FINTRAC Fines Two Canadian Gaming Corporations Over Anti-Money-Laundering Failures
- 1 day ago
- 6 min read
Canada’s financial intelligence regulator has imposed administrative monetary penalties totaling C$631,538.50 on two provincial gaming corporations after compliance examinations identified failures in their anti-money-laundering controls.

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) took enforcement action against Nova Scotia Gaming Corporation and New Brunswick Lotteries and Gaming Corporation over deficiencies involving suspicious transaction reporting. The Nova Scotia case also identified shortcomings in the corporation’s compliance policies, procedures and documented assessment of money-laundering risks.
The two enforcement actions were announced on September 3, 2026, although the penalties were imposed separately. Nova Scotia Gaming Corporation, based in Halifax, was penalized on July 23, while New Brunswick Lotteries and Gaming Corporation, headquartered in Fredericton, received its penalty on July 24.
Nova Scotia Gaming Corporation was ordered to pay C$231,826 after FINTRAC identified three administrative violations. One involved the failure to submit suspicious transaction reports in circumstances where there were reasonable grounds to suspect that attempted transactions were connected to a money-laundering offence.
The finding is significant because Canadian anti-money-laundering reporting obligations are not limited to transactions that are successfully completed. An attempted transaction can also become reportable when the available circumstances and information reach the applicable suspicion threshold.
FINTRAC also found that Nova Scotia Gaming Corporation had not developed and applied written compliance policies and procedures that were sufficiently current and approved by a senior officer. In addition, the corporation failed to adequately assess and document money-laundering risks while taking the prescribed risk factors into account.
Taken together, the findings point to shortcomings extending beyond an individual reporting decision. They concern the broader system used to identify unusual activity, evaluate its significance, escalate cases for review and determine whether a regulatory report must be filed.
New Brunswick Lotteries and Gaming Corporation received a C$399,712.50 penalty for a different, narrower violation. FINTRAC found that the corporation failed to submit reports when there were reasonable grounds to suspect that transactions were connected to a money-laundering offence.
Unlike the Nova Scotia enforcement action, the public notice concerning New Brunswick does not identify additional deficiencies involving written procedures or formal risk assessments.
The two cases therefore demonstrate related but distinct compliance problems. In one case, reporting failures were accompanied by weaknesses in governance and risk assessment. In the other, the enforcement action focused on the reporting obligation itself.
Suspicious Activity Reporting Remains a Central Casino Control
Casinos face particular financial-crime risks because customers can bring funds into a gaming environment, participate in gambling activity and subsequently receive value through casino-related payment mechanisms.
FINTRAC’s approach does not mean that every unusual transaction should automatically be treated as evidence of criminal conduct. Potential indicators of suspicious activity are warning signs that must be considered alongside the customer’s circumstances, transaction information and other available facts.
A single indicator may not be sufficient to establish reasonable grounds for suspicion. Multiple indicators, however, may become significant when combined with relevant contextual information.
This makes the investigative process following an alert especially important. Where a gaming operator uses automated alerts or other mechanisms to identify potentially suspicious activity, the alert itself is only the beginning. The matter must be reviewed promptly, investigated where appropriate, documented and assessed to determine whether the statutory reporting threshold has been reached.
The Nova Scotia case also draws attention to attempted transactions. A transaction that is cancelled, declined or abandoned does not necessarily cease to be relevant from an anti-money-laundering perspective.
For example, a customer may abandon an attempted transaction, encounter a control that prevents completion, or attempt to structure activity that ultimately does not proceed. If the surrounding facts establish the required level of suspicion, the attempted activity can remain relevant to a suspicious transaction assessment.
The enforcement notice does not provide details about the particular attempted transactions, their amounts or the specific indicators that FINTRAC considered. Consequently, it would be inappropriate to speculate about the individual circumstances.
What the enforcement action establishes is that FINTRAC determined the reporting threshold had been met.
The New Brunswick case reinforces the same basic principle: even where an organization has other compliance mechanisms in place, those controls do not remove the obligation to file a report when the applicable legal threshold for suspicion has been reached.
Policies and Risk Assessments Under Regulatory Scrutiny
The Nova Scotia enforcement action also illustrates the importance FINTRAC places on formal compliance governance.
Written policies and procedures are expected to do more than exist as reference documents. Regulated entities must develop and apply them, maintain them appropriately and obtain the required senior-level approval.
For a gaming operator, an effective compliance framework should establish how potentially suspicious behaviour is identified, who is responsible for reviewing it, what information must be considered, how decisions are documented and how reportable matters are ultimately submitted to FINTRAC.
The regulator’s public notice does not specify which individual provisions of Nova Scotia Gaming Corporation’s policies were deficient. It therefore does not provide a basis for attributing particular procedural failures beyond the findings expressly identified by FINTRAC.
Risk assessment represents another important component of the framework.
FINTRAC expects reporting entities to assess and document the risk that money laundering may occur through their businesses. That assessment must take relevant prescribed factors into account, including considerations associated with customers and their activities, products and services, delivery channels, geographic exposure and technological developments.
Where higher risks are identified, stronger or enhanced controls may be necessary.
Risk assessment is consequently closely linked to transaction monitoring. An organization that does not accurately understand where its exposure is concentrated may have difficulty determining where additional scrutiny is necessary, how investigative resources should be allocated or why particular activities warrant enhanced monitoring.
Documented risk assessments also allow regulators and internal reviewers to evaluate whether the controls being applied in practice are consistent with the risks an organization has identified.
FINTRAC Enforcement Activity Intensifies
The two gaming-sector penalties come against a backdrop of increased enforcement activity by FINTRAC.
According to the regulator, it issued 35 notices of violation during the 2025–26 period, representing its highest annual total. The associated administrative monetary penalties exceeded C$247 million.
Since FINTRAC received authority to impose administrative monetary penalties in 2008, it has issued more than 180 penalties covering most of the sectors subject to its regulatory oversight.
Administrative monetary penalties are intended to encourage compliance and changes in non-compliant behaviour. In the two gaming cases, both corporations paid their penalties in full, and FINTRAC considers the enforcement matters closed.
Lessons for Casino Operators
The enforcement actions demonstrate that simply having transaction-monitoring systems in place is not enough.
Effective compliance depends on the entire process connecting detection, investigation, risk assessment, escalation, decision-making, documentation and regulatory reporting.
For gaming businesses, this also means that unsuccessful transactions should not automatically disappear from the compliance process. Attempted, cancelled or abandoned activity may contain information that becomes important when viewed alongside other transactions and customer behaviour.
The Nova Scotia case further illustrates how different layers of an anti-money-laundering framework depend upon one another. Policies establish the procedures employees are expected to follow; risk assessments help determine where greater scrutiny is required; and case investigations apply those controls to actual customer activity.
A weakness at any of these stages can undermine the effectiveness of the overall system.
Importantly, the FINTRAC actions do not establish that either gaming corporation laundered criminal proceeds. The enforcement findings concern regulatory non-compliance and failures to meet obligations under Canada’s anti-money-laundering and terrorist-financing framework. They are not findings that either corporation itself committed a money-laundering offence.
The reporting system nevertheless plays an important role in Canada's wider financial-intelligence infrastructure. FINTRAC reported that information received from reporting entities contributed during the previous year to 7,214 financial intelligence disclosure packages derived from 3,007 unique disclosures. That intelligence identified 10,650 subjects of interest and contributed to 348 major, resource-intensive investigations, in addition to supporting other investigations at municipal, provincial and federal levels.
The combined C$631,538.50 in penalties therefore highlights an issue broader than the mechanics of filing suspicious transaction reports. For gaming operators, regulatory expectations extend from the initial identification of potentially relevant activity through to the final reporting decision.
The practical standard is an integrated compliance framework capable of identifying suspicious behaviour, including attempted activity, assessing the available facts and context, documenting the reasoning behind decisions and submitting the necessary information when the legal reporting threshold is satisfied.
By fLEXI tEAM





Comments