The Case for a Single AML Agent Model in Mortgage Transactions

Canada’s anti-money laundering and anti-terrorist financing regime should be rigorous, effective, and proportionate. Mortgage brokers, lenders, and administrators have an important role in identifying suspicious activity, detecting illicit funds, and protecting the integrity of the financial system.

But the mortgage industry needs a more coordinated way to meet those obligations.

A practical solution would be a single AML agent model: one qualified participant would complete and maintain the core AML/ATF compliance file for a mortgage transaction, while other regulated participants could rely on that work under clear statutory rules and safeguards.

This would not reduce scrutiny where genuine risk exists. It would reduce unnecessary duplication in routine transactions.

What a Single AML Agent Would Do

A mortgage transaction may involve a broker, lender, administrator, private lenders, mortgage investment corporations, lawyers, title insurers, payment providers, and compliance technology vendors. Several of those parties may have AML/ATF obligations relating to the same borrower, the same mortgage, and the same payment flow.

Under a single AML agent model, one qualified party would coordinate the common compliance work for the transaction, including:

  • identity verification;
  • collection and confirmation of client information;
  • corporate-authority and beneficial ownership inquiries;
  • third-party determinations;
  • politically exposed person (“PEP”), head of an international organization (“HIO”), and sanctions screening;
  • initial risk assessment;
  • enhanced due diligence where warranted;
  • secure retention of relevant records; and
  • monitoring and information-refresh triggers.

In a brokered mortgage, the broker would often be the logical AML agent because it is commonly the first regulated participant to receive the borrower’s application, identification, financial information, and instructions. In a direct-lending transaction, the lender would generally perform that role.

A mortgage administrator should generally be entitled to rely on the existing transaction-level AML file when servicing begins, provided the information remains current and there is no reason to doubt it.

Accountability Would Remain With Every Reporting Entity

The model should not permit a reporting entity to ignore information or warning signs that arise in its own dealings with a borrower or transaction.

Each broker, lender, and administrator would remain responsible for:

  • information it knows that was not provided to the AML agent;
  • red flags arising through its own client interactions or payment activity;
  • obligations specific to its own regulated activity;
  • suspicious-transaction reporting decisions it is required to make; and
  • failures within its own control.

The purpose is not to transfer all legal responsibility to one party. It is to prevent multiple parties from recreating the same compliance file when the underlying facts have already been properly verified through a secure, auditable process.

Why the Current System Duplicates Compliance Work

FINTRAC’s mortgage-sector guidance explains that AML/ATF obligations arise from the particular activity performed by each reporting entity. A mortgage broker arranging a mortgage, a lender funding it, and an administrator receiving payments may each have independent obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its Regulations.

Those obligations may include client identification, recordkeeping, beneficial ownership inquiries, third-party determinations, PEP/HIO screening, ongoing monitoring, and the updating of information.

The result can be that the same borrower provides identification to the broker at application, to the lender before funding, and again to the administrator once servicing begins. A corporate borrower may provide the same corporate records, authority information, and beneficial ownership information to several parties.

Each participant may then store copies of the same highly sensitive documents in separate systems and create its own audit trail.

That is compliance by duplication.

The Burden on Borrowers and Mortgage Professionals

Mortgage professionals should investigate genuine risks. They should not be required to repeat the same verification work merely because the legal framework does not clearly permit reliance on another regulated participant’s compliant work.

The burden is especially significant for private lenders, mortgage investment corporations, syndicated lender groups, and administrators, where multiple entities may have a connection to the same mortgage.

Borrowers also bear the cost. They are asked to provide the same sensitive personal information repeatedly and may reasonably wonder:

  • Why do several organizations need copies of my identification?
  • Who is storing my personal and financial information?
  • How long will it be retained?
  • Which third-party technology providers have access to it?
  • Why does a routine mortgage renewal require another full set of checks?

A coordinated model would allow a borrower to provide sensitive information once through a controlled process rather than repeatedly to different participants.

Reducing Privacy and Cybersecurity Risk

Mortgage files contain government-issued identification, dates of birth, residential addresses, bank statements, income information, credit information, corporate records, trust documents, and beneficial ownership details.

The more organizations that collect and retain this information, the greater the cybersecurity and privacy risk. Multiple compliance files mean more databases, cloud-storage environments, user accounts, technology integrations, and vendors with access to sensitive material.

A single AML agent model would reduce that exposure by centralizing the collection and secure retention of the most sensitive information. Other participants would receive only the confirmations, reports, and information reasonably needed for their own obligations.

Safeguards for a Reliance Model

A statutory reliance framework should apply only where appropriate safeguards are satisfied. These should include:

  • a written AML-agent and reliance agreement;
  • prescribed competency, insurance, cybersecurity, and recordkeeping standards for AML agents;
  • standardized identity-verification and risk-assessment procedures;
  • privacy-compliant borrower consent and information-sharing protocols;
  • secure and auditable access to relevant compliance confirmations and records;
  • defined roles for monitoring, escalation, reporting, and record retention;
  • audit rights for participating entities and FINTRAC;
  • requirements to update information when relevant circumstances change; and
  • a meaningful statutory safe harbour where a participant reasonably relies on current, compliant AML-agent work and has no reason to doubt its accuracy.

The agent should be subject to clear performance standards. Technology providers can support the process, but they should not be allowed to shift all responsibility and risk back to mortgage professionals through broad contractual disclaimers.

A Staged and Proportionate Process

Not every mortgage application proceeds to funding, and not every transaction presents the same level of risk.

The AML process should therefore be staged. At application, the AML agent should conduct initial identity verification, screening, third-party inquiries, and a preliminary risk assessment. More extensive diligence—such as detailed source-of-funds inquiries, beneficial ownership verification, or enhanced due diligence—should generally be completed only once the transaction reaches a meaningful stage, such as conditional approval, a signed commitment, or pre-funding.

A borrower who withdraws, selects another lender, fails to satisfy underwriting conditions, or elects not to proceed should not automatically be treated as suspicious. The agent should close the file as withdrawn, declined, or not completed, subject to further review only where there are genuine red flags.

This approach would preserve robust scrutiny for higher-risk activity without imposing the full compliance burden on every tentative application.

Transparent Compliance Costs

AML/ATF compliance is not cost-free. It requires trained personnel, screening tools, secure data storage, recordkeeping systems, and enhanced diligence where justified.

The current model does not avoid those costs. It duplicates them. Brokers, lenders, administrators, lawyers, and compliance technology providers may each charge, absorb, or indirectly pass on costs for overlapping work.

A single AML agent model would make the cost more transparent and more proportionate. The originating broker or lender could absorb modest initial screening as a normal cost of opening a mortgage file. More extensive transaction-specific work could be completed once the file reaches a commitment or pre-funding stage.

Any borrower-facing AML/ATF compliance fee should be clearly disclosed before it becomes payable, separately identified from other fees, proportionate to the work required, and permitted by law.

Better Regulation, Not Less Regulation

FINTRAC’s mortgage guidance confirms that brokers, lenders, and administrators may each have separate AML/ATF responsibilities. It also shows why mortgage compliance needs a coordinated framework.

A single AML agent model would allow sensitive information to be collected and verified once, through a secure and accountable process. It would reduce repetitive borrower requests, lower privacy and cybersecurity exposure, improve operational efficiency, and allow mortgage professionals to focus on meaningful financial-crime risks.

The objective is not less AML/ATF compliance.

It is smarter, more secure, and more effective compliance.

Sign up for our news

Regulatory updates delivered as they happen.

Upcoming Webinars

No event found
join CAPL

Become a member

Stay informed with the latest industry insights.
Gain access to distinguished expert speaker webinars and our industry events.