As of mid-2026
FINTRAC's Most Wanted
Failing to develop and apply written compliance policies and procedures
By Cracky we've made it!
We made it to number one on our FINTRAC's Most Wanted countdown.
We're at the #1 reason why companies in Canada got fined for AML deficiencies.
Since last year, a staggering 26 companies were penalized with: "Failing to develop and apply written compliance policies and procedures."
That is nearly double the next closest infraction, so if you only focus on one thing this year it should be this.
Many firms have this beautiful hundred page policy document and it's just sitting on a desk somewhere. But regulators don't care how good your prose is — they care how you actually apply the rules.
The number one fine happens when there's a gap between what your policy says and what your team actually does.
If your manual says you need to "screen all clients against sanctions" lists but your software doesn't actually enforce that screening or it isn't set up to actually block a transaction, you failed to apply your own program here.
This is exactly why we built Rhizome.
We don't just host your policies or recommend certain language, we take your policies and we turn them into code and workflows.
Our system bridges the gap between the written word and the daily operations.
We even have a policy editing tool with a Git or GitHub-style workflow that engineers use and what this means is basically every change, every executive approval, and every update is tracked, time stamped, and fully auditable.
So when a regulator asks, "when's the last time you updated your policies?" you actually pull down the full history and show them a detailed audit trail of everything that changed and it'll prove that you're on top of things.
Don't let your policy be a work of fiction.
Reach out to us to see how we can turn your policies into real workflows.