When you hear “anti-money laundering” (AML), you might immediately think of banks, financial institutions, or large compliance teams.
But for accountants and bookkeepers, AML can be much closer to the day-to-day work than it first appears.
Payroll and accounting professionals often have a unique view into how a business operates. You may see employee records, payroll changes, invoices, payments, ownership information, and other financial activity over time. That visibility can sometimes reveal activity that simply doesn’t fit what you know about a client or their business.
That doesn’t mean you’re expected to become a financial crime investigator.
It does mean you need to understand where your formal obligations begin, where your exposure exists, and what to do when something doesn’t add up.
That was the focus of a recent PaymentEvolution conversation with Mohit Gogna of Platino Consulting, who has more than a decade of experience in financial crime and AML compliance.
Here are the key takeaways for Canadian accountants and bookkeepers.
First: Working with financial information doesn’t automatically make you subject to FINTRAC
One of the most important distinctions discussed was the difference between working with financial information and being formally subject to Canada's AML requirements.
Your job title alone doesn't determine whether FINTRAC requirements apply to you.
For accountants and accounting firms, certain activities can trigger obligations under Canada's anti-money laundering legislation. These can include acting on behalf of a client or giving instructions on a client's behalf in activities involving things such as receiving or paying funds, transferring funds or virtual currency, purchasing or selling securities, real estate, or business assets.
So the better question isn't:
“Do I work in payroll?”
It's:
“What am I actually doing for my client?”
For example, there can be an important difference between receiving payroll information, calculating payroll, and preparing records that a client uses to make payments, and actually acting on the client's behalf to direct or make those payments.
That distinction is why understanding your workflow matters.
Ask yourself:
What information does the client provide?
What authority have they given us?
Are we calculating or recording something, or acting on the client's behalf?
Do we receive, control, transfer, or direct funds?
Who ultimately authorizes the movement of money?
What decisions are we making for the client?
It's also important not to assume that providing bookkeeping services automatically makes someone an “accountant” under the legislation. The legislation has a specific definition, so the nature of the services and activities matters.
The takeaway?
Don't assume you're in scope, and don't assume you're out of scope. Understand what your business actually does.
If you're unsure after assessing your activities, that's when professional advice about your specific circumstances can help.
Legal obligation and risk exposure aren't the same thing
Even if your work doesn't put you under formal FINTRAC reporting requirements, that doesn't mean AML-related risks disappear.
This is where the distinction between obligation and exposure becomes important.
Your legal obligations ask:
What does the law require me to do?
Your exposure asks:
What risks am I encountering through the work I perform?
Those aren't necessarily the same question.
Consider a client you've worked with for several years. They've consistently had around 12 employees, and suddenly you're given payroll information for 35.
That doesn't mean money laundering is happening.
Maybe the business landed a major contract. Maybe it acquired another company. Maybe it expanded rapidly.
But the change is significant enough that you may reasonably want to understand it.
The same applies if:
Several seemingly unrelated employees share unusual information.
Client documentation repeatedly conflicts with what you've previously been told.
The client's financial activity doesn't appear consistent with the size or nature of the business.
A client is unusually reluctant to provide basic information needed to perform your work.
There are unusual connections between employees, businesses, or payment information.
None of these things proves financial crime.
They're signals that may warrant a closer look.
Seeing a red flag doesn't automatically mean filing an STR
This is an important distinction, and one worth getting right.
If you aren't subject to FINTRAC's reporting requirements, seeing something unusual doesn't suddenly create an obligation for you to file an STR.
Your response may be to ask reasonable questions, follow your firm's escalation procedures, consider whether you're comfortable continuing with the activity, or determine whether another professional or legal obligation applies.
Separately, anyone can voluntarily provide information to FINTRAC about suspected money laundering or terrorist financing.
The important point is that spotting a red flag isn't the same thing as determining that money laundering has occurred, and it isn't automatically a reporting obligation for someone who isn't a reporting entity.
For professionals who are subject to the PCMLTFA, the analysis is different. Suspicious activity needs to be assessed against the applicable legal threshold for suspicious transaction reporting, including whether there are reasonable grounds to suspect.
Either way, context matters.
One unusual fact might have a completely reasonable explanation. Several inconsistencies together may tell a very different story.
The goal isn't to become a detective.
It's to ask:
“Does what I'm seeing make sense based on what I know?”
And if it doesn't, “What do I need to understand before I continue?”
What does AML look like in a payroll environment?
There isn't a special FINTRAC checklist that says, “Here are the top payroll money laundering red flags.”
Instead, established financial crime indicators need to be considered in the context of the work you're actually performing.
For payroll professionals, that starts with knowing your client.
1. Dramatic payroll changes without an obvious explanation
A sudden increase or decrease in employees can be perfectly legitimate. But if the change doesn't align with what you know about the business, it's worth understanding why.
2. Payments involving people who don't appear connected to the business
If you're seeing individuals receiving payments who don't appear to have an obvious relationship with the organization, that may warrant additional questions.
3. Conflicting documentation
When the information you're receiving repeatedly doesn't line up with previous explanations or records, that's another reason to pause.
4. Reluctance to provide basic information
Clients don't always have perfect records. But unusual reluctance to provide information that would ordinarily be necessary to perform your work can be a signal worth considering.
5. Activity that doesn't fit the business
Ask whether the overall activity makes sense given the company's size, industry, ownership, and business model.
Again, none of these indicators proves wrongdoing.
A rapidly growing payroll could simply mean the business is doing extremely well. An unusual payment arrangement could have a legitimate explanation. Poor documentation could just mean the client needs better administration.
Facts plus context are what matter.
If you ask a reasonable question and receive a reasonable, verifiable explanation, that context changes the picture.
If every reasonable question creates another inconsistency, that matters too.
You don't need a 150-page AML manual to start
For firms that aren't formally subject to the PCMLTFA's compliance program requirements, building sensible controls doesn't have to mean creating a massive compliance department.
The principles discussed in the conversation can be scaled to the size and risk of your business.
Know who you're doing business with
Start with the basics:
Who is the client?
What does the business actually do?
Who owns or controls it?
What services are you providing?
Does the activity you're being asked to perform make sense?
Not every client presents the same level of risk.
A local business you've worked with for 10 years may look very different from a newly incorporated company with complex international ownership asking you to perform unusual financial activities.
Create clear procedures
The goal isn't to create a manual that sits on a shelf gathering dust.
Your procedures should answer practical questions:
When something unusual happens, what do we do?
For example:
Who does an employee tell?
Who decides whether more information is needed?
When do we escalate a concern?
When might we decline an instruction?
When might we reconsider a client relationship?
If we're a reporting entity, who determines whether a FINTRAC report is required?
Good procedures make the next step clear before someone is faced with a difficult situation.
Train your team
People need to understand not only what AML is, but what it looks like in the context of their specific industry.
Training for accountants and bookkeepers shouldn't necessarily look identical to training for an MSB or another regulated sector.
The underlying AML and anti-terrorist financing principles may be shared, but the risks people encounter in their day-to-day work can be very different.
Document what you did
This was one of the strongest themes from the discussion:
It's not enough to do the right thing. You need to be able to show that you did it.
You might have an excellent conversation with a client, ask the right questions, resolve a concern, and move forward appropriately.
But if nothing is documented, someone reviewing that client file six months later may have no idea that the conversation ever happened.
Documentation doesn't have to mean expensive software or complicated systems. Even handwritten records can work, provided they accurately document what was done, when it was done, and who was involved.
For businesses subject to formal FINTRAC requirements, record-keeping obligations are particularly important.
A practical AML exercise you can do today
You don't need to overhaul your entire business in one afternoon.
Instead, start with two exercises.
Exercise 1: Map your workflow
Take the services you provide and document what actually happens.
For payroll, ask:
What does the client send us?
What do we do with that information?
Do we ever receive or control client money?
Do we give instructions regarding the movement of client money?
Who authorizes payments?
What access do we have?
What decisions are we making on the client's behalf?
Do the same exercise for your accounting, bookkeeping, payroll, and other financial services.
This can help you identify whether any of your activities may create formal AML obligations, and can also reveal operational risks you may want to address.
Exercise 2: Test one client file
Pick one reasonably representative client.
Pretend you're someone who has never worked with that client before and will be reviewing the file six months from now.
Could you answer:
Who is this client?
What does the business do?
Who owns or controls it, where relevant?
What services are we providing?
Does the activity make sense for this client?
Did anything unusual happen?
If something unusual happened, what did we do about it?
If you know all the answers but none of them are documented, you've identified a documentation gap.
If you can't answer some of the questions at all, you've identified a different kind of gap.
Either way, you've found somewhere practical to start.
AML compliance starts with understanding your own workflow
For accountants and bookkeepers, AML doesn't have to mean turning your practice into a bank-sized compliance operation.
It starts with understanding what you actually do, knowing where your formal obligations may apply, recognizing when something doesn't make sense, and having a clear process for what happens next.
And there's another practical benefit to getting your processes in order.
Payment providers and financial institutions may ask for information about your clients, including what a business does and who owns or controls it. If you already have that information organized, responding to those requests can become much easier.
Ultimately, the goal isn't to investigate every unusual transaction or treat every red flag as evidence of financial crime.
It's to build a practice where you can confidently answer:
Who is my client? What am I doing for them? Does what I'm seeing make sense? And if it doesn't, do I know what to do next?
That's a much more practical place to start.
If you have any questions about building your AML program, reach out to Platino Consulting for help:
This article is intended for general informational purposes and does not constitute legal or compliance advice. Whether specific AML obligations apply depends on the activities and circumstances of a particular business. Firms should consult FINTRAC guidance and qualified professional advisors regarding their specific situation.
When you hear “anti-money laundering” (AML), you might immediately think of banks, financial institutions, or large compliance teams.
But for accountants and bookkeepers, AML can be much closer to the day-to-day work than it first appears.
Payroll and accounting professionals often have a unique view into how a business operates. You may see employee records, payroll changes, invoices, payments, ownership information, and other financial activity over time. That visibility can sometimes reveal activity that simply doesn’t fit what you know about a client or their business.
That doesn’t mean you’re expected to become a financial crime investigator.
It does mean you need to understand where your formal obligations begin, where your exposure exists, and what to do when something doesn’t add up.
That was the focus of a recent PaymentEvolution conversation with Mohit Gogna of Platino Consulting, who has more than a decade of experience in financial crime and AML compliance.
Here are the key takeaways for Canadian accountants and bookkeepers.
First: Working with financial information doesn’t automatically make you subject to FINTRAC
One of the most important distinctions discussed was the difference between working with financial information and being formally subject to Canada's AML requirements.
Your job title alone doesn't determine whether FINTRAC requirements apply to you.
For accountants and accounting firms, certain activities can trigger obligations under Canada's anti-money laundering legislation. These can include acting on behalf of a client or giving instructions on a client's behalf in activities involving things such as receiving or paying funds, transferring funds or virtual currency, purchasing or selling securities, real estate, or business assets.
So the better question isn't:
“Do I work in payroll?”
It's:
“What am I actually doing for my client?”
For example, there can be an important difference between receiving payroll information, calculating payroll, and preparing records that a client uses to make payments, and actually acting on the client's behalf to direct or make those payments.
That distinction is why understanding your workflow matters.
Ask yourself:
What information does the client provide?
What authority have they given us?
Are we calculating or recording something, or acting on the client's behalf?
Do we receive, control, transfer, or direct funds?
Who ultimately authorizes the movement of money?
What decisions are we making for the client?
It's also important not to assume that providing bookkeeping services automatically makes someone an “accountant” under the legislation. The legislation has a specific definition, so the nature of the services and activities matters.
The takeaway?
Don't assume you're in scope, and don't assume you're out of scope. Understand what your business actually does.
If you're unsure after assessing your activities, that's when professional advice about your specific circumstances can help.
Legal obligation and risk exposure aren't the same thing
Even if your work doesn't put you under formal FINTRAC reporting requirements, that doesn't mean AML-related risks disappear.
This is where the distinction between obligation and exposure becomes important.
Your legal obligations ask:
What does the law require me to do?
Your exposure asks:
What risks am I encountering through the work I perform?
Those aren't necessarily the same question.
Consider a client you've worked with for several years. They've consistently had around 12 employees, and suddenly you're given payroll information for 35.
That doesn't mean money laundering is happening.
Maybe the business landed a major contract. Maybe it acquired another company. Maybe it expanded rapidly.
But the change is significant enough that you may reasonably want to understand it.
The same applies if:
Several seemingly unrelated employees share unusual information.
Client documentation repeatedly conflicts with what you've previously been told.
The client's financial activity doesn't appear consistent with the size or nature of the business.
A client is unusually reluctant to provide basic information needed to perform your work.
There are unusual connections between employees, businesses, or payment information.
None of these things proves financial crime.
They're signals that may warrant a closer look.
Seeing a red flag doesn't automatically mean filing an STR
This is an important distinction, and one worth getting right.
If you aren't subject to FINTRAC's reporting requirements, seeing something unusual doesn't suddenly create an obligation for you to file an STR.
Your response may be to ask reasonable questions, follow your firm's escalation procedures, consider whether you're comfortable continuing with the activity, or determine whether another professional or legal obligation applies.
Separately, anyone can voluntarily provide information to FINTRAC about suspected money laundering or terrorist financing.
The important point is that spotting a red flag isn't the same thing as determining that money laundering has occurred, and it isn't automatically a reporting obligation for someone who isn't a reporting entity.
For professionals who are subject to the PCMLTFA, the analysis is different. Suspicious activity needs to be assessed against the applicable legal threshold for suspicious transaction reporting, including whether there are reasonable grounds to suspect.
Either way, context matters.
One unusual fact might have a completely reasonable explanation. Several inconsistencies together may tell a very different story.
The goal isn't to become a detective.
It's to ask:
“Does what I'm seeing make sense based on what I know?”
And if it doesn't, “What do I need to understand before I continue?”
What does AML look like in a payroll environment?
There isn't a special FINTRAC checklist that says, “Here are the top payroll money laundering red flags.”
Instead, established financial crime indicators need to be considered in the context of the work you're actually performing.
For payroll professionals, that starts with knowing your client.
1. Dramatic payroll changes without an obvious explanation
A sudden increase or decrease in employees can be perfectly legitimate. But if the change doesn't align with what you know about the business, it's worth understanding why.
2. Payments involving people who don't appear connected to the business
If you're seeing individuals receiving payments who don't appear to have an obvious relationship with the organization, that may warrant additional questions.
3. Conflicting documentation
When the information you're receiving repeatedly doesn't line up with previous explanations or records, that's another reason to pause.
4. Reluctance to provide basic information
Clients don't always have perfect records. But unusual reluctance to provide information that would ordinarily be necessary to perform your work can be a signal worth considering.
5. Activity that doesn't fit the business
Ask whether the overall activity makes sense given the company's size, industry, ownership, and business model.
Again, none of these indicators proves wrongdoing.
A rapidly growing payroll could simply mean the business is doing extremely well. An unusual payment arrangement could have a legitimate explanation. Poor documentation could just mean the client needs better administration.
Facts plus context are what matter.
If you ask a reasonable question and receive a reasonable, verifiable explanation, that context changes the picture.
If every reasonable question creates another inconsistency, that matters too.
You don't need a 150-page AML manual to start
For firms that aren't formally subject to the PCMLTFA's compliance program requirements, building sensible controls doesn't have to mean creating a massive compliance department.
The principles discussed in the conversation can be scaled to the size and risk of your business.
Know who you're doing business with
Start with the basics:
Who is the client?
What does the business actually do?
Who owns or controls it?
What services are you providing?
Does the activity you're being asked to perform make sense?
Not every client presents the same level of risk.
A local business you've worked with for 10 years may look very different from a newly incorporated company with complex international ownership asking you to perform unusual financial activities.
Create clear procedures
The goal isn't to create a manual that sits on a shelf gathering dust.
Your procedures should answer practical questions:
When something unusual happens, what do we do?
For example:
Who does an employee tell?
Who decides whether more information is needed?
When do we escalate a concern?
When might we decline an instruction?
When might we reconsider a client relationship?
If we're a reporting entity, who determines whether a FINTRAC report is required?
Good procedures make the next step clear before someone is faced with a difficult situation.
Train your team
People need to understand not only what AML is, but what it looks like in the context of their specific industry.
Training for accountants and bookkeepers shouldn't necessarily look identical to training for an MSB or another regulated sector.
The underlying AML and anti-terrorist financing principles may be shared, but the risks people encounter in their day-to-day work can be very different.
Document what you did
This was one of the strongest themes from the discussion:
It's not enough to do the right thing. You need to be able to show that you did it.
You might have an excellent conversation with a client, ask the right questions, resolve a concern, and move forward appropriately.
But if nothing is documented, someone reviewing that client file six months later may have no idea that the conversation ever happened.
Documentation doesn't have to mean expensive software or complicated systems. Even handwritten records can work, provided they accurately document what was done, when it was done, and who was involved.
For businesses subject to formal FINTRAC requirements, record-keeping obligations are particularly important.
A practical AML exercise you can do today
You don't need to overhaul your entire business in one afternoon.
Instead, start with two exercises.
Exercise 1: Map your workflow
Take the services you provide and document what actually happens.
For payroll, ask:
What does the client send us?
What do we do with that information?
Do we ever receive or control client money?
Do we give instructions regarding the movement of client money?
Who authorizes payments?
What access do we have?
What decisions are we making on the client's behalf?
Do the same exercise for your accounting, bookkeeping, payroll, and other financial services.
This can help you identify whether any of your activities may create formal AML obligations, and can also reveal operational risks you may want to address.
Exercise 2: Test one client file
Pick one reasonably representative client.
Pretend you're someone who has never worked with that client before and will be reviewing the file six months from now.
Could you answer:
Who is this client?
What does the business do?
Who owns or controls it, where relevant?
What services are we providing?
Does the activity make sense for this client?
Did anything unusual happen?
If something unusual happened, what did we do about it?
If you know all the answers but none of them are documented, you've identified a documentation gap.
If you can't answer some of the questions at all, you've identified a different kind of gap.
Either way, you've found somewhere practical to start.
AML compliance starts with understanding your own workflow
For accountants and bookkeepers, AML doesn't have to mean turning your practice into a bank-sized compliance operation.
It starts with understanding what you actually do, knowing where your formal obligations may apply, recognizing when something doesn't make sense, and having a clear process for what happens next.
And there's another practical benefit to getting your processes in order.
Payment providers and financial institutions may ask for information about your clients, including what a business does and who owns or controls it. If you already have that information organized, responding to those requests can become much easier.
Ultimately, the goal isn't to investigate every unusual transaction or treat every red flag as evidence of financial crime.
It's to build a practice where you can confidently answer:
Who is my client? What am I doing for them? Does what I'm seeing make sense? And if it doesn't, do I know what to do next?
That's a much more practical place to start.
If you have any questions about building your AML program, reach out to Platino Consulting for help:
This article is intended for general informational purposes and does not constitute legal or compliance advice. Whether specific AML obligations apply depends on the activities and circumstances of a particular business. Firms should consult FINTRAC guidance and qualified professional advisors regarding their specific situation.
Get a 15-day free trial today,
no credit card required.
See why 20,000+ businesses trust PayEvo to handle their payroll, benefits management, and HR solutions every day.
No spam. Opt-out or cancel anytime.
Get a 15-day free trial today,
no credit card required.
See why 20,000+ businesses trust PayEvo to handle their payroll, benefits management, and HR solutions every day.
No spam. Opt-out or cancel anytime.





