply separately to transactions associated with the DPRK, Iran, and Russia.

Updating a country list is only part of the job. Depending on their products, customers, and geographic exposure, reporting entities may need to revisit jurisdiction classifications, risk-scoring methods, onboarding questionnaires, monitoring rules, escalation procedures, staff guidance, and recordkeeping practices. These changes should be reflected consistently throughout the compliance program.

Understand the jurisdiction-risk categories

Before determining which controls to apply, compliance teams should identify the source and nature of the risk.

FATF Call for Action

Jurisdictions subject to a Call for Action have significant strategic deficiencies in their frameworks for countering money laundering, terrorist financing, and proliferation financing.

As of June 19, 2026, these jurisdictions were:

  • the Democratic People’s Republic of Korea;
  • Iran; and
  • Myanmar.

The FATF response is not identical for all three. FATF calls for countermeasures concerning the DPRK and Iran, while calling for enhanced due diligence proportionate to the risks arising from Myanmar. Reporting entities should therefore review the applicable FATF statement and Canadian requirements rather than applying one generic “high-risk country” rule.

Jurisdictions under Increased Monitoring

Jurisdictions under Increased Monitoring—commonly called the FATF grey list—have committed to addressing identified strategic deficiencies within agreed timeframes.

FATF does not call for enhanced due diligence solely because a jurisdiction is under Increased Monitoring. Instead, organizations should consider the jurisdiction as part of the broader risk assessment. Any measures applied should reflect the customer, business relationship, products, services, transactions and geographic exposure as a whole.

A grey-list connection may contribute to a higher risk rating or prompt further review, but the result should not be automatic or disconnected from other material factors.

Canadian ministerial directives

Canadian ministerial directives operate separately from FATF classifications and may impose specific requirements concerning transactions associated with designated jurisdictions.
FINTRAC currently publishes guidance for directives concerning:

  • the DPRK;
  • Iran; and
  • Russia.

Russia’s inclusion in FINTRAC guidance does not mean that Russia is a FATF Call for Action jurisdiction. It is addressed through a distinct Canadian ministerial directive and other FATF statements.

Reporting entities should consult the applicable directive to determine which measures are mandatory for the transaction and sector involved.

Sanctions and other legal requirements

FATF classifications and ministerial directives do not replace sanctions screening or other legal analysis.

A person, entity, or transaction may create obligations under Canadian sanctions legislation even where the relevant jurisdiction does not appear on a FATF list. These review activities should be connected within the compliance workflow. However, jurisdiction classification, sanctions screening, suspicious transaction analysis and ministerial-directive compliance should remain separate review paths.

Where geographic risk appears

Geographic exposure often appears in places other than a customer’s address. It may emerge through beneficial ownership, corporate structures, counterparties, payment routes, overseas affiliates, the origin or destination of funds, or cross-border business activities. The significance of those connections depends on the broader customer relationship, including ownership, expected activity, products or services, and other identified risk indicators.

The central question is:

How did the jurisdiction-related information affect the organization’s risk assessment, controls, monitoring, or final decision?

Where the information did not change the outcome, the file should still contain enough context to explain why.

 A six-step high-risk jurisdiction workflow

 1. Identify the jurisdiction signal

Jurisdiction risk may first appear during onboarding, beneficial ownership verification, transaction monitoring, or periodic review. Sometimes the connection is straightforward, such as a customer’s residence or place of incorporation. In other cases, it emerges through a foreign counterparty, payment corridor, delivery destination, source of funds, or changes identified during ongoing monitoring.

Evidence to retain: customer and ownership information, transaction details, screening results, supporting documents, and the date the signal was identified.

2. Classify the jurisdiction

Determine which regulatory framework applies. This may involve reviewing FATF public statements, Canadian ministerial directives, sanctions requirements, FINTRAC advisories, and the organization’s own geographic risk classifications. Once the applicable framework is clear, determine which controls are appropriate.

Evidence to retain: the classification, source consulted, review date, and reason the classification is relevant.

3. Assess the overall risk

Evaluate the jurisdiction signal within the complete customer relationship.

The assessment may influence the customer’s overall risk rating, onboarding decision, monitoring frequency, approval requirements, or escalation thresholds. Whatever methodology is used, it should produce consistent, explainable, and repeatable decisions across similar cases. Where similar signals produce different outcomes, the customer records should identify the factors that led to those differences.

Evidence to retain: the updated risk assessment, applicable methodology, analyst rationale, and approval history.

4. Perform additional due diligence where required

The classification and overall risk assessment may require or support further due diligence.

Additional due diligence may involve reviewing the customer’s source of funds or wealth, beneficial ownership, ownership structure, expected transaction activity, counterparties and payment routes. It may also include reviewing contracts, invoices or corporate records. A completed checklist is not, by itself, a sufficient explanation. The record should show what was obtained, what concerns were considered, whether inconsistencies remained, and why the final decision was reasonable.

Evidence to retain: questions asked, documents reviewed, findings, unresolved issues, approvals, and final disposition.

5. Evaluate reporting and escalation

A connection to a FATF-listed jurisdiction does not automatically create a suspicious transaction reporting obligation.

Analysts should consider whether the circumstances require suspicious transaction reporting, sanctions-related analysis, ministerial-directive obligations, management escalation, enhanced monitoring, or other follow-up measures under the organization’s documented procedures. Each issue should follow the appropriate review path. The analysis should not exist only in an email thread or informal conversation.

Evidence to retain: the issue identified, information reviewed, analysis performed, reporting or non-reporting rationale, reviewer identity, approvals, and supporting records.

6. Preserve the decision trail

  • A reviewer should be able to determine:
  • what triggered the review;
  • which classification applied;
  • what information was considered;
  • what measures were taken;
  • who made and approved the decision;
  • whether reporting or escalation was considered; and
  • how the matter was resolved.

A complete decision trail supports quality assurance, internal audits, program effectiveness reviews, and regulatory examinations.

Applying the workflow across the customer lifecycle

Jurisdiction risk is not limited to onboarding. It may emerge or change as ownership structures evolve, business activities expand, counterparties change, or regulators publish new information.

Customer onboarding

Onboarding is the first opportunity to identify relevant geographic connections.

During onboarding, organizations should gather enough information to understand where geographic risk exists within the customer relationship. Depending on the customer, this may include residence, jurisdiction of incorporation, beneficial ownership, affiliated entities, expected counterparties, anticipated payment corridors, and the source of funds or wealth.

For KYB reviews, the analysis should extend through the ownership and control structure rather than stopping at the operating company’s Canadian address.

Before approval, the reviewer should be able to explain whether jurisdiction risk affected the risk rating, due diligence, approval path, or monitoring plan.

Customer risk assessment

Jurisdiction information should not remain an unstructured note. Where material, it should feed into the organization’s documented customer risk assessment. A customer risk assessment should explain not only that geographic risk was identified, but how it influenced the overall assessment. This helps organizations avoid two common mistakes: treating every foreign connection as inherently high risk, or collecting jurisdiction information without allowing it to influence the risk assessment when it is genuinely material.

Ongoing monitoring

Good onboarding decisions do not eliminate jurisdiction risk. Ownership changes, new payment corridors, overseas expansion, and updated FATF statements can all change the risk profile months or years later. Ongoing monitoring should therefore revisit jurisdiction risk whenever those changes occur.

Practical example: financing and leasing

A Canadian financing company receives an application from an Ontario corporation. During beneficial ownership verification, the analyst determines that its majority shareholder resides in a jurisdiction under FATF Increased Monitoring.

Grey-list status alone does not automatically require enhanced due diligence. The analyst should assess the jurisdiction alongside:

  • the customer’s business and operating history;
  • the shareholder’s role and level of control;
  • the source of the customer’s funds;
  • anticipated payment origins;
  • the purpose and location of the financed equipment;
  • transaction counterparties; and
  • other identified risk indicators.

The customer might be approved under standard controls, approved with additional measures, or declined. Whatever the outcome, the decision should be proportionate and supported by a record another reviewer can understand. A foreign beneficial owner may be relevant, but the more significant concern may be an unexplained mismatch between the borrower, the payment source, the equipment destination, and the stated purpose of the financing.

Sector-specific jurisdiction risks

The underlying workflow is consistent, but geographic risk may present differently across reporting-entity sectors.

Financing and leasing companies

Financing and leasing companies often encounter jurisdiction risk through beneficial ownership, third-party payments, export financing, or funding provided by overseas parent companies. While each of these factors may increase risk, their significance depends on how they fit within the broader customer relationship.

Relevant signals may include:

  • a Canadian borrower with a foreign beneficial owner;
  • payments made by an unrelated third party outside Canada;
  • equipment intended for export or foreign use;
  • funding or guarantees supplied by an overseas parent; or
  • a change from a Canadian operating account to payments from an unexplained foreign entity.

The review should connect the signal to the customer risk assessment, source-of-funds analysis, transaction purpose, approvals, and ongoing monitoring.

Title insurers

Title insurers may encounter jurisdiction risk when purchase funds originate overseas, ownership structures become more complex, or third parties are involved in the transaction. Foreign ownership, overseas funding sources, and sanctions or ministerial-directive considerations should all be assessed within the broader context of the transaction before a policy is issued. Examples include:

  • purchase funds originate from a foreign financial institution;
  • a purchaser uses a Canadian corporation with foreign ownership;
  • the beneficial owner differs from the apparent purchaser;
  • an overseas third party supplies purchase funds; or
  • sanctions or ministerial-directive considerations arise before policy issuance.

The record should clearly connect the purchaser, beneficial owner, source of funds, transaction parties, screening results, analysis and final decision.

Dealers in precious metals and stones (DPMS) and jewellers

Dealers in precious metals and stones and jewellers often encounter jurisdiction risk through complex payment arrangements, foreign third parties, opaque ownership structures, or export activity. These factors should be assessed alongside the customer’s overall profile rather than in isolation.

Relevant indicators may include:

  • a high-value purchase funded through several payment methods;
  • payment by a foreign third party;
  • rapid resale or export of the goods; or
  • payment and delivery routes inconsistent with the customer’s stated business.

A foreign connection does not determine the outcome by itself. It should be assessed alongside the customer profile, transaction value, ownership information, payment method, delivery arrangements, and other risk indicators.

Common workflow gaps

Most jurisdiction-risk weaknesses are not caused by poor policies; they arise because those policies are not translated into consistent operational workflows.

Common weaknesses include:

  • collecting only the customer’s address while overlooking ownership, counterparties, payment routes, and delivery destinations;
  • recording a jurisdiction signal without updating the risk assessment;
  • treating all grey-list jurisdictions as though they were subject to a Call for Action;
  • failing to separate FATF classifications, ministerial directives, and sanctions;
  • performing additional due diligence without documenting what prompted it;
  • preserving screening evidence outside the customer record;
  • documenting escalations only through email;
  • failing to update working rules after FATF or FINTRAC publications; and
  • recording that a review was completed without explaining the outcome.

These gaps usually require clearer workflow ownership, structured decision fields, evidence standards, and review controls—not simply a longer policy manual.

High-risk jurisdiction checklist

Use the following questions to assess whether your organization can apply jurisdiction guidance consistently:

Where several answers are “no,” the weakness may lie in workflow execution and evidence quality rather than policy coverage.

How AMLForms supports high-risk jurisdiction workflows

Policies define expectations, but workflows determine whether those expectations are applied consistently. The challenge is ensuring that analysts follow established procedures, document material decisions and retain the evidence required for quality assurance, audits, program effectiveness reviews and regulatory examinations.

AMLForms connects onboarding, risk assessment, beneficial ownership review, enhanced due diligence, transaction monitoring, case management and recordkeeping within one structured workflow. This helps teams show how jurisdiction risk was identified, assessed, escalated, approved and resolved instead of leaving those decisions scattered across spreadsheets, emails and disconnected systems.

For jurisdiction-related reviews, AMLForms can help teams:

  • capture geographic indicators during onboarding and periodic reviews;
  • connect jurisdiction signals to customer risk assessments;
  • route higher-risk files through additional review steps;
  • record analyst observations, approvals, and decision rationales;
  • preserve supporting documents and final dispositions; and
  • keep customer, monitoring, and escalation records connected.

AMLForms provides the operational structure to turn jurisdiction-risk requirements into consistent workflows, documented decisions, and connected evidence across the customer lifecycle.

From jurisdiction guidance to operational practice

Jurisdiction risk is not managed effectively by maintaining a list of higher-risk countries. The real work begins when a jurisdiction connection is identified.

Compliance teams need to understand why the jurisdiction is relevant, determine which regulatory or risk framework applies, assess the connection within the broader customer relationship, and decide what additional controls or escalation are appropriate. Just as importantly, they need to preserve the reasoning and evidence behind those decisions.

That is where well-designed workflows matter.

AMLForms helps Canadian reporting entities turn jurisdiction-risk requirements into structured workflows—connecting customer risk assessments, beneficial ownership reviews, enhanced due diligence, monitoring, escalations, approvals, and supporting evidence within the customer record.

See how AMLForms can help you build a more consistent, documented approach to jurisdiction risk.

See AMLForms in Action

Book a personalized demo to see how AMLForms helps you onboard, verify, screen, and monitor customers with confidence.

FAQs

“FINTRAC high-risk jurisdictions” is a commonly used search term rather than one uniform regulatory category.

FINTRAC’s advisory discusses FATF Call for Action jurisdictions, jurisdictions under Increased Monitoring, Canadian ministerial directives, and related risk and reporting considerations. Reporting entities should identify which category applies before determining the appropriate response.

No.

FATF does not call for enhanced due diligence solely because a jurisdiction is under Increased Monitoring. The jurisdiction should be considered within the reporting entity’s broader risk assessment. Separate Canadian requirements may still apply where a ministerial directive, sanctions requirement, or other legal obligation is engaged.

No.

A jurisdiction connection alone does not automatically establish reasonable grounds to suspect money laundering, terrorist financing, or sanctions evasion. The transaction should be assessed alongside the customer’s known activity, transaction purpose, source of funds, counterparties, behaviour, and other relevant indicators.

The reporting or non-reporting rationale should be documented clearly.

Geographic risk refers to money laundering, terrorist financing, or proliferation financing risks associated with jurisdictions connected to a customer, business relationship, or transaction.

Connections may arise through residence, incorporation, beneficial ownership, business operations, counterparties, payment routes, sources or destinations of funds, delivery locations, or other cross-border activity.

Organizations should review their classifications and working rules when:

  • FATF updates its public statements;
  • FINTRAC publishes a new advisory;
  • a Canadian ministerial directive changes;
  • sanctions requirements change;
  • products, services, customers, or delivery channels change; or
  • the organization’s geographic exposure changes materially.

Responsibility should also be assigned for implementing changes in risk models, forms, monitoring rules, staff instructions, and customer-review workflows.

The records should allow another reviewer to reconstruct the decision from beginning to end. Depending on the circumstances, that may include the jurisdiction signal, the source used to classify it, customer and ownership information, transaction details, risk assessment results, due diligence findings, supporting documentation, reviewer notes, approvals, and the final disposition. The record should show that a review occurred and how the conclusion was reached.

FINTRAC’s July 2026 advisory should not be treated merely as a country-list update. It is an opportunity to test whether jurisdiction information flows through the organization’s operational processes.

A defensible approach requires reporting entities to:

    1. identify the jurisdiction signal;
    2. classify it correctly;
    3. assess it in context;
    4. apply required or proportionate measures;
    5. evaluate reporting and escalation; and
    6. preserve the evidence supporting the decision.

Not every customer connected to a higher-risk or monitored jurisdiction should receive the same treatment. The goal is to make informed, proportionate and consistent decisions—and to maintain a record showing how those decisions were reached.