FINTRAC and AGLC AML Obligations in Alberta iGaming: Two Compliance Layers, One Operator
Alberta iGaming operators face a dual AML burden: federal FINTRAC reporting under PCMLTFA and AGLC's own SRIG standards. This guide separates both layers with actionable precision.
Alberta’s regulated iGaming market launched on July 13, 2026, placing private operators inside two simultaneous AML compliance regimes: the federal framework administered by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and the provincial framework set out in the Alberta Gaming, Liquor and Cannabis Commission’s (AGLC) Standards and Requirements for Internet Gaming (SRIG), issued January 14, 2026. Most operator guides treat these as a single checklist. They are not. Each regime has distinct triggers, distinct documentation obligations, and distinct recipients. Conflating them produces gaps in both, and FINTRAC’s enforcement record shows those gaps carry real penalties.
What does ‘reporting entity’ mean for Alberta iGaming operators?
Under the PCMLTFA, casinos are named as reporting entities. FINTRAC guidance confirms that a casino is any entity that operates a slot machine, a gaming table, or a lottery scheme for cash or cash equivalents. Alberta’s iGaming market is structured as a regulated online lottery scheme under the iGaming Alberta Act and the Gaming, Liquor and Cannabis Act (Alberta), and operators registered under the SRIG are therefore subject to the PCMLTFA casino reporting obligations from the date they begin accepting real-money play.
The critical structural point is that FINTRAC obligations attach to the reporting entity directly. As FINTRAC’s compliance guidance makes clear, the legal responsibility under the PCMLTFA cannot be delegated. Even where a service provider submits reports on an operator’s behalf, accountability remains with the operator. This matters in Alberta because the AGLC Go-Live Compliance Guide assigns AML and financial reporting oversight partly to Alberta’s iGaming Corporation (AiGC), and AGLC’s published FAQ directs FINTRAC process inquiries to AiGC. Operators must understand that AiGC’s commercial and administrative role does not transfer their PCMLTFA status as a reporting entity. FINTRAC does not recognise AiGC as an intermediary for statutory reporting purposes.
Key structural point: Alberta iGaming operators are FINTRAC reporting entities under the PCMLTFA from day one of operation. AGLC’s delegation of AML administrative functions to AiGC does not affect that statutory status. Operators must enrol directly with FINTRAC’s Web Reporting System (FWR) before accepting real-money play.
FINTRAC reporting obligations: the four transaction types that apply to online gaming
FINTRAC’s guidance identifies five primary report types that apply to casinos as reporting entities. Of these, four are directly relevant to online gaming operations in Alberta.
Suspicious Transaction Reports (STRs) are the most operationally significant. Under the reporting provisions of the PCMLTFA and the Proceeds of Crime (Money Laundering) and Terrorist Financing Suspicious Transaction Reporting Regulations (SOR/2001-317), a reporting entity must submit an STR when a financial transaction occurs, or is attempted, in the course of its activities and there are reasonable grounds to suspect that the transaction is related to the commission or attempted commission of a money laundering or terrorist activity financing offence. There is no monetary floor. An attempted $50 transaction exhibiting structural indicators must be reported. FINTRAC guidance on the STR standard is explicit: reasonable grounds to suspect is a step above simple suspicion, meaning there is a possibility that an offence has occurred, but the reporter does not need to verify the facts or prove that an offence was committed.
Large Cash Transaction Reports (LCTRs) are required whenever a reporting entity receives CAD $10,000 or more in cash in a single transaction. The 24-hour aggregation rule extends this: two or more cash amounts totalling $10,000 or more within a consecutive 24-hour window, where the reporting entity knows they are conducted by, on behalf of, or for the benefit of the same person or entity, must also be reported under the PCMLTFA Regulations (SOR/2002-184, section 126). For online platforms, ‘cash’ for LCTR purposes includes bank notes and coins, digital payment rails are generally handled under the EFT reporting stream rather than the LCTR stream, though the specific method of deposit determines which obligation applies.
Electronic Funds Transfer Reports (EFTRs) apply when a reporting entity sends or receives an international electronic funds transfer of CAD $10,000 or more at the request of a client. For domestic transfers, a different threshold and trigger apply, compliance teams must consult the sector-specific EFT guidance published by FINTRAC when mapping this obligation to their payment architecture.
Casino Disbursement Reports (CDRs) require reporting when a casino disburses CAD $10,000 or more to, or on behalf of, a person in a single transaction or in amounts that cumulatively total $10,000 or more within a 24-hour window. In an online context, a player withdrawal processed by cheque or wire that meets the threshold is a disbursement. Operators whose platforms process large withdrawal requests should build CDR triggers into their payment system workflow, not their back-office AML review queue: the timing of the disbursement, not the timing of a compliance review, starts the reporting clock.
| Report Type | Trigger | Monetary Threshold | Timeframe to Submit (per FINTRAC guidance) |
|---|---|---|---|
| Suspicious Transaction Report (STR) | Reasonable grounds to suspect ML/TF | None | As soon as practicable after reasonable grounds established |
| Large Cash Transaction Report (LCTR) | Receipt of cash | CAD $10,000 (single or 24-hr aggregation) | Per FINTRAC LCTR guidance, verify current deadline via FWR |
| Electronic Funds Transfer Report (EFTR) | International EFT sent or received | CAD $10,000 | Per FINTRAC EFT guidance, verify current deadline via FWR |
| Casino Disbursement Report (CDR) | Disbursement by casino | CAD $10,000 (single or 24-hr aggregation) | Per FINTRAC CDR guidance, verify current deadline via FWR |
As of July 2026, based on PCMLTFA and FINTRAC published guidance. Confirm current submission deadlines directly via the FINTRAC Web Reporting System before go-live.
What does ‘reasonable grounds to suspect’ actually require?
FINTRAC’s guidance defines reasonable grounds to suspect as requiring the reporting entity to have considered the facts, context, and money laundering or terrorist financing indicators related to a financial transaction, and to have concluded, based on that review, that there is a possibility the transaction is related to a money laundering or terrorist activity financing offence. The analysis must be demonstrable: the reporter must be able to articulate the suspicion in such a way that another individual with similar knowledge, experience, or training would be able to reach the same conclusion.
“You are required to submit a Suspicious Transaction Report when you have completed the measures that enable you to establish that there are reasonable grounds to suspect that a transaction is related to the commission of a money laundering or terrorist activity financing offence. Reasonable grounds to suspect is a step above simple suspicion, meaning that there is a possibility that a money laundering or terrorist activity financing offence has occurred.”
Source: FINTRAC, Suspicious Transaction Reporting Requirements Guidance, published on fintrac-canafe.gc.ca.
A common deficiency FINTRAC identifies in assessments is reporting entities using a higher threshold as their basis for reporting, for example waiting until a transaction exceeds $10,000 before generating an STR, or treating the LCTR threshold as an implied minimum for suspicious reporting. The two obligations operate independently. An operator who files an LCTR for a $15,000 cash-equivalent deposit but does not file an STR when that same deposit exhibits multiple layering indicators has only satisfied half of the reporting obligation. Alberta iGaming operators must design their transaction monitoring rules accordingly: STR triggers must operate on behavioural and contextual indicators, not on amount alone.
The FINTRAC compliance program: five mandatory elements
Every reporting entity is required to establish and maintain a compliance program under the PCMLTFA. FINTRAC’s compliance program guidance identifies five mandatory elements.
A designated compliance officer must be appointed with the necessary authority to implement the program. This person holds documented responsibility for the reporting entity’s AML obligations and is the named contact for FINTRAC’s liaison and examination processes. For Alberta iGaming operators, the compliance officer’s mandate must cover PCMLTFA obligations specifically, a combined responsible gambling and AML compliance officer role carries risk if the PCMLTFA-specific functions are not given adequate operational priority.
Written policies and procedures must describe the processes for identifying, assessing, and reporting suspicious transactions, meeting large cash, EFT, and disbursement reporting obligations, verifying client identity, conducting enhanced due diligence, and applying ongoing monitoring. FINTRAC expects these documents to be current, operationally specific, and tested against the reporting entity’s actual transaction flow, not a generic template.
A risk assessment must be conducted covering the reporting entity’s business model, products, delivery channels, geography, and client base. For online gaming, FINTRAC expects the risk assessment to address the specific vulnerabilities of a faceless transaction environment: rapid fund cycling, anonymous payment instruments, cross-border player activity, and the use of virtual currency where applicable.
A training program must be written, implemented, and updated when the reporting entity’s obligations change. It must cover all employees who handle transactions or exercise compliance functions.
A two-year effectiveness review, conducted by an internal or external auditor, must test the effectiveness of the policies and procedures, risk assessment, and training program at a minimum every two years. The review is not a formality: FINTRAC’s examination process specifically assesses whether effectiveness reviews are conducted on schedule and whether identified deficiencies are remediated.
What the AGLC SRIG adds on top of FINTRAC obligations
The AGLC SRIG does not incorporate FINTRAC obligations by reference and leave it at that. The AML provisions within the SRIG impose a parallel set of provincial requirements that registered operators must meet in addition to, and in alignment with, their PCMLTFA obligations.
The SRIG requires registered operators and registered goods or services suppliers to establish and maintain a comprehensive internal AML and terrorist financing (AML/TF) program in compliance with the PCMLTFA, associated regulations, FINTRAC guidelines, and the designated reporting entity’s AML/TF policies and procedures. This last element is operationally significant: the SRIG mandates that anti-money laundering internal controls align with those of the designated reporting entity under the PCMLTFA. In Alberta’s market structure, where AiGC occupies a commercial intermediary role, operators must resolve which entity holds designated reporting entity status for their specific registration and then ensure their internal controls are structurally aligned with that entity’s program, not simply with FINTRAC guidelines in the abstract.
Registered operators and registered goods or services suppliers must implement and comply with risk-based policies, procedures and controls that provide for escalating measures to address players that engage in behaviors consistent with money laundering, terrorist financing or sanction evasion indicators, including the refusal of transactions or exclusion of the player.
Source: AGLC, Standards and Requirements for Internet Gaming (SRIG), issued January 14, 2026, AML provisions within General Standards and Requirements.
Beyond the program alignment obligation, the SRIG imposes three specific operational requirements that sit above the FINTRAC baseline.
Source of funds verification must be built into the operator’s risk framework. The SRIG requires registered operators to specify times and situations, based on the assessment of risk, where they will ascertain and reasonably corroborate a player’s source of funds. This is a risk-stratified obligation rather than a fixed-threshold trigger: operators must define the circumstances in their policies and procedures, not merely respond to FINTRAC-reportable thresholds. High-volume deposit players, rapid cycling between deposit and withdrawal, and inconsistency between stated occupation and wagering volume are the standard indicators that should activate source of funds processes under a risk-calibrated policy.
Suspicious Transaction Report obligations are expressly stated in the SRIG. Registered operators and registered goods or services suppliers must submit STRs in respect of activities that occur in the course of providing goods or services to registered operators. The SRIG also states that copies of all FINTRAC reports and supporting records must be made available to AGLC in accordance with the notification matrix established by AGLC. This creates a dual-disclosure obligation: STRs go to FINTRAC through the FINTRAC Web Reporting System, and their existence, with supporting records, must be disclosed to AGLC under a separate notification framework. Operators who treat FINTRAC filing as their sole reporting obligation are missing the provincial disclosure requirement entirely.
Information sharing with other operators is a SRIG-specific obligation that has no direct equivalent in the PCMLTFA’s reporting framework. The SRIG requires that mechanisms be in place to share information, in a lawful manner, related to high-risk, suspicious, or criminal activities with other operators who may also be subject to similar activity. This inter-operator intelligence sharing obligation must be operationalised through documented procedures that satisfy both the sharing obligation and the constraints of Alberta’s Personal Information Protection Act (PIPA).
The AGLC notification matrix: a separate disclosure channel
The AGLC Notification Matrix, published as part of the SRIG framework, governs when and how registered operators must notify AGLC of specific events and activities. AML-related notifications fall within this matrix’s scope. Operators must provide AGLC with access to FINTRAC reports and supporting records when requested, and the matrix also establishes proactive notification obligations triggered by defined events, not solely by AGLC request.
An operator’s AML compliance calendar must therefore include two separate event-driven workflows. The FINTRAC submission workflow routes STRs, LCTRs, EFTRs, and CDRs to FINTRAC through the FWR within prescribed timeframes. The AGLC notification workflow routes disclosures to AGLC under the notification matrix when triggered. These workflows share the same underlying transaction monitoring input, but their outputs go to different recipients, on different timelines, under different legal authorities. Compliance teams that build a single unified AML report process without distinguishing the two channels create regulatory gaps with both FINTRAC and AGLC simultaneously.
Enforcement context: what FINTRAC penalties look like for gaming entities
FINTRAC’s enforcement record for Canadian gaming entities provides a useful calibration for operators building their Alberta programs. In 2025-26, FINTRAC issued a record 35 notices of violation across all industries, totalling $247 million in administrative monetary penalties (AMPs), according to regulatory reporting from that period.
Within that enforcement cycle, three provincial gaming corporations faced penalties directly attributable to STR and compliance program failures. Atlantic Lottery Corporation paid $212,025 in penalties for three specific violations: failure to report suspicious transactions, outdated compliance policies, and inadequate risk assessment documentation. The New Brunswick Lotteries and Gaming Corporation was fined $399,712.50, and the Nova Scotia Gaming Corporation was fined $231,826, both for failures to identify common player identifiers, unverified identification documents, and suspicious transaction reporting lapses. According to reporting by BNN Bloomberg and Canadian Gaming Business in September 2026, both corporations have since paid their fines in full and implemented corrective measures.
None of these entities were found to have facilitated actual money laundering. The violations were administrative and procedural: missing reports, stale policies, inadequate risk assessments. FINTRAC’s AMP framework does not require proof of underlying criminal activity. A gap in documentation is a violation in its own right, and the penalty follows from the gap, not from the downstream consequence. Alberta iGaming operators, particularly those newer to the Canadian market, must treat this pattern as the operational baseline: FINTRAC examinations test documentation and process, not just outcomes.
Enforcement note: British Columbia’s BCLC and Saskatchewan Indian Gaming Authority (SIGA) are both contesting larger FINTRAC penalties in federal court as of mid-2026, according to reporting on the Atlantic Lottery decision. The outcomes of those proceedings may affect how the ‘reasonable grounds to suspect’ standard is applied to online gaming platforms. Operators should consult qualified legal counsel on their implications for Alberta compliance programs.
KYC obligations under FINTRAC: identity verification for online casino clients
FINTRAC’s casino client identification and KYC requirements establish identity verification obligations that apply at defined trigger points. For online gaming operators, the primary triggers are: before conducting a transaction of CAD $3,000 or more, when there are reasonable grounds to suspect that a transaction is related to money laundering or terrorist financing, and when processing a CDR. Identity verification must be completed using one of FINTRAC’s prescribed methods: government-issued photo identification, credit file verification, or the dual-process method.
The reliance method allows reporting entities to rely on identity verification performed by other reporting entities or affiliated foreign entities, provided a written agreement or arrangement is in place and the relying entity can obtain the verification information as soon as feasible upon request. Alberta operators using white-label platforms or shared KYC infrastructure must document the reliance arrangement explicitly and confirm its scope covers all PCMLTFA-required verification points. The arrangement’s existence must be reflected in the compliance policies and procedures.
For politically exposed persons (PEPs) and heads of international organizations (HIOs), enhanced due diligence applies. FINTRAC’s guidance on PEPs and HIOs requires casino reporting entities to take reasonable measures to determine whether a client is a PEP or HIO whenever they detect a fact that would require them to ascertain the source of funds or source of wealth. In Alberta’s online environment, automated PEP screening must be built into the onboarding workflow and triggered on an ongoing basis as player data is updated.
The AGCO parallel: how Ontario handles the same dual layer
Alberta’s dual-layer AML structure mirrors the framework in Ontario under the AGCO Registrar’s Standards for Internet Gaming. Standard 6.02 of the AGCO’s framework requires that AML policies and procedures to support PCMLTFA obligations be implemented and enforced, and that copies of all reports filed with FINTRAC and supporting records be made available to the AGCO Registrar in accordance with the established notification matrix. Standard 6.03 requires reasonable measures to identify and prevent suspected money laundering, including risk-based source of funds escalation and inter-operator information sharing.
The practical difference between Ontario and Alberta at this stage is the AiGC layer. In Ontario, the commercial counterpart is iGaming Ontario (iGO), and FINTRAC reporting runs directly between the registered operator and FINTRAC with AGCO notification under the AGCO notification matrix. In Alberta, the additional AiGC commercial agreement introduces ambiguity about which entity holds designated reporting entity status in specific factual configurations. Operators structured through the AiGC agreement should seek written confirmation from both AGLC and AiGC, supported by qualified legal counsel, before finalising their PCMLTFA compliance program designation. This is the single most important structuring question for Alberta AML programs in 2026, and it is not answered definitively by the publicly available SRIG text alone.
For a broader comparison of the AGCO and AGLC compliance frameworks, see AGCO vs AGLC: Key Differences in Ontario and Alberta Internet Gaming Regulation.
Building the integrated Alberta AML program: what compliance teams must document
An Alberta iGaming AML program that satisfies both FINTRAC and AGLC requirements must contain specific documented components, each traceable to the applicable source obligation.
The compliance program foundation under the PCMLTFA covers five areas. A designated compliance officer with documented authority must be named. Written policies and procedures covering all FINTRAC report types must be maintained. A business-risk assessment reflecting the operator’s specific Alberta product and player profile must be conducted. A staff training program with completion tracking must be implemented. A biennial effectiveness review plan with an assigned auditor and a schedule must be in place. These five elements satisfy FINTRAC’s compliance program requirements. Their absence or staleness is the most common basis for AMPs against gaming entities.
The AGLC-specific layer adds four further obligations. A documented source of funds policy that specifies risk-based triggers and corroboration standards must be maintained. A dual-disclosure workflow routing FINTRAC reports to FINTRAC and AGLC notifications to AGLC under the notification matrix must be operationalised. An inter-operator information-sharing mechanism that is documented, legally reviewed for PIPA compliance, and operationally tested must exist. A third-party management obligation requiring that any supplier providing AML-adjacent services is held to the same standards through contractual obligation must also be satisfied.
The SRIG is explicit on the third-party point. Registered operators and registered goods or services suppliers are responsible for the actions of third parties with whom they contract for the provision of any aspect of their business related to gaming in Alberta, and must require those third parties to conduct themselves as if they were bound by the same laws, regulations, and standards. For AML purposes, this means that KYC or transaction monitoring provided by a platform supplier must be contractually bound to PCMLTFA standards, not merely to general AML best practice.
For a full picture of the AGLC registration framework within which these AML obligations operate, see Alberta iGaming Market Opening: What Registered Operators Must Know About the AGLC SRIG Framework. For AML compliance lessons from Ontario’s three years of live operation under the same federal FINTRAC layer, see Ontario iGaming at Year Three: AGCO Compliance Lessons for New Entrants.
Frequently asked questions
Do Alberta iGaming operators need to register directly with FINTRAC? Yes. Every operator that begins accepting real-money play in Alberta is a casino reporting entity under the PCMLTFA and must enrol with FINTRAC’s Web Reporting System before submitting any required reports. AiGC’s commercial role does not substitute for direct FINTRAC registration. Operators must treat FINTRAC enrolment as a pre-launch prerequisite alongside AGLC registration.
Is there a minimum dollar amount before a Suspicious Transaction Report must be filed? No. STRs under the PCMLTFA have no monetary threshold. The filing obligation is triggered by reasonable grounds to suspect that a transaction relates to money laundering or terrorist financing, regardless of the transaction amount. A failed $20 deposit that exhibits layering indicators must be reported. Operators whose monitoring systems only flag transactions above a dollar threshold are non-compliant with the PCMLTFA STR regime.
How does AGLC get access to an operator’s FINTRAC reports? The AGLC SRIG requires registered operators to make copies of all reports filed with FINTRAC, and supporting records, available to AGLC in accordance with the AGLC Notification Matrix. This is a standing provincial disclosure obligation. It operates separately from FINTRAC’s tipping-off prohibition: the prohibition on informing a client that an STR has been filed does not prevent disclosure to the regulator.
What penalties does FINTRAC impose for AML failures in gaming? FINTRAC uses Administrative Monetary Penalties under the PCMLTFA. Recent gaming sector examples include $212,025 (Atlantic Lottery Corporation, 2026), $399,712.50 (New Brunswick Lotteries and Gaming Corporation, 2026), and $231,826 (Nova Scotia Gaming Corporation, 2026), all for procedural violations including STR failures, outdated policies, and inadequate risk assessments, none involving proven actual money laundering.
Does the AGLC SRIG require source of funds checks at a specific dollar threshold? No. The SRIG requires operators to specify, in their own policies and procedures, the times and situations based on risk assessment where they will ascertain and corroborate a player’s source of funds. The obligation is risk-based and policy-defined, not threshold-triggered. Operators must document their risk criteria and apply them consistently, AGLC assessments will test whether those criteria exist, whether they are reasonable, and whether they are operationally followed.
Key resources
AGLC, Standards and Requirements for Internet Gaming (SRIG), issued January 14, 2026, authority: AGLC Board Chair, available at aglc.ca/igaming.
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), Suspicious Transaction Reporting Requirements guidance, available at fintrac-canafe.gc.ca.
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), Reporting Large Cash Transactions guidance, available at fintrac-canafe.gc.ca.
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), Compliance Program Requirements guidance, available at fintrac-canafe.gc.ca.
Proceeds of Crime (Money Laundering) and Terrorist Financing Act, SC 2000, c 17, and associated Regulations including SOR/2001-317 and SOR/2002-184.
AGLC, Notification Matrix (published alongside the SRIG framework), available at aglc.ca/igaming.
Matt Denney
Editorial · gamingcompliance.io
Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.