Module 22 | Global Financial Crimes, Risk, and RegTech Library
Research verification date: 2026-08-09
Primary jurisdictions: Canada and Mexico, with comparative operating implications for North American cross-border institutions.
Important notice: Educational material only; not legal advice. It does not determine obligations in any jurisdiction or replace legal counsel, regulator engagement, institution-specific risk assessment, or a documented customer, transaction, product, or account decision.
Source Quality and Currency Note
This module uses Canadian and Mexican primary legislation, FINTRAC guidance, UIF/CNBV/SAT materials, national risk assessments and official notices. It is not legal advice. Country, entity, product, customer, report and data requirements must be verified against current official sources and local counsel before operational use.
How to Use This Module
Read this module in three passes if useful:
- Enterprise leader pass: executive thesis, decision map, Global Core / Local Edge model, maturity profile, failure cascade and executive discussion questions.
- Operator pass: workflows, decision rights, metrics, delivery dependencies, quality controls, jurisdictional configuration and execution checklists.
- Specialist pass: legal and supervisory architecture, technical terminology, reporting, data, evidence, test design, enforcement/supervisory cases and glossary.
Learning Objectives
- Compare Canada’s PCMLTFA/FINTRAC system with Mexico’s UIF/CNBV/LFPIORPI/SAT environment at an operating-model level.
- Translate Canada and Mexico CDD, ownership, monitoring, suspicious reporting, sanctions and data issues into separate but interoperable decision paths.
- Identify regional financial-crime risk drivers including cross-border payments, cash, money services, trade, virtual assets, real estate, corporate structures and fraud/mule activity.
- Design a North American Global Core / Local Edge model that avoids both U.S. legal overreach and weak local accountability.
- Use national risk assessments, official guidance and supervisory/enforcement materials to improve local risk assessment and testing.
- Recognize where Canada’s federal/provincial context and Mexico’s financial/non-financial split change governance and tooling.
Primary-Source Spine
The source strategy for this module is: Canada Justice Laws, FINTRAC, Department of Finance; Mexico Cámara de Diputados, UIF, CNBV, SHCP and SAT. Representative source anchors include S01: Government of Canada; S02: FINTRAC; S03: FINTRAC; S04: FINTRAC; S05: FINTRAC; S06: FINTRAC; S07: Department of Finance Canada; S08: FINTRAC. Material legal, supervisory, enforcement and operating claims are identified in the companion claim/evidence ledger. [S01][S02][S03]
Executive Thesis
Canada and Mexico are frequently compressed into a “North America” compliance category. That is a dangerous operating shortcut. Canada’s regime is centered on the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, FINTRAC’s reporting, intelligence and compliance functions, federal and provincial dimensions, and evolving sanctions-related reporting. Mexico’s framework combines the financial-sector AML/CFT regime, the UIF, CNBV, the federal preventive law for designated non-financial activities and professions, SAT-facing obligations, cash restrictions and a high-importance cross-border and cash-intensive risk environment. Both countries are FATF members and share cross-border exposure with the United States, but their legal triggers, report types, authorities, data, customer evidence, supervision, sector coverage and enforcement practices are not interchangeable.
For a regional institution, the practical task is to run one evidence-led enterprise control spine with two distinct regulatory execution models. The group should know its customers, ownership, transactions, payment routes, merchants, intermediaries, cash exposure, cross-border flows, high-risk sectors, reports, sanctions touchpoints and data. But it must configure those capabilities to the applicable regime. In Canada, FINTRAC guidance is particularly operational about compliance programs, reasonable grounds to suspect and report quality. In Mexico, the relationship among UIF, CNBV, SAT, covered financial institutions, designated non-financial activities and professions, and official reporting formats requires its own legal and operating map. [S01][S02][S03][S09][S10][S11][S12][S14]
The executive question is not whether to centralize the region. It is what must be common and what must remain locally accountable. Data model, evidence lineage, quality standards, training taxonomy, vendor governance, risk methodology, case management and group assurance can be common. Report formats, legal thresholds, FIU and regulator engagement, language, sources, local KYC rules, recordkeeping, privacy, local data access and escalation must be intentionally configured and legally validated.
Executive decision rule. Before accepting, changing, centralising, outsourcing, automating, restricting, reporting, or closing a material financial-crime control, require a clear statement of the applicable question, the in-scope population, the accountable owner, the decision evidence, the local legal configuration, the quality test and the residual-risk authority.
The Questions This Module Answers
- Which activities and legal entities are reporting entities in Canada and Mexico, and which local authority supervises or receives reports?
- How do Canadian reasonable-grounds-to-suspect reporting and Mexican report categories differ in operational design?
- What customer, cash, payment, remittance, trade, real-estate, virtual-asset and corporate-structure indicators require local configuration?
- How should sanctions and cross-border information be assessed when U.S., Canadian and Mexican rules overlap or differ?
- What must a regional data architecture retain locally or make available to local teams and authorities?
- Which enforcement and supervisory signals should trigger regional thematic testing rather than a local-only remediation?
1. Executive Layer
The strategic stakes
Financial-crimes capability becomes strategically material when it affects what customers can be served, which products can be launched, how fast payments can move, whether a market can be entered, which relationships can be retained, what data can be used, and whether regulators or partners consider the institution trustworthy. The leadership task is to avoid two bad abstractions: viewing financial crime as an isolated compliance overhead, or treating every operational difficulty as a legal prohibition. The discipline is to identify the actual source of risk and then design an evidence-led decision path that is proportionate, timely, fair and sustainable.
Every executive should ask four linked questions. First, exposure: what customers, products, transactions, geographies, delivery channels, intermediaries, technologies and networks create the risk? Second, control: which preventive, detective, investigative, reporting, action and assurance mechanisms should respond? Third, proof: what data, documents, logs, reviewer rationale, quality results, model evidence and authority records prove the mechanism works? Fourth, adaptation: how will the institution detect that the risk, rule, product, data or capacity assumption has changed? The answer must be visible by legal entity and market, not merely at head office.
Executive decision map
| Dimension | Canada | Mexico |
|---|---|---|
| Core framework | PCMLTFA, regulations, FINTRAC guidance and reporting ecosystem. | Financial-sector rules plus UIF/CNBV oversight and the LFPIORPI/SAT framework for designated non-financial activities and professions. |
| Key intelligence / supervision | FINTRAC receives reports, analyzes intelligence and assesses compliance within its mandate. | UIF is central to financial intelligence; CNBV supervises relevant financial institutions; SAT has a role in preventive-law administration. |
| Suspicious reporting | STR when applicable reasonable grounds to suspect standard is met; content and related reports matter. | Report categories and official formats depend on the relevant sectoral framework and activity. |
| Operating emphasis | Compliance-program components, client identification, recordkeeping, report quality and evolving sanctions-property reporting. | Customer/product/sector classification, cash and cross-border context, institutional reporting, entity and beneficial-owner evidence, local supervisory coordination. |
| Regional design | Federal regime with provincial and product context. | Federal legal architecture with different financial and non-financial covered-activity routes. |
The decision map is deliberately outcome-based. It prevents a program from announcing a new standard, a vendor deployment, a training campaign or a reduced backlog as a success without showing whether the actual decision quality, coverage and resilience improved. It also gives boards and transformation sponsors a more useful way to allocate capital: fund the evidence and operating capability that changes the decision, not simply the activity that surrounds it.
Read the cascade as a management diagnostic rather than an inevitability. A visible failure at the right side of the diagram—late reporting, unsafe customer action, a supervisory finding, or a costly remediation—usually began earlier with an unstated assumption about population, data, capacity, decision rights, or change control. The control response should move upstream until it identifies the first point at which evidence, ownership, or resilience was insufficient. That approach avoids treating rework, contractors, a larger backlog team, or a new dashboard as a substitute for fixing the decision path itself.
2. Operator Layer
The execution discipline
The operator layer turns legal and risk requirements into repeatable work. It begins with a controlled inventory, not a technology implementation. For each process, record the population, trigger, required evidence, key data, legal/policy basis, routing, reviewer authority, system, action, report, time standard, exception, quality test and feedback channel. If any of those elements are missing, the program is likely relying on individual memory or an undocumented work-around.
1. Build legal-entity and coverage maps
Record each Canadian and Mexican legal entity, product, service, customer segment, channel, transaction role, reportability, licenses, local data stores, vendors, supervisor/FIU interface and accountable executive.
2. Run country-specific risk translation
Start with national risk assessments and local source material, then translate threats into customer, product, geographic, delivery-channel, transaction, cash, trade, virtual-asset and fraud indicators.
3. Configure reporting at source
Build country-specific report triggers, forms, data fields, narrative guidance, timing controls, evidence retention, confidentiality and reconciliation. Do not rely on a global “SAR” label to hide distinct local reports.
4. Apply local KYB/beneficial-owner logic
Store the common ownership/control graph but configure local collection, verification, registry, tax, entity-type, financial/non-financial and escalation requirements. Escalate contradictions to local legal/financial-crime owners.
5. Manage cross-border data and investigations
Specify permitted data categories, legal basis, access, transfer, storage, language, investigator roles, local FIU reporting and relationship with U.S. requests or sanctions exposure.
6. Assure both country and regional outcomes
Use local QA and regulatory readiness checks; then run regional thematic reviews for cross-border payments, money services, virtual assets, cash, trade, high-risk entities, fraud/mules and report quality.
Operating metrics that resist false assurance
Measure the entire decision path. Track demand and throughput, but pair them with aged risk, incomplete evidence, decision reversal, downstream escalation, report quality, customer-impact signal, QA error, model/data exceptions, vendor or system interruption, issue recurrence and time to root-cause closure. Require a management explanation for favorable metrics that move abruptly. A sharp improvement often reflects a useful control change, but it can also reveal data loss, a policy change, a case-type exclusion, a new vendor routing rule or an unrecorded suppression.
3. Specialist and Jurisdictional Layer
22.1 Canada: legal architecture and FINTRAC operating model
Canada’s AML/ATF framework is established principally through the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and associated regulations. FINTRAC publishes operational guidance on compliance-program components, risk assessment, client identification, recordkeeping and reporting. For institutions, the first design task is coverage: determine whether the entity and service are a reporting entity and which requirements apply. The second is evidence: ensure that the program can demonstrate a documented risk assessment, compliance officer and governance, written policies and procedures, training, effectiveness review and the required customer, transaction and report records. [S01][S02]
FINTRAC’s suspicious-transaction guidance is a useful operational benchmark because it focuses on the facts and context that create reasonable grounds to suspect and on the quality of the STR narrative. Reports should make the transaction, parties, roles, ownership/control where relevant, expected versus observed activity, indicators, links and action taken intelligible to a recipient outside the institution. They should be reconciled with large-cash, EFT, virtual-currency and other report types where relevant. [S03][S04] Canadian rules and forms change; teams must use the current FINTRAC guide for the reporting entity and date.
Enforcement and Supervisory Lens: FINTRAC administrative monetary penalty on Binance Holdings Limited
Official record. FINTRAC announced an administrative monetary penalty against Binance Holdings Limited. [S08]
Operating lesson. Virtual-asset activity should be evaluated through coverage, registration, customer, transaction, report, governance and evidence design—not a generic “crypto” label.
Limit of inference. The notice is specific to its official findings and should not be treated as a legal conclusion about every platform.
22.1A Canada: reporting architecture, data, and evidence quality
Canadian reporting design should begin with the reporting entity, activity, trigger, report type, time standard, data field, source record, quality review, correction process, retention, confidentiality, and reconciliation. Do not use “SAR” as a generic regional label. An STR decision, a large-cash or electronic-funds-transfer report, virtual-currency report, sanctions-property report, or another report type can involve different facts, thresholds, forms, records, and operational teams. The common control spine may link customer, entity, transaction, case, and action data, but the Canadian workflow must preserve the current FINTRAC rule/guidance and the entity’s own evidence of timely, accurate operation. [S02][S03][S04]
The STR case file needs a narrative-ready evidence record: source signal; people, entities, accounts, wallets or other identifiers; ownership/control; transactions and flow; expected and observed activity; typologies or indicators; documents and data reviewed/unavailable; inquiry and response; analysis; report rationale; linked reports; action taken; timing; reviewer/approval; and post-report monitoring. The objective is not an internally elegant alert disposition. It is a report that makes the reasoning and financial intelligence useful without overstating facts. Quality assurance should test complete and timely data, contextual narrative, accurate entity/transaction linkage, escalation, confidentiality, and whether the report decision is connected to account/action and ongoing risk management.
Client identification, beneficial ownership, business purpose and source evidence should be held as a dated, attributable evidence graph. Separate customer assertion, verified/independent source, provider result, unavailable information, analyst inference, and adverse information. Track source date, confidence, conflict, reviewer, risk impact, refresh/event trigger, and escalation. When a Canadian entity relies on a group KYC platform or service provider, it must still demonstrate that it has the information and records needed for its own obligations and can explain the Canadian configuration to FINTRAC or an appropriate supervisor.
Provincial/product considerations should be integrated into the control perimeter. A reporting entity may have provincial privacy, securities, insurance, real-estate, payments, consumer, licensing, or other obligations that affect data, customer journey, records, supervision, and conduct. The operational map should name the responsible authority and control owner, rather than treating federal AML/CFT coverage as the whole risk environment. This is especially important where a common North American product is delivered through different legal entities, agents, affiliates, or provincial channels.
Enforcement and Supervisory Lens: FINTRAC sanctions-property reporting update
Official record. FINTRAC published material about listed person or entity property reporting and the scope of related obligations. [S06]
Operating lesson. Sanctions and AML reporting may share intelligence but require distinct legal source, property/control analysis, report and evidence.
Limit of inference. This is an informational resource; institutions must check current legal scope and relevant regulations.
22.2 Canada: sanctions, ownership, provincial and product edge
Canada’s sanctions environment includes the Special Economic Measures Act and other legal instruments, while FINTRAC has published resources on listed-person-or-entity property reporting and sanctions-related reporting context. A Canadian sanctions case needs a separate legal decision path: identify the Canadian legal source, designated person/entity or ownership/control issue, asset/property/transaction, required action, report, record, law-enforcement interaction and overlap with an STR. [S05][S06][S09]
Canada’s operating edge also includes product, provincial and market structure. Securities, insurance, virtual-asset, real-estate, gaming, money-services and other activities can carry different supervisors, registrations, source-of-funds expectations, customer experience and data arrangements. A regional group must not assume that a federal FINTRAC program eliminates provincial conduct, privacy, licensing or prudential obligations. The correct management record identifies the applicable authority and what its expectation means for the particular legal entity and product.
Enforcement and Supervisory Lens: UIF-CNBV coordination agreement
Official record. CNBV announced an agreement with UIF to strengthen coordination in the national AML system. [S15]
Operating lesson. Changes in intelligence-supervisory coordination should trigger data, report, governance, training and regulatory-readiness impact assessment.
Limit of inference. The announcement does not by itself create a complete new set of firm obligations.
22.2A Canada: sanctions, virtual assets, and cross-border casework
Canadian sanctions and AML controls should share relevant data but retain separate decision records. A sanctions case should identify the applicable Canadian source and current list/program context, parties and ownership/control, property/asset/transaction facts, Canadian nexus, matching and entity-resolution evidence, action, report/notification, any authorization or legal escalation, customer/counterparty communication, and post-action monitoring. Do not use a U.S. ownership rule, an AML beneficial-owner threshold, or a global name-screening result as a substitute for Canadian legal analysis. Where an STR concern overlaps, maintain the relevant connected facts while preserving the distinct report/action authority and confidentiality requirements. [S05][S06][S09]
Virtual-asset, money-services, payment, and remittance activity should be assessed by function. Map the entity’s role, registration/coverage status, customer and counterparty population, onboarding/KYC evidence, wallet/address or transaction data where relevant, source-of-funds/wealth review, transfer and reporting flows, sanctions and fraud/mule links, providers, data lineage, exceptions, and supervisor/FINTRAC interface. A digital product can appear borderless while exposing a Canadian entity to specific local reporting and evidence requirements. Pilot or growth approval should be conditional on demonstrated data, reporting, quality, customer support, incident response, and retained accountability, not simply a successful API integration.
Cross-border Canadian investigations require a fact and authority map. Identify the Canadian entity, customer, transaction, money and information flows, foreign counterparties/entities, U.S. or Mexico nexus, potential FINTRAC report or other local action, sanctions question, foreign report consideration, data access/transfer constraints, record location, customer impact, legal owner, and time-critical decisions. The case plan should let a Canadian investigator file or act in time without waiting for a global central team to resolve every foreign question, while still giving the group a connected view of linked networks and risk.
Assurance should target new corridors, high-risk countries or FATF-related notices, cash/virtual-currency/remittance patterns, complex ownership, provider/agent flows, material data changes, and rapid product growth. Test population coverage, record quality, report/action timing, sanctions-property case handling, source evidence, customer treatment, and root cause. When a defect is identified, distinguish an isolated case error from a data, configuration, coverage, capacity, provider, or governance failure and assess the affected population before closing the issue.
22.3 Mexico: financial-sector architecture and national risk context
Mexico’s framework must be approached through its own legal and institutional architecture. Financial institutions are subject to sectoral AML/CFT provisions and CNBV supervision within its remit; the UIF is central to financial intelligence; official formats support reporting; and the 2023 national risk assessment provides a national threat and vulnerability lens. [S10][S11][S12][S13] The detailed scope, customer due diligence, beneficial ownership, monitoring, reporting, retention and audit requirements vary by regulated institution and activity. The operating model should never substitute a generic regional policy for the relevant Mexican legal or CNBV rule set.
Mexico’s cross-border, cash, remittance, trade and geographic context requires practical control design. Risk assessments should differentiate domestic versus cross-border activity, payment rails, currency/cash exposure, customer sector, business purpose, ownership/control, counterparties, intermediaries, transaction narrative, source of funds, delivery channel and local vulnerability. A program that only applies a U.S. or Canadian typology list will miss local factors; a program that creates a local heuristic without a clear source/evidence model will be impossible to test.
22.3A Mexico: financial-sector control architecture and evidence
Mexican financial-sector execution starts with the applicable regulated entity, product, customer, transaction, legal/supervisory source, and reporting role. Maintain a legal-entity/perimeter register that identifies each bank, brokerage, SOFOM, fintech or other relevant business, its authorization/registration context, CNBV or other supervisory relationship, UIF/report interface, local policies/procedures, data and records location, service providers, and accountable local executive. A regional operating model should not conclude that an entity has the same AML/CFT obligations as a related Canadian or U.S. institution simply because it offers a similar product.
Customer due diligence and beneficial-owner work need a Mexican evidence record. Capture the customer/entity type, legal capacity and business purpose, identity and relevant government/independent source information, ownership/control evidence, customer declarations, source-of-funds/wealth information where proportionate, expected activity, risk factors, data limitations, reviewer reasoning, approval, refresh/event triggers, and escalation. Preserve Spanish-language source evidence and the original name/address/identifier data where material; an English summary can support group governance, but it should not replace the source that a local investigator, regulator, or report process needs.
Transaction monitoring should be tailored to local payment, cash, remittance, trade, customer-sector, geographic, intermediary, and cross-border patterns. For each rule, scenario, or investigative process, document the in-scope population, source systems, data fields, rule/model version, exclusions, alert routing, investigative standard, report/action interface, quality testing, and change control. A generic “Latin America” threshold will not prove that the Mexican entity covered its actual products or risk factors. Test changes, onboarding cohorts, high-risk sectors, cross-border corridors, customer migrations, data defects, manual workarounds, and time-sensitive report/action paths.
Entity-level governance should coordinate, rather than conflate, financial crime, legal, data/privacy, product, operations, audit, and local regulatory engagement. Management information should show risk population, CDD/evidence quality, monitoring/reporting, exceptions, data issues, provider dependencies, QA/testing, open issues, and customer/operational consequences. When a central service supports Mexico, record its local procedure, access, language/capability, decision rights, regulatory evidence, escalation, continuity, and exit. The local entity must retain an accountable and explainable control.
22.4 Mexico: LFPIORPI, SAT and the non-financial perimeter
The Federal Law for the Prevention and Identification of Operations with Illicit Resources (LFPIORPI) creates a preventive regime relevant to designated non-financial activities and professions. SAT’s portal supports the preventive-law operating environment. This is not merely an ancillary “DNFBP” issue for a bank. It affects customers, counterparties, real-estate and high-value-good ecosystems, source-of-funds evidence, merchant and supplier risk, transaction monitoring and intelligence referrals. [S10][S14]
Global institutions should maintain an activity-perimeter map that distinguishes the regulated entity’s own direct duties from the risk implications of a customer or counterparty that operates in a covered non-financial sector. The map should record sector, relevant legal/regulatory regime, reporting role, local evidence, cash restrictions where relevant, government portal/interface, customer explanation, monitoring scenarios and escalation. This prevents a common problem: the bank has a strong financial-institution program but no meaningful understanding of a high-risk non-financial customer’s operating reality.
22.4A Mexico: designated non-financial activity, cash, trade, and KYB
The LFPIORPI/SAT perimeter should influence both a firm’s direct compliance analysis and its customer/counterparty risk design. For a covered or potentially covered activity, map the legal entity and business role; type of activity; customer and beneficial owner; goods/assets/services; transaction and cash/payment characteristics; documents and government-portal/interface evidence; relevant reporting/notice route; records; internal control owner; and escalation. For an institution that is not itself the covered non-financial actor, map the customer’s activity and its implications for KYC/KYB, expected transactions, source of funds, cash/trade patterns, monitoring, sanctions/fraud risk, and investigative/reporting decisions.
Cash is not merely a transaction field. It can affect customer risk, product and merchant policy, money-services exposure, cash-intensive sector assessment, source evidence, transaction monitoring, fraud/theft risk, reporting and legal restrictions. Record the business explanation, declared versus observed cash behavior, counterparties, locations, time patterns, related deposits/withdrawals/payment flows, supporting records, and exceptions. A group should not solve a local cash-risk problem by imposing a U.S. cash rule or a generic “no cash” policy without evaluating Mexican legal, business, customer, and crime implications.
Trade and high-value goods require connected evidence. Identify goods/services, contracts/invoices, counterparties, shipping/fulfilment and payment routes, customs or tax information where lawfully available, pricing/volume anomalies, related entities, cash and cross-border flows, and source/destination of funds. This is not a request to turn every financial institution into a trade specialist. It is a way to recognize when a customer/product/transaction profile cannot be understood without information about the activity it finances. Escalate gaps to appropriate local subject-matter, legal, or investigative roles.
KYB assurance should test real customer cases across sectors, including real estate, high-value goods, professional services, cash-intensive businesses, intermediaries, cross-border merchants, and complex ownership. Test source provenance, conflicts, language, customer purpose/expected activity, monitoring coverage, reports/actions, data-access, and customer communications. Where a process relies on a third party, registry, tax source, or central group platform, identify limitations and preserve the local evidence necessary to make a defensible Mexican decision.
22.5 Mexico: supervisory coordination and data/investigation implications
CNBV and UIF coordination is an important signal that financial intelligence, risk-based supervision, data, compliance functions and regional execution cannot be designed in isolation. In March 2026, CNBV announced an agreement with UIF intended to strengthen coordination of the national anti-money-laundering system. [S15] An institution should treat such official developments as a change-management trigger: assess the potentially affected legal entities, reports, data, supervision, evidence, training, governance and regulator-engagement processes.
The regional data model must record Spanish-language source evidence and narrative requirements, role-based access, local investigation ownership, cross-border transfer constraints, data lineage and reporting reconciliation. It should support a local investigator’s ability to tell the complete story, not require them to translate all facts into a global data warehouse before a timely escalation or report can be made.
22.5A Mexico: reporting, supervisory coordination, and remediation
Reporting architecture should be configured from the Mexican entity and activity outward. Identify the local report/notice category, UIF or other official interface as applicable, data fields and formats, trigger, time standard, supporting evidence, narrative/language requirement, reporting owner, review/approval, confidentiality, correction/retention, and reconciliation against source systems. A global case-management tool can help preserve facts, but it must represent the local reporting decision and not convert every result into a U.S.-style SAR. Maintain current official source/version and escalate legal changes, system/interface changes, and data gaps before a deadline is missed.
The UIF-CNBV coordination announcement is an example of why government/supervisory developments should trigger controlled impact assessment rather than automatic policy rewriting. [S15] Determine whether the event affects relevant legal entities, supervisory engagement, data/reporting, risk assessment, monitoring, quality assurance, training, vendor/shared-service arrangements, or evidence. Record the conclusion, source, scope, responsible owner, change/validation if needed, and next review. This turns external coordination into a governance input and prevents teams from either ignoring a significant signal or treating it as a legal obligation without analysis.
Regulator readiness should be evidence-led. Organize materials by Mexican legal entity, period, product, customer/transaction population, requirement, control, report, data source, owner, issue, and validation. Retain local risk assessment, CDD/KYB examples, monitoring and investigation records, report evidence, training, governance, data lineage, model/rule change, quality and audit results, provider/service evidence, customer-impact records, and authority correspondence. A central team can coordinate document collection, but the local entity must be able to explain its program and conclusions in a timely, consistent, locally grounded way.
Remediation must include affected-population and BAU proof. Define the underlying requirement/control objective, issue facts, scope/period, root cause, immediate safeguard, report/customer/authority implications, target state, dependencies, owner, validation, residual risk, and closure authority. Test whether the implemented change reaches the intended Mexican population, supports local report/action, has correct language/source data, is used by trained people, and survives an observation period with QA/independent challenge. A central platform release, a translated policy, or a closed project plan is not sufficient evidence that local execution is sustainable.
22.6 Comparative lens: the regional operating model
Canada and Mexico make the danger of convenience standardization visible. A global group can use common risk categories, data objects, workflow, case structure, model governance, QA, vendor standards and management reporting. It must not use one regional filing label, one customer-evidence checklist, one country risk score, one sanctions ownership approach or one governance committee as a substitute for local legal translation. Canadian and Mexican teams need direct access to the shared intelligence that helps them see cross-border networks, but they also need local authority to interpret, report, act and escalate.
The governing test is simple: can the group reconstruct the local decision, prove the local legal and policy basis, show the connected cross-border facts, and demonstrate that a regional control did not suppress a required local action? If not, the program is centralized in form but fragmented in accountability.
22.6A Regional controls, data, and cross-border assurance
The regional control model should use a shared evidence graph with controlled local edges. Common objects may include customer, legal entity, beneficial owner/controller, account, product, transaction, payment, cash event, trade/activity, alert, case, report, restriction, fraud/scam event, source, system, model/rule, test, issue, and action. Each object should retain jurisdiction, legal entity, source provenance, language, date/version, access restriction, confidence/limitation, and owner. This enables regional analytics and linked-network investigation while preserving the country-specific evidence required for local decisions.
Cross-border data access needs a fact-specific operating design. For a Canadian or Mexican entity, identify what information a central team, affiliated entity, service provider, or external party needs; why; whether raw data, a risk conclusion, a redacted record, a metric, or an escalation is sufficient; the legal/policy basis; access and security controls; local confidentiality/reporting restrictions; transfer/storage/remote-access path; record retention; and escalation. Do not assume that data is either freely shareable because a group owns it or unusable because it is local. Build lawful routes that support timely local reporting and investigation without unnecessary centralization.
Use regional thematic testing for connected risks: Canada–Mexico remittance corridors, cash and money services, virtual assets, trade/high-value goods, corporate structures, high-risk geographies, U.S. correspondents/nexus, sanctions exposure, fraud/mule patterns, shared vendors, and model/data changes. For each test, define the country populations and legal/control questions, source records, local reviewers, findings, and whether a common root cause exists. The result should be a documented decision: local remediation, regional standard change, broader lookback, interim safeguard, residual-risk acceptance, or no common action with rationale.
Management reporting should show both country and regional outcomes. Canada and Mexico each need local report, deadline, quality, data, customer, supervisory, and issue measures. Regional leaders need connected risk, coverage, capacity, vendor, data, cross-border, remediation, and legal conflict views. A strong dashboard does not average away a local red flag; it shows whether the group knows the issue, understands its scope, assigns the right owner, and can prove the response.
22.7 Canada: program testing, enforcement readiness, and customer outcomes
Canadian assurance should test the compliance program as a functioning system. Validate the entity/activity perimeter, compliance officer/governance, risk assessment, written policies/procedures, training, effectiveness review, client identification, beneficial ownership, recordkeeping, report population, STR narrative, other report pathways, sanctions-property consideration, data lineage, provider/shared-service control, and issue closure. Use real customer, transaction, and report examples, including high-risk/cross-border, virtual-asset, money-services, cash, agent, and data-exception cases. A checklist that confirms each document exists is weaker than a test that shows the Canadian entity can reconstruct the decision and report/action outcome.
Public FINTRAC enforcement material should prompt targeted self-assessment, not a generic policy rewrite. The Binance administrative monetary penalty announcement, for example, should lead relevant entities to test their own coverage/registration context, customers and geography, transaction and reporting data, risk assessment, governance, and evidence. [S08] Record the impact assessment, scope, findings, actions, limitations, and validation. The appropriate action depends on the firm’s facts; the point is to use official material as a control-evidence lens rather than a media headline.
Customer outcomes matter to a risk-based program. A request for additional evidence, payment delay, virtual-asset intervention, account restriction, or relationship exit can be necessary, but needs a reasoned basis, authority, data/evidence, customer communication within applicable constraints, complaint/review route, and monitoring. Avoid treating a report decision or risk rating as a complete explanation for customer treatment. Track reversals, complaints, repeated evidence requests, erroneous interventions, processing delays, and segment effects alongside suspicious-activity and sanctions outcomes. This helps distinguish proportionate risk control from friction caused by poor data, unclear ownership, or incentive design.
Test resilience through a Canadian scenario: a FINTRAC report deadline coincides with a data outage, a provider failure, a new sanctions-property concern, or a cross-border payment/fraud event. Confirm the entity can identify the affected population, preserve records, make time-sensitive decisions, access lawful data, escalate to local legal/compliance/operations, communicate appropriately, and document remediation. Resilience is not a global business-continuity template; it is the Canadian entity’s ability to continue its own control responsibilities under stress.
22.8 Mexico: fintech, payments, outsourcing, and digital evidence
Mexico’s fintech, payments, remittance, digital onboarding, and outsourced-service models should be analysed by legal entity and function. Identify who contracts with the customer, onboards, verifies identity, holds or moves funds, provides credit or payment initiation, controls data, monitors transactions, files reports, makes account/action decisions, and interfaces with authorities. Map the applicable authorization/registration and local legal/supervisory analysis, then design CDD, ownership, monitoring, reporting, sanctions/fraud, privacy/data, customer support, recordkeeping, and assurance around the actual flow rather than the product’s marketing label.
Digital identity and evidence must be reproducible. Preserve the source, date, method, confidence/limitation, document/image or reference as lawfully retained, provider result, human review, decision, exception, and refresh/event trigger. Treat failed or incomplete digital verification as a data and risk condition, not just a technical error. Where a provider performs biometrics, document extraction, liveness, entity resolution, device analytics, sanctions screening, or transaction monitoring, define the data/decision boundary, local access, quality testing, incident escalation, audit/regulator access, model/change governance, continuity, and exit. The Mexican entity remains responsible for knowing what evidence underpins its customer and report decisions.
Outsourcing needs retained accountability. The local control owner should be able to explain the service scope, in-scope population, data location/access, operating procedure, quality thresholds, error/rework, reporting paths, Spanish-language evidence, subcontractors, incident and data-breach response, regulatory cooperation, continuity, and exit. Metrics should show coverage and decision quality, not merely volume or SLA. Sample high-risk and exception cases; challenge provider claims; ensure a local team can act when a service fails. A central group team can offer scale, but it cannot become the only holder of Mexican evidence or report authority.
Digital payments and cross-border movement require end-to-end testing. Test onboarding, transaction data, monitoring coverage, exception handling, urgent intervention, report narrative, account action, fraud/mule patterns, sanctioned or high-risk counterparties, data gaps, refunds/returns, and customer communications. Include cases that cross into Canada or the United States, but do not assume their legal pathway determines the Mexican report/action. The goal is a locally defensible decision with a connected regional evidence graph.
22.9 Regional scenario design and management decision rights
Regional case management needs a decision-rights map. Local Canada and Mexico teams should know who owns a country report, sanctions/local legal escalation, customer action, data access, contact with an authority, product restriction, and residual-risk acceptance; regional teams should know who coordinates linked facts, analytics, vendor/data issues, and cross-border impacts. A coordination lead can keep the chronology coherent, but cannot replace a Canadian or Mexican legal entity’s accountable decision. Record the exact facts, source, date, authority, decision, action, and communications for each branch of a multi-country case.
Use scenarios that reveal conflicts: a Mexican high-value-goods customer sends funds through Canada with a U.S. correspondent; a Canada-based virtual-asset customer is linked to a Mexican payment/fraud network; a shared screening provider misses a country-specific field; a FINTRAC report, Mexican report, and potential U.S. sanctions issue arrive on different clocks; or a data-transfer restriction prevents a central investigator from viewing a local document. The test should show how local teams act safely while evidence, legal advice, data access, customer impact, reports, and cross-border coordination are managed. Preserve lessons and use them to improve configuration, training, providers, and escalation.
Executive decisions should name the trade-off. A regional group may decide to centralize a data platform, condition a cross-border product, add a local specialist, change a vendor, restrict a corridor, create a temporary manual control, or accept a limited residual risk. The record should state the legal entities/population, evidence, local legal/supervisory input, customer/financial/crime impact, alternatives, owner, duration, monitoring, and review date. This gives senior management a truthful view of what standardization enables and what local execution still requires.
Benefits realization must be local as well as regional. A shared platform might reduce manual work, but verify report quality, coverage, language, data availability, local deadlines, customer outcomes, QA, and resilience before claiming capacity or cost benefit. Track root-cause remediation and sustainment by entity. A gain that removes evidence from a Canadian investigator or delays a Mexican report is not an enterprise benefit; it is a transfer of risk.
22.10 Country-calibrated risk assessment and scenario governance
A Canada–Mexico regional risk assessment should be constructed from country-specific populations and evidence, not a weighted average that smooths out local risk. Start with each entity’s products, customers, transactions, cash and payment flows, delivery channels, provinces/states or geographic exposure, counterparties, agents/intermediaries, virtual-asset services, trade/high-value-goods exposure, ownership structures, fraud/mule patterns, U.S. connections, data limitations, provider dependencies, and local national risk assessment themes. Then identify what common cross-border risk exists and what must remain an independent country risk conclusion. A regional heat map is useful only if users can drill into the Canadian or Mexican legal entity and understand the data and assumptions behind its color.
Scenario governance should connect national threat information to system change. For each scenario, record the local rationale, entities and products, customer/transaction population, relevant data fields and sources, rule/model/threshold or investigation guidance, exclusions, alert routing, report/action paths, QA, data-quality dependencies, owner, effective date, test results, customer impact, and review trigger. Where a scenario is adapted from the United States or another region, document why it fits Canada or Mexico, what local facts were added or removed, and which source supports the decision. Do not assume that a name, geography, cash, remittance, trade, virtual-asset, or ownership signal has the same legal or investigative meaning in both countries.
Calibration should include negative testing and false-negative thinking. Test whether known high-risk patterns, synthetic cases, historical investigations, typology updates, report-quality feedback, data exceptions, linked-network relationships, and cross-border flows are recognized. Test false positives, customer friction, investigator workload, reversals, and impact on local reporting clocks. When a scenario is suppressed or tuned, preserve the approved reasoning, affected population, test evidence, exception route, monitoring, and rollback. A sharp decrease in alerts can represent successful refinement or a serious coverage gap; management needs evidence to distinguish them.
Risk assessment and scenarios should feed resource and product decisions. If a Mexican high-risk sector requires specialist evidence, language capability, or local legal escalation, resource it; do not hide the need inside a global capacity count. If Canadian reporting quality depends on a data field that a group platform does not retain, create the configuration or interim control and track the residual risk. If a cross-border corridor repeatedly generates uncertain ownership, fraud, cash, or report outcomes, condition its growth or redesign the information and control flow. This is how local risk assessment becomes an operating-control discipline rather than an annual document.
4. Cross-Border Operating Model
North America is a useful regional crime and payment lens, not a single regulatory jurisdiction. Cross-border payments, remittance corridors, trade, corporate chains, virtual assets, cash, organized-crime networks, fraud and U.S. legal exposure can create connected risk across Canada, Mexico and the United States. The operating model should allow lawful, controlled intelligence sharing and cross-border case coordination. It should retain country-specific reporting, counsel, data, action and supervisor records. A case with a Mexican customer, Canadian funds flow and U.S. correspondent touchpoint may require multiple analyses, but it should have one connected factual evidence graph.
The high-quality regional model sets a common escalation taxonomy: risk event, local reporting consideration, U.S. nexus consideration, sanctions consideration, customer-harm/fraud concern, data-transfer question, legal issue and executive risk acceptance. It assigns accountable owners for each path and uses a coordination lead to prevent timing gaps or inconsistent actions.
5. Practical Frameworks and Assurance
Framework 01: The System Proof Test
Use the following ten questions before declaring a capability effective. This is a library operating framework, not a regulatory checklist.
- Is the applicable legal, regulatory, supervisory and policy question explicitly classified?
- Is the in-scope population known, reconciled and versioned?
- Is the required customer, entity, transaction, data or evidence object complete enough for the decision?
- Is the accountable owner clear, including the local legal-entity owner where relevant?
- Does the workflow distinguish prevention, detection, investigation, reporting, action and assurance?
- Are there measurable quality, timeliness, coverage and customer-impact guardrails?
- Can a reviewer reconstruct the rule, source, data, reasoning, override, action and report?
- Can the system absorb a surge, data failure, vendor failure, legal change or material risk event?
- Has independent challenge tested real decisions and not only written procedures?
- Does the learning loop make a controlled change, retain the evidence and test whether it worked?
Framework 02: Outcome Dashboard
| Outcome | Leading / lagging indicators | Evidence source |
|---|---|---|
| Decision quality | Accuracy, completeness, timeliness, consistency, explained overrides | QA, independent testing, case review and regulatory challenge |
| Coverage | Population, product, channel, data and legal-entity inclusion | Coverage map, reconciliations, negative testing and change control |
| Customer / counterparty outcome | Friction, hold/release timing, complaints, remediation and fairness | Journey evidence, service data, root-cause analysis and governance |
| Resilience | Surge capacity, data dependency, vendor concentration, recovery and key-person exposure | Scenario test, service review, continuity exercise and exit plan |
| Learning | Issue recurrence, typology feedback, model/process change and post-implementation result | Root-cause log, risk acceptance, validation and BAU monitoring |
The dashboard should be read as a pattern, not a scorecard contest. A sharp reduction in alert volume may be good, bad, or meaningless depending on the covered population, detection precision, missed-risk testing, quality, account/action outcomes and source data. A backlog decline may signal stronger process design, or it may result from relaxed review, unrecorded exceptions, data loss or customer exits. The governance record should require the owner to explain the causal story and the independent challenger to test it.
Framework 03: Decision-Rights Map
| Role | Minimum decision rights and evidence |
|---|---|
| Global owner | Common standard, data/evidence grammar, control taxonomy, model/vendor/QA framework, thematic risk and escalation. |
| Local entity owner | Local legal translation, reportability, data access, customer action, supervisory engagement, local source and procedure. |
| Independent challenge | Second-line challenge, quality, validation/audit, issue severity, evidence review and residual-risk escalation. |
| Executive forum | Risk appetite, funding, material exceptions, product/growth conditions, remediation closure and authority engagement. |
6. What Good Looks Like / What Failure Looks Like
What mature, defensible, sustainable capability looks like
- Mature / defensible: A regional evidence graph with local legal-entity, customer, entity, transaction, report and action records for Canada and Mexico.
- Mature / defensible: Country-configured reporting, KYB, sanctions, investigation and data controls under one shared control taxonomy.
- Mature / defensible: Local language and evidence capacity paired with region-wide thematic intelligence and quality assurance.
- Mature / defensible: A financial/non-financial activity map that captures LFPIORPI/SAT relevance in Mexico and Canadian product/provincial context.
- Mature / defensible: Cross-border case governance that identifies every local report, authority, data path, customer action and U.S. nexus question.
What weak, misleading, fragile, or non-defensible implementation looks like
- Fragile / non-defensible: A single “North America SAR” queue that makes Canadian and Mexican legal triggers, report formats and authorities invisible.
- Fragile / non-defensible: A U.S. ruleset imposed on Canada and Mexico without country-specific legal translation, local data design or accountable ownership.
- Fragile / non-defensible: A Canada program that ignores provincial/product context, or a Mexico program that ignores the financial/non-financial perimeter and cash/trade reality.
- Fragile / non-defensible: Cross-border investigations that centralize data too slowly to support local reporting, action or supervisor engagement.
- Fragile / non-defensible: A national risk assessment treated as a static document rather than a source for products, data, scenarios, training and assurance.
7. Common Misconceptions and Contrarian Insights
“Canada and Mexico are just extensions of U.S. BSA/AML.”
They are distinct legal and supervisory systems with their own reports, authorities, market structures and implementation questions.
“FINTRAC guidance is only operational detail.”
It is crucial operational source material for reportability, narrative quality, compliance-program design and evidence expectations.
“Mexico’s AML framework is only for banks.”
The financial and non-financial preventive perimeter has major implications for customer, counterparty, cash, trade and merchant risk.
“One global ownership threshold answers both countries.”
Beneficial ownership, entity evidence, reporting and sanctions relevance must be assessed under applicable local and other legal regimes.
“Cross-border sharing is either prohibited or unrestricted.”
It requires a documented lawful purpose, data classification, access model, transfer route, confidentiality and local reporting plan.
8. Executive Discussion Questions
- Can management show which Canada and Mexico entities/products are in scope for each local requirement and authority?
- Are Canadian STR decisions and Mexican report categories implemented in separate, reconciled, high-quality workflows?
- Which cross-border corridors generate the greatest combined cash, remittance, trade, virtual-asset, sanctions and fraud risk?
- What does our regional data model preserve that a local investigator or supervisor needs but a global platform tends to hide?
- How do we distinguish local legal reporting, regional intelligence sharing and U.S.-nexus escalation?
- Does Mexico customer and counterparty due diligence reflect the non-financial activity perimeter where relevant?
- Can our sanctions decision record identify the distinct Canadian, U.S., Mexican or other legal source and action?
- Which national risk assessment insights have become actual scenario, segmentation, staffing and quality changes?
- Where do Canadian provincial or Mexico sector-specific requirements create a material operational exception?
- Are country teams able to challenge a regional model, vendor or policy when local evidence shows it is not working?
- What enforcement or supervision signal would force a coordinated Canada-Mexico-U.S. thematic review?
- Who owns the residual risk when regional standardization conflicts with local data, reporting, language or legal needs?
9. Practitioner and Specialist Checklists
Executive checklist
- Can we name the legal / policy question, accountable executive, local legal entity and decision authority?
- Can we see current evidence on coverage, quality, timeliness, customer impact, resilience and residual risk?
- Can we distinguish regulatory requirement, supervisory expectation, operating recommendation and untested assumption?
- Can we condition growth, product scope, outsourcing, data use or customer action when a guardrail is breached?
- Can we prove that a completed remediation is operating in BAU rather than merely deployed?
Operator checklist
- Map each decision to an in-scope population, trigger, data/evidence, procedure, system, owner, escalation, action and record.
- Reconcile source, case, report, action and quality data; do not allow unresolved data loss to become a business-as-usual assumption.
- Version rule, process, model, vendor, translation and report changes; retain test evidence and rollback/contingency decisions.
- Route complex, ambiguous, high-risk, cross-border, language or legal issues to named specialists with documented outcomes.
- Run recurring QA and root-cause analysis that reaches upstream policy, data, product, training and technology causes.
Specialist validation checklist
- Verify the applicable legal source, current effective date, scope, entity, product and authority before applying a control conclusion.
- Preserve primary source, locator, original language where relevant, translation/version, collection date, confidence and decision use.
- Test negative cases, population coverage, false positives, false negatives, overrides, edge conditions, timing and evidence reproducibility.
- Separate legal requirement, supervisory expectation, market practice and library operating inference in analysis and documentation.
- Record local variations, data restrictions, report interfaces, translation debt, legal advice and residual-risk decisions explicitly.
10. Module Glossary
| Term | Definition |
|---|---|
| CNBV | Mexico’s Comisión Nacional Bancaria y de Valores, a financial-sector supervisory authority with AML/CFT roles within its remit. |
| FINTRAC | Canada’s Financial Transactions and Reports Analysis Centre, with reporting, financial-intelligence and compliance functions. |
| LFPIORPI | Mexico’s Federal Law for the Prevention and Identification of Operations with Illicit Resources. |
| PCMLTFA | Canada’s Proceeds of Crime (Money Laundering) and Terrorist Financing Act. |
| SAT | Mexico’s Servicio de Administración Tributaria; relevant to the preventive-law operating environment. |
| STR | Suspicious Transaction Report under Canada’s FINTRAC reporting framework; do not use the label as a substitute for country-specific report analysis. |
| UIF | Mexico’s Unidad de Inteligencia Financiera. |
| Regional evidence graph | A linked set of entities, people, transactions, reports, actions and sources that retains country-specific facts and accountability. |
11. MLA 9 Works Cited
[S01] Canada. Proceeds of Crime (Money Laundering) and Terrorist Financing Act. Justice Laws Website, https://laws-lois.justice.gc.ca/eng/acts/p-24.501/. Accessed 9 Aug. 2026.
[S02] Financial Transactions and Reports Analysis Centre of Canada. Compliance Program Requirements. 11 Oct. 2024, https://fintrac-canafe.canada.ca/guidance-directives/compliance-conformite/guide4/4-eng. Accessed 9 Aug. 2026.
[S03] Financial Transactions and Reports Analysis Centre of Canada. Reporting Suspicious Transactions to FINTRAC. 22 May 2025, https://fintrac-canafe.canada.ca/guidance-directives/transaction-operation/str-dod/str-dod-eng. Accessed 9 Aug. 2026.
[S04] Financial Transactions and Reports Analysis Centre of Canada. Financial Transactions Reported to FINTRAC. 6 Aug. 2025, https://fintrac-canafe.canada.ca/individuals-individus/rpt-eng. Accessed 9 Aug. 2026.
[S05] Financial Transactions and Reports Analysis Centre of Canada. Financial Transactions Related to Countries Identified by the FATF. 28 Nov. 2025, https://fintrac-canafe.canada.ca/notices-avis/avs/2025-11-28-eng. Accessed 9 Aug. 2026.
[S06] Financial Transactions and Reports Analysis Centre of Canada. Webinar Recording: Sanctions Evasion, Property Reporting and the Listed Person or Entity Property Report. https://fintrac-canafe.canada.ca/training-formation/sanctions/video-eng. Accessed 9 Aug. 2026.
[S07] Department of Finance Canada. Canada’s Assessment of Money Laundering and Terrorist Financing Risks. 2023, https://www.canada.ca/en/department-finance/programs/financial-sector-policy/anti-money-laundering-anti-terrorist-financing/assessment-inherent-risks-money-laundering-terrorist-financing.html. Accessed 9 Aug. 2026.
[S08] Financial Transactions and Reports Analysis Centre of Canada. FINTRAC Imposes Administrative Monetary Penalty on Binance Holdings Limited. 9 May 2024, https://fintrac-canafe.canada.ca/new-neuf/nr/2024-05-09-eng. Accessed 9 Aug. 2026.
[S09] Canada. Special Economic Measures Act. Justice Laws Website, https://laws-lois.justice.gc.ca/eng/acts/s-14.5/. Accessed 9 Aug. 2026.
[S10] Mexico. Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita. Cámara de Diputados, https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPIORPI.pdf. Accessed 9 Aug. 2026.
[S11] Unidad de Inteligencia Financiera. Formatos Oficiales. Gobierno de México, https://www.gob.mx/uif/documentos/uif-marco-juridico-formatos-oficiales-337832. Accessed 9 Aug. 2026.
[S12] Comisión Nacional Bancaria y de Valores. Disposiciones Legales: Sofom ENR. Gobierno de México, https://www.gob.mx/cnbv/acciones-y-programas/disposiciones-legales-sofom-enr. Accessed 9 Aug. 2026.
[S13] Secretaría de Hacienda y Crédito Público. Evaluación Nacional de Riesgos de Lavado de Dinero y Financiamiento al Terrorismo 2023. https://www.pld.hacienda.gob.mx/work/models/PLD/documentos/enr2023.pdf. Accessed 9 Aug. 2026.
[S14] Servicio de Administración Tributaria. Portal de Prevención de Lavado de Dinero. https://sppld.sat.gob.mx/. Accessed 9 Aug. 2026.
[S15] Comisión Nacional Bancaria y de Valores. UIF y CNBV Suscriben Convenio que Fortalece la Coordinación del Sistema Nacional Antilavado. 16 Mar. 2026, https://www.gob.mx/cnbv/prensa/uif-y-cnbv-suscriben-convenio-que-fortalece-la-coordinacion-del-sistema-nacional-antilavado?idiom=es-MX. Accessed 9 Aug. 2026.
[S16] Comisión Nacional Bancaria y de Valores. Tablero de Control PLD/FT/FPADM. Gobierno de México, https://www.gob.mx/cnbv/acciones-y-programas/tablero-de-control-pld-ft-27892. Accessed 9 Aug. 2026.