Four Credit Unions, Four Penalties: What FINTRAC's September 24 Announcements Tell Us

On September 24, 2026, FINTRAC announced administrative monetary penalties (AMPs) against four credit unions: Caisse populaire acadienne ltée (Caraquet, NB), Pathwise Credit Union (Oshawa, ON), Your Neighbourhood Credit Union Limited (Kitchener, ON), and Caisse populaire Alliance limitée (North Bay, ON). The penalties total $816,750. Each was imposed after a compliance examination under Part 1 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and each has been paid in full and closed.
Together they read as a useful case study in how compliance program failures stack up, and in what drives the size of a penalty.
The Four Penalties at a Glance
Entity | Penalty | Date imposed | Violations |
Caisse populaire acadienne ltée (UNI Financial) | $676,500 | July 23, 2026 | 3 |
Caisse populaire Alliance limitée | $82,500 | June 5, 2026 | 4 |
Pathwise Credit Union | $41,250 | June 4, 2026 | 2 |
Your Neighbourhood Credit Union Limited | $16,500 | Aug. 10, 2026 | 1 |
Case by Case
Caisse populaire acadienne ltée: $676,500. This federally regulated credit union received by far the largest penalty. FINTRAC found it failed to report suspicious transactions in four instances where there were reasonable grounds to suspect a link to money laundering or terrorist activity financing. It also failed to develop and apply up-to-date, senior-officer-approved written compliance policies and procedures, and failed to assess and document its money laundering and terrorist financing risk, including relevant developments and technologies.
Caisse populaire Alliance limitée: $82,500. This entity had the most violations, four, but a much lower penalty. They were outdated or unapproved policies and procedures, failure to take prescribed special measures for high-risk activities, failure to assess and document risk, and failure to carry out and document the required two-yearly effectiveness review of its compliance program by an internal or external auditor.
Pathwise Credit Union: $41,250. Two violations: the policies and procedures requirement and the risk assessment requirement.
Your Neighbourhood Credit Union Limited: $16,500. A single violation, the failure to develop and apply up-to-date, senior-officer-approved compliance policies and procedures.
What Stands Out
1. Suspicious transaction reporting drives the biggest penalty. The only entity penalized for failing to file Suspicious Transaction Reports (STRs) also received a penalty more than eight times larger than the next highest, even though it had fewer violations than Caisse Alliance. Count alone doesn't predict penalty size. What matters is what was missed. FINTRAC's own release calls STR reporting critical to its ability to generate actionable financial intelligence, and this outcome shows how that priority translates into enforcement.
2. Policies and procedures are the universal failing. All four institutions were cited for this. It is the most basic element of a compliance program, and it is one of the most common deficiencies. The requirement has three parts: written, kept up to date, and approved by a senior officer. Any one of these can be the gap.
3. Risk assessment shows up in three of four. Pathwise, Caisse Alliance, and Caisse acadienne were all cited for not assessing and documenting their money laundering and terrorist financing risk. Caisse acadienne's finding specifically referenced relevant developments and technologies, a reminder that a risk assessment is not a one-time exercise and should evolve with the business and its environment.
4. Later-stage program elements matter too. Caisse Alliance's findings on special measures for high-risk activities and on the two-year effectiveness review go beyond having documents on file. They test whether a program is applied and independently verified over time.
5. Foundational failures cluster. Every institution with more than one violation had a documentation-based failure (policies, risk assessment) alongside its other findings. It is a plausible reading, though FINTRAC doesn't state it, that weak foundations make operational failures such as missed STRs more likely. That is a fair working hypothesis for compliance teams.
The Broader Enforcement Picture
FINTRAC's releases place these penalties in context. In 2025–26 the agency issued 35 notices of violation, its highest annual number ever, totalling more than $247 million. It has imposed over 180 penalties since gaining the authority in 2008. Against that backdrop, this batch shows enforcement reaching smaller institutions too, not just headline-grabbing cases. All four are credit unions, and three are provincially regulated.
Takeaways for Compliance Teams
Test your STR process end to end. Detection, escalation, decision-making and filing timelines all need to hold up under examination.
Keep policies current and approved. Build in a scheduled review and a documented senior officer sign-off.
Refresh the risk assessment regularly. Document the prescribed factors and revisit it as products, delivery channels, and technologies change.
Don't skip the two-year effectiveness review. It must be done by an internal or external auditor and the results documented.
Apply special measures to high-risk activity. Identifying high-risk activity isn't enough. The enhanced measures must actually be taken.
